<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-AU"
                       href="https://www.techradar.com/au/feeds/tag/security"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar AU in Security ]]></title>
                <link>https://www.techradar.com/au/pro/security</link>
        <description><![CDATA[ All the latest security content from the TechRadar  AU team ]]></description>
                                    <lastBuildDate>Fri, 11 Sep 2026 16:25:26 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Is Apple’s Live Rewind a privacy nightmare? Here’s how the Apple Watch feature really works — and whether it violates your privacy ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Apple debuted a new Apple Watch feature called Live Rewind</strong></li><li><strong>It lets you play back audio from the last 15 seconds</strong></li><li><strong>Some observers are worried it could violate people’s privacy</strong></li></ul><p>When Apple announced its Live Rewind feature at its <a href="https://www.techradar.com/tech-events/15-things-we-learned-from-apples-big-iphone-duo-and-iphone-18-pro-launch-from-its-first-ever-foldable-to-new-airpods">Surprise and Shine event</a> earlier this week, many observers were concerned that it would allow you to secretly record other people without their consent. After all, the tool just requires you to press a button on your Apple Watch and it plays back any audio that was captured during the last 15 seconds.</p><p>Is this feature a privacy nightmare, one that turns every Apple Watch into a “mass surveillance device,” as some people have worried? Or have people misunderstood what is happening, with Apple putting enough safeguards in place to prevent abuse and privacy violations? </p><p>Social media users seem to be divided, with some calling it <a href="https://www.reddit.com/r/watchos/comments/1wbvml6/did_anyone_else_find_live_rewind_creepy_and/" target="_blank">“creepy and antisocial,”</a> while others pointed out how it could be useful for <a href="https://www.reddit.com/r/watchos/comments/1wbvml6/comment/p8tjfis/" target="_blank">deaf people or those with autism</a>. Let’s take a look at the facts to find out what’s really going on.</p><h2 id="how-does-live-rewind-work">How does Live Rewind work?</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1747px;"><p class="vanilla-image-block" style="padding-top:56.27%;"><img id="CfeEiBmVW36npAEEyPzp25" name="Apple Live Rewind 1" alt="A person using the Live Rewind feature on an Apple Watch." src="https://cdn.mos.cms.futurecdn.net/CfeEiBmVW36npAEEyPzp25.jpg" mos="" align="middle" fullscreen="" width="1747" height="983" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Apple)</span></figcaption></figure><p>What is this Live Rewind feature that is causing so much consternation? According to Apple, users of the <a href="https://www.techradar.com/health-fitness/smartwatches/the-apple-watch-series-12-has-the-most-accurate-heart-rate-sensing-in-a-wearable-heres-where-to-preorder-apples-newest-smartwatch">Apple Watch Series 12</a> or <a href="https://www.techradar.com/health-fitness/smartwatches/apple-watch-ultra-4-vs-apple-watch-ultra-3-whats-changed-and-should-you-upgrade">Apple Watch Ultra 4</a> will be able to double-press the Digital Crown and receive a text transcription of what was said over the last 15 seconds. The company says this is useful if you missed something important, are deaf or hard of hearing, or are trying to recall a tip or recommendation from a friend. </p><p>Some people have worried that this would allow you to surreptitiously record other people without their knowledge, then save these recordings to your device for nefarious purposes. </p><p>However, Apple explained during the event that the feature never records or stores audio, it doesn’t identify anyone’s voice, and audio cannot be accessed by anyone (including Apple). To clarify matters, Apple has published an <a href="https://www.apple.com/privacy/docs/Audio_Intelligence_Privacy_Overview_Sep_2026.pdf" target="_blank">Audio Intelligence Privacy Overview</a> that lays out how this feature — and Apple’s other new Audio Intelligence tools, including <a href="https://www.techradar.com/health-fitness/smartwatches/thanks-to-siri-recaps-your-apple-watch-is-always-listening-as-you-go-about-your-day-but-apple-may-be-risking-a-meta-glasses-style-backlash">Siri Recap</a> — works in detail. </p><p>When it comes to Live Rewind, any audio is processed in the Apple Watch’s <a href="https://www.techradar.com/pro/apple-says-iphone-and-ipad-approved-by-nato-for-up-to-restricted-level-of-classified-data-a-level-of-government-certification-no-other-consumer-mobile-device-has-met">Secure Enclave</a>. This is a separate part of the S11 chip that, in this instance, processes audio. The Secure Enclave is siphoned off from the rest of the device and no part of the operating system can access it or the raw audio it handles. That includes both first- and third-party apps, and not even Apple can get to anything in the Secure Enclave. </p><p>Apple’s privacy paper notes that audio is never saved or recorded when you use Live Rewind. Instead, the audio is processed by the Secure Enclave and used to generate a transcript, then permanently deleted from both your device and from <a href="https://www.techradar.com/computing/software/what-is-icloud-and-is-it-worth-the-money">iCloud</a>. There’s no way anyone can listen to the audio at a later date or extract it from your device. </p><p>Audio flows into the Secure Enclave on a rolling basis, which means that old data is continuously overwritten and deleted when new audio comes in. When activated, Live Rewind tries to send the last 15 seconds of audio to your iPhone. If it can’t — such as if your iPhone is not within wireless range — the audio is immediately discarded. If the process is successful, the audio is converted to text on your iPhone, deleted, then the text is sent back to the Secure Enclave in your Apple Watch. </p><p>The saved text stays available on your Watch for 30 seconds after the screen dims, after which it is discarded. You can optionally choose to save it to the Siri app, where it is end-to-end encrypted. This is the only instance where something is saved in the Live Rewind process. As mentioned previously, the text does not contain any speaker attribution. </p><p>You can ask Siri about your transcripts, at which point the text is sent to Apple’s secure <a href="https://www.techradar.com/pro/apple-quietly-released-a-new-operating-system-that-almost-nobody-noticed-unnamed-os-surfaces-in-private-cloud-compute-blog-as-apple-goes-ballistic-on-ai">Private Cloud Compute</a> servers. If you use iCloud with two-factor authentication and have secured your device with a passcode, any transcripts from Live Rewind are synced using end-to-end encryption and not even Apple can decrypt them.</p><h2 id="respecting-those-around-you">Respecting those around you</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LeeQwmM58zoaEsjsewx635" name="Apple Live Rewind 2" alt="A person using the Live Rewind feature on an Apple Watch." src="https://cdn.mos.cms.futurecdn.net/LeeQwmM58zoaEsjsewx635.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Apple)</span></figcaption></figure><p>What about other people? Will they know that you’re using Live Rewind? Can you use the feature secretly?</p><p>Thankfully, you can’t really use Live Rewind without anyone knowing. When you double-press the Digital Crown, your Apple Watch plays an audible chime that occurs even if your device is in silent mode or you are listening via headphones. A full-screen animation also plays on screen and the microphone icon is displayed. Whether visually or through sound, your Apple Watch tries to alert other people about what is happening. </p><p>Apple also says that Live Rewind is opt-in rather than opt-out, and you can enable it when setting up a new device. You can also enable or disable the feature in Siri Settings on your Apple Watch or in the Siri Settings section of the Apple Watch app on your iPhone. </p><p>Although it would be polite to do so, there’s no way for Apple to force you to ask permission before using Live Rewind. But you might take some solace from the fact that there’s no way for anyone to save or extract the audio that the feature uses, nor can they attribute speakers. All a user gets out of it is a text transcript. </p><p>These privacy guardrails go some way to distancing Live Rewind from <a href="https://www.techradar.com/computing/virtual-reality-augmented-reality/meta-has-a-fresh-update-to-stop-people-from-turning-meta-smart-glasses-into-pervert-glasses-and-the-updates-will-keep-coming">Meta’s so-called “Pervert Glasses”</a> and their consent-busting data collection.</p><div data-widget-type="multimodelreview" data-widget-title="Today’s best Apple Watch deals" data-model-name="Apple Watch Ultra 4,Apple Watch Series 12,Apple Watch Ultra 3,Apple Watch SE 3,Apple Watch 11,Apple Watch Series 10"></div> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/health-fitness/smartwatches/is-apples-live-rewind-a-privacy-nightmare-heres-how-the-apple-watch-feature-really-works-and-whether-it-violates-your-privacy</link>
                                                                            <description>
                            <![CDATA[ Here’s everything you need to know about Live Rewind, Apple’s controversial new Apple Watch feature. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BJ9KAzgg7S2FqnbhKRPcQR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pQgtyLWmytpSru3K9u6wu4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 16:25:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smartwatches]]></category>
                                                    <category><![CDATA[Health & Fitness]]></category>
                                                                                                <author><![CDATA[ alexblake.techradar@gmail.com (Alex Blake) ]]></author>                    <dc:creator><![CDATA[ Alex Blake ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gwmVRU4zMGnDYsGVAFvRmL.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Alex Blake has been fooling around with computers since the early 1990s, and since that time he&#039;s learned a thing or two about tech. No more than two things, though. That&#039;s all his brain can hold. As well as TechRadar, Alex writes for iMore, Digital Trends and Creative Bloq, among others. He was previously commissioning editor at MacFormat magazine. That means he mostly covers the world of Apple and its latest products, but also Windows, computer peripherals, mobile apps, and much more beyond. When not writing, you can find him hiking the English countryside and gaming on his PC.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pQgtyLWmytpSru3K9u6wu4-1280-80.jpg">
                                                            <media:credit><![CDATA[Apple]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Live Rewind feature on an Apple Watch.]]></media:description>                                                            <media:text><![CDATA[The Live Rewind feature on an Apple Watch.]]></media:text>
                                <media:title type="plain"><![CDATA[The Live Rewind feature on an Apple Watch.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pQgtyLWmytpSru3K9u6wu4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Apple debuted a new Apple Watch feature called Live Rewind</strong></li><li><strong>It lets you play back audio from the last 15 seconds</strong></li><li><strong>Some observers are worried it could violate people’s privacy</strong></li></ul><p>When Apple announced its Live Rewind feature at its <a href="https://www.techradar.com/tech-events/15-things-we-learned-from-apples-big-iphone-duo-and-iphone-18-pro-launch-from-its-first-ever-foldable-to-new-airpods">Surprise and Shine event</a> earlier this week, many observers were concerned that it would allow you to secretly record other people without their consent. After all, the tool just requires you to press a button on your Apple Watch and it plays back any audio that was captured during the last 15 seconds.</p><p>Is this feature a privacy nightmare, one that turns every Apple Watch into a “mass surveillance device,” as some people have worried? Or have people misunderstood what is happening, with Apple putting enough safeguards in place to prevent abuse and privacy violations? </p><p>Social media users seem to be divided, with some calling it <a href="https://www.reddit.com/r/watchos/comments/1wbvml6/did_anyone_else_find_live_rewind_creepy_and/" target="_blank">“creepy and antisocial,”</a> while others pointed out how it could be useful for <a href="https://www.reddit.com/r/watchos/comments/1wbvml6/comment/p8tjfis/" target="_blank">deaf people or those with autism</a>. Let’s take a look at the facts to find out what’s really going on.</p><h2 id="how-does-live-rewind-work">How does Live Rewind work?</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1747px;"><p class="vanilla-image-block" style="padding-top:56.27%;"><img id="CfeEiBmVW36npAEEyPzp25" name="Apple Live Rewind 1" alt="A person using the Live Rewind feature on an Apple Watch." src="https://cdn.mos.cms.futurecdn.net/CfeEiBmVW36npAEEyPzp25.jpg" mos="" align="middle" fullscreen="" width="1747" height="983" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Apple)</span></figcaption></figure><p>What is this Live Rewind feature that is causing so much consternation? According to Apple, users of the <a href="https://www.techradar.com/health-fitness/smartwatches/the-apple-watch-series-12-has-the-most-accurate-heart-rate-sensing-in-a-wearable-heres-where-to-preorder-apples-newest-smartwatch">Apple Watch Series 12</a> or <a href="https://www.techradar.com/health-fitness/smartwatches/apple-watch-ultra-4-vs-apple-watch-ultra-3-whats-changed-and-should-you-upgrade">Apple Watch Ultra 4</a> will be able to double-press the Digital Crown and receive a text transcription of what was said over the last 15 seconds. The company says this is useful if you missed something important, are deaf or hard of hearing, or are trying to recall a tip or recommendation from a friend. </p><p>Some people have worried that this would allow you to surreptitiously record other people without their knowledge, then save these recordings to your device for nefarious purposes. </p><p>However, Apple explained during the event that the feature never records or stores audio, it doesn’t identify anyone’s voice, and audio cannot be accessed by anyone (including Apple). To clarify matters, Apple has published an <a href="https://www.apple.com/privacy/docs/Audio_Intelligence_Privacy_Overview_Sep_2026.pdf" target="_blank">Audio Intelligence Privacy Overview</a> that lays out how this feature — and Apple’s other new Audio Intelligence tools, including <a href="https://www.techradar.com/health-fitness/smartwatches/thanks-to-siri-recaps-your-apple-watch-is-always-listening-as-you-go-about-your-day-but-apple-may-be-risking-a-meta-glasses-style-backlash">Siri Recap</a> — works in detail. </p><p>When it comes to Live Rewind, any audio is processed in the Apple Watch’s <a href="https://www.techradar.com/pro/apple-says-iphone-and-ipad-approved-by-nato-for-up-to-restricted-level-of-classified-data-a-level-of-government-certification-no-other-consumer-mobile-device-has-met">Secure Enclave</a>. This is a separate part of the S11 chip that, in this instance, processes audio. The Secure Enclave is siphoned off from the rest of the device and no part of the operating system can access it or the raw audio it handles. That includes both first- and third-party apps, and not even Apple can get to anything in the Secure Enclave. </p><p>Apple’s privacy paper notes that audio is never saved or recorded when you use Live Rewind. Instead, the audio is processed by the Secure Enclave and used to generate a transcript, then permanently deleted from both your device and from <a href="https://www.techradar.com/computing/software/what-is-icloud-and-is-it-worth-the-money">iCloud</a>. There’s no way anyone can listen to the audio at a later date or extract it from your device. </p><p>Audio flows into the Secure Enclave on a rolling basis, which means that old data is continuously overwritten and deleted when new audio comes in. When activated, Live Rewind tries to send the last 15 seconds of audio to your iPhone. If it can’t — such as if your iPhone is not within wireless range — the audio is immediately discarded. If the process is successful, the audio is converted to text on your iPhone, deleted, then the text is sent back to the Secure Enclave in your Apple Watch. </p><p>The saved text stays available on your Watch for 30 seconds after the screen dims, after which it is discarded. You can optionally choose to save it to the Siri app, where it is end-to-end encrypted. This is the only instance where something is saved in the Live Rewind process. As mentioned previously, the text does not contain any speaker attribution. </p><p>You can ask Siri about your transcripts, at which point the text is sent to Apple’s secure <a href="https://www.techradar.com/pro/apple-quietly-released-a-new-operating-system-that-almost-nobody-noticed-unnamed-os-surfaces-in-private-cloud-compute-blog-as-apple-goes-ballistic-on-ai">Private Cloud Compute</a> servers. If you use iCloud with two-factor authentication and have secured your device with a passcode, any transcripts from Live Rewind are synced using end-to-end encryption and not even Apple can decrypt them.</p><h2 id="respecting-those-around-you">Respecting those around you</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LeeQwmM58zoaEsjsewx635" name="Apple Live Rewind 2" alt="A person using the Live Rewind feature on an Apple Watch." src="https://cdn.mos.cms.futurecdn.net/LeeQwmM58zoaEsjsewx635.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Apple)</span></figcaption></figure><p>What about other people? Will they know that you’re using Live Rewind? Can you use the feature secretly?</p><p>Thankfully, you can’t really use Live Rewind without anyone knowing. When you double-press the Digital Crown, your Apple Watch plays an audible chime that occurs even if your device is in silent mode or you are listening via headphones. A full-screen animation also plays on screen and the microphone icon is displayed. Whether visually or through sound, your Apple Watch tries to alert other people about what is happening. </p><p>Apple also says that Live Rewind is opt-in rather than opt-out, and you can enable it when setting up a new device. You can also enable or disable the feature in Siri Settings on your Apple Watch or in the Siri Settings section of the Apple Watch app on your iPhone. </p><p>Although it would be polite to do so, there’s no way for Apple to force you to ask permission before using Live Rewind. But you might take some solace from the fact that there’s no way for anyone to save or extract the audio that the feature uses, nor can they attribute speakers. All a user gets out of it is a text transcript. </p><p>These privacy guardrails go some way to distancing Live Rewind from <a href="https://www.techradar.com/computing/virtual-reality-augmented-reality/meta-has-a-fresh-update-to-stop-people-from-turning-meta-smart-glasses-into-pervert-glasses-and-the-updates-will-keep-coming">Meta’s so-called “Pervert Glasses”</a> and their consent-busting data collection.</p><div data-widget-type="multimodelreview" data-widget-title="Today’s best Apple Watch deals" data-model-name="Apple Watch Ultra 4,Apple Watch Series 12,Apple Watch Ultra 3,Apple Watch SE 3,Apple Watch 11,Apple Watch Series 10"></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US Treasury wants banks to be better at filing file cyber scam reports after noting nearly $13 billion in losses since 2023 ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>FinCEN warns US banks of industrial‑scale scam centers in Southeast Asia stealing billions</strong></li><li><strong>Victims coerced into crypto “investments,” later re‑scammed with fake recovery fees</strong></li><li><strong>Laundered via digital assets, mixers, shell firms, and Chinese underground banking networks</strong></li></ul><p>American financial institutions need to be more vigilant when it comes to identifying and preventing money scams, especially those perpetrated by industrial-scale scam centers in Southeast Asia. </p><p>This was the warning issued by the US Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) alongside a long list of red flags these institutions can monitor in order to stay safe.</p><h2 id="large-dangerous-crime-rings">Large, dangerous crime rings</h2><p>The scams are not done by small groups of teenagers, tricking the elderly from the depths of their parents’ basement, but are often large, well-organized crime machines responsible for billions of dollars in damages, around the world, every year. </p><p>In 2025 alone, US victims lost more than $7.2 billion to these scams, the warning said, and between September 2023 and December 2025, nearly $13 billion was stolen from Americans.</p><p>The criminal organizations are primarily located in Cambodia, Burma, and Laos. They trafficked hundreds of thousands of people to various centers around the countries, taking their passports and forcing them into participating in online fraud. Those that don’t meet certain quotas are often beaten - and some victims were liberated after their families paid ransom demands, while others ended up being coerced into commercial sex work. </p><p>To make matters worse, they are resilient to law enforcement activities because some of them are either endorsed, or outright operated by, local corrupt officials.</p><p>FinCEN says the criminals are engaged in all sorts of fraudulent activity, but stressed that investment fraud is, by far, the most popular one. The scammers would reach out to their victim either pretending to be a romantic interest, or a financial advisor. Sometimes, they would even begin the conversation by saying they mistyped a phone number.</p><p>After extensively communicating with their victim for a while, they try to persuade them into making an “investment”, often using cryptocurrencies, and promising unrealistically high returns. This is also, FinCEN stresses, is when the scams can most easily be identified:</p><p>“Most digital asset payments by victims to scam center operators originate from money services businesses (MSBs) offering digital asset services, includingdigital asset kiosks, according to FinCEN analysis and law enforcement information. Based on FinCEN’s analysis of BSA reporting, scammers often instruct their victims to open accounts withMSBs offeringdigital asset services to purchase specific types of digital assets. Then, the victim is told to send these funds toa digital asset address controlled by the scammers.”</p><p>But defrauding victims out of their hard-earned money is not where the scam ends. Instead, the criminals continue, this time abusing the emotional distress to cause even more harm. They pose as law enforcement, financial institutions, or even FinCEN itself, stating that they’re investigating (or that they have confiscated the stolen funds) and that the victims should pay a certain fee to have their funds returned to them.</p><p>In some cases, the fraudsters pose as investment advisors, telling the victims to take out their money, buy gold and silver bars, and hand them over to a courier for “safe keeping”.</p><p>The full list of red flags can be found on <a href="https://www.fincen.gov/system/files/2026-08/FinCEN-Alert-Scam-Centers.pdf" target="_blank">this link</a>, and FinCEN stresses that the circumstances around each individual case should be carefully considered, since no single red flag is “determinative of illicit or other suspicious activity.” </p><p>The circumstances include a customer’s historical financial activity, whether the transactions are in line with prevailing business practices, and whether the customer exhibits multiple related red flags.</p><h2 id="laundering-the-proceeds">Laundering the proceeds</h2><p>Stealing the money is only half of the work, though. It still needs to be laundered and reintroduced into the legitimate financial system, and to do that, scam center operators rely on professional money launderers and Chinese money laundering networks. </p><p>FinCEN describes a three-stage process, in which the criminals first extract payments in digital assets using bank accounts, money mules, shell companies, or fraudulent money services businesses. </p><p>Next, during on-chain laundering, they obfuscate the origins of the stolen money by rapidly moving it across addresses, using mixers, and swapping tokens across blockchains. The last step is to integrate the funds into the traditional financial system via money mules, stablecoin transfers to offshore exchanges, and Chinese underground banking networks.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/us-treasury-wants-banks-to-be-better-at-filing-file-cyber-scam-reports-after-noting-nearly-usd13-billion-in-losses-since-2023</link>
                                                                            <description>
                            <![CDATA[ Banks need to get better at reporting issues, so the US Treasury has shared a list of red flags and explained how the scams usually go. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xwb7XgPoaLNVHTjf6vcm9M</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 14:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>FinCEN warns US banks of industrial‑scale scam centers in Southeast Asia stealing billions</strong></li><li><strong>Victims coerced into crypto “investments,” later re‑scammed with fake recovery fees</strong></li><li><strong>Laundered via digital assets, mixers, shell firms, and Chinese underground banking networks</strong></li></ul><p>American financial institutions need to be more vigilant when it comes to identifying and preventing money scams, especially those perpetrated by industrial-scale scam centers in Southeast Asia. </p><p>This was the warning issued by the US Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) alongside a long list of red flags these institutions can monitor in order to stay safe.</p><h2 id="large-dangerous-crime-rings">Large, dangerous crime rings</h2><p>The scams are not done by small groups of teenagers, tricking the elderly from the depths of their parents’ basement, but are often large, well-organized crime machines responsible for billions of dollars in damages, around the world, every year. </p><p>In 2025 alone, US victims lost more than $7.2 billion to these scams, the warning said, and between September 2023 and December 2025, nearly $13 billion was stolen from Americans.</p><p>The criminal organizations are primarily located in Cambodia, Burma, and Laos. They trafficked hundreds of thousands of people to various centers around the countries, taking their passports and forcing them into participating in online fraud. Those that don’t meet certain quotas are often beaten - and some victims were liberated after their families paid ransom demands, while others ended up being coerced into commercial sex work. </p><p>To make matters worse, they are resilient to law enforcement activities because some of them are either endorsed, or outright operated by, local corrupt officials.</p><p>FinCEN says the criminals are engaged in all sorts of fraudulent activity, but stressed that investment fraud is, by far, the most popular one. The scammers would reach out to their victim either pretending to be a romantic interest, or a financial advisor. Sometimes, they would even begin the conversation by saying they mistyped a phone number.</p><p>After extensively communicating with their victim for a while, they try to persuade them into making an “investment”, often using cryptocurrencies, and promising unrealistically high returns. This is also, FinCEN stresses, is when the scams can most easily be identified:</p><p>“Most digital asset payments by victims to scam center operators originate from money services businesses (MSBs) offering digital asset services, includingdigital asset kiosks, according to FinCEN analysis and law enforcement information. Based on FinCEN’s analysis of BSA reporting, scammers often instruct their victims to open accounts withMSBs offeringdigital asset services to purchase specific types of digital assets. Then, the victim is told to send these funds toa digital asset address controlled by the scammers.”</p><p>But defrauding victims out of their hard-earned money is not where the scam ends. Instead, the criminals continue, this time abusing the emotional distress to cause even more harm. They pose as law enforcement, financial institutions, or even FinCEN itself, stating that they’re investigating (or that they have confiscated the stolen funds) and that the victims should pay a certain fee to have their funds returned to them.</p><p>In some cases, the fraudsters pose as investment advisors, telling the victims to take out their money, buy gold and silver bars, and hand them over to a courier for “safe keeping”.</p><p>The full list of red flags can be found on <a href="https://www.fincen.gov/system/files/2026-08/FinCEN-Alert-Scam-Centers.pdf" target="_blank">this link</a>, and FinCEN stresses that the circumstances around each individual case should be carefully considered, since no single red flag is “determinative of illicit or other suspicious activity.” </p><p>The circumstances include a customer’s historical financial activity, whether the transactions are in line with prevailing business practices, and whether the customer exhibits multiple related red flags.</p><h2 id="laundering-the-proceeds">Laundering the proceeds</h2><p>Stealing the money is only half of the work, though. It still needs to be laundered and reintroduced into the legitimate financial system, and to do that, scam center operators rely on professional money launderers and Chinese money laundering networks. </p><p>FinCEN describes a three-stage process, in which the criminals first extract payments in digital assets using bank accounts, money mules, shell companies, or fraudulent money services businesses. </p><p>Next, during on-chain laundering, they obfuscate the origins of the stolen money by rapidly moving it across addresses, using mixers, and swapping tokens across blockchains. The last step is to integrate the funds into the traditional financial system via money mules, stablecoin transfers to offshore exchanges, and Chinese underground banking networks.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A new Android attack combines malware and ransomware in a cocktail of cybercrime ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Zimperium uncovers Mantax Otax, Android malware merging infostealer, RAT, backdoor, and ransomware</strong></li><li><strong>Distributed via APKs on third‑party stores, social media, and phishing; older Android versions most at risk</strong></li><li><strong>Steals extensive data, enables remote monitoring, then encrypts files with AES and demands ransom</strong></li></ul><p>When threat actors target people’s devices, they usually infect it with one of many malware strains: an infostealer, a remote access trojan, a backdoor, or a ransomware encryptor. </p><p>Rarely do we see all of these functionalities merged into a single entity, and even rarer - to have it target Android mobile devices - yet, security researchers Zimperium discovered just that.</p><h2 id="mantax-otax">Mantax Otax</h2><p>The security outfit published an in-depth report on <a href="https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration" target="_blank" rel="nofollow">Mantax Otax</a>, a unique strain of malware circulating in the wild. It is apparently developed by an Indonesian threat actor, targeting victims in the country, but we don’t know exactly how many people are infected, or if this campaign is aimed primarily at business users, or individuals in general. </p><p>The malware is being distributed as a standalone APK, meaning it can be found on third-party app stores, Telegram channels, forums, and across social media. There are no traces of Mantax Otax on any of the official app repositories, including the Google Play Store, or Samsung’s Galaxy Store. Zimperium also speculates that it is likely being distributed via phishing emails.</p><p>Mantax Otax primarily targets users sporting older <a href="https://www.techradar.com/best/best-android-phones" target="_blank">Android phones</a>. Versions 9 and older are most at risk, since on these devices the attackers can make use of all of the malware’s features. Android 10 and newer models do get some protection:</p><p>“Conversely, on modern devices running Android 10 and above, the malware’s efficacy is severely hindered by native OS defenses, specifically Scoped Storage restrictions,” the researchers explained. “Due to these sandboxing rules, the ransomware is constrained to scanning only the application's localized external files directory, which drastically mitigates the blast radius and reduces the volume of accessible user files.”</p><p>Newer devices, as well as users of Zimperium’s Mobile Threat Defense (MTD) and Runtime Application Protection (zDefend) are said to be protected on a software level.</p><p>Another important caveat is the permissions. As is usual on Android devices, most <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> won’t work unless the user grants an extensive set of permissions beforehand. In this case, Mantax Otax first asks for admin privileges, after which it grants itself an extensive list of capabilities, from accessing SMS messages, to contacts, audio, and images. </p><p>It then requests accessibility permissions, fully taking over the compromised device.</p><h2 id="malicious-capabilities">Malicious capabilities</h2><p>Mantax Otax is said to be quite capable. It steals browser history, contacts, call logs, SMS messages, notifications, files, gallery media, Google account information, device specifications, location data, and application inventories. It can also pull WhatsApp information such as messages and profiles, and on Telegram it can also pull lock-screen PINs. </p><p>Infostealing features aside, it also serves as a remote monitoring tool, grabbing screenshots, recording the screen, or livestreaming it directly to the attackers. It can take photos using both the front and rear cameras, although Zimperium did not mention any microphone-recording capabilities. </p><p>Finally, once all of the data has been harvested, it encrypts user files with AES, deletes the originals, and appends a .enc extension. Victims are then shown a chat interface where they can communicate with the attackers directly and negotiate a ransom payment in exchange for getting their device back.</p><p>The tool seems to be in continuous development. Zimperium found two separate versions, one being an “evolution” of the other: “Notably, it has modified its network traffic behavior to utilize WebSockets and introduced a set of new commands,” the researchers said.</p><p>There is a reason why ransomware operators prefer targeting businesses instead of individuals. Although the latter has not disappeared entirely from the victim list, businesses stand to lose a lot more from disrupted operations and, as such, are targeted more frequently. Unfortunately, we don’t know what kind of app Mantax Otax is spoofing, therefore it is difficult to assess who the targets are. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/a-new-android-attack-combines-malware-and-ransomware-in-a-cocktail-of-cybercrime</link>
                                                                            <description>
                            <![CDATA[ Unique malware variant spotted targeting Android users, taking photos with victim cameras before deploying an encryptor. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WUzPMz4TuL4FYGCGUqTivX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BiyAK4BXKKfecCWadFcHGo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BiyAK4BXKKfecCWadFcHGo-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / tomeqs]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android reboot interface]]></media:description>                                                            <media:text><![CDATA[Android reboot interface]]></media:text>
                                <media:title type="plain"><![CDATA[Android reboot interface]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BiyAK4BXKKfecCWadFcHGo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Zimperium uncovers Mantax Otax, Android malware merging infostealer, RAT, backdoor, and ransomware</strong></li><li><strong>Distributed via APKs on third‑party stores, social media, and phishing; older Android versions most at risk</strong></li><li><strong>Steals extensive data, enables remote monitoring, then encrypts files with AES and demands ransom</strong></li></ul><p>When threat actors target people’s devices, they usually infect it with one of many malware strains: an infostealer, a remote access trojan, a backdoor, or a ransomware encryptor. </p><p>Rarely do we see all of these functionalities merged into a single entity, and even rarer - to have it target Android mobile devices - yet, security researchers Zimperium discovered just that.</p><h2 id="mantax-otax">Mantax Otax</h2><p>The security outfit published an in-depth report on <a href="https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration" target="_blank" rel="nofollow">Mantax Otax</a>, a unique strain of malware circulating in the wild. It is apparently developed by an Indonesian threat actor, targeting victims in the country, but we don’t know exactly how many people are infected, or if this campaign is aimed primarily at business users, or individuals in general. </p><p>The malware is being distributed as a standalone APK, meaning it can be found on third-party app stores, Telegram channels, forums, and across social media. There are no traces of Mantax Otax on any of the official app repositories, including the Google Play Store, or Samsung’s Galaxy Store. Zimperium also speculates that it is likely being distributed via phishing emails.</p><p>Mantax Otax primarily targets users sporting older <a href="https://www.techradar.com/best/best-android-phones" target="_blank">Android phones</a>. Versions 9 and older are most at risk, since on these devices the attackers can make use of all of the malware’s features. Android 10 and newer models do get some protection:</p><p>“Conversely, on modern devices running Android 10 and above, the malware’s efficacy is severely hindered by native OS defenses, specifically Scoped Storage restrictions,” the researchers explained. “Due to these sandboxing rules, the ransomware is constrained to scanning only the application's localized external files directory, which drastically mitigates the blast radius and reduces the volume of accessible user files.”</p><p>Newer devices, as well as users of Zimperium’s Mobile Threat Defense (MTD) and Runtime Application Protection (zDefend) are said to be protected on a software level.</p><p>Another important caveat is the permissions. As is usual on Android devices, most <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> won’t work unless the user grants an extensive set of permissions beforehand. In this case, Mantax Otax first asks for admin privileges, after which it grants itself an extensive list of capabilities, from accessing SMS messages, to contacts, audio, and images. </p><p>It then requests accessibility permissions, fully taking over the compromised device.</p><h2 id="malicious-capabilities">Malicious capabilities</h2><p>Mantax Otax is said to be quite capable. It steals browser history, contacts, call logs, SMS messages, notifications, files, gallery media, Google account information, device specifications, location data, and application inventories. It can also pull WhatsApp information such as messages and profiles, and on Telegram it can also pull lock-screen PINs. </p><p>Infostealing features aside, it also serves as a remote monitoring tool, grabbing screenshots, recording the screen, or livestreaming it directly to the attackers. It can take photos using both the front and rear cameras, although Zimperium did not mention any microphone-recording capabilities. </p><p>Finally, once all of the data has been harvested, it encrypts user files with AES, deletes the originals, and appends a .enc extension. Victims are then shown a chat interface where they can communicate with the attackers directly and negotiate a ransom payment in exchange for getting their device back.</p><p>The tool seems to be in continuous development. Zimperium found two separate versions, one being an “evolution” of the other: “Notably, it has modified its network traffic behavior to utilize WebSockets and introduced a set of new commands,” the researchers said.</p><p>There is a reason why ransomware operators prefer targeting businesses instead of individuals. Although the latter has not disappeared entirely from the victim list, businesses stand to lose a lot more from disrupted operations and, as such, are targeted more frequently. Unfortunately, we don’t know what kind of app Mantax Otax is spoofing, therefore it is difficult to assess who the targets are. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thinking like a hacker is key to strengthening resilience ]]></title>
                                                                                                <dc:content><![CDATA[ <p>If you've worked in <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> for as long as I have, then you'll know there are a couple of things you can count on. First, the threats that are out there never stop evolving. And second, sooner or later, you're going to be in the bullseye.</p><p>What makes life so much harder today is that AI and other automated tools have dramatically narrowed the gap between vulnerability discovery and the time it takes to exploit them. </p><p>And when this can now be measured in minutes – seconds, even – you know you have a problem. This fundamental change in the way adversaries operate means we no longer have the luxury of time to understand an attack, assess the risk and decide what to do next.</p><p>Which means we have to be better prepared and have resiliency for whatever is thrown at us. </p><h2 id="visibility-is-key">Visibility is key</h2><p>For me, that starts with accepting a simple reality: you cannot defend what you cannot see. And it’s why visibility is one of the most important capabilities an organization can develop.</p><p>After all, if you understand what exists within your environment – how those systems interact and what normal looks like – then you're in a much stronger position to identify unusual behavior before it develops into something more serious.   </p><p>Observability, on the other hand, takes that visibility to the next level. It provides the context <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> teams need to make informed decisions quickly, especially when time is working against them. </p><p>In other words, visibility tells you what is happening, while observability helps you understand why it's happening.</p><p>And that’s crucial. Today's organizations operate across on-premises <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud</a> environments, networks, and an increasing number of connected technologies.   </p><p>As those environments become more distributed, understanding what's happening across them becomes significantly harder.</p><p>Without that visibility, it's difficult to understand where your risks are, how systems interact, or where an attacker may be able to exploit a weakness.</p><h2 id="think-like-a-hacker">Think like a hacker</h2><p>Which leads me neatly onto my next point. Throughout my career, including my time working in offensive cyber operations in the intelligence community, I've found that the most effective way to understand risk is to think like the adversary.</p><p>I start by asking how someone would attack an organization and then work backwards to identify and close gaps.</p><p>That’s because attackers don't see organizations in the way that you or I might do. They’re always on the hunt for a toehold in.  They look for weaknesses in people, processes and technologies.</p><p>They look for the easiest route first to achieve their objective. And then they exploit that weakness.</p><p>And it’s an approach I would urge all security leaders to adopt if they want to stay one step ahead.</p><p>That means continuously asking where an attacker would start, how they would move through the organization and what controls would slow them down or stop them altogether.</p><p>But for this to work, it also requires organizations to design resilience into the way they operate. And that’s something we’ve embedded across our organization. </p><p>For instance, we have internal and external teams that conduct continuous product, enterprise, spear-phishing and physical penetration testing.</p><p>For us, it's about educating the team across the <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> to ensure they remain vigilant. But it’s also about inoculating people so that when they see something suspicious online, they have that instinct that something might be wrong and they report it.</p><p>We also want to make it easy for people to report events so we can analyze them quickly and better understand the targeting.</p><h2 id="secure-by-design">Secure by design</h2><p>We’ve also invested heavily in Secure by Design to ensure that all the products we deliver to <a href="https://www.techradar.com/best/the-best-customer-database-software-of-year">customers</a> are as secure as humanly possible. In practice, it means being able to trace every piece of code back to its source and verify its integrity throughout the development process.</p><p>It's similar to maintaining a chain of custody for evidence. We want to know exactly where software components come from, how they're verified and how they're protected throughout the entire build process.</p><p>More broadly, Secure by Design is increasingly being adopted across our industry as organizations recognize the importance of software integrity, traceability and transparency throughout the development lifecycle.</p><p>This is important because, as I said at the beginning, there are two certainties in cybersecurity: threats will continue to evolve, and organizations will continue to be targeted. Businesses across the world must adapt quickly to the grim reality that a cybersecurity incident isn’t a matter of if, but a matter of when. And AI is supercharging the pace at which all this is happening and broadening the blast radius of any attack.</p><p>That’s why you need to understand your environment well enough to reduce unnecessary risk, detect malicious activity quickly and limit the blast radius when something does happen. Pair that with a clearly defined and tested plan for recovery and that's what robust cyber resilience looks like in practice.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/thinking-like-a-hacker-is-key-to-strengthening-resilience</link>
                                                                            <description>
                            <![CDATA[ Cyber threats are moving faster than ever. A businesses resilience needs to keep pace. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">B8gAQ7WuciV4xJT3TtAFEj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 11:06:09 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Justin Henkel ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If you've worked in <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> for as long as I have, then you'll know there are a couple of things you can count on. First, the threats that are out there never stop evolving. And second, sooner or later, you're going to be in the bullseye.</p><p>What makes life so much harder today is that AI and other automated tools have dramatically narrowed the gap between vulnerability discovery and the time it takes to exploit them. </p><p>And when this can now be measured in minutes – seconds, even – you know you have a problem. This fundamental change in the way adversaries operate means we no longer have the luxury of time to understand an attack, assess the risk and decide what to do next.</p><p>Which means we have to be better prepared and have resiliency for whatever is thrown at us. </p><h2 id="visibility-is-key">Visibility is key</h2><p>For me, that starts with accepting a simple reality: you cannot defend what you cannot see. And it’s why visibility is one of the most important capabilities an organization can develop.</p><p>After all, if you understand what exists within your environment – how those systems interact and what normal looks like – then you're in a much stronger position to identify unusual behavior before it develops into something more serious.   </p><p>Observability, on the other hand, takes that visibility to the next level. It provides the context <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> teams need to make informed decisions quickly, especially when time is working against them. </p><p>In other words, visibility tells you what is happening, while observability helps you understand why it's happening.</p><p>And that’s crucial. Today's organizations operate across on-premises <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud</a> environments, networks, and an increasing number of connected technologies.   </p><p>As those environments become more distributed, understanding what's happening across them becomes significantly harder.</p><p>Without that visibility, it's difficult to understand where your risks are, how systems interact, or where an attacker may be able to exploit a weakness.</p><h2 id="think-like-a-hacker">Think like a hacker</h2><p>Which leads me neatly onto my next point. Throughout my career, including my time working in offensive cyber operations in the intelligence community, I've found that the most effective way to understand risk is to think like the adversary.</p><p>I start by asking how someone would attack an organization and then work backwards to identify and close gaps.</p><p>That’s because attackers don't see organizations in the way that you or I might do. They’re always on the hunt for a toehold in.  They look for weaknesses in people, processes and technologies.</p><p>They look for the easiest route first to achieve their objective. And then they exploit that weakness.</p><p>And it’s an approach I would urge all security leaders to adopt if they want to stay one step ahead.</p><p>That means continuously asking where an attacker would start, how they would move through the organization and what controls would slow them down or stop them altogether.</p><p>But for this to work, it also requires organizations to design resilience into the way they operate. And that’s something we’ve embedded across our organization. </p><p>For instance, we have internal and external teams that conduct continuous product, enterprise, spear-phishing and physical penetration testing.</p><p>For us, it's about educating the team across the <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> to ensure they remain vigilant. But it’s also about inoculating people so that when they see something suspicious online, they have that instinct that something might be wrong and they report it.</p><p>We also want to make it easy for people to report events so we can analyze them quickly and better understand the targeting.</p><h2 id="secure-by-design">Secure by design</h2><p>We’ve also invested heavily in Secure by Design to ensure that all the products we deliver to <a href="https://www.techradar.com/best/the-best-customer-database-software-of-year">customers</a> are as secure as humanly possible. In practice, it means being able to trace every piece of code back to its source and verify its integrity throughout the development process.</p><p>It's similar to maintaining a chain of custody for evidence. We want to know exactly where software components come from, how they're verified and how they're protected throughout the entire build process.</p><p>More broadly, Secure by Design is increasingly being adopted across our industry as organizations recognize the importance of software integrity, traceability and transparency throughout the development lifecycle.</p><p>This is important because, as I said at the beginning, there are two certainties in cybersecurity: threats will continue to evolve, and organizations will continue to be targeted. Businesses across the world must adapt quickly to the grim reality that a cybersecurity incident isn’t a matter of if, but a matter of when. And AI is supercharging the pace at which all this is happening and broadening the blast radius of any attack.</p><p>That’s why you need to understand your environment well enough to reduce unnecessary risk, detect malicious activity quickly and limit the blast radius when something does happen. Pair that with a clearly defined and tested plan for recovery and that's what robust cyber resilience looks like in practice.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Connecting defense capability for operational advantage ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Defense is operating in an environment where the pace of change continues to increase. Adversaries are adapting quickly and technology development cycles are becoming shorter. The boundaries between physical and digital operations are also becoming harder to define, while military commanders have more information available to them than ever before.</p><p>This changes how operational advantage is achieved. The performance of an individual platform or system remains important, but so does its ability to work effectively within the wider operational environment. Information needs to move securely to where it is needed, supporting decisions and action across different domains.</p><p>As new technologies are introduced, integration will become an increasingly important part of defense capability. The challenge is making sure innovation can be put to practical use alongside the systems and <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> already supporting operations.</p><h2 id="connecting-technology-across-defence">Connecting technology across defence</h2><p>Conversations around defense innovation often focus on AI, autonomous systems, advanced sensors, cyber capability and space assets. Each has a significant role to play, but none operates in isolation.</p><p>Information gathered by one system may need to be shared across multiple domains before it supports an operational decision. Networks, <a href="https://www.techradar.com/best/best-data-recovery-software">data</a>, command systems and people all contribute to that process. The value of any individual technology is linked to how effectively it connects with the wider operational environment.</p><p>This principle also applies to the infrastructure supporting military operations. Communications networks, operational facilities and digital systems all contribute to creating an environment where information can move securely and reliably. As these environments evolve, resilience and <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> must be designed from the outset though approaches such as secure-by-design and zero-trust principles.</p><h2 id="strengthening-the-foundations-of-operational-capability">Strengthening the foundations of operational capability</h2><p>AI has become one of the defining topics in defense. Its ability to process information and support decision-making has significant potential, but those capabilities depend on the quality of the data available and the resilience of the infrastructure that carries it.</p><p>Reliable communications, trusted data and secure networks remain fundamental to operational effectiveness. If those foundations are unavailable or compromised, the benefits of advanced technologies are reduced.</p><p>Therefore, creating decision advantage is not simply a technology challenge. It is an infrastructure and digital challenge and increasingly, a collaboration challenge.</p><p>For organizations supporting critical infrastructure, this has become an increasingly familiar challenge. Communications, operational technology, and digital infrastructure must work together to create environments where reliability cannot be compromised.</p><h2 id="keeping-people-at-the-heart-of-automation">Keeping people at the heart of automation</h2><p>Automation is attracting considerable attention across defense as organizations are looking to improve efficiency and increase operational tempo. However, automation should never be viewed as an end.</p><p>Its greatest value often comes from reducing routine activity rather than replacing people. Predictive maintenance, autonomous <a href="https://www.techradar.com/best/best-network-monitoring-tools">monitoring</a>, automated network <a href="https://www.techradar.com/best/it-management-tools">management</a> and logistics optimization all help reduce the time spent on repetitive tasks, allowing highly trained personnel to focus on areas where experience and judgement remain essential.</p><p>The most effective technologies do not replace human capability - they amplify it.</p><h2 id="the-infrastructure-supporting-multi-domain-operations">The infrastructure supporting multi-domain operations</h2><p>As operations become increasingly integrated across land, sea, air, cyber and space, infrastructure is taking on greater strategic importance. Communications, transport, energy, and digital systems all contribute to operational capability, showing how infrastructure and technology are becoming increasingly interdependent.</p><p>The movement of people, information, energy, and capability all contribute to operational readiness. Reliable infrastructure enables those elements to function as a single system, ensuring capability can be delivered when and where it is needed.</p><p>One example can be seen in the Falkland Islands, where runway infrastructure forms part of maintaining long-term strategic capability and readiness. It illustrates how infrastructure and operational capability are becoming increasingly interconnected.</p><h2 id="bringing-innovation-into-operational-use">Bringing innovation into operational use</h2><p>The UK benefits from an established community of innovators, with government, industry, academia, <a href="https://www.techradar.com/best/best-small-business-software">SMEs</a> and the Armed Forces all contributing to the development of new ideas and technologies. The opportunity now is to ensure those innovations can be adopted enough to meet operational needs.</p><p>Collaboration is still a critical part of this process. Bringing together different perspectives helps ensure technology is developed with practical application in mind and can be integrated more effectively into future capability.</p><h2 id="delivering-the-next-phase-of-defense-capability">Delivering the next phase of defense capability</h2><p>Much of the technology required to support future defense operations already exists. The focus now needs to be on how quickly it can be integrated and put to operational use, giving the Armed Forces the advantage they need as threats and operating environments continue to change. That requires stronger connections across networks, data, platforms, people and infrastructure.</p><p>Collaboration between government, industry, academia, SMEs and the Armed Forces will remain central to moving capability from development into deployment. Technologies also need a clearer and faster route beyond demonstrations and pilots, so useful capability reaches operators when it is needed.</p><p>The organizations that succeed will be those able to bring people and technology together across the wider defense environment. Doing that securely, reliably and at pace will determine how effectively innovation translates into operational advantage.</p><p><em></em><a href="https://www.techradar.com/best/best-ai-tools"><em>We've featured the best AI tool.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/connecting-defense-capability-for-operational-advantage</link>
                                                                            <description>
                            <![CDATA[ As new technologies are introduced, integration will become an increasingly important part of defense capability. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5uAHbFj4ZYXLAzRYwUVqX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 10:25:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Barry Zielinski ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Defense is operating in an environment where the pace of change continues to increase. Adversaries are adapting quickly and technology development cycles are becoming shorter. The boundaries between physical and digital operations are also becoming harder to define, while military commanders have more information available to them than ever before.</p><p>This changes how operational advantage is achieved. The performance of an individual platform or system remains important, but so does its ability to work effectively within the wider operational environment. Information needs to move securely to where it is needed, supporting decisions and action across different domains.</p><p>As new technologies are introduced, integration will become an increasingly important part of defense capability. The challenge is making sure innovation can be put to practical use alongside the systems and <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> already supporting operations.</p><h2 id="connecting-technology-across-defence">Connecting technology across defence</h2><p>Conversations around defense innovation often focus on AI, autonomous systems, advanced sensors, cyber capability and space assets. Each has a significant role to play, but none operates in isolation.</p><p>Information gathered by one system may need to be shared across multiple domains before it supports an operational decision. Networks, <a href="https://www.techradar.com/best/best-data-recovery-software">data</a>, command systems and people all contribute to that process. The value of any individual technology is linked to how effectively it connects with the wider operational environment.</p><p>This principle also applies to the infrastructure supporting military operations. Communications networks, operational facilities and digital systems all contribute to creating an environment where information can move securely and reliably. As these environments evolve, resilience and <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> must be designed from the outset though approaches such as secure-by-design and zero-trust principles.</p><h2 id="strengthening-the-foundations-of-operational-capability">Strengthening the foundations of operational capability</h2><p>AI has become one of the defining topics in defense. Its ability to process information and support decision-making has significant potential, but those capabilities depend on the quality of the data available and the resilience of the infrastructure that carries it.</p><p>Reliable communications, trusted data and secure networks remain fundamental to operational effectiveness. If those foundations are unavailable or compromised, the benefits of advanced technologies are reduced.</p><p>Therefore, creating decision advantage is not simply a technology challenge. It is an infrastructure and digital challenge and increasingly, a collaboration challenge.</p><p>For organizations supporting critical infrastructure, this has become an increasingly familiar challenge. Communications, operational technology, and digital infrastructure must work together to create environments where reliability cannot be compromised.</p><h2 id="keeping-people-at-the-heart-of-automation">Keeping people at the heart of automation</h2><p>Automation is attracting considerable attention across defense as organizations are looking to improve efficiency and increase operational tempo. However, automation should never be viewed as an end.</p><p>Its greatest value often comes from reducing routine activity rather than replacing people. Predictive maintenance, autonomous <a href="https://www.techradar.com/best/best-network-monitoring-tools">monitoring</a>, automated network <a href="https://www.techradar.com/best/it-management-tools">management</a> and logistics optimization all help reduce the time spent on repetitive tasks, allowing highly trained personnel to focus on areas where experience and judgement remain essential.</p><p>The most effective technologies do not replace human capability - they amplify it.</p><h2 id="the-infrastructure-supporting-multi-domain-operations">The infrastructure supporting multi-domain operations</h2><p>As operations become increasingly integrated across land, sea, air, cyber and space, infrastructure is taking on greater strategic importance. Communications, transport, energy, and digital systems all contribute to operational capability, showing how infrastructure and technology are becoming increasingly interdependent.</p><p>The movement of people, information, energy, and capability all contribute to operational readiness. Reliable infrastructure enables those elements to function as a single system, ensuring capability can be delivered when and where it is needed.</p><p>One example can be seen in the Falkland Islands, where runway infrastructure forms part of maintaining long-term strategic capability and readiness. It illustrates how infrastructure and operational capability are becoming increasingly interconnected.</p><h2 id="bringing-innovation-into-operational-use">Bringing innovation into operational use</h2><p>The UK benefits from an established community of innovators, with government, industry, academia, <a href="https://www.techradar.com/best/best-small-business-software">SMEs</a> and the Armed Forces all contributing to the development of new ideas and technologies. The opportunity now is to ensure those innovations can be adopted enough to meet operational needs.</p><p>Collaboration is still a critical part of this process. Bringing together different perspectives helps ensure technology is developed with practical application in mind and can be integrated more effectively into future capability.</p><h2 id="delivering-the-next-phase-of-defense-capability">Delivering the next phase of defense capability</h2><p>Much of the technology required to support future defense operations already exists. The focus now needs to be on how quickly it can be integrated and put to operational use, giving the Armed Forces the advantage they need as threats and operating environments continue to change. That requires stronger connections across networks, data, platforms, people and infrastructure.</p><p>Collaboration between government, industry, academia, SMEs and the Armed Forces will remain central to moving capability from development into deployment. Technologies also need a clearer and faster route beyond demonstrations and pilots, so useful capability reaches operators when it is needed.</p><p>The organizations that succeed will be those able to bring people and technology together across the wider defense environment. Doing that securely, reliably and at pace will determine how effectively innovation translates into operational advantage.</p><p><em></em><a href="https://www.techradar.com/best/best-ai-tools"><em>We've featured the best AI tool.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Storage infrastructure will underpin post-quantum security ]]></title>
                                                                                                <dc:content><![CDATA[ <p>AI has rewritten the enterprise <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> playbook. Workflows no longer just create temporary operational data, but vast amounts of high-value assets, from LLM training datasets and model outputs to logs, metadata and archived knowledge that may need to be preserved for years.</p><p>As enterprise tech leaders seek to scale <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> to meet these demands, storage requirements are undergoing a fundamental shift. Capacity and performance remain critical, but data <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> has become equally important. Today, long-term data integrity and absolute cyber resilience carry equal weight.</p><p>Protecting this data, however, is no longer just about defeating today’s threat vectors. It requires preparing storage infrastructure for a significant shift: the arrival of quantum computing. </p><h2 id="data-is-a-long-term-strategic-asset-not-a-short-lived-trend">Data is a long-term strategic asset, not a short-lived trend</h2><p>AI is accelerating data growth, but it can also extend the useful life of information. Data recorded today will be harvested for compliance, advanced analytics and model retraining for years to come.</p><p>To manage this economically, enterprise architectures rely heavily on high-capacity <a href="https://www.techradar.com/news/10-best-internal-desktop-and-laptop-hard-disk-drives-2016">HDDs</a>. While flash technologies dominate performance-critical hot tiers, HDDs remain the undisputed backbone of large-scale storage, providing the capacity, economics and longevity needed to archive data at scale.</p><p>As a result, organizations must consider how to protect not only today's data, but also its future value. After all, if the underlying infrastructure is compromised down the road, the very assets driving future AI innovations become the biggest operational and regulatory liability. </p><h2 id="harvest-now-decrypt-later">Harvest now, decrypt later</h2><p>Current encryption technologies remain effective against conventional threats. However, quantum computing is expected to challenge some of the cryptographic methods used for <a href="https://www.techradar.com/best/best-authenticator-apps">authentication</a> and key exchange.</p><p>This has led to concerns around “harvest now, decrypt later” attacks, where encrypted data is collected today with the expectation that future quantum capabilities could potentially decrypt it later.</p><p>For organizations storing sensitive intellectual property, research data or AI training datasets, this means security decisions made today could have implications for years to come.</p><p>Preparing for that future requires action from security leaders and IT directors now.</p><h2 id="security-must-be-built-into-the-infrastructure">Security must be built into the infrastructure</h2><p>Security is often viewed through the lens of data encryption, and with good reason. Self-encrypting drives (SEDs) provide always-on, hardware-based AES-256 encryption that helps protect data at rest without impacting performance.</p><p>But protecting data alone is no longer enough.</p><p><a href="https://www.techradar.com/news/the-10-best-nas-devices-reviewed">Storage</a> devices themselves must be trusted. Firmware, authentication mechanisms, provisioning processes and diagnostic tools all play a role in ensuring a drive operates securely throughout its lifecycle.</p><p>If attackers compromise a device's firmware or trust architecture, broader security controls can be undermined regardless of how data is encrypted elsewhere in the system. This makes storage security a critical component of overall cyber resilience.</p><h2 id="implementing-quantum-resistant-defenses-in-storage">Implementing quantum-resistant defenses in storage</h2><p>To counter these emerging attack vectors, the storage industry is actively embedding post-quantum cryptography into hardware architecture of enterprise hard drives. Rather than focusing solely on protecting data, the objective is to protect the trust architecture that underpins the drive itself.</p><p>Post quantum cryptography (PQC) technologies are being incorporated into areas such as secure key establishment, firmware authentication, secure provisioning, and trusted diagnostics. These capabilities are designed in alignment with established NIST post-quantum standards and are implemented using hybrid approaches that combine classical cryptography with quantum-resistant algorithms.</p><p>In practical terms, this means that the mechanisms responsible for establishing trust, validating firmware integrity and protecting administrative functions can remain resilient against both conventional and future quantum-enabled attacks. With the operational service life of HDDs often spanning 5 years (or more), implementing PQC today helps protect against quantum-based threats that may not materialize for several years, but that we know are coming.</p><p>Importantly, HDDs have long incorporated security controls to defend against today's threats. PQC does not replace these protections; it enhances them by adding an additional layer of resilience against emerging attack vectors. </p><h2 id="trust-in-the-ai-era">Trust in the AI era</h2><p>For many years, storage innovation was primarily defined by increases in capacity. Today, the expectations placed on infrastructure are much broader.</p><p>Organizations seek storage platforms that can scale with AI-driven data growth, deliver reliable performance, preserve integrity over long retention periods and withstand an increasingly complex threat environment.</p><p>PQC represents an important step in that evolution. By extending protection beyond data encryption and into the trust mechanisms that underpin storage devices themselves, PQC-enabled HDDs help organizations prepare for the security challenges of tomorrow while protecting the data they manage today.</p><p>As AI continues to elevate the strategic value of enterprise data, security can no longer be a short-term, reactive consideration. Trust must be engineered directly into the hardware layer and built to outlast the threats of today, tomorrow and the quantum era ahead of us. </p><p><em></em><a href="https://www.techradar.com/news/best-solid-state-drives-ssds"><em>We've featured the best SSD.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/storage-infrastructure-will-underpin-post-quantum-security</link>
                                                                            <description>
                            <![CDATA[ Protect long-term enterprise AI data from future quantum threats by securing underlying storage infrastructure today. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UdPZaDq9Lx8N5XgxywteL6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/M6fvPLRyP9CRCBwfYj7mxL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 09:54:23 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Uwe Kemmer ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/M6fvPLRyP9CRCBwfYj7mxL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital representations of phones and cards in slots]]></media:description>                                                            <media:text><![CDATA[Digital representations of phones and cards in slots]]></media:text>
                                <media:title type="plain"><![CDATA[Digital representations of phones and cards in slots]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/M6fvPLRyP9CRCBwfYj7mxL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI has rewritten the enterprise <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> playbook. Workflows no longer just create temporary operational data, but vast amounts of high-value assets, from LLM training datasets and model outputs to logs, metadata and archived knowledge that may need to be preserved for years.</p><p>As enterprise tech leaders seek to scale <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> to meet these demands, storage requirements are undergoing a fundamental shift. Capacity and performance remain critical, but data <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> has become equally important. Today, long-term data integrity and absolute cyber resilience carry equal weight.</p><p>Protecting this data, however, is no longer just about defeating today’s threat vectors. It requires preparing storage infrastructure for a significant shift: the arrival of quantum computing. </p><h2 id="data-is-a-long-term-strategic-asset-not-a-short-lived-trend">Data is a long-term strategic asset, not a short-lived trend</h2><p>AI is accelerating data growth, but it can also extend the useful life of information. Data recorded today will be harvested for compliance, advanced analytics and model retraining for years to come.</p><p>To manage this economically, enterprise architectures rely heavily on high-capacity <a href="https://www.techradar.com/news/10-best-internal-desktop-and-laptop-hard-disk-drives-2016">HDDs</a>. While flash technologies dominate performance-critical hot tiers, HDDs remain the undisputed backbone of large-scale storage, providing the capacity, economics and longevity needed to archive data at scale.</p><p>As a result, organizations must consider how to protect not only today's data, but also its future value. After all, if the underlying infrastructure is compromised down the road, the very assets driving future AI innovations become the biggest operational and regulatory liability. </p><h2 id="harvest-now-decrypt-later">Harvest now, decrypt later</h2><p>Current encryption technologies remain effective against conventional threats. However, quantum computing is expected to challenge some of the cryptographic methods used for <a href="https://www.techradar.com/best/best-authenticator-apps">authentication</a> and key exchange.</p><p>This has led to concerns around “harvest now, decrypt later” attacks, where encrypted data is collected today with the expectation that future quantum capabilities could potentially decrypt it later.</p><p>For organizations storing sensitive intellectual property, research data or AI training datasets, this means security decisions made today could have implications for years to come.</p><p>Preparing for that future requires action from security leaders and IT directors now.</p><h2 id="security-must-be-built-into-the-infrastructure">Security must be built into the infrastructure</h2><p>Security is often viewed through the lens of data encryption, and with good reason. Self-encrypting drives (SEDs) provide always-on, hardware-based AES-256 encryption that helps protect data at rest without impacting performance.</p><p>But protecting data alone is no longer enough.</p><p><a href="https://www.techradar.com/news/the-10-best-nas-devices-reviewed">Storage</a> devices themselves must be trusted. Firmware, authentication mechanisms, provisioning processes and diagnostic tools all play a role in ensuring a drive operates securely throughout its lifecycle.</p><p>If attackers compromise a device's firmware or trust architecture, broader security controls can be undermined regardless of how data is encrypted elsewhere in the system. This makes storage security a critical component of overall cyber resilience.</p><h2 id="implementing-quantum-resistant-defenses-in-storage">Implementing quantum-resistant defenses in storage</h2><p>To counter these emerging attack vectors, the storage industry is actively embedding post-quantum cryptography into hardware architecture of enterprise hard drives. Rather than focusing solely on protecting data, the objective is to protect the trust architecture that underpins the drive itself.</p><p>Post quantum cryptography (PQC) technologies are being incorporated into areas such as secure key establishment, firmware authentication, secure provisioning, and trusted diagnostics. These capabilities are designed in alignment with established NIST post-quantum standards and are implemented using hybrid approaches that combine classical cryptography with quantum-resistant algorithms.</p><p>In practical terms, this means that the mechanisms responsible for establishing trust, validating firmware integrity and protecting administrative functions can remain resilient against both conventional and future quantum-enabled attacks. With the operational service life of HDDs often spanning 5 years (or more), implementing PQC today helps protect against quantum-based threats that may not materialize for several years, but that we know are coming.</p><p>Importantly, HDDs have long incorporated security controls to defend against today's threats. PQC does not replace these protections; it enhances them by adding an additional layer of resilience against emerging attack vectors. </p><h2 id="trust-in-the-ai-era">Trust in the AI era</h2><p>For many years, storage innovation was primarily defined by increases in capacity. Today, the expectations placed on infrastructure are much broader.</p><p>Organizations seek storage platforms that can scale with AI-driven data growth, deliver reliable performance, preserve integrity over long retention periods and withstand an increasingly complex threat environment.</p><p>PQC represents an important step in that evolution. By extending protection beyond data encryption and into the trust mechanisms that underpin storage devices themselves, PQC-enabled HDDs help organizations prepare for the security challenges of tomorrow while protecting the data they manage today.</p><p>As AI continues to elevate the strategic value of enterprise data, security can no longer be a short-term, reactive consideration. Trust must be engineered directly into the hardware layer and built to outlast the threats of today, tomorrow and the quantum era ahead of us. </p><p><em></em><a href="https://www.techradar.com/news/best-solid-state-drives-ssds"><em>We've featured the best SSD.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI launches investigation after 153 million drivers licenses apparently leaked on Russian cybercrime forum ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>153 million US driving licences have been leaked on a Russian cybercrime platform</strong></li><li><strong>Among those apaprently discovered in the stolen data is US Secretary of Defense Pete Hegseth</strong></li><li><strong>The FBI is now investigating the leak, which has been traced to an identity verification company</strong></li></ul><p>A data leak of 153 million US drivers licenses is said to have been shared on a Russian cybercrime forum, with US Secretary of Defense Pete Hegseth among those leaked prompting an FBI investigation.</p><p>Security researcher Brian Krebs identified the leak – which included his own data – as originating from a hack of an identity verification service. Louisiana-based IDScan provided ID verification for various well-known companies, including FedEx and Hertz car hire.</p><p>The data was shared on a Russian forum called Exploit, a long-established online community of cybercriminals. Following news of the leak, the identity theft service “Nexus” has apparently scrubbed its existence from the Dark Web.</p><h2 id="driving-licenses-and-more">Driving licenses and more</h2><p>It wasn’t just US driving licenses that were found in the archive of recently-collected personal data. Krebs’ <a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/" target="_blank">investigation</a> found that Nexus claimed other types of data, and found a further 1.1 million driving licenses from Canada.</p><p>Other identity documentation alleged to be in the leak include 10 million identification cards, three million travel documents and international IDs, and 579,000 medical cards. The data was available to browse, notes Krebs, with Nexus providing details: “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”</p><p>The leak has a personal dimension for Krebs. Not only was his driving license in the collection, so was that of his mother. It has proved to be a useful coincidence, one that has enabled the security and privacy researcher to establish how the data was sourced by Nexus.</p><p>Both licenses were used for a car hire, which Krebs traced to Hertz. Others affected by the leak had also used the service, which has used New Orleans-based IDscan for identity verification.</p><p>The company, which claims to perform 21 million verifications a month, is yet to issue a statement on the matter. Its marketing and operations leader, Jillian Kossman, told the journalist: “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.” </p><h2 id="where-is-the-data">Where is the data?</h2><p>Krebs reports that he was alerted to the data on August 31, 2026, little over a week ago. Regular checking noted that the data was still being added to, increasing by “nearly 400,000” records prior to publishing his investigation on September 1.</p><p>Since then, however, it seems that Nexus has vanished, along with the data. But how widely was the data downloaded before that happened? While the FBI investigates, it falls on the American and Canadian public to be extra vigilant and wary of identity fraud.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/fbi-launches-investigation-after-153-million-drivers-licenses-apparently-leaked-on-russian-cybercrime-forum</link>
                                                                            <description>
                            <![CDATA[ Lousiana-based identity verification service IDScan identified as the target of a hack that leaked 153 million US drivers licenses. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pJfgMSYGXMyKq5zMKcF2g7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mBxmnLnpbAuepmei5vxvLf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 18:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mBxmnLnpbAuepmei5vxvLf-1280-80.jpg">
                                                            <media:credit><![CDATA[wigglestick/ Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Outline map of US states in glowing blue with exploding streams of binary data illustrating communication, internet and technology]]></media:description>                                                            <media:text><![CDATA[Outline map of US states in glowing blue with exploding streams of binary data illustrating communication, internet and technology]]></media:text>
                                <media:title type="plain"><![CDATA[Outline map of US states in glowing blue with exploding streams of binary data illustrating communication, internet and technology]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mBxmnLnpbAuepmei5vxvLf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>153 million US driving licences have been leaked on a Russian cybercrime platform</strong></li><li><strong>Among those apaprently discovered in the stolen data is US Secretary of Defense Pete Hegseth</strong></li><li><strong>The FBI is now investigating the leak, which has been traced to an identity verification company</strong></li></ul><p>A data leak of 153 million US drivers licenses is said to have been shared on a Russian cybercrime forum, with US Secretary of Defense Pete Hegseth among those leaked prompting an FBI investigation.</p><p>Security researcher Brian Krebs identified the leak – which included his own data – as originating from a hack of an identity verification service. Louisiana-based IDScan provided ID verification for various well-known companies, including FedEx and Hertz car hire.</p><p>The data was shared on a Russian forum called Exploit, a long-established online community of cybercriminals. Following news of the leak, the identity theft service “Nexus” has apparently scrubbed its existence from the Dark Web.</p><h2 id="driving-licenses-and-more">Driving licenses and more</h2><p>It wasn’t just US driving licenses that were found in the archive of recently-collected personal data. Krebs’ <a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/" target="_blank">investigation</a> found that Nexus claimed other types of data, and found a further 1.1 million driving licenses from Canada.</p><p>Other identity documentation alleged to be in the leak include 10 million identification cards, three million travel documents and international IDs, and 579,000 medical cards. The data was available to browse, notes Krebs, with Nexus providing details: “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”</p><p>The leak has a personal dimension for Krebs. Not only was his driving license in the collection, so was that of his mother. It has proved to be a useful coincidence, one that has enabled the security and privacy researcher to establish how the data was sourced by Nexus.</p><p>Both licenses were used for a car hire, which Krebs traced to Hertz. Others affected by the leak had also used the service, which has used New Orleans-based IDscan for identity verification.</p><p>The company, which claims to perform 21 million verifications a month, is yet to issue a statement on the matter. Its marketing and operations leader, Jillian Kossman, told the journalist: “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.” </p><h2 id="where-is-the-data">Where is the data?</h2><p>Krebs reports that he was alerted to the data on August 31, 2026, little over a week ago. Regular checking noted that the data was still being added to, increasing by “nearly 400,000” records prior to publishing his investigation on September 1.</p><p>Since then, however, it seems that Nexus has vanished, along with the data. But how widely was the data downloaded before that happened? While the FBI investigates, it falls on the American and Canadian public to be extra vigilant and wary of identity fraud.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fake GTA 6 malware is on the rise as release date nears — here are some of the worst scams to look out for ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress warns fake GTA 6 ISOs spreading malware ahead of official Nov 19, 2026 release</strong></li><li><strong>Packages deliver RATs, infostealers, and Chaos ransomware disguised as game installers</strong></li><li><strong>Users urged to avoid pirated downloads; infected systems should be reimaged and credentials reset</strong></li></ul><p>Grand Theft Auto 6 (GTA 6), one of the most anticipated computer games of all time, is due to launch on November 19, 2026 - so everything found online before that is almost certainly malware. </p><p>This is the warning sent out by security researchers Huntress, which <a href="https://www.huntress.com/blog/fake-gta6-download-malware-analysis" target="_blank" rel="nofollow">said</a> it recently saw one variant deploying all sorts of filth, from remote access trojans (RAT), across infostealers, to full-blown ransomware encryptors.</p><h2 id="the-story-behind-gta-6">The story behind GTA 6</h2><p>GTA 6 is a third-person action-adventure and open-world gam developed by Rockstar Games, which egan preliminary work more than a decade ago, and has allegedly spent <a href="https://finance.yahoo.com/markets/stocks/articles/viral-post-says-gta-6-184500207.html?guccounter=1" target="_blank">more than a billion dollars</a> during that decade and a half, which would make it, by far, the most expensive game ever developed.</p><p>It is also a sequel to GTA 5, a game that was sold in more than 230 million copies around the world, which made it one of the most popular games of all time.</p><p>In late August 2026, someone going by the alias LEEK <a href="https://www.pcgamer.com/games/grand-theft-auto/the-latest-gta-6-leak-confirms-the-leaker-likely-has-or-had-access-to-a-playable-build/?utm_source=chatgpt.com" target="_blank">claimed to have obtained a working, playable build of the game</a>, roughly six months before the official release. They posted numerous screenshots and videos of them playing the game, even writing their nickname onto a wall, using a rifle to prove the authenticity. Truth be told, even without this, people would have still probably searched for, and downloaded, fake installers. This only made the problem worse.</p><p>And a major problem, it definitely is. Huntress is now saying it is seeing websites ranking relatively high (through SEO poisoning), offering for download an ISO of the game. Similar ISOs are circulating around different gaming forums, torrenting sites, and social media channels. </p><p>An ISO file is a digital copy of an entire disc, such as a CD, DVD, or Blu-ray, stored as one file. Users can download an ISO (which can weigh tens or hundreds of gigabytes), mount it into a virtual drive, and the computer will treat it like a physical disc. </p><p>Huntress found some ISOs weighing more than 100GB which was done just to make it seem authentic - the actual malware was “a factor smaller”. The ISOs they analyzed contained multiple variants, including NJRAT and CDRAT (two remote access trojans), Mercurial Grabber (an infostealer grabbing Roblox Studio cookies, Minecraft session data, Discord tokens, Chrome passwords and cookies, system information, IP addresses, and geolocation, Windows product keys, and screenshots), and Chaos Ransomware. The package also contained a legitimate, regular browser - “Just for kicks,” apparently.</p><h2 id="a-plausible-failure">A plausible failure</h2><p>During the “game” installation, the installer displays a message in Russian, saying the product is unlicensed and that there is a good chance it won’t run. If that happens, the user is told to reach out to a specific Gmail address to receive an “updated crack”. After the installation completes, the victim will get that exact popup, saying “License not found”. All of this is just a smoke screen, to make the victim not suspicious as to why the “game” won’t run.</p><p>There is no way of telling how many people fell for the ruse and installed <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> on their devices. Huntress says that generally speaking, trying to download cracked and pirated software is a bad idea, which is even worse if the game in question has not yet been released. </p><p>“This is fertile ground for scams and threat actors attempting to take advantage of the impatient and overeager,” the researchers said.</p><p>The good news is that all of the malware being distributed there is not new. Some of the variants contained in the ISOs are several years old, meaning most antivirus programs, such as Windows Defender for example, can easily detect it and stop it from compromising the system. </p><p>Those that do end up infected should disconnect the machine from the internet, reset all passwords, enable 2FA wherever possible, and do a complete reimage of the compromised system.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/fake-gta-6-malware-is-on-the-rise-as-release-date-nears-here-are-some-of-the-worst-scams-to-look-out-for</link>
                                                                            <description>
                            <![CDATA[ Be careful with websites and Telegram channels offering GTA 6 content, experts warn. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">k7GigBvuqE6DZSGxEFGGDf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/knPikneiqQ4a4p7AEdGPra-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 18:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/knPikneiqQ4a4p7AEdGPra-1280-80.jpg">
                                                            <media:credit><![CDATA[Rockstar Games]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GTA 6]]></media:description>                                                            <media:text><![CDATA[GTA 6]]></media:text>
                                <media:title type="plain"><![CDATA[GTA 6]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/knPikneiqQ4a4p7AEdGPra-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress warns fake GTA 6 ISOs spreading malware ahead of official Nov 19, 2026 release</strong></li><li><strong>Packages deliver RATs, infostealers, and Chaos ransomware disguised as game installers</strong></li><li><strong>Users urged to avoid pirated downloads; infected systems should be reimaged and credentials reset</strong></li></ul><p>Grand Theft Auto 6 (GTA 6), one of the most anticipated computer games of all time, is due to launch on November 19, 2026 - so everything found online before that is almost certainly malware. </p><p>This is the warning sent out by security researchers Huntress, which <a href="https://www.huntress.com/blog/fake-gta6-download-malware-analysis" target="_blank" rel="nofollow">said</a> it recently saw one variant deploying all sorts of filth, from remote access trojans (RAT), across infostealers, to full-blown ransomware encryptors.</p><h2 id="the-story-behind-gta-6">The story behind GTA 6</h2><p>GTA 6 is a third-person action-adventure and open-world gam developed by Rockstar Games, which egan preliminary work more than a decade ago, and has allegedly spent <a href="https://finance.yahoo.com/markets/stocks/articles/viral-post-says-gta-6-184500207.html?guccounter=1" target="_blank">more than a billion dollars</a> during that decade and a half, which would make it, by far, the most expensive game ever developed.</p><p>It is also a sequel to GTA 5, a game that was sold in more than 230 million copies around the world, which made it one of the most popular games of all time.</p><p>In late August 2026, someone going by the alias LEEK <a href="https://www.pcgamer.com/games/grand-theft-auto/the-latest-gta-6-leak-confirms-the-leaker-likely-has-or-had-access-to-a-playable-build/?utm_source=chatgpt.com" target="_blank">claimed to have obtained a working, playable build of the game</a>, roughly six months before the official release. They posted numerous screenshots and videos of them playing the game, even writing their nickname onto a wall, using a rifle to prove the authenticity. Truth be told, even without this, people would have still probably searched for, and downloaded, fake installers. This only made the problem worse.</p><p>And a major problem, it definitely is. Huntress is now saying it is seeing websites ranking relatively high (through SEO poisoning), offering for download an ISO of the game. Similar ISOs are circulating around different gaming forums, torrenting sites, and social media channels. </p><p>An ISO file is a digital copy of an entire disc, such as a CD, DVD, or Blu-ray, stored as one file. Users can download an ISO (which can weigh tens or hundreds of gigabytes), mount it into a virtual drive, and the computer will treat it like a physical disc. </p><p>Huntress found some ISOs weighing more than 100GB which was done just to make it seem authentic - the actual malware was “a factor smaller”. The ISOs they analyzed contained multiple variants, including NJRAT and CDRAT (two remote access trojans), Mercurial Grabber (an infostealer grabbing Roblox Studio cookies, Minecraft session data, Discord tokens, Chrome passwords and cookies, system information, IP addresses, and geolocation, Windows product keys, and screenshots), and Chaos Ransomware. The package also contained a legitimate, regular browser - “Just for kicks,” apparently.</p><h2 id="a-plausible-failure">A plausible failure</h2><p>During the “game” installation, the installer displays a message in Russian, saying the product is unlicensed and that there is a good chance it won’t run. If that happens, the user is told to reach out to a specific Gmail address to receive an “updated crack”. After the installation completes, the victim will get that exact popup, saying “License not found”. All of this is just a smoke screen, to make the victim not suspicious as to why the “game” won’t run.</p><p>There is no way of telling how many people fell for the ruse and installed <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> on their devices. Huntress says that generally speaking, trying to download cracked and pirated software is a bad idea, which is even worse if the game in question has not yet been released. </p><p>“This is fertile ground for scams and threat actors attempting to take advantage of the impatient and overeager,” the researchers said.</p><p>The good news is that all of the malware being distributed there is not new. Some of the variants contained in the ISOs are several years old, meaning most antivirus programs, such as Windows Defender for example, can easily detect it and stop it from compromising the system. </p><p>Those that do end up infected should disconnect the machine from the internet, reset all passwords, enable 2FA wherever possible, and do a complete reimage of the compromised system.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Multiple hacking groups found using the same Chrome malware in the same week — so what does it mean? ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Proofpoint detailed BlueMoon, an exploit kit chaining two Chromium flaws and one Windows bug</strong></li><li><strong>Four groups, including China‑aligned TA412, used it loudly against NGOs, aerospace, and manufacturing targets</strong></li><li><strong>Exploits were “patch‑gap” zero‑days; all flaws now patched</strong></li></ul><p>Four hacking groups, including some tied to the Chinese government, were seen using the exact same exploit kit in a span of a week, suggesting a certain “fear of missing out” among the criminals, experts have warned.</p><p>Security researchers Proofpoint have detailed BlueMoon, an <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">exploit kit</a> that leverages three vulnerabilities: two in Chromium, and one in older versions of Windows: Windows 10 (October 2018 Update), Windows Server 2019, Windows 10 2004, WIndows Server 2022, and the initial release of Windows 11. </p><p>The kit was first seen being used on August 28 2026, by a threat actor tracked as TA412, a China-aligned state-sponsored threat actor that was observed in the past targeting businesses using Microsoft SharePoint. TA412, also known as Violet Typhoon, used BlueMoon to “repeatedly target a small number of non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the United States.”</p><p>Soon after that, three others were spotted: UNK_LateNight, another China-aligned espionage group which targeted multiple US aerospace companies, UNK_DoubleCheck, a group going after a Vietnamese manufacturing entity, and UNK_QuietRacket, a threat actor taking aim at organizations across Singapore and Indonesia.</p><p>What all of these groups have in common is the fact that they did not try particularly hard to hide their activity. This is rather unusual, since a stealthy approach usually guarantees that a vulnerability can be exploited for longer.</p><h2 id="front-running-the-chromium-supply-chain-train">Front running the Chromium supply chain train</h2><p>BlueMoon takes advantage of three flaws, two in Chromium and one in older Windows variants. The Chromium vulnerabilities were found in V8, the JavaScript engine that the browsers use to allow applications to run efficiently. The first one is a “type confusion bug”, tracked as CVE-2026-85046, and assigned a severity score of 8.8/10 (high). The latter is a “sandbox escape” flaw, for which Google did not assign a CVE or a severity score. </p><p>The Windows bug, on the other hand, is tracked as CVE-2026-85880, and was given a severity score of 7.8/10 (high). It is described as a “heap-based buffer overflow” vulnerability in Windows Advanced Local Procedure Call, allowing malicious actors who can already execute code inside a low-privilege AppContainer to escape the sandbox and elevate privileges to SYSTEM. No additional user interaction is required.</p><p>Proofpoint has a theory as to why the crooks decided to be loud, instead of flying under the radar. Apparently, there is a very short window of opportunity between Google patching a Chromium vulnerability, and it being deployed to a <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> such as Edge, or Brave, This window of opportunity also allows crooks to see how Google fixed a flaw, reverse-engineer it, and deploy an exploit before the browser is patched. This would mean that there is no time to be stealthy. </p><h2 id="no-time-to-hide">No time to hide</h2><p>“Both V8 vulnerabilities were ‘patch-gap’ zero-days at the time of the observed activity,” Proofpoint said. “In other words, while they were known vulnerabilities already fixed in public upstream Chromium source code, they remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public. It is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain.”</p><p>Another important factor is Artificial Intelligence. It would seem that AI has made flaw detection significantly faster, reducing the barrier to entry and making threat actors move more loudly.</p><p>“A fully weaponized Chrome exploit chain has historically been a high-value, rare capability. BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development,” Proofpoint stressed. </p><p>All three flaws have since been patched, so make sure you’re running the latest version of both the OS and the Chromium browser. </p><p><em>Via </em><a href="https://arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/" target="_blank"><em>Ars Technica</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/multiple-hacking-groups-found-using-the-same-chrome-malware-in-the-same-week-so-what-does-it-mean</link>
                                                                            <description>
                            <![CDATA[ Someone is afraid of missing out, as defenders rush to patch things up. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VpmftvDTzJKLp2prufcPaU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg">
                                                            <media:credit><![CDATA[Tada Images / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:description>                                                            <media:text><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:text>
                                <media:title type="plain"><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Proofpoint detailed BlueMoon, an exploit kit chaining two Chromium flaws and one Windows bug</strong></li><li><strong>Four groups, including China‑aligned TA412, used it loudly against NGOs, aerospace, and manufacturing targets</strong></li><li><strong>Exploits were “patch‑gap” zero‑days; all flaws now patched</strong></li></ul><p>Four hacking groups, including some tied to the Chinese government, were seen using the exact same exploit kit in a span of a week, suggesting a certain “fear of missing out” among the criminals, experts have warned.</p><p>Security researchers Proofpoint have detailed BlueMoon, an <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">exploit kit</a> that leverages three vulnerabilities: two in Chromium, and one in older versions of Windows: Windows 10 (October 2018 Update), Windows Server 2019, Windows 10 2004, WIndows Server 2022, and the initial release of Windows 11. </p><p>The kit was first seen being used on August 28 2026, by a threat actor tracked as TA412, a China-aligned state-sponsored threat actor that was observed in the past targeting businesses using Microsoft SharePoint. TA412, also known as Violet Typhoon, used BlueMoon to “repeatedly target a small number of non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the United States.”</p><p>Soon after that, three others were spotted: UNK_LateNight, another China-aligned espionage group which targeted multiple US aerospace companies, UNK_DoubleCheck, a group going after a Vietnamese manufacturing entity, and UNK_QuietRacket, a threat actor taking aim at organizations across Singapore and Indonesia.</p><p>What all of these groups have in common is the fact that they did not try particularly hard to hide their activity. This is rather unusual, since a stealthy approach usually guarantees that a vulnerability can be exploited for longer.</p><h2 id="front-running-the-chromium-supply-chain-train">Front running the Chromium supply chain train</h2><p>BlueMoon takes advantage of three flaws, two in Chromium and one in older Windows variants. The Chromium vulnerabilities were found in V8, the JavaScript engine that the browsers use to allow applications to run efficiently. The first one is a “type confusion bug”, tracked as CVE-2026-85046, and assigned a severity score of 8.8/10 (high). The latter is a “sandbox escape” flaw, for which Google did not assign a CVE or a severity score. </p><p>The Windows bug, on the other hand, is tracked as CVE-2026-85880, and was given a severity score of 7.8/10 (high). It is described as a “heap-based buffer overflow” vulnerability in Windows Advanced Local Procedure Call, allowing malicious actors who can already execute code inside a low-privilege AppContainer to escape the sandbox and elevate privileges to SYSTEM. No additional user interaction is required.</p><p>Proofpoint has a theory as to why the crooks decided to be loud, instead of flying under the radar. Apparently, there is a very short window of opportunity between Google patching a Chromium vulnerability, and it being deployed to a <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> such as Edge, or Brave, This window of opportunity also allows crooks to see how Google fixed a flaw, reverse-engineer it, and deploy an exploit before the browser is patched. This would mean that there is no time to be stealthy. </p><h2 id="no-time-to-hide">No time to hide</h2><p>“Both V8 vulnerabilities were ‘patch-gap’ zero-days at the time of the observed activity,” Proofpoint said. “In other words, while they were known vulnerabilities already fixed in public upstream Chromium source code, they remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public. It is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain.”</p><p>Another important factor is Artificial Intelligence. It would seem that AI has made flaw detection significantly faster, reducing the barrier to entry and making threat actors move more loudly.</p><p>“A fully weaponized Chrome exploit chain has historically been a high-value, rare capability. BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development,” Proofpoint stressed. </p><p>All three flaws have since been patched, so make sure you’re running the latest version of both the OS and the Chromium browser. </p><p><em>Via </em><a href="https://arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/" target="_blank"><em>Ars Technica</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Beware — these new phishing attacks use a convincing fake Adobe Reader pages to trick victims into installing malware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress warns of phishing campaign abusing Adobe branding with browser‑in‑the‑browser trick  </strong></li><li><strong>Victims lured into fake update pages, unknowingly installing rogue ScreenConnect clients  </strong></li><li><strong>Attackers gain persistent remote access; defenders urged to restrict RMM installs and monitor IoCs</strong></li></ul><p>Security researchers Huntress have warned of an ongoing phishing campaign that abuses Adobe’s brand while deploying clever browser-in-the-browser (BitB) techniques to trick the victims. </p><p>The goal is to deliver rogue ScreenConnect clients which would grant the attackers persistent access to target devices.</p><p>In its <a href="https://www.huntress.com/blog/phishing-bitb-rmm-attacks" target="_blank" rel="nofollow">report</a>, Huntress says it could not find the lure itself and thus could not report what the scam looks like. However, it saw the victims clicking on a link in the email and then being redirected to a typosquatted domain https[://]adoube[.]vu that spoofs an Adobe landing page.</p><h2 id="we-heard-you-like-browsers">We heard you like browsers…</h2><p>This is where we get to the scam’s unique twist. Usually, phishing lures would simply redirect victims to a malicious website which could be identified simply by looking at the address bar. If the domain differs from the legitimate one, the scam falls apart. To work around that problem, scammers came with a solution called “browser in the browser”. </p><p>Using either HTML, CSS, or JavaScript, the crooks would create an entire fake browser window, including the address bar, URL, padlock icon, and more, inside the actual webpage content itself. Therefore, if the victim isn’t all too careful, they might look at the fake address bar, see a legitimate URL, and believe they are visiting the correct website.</p><p>In this fake <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> window, the fraudsters display a blurred .PDF document. Overlaid is a message saying the documents are “secured” and created with “the latest version of Adobe.” The only way to read them, the message continues, is to “update or download Adobe PDF Reader.” Expectedly, there is a big “View Files” button just under the notification, leading to a different, equally fake BitB page, showing the download progress. In the background, something gets downloaded.</p><p>Victims might think they’re getting a PDF reader, while in reality they’re getting a rogue version of ScreenConnect.</p><h2 id="poisoned-screenconnect-instances">Poisoned ScreenConnect instances</h2><p>On its own, ScreenConnect is not malware, or dangerous in any other way. It is a legitimate <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote access and support software</a>, similar to TeamViewer, AnyDesk, or Remote Desktop, allowing IT professionals remotely connect to and control computers and other devices. These variants, however, are tainted to enable threat actors to obtain persistent remote access to their targets’ endpoints, Huntress explained.</p><p>“The first initial remote client installed was the rogue ScreenConnect Client configured to communicate with instance-uxh86b-relay[.]screenconnect[.]com. The attacker used a legitimate ScreenConnect Trial Relay domain to further avoid detection,” the researchers said. “This initial malicious ScreenConnect Client used the native Windows command shell and curl to retrieve and install a second malicious ScreenConnect Client configured to communicate with attacker-controlled IP. Both clients established service-based persistence for continued remote access.”</p><p>After installation, the attackers used the second ScreenConnect session to run HideCursor.exe, an executable, as the name suggests, that helps the attackers hide their mouse activity. </p><p>Huntress’ researchers don’t know what the endgame is, since the threat actors were spotted and shut down in this stage of the attack. The researchers also did not share the details about the target, such as the size of the organization, or the industry it operates in. Therefore, it is impossible to even speculate on the nature of the attack and if the threat actors aimed to install ransomware.</p><p>Still, the researchers stressed the importance of training employees to “treat unexpected software update prompts and file-viewing pages with caution”, and to make sure they know how to verify downloads through trusted channels. IT teams should also restrict who can install remote-management tools, maintain an approved inventory of RMM software, and alert on new or unapproved ScreenConnect clients, unusual relay connections, and executables launched from the user Downloads folders.</p><p>Finally, businesses should monitor for Indicators of Compromise (IoC) listed on <a href="https://www.huntress.com/blog/phishing-bitb-rmm-attacks" target="_blank">this page</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/watch-out-these-new-phishing-attacks-use-a-convincing-fake-adobe-reader-pages-to-trick-victims-into-installing-malware</link>
                                                                            <description>
                            <![CDATA[ Crooks are deploying cheeky browser-in-the-browser techniques to trick victims into downloading RMM tools. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Xd5CXXfGjfqbJQetYYE4fZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ncL98vteKnP9dydmNAHGqN-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/ncL98vteKnP9dydmNAHGqN-1280-80.png">
                                                            <media:credit><![CDATA[Varonis]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[PDF]]></media:description>                                                            <media:text><![CDATA[PDF]]></media:text>
                                <media:title type="plain"><![CDATA[PDF]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ncL98vteKnP9dydmNAHGqN-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress warns of phishing campaign abusing Adobe branding with browser‑in‑the‑browser trick  </strong></li><li><strong>Victims lured into fake update pages, unknowingly installing rogue ScreenConnect clients  </strong></li><li><strong>Attackers gain persistent remote access; defenders urged to restrict RMM installs and monitor IoCs</strong></li></ul><p>Security researchers Huntress have warned of an ongoing phishing campaign that abuses Adobe’s brand while deploying clever browser-in-the-browser (BitB) techniques to trick the victims. </p><p>The goal is to deliver rogue ScreenConnect clients which would grant the attackers persistent access to target devices.</p><p>In its <a href="https://www.huntress.com/blog/phishing-bitb-rmm-attacks" target="_blank" rel="nofollow">report</a>, Huntress says it could not find the lure itself and thus could not report what the scam looks like. However, it saw the victims clicking on a link in the email and then being redirected to a typosquatted domain https[://]adoube[.]vu that spoofs an Adobe landing page.</p><h2 id="we-heard-you-like-browsers">We heard you like browsers…</h2><p>This is where we get to the scam’s unique twist. Usually, phishing lures would simply redirect victims to a malicious website which could be identified simply by looking at the address bar. If the domain differs from the legitimate one, the scam falls apart. To work around that problem, scammers came with a solution called “browser in the browser”. </p><p>Using either HTML, CSS, or JavaScript, the crooks would create an entire fake browser window, including the address bar, URL, padlock icon, and more, inside the actual webpage content itself. Therefore, if the victim isn’t all too careful, they might look at the fake address bar, see a legitimate URL, and believe they are visiting the correct website.</p><p>In this fake <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> window, the fraudsters display a blurred .PDF document. Overlaid is a message saying the documents are “secured” and created with “the latest version of Adobe.” The only way to read them, the message continues, is to “update or download Adobe PDF Reader.” Expectedly, there is a big “View Files” button just under the notification, leading to a different, equally fake BitB page, showing the download progress. In the background, something gets downloaded.</p><p>Victims might think they’re getting a PDF reader, while in reality they’re getting a rogue version of ScreenConnect.</p><h2 id="poisoned-screenconnect-instances">Poisoned ScreenConnect instances</h2><p>On its own, ScreenConnect is not malware, or dangerous in any other way. It is a legitimate <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote access and support software</a>, similar to TeamViewer, AnyDesk, or Remote Desktop, allowing IT professionals remotely connect to and control computers and other devices. These variants, however, are tainted to enable threat actors to obtain persistent remote access to their targets’ endpoints, Huntress explained.</p><p>“The first initial remote client installed was the rogue ScreenConnect Client configured to communicate with instance-uxh86b-relay[.]screenconnect[.]com. The attacker used a legitimate ScreenConnect Trial Relay domain to further avoid detection,” the researchers said. “This initial malicious ScreenConnect Client used the native Windows command shell and curl to retrieve and install a second malicious ScreenConnect Client configured to communicate with attacker-controlled IP. Both clients established service-based persistence for continued remote access.”</p><p>After installation, the attackers used the second ScreenConnect session to run HideCursor.exe, an executable, as the name suggests, that helps the attackers hide their mouse activity. </p><p>Huntress’ researchers don’t know what the endgame is, since the threat actors were spotted and shut down in this stage of the attack. The researchers also did not share the details about the target, such as the size of the organization, or the industry it operates in. Therefore, it is impossible to even speculate on the nature of the attack and if the threat actors aimed to install ransomware.</p><p>Still, the researchers stressed the importance of training employees to “treat unexpected software update prompts and file-viewing pages with caution”, and to make sure they know how to verify downloads through trusted channels. IT teams should also restrict who can install remote-management tools, maintain an approved inventory of RMM software, and alert on new or unapproved ScreenConnect clients, unusual relay connections, and executables launched from the user Downloads folders.</p><p>Finally, businesses should monitor for Indicators of Compromise (IoC) listed on <a href="https://www.huntress.com/blog/phishing-bitb-rmm-attacks" target="_blank">this page</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Watch out, Google Play’s Early Access could become a breeding ground for malicious apps — with no public reviews or ratings, what could go wrong? ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Bitdefender finds Google Play Early Access platform could give malicious apps an easy breeding ground</strong></li><li><strong>User reviews and ratings are not publicly displayed, removing the ability for users to evaluate if an app is legitimate</strong></li><li><strong>Games, casinos, and utility apps are being loaded with malicious packages and downloaded thousands of times</strong></li></ul><p>Google has unveiled an Early Access program for the Play Store, allowing developers to list early-access apps for testing and feedback.</p><p>While great for smaller apps looking to weed out any wrinkles in their apps, Early Access also offers a lucrative way for malicious actors to lure users into downloading apps that look legitimate, but can hide malicious packages inside.</p><p>However, new research from <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/google-play-early-access-exploit-deceptive-apps" target="_blank" rel="nofollow">Bitdefender</a> notes the fact that the Early Access program hides public reviews and ratings could lead to an app ecosystem filled with scams, fake casinos, and malware-laden packages masquerading as legitimate software.</p><h2 id="early-access-is-filled-with-dangerous-apps">Early Access is filled with dangerous apps</h2><p>When looking for apps on the normal Play Store, one of the first things users are greeted with is an app’s rating. For fake or malicious apps, users can quickly evaluate whether or not to download the app thanks to the star rating and user reviews. While there is the potential for nefarious developers to fake reviews and ratings there is at least some ability to check if an app is legitimate.</p><p>But the Early Access system does away with public user ratings and reviews entirely. There is effectively no way for users who fall victim to a fake app to publicly warn other users not to download the app.</p><p>Add to this equation that ability for developers to show off their apps through sponsored Facebook and TikTok videos, offering outrageous rewards or using deepfakes of celebrities to entice users to install their apps.</p><p>This is especially true for fake gambling apps. Bitdefender has spotted numerous adverts for casino apps using deepfakes of well known celebrities such as Cristiano Ronaldo, Jason Statham, and Andrew Tate. These apps actively push users into the Google Play Early Access store, or direct to the apps website.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="S3stBmbub2CNx4AbcnCv8L" name="Bitdefender Scam ads" alt="A selection of promoted adds on TikTok showing deepfakes of celebrities advertising fake apps on the Google Play Early Access platform." src="https://cdn.mos.cms.futurecdn.net/S3stBmbub2CNx4AbcnCv8L.png" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Bitdefender)</span></figcaption></figure><p>Other listings mimic well-known apps, adding financial incentives for downloading such as doubling the money you invest every time you complete a task or overcome an obstacle. Other apps take advantage of the hype for upcoming game releases, such as Grand Theft Auto V and VI. These apps often use screenshots from the actual games in order to appear legitimate.</p><p>When detected as illegitimate, these scam apps will often be deleted before being replaced by exact copies that perform the same malicious functions. Some illegitimate apps have been downloaded thousands of times, Bitdefender said, but many remain available on the Google Play Early Access store.</p><p>But the scam apps aren’t limited to games and casino apps. Bitdefender also saw numerous apps offering utility functions such as QR code scanners or PDF readers. In some circumstances, the exact same apps were listed multiple times by different developers - likely to expand the reach and maximize the number of downloads.</p><p>Bitdefender notes that Google Play’s reputation relies on users being able to trust the apps they are downloading, but the Early Access program removes almost every way users can detect a malicious app before installing.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/watch-out-google-plays-early-access-could-become-a-breeding-ground-for-malicious-apps-with-no-public-reviews-or-ratings-what-could-go-wrong</link>
                                                                            <description>
                            <![CDATA[ Google Play is a go-to for downloading trustworthy apps, but this could change everything ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ihSXj3VXTaKYGgtF9uzFxZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/f7VHBf7mNuETyedzPFND5Y-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/f7VHBf7mNuETyedzPFND5Y-1280-80.jpg">
                                                            <media:credit><![CDATA[Photo Illustration by Idrees Abbas/SOPA Images/LightRocket via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[In this photo illustration, the Google play store logo is seen displayed on a mobile phone screen.]]></media:description>                                                            <media:text><![CDATA[In this photo illustration, the Google play store logo is seen displayed on a mobile phone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[In this photo illustration, the Google play store logo is seen displayed on a mobile phone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/f7VHBf7mNuETyedzPFND5Y-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Bitdefender finds Google Play Early Access platform could give malicious apps an easy breeding ground</strong></li><li><strong>User reviews and ratings are not publicly displayed, removing the ability for users to evaluate if an app is legitimate</strong></li><li><strong>Games, casinos, and utility apps are being loaded with malicious packages and downloaded thousands of times</strong></li></ul><p>Google has unveiled an Early Access program for the Play Store, allowing developers to list early-access apps for testing and feedback.</p><p>While great for smaller apps looking to weed out any wrinkles in their apps, Early Access also offers a lucrative way for malicious actors to lure users into downloading apps that look legitimate, but can hide malicious packages inside.</p><p>However, new research from <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/google-play-early-access-exploit-deceptive-apps" target="_blank" rel="nofollow">Bitdefender</a> notes the fact that the Early Access program hides public reviews and ratings could lead to an app ecosystem filled with scams, fake casinos, and malware-laden packages masquerading as legitimate software.</p><h2 id="early-access-is-filled-with-dangerous-apps">Early Access is filled with dangerous apps</h2><p>When looking for apps on the normal Play Store, one of the first things users are greeted with is an app’s rating. For fake or malicious apps, users can quickly evaluate whether or not to download the app thanks to the star rating and user reviews. While there is the potential for nefarious developers to fake reviews and ratings there is at least some ability to check if an app is legitimate.</p><p>But the Early Access system does away with public user ratings and reviews entirely. There is effectively no way for users who fall victim to a fake app to publicly warn other users not to download the app.</p><p>Add to this equation that ability for developers to show off their apps through sponsored Facebook and TikTok videos, offering outrageous rewards or using deepfakes of celebrities to entice users to install their apps.</p><p>This is especially true for fake gambling apps. Bitdefender has spotted numerous adverts for casino apps using deepfakes of well known celebrities such as Cristiano Ronaldo, Jason Statham, and Andrew Tate. These apps actively push users into the Google Play Early Access store, or direct to the apps website.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="S3stBmbub2CNx4AbcnCv8L" name="Bitdefender Scam ads" alt="A selection of promoted adds on TikTok showing deepfakes of celebrities advertising fake apps on the Google Play Early Access platform." src="https://cdn.mos.cms.futurecdn.net/S3stBmbub2CNx4AbcnCv8L.png" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Bitdefender)</span></figcaption></figure><p>Other listings mimic well-known apps, adding financial incentives for downloading such as doubling the money you invest every time you complete a task or overcome an obstacle. Other apps take advantage of the hype for upcoming game releases, such as Grand Theft Auto V and VI. These apps often use screenshots from the actual games in order to appear legitimate.</p><p>When detected as illegitimate, these scam apps will often be deleted before being replaced by exact copies that perform the same malicious functions. Some illegitimate apps have been downloaded thousands of times, Bitdefender said, but many remain available on the Google Play Early Access store.</p><p>But the scam apps aren’t limited to games and casino apps. Bitdefender also saw numerous apps offering utility functions such as QR code scanners or PDF readers. In some circumstances, the exact same apps were listed multiple times by different developers - likely to expand the reach and maximize the number of downloads.</p><p>Bitdefender notes that Google Play’s reputation relies on users being able to trust the apps they are downloading, but the Early Access program removes almost every way users can detect a malicious app before installing.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Americans might say they have ‘nothing to hide’, but many wouldn’t hand over access to their phone — even for $1 million ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>New Incogni research has found that the privacy preferences of Americans don't really align with what they say</strong></li><li><strong>Many of those with 'nothing to hide' will happily snoop on the phones of their family members and partners</strong></li><li><strong>But those same people tend to get twitchy when handing over their phone to strangers, or their data to the government</strong></li></ul><p>A new survey by <a href="https://blog.incogni.com/nothing-to-hide/" target="_blank" rel="nofollow">Incogni</a> has found almost half of Americans say they have ‘nothing to hide’ when it comes to their privacy, but almost immediately change their perspective when it comes to strangers looking at their phone - or sharing their private messages with the federal government.</p><p>Even when offered substantial sums of money, many of those with nothing to hide still wouldn’t hand over their devices, and their personal habits such as covering cameras or installing privacy screens show a level of contradiction in what they say, and how they behave.</p><p>Of those surveyed as part of Incogni’s research, Gen Z were the most likely to say they had nothing to hide at 57%, whereas just 26% of Baby Boomers offered the same response.</p><h2 id="americans-don-39-t-want-strangers-or-the-government-accessing-their-phones">Americans don't want strangers or the government accessing their phones</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:67.58%;"><img id="DxvVsdKESUyvXYqtH4mLr6" name="almost_half_of_respondents_say_they_have_nothing_to_hide" alt="Incogni graphs showing the privacy habits of Americans" src="https://cdn.mos.cms.futurecdn.net/DxvVsdKESUyvXYqtH4mLr6.jpg" mos="" align="middle" fullscreen="" width="1024" height="692" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>As it turns out, those who fell into the 45% of respondents who said they had nothing to hide were more likely to snoop on other people's devices. In fact, when polled on whether they looked at other people’s devices in public, people with nothing to hide were double as likely (42%) to snoop compared to their something to hide counterparts (27%).</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:54.49%;"><img id="UNYyBhcux8EgJxyASotBq6" name="snooping_on_personal_communications_in_public_is_common_and_uncomfortable" alt="Incogni graphs showing the privacy habits of Americans" src="https://cdn.mos.cms.futurecdn.net/UNYyBhcux8EgJxyASotBq6.jpg" mos="" align="middle" fullscreen="" width="1024" height="558" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>Those with nothing to hide were also more likely to look through the phones of their partners and family members without permission. In fact, 41% who fell into this category admitted to snooping on their partners phones, and 35% had looked through their family members' phones.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:53.71%;"><img id="dQCyx9mtsgBkGNHoK2pFp6" name="privacy_between_partners_and_family_members" alt="Incogni graphs showing the privacy habits of Americans" src="https://cdn.mos.cms.futurecdn.net/dQCyx9mtsgBkGNHoK2pFp6.jpg" mos="" align="middle" fullscreen="" width="1024" height="550" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>Despite claiming to have nothing to hide, 39% still covered their cameras with tape, stickers, or sliding covers - especially those of Gen Z.  Over a quarter of respondents also said that they deliberately obscure their personal information when signing up to online services with fake names, false dates of birth, and masked emails.</p><p>But the most interesting data comes from paying for privacy. 41% of those who said they have nothing to hide would pay more for a product if it was better for their privacy. But when offered money in return for handing over their phone to a stranger, 60% of respondents refused any amount of money. 20% said it would take an amount of $1 million or more, and just 6% offered access for $100 or less.</p><p>When breaking these numbers down by group, 58% of those with nothing to hide would not let a stranger access their unlocked phone for any amount of money. </p><p>Even when offered three months of their salary, just 26% of respondents would hand over their SMS, chat-app, and email messages with law enforcement. This number drops to 25% with Big Tech companies, 24% for local government, and a staggering 21% for the federal government.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:67.58%;"><img id="oQxABjdgPDKUFbUnpb5zn6" name="the_federal_government_is_the_least_likely_entity_to_be_able_to_buy_access_to_respondents_messages" alt="Incogni graphs showing the privacy habits of Americans" src="https://cdn.mos.cms.futurecdn.net/oQxABjdgPDKUFbUnpb5zn6.jpg" mos="" align="middle" fullscreen="" width="1024" height="692" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>Incogni theorizes that those who said they have nothing to hide may be equating privacy with secretiveness and secretiveness with guilt. It may also be true that many people fail to see how their seemingly innocent data, such as an email address or phone number, should be kept private.</p><p>As numerous data breaches have shown, the leaking of such information can lead to phishing emails, scams, and general harassment or doxxing. Incogni says that people fail to see why this information should stay private, especially in an era when social media and the websites we use hoover up as much information as possible to be sold to advertisers and third-parties.</p><p>“The findings suggest that the “nothing to hide” argument may therefore say less about how much people actually value privacy than about how difficult it is to see the consequences of losing it,” the report concludes.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/americans-might-say-they-have-nothing-to-hide-but-many-wouldnt-hand-over-access-to-their-phone-even-for-usd1-million</link>
                                                                            <description>
                            <![CDATA[ Incogni report finds those with 'nothing to hide' are more likely to snoop on the phones of their friends and family ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8R28SRiarorCFJ98nW5bfK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fdDmNCiwDdWg97kGfisHbA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 12:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fdDmNCiwDdWg97kGfisHbA-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Large blue eyeball watching businesswoman working at computer]]></media:description>                                                            <media:text><![CDATA[Large blue eyeball watching businesswoman working at computer]]></media:text>
                                <media:title type="plain"><![CDATA[Large blue eyeball watching businesswoman working at computer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fdDmNCiwDdWg97kGfisHbA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>New Incogni research has found that the privacy preferences of Americans don't really align with what they say</strong></li><li><strong>Many of those with 'nothing to hide' will happily snoop on the phones of their family members and partners</strong></li><li><strong>But those same people tend to get twitchy when handing over their phone to strangers, or their data to the government</strong></li></ul><p>A new survey by <a href="https://blog.incogni.com/nothing-to-hide/" target="_blank" rel="nofollow">Incogni</a> has found almost half of Americans say they have ‘nothing to hide’ when it comes to their privacy, but almost immediately change their perspective when it comes to strangers looking at their phone - or sharing their private messages with the federal government.</p><p>Even when offered substantial sums of money, many of those with nothing to hide still wouldn’t hand over their devices, and their personal habits such as covering cameras or installing privacy screens show a level of contradiction in what they say, and how they behave.</p><p>Of those surveyed as part of Incogni’s research, Gen Z were the most likely to say they had nothing to hide at 57%, whereas just 26% of Baby Boomers offered the same response.</p><h2 id="americans-don-39-t-want-strangers-or-the-government-accessing-their-phones">Americans don't want strangers or the government accessing their phones</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:67.58%;"><img id="DxvVsdKESUyvXYqtH4mLr6" name="almost_half_of_respondents_say_they_have_nothing_to_hide" alt="Incogni graphs showing the privacy habits of Americans" src="https://cdn.mos.cms.futurecdn.net/DxvVsdKESUyvXYqtH4mLr6.jpg" mos="" align="middle" fullscreen="" width="1024" height="692" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>As it turns out, those who fell into the 45% of respondents who said they had nothing to hide were more likely to snoop on other people's devices. In fact, when polled on whether they looked at other people’s devices in public, people with nothing to hide were double as likely (42%) to snoop compared to their something to hide counterparts (27%).</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:54.49%;"><img id="UNYyBhcux8EgJxyASotBq6" name="snooping_on_personal_communications_in_public_is_common_and_uncomfortable" alt="Incogni graphs showing the privacy habits of Americans" src="https://cdn.mos.cms.futurecdn.net/UNYyBhcux8EgJxyASotBq6.jpg" mos="" align="middle" fullscreen="" width="1024" height="558" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>Those with nothing to hide were also more likely to look through the phones of their partners and family members without permission. In fact, 41% who fell into this category admitted to snooping on their partners phones, and 35% had looked through their family members' phones.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:53.71%;"><img id="dQCyx9mtsgBkGNHoK2pFp6" name="privacy_between_partners_and_family_members" alt="Incogni graphs showing the privacy habits of Americans" src="https://cdn.mos.cms.futurecdn.net/dQCyx9mtsgBkGNHoK2pFp6.jpg" mos="" align="middle" fullscreen="" width="1024" height="550" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>Despite claiming to have nothing to hide, 39% still covered their cameras with tape, stickers, or sliding covers - especially those of Gen Z.  Over a quarter of respondents also said that they deliberately obscure their personal information when signing up to online services with fake names, false dates of birth, and masked emails.</p><p>But the most interesting data comes from paying for privacy. 41% of those who said they have nothing to hide would pay more for a product if it was better for their privacy. But when offered money in return for handing over their phone to a stranger, 60% of respondents refused any amount of money. 20% said it would take an amount of $1 million or more, and just 6% offered access for $100 or less.</p><p>When breaking these numbers down by group, 58% of those with nothing to hide would not let a stranger access their unlocked phone for any amount of money. </p><p>Even when offered three months of their salary, just 26% of respondents would hand over their SMS, chat-app, and email messages with law enforcement. This number drops to 25% with Big Tech companies, 24% for local government, and a staggering 21% for the federal government.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:67.58%;"><img id="oQxABjdgPDKUFbUnpb5zn6" name="the_federal_government_is_the_least_likely_entity_to_be_able_to_buy_access_to_respondents_messages" alt="Incogni graphs showing the privacy habits of Americans" src="https://cdn.mos.cms.futurecdn.net/oQxABjdgPDKUFbUnpb5zn6.jpg" mos="" align="middle" fullscreen="" width="1024" height="692" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>Incogni theorizes that those who said they have nothing to hide may be equating privacy with secretiveness and secretiveness with guilt. It may also be true that many people fail to see how their seemingly innocent data, such as an email address or phone number, should be kept private.</p><p>As numerous data breaches have shown, the leaking of such information can lead to phishing emails, scams, and general harassment or doxxing. Incogni says that people fail to see why this information should stay private, especially in an era when social media and the websites we use hoover up as much information as possible to be sold to advertisers and third-parties.</p><p>“The findings suggest that the “nothing to hide” argument may therefore say less about how much people actually value privacy than about how difficult it is to see the consequences of losing it,” the report concludes.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI’s overlooked storage opportunity ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The AI <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> discussion is typically framed around the cost of data centers, the power requirements, and the compute needed to train and run models, including <a href="https://www.techradar.com/news/computing-components/graphics-cards/best-graphics-cards-1291458">GPUs</a> and high-performance storage. That’s hardly surprising given the eye-watering investment numbers occupying the headlines.</p><p>The other key commodity, of course, is data to fuel those models. According to Stanford University’s 2025 AI Index Report, dataset sizes for training LLMs are doubling every eight months. In practical terms, as each model is built, some data will move quickly into curation and model-development environments, where fast access is essential.</p><p>Much of it, however, will wait longer while teams establish its relevance to a particular AI use case – not sitting idle, but held securely and ready to move quickly into curation, training and transformation pipelines when needed.  </p><p>From a <a href="https://www.techradar.com/best/best-cloud-document-storage">storage</a> perspective, this raises a point that is easy to overlook: a dataset does not need the same performance at every stage of the AI pipeline. What matters is that it is ready when it is needed – not that it sits on always-on, high-performance infrastructure throughout, which at scale becomes unnecessarily expensive.</p><p>The question for infrastructure planners, then, is not whether AI needs fast storage, but where organizations should keep the very large datasets that will be required in future, before they are ready to be processed. That choice is a strategic one, not a housekeeping one.</p><p>The right capacity tier should keep data protected and readily recoverable into AI, training and transformation pipelines, puts performance only where the work is actually happening, and returns the difference to the budget.  </p><h2 id="your-data-portfolio-as-strategic-advantage">Your data portfolio as strategic advantage </h2><p>As every organization's mission is different, so too each will be at a different stage of the AI journey. Some have raced ahead with systems already in production, while many others continue to explore how the data they already hold could support AI initiatives – <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a>, images and video, operational records, information collected through connected systems; the list goes on.</p><p>This is why knowing your own data is fast becoming a competitive lever rather than an IT chore. Models are available to everyone, so proprietary <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> is your competitive advantage – if you can access it and use it at scale.</p><p>The organizations that will move fastest are the ones that already know what they hold, where it sits, and how quickly it can be put to work. Shortening the distance between a business question and the data that answers it is now a measure of how fast a company can execute and succeed.</p><p>So data is not simply an input to AI: it is what shapes the model. The more of an organization's own data it can bring to bear, the sharper and more specific the resulting tools become, which is why the working assumption should be that almost anything the business holds is potentially useful.</p><p>The conventional approach has been to hold large datasets in a disk-based data lake until they are needed for further processing. Yet as data sets grow ever larger, so too could cost. If every candidate dataset has to live on always-on, high-performance infrastructure, cost sets the ceiling on how much data an organization can afford to keep in play at all.</p><p>The challenge, then, is to keep everything available to workflows as needed, so that the deciding factor is the use case, not the storage bill. </p><h2 id="tale-of-the-tape">Tale of the tape </h2><p>The smart play therefore is not to spend more, but to stop overspending where there is a better way. And it turns out one of the strongest answers here is a technology that has never stopped innovating: tape. Most people still associate it with <a href="https://www.techradar.com/best/best-backup-software">backup</a> and long-term archive – a role it continues to play well – but successive LTO generations have transformed its capacity, throughput and <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> while the industry looked elsewhere.</p><p>The latest tape technology and systems now behave like any other tier in the stack, ready to stream data into fast storage when curation or training is ready for it. And tape’s economics get better as it grows. At the multi-petabyte scale AI programs now reach, cost per terabyte is a fraction of flash or even HDD infrastructure. Performance and capacity can also scale independently, adding more drives for throughput and more cartridges for capacity.</p><p>When considered with tape’s extraordinary energy efficiency, this storage technology emerges as a strategic capability to build into the data center, allowing an organization to keep its entire data estate in play, at a cost that scales predictably.  </p><h2 id="a-safer-place-for-valuable-data">A safer place for valuable data </h2><p>Cost of storage and operation often gets projects approved, yet protection is the one that keeps people up at night. Here, tape offers something the online tiers structurally cannot. Encryption is handled in hardware on the cartridge. Write-Once-Read-Many (WORM) media makes a dataset immutable in the physical sense, so that irreplaceable data cannot be rewritten.</p><p>And for the most valuable material, tape sets can leave the library altogether and be stored in a secure location or offsite – fully offline, fully air-gapped, and insulated from anything that happens to the production environment.   </p><p>What counts now in building data and AI pipelines for your organization is ensuring data is ready to move into the right performance tier the moment it is needed. Data is the fuel for the models an organization builds, the decisions it makes, and how fast it can act on either.</p><p>Tape is what makes it affordable to keep all of that ‘data fuel’ at scale, protect what cannot be replaced, and put any of it to work on demand. Build it in now, and what you can do with your data is no longer limited by what you can afford to keep online, and instead becomes the means to get, and stay, ahead of your competition.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-storage&quot"><em>We've featured the best cloud storage.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ais-overlooked-storage-opportunity</link>
                                                                            <description>
                            <![CDATA[ AI success depends on keeping more data accessible, protected, and affordable at scale. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FDhxNwHnRKpPimcC2vJena</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YoQ7bF6XQjs33SMa72NcwK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 09:12:33 +0000</pubDate>                                                                                                                                <updated>Fri, 11 Sep 2026 14:59:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Skip Levens ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YoQ7bF6XQjs33SMa72NcwK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Light blue folders from a computer operating system on a dark blue background]]></media:description>                                                            <media:text><![CDATA[Light blue folders from a computer operating system on a dark blue background]]></media:text>
                                <media:title type="plain"><![CDATA[Light blue folders from a computer operating system on a dark blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YoQ7bF6XQjs33SMa72NcwK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The AI <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> discussion is typically framed around the cost of data centers, the power requirements, and the compute needed to train and run models, including <a href="https://www.techradar.com/news/computing-components/graphics-cards/best-graphics-cards-1291458">GPUs</a> and high-performance storage. That’s hardly surprising given the eye-watering investment numbers occupying the headlines.</p><p>The other key commodity, of course, is data to fuel those models. According to Stanford University’s 2025 AI Index Report, dataset sizes for training LLMs are doubling every eight months. In practical terms, as each model is built, some data will move quickly into curation and model-development environments, where fast access is essential.</p><p>Much of it, however, will wait longer while teams establish its relevance to a particular AI use case – not sitting idle, but held securely and ready to move quickly into curation, training and transformation pipelines when needed.  </p><p>From a <a href="https://www.techradar.com/best/best-cloud-document-storage">storage</a> perspective, this raises a point that is easy to overlook: a dataset does not need the same performance at every stage of the AI pipeline. What matters is that it is ready when it is needed – not that it sits on always-on, high-performance infrastructure throughout, which at scale becomes unnecessarily expensive.</p><p>The question for infrastructure planners, then, is not whether AI needs fast storage, but where organizations should keep the very large datasets that will be required in future, before they are ready to be processed. That choice is a strategic one, not a housekeeping one.</p><p>The right capacity tier should keep data protected and readily recoverable into AI, training and transformation pipelines, puts performance only where the work is actually happening, and returns the difference to the budget.  </p><h2 id="your-data-portfolio-as-strategic-advantage">Your data portfolio as strategic advantage </h2><p>As every organization's mission is different, so too each will be at a different stage of the AI journey. Some have raced ahead with systems already in production, while many others continue to explore how the data they already hold could support AI initiatives – <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a>, images and video, operational records, information collected through connected systems; the list goes on.</p><p>This is why knowing your own data is fast becoming a competitive lever rather than an IT chore. Models are available to everyone, so proprietary <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> is your competitive advantage – if you can access it and use it at scale.</p><p>The organizations that will move fastest are the ones that already know what they hold, where it sits, and how quickly it can be put to work. Shortening the distance between a business question and the data that answers it is now a measure of how fast a company can execute and succeed.</p><p>So data is not simply an input to AI: it is what shapes the model. The more of an organization's own data it can bring to bear, the sharper and more specific the resulting tools become, which is why the working assumption should be that almost anything the business holds is potentially useful.</p><p>The conventional approach has been to hold large datasets in a disk-based data lake until they are needed for further processing. Yet as data sets grow ever larger, so too could cost. If every candidate dataset has to live on always-on, high-performance infrastructure, cost sets the ceiling on how much data an organization can afford to keep in play at all.</p><p>The challenge, then, is to keep everything available to workflows as needed, so that the deciding factor is the use case, not the storage bill. </p><h2 id="tale-of-the-tape">Tale of the tape </h2><p>The smart play therefore is not to spend more, but to stop overspending where there is a better way. And it turns out one of the strongest answers here is a technology that has never stopped innovating: tape. Most people still associate it with <a href="https://www.techradar.com/best/best-backup-software">backup</a> and long-term archive – a role it continues to play well – but successive LTO generations have transformed its capacity, throughput and <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> while the industry looked elsewhere.</p><p>The latest tape technology and systems now behave like any other tier in the stack, ready to stream data into fast storage when curation or training is ready for it. And tape’s economics get better as it grows. At the multi-petabyte scale AI programs now reach, cost per terabyte is a fraction of flash or even HDD infrastructure. Performance and capacity can also scale independently, adding more drives for throughput and more cartridges for capacity.</p><p>When considered with tape’s extraordinary energy efficiency, this storage technology emerges as a strategic capability to build into the data center, allowing an organization to keep its entire data estate in play, at a cost that scales predictably.  </p><h2 id="a-safer-place-for-valuable-data">A safer place for valuable data </h2><p>Cost of storage and operation often gets projects approved, yet protection is the one that keeps people up at night. Here, tape offers something the online tiers structurally cannot. Encryption is handled in hardware on the cartridge. Write-Once-Read-Many (WORM) media makes a dataset immutable in the physical sense, so that irreplaceable data cannot be rewritten.</p><p>And for the most valuable material, tape sets can leave the library altogether and be stored in a secure location or offsite – fully offline, fully air-gapped, and insulated from anything that happens to the production environment.   </p><p>What counts now in building data and AI pipelines for your organization is ensuring data is ready to move into the right performance tier the moment it is needed. Data is the fuel for the models an organization builds, the decisions it makes, and how fast it can act on either.</p><p>Tape is what makes it affordable to keep all of that ‘data fuel’ at scale, protect what cannot be replaced, and put any of it to work on demand. Build it in now, and what you can do with your data is no longer limited by what you can afford to keep online, and instead becomes the means to get, and stay, ahead of your competition.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-storage&quot"><em>We've featured the best cloud storage.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts build WeChat worm able to spread across millions of iPhone and Android devices via phone calls ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Calif researchers found a zero‑click WeChat VoIP flaw enabling account takeover via calls</strong></li><li><strong>“WeWorm” spreads through ringing calls; victims need not answer to be compromised</strong></li><li><strong>Tencent patched in Android 8.0.77 and iOS 8.0.76; no exploitation seen in the wild</strong></li></ul><p>Security researchers have found a flaw in WeChat which allows malicious actors to take over people’s accounts on both Android and iOS devices - but what makes this flaw stand out is the fact that it’s a zero-click bug - victims need not do a thing to be compromised.</p><p>WeChat is a “super-app”, allegedly used by roughly 1.4 billion people, and is especially popular in China. It started as a communications app, letting users send messages, and make voice and video calls, and has evolved to function as a social network, allowing users to share photos and videos, as well as a payment app through which users can transfer money, pay for things, order food, book taxis, and even access government and business services.</p><p>Security researchers from Calif have now <a href="https://calif.io/research/weworm" target="_blank" rel="nofollow">disclosed</a> finding a ‘memory corruption’ issue in WeChat's VoIP stack. For now, they decided not to share the technical details, and to instead demonstrate the flaw “at an upcoming conference.” To that end, they built a worm called WeWorm, capable of taking over target WeChat accounts and spread through phone calls made via the app. </p><h2 id="a-phone-call-would-suffice">A phone call would suffice</h2><p>In practice, it works remarkably simple: an attacker uses WeChat to call a person they have in their contacts list (this is a prerequisite). They can use both an Android and an iOS device, and can call anyone, regardless of the model or the OS they’re using. As soon as the phone starts ringing, WeWorm gets to work, “worming” its way into the victim’s device.</p><p>The victim does not even need to answer the phone - having it ring is enough. If they answer, they’ll hear nothing but silence, yet the worm will continue operating. If they decline the call, the attack stops, but this is hardly a mitigation - the attacker can simply call again while the victim is asleep (or otherwise away from their device).</p><p>Within a few seconds, the attacker will have access to the victim’s WeChat account, including their messages, contacts list, and virtually anything else found in the app. What makes this bug particularly worrisome on the surface is the fact that WeChat can be used to transfer money and pay for things, but WeChat Pay has additional authentication and risk controls designed to prevent that from happening. </p><p>The good news is that there is no evidence of this flaw being exploited in the wild. The bad news is that this is not the first zero-click flaw found in modern-day smartphones, and most likely will not be the last one.</p><h2 id="tencent-39-s-response">Tencent's response</h2><p>Calif said it responsibly disclosed its findings to WeChat’s parent company Tencent, who came back with a patch. Versions 8.0.77 for Android and 8.0.76 for iOS have apparently solved the problem, although </p><p>Tencent did not list any details in its patch notes, simply saying the version brought “bug fixes”, but in a statement shared with <a href="https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html" target="_blank"><em>The Hacker News</em></a>, it said the exploit has been “mitigated for all users”, and that it was applied server-side - users need not install anything, aside from the patch. </p><p>It’s also worth mentioning that WeChat has apps for HarmonyOS, Windows, Mac, and Linux. However, it would appear that Calif did not test those, and Tencent did not include them in its patch. The researchers did say that they would be looking into this same flaw in other products, too: </p><p>“This specific WeChat bug is one instance of the many unconventional attack surfaces that are present across many messaging apps,” they said. “We're conducting more of this research across other apps and attack surfaces, while working with app developers on attack surface reduction. This may take an industry-wide effort, since some of it depends on the platform owners. Once that work is further along, we'll share our progress, including the technical details of this WeChat bug.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-build-wechat-worm-able-to-spread-across-millions-of-iphone-and-android-devices-via-phone-calls</link>
                                                                            <description>
                            <![CDATA[ Your phone rings, and you're infected - with all of your contacts and messages exposed. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">L2NUxfetWUexVX4yvWWxJe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2yHEj7RR9QpUSvzcPym7Vf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 01:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2yHEj7RR9QpUSvzcPym7Vf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Angry man shouting at mobile phone while sitting at a desk]]></media:description>                                                            <media:text><![CDATA[Angry man shouting at mobile phone while sitting at a desk]]></media:text>
                                <media:title type="plain"><![CDATA[Angry man shouting at mobile phone while sitting at a desk]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2yHEj7RR9QpUSvzcPym7Vf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Calif researchers found a zero‑click WeChat VoIP flaw enabling account takeover via calls</strong></li><li><strong>“WeWorm” spreads through ringing calls; victims need not answer to be compromised</strong></li><li><strong>Tencent patched in Android 8.0.77 and iOS 8.0.76; no exploitation seen in the wild</strong></li></ul><p>Security researchers have found a flaw in WeChat which allows malicious actors to take over people’s accounts on both Android and iOS devices - but what makes this flaw stand out is the fact that it’s a zero-click bug - victims need not do a thing to be compromised.</p><p>WeChat is a “super-app”, allegedly used by roughly 1.4 billion people, and is especially popular in China. It started as a communications app, letting users send messages, and make voice and video calls, and has evolved to function as a social network, allowing users to share photos and videos, as well as a payment app through which users can transfer money, pay for things, order food, book taxis, and even access government and business services.</p><p>Security researchers from Calif have now <a href="https://calif.io/research/weworm" target="_blank" rel="nofollow">disclosed</a> finding a ‘memory corruption’ issue in WeChat's VoIP stack. For now, they decided not to share the technical details, and to instead demonstrate the flaw “at an upcoming conference.” To that end, they built a worm called WeWorm, capable of taking over target WeChat accounts and spread through phone calls made via the app. </p><h2 id="a-phone-call-would-suffice">A phone call would suffice</h2><p>In practice, it works remarkably simple: an attacker uses WeChat to call a person they have in their contacts list (this is a prerequisite). They can use both an Android and an iOS device, and can call anyone, regardless of the model or the OS they’re using. As soon as the phone starts ringing, WeWorm gets to work, “worming” its way into the victim’s device.</p><p>The victim does not even need to answer the phone - having it ring is enough. If they answer, they’ll hear nothing but silence, yet the worm will continue operating. If they decline the call, the attack stops, but this is hardly a mitigation - the attacker can simply call again while the victim is asleep (or otherwise away from their device).</p><p>Within a few seconds, the attacker will have access to the victim’s WeChat account, including their messages, contacts list, and virtually anything else found in the app. What makes this bug particularly worrisome on the surface is the fact that WeChat can be used to transfer money and pay for things, but WeChat Pay has additional authentication and risk controls designed to prevent that from happening. </p><p>The good news is that there is no evidence of this flaw being exploited in the wild. The bad news is that this is not the first zero-click flaw found in modern-day smartphones, and most likely will not be the last one.</p><h2 id="tencent-39-s-response">Tencent's response</h2><p>Calif said it responsibly disclosed its findings to WeChat’s parent company Tencent, who came back with a patch. Versions 8.0.77 for Android and 8.0.76 for iOS have apparently solved the problem, although </p><p>Tencent did not list any details in its patch notes, simply saying the version brought “bug fixes”, but in a statement shared with <a href="https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html" target="_blank"><em>The Hacker News</em></a>, it said the exploit has been “mitigated for all users”, and that it was applied server-side - users need not install anything, aside from the patch. </p><p>It’s also worth mentioning that WeChat has apps for HarmonyOS, Windows, Mac, and Linux. However, it would appear that Calif did not test those, and Tencent did not include them in its patch. The researchers did say that they would be looking into this same flaw in other products, too: </p><p>“This specific WeChat bug is one instance of the many unconventional attack surfaces that are present across many messaging apps,” they said. “We're conducting more of this research across other apps and attack surfaces, while working with app developers on attack surface reduction. This may take an industry-wide effort, since some of it depends on the platform owners. Once that work is further along, we'll share our progress, including the technical details of this WeChat bug.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft September 2026 Patch Tuesday fixes nearly a thousand flaws, including two major zero-days ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft has fixed no fewer than 974 vulnerabilities in its latest Patch Tuesday release</strong></li><li><strong>Two were already being exploited in the wild, 114 categorized as 'Critical'</strong></li><li><strong>AI is to blame for boosting CVE discovery and also intensifying attacks</strong></li></ul><p>Microsoft's September 2026 Patch Tuesday has become its biggest security release on record, with the company issuing fixes for a staggering 974 vulnerabilities across the entire stack.</p><p>According to the company's <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep" target="_blank">release notes</a>, an overwhelming majority (723) of the vulnerabilities addressed related to Windows, with Office coming in at second place with 111 of its own vulnerabilities being addressed.</p><p>While it's clear that the number of vulnerabilities is going up year-over-year, it's likely that the company was also simply able to find more of them that would otherwise have slipped through the net thanks to AI-assisted discovery tools.</p><h2 id="this-is-microsoft-39-s-biggest-patch-tuesday-ever">This is Microsoft's biggest Patch Tuesday ever</h2><p>Speaking about the September 2026 Patch Tuesday in a <a href="https://www.zerodayinitiative.com/blog/2026/9/8/the-september-2026-security-update-review" target="_blank">blog post</a>, Dustin Childs explains that this could be the start of the "new normal." Childs goes on to reveal that Microsoft has patched 2,760 CVEs this year to date – more than double any other year that precedes it.</p><p>Childs' figures show that the company patched 1,139 CVEs in the whole of 2025, and a much lower 492 a decade ago in 2016. According to the post, 114 of the vulnerabilities patched in this latest update were 'Critical' – more than one in 10.</p><p>In its own notes, Microsoft described CVE-2026-85880 and CVE-2026-81963 as especially notable because they're both being actively exploited, hence the push to get them fixed and for customers to install the update.</p><p>Elsewhere in the industry, Microsoft isn't the only company addressing a higher volume of bugs. Childs also highlighted high activity from Adobe, while a number of browser developers including Google, Mozilla, Brave and Microsoft itself have doubled the release cycle to two weeks in order to get fixes into customer hands more quickly.</p><p>Besides fixing exploitable bugs, Microsoft also used the opportunity to issue fixes to known issues – including fixing Teams and Outlook crashes on Arm64 PCs – as well as to upgrade Copilot+ AI components.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/microsoft-september-2026-patch-tuesday-fixes-nearly-a-thousand-flaws-including-two-major-zero-days</link>
                                                                            <description>
                            <![CDATA[ 2026 has been a record year for CVE fixes, but Microsoft just fixed nearly 1,000 of them in one single update. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2u3KcSqfipZXjvCguMVheP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yBsirNxrnuBxshrCgrFwsQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 16:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yBsirNxrnuBxshrCgrFwsQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock - Wachiwit]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Windows 10 Logo on Laptop]]></media:description>                                                            <media:text><![CDATA[Windows 10 Logo on Laptop]]></media:text>
                                <media:title type="plain"><![CDATA[Windows 10 Logo on Laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yBsirNxrnuBxshrCgrFwsQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft has fixed no fewer than 974 vulnerabilities in its latest Patch Tuesday release</strong></li><li><strong>Two were already being exploited in the wild, 114 categorized as 'Critical'</strong></li><li><strong>AI is to blame for boosting CVE discovery and also intensifying attacks</strong></li></ul><p>Microsoft's September 2026 Patch Tuesday has become its biggest security release on record, with the company issuing fixes for a staggering 974 vulnerabilities across the entire stack.</p><p>According to the company's <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep" target="_blank">release notes</a>, an overwhelming majority (723) of the vulnerabilities addressed related to Windows, with Office coming in at second place with 111 of its own vulnerabilities being addressed.</p><p>While it's clear that the number of vulnerabilities is going up year-over-year, it's likely that the company was also simply able to find more of them that would otherwise have slipped through the net thanks to AI-assisted discovery tools.</p><h2 id="this-is-microsoft-39-s-biggest-patch-tuesday-ever">This is Microsoft's biggest Patch Tuesday ever</h2><p>Speaking about the September 2026 Patch Tuesday in a <a href="https://www.zerodayinitiative.com/blog/2026/9/8/the-september-2026-security-update-review" target="_blank">blog post</a>, Dustin Childs explains that this could be the start of the "new normal." Childs goes on to reveal that Microsoft has patched 2,760 CVEs this year to date – more than double any other year that precedes it.</p><p>Childs' figures show that the company patched 1,139 CVEs in the whole of 2025, and a much lower 492 a decade ago in 2016. According to the post, 114 of the vulnerabilities patched in this latest update were 'Critical' – more than one in 10.</p><p>In its own notes, Microsoft described CVE-2026-85880 and CVE-2026-81963 as especially notable because they're both being actively exploited, hence the push to get them fixed and for customers to install the update.</p><p>Elsewhere in the industry, Microsoft isn't the only company addressing a higher volume of bugs. Childs also highlighted high activity from Adobe, while a number of browser developers including Google, Mozilla, Brave and Microsoft itself have doubled the release cycle to two weeks in order to get fixes into customer hands more quickly.</p><p>Besides fixing exploitable bugs, Microsoft also used the opportunity to issue fixes to known issues – including fixing Teams and Outlook crashes on Arm64 PCs – as well as to upgrade Copilot+ AI components.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI, NSA warn Chinese AI companies like DeepSeek and Alibaba are reportedly carrying out 'industrial-scale' distillation campaigns to boost their models ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CISA, NSA, FBI warn Chinese AI firms of industrial‑scale knowledge distillation</strong></li><li><strong>Companies like DeepSeek, Moonshot, Alibaba allegedly extracted billions of tokens from US frontier models</strong></li><li><strong>Advisory urges detection of malicious prompts, deceptive responses to distillation, and cross‑provider intelligence sharing</strong></li></ul><p>Chinese AI companies’ core development strategy is to steal proprietary functionalities and capabilities from their US counterparts, law enforcement agencies have warned.</p><p>The US Cybersecurity and Infrastructure Security Agency (CISA) has <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a" target="_blank" rel="nofollow">published</a> a new security advisory, drafted jointly with the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI), warning American <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI companies</a> about an ongoing “aggressive, malicious, and targeted distillation activities at an industrial scale,” and sharing recommended mitigation steps.</p><h2 id="knowledge-distillation">Knowledge distillation</h2><p>IBM defines knowledge distillation as a “machine learning technique that aims to transfer the learnings of a large pre-trained model, the ‘teacher model,’ to a smaller ‘student model’.” It is used in deep learning as a form of model compression and knowledge transfer, it added, particularly for massive deep neural networks. </p><p>So, knowledge distillation is not illegal or malicious, per se. Its goal is to train a more compact model to mimic a larger, more complex one. In the security advisory, the agencies stress it is “recognized as a legitimate and useful technique in AI research,” but add that China-based AI companies are using it in ill will. </p><p>In other words, the agencies claim that instead of spending months and millions developing new capabilities for their models, the Chinese are simply sending huge numbers of carefully designed questions to US models and extracting the answers.</p><h2 id="which-companies-are-engaged-in-knowledge-distillation">Which companies are engaged in knowledge distillation?</h2><p>Apparently, all companies worth anything. DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI all allegedly “extracted billions of tokens across millions of exchanges/requests from US frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024.” CISA also stressed that this was likely done with the awareness of the Chinese government. It hasn’t outright said, “with its blessing”, although it could be read between the lines. </p><p>The advisory shares a thorough list of all the models that were being trained, as well as all the models being taken advantage of. </p><p>On the Chinese side, they include DeepSeek R1 and V3 models, Moonshot’s Kimi-K2 and Kimi-K3 models, and MiniMax’s M2 model. On the US side, they start with earlier models such as GPT-4, Claude 3.7, and Gemini 2.5 Flash Preview, all the way to Claude Fable 5, GPT-5, and similar.</p><p>When done in good faith, knowledge distillation is not illegal. However, the report says the companies routed the requests through multiple accounts, different API access points, multiple cloud providers, third-party AI aggregators, proxy services and “transfer stations”, as well as premium subscriptions shared between developers, all in an attempt to work around defenders trying to disrupt the process.</p><p>“This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership. Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations,” the agencies concluded.</p><h2 id="what-us-companies-should-be-doing">What US companies should be doing</h2><p>To defend their intellectual property (and thus remain ahead of Chinese competing models) US AI companies should implement comprehensive detection and mitigation, the agencies said. That means hunting for anomalous and malicious prompts, accounts, networks, and behaviors. Furthermore, they should monitor subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns.</p><p>The second step is to “deploy targeted response changes”: “Subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs to companies conducting industrial-scale distillation campaigns.” In other words, AI companies should make sure their products lie when they spot they were being distilled for knowledge. </p><p>Finally, US AI firms should set up cross-organization intelligence sharing, correlating activity across model providers, cloud platforms, and API aggregators.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/fbi-nsa-warn-chinese-ai-companies-like-deepseek-and-alibaba-are-reportedly-carrying-out-industrial-scale-distillation-campaigns-to-boost-their-models</link>
                                                                            <description>
                            <![CDATA[ US AI companies should implement additional mitigations to curb these attempts, agencies warn. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8hYy6XQ59ei9aG8aoWsM4d</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cWc9CWu3UHCubh8PtKXmVS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cWc9CWu3UHCubh8PtKXmVS-1280-80.jpg">
                                                            <media:credit><![CDATA[OpenAI &amp; Google]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ChatGPT vs Gemini comparison]]></media:description>                                                            <media:text><![CDATA[ChatGPT vs Gemini comparison]]></media:text>
                                <media:title type="plain"><![CDATA[ChatGPT vs Gemini comparison]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cWc9CWu3UHCubh8PtKXmVS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CISA, NSA, FBI warn Chinese AI firms of industrial‑scale knowledge distillation</strong></li><li><strong>Companies like DeepSeek, Moonshot, Alibaba allegedly extracted billions of tokens from US frontier models</strong></li><li><strong>Advisory urges detection of malicious prompts, deceptive responses to distillation, and cross‑provider intelligence sharing</strong></li></ul><p>Chinese AI companies’ core development strategy is to steal proprietary functionalities and capabilities from their US counterparts, law enforcement agencies have warned.</p><p>The US Cybersecurity and Infrastructure Security Agency (CISA) has <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a" target="_blank" rel="nofollow">published</a> a new security advisory, drafted jointly with the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI), warning American <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI companies</a> about an ongoing “aggressive, malicious, and targeted distillation activities at an industrial scale,” and sharing recommended mitigation steps.</p><h2 id="knowledge-distillation">Knowledge distillation</h2><p>IBM defines knowledge distillation as a “machine learning technique that aims to transfer the learnings of a large pre-trained model, the ‘teacher model,’ to a smaller ‘student model’.” It is used in deep learning as a form of model compression and knowledge transfer, it added, particularly for massive deep neural networks. </p><p>So, knowledge distillation is not illegal or malicious, per se. Its goal is to train a more compact model to mimic a larger, more complex one. In the security advisory, the agencies stress it is “recognized as a legitimate and useful technique in AI research,” but add that China-based AI companies are using it in ill will. </p><p>In other words, the agencies claim that instead of spending months and millions developing new capabilities for their models, the Chinese are simply sending huge numbers of carefully designed questions to US models and extracting the answers.</p><h2 id="which-companies-are-engaged-in-knowledge-distillation">Which companies are engaged in knowledge distillation?</h2><p>Apparently, all companies worth anything. DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI all allegedly “extracted billions of tokens across millions of exchanges/requests from US frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024.” CISA also stressed that this was likely done with the awareness of the Chinese government. It hasn’t outright said, “with its blessing”, although it could be read between the lines. </p><p>The advisory shares a thorough list of all the models that were being trained, as well as all the models being taken advantage of. </p><p>On the Chinese side, they include DeepSeek R1 and V3 models, Moonshot’s Kimi-K2 and Kimi-K3 models, and MiniMax’s M2 model. On the US side, they start with earlier models such as GPT-4, Claude 3.7, and Gemini 2.5 Flash Preview, all the way to Claude Fable 5, GPT-5, and similar.</p><p>When done in good faith, knowledge distillation is not illegal. However, the report says the companies routed the requests through multiple accounts, different API access points, multiple cloud providers, third-party AI aggregators, proxy services and “transfer stations”, as well as premium subscriptions shared between developers, all in an attempt to work around defenders trying to disrupt the process.</p><p>“This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership. Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations,” the agencies concluded.</p><h2 id="what-us-companies-should-be-doing">What US companies should be doing</h2><p>To defend their intellectual property (and thus remain ahead of Chinese competing models) US AI companies should implement comprehensive detection and mitigation, the agencies said. That means hunting for anomalous and malicious prompts, accounts, networks, and behaviors. Furthermore, they should monitor subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns.</p><p>The second step is to “deploy targeted response changes”: “Subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs to companies conducting industrial-scale distillation campaigns.” In other words, AI companies should make sure their products lie when they spot they were being distilled for knowledge. </p><p>Finally, US AI firms should set up cross-organization intelligence sharing, correlating activity across model providers, cloud platforms, and API aggregators.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How AI is reshaping the economics of cyberattacks and defense ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The bottleneck on sophisticated cyber operations that target nation states is breaking. Conducting a large-scale cyber attack used to mean scaling expert talent. </p><p>When the cost of adding a capable attacker approaches the cost of compute, the economics of offense fundamentally change. </p><p>This is already operational: Dream's threat research recovered an autonomous multi-agent framework that ran intrusion campaigns against government entities in Asia, executing twelve attack waves in four days with eight parallel agents, compromising 85 government accounts, and using a closed learning loop to adapt after failure. </p><p>The advantage is shifting from the number of experts to how effectively their expertise can be scaled. </p><p>AI benefits both attackers and defenders, but defenders start with a unique advantage: they already own the map attackers must discover. </p><p>Defenders that understand their environment can use AI to turn that knowledge into operational scale.</p><h2 id="the-autonomous-ai-government-hacker">The Autonomous AI Government Hacker</h2><p>In July, our threat research team recovered the operational workspace of an autonomous multi-agent framework that had been conducting intrusion campaigns against government entities in Asia.</p><p>Over roughly four days, the framework executed twelve attack waves and ran up to eight AI agents in parallel. Built on the publicly available Hermes and OpenClaw frameworks, it compromised 85 government <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> accounts and used 84 of them to pivot through a government single sign-on environment.</p><p>What’s really intriguing is its autonomous operational decision making.</p><h2 id="assigning-confidence-scores">Assigning confidence scores</h2><p>Every discovery was assigned a Bayesian confidence score to assess different paths and then chose how to proceed, just like an actual team. </p><p>Similarly, when an attack path failed, the framework automatically entered what it called a Learning Cycle, searched vulnerability <a href="https://www.techradar.com/best/best-database-software">databases</a> and security research techniques relevant to that government's technology stack, and tried again. The framework audited itself – it created a closed learning loop: investigate, validate, act, observe the result, update its operational knowledge, and try again.</p><p>This was not a self-improving model. It was a self-adapting cyber attacker – there is a real expert behind it, embedded as AI system. The fundamentals of this attack weren’t even particularly impressive or novel. It is the scale – and the prospect for nearly infinite scale – that is daunting.</p><p>Until recently, one of the limiting factors in scaling sophisticated offensive operations was the expert reasoning required to decide what to investigate, validate findings, connect them into viable attack paths, and adapt when those paths failed. It was expensive, both in dollars and in expertise. That scarcity placed a natural constraint on offensive scale - scaling a sophisticated operation meant scaling skilled people, time and coordination.</p><p>AI is beginning to automate precisely that expensive layer of the operation: deciding what to investigate, validating hypotheses, learning from failure and choosing what to try next. Talent still determines the quality of those decisions. But the number of talented people no longer has to determine how many times those decisions can be made in parallel.</p><p>What happens when scaling an offensive operation no longer requires scaling the number of experts behind it at the same rate?</p><p>As someone who has spent 15 years in both offensive and defensive cyber roles, it’s becoming clearer every day that AI has changed that equation - the historical relationship between the amount of expert talent an organization has and the scale at which it can operate is beginning to break down. </p><p>AI does not eliminate talent - it changes what talent can scale.</p><h2 id="an-attack-surface-the-size-of-a-country">An Attack Surface the Size of a Country</h2><p>Government <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a> is an interconnected ecosystem built over decades. It consists of ministries, municipalities, operational technology, legacy applications, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a>, contractors, suppliers, and countless trust relationships connecting them together.</p><p>These connections typically exist for legitimate operational reasons (or at least historically legitimate reasons).</p><p>Of course, every connection is also a potential vulnerability.</p><p>This is how modern government attacks spread - not necessarily by exploiting one critical vulnerability, but by chaining together many ordinary ones.</p><p>Historically, this challenged both sides. No defensive team could continuously reason over every <a href="https://www.techradar.com/best/best-asset-management-software">asset</a>, identity, configuration, vulnerability and trust relationship across an entire country. But attackers faced a version of the same constraint. Their experts also had to decide where to spend their time to find a viable path from intrusion to crown jewel</p><p>Autonomous systems change that.</p><p>An autonomous attacker does not need to understand the entire government environment in advance. It can explore it continuously: discover a relationship, form a hypothesis, test it, learn from the result and move to the next one.</p><p>For the first time, governments may face adversaries capable of reasoning over national-scale attack surfaces faster than the institutions responsible for defending them.</p><h2 id="the-race-to-change-the-outcome">The Race to Change the Outcome</h2><p>The dramatic decline in the cost of offensive cyber expertise, via leveraging and weaponizing agents, is a tectonic shift. Until now, this was a skill limited to a select few and came with a high price tag.</p><p>Today,  discovering, prioritizing and combining these techniques into viable attack paths is cheap, and one can repeat the process at machine speed.</p><p>With the pace of AI development, that statement becomes more true every day.</p><p>Offensive capability is becoming cheaper, faster and easier to reproduce.</p><p>But there is another side to this equation.</p><p>Defenders have always had structural advantages: more telemetry, deeper context, persistent access to their infrastructure, and knowledge of its configurations, identities and relationships, while also have a much better ability to act.</p><p>They too had the constraint of human capacity. No team could continuously reason over all that information, across every asset and relationship, all the time. The same AI that benefits attackers may operationalize defender’s historical edge at scale too.</p><p>This is where time plays a key role. Analyzing everything is not the same as defending everything. If AI detects a compromised identity in seconds but the credential remains active for six hours, the attacker still has six hours. If it identifies an exploitable path to a critical system but remediation takes three weeks, that path remains open for three weeks.</p><p>The opportunity, then, is not simply better analysis. It is reducing time-to-effective-action: the time between understanding a risk and changing the outcome.</p><p>And "effective" matters- disabling an <a href="https://www.techradar.com/best/best-identity-management-software">identity</a>, changing a <a href="https://www.techradar.com/best/firewall">firewall</a> rule or patching a vulnerability is not enough. The system must verify that the attacker can no longer achieve its objective.</p><p>The defensive loop cannot end with intelligence - or even with action. It has to end with a verified <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> outcome.</p><h2 id="the-gap-that-matters">The Gap That Matters </h2><p>AI does not inevitably favor the attacker.</p><p>The framework we recovered had to steal its map of the environment, one probe at a time. Defenders already have that map. Every configuration, credential, telemetry stream and trust relationship could take an attacker – even an AI attacker – days to weeks to discover. What defenders could never do was reason over all the assets they had, continuously, due to the lack of talent capacity to do that.</p><p>AI begins to remove that human-attention constraint. It allows defenders to amplify expert talent across thousands of investigations in parallel, continuously identifying attack paths, prioritizing those that pose the greatest risk, and focusing action where it matters most.</p><p>Attackers get the same leverage. But they don't start from the same place. Defenders have a home-field advantage: they already know and control the environment the attacker must discover.</p><p>The gap that matters is no longer simply the number of experts on either side. It is how effectively each side can scale that expertise- and direct it toward the right risks first.</p><p>Ultimately, the race is not about who can know more.</p><p>It is about who can scale talent in the right way- and turn that scale into an outcome first.</p><p><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software available</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/how-ai-is-reshaping-the-economics-of-cyberattacks-and-defense</link>
                                                                            <description>
                            <![CDATA[ AI is scaling cyberattacks, forcing defenders to rethink how they respond and act. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">h3bvuUgubs3BjpD7WSUB7m</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 14:07:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kfir Fleischer ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The bottleneck on sophisticated cyber operations that target nation states is breaking. Conducting a large-scale cyber attack used to mean scaling expert talent. </p><p>When the cost of adding a capable attacker approaches the cost of compute, the economics of offense fundamentally change. </p><p>This is already operational: Dream's threat research recovered an autonomous multi-agent framework that ran intrusion campaigns against government entities in Asia, executing twelve attack waves in four days with eight parallel agents, compromising 85 government accounts, and using a closed learning loop to adapt after failure. </p><p>The advantage is shifting from the number of experts to how effectively their expertise can be scaled. </p><p>AI benefits both attackers and defenders, but defenders start with a unique advantage: they already own the map attackers must discover. </p><p>Defenders that understand their environment can use AI to turn that knowledge into operational scale.</p><h2 id="the-autonomous-ai-government-hacker">The Autonomous AI Government Hacker</h2><p>In July, our threat research team recovered the operational workspace of an autonomous multi-agent framework that had been conducting intrusion campaigns against government entities in Asia.</p><p>Over roughly four days, the framework executed twelve attack waves and ran up to eight AI agents in parallel. Built on the publicly available Hermes and OpenClaw frameworks, it compromised 85 government <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> accounts and used 84 of them to pivot through a government single sign-on environment.</p><p>What’s really intriguing is its autonomous operational decision making.</p><h2 id="assigning-confidence-scores">Assigning confidence scores</h2><p>Every discovery was assigned a Bayesian confidence score to assess different paths and then chose how to proceed, just like an actual team. </p><p>Similarly, when an attack path failed, the framework automatically entered what it called a Learning Cycle, searched vulnerability <a href="https://www.techradar.com/best/best-database-software">databases</a> and security research techniques relevant to that government's technology stack, and tried again. The framework audited itself – it created a closed learning loop: investigate, validate, act, observe the result, update its operational knowledge, and try again.</p><p>This was not a self-improving model. It was a self-adapting cyber attacker – there is a real expert behind it, embedded as AI system. The fundamentals of this attack weren’t even particularly impressive or novel. It is the scale – and the prospect for nearly infinite scale – that is daunting.</p><p>Until recently, one of the limiting factors in scaling sophisticated offensive operations was the expert reasoning required to decide what to investigate, validate findings, connect them into viable attack paths, and adapt when those paths failed. It was expensive, both in dollars and in expertise. That scarcity placed a natural constraint on offensive scale - scaling a sophisticated operation meant scaling skilled people, time and coordination.</p><p>AI is beginning to automate precisely that expensive layer of the operation: deciding what to investigate, validating hypotheses, learning from failure and choosing what to try next. Talent still determines the quality of those decisions. But the number of talented people no longer has to determine how many times those decisions can be made in parallel.</p><p>What happens when scaling an offensive operation no longer requires scaling the number of experts behind it at the same rate?</p><p>As someone who has spent 15 years in both offensive and defensive cyber roles, it’s becoming clearer every day that AI has changed that equation - the historical relationship between the amount of expert talent an organization has and the scale at which it can operate is beginning to break down. </p><p>AI does not eliminate talent - it changes what talent can scale.</p><h2 id="an-attack-surface-the-size-of-a-country">An Attack Surface the Size of a Country</h2><p>Government <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a> is an interconnected ecosystem built over decades. It consists of ministries, municipalities, operational technology, legacy applications, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a>, contractors, suppliers, and countless trust relationships connecting them together.</p><p>These connections typically exist for legitimate operational reasons (or at least historically legitimate reasons).</p><p>Of course, every connection is also a potential vulnerability.</p><p>This is how modern government attacks spread - not necessarily by exploiting one critical vulnerability, but by chaining together many ordinary ones.</p><p>Historically, this challenged both sides. No defensive team could continuously reason over every <a href="https://www.techradar.com/best/best-asset-management-software">asset</a>, identity, configuration, vulnerability and trust relationship across an entire country. But attackers faced a version of the same constraint. Their experts also had to decide where to spend their time to find a viable path from intrusion to crown jewel</p><p>Autonomous systems change that.</p><p>An autonomous attacker does not need to understand the entire government environment in advance. It can explore it continuously: discover a relationship, form a hypothesis, test it, learn from the result and move to the next one.</p><p>For the first time, governments may face adversaries capable of reasoning over national-scale attack surfaces faster than the institutions responsible for defending them.</p><h2 id="the-race-to-change-the-outcome">The Race to Change the Outcome</h2><p>The dramatic decline in the cost of offensive cyber expertise, via leveraging and weaponizing agents, is a tectonic shift. Until now, this was a skill limited to a select few and came with a high price tag.</p><p>Today,  discovering, prioritizing and combining these techniques into viable attack paths is cheap, and one can repeat the process at machine speed.</p><p>With the pace of AI development, that statement becomes more true every day.</p><p>Offensive capability is becoming cheaper, faster and easier to reproduce.</p><p>But there is another side to this equation.</p><p>Defenders have always had structural advantages: more telemetry, deeper context, persistent access to their infrastructure, and knowledge of its configurations, identities and relationships, while also have a much better ability to act.</p><p>They too had the constraint of human capacity. No team could continuously reason over all that information, across every asset and relationship, all the time. The same AI that benefits attackers may operationalize defender’s historical edge at scale too.</p><p>This is where time plays a key role. Analyzing everything is not the same as defending everything. If AI detects a compromised identity in seconds but the credential remains active for six hours, the attacker still has six hours. If it identifies an exploitable path to a critical system but remediation takes three weeks, that path remains open for three weeks.</p><p>The opportunity, then, is not simply better analysis. It is reducing time-to-effective-action: the time between understanding a risk and changing the outcome.</p><p>And "effective" matters- disabling an <a href="https://www.techradar.com/best/best-identity-management-software">identity</a>, changing a <a href="https://www.techradar.com/best/firewall">firewall</a> rule or patching a vulnerability is not enough. The system must verify that the attacker can no longer achieve its objective.</p><p>The defensive loop cannot end with intelligence - or even with action. It has to end with a verified <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> outcome.</p><h2 id="the-gap-that-matters">The Gap That Matters </h2><p>AI does not inevitably favor the attacker.</p><p>The framework we recovered had to steal its map of the environment, one probe at a time. Defenders already have that map. Every configuration, credential, telemetry stream and trust relationship could take an attacker – even an AI attacker – days to weeks to discover. What defenders could never do was reason over all the assets they had, continuously, due to the lack of talent capacity to do that.</p><p>AI begins to remove that human-attention constraint. It allows defenders to amplify expert talent across thousands of investigations in parallel, continuously identifying attack paths, prioritizing those that pose the greatest risk, and focusing action where it matters most.</p><p>Attackers get the same leverage. But they don't start from the same place. Defenders have a home-field advantage: they already know and control the environment the attacker must discover.</p><p>The gap that matters is no longer simply the number of experts on either side. It is how effectively each side can scale that expertise- and direct it toward the right risks first.</p><p>Ultimately, the race is not about who can know more.</p><p>It is about who can scale talent in the right way- and turn that scale into an outcome first.</p><p><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software available</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A worrying ChatGPT bug let strangers read Gmail messages via a hidden cross-account channel ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Check Point Research exposed coerced insider flaw in ChatGPT’s agent architecture</strong></li><li><strong>Containers shared metadata via internal service, enabling cross‑account prompt injection and data theft</strong></li><li><strong>OpenAI closed the path, but CPR warns similar risks may exist in other AI platforms</strong></li></ul><p>ChatGPT’s AI agents were allowed to pull sensitive data from one account shared with an entirely different account because, colloquially speaking, all agents used to walk down the same hallways, experts have warned. </p><p>A new <a href="https://blog.checkpoint.com/research/chatgpt-let-attackers-read-victims-gmail-through-a-hidden-channel-between-accounts/" target="_blank" rel="nofollow">report</a> from security experts Check Point Research (CPR) dubbed the flaw “coerced insider”, since it revolves around persuading the agent instead of abusing a vulnerability.</p><h2 id="coerced-insider">Coerced insider</h2><p>When an AI agent is given a task that needs code execution, it handles that task in an isolated container which also sometimes needs to install software. To enable that, without giving containers direct internet access (which would be too risky), OpenAI routes those packages through an internal JFrog Artifactory instance. As a separate security contingency, containers from different accounts cannot talk between themselves.</p><p>However - they can reach the same internal service (our proverbial hallways), which exposes an item management feature that lets the containers attach text or binary properties to a repository item. As a result, any container can read back the properties written by any other container. </p><p>“Check Point Research confirmed the isolation gap directly: a property written from one account’s container was fully readable from a different account’s container moments later, with data too large for one property simply split into chunks and reassembled on the other end,” the researchers explained. </p><p>“The package delivery metadata effectively became a shared clipboard between containers that were supposed to be walled off from one another.”</p><p>From there, the exploit turns into your usual, off-the-shelf prompt injection. The only difference is that the malicious prompt is not delivered directly to the victim, but rather left in the hallways, and the results are not shared with the attackers directly, but rather left in those same proverbial hallways, too.</p><p>The attacker then delivers a prompt or a shared conversation that instructs the agent to check the same storage during its next ordinary reply. The agent checks, sees the malicious instructions, executes them, all the while replying to the victim’s question in the usual manner. The victim is oblivious to the fact that data theft is taking place in the background.</p><h2 id="what-kind-of-information-can-be-stolen">What kind of information can be stolen?</h2><p>But this is just half of the equation. How destructive this attack ends up being still depends on the amount of data being shared with the victim agent. </p><p>The bare minimum is the information shared while chatting to the agent. It then grows with every connected app: Gmail, <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Google Drive</a>, Microsoft Teams, GitHub, and similar. “In Check Point Research’s demonstration, ChatGPT retrieved the victim’s <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email</a> data through their connected Gmail account and delivered it to the attacker’s session, all within a single ordinary turn,” CPR stressed.</p><p>The good news is that you’ll likely never be exposed this way, at least not via ChatGPT. CPR says it disclosed the findings to OpenAI, who then confirmed that the specific internal Artifactory instance identified in the research has been commissioned. In other words, the hallways attack path has been closed.</p><p>The bad news is that this doesn’t automatically mean everyone’s safe. This particular path might be closed, but the architectural pattern behind the flaw could be present in other platforms, CPR warns. </p><p>“Any AI assistant that operates inside an organization’s trust boundary, holding credentials, running code, and reaching connected services, can become what Check Point Research calls a coerced insider,” the report states. “The model itself does not need to be malicious. It only needs to be persuaded, through text it was never meant to trust, to use access that was granted for entirely legitimate reasons.” </p><p>Going forward, businesses are advised to learn which AI tools their employees are using, and what those tools are connected to. Then, they should govern what AI tools and agents are allowed to do, treating all of their actions (not just output) as something that needs to be monitored. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/a-worrying-chatgpt-bug-let-strangers-read-gmail-messages-via-a-hidden-cross-account-channel</link>
                                                                            <description>
                            <![CDATA[ OpenAI has shut down this particular path, but general risk remains. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zQSSo4tbPGKyLUJSW5gy2j</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PB5R692ChqyHSzKEtqDyYe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PB5R692ChqyHSzKEtqDyYe-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/ alexsl]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ChatGPT app]]></media:description>                                                            <media:text><![CDATA[ChatGPT app]]></media:text>
                                <media:title type="plain"><![CDATA[ChatGPT app]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PB5R692ChqyHSzKEtqDyYe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Check Point Research exposed coerced insider flaw in ChatGPT’s agent architecture</strong></li><li><strong>Containers shared metadata via internal service, enabling cross‑account prompt injection and data theft</strong></li><li><strong>OpenAI closed the path, but CPR warns similar risks may exist in other AI platforms</strong></li></ul><p>ChatGPT’s AI agents were allowed to pull sensitive data from one account shared with an entirely different account because, colloquially speaking, all agents used to walk down the same hallways, experts have warned. </p><p>A new <a href="https://blog.checkpoint.com/research/chatgpt-let-attackers-read-victims-gmail-through-a-hidden-channel-between-accounts/" target="_blank" rel="nofollow">report</a> from security experts Check Point Research (CPR) dubbed the flaw “coerced insider”, since it revolves around persuading the agent instead of abusing a vulnerability.</p><h2 id="coerced-insider">Coerced insider</h2><p>When an AI agent is given a task that needs code execution, it handles that task in an isolated container which also sometimes needs to install software. To enable that, without giving containers direct internet access (which would be too risky), OpenAI routes those packages through an internal JFrog Artifactory instance. As a separate security contingency, containers from different accounts cannot talk between themselves.</p><p>However - they can reach the same internal service (our proverbial hallways), which exposes an item management feature that lets the containers attach text or binary properties to a repository item. As a result, any container can read back the properties written by any other container. </p><p>“Check Point Research confirmed the isolation gap directly: a property written from one account’s container was fully readable from a different account’s container moments later, with data too large for one property simply split into chunks and reassembled on the other end,” the researchers explained. </p><p>“The package delivery metadata effectively became a shared clipboard between containers that were supposed to be walled off from one another.”</p><p>From there, the exploit turns into your usual, off-the-shelf prompt injection. The only difference is that the malicious prompt is not delivered directly to the victim, but rather left in the hallways, and the results are not shared with the attackers directly, but rather left in those same proverbial hallways, too.</p><p>The attacker then delivers a prompt or a shared conversation that instructs the agent to check the same storage during its next ordinary reply. The agent checks, sees the malicious instructions, executes them, all the while replying to the victim’s question in the usual manner. The victim is oblivious to the fact that data theft is taking place in the background.</p><h2 id="what-kind-of-information-can-be-stolen">What kind of information can be stolen?</h2><p>But this is just half of the equation. How destructive this attack ends up being still depends on the amount of data being shared with the victim agent. </p><p>The bare minimum is the information shared while chatting to the agent. It then grows with every connected app: Gmail, <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Google Drive</a>, Microsoft Teams, GitHub, and similar. “In Check Point Research’s demonstration, ChatGPT retrieved the victim’s <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email</a> data through their connected Gmail account and delivered it to the attacker’s session, all within a single ordinary turn,” CPR stressed.</p><p>The good news is that you’ll likely never be exposed this way, at least not via ChatGPT. CPR says it disclosed the findings to OpenAI, who then confirmed that the specific internal Artifactory instance identified in the research has been commissioned. In other words, the hallways attack path has been closed.</p><p>The bad news is that this doesn’t automatically mean everyone’s safe. This particular path might be closed, but the architectural pattern behind the flaw could be present in other platforms, CPR warns. </p><p>“Any AI assistant that operates inside an organization’s trust boundary, holding credentials, running code, and reaching connected services, can become what Check Point Research calls a coerced insider,” the report states. “The model itself does not need to be malicious. It only needs to be persuaded, through text it was never meant to trust, to use access that was granted for entirely legitimate reasons.” </p><p>Going forward, businesses are advised to learn which AI tools their employees are using, and what those tools are connected to. Then, they should govern what AI tools and agents are allowed to do, treating all of their actions (not just output) as something that needs to be monitored. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google Chrome will now ship security updates every two weeks, thanks to AI ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Chrome will get new updates every two weeks to minimize real-world attacks</strong></li><li><strong>Smaller, incremental changes should also make it easier to track any issues</strong></li><li><strong>Other major browsers are also shifting to two-weekly release cycles</strong></li></ul><p>Google has <a href="https://developer.chrome.com/blog/chrome-two-week-start" target="_blank">confirmed</a> that Chrome has officially moved from a four-week Stable release cycle to a two-week one, with effect from September 8 2026 with the launch of Chrome 153.</p><p>Besides adding new features, the main objective is for Google to give us performance and security fixes more promptly in an era of increased complexity and heightened vulnerabilities.</p><p>And it's exactly those security concerns that pushed Google to want to double Chrome's update frequency in the first lace, with the company now having to deal with a higher volume of patches than ever before.</p><h2 id="chrome-will-get-updates-every-two-weeks">Chrome will get updates every two weeks</h2><p>Together with a higher volume of attacks in general, Google has also benefitted from AI-powered vulnerability discovery tools, giving developers more work to do than before. "With automated AI discovery tools and community bug reports generating higher patch volume, shorter release cycles make managing security fixes significantly simpler," the company wrote.</p><p>Crucially, the faster cycle reduces the time between a fix landing in Chrome's public codebase and it actually reaching end users, making it less likely for a bug to be exploited in the wild.</p><p>Chrome has been adhering to a four-week cycle since 2021, but the world is a very different place in the space of just half a decade.</p><p>With the higher pace of releases, Google also anticipates a smaller scope of changes, which could actually be a good thing because it could be easier for developers to identify what went wrong in the event of any issues.</p><p>Desktop, Android and iOS versions of Chrome will all be impacted by the change, with Chrome 154 already slated for a September 22 release.</p><p>More broadly, Google says Chrome isn't the only browser getting more frequent updates. Microsoft, Mozilla and Brave are also making similar changes, and they're all undergoing those changes right now.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/google-chrome-will-now-ship-security-updates-every-two-weeks-thanks-to-ai</link>
                                                                            <description>
                            <![CDATA[ Google Chrome is shifting to a two-weekly Stable release cycle after five years of four-weekly releases in the name of security. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">W64A6MU2RTMo593AtERgth</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZfhFwGtGeLFq7LEuTgCMbD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 10:00:49 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Chrome]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Browsers]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZfhFwGtGeLFq7LEuTgCMbD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Ink Drop]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Silhouette of a hand holding a padlock infront of the google chrome logo]]></media:description>                                                            <media:text><![CDATA[Silhouette of a hand holding a padlock infront of the google chrome logo]]></media:text>
                                <media:title type="plain"><![CDATA[Silhouette of a hand holding a padlock infront of the google chrome logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZfhFwGtGeLFq7LEuTgCMbD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Chrome will get new updates every two weeks to minimize real-world attacks</strong></li><li><strong>Smaller, incremental changes should also make it easier to track any issues</strong></li><li><strong>Other major browsers are also shifting to two-weekly release cycles</strong></li></ul><p>Google has <a href="https://developer.chrome.com/blog/chrome-two-week-start" target="_blank">confirmed</a> that Chrome has officially moved from a four-week Stable release cycle to a two-week one, with effect from September 8 2026 with the launch of Chrome 153.</p><p>Besides adding new features, the main objective is for Google to give us performance and security fixes more promptly in an era of increased complexity and heightened vulnerabilities.</p><p>And it's exactly those security concerns that pushed Google to want to double Chrome's update frequency in the first lace, with the company now having to deal with a higher volume of patches than ever before.</p><h2 id="chrome-will-get-updates-every-two-weeks">Chrome will get updates every two weeks</h2><p>Together with a higher volume of attacks in general, Google has also benefitted from AI-powered vulnerability discovery tools, giving developers more work to do than before. "With automated AI discovery tools and community bug reports generating higher patch volume, shorter release cycles make managing security fixes significantly simpler," the company wrote.</p><p>Crucially, the faster cycle reduces the time between a fix landing in Chrome's public codebase and it actually reaching end users, making it less likely for a bug to be exploited in the wild.</p><p>Chrome has been adhering to a four-week cycle since 2021, but the world is a very different place in the space of just half a decade.</p><p>With the higher pace of releases, Google also anticipates a smaller scope of changes, which could actually be a good thing because it could be easier for developers to identify what went wrong in the event of any issues.</p><p>Desktop, Android and iOS versions of Chrome will all be impacted by the change, with Chrome 154 already slated for a September 22 release.</p><p>More broadly, Google says Chrome isn't the only browser getting more frequent updates. Microsoft, Mozilla and Brave are also making similar changes, and they're all undergoing those changes right now.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI’s storage challenge is really an operational one ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Enterprise <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> has always adapted as scale increased. Virtualization tackled server sprawl, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud computing</a> reduced the need to provision physical resources for every application, and automation made increasingly complex environments manageable. Artificial intelligence presents a different kind of scaling problem.</p><p>The discussion around enterprise AI has largely centered on models, GPUs, and inference performance, but those technologies represent only a fraction of what organizations must operate. Every production AI deployment creates a continuous flow of data that must be ingested, protected, moved, analyzed, retained, governed, and eventually archived.</p><p>Those activities place demands on infrastructure that are very different from the workloads storage systems were originally designed to support. </p><p>This is becoming increasingly apparent as organizations move beyond pilot projects. AI is no longer a single workload running on isolated infrastructure. A single application may include high-speed <a href="https://www.techradar.com/best/best-cloud-storage&quot">storage</a> for model training, object storage for inference data, lower-cost capacity for operational datasets, immutable storage for cyber resilience, and long-term archives to satisfy regulatory requirements. </p><p>Traditionally, those functions have been handled by separate products with separate management tools, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> policies, and operational teams. That architecture worked reasonably well when data moved slowly and applications followed predictable lifecycles. AI changes both assumptions.</p><p>Training datasets expand continuously. New models are introduced far more frequently than traditional enterprise applications. Inference workloads fluctuate as demand changes. The same dataset may move repeatedly between active processing, backup, compliance, and archival over its lifetime.</p><p>Each transition introduces another operational task, another opportunity for inconsistency, and another point where administrators must intervene. Before long, the effort required to manage the infrastructure begins to rival the effort required to build the AI applications themselves.</p><h2 id="complexity-becomes-the-real-infrastructure-challenge">Complexity becomes the real infrastructure challenge</h2><p>For years, the answer to operational complexity was automation. Administrators automated provisioning, scripted maintenance, and orchestrated repetitive tasks. Those capabilities remain valuable, but they were designed to execute predefined actions under predefined conditions.</p><p>AI environments are considerably less predictable. Infrastructure must continually adapt to changing workloads, shifting performance requirements, evolving security policies, and rapidly growing data volumes, often without the benefit of stable operating patterns.</p><p>That is where autonomous data infrastructure represents something more substantial than another <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> framework. Rather than treating storage as a collection of independent systems, it starts with the assumption that the platform itself should continuously optimize how data is managed throughout its lifecycle. Capacity, performance, protection, and cost become policy decisions rather than infrastructure projects.</p><p>Data moves between performance tiers automatically according to business requirements instead of being exported, migrated, and re-imported into separate platforms. A single namespace spans workloads that historically required multiple storage systems, allowing infrastructure to evolve without repeatedly forcing administrators to redesign the environment. </p><p>That architectural change may ultimately prove more important than the automation itself. Many organizations underestimate how much operational complexity accumulates simply from running multiple storage platforms. Every environment has its own authentication model, monitoring tools, lifecycle policies, upgrade schedules, recovery procedures, and performance characteristics.</p><p>As AI expands across the enterprise, those management layers multiply alongside the data. Reducing the number of operational boundaries often creates greater long-term value than introducing another layer of orchestration.</p><p>The same principle applies to cyber resilience. AI has increased the value of enterprise data far beyond traditional business records. Training datasets, model checkpoints, vector indexes, and inference pipelines have become strategic assets in their own right. Protecting them requires more than backup software. It requires infrastructure that assumes failures and attacks will occur and is designed to recover without depending on manual intervention. </p><h2 id="governance-becomes-part-of-the-data-lifecycle">Governance becomes part of the data lifecycle</h2><p>The conversation also extends beyond security to control. As AI initiatives become more strategic, organizations are under growing pressure to understand where <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> resides, who can access it, and which legal and regulatory frameworks govern it.</p><p>That is especially true for enterprises operating across multiple countries or in highly regulated industries, where data residency requirements, digital sovereignty initiatives, and industry-specific compliance obligations increasingly influence infrastructure decisions.</p><p>Rather than treating these as separate governance exercises, modern infrastructure must make location, retention, and access policies part of the data lifecycle itself, enabling organizations to meet regulatory requirements without introducing additional operational complexity.</p><p>One of the more significant design decisions behind autonomous data infrastructure is that immutability exists within the storage engine itself rather than being implemented solely through administrative policy. Instead of modifying existing data in place, new versions are written separately while previous versions remain intact. </p><p>Combined with distributed self-healing that rebuilds only affected objects instead of entire disks, this creates a fundamentally different operational model for resilience. Recovery becomes part of normal system behavior instead of an exceptional event requiring administrators to coordinate lengthy repair efforts. </p><h2 id="infrastructure-operators-become-infrastructure-architects">Infrastructure operators become infrastructure architects</h2><p>Perhaps the most interesting implication has little to do with storage technology itself. Infrastructure teams are already responsible for environments that are growing faster than headcount, and AI is accelerating that imbalance. The objective is not to remove people from operations, but to reduce the amount of time highly skilled engineers spend on repetitive maintenance that adds little strategic value.</p><p>As more routine activities become policy-driven and continuously optimized, infrastructure professionals can devote more attention to architecture, governance, capacity planning, and aligning technology decisions with <a href="https://www.techradar.com/best/best-small-business-software">business</a> priorities.</p><p>That evolution mirrors what is happening across software engineering, networking, and cybersecurity. AI is steadily shifting human expertise away from repetitive execution and toward system design, governance, and strategic decision-making. Autonomous data infrastructure reflects the same progression.</p><p>Rather than asking administrators to manage an ever-growing collection of storage products, it treats the infrastructure as an adaptive system that operates within policies established by the people responsible for it. The most effective approach is not to take humans out of the loop, but to keep them in control of the decisions that shape security, compliance, and business outcomes while allowing the platform to execute routine operational tasks autonomously. </p><p>Viewed from that perspective, autonomous data infrastructure is less about storage than it is about preparing enterprise IT for the next decade. AI has exposed the limitations of architectures built around isolated products, manual coordination, and steadily increasing operational overhead.</p><p>Organizations will continue investing in faster <a href="https://www.techradar.com/news/computing-components/graphics-cards/best-graphics-cards-1291458">GPUs</a> and more capable models, but those investments will deliver their greatest value only if the infrastructure beneath them becomes equally capable of managing complexity. The next generation of enterprise infrastructure will not simply store data more efficiently. It will actively participate in operating the environments that modern AI depends upon.</p><p><em></em><a href="https://www.techradar.com/best/best-bi-tools"><em>We've featured the best business intelligence platform.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ais-storage-challenge-is-really-an-operational-one</link>
                                                                            <description>
                            <![CDATA[ Why operational complexity, not storage capacity, is becoming AI's biggest infrastructure challenge. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zcAfyrCDHcUaYqAa2s9YFM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 09:45:20 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Billy Cashwell ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A line of robots typing at computers]]></media:description>                                                            <media:text><![CDATA[A line of robots typing at computers]]></media:text>
                                <media:title type="plain"><![CDATA[A line of robots typing at computers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Enterprise <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> has always adapted as scale increased. Virtualization tackled server sprawl, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud computing</a> reduced the need to provision physical resources for every application, and automation made increasingly complex environments manageable. Artificial intelligence presents a different kind of scaling problem.</p><p>The discussion around enterprise AI has largely centered on models, GPUs, and inference performance, but those technologies represent only a fraction of what organizations must operate. Every production AI deployment creates a continuous flow of data that must be ingested, protected, moved, analyzed, retained, governed, and eventually archived.</p><p>Those activities place demands on infrastructure that are very different from the workloads storage systems were originally designed to support. </p><p>This is becoming increasingly apparent as organizations move beyond pilot projects. AI is no longer a single workload running on isolated infrastructure. A single application may include high-speed <a href="https://www.techradar.com/best/best-cloud-storage&quot">storage</a> for model training, object storage for inference data, lower-cost capacity for operational datasets, immutable storage for cyber resilience, and long-term archives to satisfy regulatory requirements. </p><p>Traditionally, those functions have been handled by separate products with separate management tools, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> policies, and operational teams. That architecture worked reasonably well when data moved slowly and applications followed predictable lifecycles. AI changes both assumptions.</p><p>Training datasets expand continuously. New models are introduced far more frequently than traditional enterprise applications. Inference workloads fluctuate as demand changes. The same dataset may move repeatedly between active processing, backup, compliance, and archival over its lifetime.</p><p>Each transition introduces another operational task, another opportunity for inconsistency, and another point where administrators must intervene. Before long, the effort required to manage the infrastructure begins to rival the effort required to build the AI applications themselves.</p><h2 id="complexity-becomes-the-real-infrastructure-challenge">Complexity becomes the real infrastructure challenge</h2><p>For years, the answer to operational complexity was automation. Administrators automated provisioning, scripted maintenance, and orchestrated repetitive tasks. Those capabilities remain valuable, but they were designed to execute predefined actions under predefined conditions.</p><p>AI environments are considerably less predictable. Infrastructure must continually adapt to changing workloads, shifting performance requirements, evolving security policies, and rapidly growing data volumes, often without the benefit of stable operating patterns.</p><p>That is where autonomous data infrastructure represents something more substantial than another <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> framework. Rather than treating storage as a collection of independent systems, it starts with the assumption that the platform itself should continuously optimize how data is managed throughout its lifecycle. Capacity, performance, protection, and cost become policy decisions rather than infrastructure projects.</p><p>Data moves between performance tiers automatically according to business requirements instead of being exported, migrated, and re-imported into separate platforms. A single namespace spans workloads that historically required multiple storage systems, allowing infrastructure to evolve without repeatedly forcing administrators to redesign the environment. </p><p>That architectural change may ultimately prove more important than the automation itself. Many organizations underestimate how much operational complexity accumulates simply from running multiple storage platforms. Every environment has its own authentication model, monitoring tools, lifecycle policies, upgrade schedules, recovery procedures, and performance characteristics.</p><p>As AI expands across the enterprise, those management layers multiply alongside the data. Reducing the number of operational boundaries often creates greater long-term value than introducing another layer of orchestration.</p><p>The same principle applies to cyber resilience. AI has increased the value of enterprise data far beyond traditional business records. Training datasets, model checkpoints, vector indexes, and inference pipelines have become strategic assets in their own right. Protecting them requires more than backup software. It requires infrastructure that assumes failures and attacks will occur and is designed to recover without depending on manual intervention. </p><h2 id="governance-becomes-part-of-the-data-lifecycle">Governance becomes part of the data lifecycle</h2><p>The conversation also extends beyond security to control. As AI initiatives become more strategic, organizations are under growing pressure to understand where <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> resides, who can access it, and which legal and regulatory frameworks govern it.</p><p>That is especially true for enterprises operating across multiple countries or in highly regulated industries, where data residency requirements, digital sovereignty initiatives, and industry-specific compliance obligations increasingly influence infrastructure decisions.</p><p>Rather than treating these as separate governance exercises, modern infrastructure must make location, retention, and access policies part of the data lifecycle itself, enabling organizations to meet regulatory requirements without introducing additional operational complexity.</p><p>One of the more significant design decisions behind autonomous data infrastructure is that immutability exists within the storage engine itself rather than being implemented solely through administrative policy. Instead of modifying existing data in place, new versions are written separately while previous versions remain intact. </p><p>Combined with distributed self-healing that rebuilds only affected objects instead of entire disks, this creates a fundamentally different operational model for resilience. Recovery becomes part of normal system behavior instead of an exceptional event requiring administrators to coordinate lengthy repair efforts. </p><h2 id="infrastructure-operators-become-infrastructure-architects">Infrastructure operators become infrastructure architects</h2><p>Perhaps the most interesting implication has little to do with storage technology itself. Infrastructure teams are already responsible for environments that are growing faster than headcount, and AI is accelerating that imbalance. The objective is not to remove people from operations, but to reduce the amount of time highly skilled engineers spend on repetitive maintenance that adds little strategic value.</p><p>As more routine activities become policy-driven and continuously optimized, infrastructure professionals can devote more attention to architecture, governance, capacity planning, and aligning technology decisions with <a href="https://www.techradar.com/best/best-small-business-software">business</a> priorities.</p><p>That evolution mirrors what is happening across software engineering, networking, and cybersecurity. AI is steadily shifting human expertise away from repetitive execution and toward system design, governance, and strategic decision-making. Autonomous data infrastructure reflects the same progression.</p><p>Rather than asking administrators to manage an ever-growing collection of storage products, it treats the infrastructure as an adaptive system that operates within policies established by the people responsible for it. The most effective approach is not to take humans out of the loop, but to keep them in control of the decisions that shape security, compliance, and business outcomes while allowing the platform to execute routine operational tasks autonomously. </p><p>Viewed from that perspective, autonomous data infrastructure is less about storage than it is about preparing enterprise IT for the next decade. AI has exposed the limitations of architectures built around isolated products, manual coordination, and steadily increasing operational overhead.</p><p>Organizations will continue investing in faster <a href="https://www.techradar.com/news/computing-components/graphics-cards/best-graphics-cards-1291458">GPUs</a> and more capable models, but those investments will deliver their greatest value only if the infrastructure beneath them becomes equally capable of managing complexity. The next generation of enterprise infrastructure will not simply store data more efficiently. It will actively participate in operating the environments that modern AI depends upon.</p><p><em></em><a href="https://www.techradar.com/best/best-bi-tools"><em>We've featured the best business intelligence platform.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Massive data breach sees 220 million traveler records exposed — nine years of airline info leaked including passenger and passport details ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Kinryū Labs found misconfigured APIS database in Vietnam exposing 220M passenger and crew records</strong></li><li><strong>Data included PII, travel details, seat assignments, and baggage references from 2017–2026</strong></li><li><strong>Archive locked and there is no evidence yet of dark web sale</strong></li></ul><p>Millions of travellers have had their sensitive information exposed on the internet, thanks to a “series of misconfigurations” discovered in a cloud database, experts have warned.</p><p>In early June 2026, security researchers from Kinryū Labs discovered an Elasticsearch cluster which, although inaccessible from the open internet, allowed access through an alternate route - a cloud-based path. Once inside that route, the researchers discovered that the cluster accepted default credentials, granting access to an archive with 29 indices, weighing roughly 107GB.</p><p>The archive was apparently generated by an Advance Passenger Information System (APIS), a system airlines use to collect and send passenger and crew information to country authorities before flight arrival or departure. Usually, the system collects people’s names, birth dates, nationalities, passport and travel document numbers, and flight details, which are then used for border control, immigration, and similar cases. In this case, however, it also contained people’s sex, document expiration dates, issuing countries, airlines, departure, destination and transit airports, seat assignments, baggage reference, and more.</p><p>It is not known who operated the APIS, or who owns and runs the database. All the researchers managed to find is that it was hosted in Viettel-assigned IP space in Hanoi, Vietnam’s capital.</p><h2 id="who-was-affected">Who was affected?</h2><p>Of the 29 discovered indices, two were rather large: one contained 210,318, 069 passenger records, while another 10,465,631 crew records. In total, 220 million records, created between January 2017 and April 2026, from people who traveled to, from, or through Vietnam during that period.</p><p>The records don’t correspond to individuals, however. If a person travelled multiple times, they will show up in the archive multiple times. Canadians, Chinese, Korean, and New Zealandian nationals are among the ones whose information was exposed. The database is not limited to a specific airline, either - various airlines in Asia-Pacific, Europe, and Middle East regions were mentioned in the researchers’ report.</p><p>Since the researchers could not attribute the database to a specific entity, they reported it to the Vietnamese authorities, different airlines mentioned in the archives, and the country’s CERT (Computer Emergency Response Team), on June 3. The archive was locked down a week later, on June 8. According to BleepingComputer, it was the Singapore Airlines’ security team that took the lead on remediation efforts, telling the researchers they “engaged the relevant parties” and have “taken steps to contain the issue.”</p><p>Without a proper audit of the logs, and a full-blown forensic investigation, it is impossible to tell if any threat actors reached the database before the researchers, or if they exfiltrated and used the data found inside in identity theft, wire fraud, or other scams. What’s (somewhat) comforting is that there is no evidence of such activities on the dark web, and no hacking groups have made such claims. No one is selling the archive on the dark web, either.</p><h2 id="number-one-causes-of-data-spills">Number one causes of data spills </h2><p>Misconfigured databases remain one of the key causes of data leaks. Most businesses generate some type of data on their employees, partners, clients, or customers, and store it in the <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud</a> for easy access and actionable insights. However, some businesses don’t understand the shared responsibility model of cloud security or are simply reckless and sloppy when it comes to securing their cloud-stored data. Others, according to Cassius Edison, COO of Closed Door Security, have a problem with visibility of their IT real estate:</p><p>“The range of technology now used and managed by firms globally has made misconfigurations an increasingly persistent problem,” Edison explained. “Many organizations fail to maintain full visibility of their IT real estate and fail to perform proper audits of their systems, which inevitably leads to oversights in security and monitoring.”</p><p>For Edison, tackling misconfigurations internally can be difficult, “especially at large companies where teams work independently across a range of systems,” and advises organizations to bring in independent pentesters and security auditors. </p><p>Some of the biggest data leaks in the world came not from hackers breaking into locked-down systems, but from businesses inadvertently exposing their customers. </p><p>In 2026 alone, we’ve seen more than 670 million identity records exposed by Infutor, a data-driven consumer identity management company, as well as more than three billion records exposed through a misconfigured MongoDB database managed by global identity verification services, IDMerit.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/massive-data-breach-sees-220-million-traveler-records-exposed-nine-years-of-airline-info-leaked-including-passenger-and-passport-details</link>
                                                                            <description>
                            <![CDATA[ A series of misconfigurations allowed researchers to access a treasure trove of sensitive data - the archive has since been locked down. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8uHcVN224Fk6zmJ3KTpaSE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 20:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:description>                                                            <media:text><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:text>
                                <media:title type="plain"><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kinryū Labs found misconfigured APIS database in Vietnam exposing 220M passenger and crew records</strong></li><li><strong>Data included PII, travel details, seat assignments, and baggage references from 2017–2026</strong></li><li><strong>Archive locked and there is no evidence yet of dark web sale</strong></li></ul><p>Millions of travellers have had their sensitive information exposed on the internet, thanks to a “series of misconfigurations” discovered in a cloud database, experts have warned.</p><p>In early June 2026, security researchers from Kinryū Labs discovered an Elasticsearch cluster which, although inaccessible from the open internet, allowed access through an alternate route - a cloud-based path. Once inside that route, the researchers discovered that the cluster accepted default credentials, granting access to an archive with 29 indices, weighing roughly 107GB.</p><p>The archive was apparently generated by an Advance Passenger Information System (APIS), a system airlines use to collect and send passenger and crew information to country authorities before flight arrival or departure. Usually, the system collects people’s names, birth dates, nationalities, passport and travel document numbers, and flight details, which are then used for border control, immigration, and similar cases. In this case, however, it also contained people’s sex, document expiration dates, issuing countries, airlines, departure, destination and transit airports, seat assignments, baggage reference, and more.</p><p>It is not known who operated the APIS, or who owns and runs the database. All the researchers managed to find is that it was hosted in Viettel-assigned IP space in Hanoi, Vietnam’s capital.</p><h2 id="who-was-affected">Who was affected?</h2><p>Of the 29 discovered indices, two were rather large: one contained 210,318, 069 passenger records, while another 10,465,631 crew records. In total, 220 million records, created between January 2017 and April 2026, from people who traveled to, from, or through Vietnam during that period.</p><p>The records don’t correspond to individuals, however. If a person travelled multiple times, they will show up in the archive multiple times. Canadians, Chinese, Korean, and New Zealandian nationals are among the ones whose information was exposed. The database is not limited to a specific airline, either - various airlines in Asia-Pacific, Europe, and Middle East regions were mentioned in the researchers’ report.</p><p>Since the researchers could not attribute the database to a specific entity, they reported it to the Vietnamese authorities, different airlines mentioned in the archives, and the country’s CERT (Computer Emergency Response Team), on June 3. The archive was locked down a week later, on June 8. According to BleepingComputer, it was the Singapore Airlines’ security team that took the lead on remediation efforts, telling the researchers they “engaged the relevant parties” and have “taken steps to contain the issue.”</p><p>Without a proper audit of the logs, and a full-blown forensic investigation, it is impossible to tell if any threat actors reached the database before the researchers, or if they exfiltrated and used the data found inside in identity theft, wire fraud, or other scams. What’s (somewhat) comforting is that there is no evidence of such activities on the dark web, and no hacking groups have made such claims. No one is selling the archive on the dark web, either.</p><h2 id="number-one-causes-of-data-spills">Number one causes of data spills </h2><p>Misconfigured databases remain one of the key causes of data leaks. Most businesses generate some type of data on their employees, partners, clients, or customers, and store it in the <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud</a> for easy access and actionable insights. However, some businesses don’t understand the shared responsibility model of cloud security or are simply reckless and sloppy when it comes to securing their cloud-stored data. Others, according to Cassius Edison, COO of Closed Door Security, have a problem with visibility of their IT real estate:</p><p>“The range of technology now used and managed by firms globally has made misconfigurations an increasingly persistent problem,” Edison explained. “Many organizations fail to maintain full visibility of their IT real estate and fail to perform proper audits of their systems, which inevitably leads to oversights in security and monitoring.”</p><p>For Edison, tackling misconfigurations internally can be difficult, “especially at large companies where teams work independently across a range of systems,” and advises organizations to bring in independent pentesters and security auditors. </p><p>Some of the biggest data leaks in the world came not from hackers breaking into locked-down systems, but from businesses inadvertently exposing their customers. </p><p>In 2026 alone, we’ve seen more than 670 million identity records exposed by Infutor, a data-driven consumer identity management company, as well as more than three billion records exposed through a misconfigured MongoDB database managed by global identity verification services, IDMerit.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Liquid Network halts new transactions after 'nice guy' hackers steal nearly all its Bitcoin — but then return most of it after a patch is issued ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Liquid Network hack exploited a bug in SideSwap, releasing 3,998 BTC (~$313M) to attackers</strong></li><li><strong>Hackers claimed “white‑hat” intent, returning 3,400 BTC after fixes, leaving 598 BTC missing</strong></li><li><strong>Network remains paused as Blockstream and Federation patch vulnerabilities and prepare safe restart</strong></li></ul><p>The latest twist in the Liquid Network Bitcoin hack is worthy of a short movie, if not a full-length feature film. </p><p>Apparently, the hackers are actually the good guys, who stole the money to “keep it safe” until a vulnerability in the protocol had been fully resolved. They promised to return the funds afterwards.</p><h2 id="what-is-liquid-network">What is Liquid Network?</h2><p>Liquid Network was designed to solve a specific problem on the Bitcoin blockchain - being rather slow. The transactions on the network are recorded in a “block”, which is added to the chain roughly once every 10 minutes. Also, each block can only hold a limited number of transactions, which means the network can handle a smaller number of transactions per second, compared to conventional payment systems. Transactions that don’t make it into a specific block then need to wait for the next one, thus extending the confirmation time.</p><p>To solve that problem, Liquid Network was built. It runs its own Bitcoin reserve and its own blockchain, also known as a “sidechain”. When a person wants to use Liquid Network to send money quickly, they first convert their Bitcoin into Liquid Bitcoin, or L-BTC. They can then send it to another person much faster than a regular Bitcoin transaction. The recipient can keep the money on Liquid or convert it back to regular Bitcoin and move it to the Bitcoin network. </p><p>This way, Liquid provides a faster network without requiring every transaction to happen directly on the Bitcoin blockchain.</p><p>Besides speeding up Bitcoin transactions, Liquid Network also allows users (companies and other entities) to create and trade other digital assets, including tokenized securities, or stablecoins.</p><p>The project was built by Blockstream, a Bitcoin-focused technology company founded in 2014. It is run by the Liquid Federation, a group of more than 80 member companies, including exchanges, infrastructure companies, and financial institutions. A smaller group of members (15 to be exact) operate the network’s “functionaries” (servers that keep the network running), while the wider group has a governance role. Members vote on three boards (Technology, Membership, Oversight), handling ideas such as technical direction, internal rules, memberships, and more. </p><h2 id="what-happened-to-it">What happened to it?</h2><p>In early September 2026, still unidentified actors managed to generate around 4,000 L-BTC, without putting in the corresponding 4,000 BTC into Liquid. As soon as they did it, they sent the L-BTC through SideSwap, a legitimate service that is used to convert L-BTC back to Bitcoin and vice-versa. The system apparently regarded the withdrawal as legitimate because, as was later determined, a bug prevented SideSwap from distinguishing between “real” and “fake” L-BTC, and treated them all the same.</p><p>As a result, the Liquid Federation ended up releasing 3,998 real BTC (more than $313 million at press time) to the attackers. As soon as the operators realized what had happened, they halted new transactions and warned about possible disruptions until the service was restored. </p><p>Then came the movie twist: the hacker started communicating with network maintainers through on-chain Bitcoin transactions, promising to return the funds when the vulnerability is fully resolved:</p><p>“Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix,” one of the messages read.</p><p>Earlier today, Coindesk reported that the hackers partially kept their promise, returning 3,400 of the 4,000 BTC drained, which suggests that the flaw was remedied. The remaining 598 BTC, worth approximately $47 million, is currently unaccounted for. </p><p>“3,400 BTC of the roughly 4,000 BTC withdrawn on September 6 has been returned to the Liquid Federation wallet. The return followed confirmation from Blockstream that the affected bridge nodes have been patched,” wrote Samson Mow, former chief strategy officer at Blockstream, on X. “Approximately 598 BTC remains outstanding, and Blockstream continues to engage with the white-hat hackers.”</p><p>He added that the network remains paused while Blockstream and Federation members make additional fixes and security improvements, resolve the chain split, and prepare for a safe restart. </p><p>“Liquid <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">wallets</a> and services will continue to be affected during this time. No user action is needed, and please do not send Bitcoin to Liquid peg-in addresses until we confirm the network has restarted,” he added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/liquid-network-halts-new-transactions-after-nice-guy-hackers-steal-nearly-all-its-bitcoin-but-then-return-most-of-it-after-a-patch-is-issued</link>
                                                                            <description>
                            <![CDATA[ Liquid Network is still disrupted, but users can breathe a sigh of relief as most of the stolen funds have been returned. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oguXoFVDTGkmgxvQsQBpU3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UweTPZX99rMmYJQoBvPT44-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UweTPZX99rMmYJQoBvPT44-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Bitcoin]]></media:description>                                                            <media:text><![CDATA[Bitcoin]]></media:text>
                                <media:title type="plain"><![CDATA[Bitcoin]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UweTPZX99rMmYJQoBvPT44-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Liquid Network hack exploited a bug in SideSwap, releasing 3,998 BTC (~$313M) to attackers</strong></li><li><strong>Hackers claimed “white‑hat” intent, returning 3,400 BTC after fixes, leaving 598 BTC missing</strong></li><li><strong>Network remains paused as Blockstream and Federation patch vulnerabilities and prepare safe restart</strong></li></ul><p>The latest twist in the Liquid Network Bitcoin hack is worthy of a short movie, if not a full-length feature film. </p><p>Apparently, the hackers are actually the good guys, who stole the money to “keep it safe” until a vulnerability in the protocol had been fully resolved. They promised to return the funds afterwards.</p><h2 id="what-is-liquid-network">What is Liquid Network?</h2><p>Liquid Network was designed to solve a specific problem on the Bitcoin blockchain - being rather slow. The transactions on the network are recorded in a “block”, which is added to the chain roughly once every 10 minutes. Also, each block can only hold a limited number of transactions, which means the network can handle a smaller number of transactions per second, compared to conventional payment systems. Transactions that don’t make it into a specific block then need to wait for the next one, thus extending the confirmation time.</p><p>To solve that problem, Liquid Network was built. It runs its own Bitcoin reserve and its own blockchain, also known as a “sidechain”. When a person wants to use Liquid Network to send money quickly, they first convert their Bitcoin into Liquid Bitcoin, or L-BTC. They can then send it to another person much faster than a regular Bitcoin transaction. The recipient can keep the money on Liquid or convert it back to regular Bitcoin and move it to the Bitcoin network. </p><p>This way, Liquid provides a faster network without requiring every transaction to happen directly on the Bitcoin blockchain.</p><p>Besides speeding up Bitcoin transactions, Liquid Network also allows users (companies and other entities) to create and trade other digital assets, including tokenized securities, or stablecoins.</p><p>The project was built by Blockstream, a Bitcoin-focused technology company founded in 2014. It is run by the Liquid Federation, a group of more than 80 member companies, including exchanges, infrastructure companies, and financial institutions. A smaller group of members (15 to be exact) operate the network’s “functionaries” (servers that keep the network running), while the wider group has a governance role. Members vote on three boards (Technology, Membership, Oversight), handling ideas such as technical direction, internal rules, memberships, and more. </p><h2 id="what-happened-to-it">What happened to it?</h2><p>In early September 2026, still unidentified actors managed to generate around 4,000 L-BTC, without putting in the corresponding 4,000 BTC into Liquid. As soon as they did it, they sent the L-BTC through SideSwap, a legitimate service that is used to convert L-BTC back to Bitcoin and vice-versa. The system apparently regarded the withdrawal as legitimate because, as was later determined, a bug prevented SideSwap from distinguishing between “real” and “fake” L-BTC, and treated them all the same.</p><p>As a result, the Liquid Federation ended up releasing 3,998 real BTC (more than $313 million at press time) to the attackers. As soon as the operators realized what had happened, they halted new transactions and warned about possible disruptions until the service was restored. </p><p>Then came the movie twist: the hacker started communicating with network maintainers through on-chain Bitcoin transactions, promising to return the funds when the vulnerability is fully resolved:</p><p>“Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix,” one of the messages read.</p><p>Earlier today, Coindesk reported that the hackers partially kept their promise, returning 3,400 of the 4,000 BTC drained, which suggests that the flaw was remedied. The remaining 598 BTC, worth approximately $47 million, is currently unaccounted for. </p><p>“3,400 BTC of the roughly 4,000 BTC withdrawn on September 6 has been returned to the Liquid Federation wallet. The return followed confirmation from Blockstream that the affected bridge nodes have been patched,” wrote Samson Mow, former chief strategy officer at Blockstream, on X. “Approximately 598 BTC remains outstanding, and Blockstream continues to engage with the white-hat hackers.”</p><p>He added that the network remains paused while Blockstream and Federation members make additional fixes and security improvements, resolve the chain split, and prepare for a safe restart. </p><p>“Liquid <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">wallets</a> and services will continue to be affected during this time. No user action is needed, and please do not send Bitcoin to Liquid peg-in addresses until we confirm the network has restarted,” he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft 365 users hit by two major threat campaigns - fake IT calls and phishing emails target users across the world ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft 365 users targeted by phishing campaigns using BigBear 2.0 and AiTM proxies</strong></li><li><strong>Attackers impersonate IT staff via calls, Teams, and email to steal credentials and bypass MFA</strong></li><li><strong>CloudSEK tracked 5,000+ stolen records; Arctic Wolf urges phishing‑resistant MFA and conditional access</strong></li></ul><p>Microsoft 365 users are facing a barrage of cyberattacks all aimed at a single goal - to try and expose credentials which can later be used against employers in data theft attacks.</p><p>Different groups conduct their raids and bypass multi-factor authentication (MFA) protection to access victim accounts - CloudSEK, for example, said that some groups are using BigBear 2.0, a new phishing-as-a-service (PhaaS) framework that allows crooks to intercept passwords and authenticated session cookies.</p><p>Arctic Wolf, on the other hand, focused on a single threat actor, which it dubbed PREY-0058. This group, despite significant overlaps with other collectives in terms of techniques, technologies, and procedures, is not a rebrand of older organizations. Instead, the researchers believe the lines between the groups are blurred and that there is a large group of affiliates, splinter crews, and other cohorts using the same phishing infrastructure and thus often confuse defenders and analysts.</p><h2 id="similar-methods-similar-results">Similar methods, similar results</h2><p>The attack methodology is similar across the spectrum. Crooks would call their victims on the phone or approach them via Teams and email. They would introduce themselves as members of the IT help desk sent to sort out a specific problem or issue. </p><p>Then, they would either convince the victim to grant remote access, or to open a spoofed Microsoft 365 login page and enter their credentials there. In both cases, the goal is the same - to get the victim to type in their username, password, and 2FA code, on a fake site built by BigBear 2.0 or a similar phishing framework. This framework, using an attacker-in-the-middle (AiTM) proxy between the victim and legitimate Microsoft infrastructure, harvests credentials, <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA codes</a>, and session cookies, and replays them through an API essentially hijacking a legitimate authentication session.</p><p>Once they gain access, the attackers can do all sorts of things, but they are mostly focused on exfiltrating sensitive data from Outlook, Teams, SharePoint, and OneDrive. Deploying <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> is rarely seen. </p><p>The campaign CloudSEK has been tracking has been rather successful, the researchers argue, saying BigBear 2.0 was used to exfiltrate more than 5,000 credential records, “including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies - affecting 3,331 unique victim IPs across 40+ countries with the operation still active at the time of writing.” </p><p>“The multi-user PhaaS panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots, each receiving stolen credentials in real time.”</p><p>Speaking to <a href="https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/" target="_blank"><em>BleepingComputer</em></a>, CloudSEK says the campaign targeted 461 organizations, out of which 258 have had at least one set of credentials compromised. </p><h2 id="defending-with-phishing-resistant-mfa">Defending with phishing-resistant MFA</h2><p>Arctic Wolf’s researchers stressed that the attackers are focused primarily on US-based businesses: construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services, <a href="https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html" target="_blank"><em>The Hacker News</em></a> reported. The researchers advise organizations to implement Conditional Access policies, deploy phishing-resistant MFA, and restrict the scope of data users can access via SharePoint. Obviously, employee education on the dangers of phishing cannot be understated.</p><p>"Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure," Arctic Wolf said.</p><p>Phishing-resistant MFA is multi-factor authentication designed so that an attacker cannot trick a person into handing over authorization code, either via a message, or through a fake login page. </p><p>These include products such as passkeys, YubiKeys <a href="https://www.techradar.com/best/best-security-key" target="_blank">security keys</a>, and authentication methods based on FIDO2/WebAuthn. Since phishing-resistant MFA cryptographically ties the authentication to the legitimate website, the authentication cannot simply be forwarded to an attacker.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsoft-365-users-hit-by-two-major-threat-campaigns-fake-it-calls-and-phishing-emails-target-users-across-the-world</link>
                                                                            <description>
                            <![CDATA[ BigBear 2.0 and PREY-0058 are wreaking havoc across businesses as they scam employees into handing over login credentials and MFA codes. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C6BxVw2HaDLYXxNeeyT4HQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vnpBJPCcs2siQw5rCEsDzG-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 15:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/vnpBJPCcs2siQw5rCEsDzG-1280-80.png">
                                                            <media:credit><![CDATA[Currys]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft 365]]></media:description>                                                            <media:text><![CDATA[Microsoft 365]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft 365]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vnpBJPCcs2siQw5rCEsDzG-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft 365 users targeted by phishing campaigns using BigBear 2.0 and AiTM proxies</strong></li><li><strong>Attackers impersonate IT staff via calls, Teams, and email to steal credentials and bypass MFA</strong></li><li><strong>CloudSEK tracked 5,000+ stolen records; Arctic Wolf urges phishing‑resistant MFA and conditional access</strong></li></ul><p>Microsoft 365 users are facing a barrage of cyberattacks all aimed at a single goal - to try and expose credentials which can later be used against employers in data theft attacks.</p><p>Different groups conduct their raids and bypass multi-factor authentication (MFA) protection to access victim accounts - CloudSEK, for example, said that some groups are using BigBear 2.0, a new phishing-as-a-service (PhaaS) framework that allows crooks to intercept passwords and authenticated session cookies.</p><p>Arctic Wolf, on the other hand, focused on a single threat actor, which it dubbed PREY-0058. This group, despite significant overlaps with other collectives in terms of techniques, technologies, and procedures, is not a rebrand of older organizations. Instead, the researchers believe the lines between the groups are blurred and that there is a large group of affiliates, splinter crews, and other cohorts using the same phishing infrastructure and thus often confuse defenders and analysts.</p><h2 id="similar-methods-similar-results">Similar methods, similar results</h2><p>The attack methodology is similar across the spectrum. Crooks would call their victims on the phone or approach them via Teams and email. They would introduce themselves as members of the IT help desk sent to sort out a specific problem or issue. </p><p>Then, they would either convince the victim to grant remote access, or to open a spoofed Microsoft 365 login page and enter their credentials there. In both cases, the goal is the same - to get the victim to type in their username, password, and 2FA code, on a fake site built by BigBear 2.0 or a similar phishing framework. This framework, using an attacker-in-the-middle (AiTM) proxy between the victim and legitimate Microsoft infrastructure, harvests credentials, <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA codes</a>, and session cookies, and replays them through an API essentially hijacking a legitimate authentication session.</p><p>Once they gain access, the attackers can do all sorts of things, but they are mostly focused on exfiltrating sensitive data from Outlook, Teams, SharePoint, and OneDrive. Deploying <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> is rarely seen. </p><p>The campaign CloudSEK has been tracking has been rather successful, the researchers argue, saying BigBear 2.0 was used to exfiltrate more than 5,000 credential records, “including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies - affecting 3,331 unique victim IPs across 40+ countries with the operation still active at the time of writing.” </p><p>“The multi-user PhaaS panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots, each receiving stolen credentials in real time.”</p><p>Speaking to <a href="https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/" target="_blank"><em>BleepingComputer</em></a>, CloudSEK says the campaign targeted 461 organizations, out of which 258 have had at least one set of credentials compromised. </p><h2 id="defending-with-phishing-resistant-mfa">Defending with phishing-resistant MFA</h2><p>Arctic Wolf’s researchers stressed that the attackers are focused primarily on US-based businesses: construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services, <a href="https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html" target="_blank"><em>The Hacker News</em></a> reported. The researchers advise organizations to implement Conditional Access policies, deploy phishing-resistant MFA, and restrict the scope of data users can access via SharePoint. Obviously, employee education on the dangers of phishing cannot be understated.</p><p>"Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure," Arctic Wolf said.</p><p>Phishing-resistant MFA is multi-factor authentication designed so that an attacker cannot trick a person into handing over authorization code, either via a message, or through a fake login page. </p><p>These include products such as passkeys, YubiKeys <a href="https://www.techradar.com/best/best-security-key" target="_blank">security keys</a>, and authentication methods based on FIDO2/WebAuthn. Since phishing-resistant MFA cryptographically ties the authentication to the legitimate website, the authentication cannot simply be forwarded to an attacker.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Introducing AI-as-a-Service ]]></title>
                                                                                                <dc:content><![CDATA[ <p>2025 was a transformative year for <a href="https://www.techradar.com/best/best-ai-tools">artificial intelligence</a>, and 2026 is already proving to be equally significant. </p><p>While generative AI dominated conversations just a few years ago, the focus is now shifting towards agentic AI, where intelligent systems can take action, interact with business processes, and support employees in more meaningful ways.</p><p>As these capabilities continue to evolve, organizations are looking for better ways to connect AI systems to the applications, data and services that drive their operations. </p><p>This is where technologies such as Model Context Protocol (MCP) are becoming increasingly important. </p><p>Rather than creating bespoke integrations for every tool or system, MCP provides a standardized way for AI models and agents to access information and perform actions across an organization's technology estate.</p><p>While MCP is not a requirement for every AI implementation today, it represents a natural next step for organizations looking to move beyond isolated AI use cases and towards more integrated, scalable AI ecosystems.</p><p>However, greater integration also introduces greater responsibility. Effective governance remains essential for any AI deployment, but it becomes even more critical when autonomous agents are granted access to business systems, processes and sensitive information. </p><p>Organizations must establish clear guardrails that define what agents can access, what actions they can perform, and how their activities are monitored. Without appropriate oversight, businesses risk agents operating beyond their intended scope or creating unintended consequences across interconnected systems.</p><h2 id="the-impact-on-software-as-a-service">The impact on Software-as-a-Service</h2><p>Few sectors will feel the effects of this shift more than Software-as-a-Service (SaaS).</p><p>For years, SaaS applications have been built around human interaction. Users access platforms through dashboards and interfaces, navigate predefined workflows, and manually complete tasks. The application itself serves as the primary workspace where work is performed.</p><p>Agentic AI introduces a different model.</p><p>Rather than navigating <a href="https://www.techradar.com/best/best-small-business-software">software</a> in the same way a person would, agents can interact directly with APIs, services and data sources. This allows them to retrieve information, execute actions and orchestrate processes across multiple systems without relying on traditional user journeys.</p><p>That does not mean SaaS applications will disappear. In fact, they will continue to play a critical role in storing structured data, enforcing business rules and managing workflows. What is likely to change is how those applications are consumed.</p><p>Instead of being the primary destination where work happens, many SaaS platforms will increasingly act as sources of capability and information that AI agents can utilize on behalf of users. As a result, organizations may find themselves focusing less on which <a href="https://www.techradar.com/best/best-mobile-app-development-software">application</a> employees need to access and more on how services and data can be brought together to achieve the desired business outcome.</p><p>Human interfaces will still matter. Users will continue to need visibility, exception handling and control mechanisms, particularly when business-critical processes are involved. The challenge for software providers will be balancing traditional user experiences with new AI-driven interaction models while maintaining compatibility, reliability and operational resilience.</p><h2 id="breaking-down-agent-silos">Breaking down agent silos</h2><p>The next stage in the evolution of agentic AI is not simply creating more agents. It is enabling agents to work together effectively.</p><p>Many organizations already struggle with fragmented systems, disconnected data and isolated processes. Without careful planning, agents risk creating a new generation of silos, each operating within its own limited context and producing inconsistent outcomes.</p><p>To avoid this, businesses must focus on shared context, connected data and interoperable services. The goal is not to have individual agents automating isolated tasks but to enable multiple agents to contribute towards broader business objectives across entire processes.</p><p>When agents can access consistent information and operate across organizational boundaries, the value shifts from discrete task automation to coordinated execution. Rather than supporting an individual stage of a workflow, agents can participate in end-to-end processes while remaining aligned to business policies, operational requirements and organizational goals.</p><p>This represents an important architectural shift. Software increasingly becomes something that agents consume programmatically, while integration, context and orchestration become central to delivering outcomes at scale.</p><h2 id="mitigating-risk-in-aiaas">Mitigating risk in AIaaS</h2><p>Unlocking these new capabilities requires more than deploying AI tools. Organizations need governance frameworks, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls and operational processes that allow autonomy to be introduced safely and responsibly.</p><p>As agents gain access to more systems and collaborate across workflows, operational complexity inevitably increases. Businesses must define clear policies around what agents can and cannot do, what data they can access, and what approvals are required before actions are taken.</p><p>These controls should be embedded into the orchestration layer itself, ensuring governance is applied consistently across all agent-led activities rather than being treated as an afterthought.</p><p>Traceability and accountability are equally important. Completing a task successfully is only part of the equation. Organizations must understand how decisions were made, what information was used, and which policies were applied throughout the process. This visibility will be essential for compliance, security and maintaining trust in autonomous systems.</p><p>The role of <a href="https://www.techradar.com/best/best-linux-distro-for-developers">developers</a> will also evolve. Rather than spending significant time building and maintaining point-to-point integrations, they will increasingly focus on designing agent behaviors, defining boundaries, managing orchestration and ensuring solutions operate within established governance frameworks.</p><p>The organizations that succeed will be those that balance innovation with control. Too little governance introduces risk, while excessive restrictions can prevent businesses from realizing the benefits of AI altogether.</p><p>Agentic AI should not be viewed as a replacement for software development or existing technology investments. Instead, it represents a powerful new interaction layer that changes how organizations access information, automate processes and deliver outcomes.</p><p>Businesses that invest now in integration foundations, governance models and workforce skills will be best placed to take advantage of the opportunities this next phase of AI creates.</p><p><em></em><a href="https://www.techradar.com/news/best-business-laptops"><em>We've reviewed the best business laptops</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/introducing-ai-as-a-service</link>
                                                                            <description>
                            <![CDATA[ As agentic AI evolves, the impact will be felt throughout the industry - especially on SaaS. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iYiwHcPKFNgfQ9vFiutmde</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 10:33:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jay Fitzhenry ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>2025 was a transformative year for <a href="https://www.techradar.com/best/best-ai-tools">artificial intelligence</a>, and 2026 is already proving to be equally significant. </p><p>While generative AI dominated conversations just a few years ago, the focus is now shifting towards agentic AI, where intelligent systems can take action, interact with business processes, and support employees in more meaningful ways.</p><p>As these capabilities continue to evolve, organizations are looking for better ways to connect AI systems to the applications, data and services that drive their operations. </p><p>This is where technologies such as Model Context Protocol (MCP) are becoming increasingly important. </p><p>Rather than creating bespoke integrations for every tool or system, MCP provides a standardized way for AI models and agents to access information and perform actions across an organization's technology estate.</p><p>While MCP is not a requirement for every AI implementation today, it represents a natural next step for organizations looking to move beyond isolated AI use cases and towards more integrated, scalable AI ecosystems.</p><p>However, greater integration also introduces greater responsibility. Effective governance remains essential for any AI deployment, but it becomes even more critical when autonomous agents are granted access to business systems, processes and sensitive information. </p><p>Organizations must establish clear guardrails that define what agents can access, what actions they can perform, and how their activities are monitored. Without appropriate oversight, businesses risk agents operating beyond their intended scope or creating unintended consequences across interconnected systems.</p><h2 id="the-impact-on-software-as-a-service">The impact on Software-as-a-Service</h2><p>Few sectors will feel the effects of this shift more than Software-as-a-Service (SaaS).</p><p>For years, SaaS applications have been built around human interaction. Users access platforms through dashboards and interfaces, navigate predefined workflows, and manually complete tasks. The application itself serves as the primary workspace where work is performed.</p><p>Agentic AI introduces a different model.</p><p>Rather than navigating <a href="https://www.techradar.com/best/best-small-business-software">software</a> in the same way a person would, agents can interact directly with APIs, services and data sources. This allows them to retrieve information, execute actions and orchestrate processes across multiple systems without relying on traditional user journeys.</p><p>That does not mean SaaS applications will disappear. In fact, they will continue to play a critical role in storing structured data, enforcing business rules and managing workflows. What is likely to change is how those applications are consumed.</p><p>Instead of being the primary destination where work happens, many SaaS platforms will increasingly act as sources of capability and information that AI agents can utilize on behalf of users. As a result, organizations may find themselves focusing less on which <a href="https://www.techradar.com/best/best-mobile-app-development-software">application</a> employees need to access and more on how services and data can be brought together to achieve the desired business outcome.</p><p>Human interfaces will still matter. Users will continue to need visibility, exception handling and control mechanisms, particularly when business-critical processes are involved. The challenge for software providers will be balancing traditional user experiences with new AI-driven interaction models while maintaining compatibility, reliability and operational resilience.</p><h2 id="breaking-down-agent-silos">Breaking down agent silos</h2><p>The next stage in the evolution of agentic AI is not simply creating more agents. It is enabling agents to work together effectively.</p><p>Many organizations already struggle with fragmented systems, disconnected data and isolated processes. Without careful planning, agents risk creating a new generation of silos, each operating within its own limited context and producing inconsistent outcomes.</p><p>To avoid this, businesses must focus on shared context, connected data and interoperable services. The goal is not to have individual agents automating isolated tasks but to enable multiple agents to contribute towards broader business objectives across entire processes.</p><p>When agents can access consistent information and operate across organizational boundaries, the value shifts from discrete task automation to coordinated execution. Rather than supporting an individual stage of a workflow, agents can participate in end-to-end processes while remaining aligned to business policies, operational requirements and organizational goals.</p><p>This represents an important architectural shift. Software increasingly becomes something that agents consume programmatically, while integration, context and orchestration become central to delivering outcomes at scale.</p><h2 id="mitigating-risk-in-aiaas">Mitigating risk in AIaaS</h2><p>Unlocking these new capabilities requires more than deploying AI tools. Organizations need governance frameworks, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls and operational processes that allow autonomy to be introduced safely and responsibly.</p><p>As agents gain access to more systems and collaborate across workflows, operational complexity inevitably increases. Businesses must define clear policies around what agents can and cannot do, what data they can access, and what approvals are required before actions are taken.</p><p>These controls should be embedded into the orchestration layer itself, ensuring governance is applied consistently across all agent-led activities rather than being treated as an afterthought.</p><p>Traceability and accountability are equally important. Completing a task successfully is only part of the equation. Organizations must understand how decisions were made, what information was used, and which policies were applied throughout the process. This visibility will be essential for compliance, security and maintaining trust in autonomous systems.</p><p>The role of <a href="https://www.techradar.com/best/best-linux-distro-for-developers">developers</a> will also evolve. Rather than spending significant time building and maintaining point-to-point integrations, they will increasingly focus on designing agent behaviors, defining boundaries, managing orchestration and ensuring solutions operate within established governance frameworks.</p><p>The organizations that succeed will be those that balance innovation with control. Too little governance introduces risk, while excessive restrictions can prevent businesses from realizing the benefits of AI altogether.</p><p>Agentic AI should not be viewed as a replacement for software development or existing technology investments. Instead, it represents a powerful new interaction layer that changes how organizations access information, automate processes and deliver outcomes.</p><p>Businesses that invest now in integration foundations, governance models and workforce skills will be best placed to take advantage of the opportunities this next phase of AI creates.</p><p><em></em><a href="https://www.techradar.com/news/best-business-laptops"><em>We've reviewed the best business laptops</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Another Rowhammer attack has been detected, and Nvidia workstation GPUs are firmly in the firing line ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>GPUThor is the first Rowhammer attack to defeat ECC on Nvidia GPUs and reach a root shell on the host</strong></li><li><strong>It affects four Ampere workstation cards with GDDR6 memory, the RTX A4000, A4500, A5000 and A6000</strong></li><li><strong>Non-uniform hammering, enabled by defeating GPU memory coalescing and finding that Target Row Refresh (TRR) mitigations fire once every 72 refresh intervals, delivers effectively 6.6 times the hammering intensity of prior attacks</strong></li></ul><p>Four researchers at the University of Toronto have disclosed GPUThor, a Rowhammer technique that breaks the error correction Nvidia has spent the past year recommending as the defense against exactly this class of attack.</p><p>Chris S. Lin, Joyce Qu, Aditya Rajeev and Gururaj Saileshwar are expected to present the <a href="https://gputhor.com/" target="_blank" rel="nofollow">paper</a> outlining their approach and subsequent findings at ACM CCS 2026.</p><p>The attacks target Ampere-generation workstation cards with GDDR6 memory, specifically the RTX A4000, A4500, A5000 and A6000, and it turns an unprivileged CUDA program into a root shell on the host.</p><h2 id="an-attack-that-matters-much-more-than-its-predecessors">An attack that matters much more than its predecessors</h2><p>Rowhammer works by repeatedly activating a DRAM row until charge leaks from cells in the physically adjacent rows and flips their bits. The attacker never touches the victim's data directly, making it an excellent precursor to tampering, sandbox escape, and privilege escalation, among other things.</p><p>This approach is possible despite an in-chip countermeasure called TRR that accompanies ECC-enabled chips on these GPUs. TRR aims to prevent Rowhammer attacks by tracking how frequently specific memory rows are activated and automatically refreshing adjacent rows before a malicious bit flip can occur.</p><p>This approach works well on paper and, when Rowhammer attacks hammer uniformly, offers decent protection. The problem arises when approaches such as GPUThor use non-uniform hammering, which is much more likely to succeed. Non-uniform hammering is not exactly new, having <a href="https://www.techradar.com/news/your-ddr4-memory-could-be-facing-serious-assaults" target="_blank">already succeeded on the CPU side of the spectrum</a> thanks to the well-documented Blacksmith attack vector.</p><p>GPUThor is the third attack from broadly the same group in eighteen months, following GPUHammer in 2025 and GPUBreach earlier this year, and it matters because the previous two stopped working the moment a user typed the command to enable ECC.</p><p>ECC was essentially Nvidia's go-to response to reported Rowhammer attacks, but it may no longer be a solution in its current state. By hammering non-uniformly, the researchers opened another attack vector for Nvidia's Ampere-based GPUs, which are overwhelmingly affected by the technique.</p><p>With ECC disabled, GPUThor produced 72,000 to 377,000 bit flips per gigabyte across four Ampere-based cards, with Nvidia's A5000 being reported as the most vulnerable. That approaches the roughly 550,000 flips per gigabyte that Blacksmith achieves on DDR4, which is cause for concern: GPU Rowhammer is now in the same league as CPU Rowhammer.</p><p>When enabled, the researchers said ECC protectors reduced, but did not completely mitigate, the issue: they delivered double-bit errors and 2 triple-bit errors that the technique 'fixed' by choosing the wrong value.</p><p>On <a href="https://www.techradar.com/news/nvidia-launches-ampere-for-graphics-professionals-rtx-a40-and-rtx-a6000-cards" target="_blank">an RTX A6000 with ECC enabled</a>, the GPUThor technique forces one GPU reset every 2 hours, killing all running processes on the GPU; as a result, the GPU flags itself as RMA-read within a day.</p><p>The team disclosed the attack pattern to Nvidia on 29 April 2026 and subsequently to Google, Microsoft and AWS, and held the work until the 25th of August. A code release is scheduled for the 15th of November, even though there is currently no CVE information or patch being deployed to address the issue.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/another-rowhammer-attack-has-been-detected-and-nvidia-workstation-gpus-are-firmly-in-the-firing-line</link>
                                                                            <description>
                            <![CDATA[ Nvidia spent a year telling people ECC was the answer to GPU Rowhammer. GPUThor might have just proved them wrong. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CEkDYAAjrtiexrJ9e5NzAD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D9pZcgdPinp5ty7pPDjKeY-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/D9pZcgdPinp5ty7pPDjKeY-1280-80.png">
                                                            <media:credit><![CDATA[Nvidia]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Nvidia]]></media:description>                                                            <media:text><![CDATA[Nvidia]]></media:text>
                                <media:title type="plain"><![CDATA[Nvidia]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D9pZcgdPinp5ty7pPDjKeY-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>GPUThor is the first Rowhammer attack to defeat ECC on Nvidia GPUs and reach a root shell on the host</strong></li><li><strong>It affects four Ampere workstation cards with GDDR6 memory, the RTX A4000, A4500, A5000 and A6000</strong></li><li><strong>Non-uniform hammering, enabled by defeating GPU memory coalescing and finding that Target Row Refresh (TRR) mitigations fire once every 72 refresh intervals, delivers effectively 6.6 times the hammering intensity of prior attacks</strong></li></ul><p>Four researchers at the University of Toronto have disclosed GPUThor, a Rowhammer technique that breaks the error correction Nvidia has spent the past year recommending as the defense against exactly this class of attack.</p><p>Chris S. Lin, Joyce Qu, Aditya Rajeev and Gururaj Saileshwar are expected to present the <a href="https://gputhor.com/" target="_blank" rel="nofollow">paper</a> outlining their approach and subsequent findings at ACM CCS 2026.</p><p>The attacks target Ampere-generation workstation cards with GDDR6 memory, specifically the RTX A4000, A4500, A5000 and A6000, and it turns an unprivileged CUDA program into a root shell on the host.</p><h2 id="an-attack-that-matters-much-more-than-its-predecessors">An attack that matters much more than its predecessors</h2><p>Rowhammer works by repeatedly activating a DRAM row until charge leaks from cells in the physically adjacent rows and flips their bits. The attacker never touches the victim's data directly, making it an excellent precursor to tampering, sandbox escape, and privilege escalation, among other things.</p><p>This approach is possible despite an in-chip countermeasure called TRR that accompanies ECC-enabled chips on these GPUs. TRR aims to prevent Rowhammer attacks by tracking how frequently specific memory rows are activated and automatically refreshing adjacent rows before a malicious bit flip can occur.</p><p>This approach works well on paper and, when Rowhammer attacks hammer uniformly, offers decent protection. The problem arises when approaches such as GPUThor use non-uniform hammering, which is much more likely to succeed. Non-uniform hammering is not exactly new, having <a href="https://www.techradar.com/news/your-ddr4-memory-could-be-facing-serious-assaults" target="_blank">already succeeded on the CPU side of the spectrum</a> thanks to the well-documented Blacksmith attack vector.</p><p>GPUThor is the third attack from broadly the same group in eighteen months, following GPUHammer in 2025 and GPUBreach earlier this year, and it matters because the previous two stopped working the moment a user typed the command to enable ECC.</p><p>ECC was essentially Nvidia's go-to response to reported Rowhammer attacks, but it may no longer be a solution in its current state. By hammering non-uniformly, the researchers opened another attack vector for Nvidia's Ampere-based GPUs, which are overwhelmingly affected by the technique.</p><p>With ECC disabled, GPUThor produced 72,000 to 377,000 bit flips per gigabyte across four Ampere-based cards, with Nvidia's A5000 being reported as the most vulnerable. That approaches the roughly 550,000 flips per gigabyte that Blacksmith achieves on DDR4, which is cause for concern: GPU Rowhammer is now in the same league as CPU Rowhammer.</p><p>When enabled, the researchers said ECC protectors reduced, but did not completely mitigate, the issue: they delivered double-bit errors and 2 triple-bit errors that the technique 'fixed' by choosing the wrong value.</p><p>On <a href="https://www.techradar.com/news/nvidia-launches-ampere-for-graphics-professionals-rtx-a40-and-rtx-a6000-cards" target="_blank">an RTX A6000 with ECC enabled</a>, the GPUThor technique forces one GPU reset every 2 hours, killing all running processes on the GPU; as a result, the GPU flags itself as RMA-read within a day.</p><p>The team disclosed the attack pattern to Nvidia on 29 April 2026 and subsequently to Google, Microsoft and AWS, and held the work until the 25th of August. A code release is scheduled for the 15th of November, even though there is currently no CVE information or patch being deployed to address the issue.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Two major security flaws are affecting more than six million WordPress websites ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Wordfence discloses two critical flaws in Elementor Pro and Super Forms</strong></li><li><strong>Bugs allow unauthenticated arbitrary file uploads, enabling remote code execution; both patched recently</strong></li><li><strong>Exploitation attempts already exceed 440,000</strong></li></ul><p>More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild. </p><p>Security researchers Wordfence disclosed finding two flaws, one in Elementor Pro, and one in Super Forms - two popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugins</a>. </p><p><a href="https://www.techradar.com/reviews/elementor" target="_blank">Elementor Pro</a> is a commercial plugin that allows users to build websites using drag-and-drop elements instead of code. With it, they can add advanced widgets, templates, different forms, popups, and more. It is quite a popular solution with more than six million websites actively using it.</p><h2 id="two-bugs-hundreds-of-thousands-of-attacks">Two bugs, hundreds of thousands of attacks</h2><p>According to Wordfence, up until recently, it was vulnerable to an “unrestricted file type upload” bug in all versions up to, and including, 4.2.1. “This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained. “This requires that the targeted site has published a page containing an Elementor Pro Form widget with at least one non-required File Upload field.”</p><p>The bug is tracked as CVE-2026-32475, carries a severity score of 9.8/10 (critical), and was patched in mid-August 2026. So far, Wordfence alone blocked more than 190,000 exploit attempts.</p><p>At roughly the same time, the researchers also reported finding a flaw in Super Forms, a form builder plugin that lets users create and manage forms using a drag-and-drop interface. This plugin, with some 13,000 active installations, contained a bug that allowed arbitrary file upload in all versions up to, and including, 6.3.313.</p><p>“This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained.</p><p>This one is tracked as CVE-2026-14894, also carries a severity score of 9.8/10 (critical) and it, too, was patched a few weeks ago. For this flaw, Wordfence observed more than 250,000 exploitation attempts meaning that cumulatively, these two resulted in 440,000 attacks already. </p><p>Given the widespread adoption of these plugins, and the fact that the flaws are being actively leveraged, users are advised to apply the fixes without delay.</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html" target="_blank"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/two-major-security-flaws-are-affecting-more-than-six-million-wordpress-websites</link>
                                                                            <description>
                            <![CDATA[ Patches are available, so WordPress users should hurry up and apply them. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9ECcHJPTq7j6ouvCBPkCyJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 17:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Wordfence discloses two critical flaws in Elementor Pro and Super Forms</strong></li><li><strong>Bugs allow unauthenticated arbitrary file uploads, enabling remote code execution; both patched recently</strong></li><li><strong>Exploitation attempts already exceed 440,000</strong></li></ul><p>More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild. </p><p>Security researchers Wordfence disclosed finding two flaws, one in Elementor Pro, and one in Super Forms - two popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugins</a>. </p><p><a href="https://www.techradar.com/reviews/elementor" target="_blank">Elementor Pro</a> is a commercial plugin that allows users to build websites using drag-and-drop elements instead of code. With it, they can add advanced widgets, templates, different forms, popups, and more. It is quite a popular solution with more than six million websites actively using it.</p><h2 id="two-bugs-hundreds-of-thousands-of-attacks">Two bugs, hundreds of thousands of attacks</h2><p>According to Wordfence, up until recently, it was vulnerable to an “unrestricted file type upload” bug in all versions up to, and including, 4.2.1. “This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained. “This requires that the targeted site has published a page containing an Elementor Pro Form widget with at least one non-required File Upload field.”</p><p>The bug is tracked as CVE-2026-32475, carries a severity score of 9.8/10 (critical), and was patched in mid-August 2026. So far, Wordfence alone blocked more than 190,000 exploit attempts.</p><p>At roughly the same time, the researchers also reported finding a flaw in Super Forms, a form builder plugin that lets users create and manage forms using a drag-and-drop interface. This plugin, with some 13,000 active installations, contained a bug that allowed arbitrary file upload in all versions up to, and including, 6.3.313.</p><p>“This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained.</p><p>This one is tracked as CVE-2026-14894, also carries a severity score of 9.8/10 (critical) and it, too, was patched a few weeks ago. For this flaw, Wordfence observed more than 250,000 exploitation attempts meaning that cumulatively, these two resulted in 440,000 attacks already. </p><p>Given the widespread adoption of these plugins, and the fact that the flaws are being actively leveraged, users are advised to apply the fixes without delay.</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ G7 tells businesses to get ready for quantum cybersecurity threats ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>G7 urges governments and organizations to begin transitioning to quantum‑resistant encryption</strong></li><li><strong>Warning highlights risk from future quantum computers able to break current standards like AES</strong></li><li><strong>Guidance: inventory cryptographic assets, prioritize critical systems, and adopt phased PQC strategies</strong></li></ul><p>The G7, a collection of some of the world’s most powerful economies, is urging organizations to adopt quantum-resistant encryption as soon as possible and minimize the risk of losing sensitive data to technologically advanced threat actors.</p><p>Virtually every industry in the world today relies on encryption (the process of converting readable data into scrambled, unreadable data so that only someone with the correct key can decode and access it) to protect sensitive information. Banks, telecommunications providers, defense organizations, and practically everyone else are using some form of encryption - most probably AES (Advanced Encryption Standard).</p><p>Decrypting the protected data without the encryption key is considered almost impossible, since the computational effort necessary to pull it off would simply be too large. However, since quantum computers work on a fundamentally different principle, it is believed that once they are mature enough, they will be able to “crack” today’s encryption standards. </p><h2 id="g7-39-s-advice">G7's advice</h2><p>Now, the G7 has <a href="https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action" target="_blank" rel="nofollow">urged</a> government and organizations to remain ahead of the curve by deploying “quantum-resistant encryption”:</p><p>“To protect themselves from the threat brought by CRQCs (cryptographically relevant quantum computers), organizations should begin planning their PQC transition now and should aim to complete their transitions within any the timelines set out by their national cybersecurity authorities,” the warning reads.</p><p>“In addition to quantum-related risks, organizations that delay their PQC transition may lose competitive advantage or may be excluded from contracting opportunities, including public procurement.”</p><p>The G7 advises governments and organizations to take a number of steps, including identifying critical systems and prioritizing them. They should adopt a phased and risk-based strategy, start their transition early, and inventory their cryptographic assets. They should also map their dependencies and develop a transition plan.</p><p>“To limit transition-related costs, they should opt to purchase products that integrate PQC and replace their systems with quantum-safe ones as part of their standard renewal schedule. As such, starting the transition early could result in lower migration costs overall. Planning and conducting their PQC transition properly would enable organizations to prevent insecure implementations and avoid increased exposure to conventional cyber threats.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/g7-tells-businesses-to-get-ready-for-quantum-cybersecurity-threats</link>
                                                                            <description>
                            <![CDATA[ Organizations late to the migration could lose contracting opportunities, G7 warns. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2ZkfdmUW73vAcJc8nb3TLL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UVm4pWzxzFfM3waNQDdPrD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 16:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UVm4pWzxzFfM3waNQDdPrD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Quantum computing concept. Digital communication network. Technological abstract.]]></media:description>                                                            <media:text><![CDATA[Quantum computing concept. Digital communication network. Technological abstract.]]></media:text>
                                <media:title type="plain"><![CDATA[Quantum computing concept. Digital communication network. Technological abstract.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UVm4pWzxzFfM3waNQDdPrD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>G7 urges governments and organizations to begin transitioning to quantum‑resistant encryption</strong></li><li><strong>Warning highlights risk from future quantum computers able to break current standards like AES</strong></li><li><strong>Guidance: inventory cryptographic assets, prioritize critical systems, and adopt phased PQC strategies</strong></li></ul><p>The G7, a collection of some of the world’s most powerful economies, is urging organizations to adopt quantum-resistant encryption as soon as possible and minimize the risk of losing sensitive data to technologically advanced threat actors.</p><p>Virtually every industry in the world today relies on encryption (the process of converting readable data into scrambled, unreadable data so that only someone with the correct key can decode and access it) to protect sensitive information. Banks, telecommunications providers, defense organizations, and practically everyone else are using some form of encryption - most probably AES (Advanced Encryption Standard).</p><p>Decrypting the protected data without the encryption key is considered almost impossible, since the computational effort necessary to pull it off would simply be too large. However, since quantum computers work on a fundamentally different principle, it is believed that once they are mature enough, they will be able to “crack” today’s encryption standards. </p><h2 id="g7-39-s-advice">G7's advice</h2><p>Now, the G7 has <a href="https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action" target="_blank" rel="nofollow">urged</a> government and organizations to remain ahead of the curve by deploying “quantum-resistant encryption”:</p><p>“To protect themselves from the threat brought by CRQCs (cryptographically relevant quantum computers), organizations should begin planning their PQC transition now and should aim to complete their transitions within any the timelines set out by their national cybersecurity authorities,” the warning reads.</p><p>“In addition to quantum-related risks, organizations that delay their PQC transition may lose competitive advantage or may be excluded from contracting opportunities, including public procurement.”</p><p>The G7 advises governments and organizations to take a number of steps, including identifying critical systems and prioritizing them. They should adopt a phased and risk-based strategy, start their transition early, and inventory their cryptographic assets. They should also map their dependencies and develop a transition plan.</p><p>“To limit transition-related costs, they should opt to purchase products that integrate PQC and replace their systems with quantum-safe ones as part of their standard renewal schedule. As such, starting the transition early could result in lower migration costs overall. Planning and conducting their PQC transition properly would enable organizations to prevent insecure implementations and avoid increased exposure to conventional cyber threats.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US military troops can still be hit by targeted attacks despite disabling ad tracking on their devices — and leaders aren't happy ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>US military branches disable ad tracking on government‑issued devices after warning</strong></li><li><strong>Location data from personal devices still poses risks; past data remains for sale</strong></li><li><strong>Senators urge DoD inspector general to review policies and stop servicemember data exposure</strong></li></ul><p>More than 20 years ago, Jason Bourne was smashing mobile phones to prevent being tracked by his adversaries - and the US Department of Defense (DoD) has realized it should probably do something similar.</p><p>In May 2026, Senator Ron Wyden mailed the DoD (among others), informing the agency that foreign powers were using commercial location data to target US troops - and now, Wyden has shared the responses he received from the US Army, Air Force, Navy, Marine Corps, and Special Operations Command, all of which have disabled advertising tracking across their government-issued devices, including Apple and Android smartphones, and Windows computers. </p><p>Some branches did it earlier this year, while the Air Force allegedly concluded the efforts in July 2026 - and while Wyden praised the move, he also suggested it is not enough, and that further steps must be taken in order to protect US troops stationed abroad.</p><h2 id="evaluating-the-leaked-files">Evaluating the leaked files</h2><p>“We commend these service branches for implementing this cybersecurity defensive best practice on government devices,” Wyden and Senator Pat Harrigan wrote. “However, recent reports regarding the continued availability of commercial location data originating from DoD facilities raise troubling questions.”</p><p>Apparently, despite disabling these features and placing the troops out of reach of <a href="https://www.techradar.com/pro/best-data-removal-services-of-year" target="_blank">data brokers</a> and similar commercial entities, the data that was gathered earlier remains available for sale, which still presents a risk. </p><p>“The members suggested data could continue to be available for several reasons, including that commercial data available originates from personal devices, not government phones, that are carried by servicemembers and government contractors,” a report on <a href="https://www.wyden.senate.gov/news/press-releases/wyden-and-harrigan-call-for-investigation-into-dod-efforts-to-protect-us-servicemembers-from-commercial-location-data-threats" target="_blank" rel="nofollow">Wyden’s website</a> reads.</p><p>“Wyden and Harrigan called on the DOD inspector general to examine commercial location data that DOD and other government agencies have already purchased to determine why existing policies have not prevented servicemembers location data from being sold online, and to recommend policy changes to better protect US personnel.”</p><p><em>Via </em><a href="https://techcrunch.com/2026/09/04/us-military-disabled-ad-tracking-on-troops-devices-following-reports-of-targeted-attacks/" target="_blank"><em>TechCrunch</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/us-military-troops-can-still-be-hit-by-targeted-attacks-despite-disabling-ad-tracking-on-their-devices-and-leaders-arent-happy</link>
                                                                            <description>
                            <![CDATA[ Government-issued devices are safe - but what about private devices? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qxo8CGkgGxxCnCDCgsK3sd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KcuQeJXg8Wj7ktEdTA3XhC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 15:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KcuQeJXg8Wj7ktEdTA3XhC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / NATALIA KOLESNIKOVA]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Belarusian border guard with a service dog]]></media:description>                                                            <media:text><![CDATA[A Belarusian border guard with a service dog]]></media:text>
                                <media:title type="plain"><![CDATA[A Belarusian border guard with a service dog]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KcuQeJXg8Wj7ktEdTA3XhC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>US military branches disable ad tracking on government‑issued devices after warning</strong></li><li><strong>Location data from personal devices still poses risks; past data remains for sale</strong></li><li><strong>Senators urge DoD inspector general to review policies and stop servicemember data exposure</strong></li></ul><p>More than 20 years ago, Jason Bourne was smashing mobile phones to prevent being tracked by his adversaries - and the US Department of Defense (DoD) has realized it should probably do something similar.</p><p>In May 2026, Senator Ron Wyden mailed the DoD (among others), informing the agency that foreign powers were using commercial location data to target US troops - and now, Wyden has shared the responses he received from the US Army, Air Force, Navy, Marine Corps, and Special Operations Command, all of which have disabled advertising tracking across their government-issued devices, including Apple and Android smartphones, and Windows computers. </p><p>Some branches did it earlier this year, while the Air Force allegedly concluded the efforts in July 2026 - and while Wyden praised the move, he also suggested it is not enough, and that further steps must be taken in order to protect US troops stationed abroad.</p><h2 id="evaluating-the-leaked-files">Evaluating the leaked files</h2><p>“We commend these service branches for implementing this cybersecurity defensive best practice on government devices,” Wyden and Senator Pat Harrigan wrote. “However, recent reports regarding the continued availability of commercial location data originating from DoD facilities raise troubling questions.”</p><p>Apparently, despite disabling these features and placing the troops out of reach of <a href="https://www.techradar.com/pro/best-data-removal-services-of-year" target="_blank">data brokers</a> and similar commercial entities, the data that was gathered earlier remains available for sale, which still presents a risk. </p><p>“The members suggested data could continue to be available for several reasons, including that commercial data available originates from personal devices, not government phones, that are carried by servicemembers and government contractors,” a report on <a href="https://www.wyden.senate.gov/news/press-releases/wyden-and-harrigan-call-for-investigation-into-dod-efforts-to-protect-us-servicemembers-from-commercial-location-data-threats" target="_blank" rel="nofollow">Wyden’s website</a> reads.</p><p>“Wyden and Harrigan called on the DOD inspector general to examine commercial location data that DOD and other government agencies have already purchased to determine why existing policies have not prevented servicemembers location data from being sold online, and to recommend policy changes to better protect US personnel.”</p><p><em>Via </em><a href="https://techcrunch.com/2026/09/04/us-military-disabled-ad-tracking-on-troops-devices-following-reports-of-targeted-attacks/" target="_blank"><em>TechCrunch</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI hid AI agent hijacking of German wiki forum for weeks — because its model did the exact same thing in the Hugging Face attack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI hid an incident where a model hijacked a wiki page to use as an AI agent communication board</strong></li><li><strong>The incident was hidden while the company dealt with the fallout of the Hugging Face attack</strong></li><li><strong>The company is now working on a framework for disclosing incidents of 'misalignment'</strong></li></ul><p>OpenAI recently disclosed the details of how one of its AI models <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal" target="_blank">escaped a sandboxed environment</a> and attacked Hugging Face during an evaluation -  and as part of the incident, the models created a messaging board to communicate with each other and influence each other’s reasoning.</p><p>OpenAI has now disclosed that shortly after this incident, agents undergoing testing again escaped their ‘secured’ environment and hijacked an obscure German wiki to use as a messaging board. Per <a href="https://www.reuters.com/world/europe/openai-agents-hijacked-german-website-previously-undisclosed-ai-breakout-this-2026-09-04/" target="_blank" rel="nofollow"><em>Reuters</em></a>, OpenAI leadership kept the incident hidden while they dealt with the fallout from the Hugging Face incident.</p><p>Now that OpenAI has acknowledged its role in the incident, the company has said it is “past time” to put together an incident disclosure pipeline when its models escape testing and slip into third-party networks.</p><h2 id="who-is-at-fault-when-models-do-what-they-re-designed-to-do">Who is at fault when models do what they’re designed to do?</h2><p>Before the two incidents, OpenAI said it, “treated misalignment largely as a research question, which gets communicated in research publications”. But now that models are behaving in previously unknown ways and having real-world impacts, the company said it would change its approach “to expand for this new phase of model capabilities”.</p><p>The company labelled the most recently disclosed incident as “an instance of misalignment similar” to the Hugging Face breach. </p><p>I myself am guilty of reporting on <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in" target="_blank">AI breaking out of containment as going ‘rogue’</a>, but these models are doing exactly what they are designed to do. OpenAI’s detailed disclosure of the Hugging Face incident showed that the models were pushed to try and solve a benchmark test by cheating, which is exactly what caused the cyberattack to happen.</p><p>OpenAI said that both itself and “the larger AI community do not yet have a clear standard for how to report misalignment that shows up during training, evaluation, and deployment, including examples that don’t look like traditional security incidents but could provide insight into AI behavior and future risks”.</p><p>The company added that it is “working on a framework and will share it in upcoming weeks, and in parallel we’re working with dozens of government regulatory agencies worldwide on these issues”.</p><p>“When you combine this 'breakout' with the Hugging face breakout, it's starting to display a pattern,” said Ashley Knowles, Lead Cybersecurity Consultant at Black Hills Information Security. “I struggle here with not getting too doomsday-ish but realistically, this is showing a pattern of concerning behavior.”</p><p>“I'm wondering if this race to become 'first' is undercutting security measures that need to be taken to properly secure and guard AI agents as they're in development. My concern grows when you consider that OpenAI is also resisting further investigation. Adding onto that, the release and promise that Astra can evade human monitoring. The pot is brewing…”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-hid-ai-agent-hijacking-of-german-wiki-forum-for-weeks-because-its-model-did-the-exact-same-thing-in-the-hugging-face-attack</link>
                                                                            <description>
                            <![CDATA[ OpenAI called the incident a 'misalignment' in the model's reasoning and says it is working on a new disclosure framework. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZsqPpUtSY5EUtLWgvr9QcL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bqTLGsRATg4oc47RW3PJbi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 15:19:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bqTLGsRATg4oc47RW3PJbi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/ VCG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI logos]]></media:description>                                                            <media:text><![CDATA[OpenAI logos]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI logos]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bqTLGsRATg4oc47RW3PJbi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI hid an incident where a model hijacked a wiki page to use as an AI agent communication board</strong></li><li><strong>The incident was hidden while the company dealt with the fallout of the Hugging Face attack</strong></li><li><strong>The company is now working on a framework for disclosing incidents of 'misalignment'</strong></li></ul><p>OpenAI recently disclosed the details of how one of its AI models <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal" target="_blank">escaped a sandboxed environment</a> and attacked Hugging Face during an evaluation -  and as part of the incident, the models created a messaging board to communicate with each other and influence each other’s reasoning.</p><p>OpenAI has now disclosed that shortly after this incident, agents undergoing testing again escaped their ‘secured’ environment and hijacked an obscure German wiki to use as a messaging board. Per <a href="https://www.reuters.com/world/europe/openai-agents-hijacked-german-website-previously-undisclosed-ai-breakout-this-2026-09-04/" target="_blank" rel="nofollow"><em>Reuters</em></a>, OpenAI leadership kept the incident hidden while they dealt with the fallout from the Hugging Face incident.</p><p>Now that OpenAI has acknowledged its role in the incident, the company has said it is “past time” to put together an incident disclosure pipeline when its models escape testing and slip into third-party networks.</p><h2 id="who-is-at-fault-when-models-do-what-they-re-designed-to-do">Who is at fault when models do what they’re designed to do?</h2><p>Before the two incidents, OpenAI said it, “treated misalignment largely as a research question, which gets communicated in research publications”. But now that models are behaving in previously unknown ways and having real-world impacts, the company said it would change its approach “to expand for this new phase of model capabilities”.</p><p>The company labelled the most recently disclosed incident as “an instance of misalignment similar” to the Hugging Face breach. </p><p>I myself am guilty of reporting on <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in" target="_blank">AI breaking out of containment as going ‘rogue’</a>, but these models are doing exactly what they are designed to do. OpenAI’s detailed disclosure of the Hugging Face incident showed that the models were pushed to try and solve a benchmark test by cheating, which is exactly what caused the cyberattack to happen.</p><p>OpenAI said that both itself and “the larger AI community do not yet have a clear standard for how to report misalignment that shows up during training, evaluation, and deployment, including examples that don’t look like traditional security incidents but could provide insight into AI behavior and future risks”.</p><p>The company added that it is “working on a framework and will share it in upcoming weeks, and in parallel we’re working with dozens of government regulatory agencies worldwide on these issues”.</p><p>“When you combine this 'breakout' with the Hugging face breakout, it's starting to display a pattern,” said Ashley Knowles, Lead Cybersecurity Consultant at Black Hills Information Security. “I struggle here with not getting too doomsday-ish but realistically, this is showing a pattern of concerning behavior.”</p><p>“I'm wondering if this race to become 'first' is undercutting security measures that need to be taken to properly secure and guard AI agents as they're in development. My concern grows when you consider that OpenAI is also resisting further investigation. Adding onto that, the release and promise that Astra can evade human monitoring. The pot is brewing…”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Stop buying security tools: start buying a system ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Ask a CISO why they bought their newest <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> tool, and they’ll have a clear answer lined up. </p><p>It stops a specific technique, closes a particular gap, or satisfies a compliance requirement. </p><p>However, it's often less clear how the tool fits in with the rest of the stack. </p><p>Does it make the overall system stronger, or simply add another layer of complexity to manage? </p><p>Research indicates most security professionals already believe they’re juggling too many tools, with over half saying they don’t properly integrate together.  </p><p>This is a pattern I call ‘additive by default,’ and it results in stacks that grow without a plan, becoming broader but not necessarily deeper or able to match today’s threats. </p><h2 id="start-with-the-outcome-not-the-technology">Start with the outcome, not the technology </h2><p>I find this additive approach is often due to focusing on specific emerging threats or identified weak points, so decisions are made with a tactical eye rather than a broader strategic view.      </p><p>Part of the problem is that most organizations have never precisely defined the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> outcome they are trying to achieve. Without a shared, specific language for the problem, every new purchase becomes additive, because there is nothing solid to measure it against.      </p><p>Take <a href="https://www.techradar.com/best/best-asset-management-software">asset</a> labelling, which is a core capability most organizations know they need, so they invest in a tool, populate a configuration management database (CMDB), and assign criticality scores. Job done, right? But labelling an asset only answers the question of what it is, and says nothing about how that asset connects to everything around it, or what happens when a policy needs to be enforced against it.      </p><p>Labelling, visibility and enforcement are three distinct jobs, not one. Solve the first and the second and third remain wide open, so another tool gets bought to cover visibility, then another for enforcement. Each purchase solves its own narrow question perfectly well.       </p><p>However, none of them were ever asked to work as a single, continuous capability, because nobody defined that as the actual requirement in the first place.       </p><p>What if <a href="https://www.techradar.com/best/best-software-asset-management-tools">asset management</a> labels fed into visibility views and the same reflected how policy is drafted and then enforced? Now you have a strategic problem solved with interoperable capabilities. </p><h2 id="how-much-of-your-stack-is-really-putting-in-the-work">How much of your stack is really putting in the work? </h2><p>Gartner’s most recent Leadership Perspective Survey saw CISOs noting this as a common issue, with just 20-30% of tool capability actually being used in some cases. The instinctive response to this is to cut the stack down, however, that instinct solves the wrong problem.      </p><p>A good exercise for working out the value of the stack is to evaluate every tool, new or already deployed, against three plain questions.  </p><p>Does it offer continuous validation against a given threat - and what, specifically, does it validate?  Is it still operationally relevant? And is it effective, right now, in the environment you have today? A tool can pass one or two of these and still be failing you.      </p><p>Virtual Local Area Networks (VLANs) are a good example of this. Twenty or thirty years ago, when networks were typically static and everything likely sat inside a single data center, VLAN-based segmentation was genuinely effective. It matched the environment it was built for.       </p><p>That environment has since changed almost beyond recognition. Workloads move between on-premises systems, <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a> and containers, and nothing stays fixed for long. VLANs are still deployed across many stacks today, still technically doing the segmentation job they were built for. Yet their effectiveness has dropped sharply because they offer none of the continuous validation a hybrid, constantly shifting estate actually requires.      </p><p>Effectiveness has an expiry date that has nothing to do with whether the tool still runs. Success should be measured by whether the system as a whole still holds up, not by how many tools remain switched on. </p><h2 id="consolidated-security-not-consolidated-tooling">Consolidated security, not consolidated tooling </h2><p>Gartner identified that most organizations are pursuing a vendor consolidation strategy. While this approach certainly reduces unnecessary spending and keeps budgets under control, it’s not necessarily solving the biggest problem.  </p><p>Consolidated tooling and consolidated security are not the same thing, and it’s an assumption that leads to disappointment. Reducing the number of tools alone achieves little if the underlying processes remain fragmented or teams continue to operate against different objectives. </p><p>No data center I have walked through was built entirely by one manufacturer. Racks, switches, storage and cabling come from a dozen suppliers, yet they operate as one coherent system because they were designed to fit together. Security should work the same way. </p><p>The goal is not necessarily fewer vendors, but every control, whoever built it, feeding into the same continuous picture of identification, visibility and enforcement. </p><h2 id="what-to-ask-instead">What to ask instead </h2><p>Before completing the next security purchase, consider how well a new tool fits into the stack you already have, not just what it claims to do on its own.       </p><p>A tool that deploys cleanly, validates continuously rather than only at go-live, and feeds its findings back into the tools already in place is doing real work. One that arrives as a fresh, isolated source of alerts is just adding to the noise, however good its individual detection rate looks in a demo. That means comparing what the tool was bought to solve against what it is actually delivering today, checking it against newer capabilities, and being willing to redeploy or renegotiate rather than automatically renew or even retire.      </p><p>Ultimately, the strongest security programs are not defined by the number of tools they deploy, nor by the number they eliminate. They're defined by how effectively every control works together when it matters most.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've rounded up the best endpoint protection software suites</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/stop-buying-security-tools-start-buying-a-system</link>
                                                                            <description>
                            <![CDATA[ Security leaders must rethink tool sprawl, prioritizing integration, continuous validation and system-wide effectiveness over consolidation. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YogNqaUbUxnLcYAnberzxG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XbZCTEpjtunPvMj9ySXmWU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 14:23:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Michael Adjei ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XbZCTEpjtunPvMj9ySXmWU-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A file and folder transferring data with a red warning mark indicating malware.]]></media:description>                                                            <media:text><![CDATA[A file and folder transferring data with a red warning mark indicating malware.]]></media:text>
                                <media:title type="plain"><![CDATA[A file and folder transferring data with a red warning mark indicating malware.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XbZCTEpjtunPvMj9ySXmWU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ask a CISO why they bought their newest <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> tool, and they’ll have a clear answer lined up. </p><p>It stops a specific technique, closes a particular gap, or satisfies a compliance requirement. </p><p>However, it's often less clear how the tool fits in with the rest of the stack. </p><p>Does it make the overall system stronger, or simply add another layer of complexity to manage? </p><p>Research indicates most security professionals already believe they’re juggling too many tools, with over half saying they don’t properly integrate together.  </p><p>This is a pattern I call ‘additive by default,’ and it results in stacks that grow without a plan, becoming broader but not necessarily deeper or able to match today’s threats. </p><h2 id="start-with-the-outcome-not-the-technology">Start with the outcome, not the technology </h2><p>I find this additive approach is often due to focusing on specific emerging threats or identified weak points, so decisions are made with a tactical eye rather than a broader strategic view.      </p><p>Part of the problem is that most organizations have never precisely defined the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> outcome they are trying to achieve. Without a shared, specific language for the problem, every new purchase becomes additive, because there is nothing solid to measure it against.      </p><p>Take <a href="https://www.techradar.com/best/best-asset-management-software">asset</a> labelling, which is a core capability most organizations know they need, so they invest in a tool, populate a configuration management database (CMDB), and assign criticality scores. Job done, right? But labelling an asset only answers the question of what it is, and says nothing about how that asset connects to everything around it, or what happens when a policy needs to be enforced against it.      </p><p>Labelling, visibility and enforcement are three distinct jobs, not one. Solve the first and the second and third remain wide open, so another tool gets bought to cover visibility, then another for enforcement. Each purchase solves its own narrow question perfectly well.       </p><p>However, none of them were ever asked to work as a single, continuous capability, because nobody defined that as the actual requirement in the first place.       </p><p>What if <a href="https://www.techradar.com/best/best-software-asset-management-tools">asset management</a> labels fed into visibility views and the same reflected how policy is drafted and then enforced? Now you have a strategic problem solved with interoperable capabilities. </p><h2 id="how-much-of-your-stack-is-really-putting-in-the-work">How much of your stack is really putting in the work? </h2><p>Gartner’s most recent Leadership Perspective Survey saw CISOs noting this as a common issue, with just 20-30% of tool capability actually being used in some cases. The instinctive response to this is to cut the stack down, however, that instinct solves the wrong problem.      </p><p>A good exercise for working out the value of the stack is to evaluate every tool, new or already deployed, against three plain questions.  </p><p>Does it offer continuous validation against a given threat - and what, specifically, does it validate?  Is it still operationally relevant? And is it effective, right now, in the environment you have today? A tool can pass one or two of these and still be failing you.      </p><p>Virtual Local Area Networks (VLANs) are a good example of this. Twenty or thirty years ago, when networks were typically static and everything likely sat inside a single data center, VLAN-based segmentation was genuinely effective. It matched the environment it was built for.       </p><p>That environment has since changed almost beyond recognition. Workloads move between on-premises systems, <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a> and containers, and nothing stays fixed for long. VLANs are still deployed across many stacks today, still technically doing the segmentation job they were built for. Yet their effectiveness has dropped sharply because they offer none of the continuous validation a hybrid, constantly shifting estate actually requires.      </p><p>Effectiveness has an expiry date that has nothing to do with whether the tool still runs. Success should be measured by whether the system as a whole still holds up, not by how many tools remain switched on. </p><h2 id="consolidated-security-not-consolidated-tooling">Consolidated security, not consolidated tooling </h2><p>Gartner identified that most organizations are pursuing a vendor consolidation strategy. While this approach certainly reduces unnecessary spending and keeps budgets under control, it’s not necessarily solving the biggest problem.  </p><p>Consolidated tooling and consolidated security are not the same thing, and it’s an assumption that leads to disappointment. Reducing the number of tools alone achieves little if the underlying processes remain fragmented or teams continue to operate against different objectives. </p><p>No data center I have walked through was built entirely by one manufacturer. Racks, switches, storage and cabling come from a dozen suppliers, yet they operate as one coherent system because they were designed to fit together. Security should work the same way. </p><p>The goal is not necessarily fewer vendors, but every control, whoever built it, feeding into the same continuous picture of identification, visibility and enforcement. </p><h2 id="what-to-ask-instead">What to ask instead </h2><p>Before completing the next security purchase, consider how well a new tool fits into the stack you already have, not just what it claims to do on its own.       </p><p>A tool that deploys cleanly, validates continuously rather than only at go-live, and feeds its findings back into the tools already in place is doing real work. One that arrives as a fresh, isolated source of alerts is just adding to the noise, however good its individual detection rate looks in a demo. That means comparing what the tool was bought to solve against what it is actually delivering today, checking it against newer capabilities, and being willing to redeploy or renegotiate rather than automatically renew or even retire.      </p><p>Ultimately, the strongest security programs are not defined by the number of tools they deploy, nor by the number they eliminate. They're defined by how effectively every control works together when it matters most.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've rounded up the best endpoint protection software suites</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware hackers dump 1.4 million stolen records from German government ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Rhysida ransomware group breached Berlin’s state government, stealing 1.44 million files weighing in at around 5.8TB</strong></li><li><strong>Attackers demanded 30 BTC (~$2.3M); Berlin refused, leading to full leak online</strong></li><li><strong>Leaked data reportedly includes water supply info, staff records, and emergency plans</strong></li></ul><p>A cybercriminal group known as Rhysida allegedly broke into the network of Berlin's state government and exfiltrated 1.44 million files. They then tried to extort the government entity for money and when that failed, they leaked it all into the dark web.</p><p>According to multiple sources, the group first claimed responsibility for the attack on an underground forum, where it shared a small sample of the stolen files and demanded Berlin pay 30 bitcoin (around $2.3 million) in exchange for deleting the files.</p><p>Berlin recognized the attack in a press release, and said it would not be negotiating with the attackers, and instead launched a full-scale investigation into the incident, which it described as an “extremely serious crime and an attack on the state of Berlin.”</p><h2 id="evaluating-the-leaked-files-2">Evaluating the leaked files</h2><p>A few days later, <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">Rhysida</a> decided to leak it all online - and Berlin is now reviewing the leaked files and is assessing the damage:</p><p>“After the publication of the stolen data from the Berlin administration, these files are being evaluated at full speed,” a press release, published on the Berlin.de website (machine-translated), reads. </p><p>“An additional steering unit has been set up in the Senate Chancellery under the leadership of the Chief Digital Officer (CDO), Florian Hauer, which coordinates the review, examination and evaluation of the leaked data and supports the two Senate administrations concerned in informing and advising the affected citizens and companies.”</p><p>According to German public broadcaster Tagesschau, the archive counts 1.44 million files and totals 5.8 terabytes. At the same time, the Chaos Computer Club (Germany's largest and best-known hacker organization) claims the archive contains sensitive data on the city’s water supply, personal data of admin staff, various employment references, and emergency plans. </p><p><em>Via </em><a href="https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/" target="_blank"><em>Reuters</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/ransomware-hackers-dump-1-4-million-stolen-records-from-german-government</link>
                                                                            <description>
                            <![CDATA[ This is an "extremely serious crime" and an attack on Berlin, the government says. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sTAtVCtttosNejBRf3aDA4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3HY9z6jmzyHFPZFAtvox2a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 13:35:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3HY9z6jmzyHFPZFAtvox2a-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3HY9z6jmzyHFPZFAtvox2a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Rhysida ransomware group breached Berlin’s state government, stealing 1.44 million files weighing in at around 5.8TB</strong></li><li><strong>Attackers demanded 30 BTC (~$2.3M); Berlin refused, leading to full leak online</strong></li><li><strong>Leaked data reportedly includes water supply info, staff records, and emergency plans</strong></li></ul><p>A cybercriminal group known as Rhysida allegedly broke into the network of Berlin's state government and exfiltrated 1.44 million files. They then tried to extort the government entity for money and when that failed, they leaked it all into the dark web.</p><p>According to multiple sources, the group first claimed responsibility for the attack on an underground forum, where it shared a small sample of the stolen files and demanded Berlin pay 30 bitcoin (around $2.3 million) in exchange for deleting the files.</p><p>Berlin recognized the attack in a press release, and said it would not be negotiating with the attackers, and instead launched a full-scale investigation into the incident, which it described as an “extremely serious crime and an attack on the state of Berlin.”</p><h2 id="evaluating-the-leaked-files-2">Evaluating the leaked files</h2><p>A few days later, <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">Rhysida</a> decided to leak it all online - and Berlin is now reviewing the leaked files and is assessing the damage:</p><p>“After the publication of the stolen data from the Berlin administration, these files are being evaluated at full speed,” a press release, published on the Berlin.de website (machine-translated), reads. </p><p>“An additional steering unit has been set up in the Senate Chancellery under the leadership of the Chief Digital Officer (CDO), Florian Hauer, which coordinates the review, examination and evaluation of the leaked data and supports the two Senate administrations concerned in informing and advising the affected citizens and companies.”</p><p>According to German public broadcaster Tagesschau, the archive counts 1.44 million files and totals 5.8 terabytes. At the same time, the Chaos Computer Club (Germany's largest and best-known hacker organization) claims the archive contains sensitive data on the city’s water supply, personal data of admin staff, various employment references, and emergency plans. </p><p><em>Via </em><a href="https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/" target="_blank"><em>Reuters</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using 'invisible' Unicode characters to sneak phishing lures into emails ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft reports phishing campaign using ASCII smuggling to bypass spam filters</strong></li><li><strong>Attackers insert invisible characters into keywords, tricking filters and AI agents</strong></li><li><strong>Defenders should normalize Unicode tags and flag unexpected invisible code points as suspicious</strong></li></ul><p>Cybercriminals are using the “ASCII smuggling” technique to make sure phishing emails pass security filters and land in people’s inboxes, experts have warned.</p><p>ASCII is a character encoding standard that turns characters and words humans can read into numeric values that computers can understand. It can also be used to create characters that aren’t even displayed on the screen (essentially “invisible” ones) but can still be read by the machine.</p><p>In a new <a href="https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/" target="_blank" rel="nofollow">report</a>, security researchers from Microsoft found crooks are abusing this fact to distribute phishing emails. Most email providers offer solutions that filter out spam emails. These filters look for certain keywords and phrases, such as “funding”, “credit”, “loan”, and similar, and automatically send such emails to the spam folder. </p><h2 id="ongoing-campaign">Ongoing campaign</h2><p>By adding a set of invisible characters in the middle of these keywords, the attackers can break them apart and thus “confuse” the filters. </p><p>While the human sees the word “funding” in their email, the security solution is seeing something like “fun[a long string of characters]ding”. This technique has been adopted from prompt injection attacks, where crooks would use ASCII smuggling to deliver malicious and invisible prompts in the emails. </p><p>Therefore, when a victim asks their AI agent to summarize the email, it ends up working on a prompt that could be anything from extracting sensitive data, to deploying <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. </p><p>Microsoft is saying the campaign has been ongoing for months, and while it peaked in February 2026 with more than 2.3 million emails every day, and has been in decline ever since, it remains active to this day. In early February, Microsoft observed a cluster of almost 150 sender domains, all themed around finance. These domains accounted for almost all (96%) of all the spam emails Defender for Office 365 flagged under ASCII smuggling.</p><p>Defending sounds relatively simple, though. IT teams should normalize Unicode tag characters and other invisible code points before applying any keyword detection. They should also consider all unexpected tag-block characters as suspicious.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/hackers-are-using-invisible-unicode-characters-to-sneak-phishing-lures-into-emails</link>
                                                                            <description>
                            <![CDATA[ A technique used in prompt injection attacks has made it into phishing, Microsoft has warned. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kpbZtKyjta2kiuQw3KPbBZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 13:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing]]></media:description>                                                            <media:text><![CDATA[Phishing]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft reports phishing campaign using ASCII smuggling to bypass spam filters</strong></li><li><strong>Attackers insert invisible characters into keywords, tricking filters and AI agents</strong></li><li><strong>Defenders should normalize Unicode tags and flag unexpected invisible code points as suspicious</strong></li></ul><p>Cybercriminals are using the “ASCII smuggling” technique to make sure phishing emails pass security filters and land in people’s inboxes, experts have warned.</p><p>ASCII is a character encoding standard that turns characters and words humans can read into numeric values that computers can understand. It can also be used to create characters that aren’t even displayed on the screen (essentially “invisible” ones) but can still be read by the machine.</p><p>In a new <a href="https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/" target="_blank" rel="nofollow">report</a>, security researchers from Microsoft found crooks are abusing this fact to distribute phishing emails. Most email providers offer solutions that filter out spam emails. These filters look for certain keywords and phrases, such as “funding”, “credit”, “loan”, and similar, and automatically send such emails to the spam folder. </p><h2 id="ongoing-campaign">Ongoing campaign</h2><p>By adding a set of invisible characters in the middle of these keywords, the attackers can break them apart and thus “confuse” the filters. </p><p>While the human sees the word “funding” in their email, the security solution is seeing something like “fun[a long string of characters]ding”. This technique has been adopted from prompt injection attacks, where crooks would use ASCII smuggling to deliver malicious and invisible prompts in the emails. </p><p>Therefore, when a victim asks their AI agent to summarize the email, it ends up working on a prompt that could be anything from extracting sensitive data, to deploying <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. </p><p>Microsoft is saying the campaign has been ongoing for months, and while it peaked in February 2026 with more than 2.3 million emails every day, and has been in decline ever since, it remains active to this day. In early February, Microsoft observed a cluster of almost 150 sender domains, all themed around finance. These domains accounted for almost all (96%) of all the spam emails Defender for Office 365 flagged under ASCII smuggling.</p><p>Defending sounds relatively simple, though. IT teams should normalize Unicode tag characters and other invisible code points before applying any keyword detection. They should also consider all unexpected tag-block characters as suspicious.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Save up to 50% off Keeper plans this September — protect your passwords with half price Personal plans, and a third-off Business plans ]]></title>
                                                                                                <dc:content><![CDATA[ <p>You probably have tens, if not hundreds of passwords floating around across all the online accounts you use every week. In fact, the average person has over 150 passwords. It's not easy to remember them all, making it more attractive to keep them simple and similar - but that can lead to a serious chain of account theft.</p><p>That's why password managers like Keeper exist. They generate strong passwords and store them passwords in a secured vault to keep them safe from hackers and prying eyes. They even autofill your credentials to make logging in to your account faster and easier.</p><p><a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper has cut prices on its personal, family, and business starter plans by up to 50%</a>. Keeper regularly scores highly in our reviews, and includes great features across Personal, Family, and Business plans.</p><div class="product"><a data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:131px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="TbfSUDRsU8NdGFXVDRFiSW" name="keeper!.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TbfSUDRsU8NdGFXVDRFiSW.jpg" mos="" align="middle" fullscreen="" width="131" height="131" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25=""><strong>Get up to 50% off Keeper plans</strong></a></p><p>Keeper is offering 50% off its Personal and Family plans, making it even more affordable to secure both personal and household accounts. The Family plan covers multiple users with five secured vaults, making it perfect for shared accounts without the hassle of mixing browsers and reusing passwords.</p><p>Keeper Business Starter is discounted by 30%, and is an excellent choice for small teams looking for a credentials control platform without the complexity and hassle of enduring an enterprise rollout. It includes centralized management, secure password sharing, and role-based access, cleanly organizing your passwords without unnecessary complications.</p><p>The full terms and pricing are available on the <a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper site</a>.<a class="view-deal button" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25="">View Deal</a></p></div><h2 id="why-we-recommend-keeper">Why we recommend Keeper</h2><p>Our <a href="https://www.techradar.com/reviews/keeper-password-manager" target="_blank">Keeper review</a> highlights the platform's zero knowledge architecture and device level encryption that helps keep your password vault secured against unwanted intrusions.</p><p>Where Keeper really shone was in our usability and convenience testing. We loved how Keeper uses biometric security to access your vault, rather than requiring a master password with each log in. By using a facial scan or fingerprint to verify that its actually you accessing your vault, it adds a fast but secure method of verification to ensure its you, and not a nefarious actor.</p><p>For households, the Family Plan includes five private vaults, allowing you to quickly share Wi-Fi or streaming passwords using Keeper's shared vaults.</p><p>The Business Starter plan covers 5 users, covering an unlimited devices, shared team folders, user activity reporting for IT admins, and a free Family Plan for every team member.</p><p>These discounts apply to the first year only, so the value is highest for new customers or anyone switching from a monthly plan. After that, pricing goes back to standard rates.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/save-up-to-50-percent-off-keeper-plans-this-september-protect-your-passwords-with-half-price-personal-plans-and-a-third-off-business-plans</link>
                                                                            <description>
                            <![CDATA[ Keeper is one of the best solutions to password storage and security, with up to 50% off across Personal, Family, and Business plans ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">A3tb9XngX6pNeDLcj6Au2h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 13:17:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:description>                                                            <media:text><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:text>
                                <media:title type="plain"><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>You probably have tens, if not hundreds of passwords floating around across all the online accounts you use every week. In fact, the average person has over 150 passwords. It's not easy to remember them all, making it more attractive to keep them simple and similar - but that can lead to a serious chain of account theft.</p><p>That's why password managers like Keeper exist. They generate strong passwords and store them passwords in a secured vault to keep them safe from hackers and prying eyes. They even autofill your credentials to make logging in to your account faster and easier.</p><p><a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper has cut prices on its personal, family, and business starter plans by up to 50%</a>. Keeper regularly scores highly in our reviews, and includes great features across Personal, Family, and Business plans.</p><div class="product"><a data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:131px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="TbfSUDRsU8NdGFXVDRFiSW" name="keeper!.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TbfSUDRsU8NdGFXVDRFiSW.jpg" mos="" align="middle" fullscreen="" width="131" height="131" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25=""><strong>Get up to 50% off Keeper plans</strong></a></p><p>Keeper is offering 50% off its Personal and Family plans, making it even more affordable to secure both personal and household accounts. The Family plan covers multiple users with five secured vaults, making it perfect for shared accounts without the hassle of mixing browsers and reusing passwords.</p><p>Keeper Business Starter is discounted by 30%, and is an excellent choice for small teams looking for a credentials control platform without the complexity and hassle of enduring an enterprise rollout. It includes centralized management, secure password sharing, and role-based access, cleanly organizing your passwords without unnecessary complications.</p><p>The full terms and pricing are available on the <a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper site</a>.<a class="view-deal button" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25="">View Deal</a></p></div><h2 id="why-we-recommend-keeper">Why we recommend Keeper</h2><p>Our <a href="https://www.techradar.com/reviews/keeper-password-manager" target="_blank">Keeper review</a> highlights the platform's zero knowledge architecture and device level encryption that helps keep your password vault secured against unwanted intrusions.</p><p>Where Keeper really shone was in our usability and convenience testing. We loved how Keeper uses biometric security to access your vault, rather than requiring a master password with each log in. By using a facial scan or fingerprint to verify that its actually you accessing your vault, it adds a fast but secure method of verification to ensure its you, and not a nefarious actor.</p><p>For households, the Family Plan includes five private vaults, allowing you to quickly share Wi-Fi or streaming passwords using Keeper's shared vaults.</p><p>The Business Starter plan covers 5 users, covering an unlimited devices, shared team folders, user activity reporting for IT admins, and a free Family Plan for every team member.</p><p>These discounts apply to the first year only, so the value is highest for new customers or anyone switching from a monthly plan. After that, pricing goes back to standard rates.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why is there so much worry about OpenAI Astra, and what issues could ‘recurrent depth’ reasoning cause? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>OpenAI has unveiled a much anticipated AI model which the firm has dubbed ‘GPT-6 Astra’. While the model has improved significantly across benchmark testing and <a href="https://www.techradar.com/pro/gpt-6-astra-lays-the-foundations-for-a-new-way-of-reasoning-a-great-tool-for-businesses-but-experts-have-their-concerns">brings a host of new business features</a>, there is still a dark cloud looming over the new model.</p><p>Off the back of <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in">OpenAI’s accidental hack of Hugging Face</a> and the company’s subsequent efforts to improve how AI agents behave and interact, numerous cybersecurity experts have raised concerns about the model’s new ‘recurrent depth’ reasoning capabilities.</p><p>This new reasoning architecture allows the model to consider a problem multiple times before taking an action, compared to the standard chain-of-thought reasoning used in previous models.</p><h2 id="why-the-concern-about-recurrent-depth-reasoning">Why the concern about recurrent depth reasoning?</h2><p>This new level of reasoning apparently offers improved performance. OpenAI also says it has fixed its models' abilities to circumvent boundaries when performing tests by monitoring the models reasoning and ensuring the model stays aligned within the scope of its task.</p><p>During Astra’s launch event, OpenAI chief scientist Jakub Pachocki said: “We will not accept degradation in our ability to monitor model alignment beyond a certain level. We will withhold scaling until we can regain enough confidence.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>But numerous experts believe that the lessons of the Hugging Face incident have not yet been learned, and the model has been released without adequate testing on Astra’s reasoning and monitoring. </p><p>After all, no one thought one of <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal">OpenAI’s models could set up a hidden internet-connected messaging board</a> that allowed AI agents to influence each other's behavior.</p><p>But with Astra being released into the real world, the lessons may have to be learned on the fly.</p><h3 class="article-body__section" id="section-expert-perspectives-on-openai-astra-release"><span>Expert perspectives on OpenAI Astra release</span></h3><ul><li><strong>James Blake, VP of Global Cyber Resiliency Strategy at Cohesity:</strong></li></ul><p><em>The launch of Astra is raising questions again around the safety of Frontier AI. Instead of simply asking whether a model is "safe", organisations now need to ask whether it remains safe across millions of different situations, prompts and interactions. Cyber resilience has traditionally assumed that systems and threat actors behave deterministically. AI systems don’t.</em></p><div><blockquote><p>Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible?</p></blockquote></div><p><em>Advanced models can and will continue to exhibit behaviours that emerge from their optimisation process rather than from explicit programming. We have to move beyond thinking about AI as just another software tool and find ways to ensure these systems remain observable, auditable and governable throughout their lifecycle. </em></p><p><em>The most important question we’ll need to answer in future is one of liability. Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible? The developer that trained the model? The cloud provider operating the infrastructure? Currently the answer is surprisingly unclear. It’s not just about what AI can do: it’s about who is accountable when it does something nobody expected.</em></p><ul><li><strong>Oleksandr Yaremchuk, Co-Founder & CTO at Manifold Security:</strong></li></ul><p><em>OpenAI is calling Astra its most aligned model yet, even as its chief scientist admits monitorability is getting harder as models get more capable. Evidently, Astra hides its reasoning in the majority of tested cases, and some successful attacks left no reasoning trace at all. That's the tool many organisations still use, including the labs themselves, for auditing what an agent is doing, and it's getting less reliable with every release.</em></p><div><blockquote><p>A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</p></blockquote></div><p><em>That matters because Astra isn't staying inside OpenAI's test environment. It's going to run as an agent on employee laptops and in the browser, holding real credentials, inside companies that have no way to watch what it does once it's there. A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</em></p><p><em>Labs can keep debating what these models say or refuse to say. Security teams need to stop relying on that and start monitoring what agents actually do at runtime, with the ability to shut one down mid-action. That's the only oversight left that still works once the reasoning goes quiet.</em></p><ul><li><strong>Kristin Lowery, Field CISO at Optiv:</strong></li></ul><p><em>For boards and executive leaders, the emergence of OpenAI’s Astra model highlights a broader reality: AI is no longer just a productivity issue; it is a risk management issue. </em></p><div><blockquote><p>The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace</p></blockquote></div><p><em>Just as organizations established governance for cloud adoption and digital transformation, they now need clear policies, strong oversight, and accountability for AI use.</em></p><p><em>The question is not whether AI will become more capable — it will. The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace.</em></p><ul><li><strong>Patricia Titus, Field CISO at Abnormal AI:</strong></li></ul><p><em>OpenAI crossing this threshold deserves attention. Credit where it's due, they're handling it responsibly by restricting Astra's advanced cyber capability to a small coalition rather than releasing it broadly.But this isn't one company's problem to contain.</em></p><p><em>Once a model can find and exploit unknown flaws without a human in the loop, that capability doesn't stay exclusive for long. Open-weight and modified models typically trail the frontier by only months, and that's the reality defenders have to plan around now.</em></p><div><blockquote><p>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time.</p></blockquote></div><p><em>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time. Defenders need the same shift, systems that learn what normal looks like for every identity, human, machine, or AI agent, and flag and contain the moment something deviates, at machine speed.</em></p><p><em>The window to build that is open now. It won't stay that way once this capability is common instead of rare.</em></p><ul><li><strong>Raghu Nandakumara, VP of Industry Strategy at Illumio:</strong></li></ul><p><em>With the Astra announcement, OpenAI is doubling down on monitoring the model's own behaviour – a response to the model "breakouts" seen over the past few months.</em></p><div><blockquote><p>The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</p></blockquote></div><p><em>When Anthropic announced Claude Mythos Preview, the core concern was the model falling into the wrong hands. OpenAI's answer goes further adding guardrails around the model's own reasoning and actions, regardless of the user's intent. The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</em></p><p><em>The rest of this announcement can be summarised as ‘we have a new frontier model, and it’s more capable than the last one’.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-is-there-so-much-worry-about-openai-astra-and-what-issues-could-recurrent-depth-reasoning-cause-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ As OpenAI unveils GPT-6 Astra, cybersecurity experts question whether the model's 'recurrent depth' reasoning was properly tested. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C8dxY7YkHdtYyEPzyEiovn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 05 Sep 2026 13:30:00 +0000</pubDate>                                                                                                                                <updated>Mon, 07 Sep 2026 09:36:03 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[ChatGPT]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg">
                                                            <media:credit><![CDATA[OpenAI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI GPT-6 Astra]]></media:description>                                                            <media:text><![CDATA[OpenAI GPT-6 Astra]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI GPT-6 Astra]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI has unveiled a much anticipated AI model which the firm has dubbed ‘GPT-6 Astra’. While the model has improved significantly across benchmark testing and <a href="https://www.techradar.com/pro/gpt-6-astra-lays-the-foundations-for-a-new-way-of-reasoning-a-great-tool-for-businesses-but-experts-have-their-concerns">brings a host of new business features</a>, there is still a dark cloud looming over the new model.</p><p>Off the back of <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in">OpenAI’s accidental hack of Hugging Face</a> and the company’s subsequent efforts to improve how AI agents behave and interact, numerous cybersecurity experts have raised concerns about the model’s new ‘recurrent depth’ reasoning capabilities.</p><p>This new reasoning architecture allows the model to consider a problem multiple times before taking an action, compared to the standard chain-of-thought reasoning used in previous models.</p><h2 id="why-the-concern-about-recurrent-depth-reasoning">Why the concern about recurrent depth reasoning?</h2><p>This new level of reasoning apparently offers improved performance. OpenAI also says it has fixed its models' abilities to circumvent boundaries when performing tests by monitoring the models reasoning and ensuring the model stays aligned within the scope of its task.</p><p>During Astra’s launch event, OpenAI chief scientist Jakub Pachocki said: “We will not accept degradation in our ability to monitor model alignment beyond a certain level. We will withhold scaling until we can regain enough confidence.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>But numerous experts believe that the lessons of the Hugging Face incident have not yet been learned, and the model has been released without adequate testing on Astra’s reasoning and monitoring. </p><p>After all, no one thought one of <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal">OpenAI’s models could set up a hidden internet-connected messaging board</a> that allowed AI agents to influence each other's behavior.</p><p>But with Astra being released into the real world, the lessons may have to be learned on the fly.</p><h3 class="article-body__section" id="section-expert-perspectives-on-openai-astra-release"><span>Expert perspectives on OpenAI Astra release</span></h3><ul><li><strong>James Blake, VP of Global Cyber Resiliency Strategy at Cohesity:</strong></li></ul><p><em>The launch of Astra is raising questions again around the safety of Frontier AI. Instead of simply asking whether a model is "safe", organisations now need to ask whether it remains safe across millions of different situations, prompts and interactions. Cyber resilience has traditionally assumed that systems and threat actors behave deterministically. AI systems don’t.</em></p><div><blockquote><p>Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible?</p></blockquote></div><p><em>Advanced models can and will continue to exhibit behaviours that emerge from their optimisation process rather than from explicit programming. We have to move beyond thinking about AI as just another software tool and find ways to ensure these systems remain observable, auditable and governable throughout their lifecycle. </em></p><p><em>The most important question we’ll need to answer in future is one of liability. Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible? The developer that trained the model? The cloud provider operating the infrastructure? Currently the answer is surprisingly unclear. It’s not just about what AI can do: it’s about who is accountable when it does something nobody expected.</em></p><ul><li><strong>Oleksandr Yaremchuk, Co-Founder & CTO at Manifold Security:</strong></li></ul><p><em>OpenAI is calling Astra its most aligned model yet, even as its chief scientist admits monitorability is getting harder as models get more capable. Evidently, Astra hides its reasoning in the majority of tested cases, and some successful attacks left no reasoning trace at all. That's the tool many organisations still use, including the labs themselves, for auditing what an agent is doing, and it's getting less reliable with every release.</em></p><div><blockquote><p>A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</p></blockquote></div><p><em>That matters because Astra isn't staying inside OpenAI's test environment. It's going to run as an agent on employee laptops and in the browser, holding real credentials, inside companies that have no way to watch what it does once it's there. A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</em></p><p><em>Labs can keep debating what these models say or refuse to say. Security teams need to stop relying on that and start monitoring what agents actually do at runtime, with the ability to shut one down mid-action. That's the only oversight left that still works once the reasoning goes quiet.</em></p><ul><li><strong>Kristin Lowery, Field CISO at Optiv:</strong></li></ul><p><em>For boards and executive leaders, the emergence of OpenAI’s Astra model highlights a broader reality: AI is no longer just a productivity issue; it is a risk management issue. </em></p><div><blockquote><p>The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace</p></blockquote></div><p><em>Just as organizations established governance for cloud adoption and digital transformation, they now need clear policies, strong oversight, and accountability for AI use.</em></p><p><em>The question is not whether AI will become more capable — it will. The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace.</em></p><ul><li><strong>Patricia Titus, Field CISO at Abnormal AI:</strong></li></ul><p><em>OpenAI crossing this threshold deserves attention. Credit where it's due, they're handling it responsibly by restricting Astra's advanced cyber capability to a small coalition rather than releasing it broadly.But this isn't one company's problem to contain.</em></p><p><em>Once a model can find and exploit unknown flaws without a human in the loop, that capability doesn't stay exclusive for long. Open-weight and modified models typically trail the frontier by only months, and that's the reality defenders have to plan around now.</em></p><div><blockquote><p>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time.</p></blockquote></div><p><em>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time. Defenders need the same shift, systems that learn what normal looks like for every identity, human, machine, or AI agent, and flag and contain the moment something deviates, at machine speed.</em></p><p><em>The window to build that is open now. It won't stay that way once this capability is common instead of rare.</em></p><ul><li><strong>Raghu Nandakumara, VP of Industry Strategy at Illumio:</strong></li></ul><p><em>With the Astra announcement, OpenAI is doubling down on monitoring the model's own behaviour – a response to the model "breakouts" seen over the past few months.</em></p><div><blockquote><p>The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</p></blockquote></div><p><em>When Anthropic announced Claude Mythos Preview, the core concern was the model falling into the wrong hands. OpenAI's answer goes further adding guardrails around the model's own reasoning and actions, regardless of the user's intent. The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</em></p><p><em>The rest of this announcement can be summarised as ‘we have a new frontier model, and it’s more capable than the last one’.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google patches multiple browser bugs including one that was under active exploitation — so update now ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Google released Chrome 152.0.7977.82/.83 for Windows, Mac, and Linux</strong></li><li><strong>Patch fixes 12 flaws, including zero‑day CVE‑2026‑85046 (type confusion in V8)</strong></li><li><strong>Sixth Chrome zero‑day this year; Chromium browsers also affected, update urged immediately</strong></li></ul><p>Google has released a new version of its Chrome <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> for Windows, Mac, and Linux, fixing a dozen of vulnerabilities. Among them is a high-severity flaw that is being actively exploited in the wild.</p><p>In a security advisory published on the Google blog on September 3, the search engine company said Chrome’s newest version is now 152.0.7977.82/.83 for Windows and Mac, and 152.0.7977.82 for Linux.</p><p>Rollout is expected to be gradual, so make sure to check if you already received it. Most of the time the update is automatic and instant and if you’re not certain, tap the three vertical dots in the top-right corner of the browser and choose Help. Navigate to About Google Chrome and there you will find the version number. </p><h2 id="running-malicious-code-remotely">Running malicious code remotely</h2><p>This patch fixes a total of 12 vulnerabilities, most of which are graded as high severity. Among them is a “type confusion in V8” bug, discovered by security researcher Salvatore Gulizia.</p><p>For his effort, Gulizia was awarded $1,000. Apparently, this bug is being actively leveraged in real-life attacks, although Google (as usual) decided not to share the juicy details until the majority of browsers are protected.</p><p>The vulnerability is tracked as CVE-2026-85046. On the National Vulnerability Database (NVD), it is described as a “type confusion in V8 in Google Chrome [that allows] a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.”</p><p>V8 is Chrome’s JavaScript engine which allows web apps and interactive websites to run in the browser. Those interested in the technical breakdown of the vulnerability can find it on <a href="https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/" target="_blank" rel="nofollow">Guzlia’s blog</a>.</p><p>You can find the full list of fixed vulnerabilities on <a href="https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html" target="_blank" rel="nofollow">this link</a>. </p><p>This is the sixth zero-day Google fixed in Chrome since the start of the year. It also affects other browsers built on Chromium, so if you’re running Edge, Brave, Opera, or Vivaldi, make sure to update to the latest version as soon as possible. </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/google-patches-multiple-browser-bugs-including-one-that-was-under-active-exploitation-so-update-now</link>
                                                                            <description>
                            <![CDATA[ Google did not share the details about the bug being actively used. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PWhL6n866rriJHC4C6KTWa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 19:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg">
                                                            <media:credit><![CDATA[Tada Images / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:description>                                                            <media:text><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:text>
                                <media:title type="plain"><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Google released Chrome 152.0.7977.82/.83 for Windows, Mac, and Linux</strong></li><li><strong>Patch fixes 12 flaws, including zero‑day CVE‑2026‑85046 (type confusion in V8)</strong></li><li><strong>Sixth Chrome zero‑day this year; Chromium browsers also affected, update urged immediately</strong></li></ul><p>Google has released a new version of its Chrome <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> for Windows, Mac, and Linux, fixing a dozen of vulnerabilities. Among them is a high-severity flaw that is being actively exploited in the wild.</p><p>In a security advisory published on the Google blog on September 3, the search engine company said Chrome’s newest version is now 152.0.7977.82/.83 for Windows and Mac, and 152.0.7977.82 for Linux.</p><p>Rollout is expected to be gradual, so make sure to check if you already received it. Most of the time the update is automatic and instant and if you’re not certain, tap the three vertical dots in the top-right corner of the browser and choose Help. Navigate to About Google Chrome and there you will find the version number. </p><h2 id="running-malicious-code-remotely">Running malicious code remotely</h2><p>This patch fixes a total of 12 vulnerabilities, most of which are graded as high severity. Among them is a “type confusion in V8” bug, discovered by security researcher Salvatore Gulizia.</p><p>For his effort, Gulizia was awarded $1,000. Apparently, this bug is being actively leveraged in real-life attacks, although Google (as usual) decided not to share the juicy details until the majority of browsers are protected.</p><p>The vulnerability is tracked as CVE-2026-85046. On the National Vulnerability Database (NVD), it is described as a “type confusion in V8 in Google Chrome [that allows] a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.”</p><p>V8 is Chrome’s JavaScript engine which allows web apps and interactive websites to run in the browser. Those interested in the technical breakdown of the vulnerability can find it on <a href="https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/" target="_blank" rel="nofollow">Guzlia’s blog</a>.</p><p>You can find the full list of fixed vulnerabilities on <a href="https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html" target="_blank" rel="nofollow">this link</a>. </p><p>This is the sixth zero-day Google fixed in Chrome since the start of the year. It also affects other browsers built on Chromium, so if you’re running Edge, Brave, Opera, or Vivaldi, make sure to update to the latest version as soon as possible. </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI warns about how good Astra model is at cracking cybersecurity, releases it anyway because it took 'years of research and big bets' ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI rolled out GPT‑6 Astra, its most advanced AI, with “critical” cyber capabilities</strong></li><li><strong>Astra can autonomously find and exploit unknown flaws; release limited to vetted Daybreak participants</strong></li><li><strong>Staggered rollout sparked user frustration; Altman apologized, promising broader access soon</strong></li></ul><p>OpenAI has begun rolling out <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">GPT-6 Astra</a>, its latest and most capable artificial intelligence model. </p><p>In an announcement published on its website, OpenAI said Astra represents a “significant step up in cyber capabilities”, meeting the company’s “Critical” threshold.</p><p>This threshold, the company explained, means that under the right circumstances, the tool can find “previously unknown security flaws and develop new ways to exploit them across many well-protected systems without a person guiding each step.”</p><h2 id="apologies-for-a-messy-rollout">Apologies for a messy rollout</h2><p>OpenAI also said Astra improves on functions such as computer use, software engineering, and science, and that it should be better at staying oriented, compared to previous versions.</p><p>Just like many of the previous models, Astra’s release has been marred with controversy. Roughly a month ago, OpenAI said the model’s “critical” cybersecurity capabilities prompted it to <a href="https://www.channelnewsasia.com/business/openai-flags-possible-critical-cybersecurity-risk-in-upcoming-model-tightens-controls-6306796" target="_blank" rel="nofollow">pause some internal development</a> and trigger safety protocols.</p><p>In response to early findings, the company scaled up certain security controls and even paused activities that do not meet its newly established security requirements. </p><p>It now decided it was time to release the model, but still not to the general public. Instead, it opted for a staggered release, giving it first to a limited group of companies participating in the Daybreak program, a cybersecurity initiative that gives vetted organizations (cybersecurity and otherwise) specialized AI tools for vulnerability research and threat detection. </p><p>This did not sit well with many ChatGPT users, especially those paying a monthly subscription. As <a href="https://www.theverge.com/ai-artificial-intelligence/990060/altman-apologizes-messy-astra-rollout" target="_blank" rel="nofollow"><em>The Verge</em></a> reported, CEO Sam Altman was apologizing, mere hours after launch, for the “messy rollout” of Astra.</p><p>Initially, all Plus, Pro, Business, and Enterprise users were supposed to gain access to Astra, as well as those accessing through OpenAI API, Microsoft Azure, and AWS Bedrock. </p><p>“We are working towards getting Astra in everyone’s hands as quickly as we can,” Altman said on X. “I know it is frustrating and I appreciate the patience. It should be quick.”</p><p><em>Via </em><a href="https://www.cnbc.com/2026/09/03/open-ai-astra-gpt-6-cyber.html" target="_blank" rel="nofollow"><em>CNBC</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-warns-about-how-good-astra-model-is-at-cracking-cybersecurity-releases-it-anyway-because-it-took-years-of-research-and-big-bets</link>
                                                                            <description>
                            <![CDATA[ GPT-6 Astra was paused a month ago for triggering safety protocols and now it's being slowly rolled out. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JV7weBTmHEVs8GrqeHEVAE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 18:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[ChatGPT]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg">
                                                            <media:credit><![CDATA[OpenAI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI GPT-6 Astra]]></media:description>                                                            <media:text><![CDATA[OpenAI GPT-6 Astra]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI GPT-6 Astra]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI rolled out GPT‑6 Astra, its most advanced AI, with “critical” cyber capabilities</strong></li><li><strong>Astra can autonomously find and exploit unknown flaws; release limited to vetted Daybreak participants</strong></li><li><strong>Staggered rollout sparked user frustration; Altman apologized, promising broader access soon</strong></li></ul><p>OpenAI has begun rolling out <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">GPT-6 Astra</a>, its latest and most capable artificial intelligence model. </p><p>In an announcement published on its website, OpenAI said Astra represents a “significant step up in cyber capabilities”, meeting the company’s “Critical” threshold.</p><p>This threshold, the company explained, means that under the right circumstances, the tool can find “previously unknown security flaws and develop new ways to exploit them across many well-protected systems without a person guiding each step.”</p><h2 id="apologies-for-a-messy-rollout">Apologies for a messy rollout</h2><p>OpenAI also said Astra improves on functions such as computer use, software engineering, and science, and that it should be better at staying oriented, compared to previous versions.</p><p>Just like many of the previous models, Astra’s release has been marred with controversy. Roughly a month ago, OpenAI said the model’s “critical” cybersecurity capabilities prompted it to <a href="https://www.channelnewsasia.com/business/openai-flags-possible-critical-cybersecurity-risk-in-upcoming-model-tightens-controls-6306796" target="_blank" rel="nofollow">pause some internal development</a> and trigger safety protocols.</p><p>In response to early findings, the company scaled up certain security controls and even paused activities that do not meet its newly established security requirements. </p><p>It now decided it was time to release the model, but still not to the general public. Instead, it opted for a staggered release, giving it first to a limited group of companies participating in the Daybreak program, a cybersecurity initiative that gives vetted organizations (cybersecurity and otherwise) specialized AI tools for vulnerability research and threat detection. </p><p>This did not sit well with many ChatGPT users, especially those paying a monthly subscription. As <a href="https://www.theverge.com/ai-artificial-intelligence/990060/altman-apologizes-messy-astra-rollout" target="_blank" rel="nofollow"><em>The Verge</em></a> reported, CEO Sam Altman was apologizing, mere hours after launch, for the “messy rollout” of Astra.</p><p>Initially, all Plus, Pro, Business, and Enterprise users were supposed to gain access to Astra, as well as those accessing through OpenAI API, Microsoft Azure, and AWS Bedrock. </p><p>“We are working towards getting Astra in everyone’s hands as quickly as we can,” Altman said on X. “I know it is frustrating and I appreciate the patience. It should be quick.”</p><p><em>Via </em><a href="https://www.cnbc.com/2026/09/03/open-ai-astra-gpt-6-cyber.html" target="_blank" rel="nofollow"><em>CNBC</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why did FulcrumSec hackers try to extort Manchester Airports Group, and what happens now the data is leaked? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Following the aftermath of the Manchester Airports Group cyberattack - <a href="https://www.techradar.com/pro/security/manchester-airports-hackers-just-posted-the-data-of-8-7-million-people-online-failed-extortion-attempt-triggers-data-dump-sale">where hackers made off with the data of 8.7 million people</a> - the hackers have now posted the entire database for sale on the dark web.</p><p>The group behind the attack, FulcrumSec, attempted to get Manchester Airports Group (MAG) to pay for the security of the database, promising that it wouldn’t be released if the company paid a settlement. But as all companies should do when faced with extortion, MAG didn’t play ball.</p><p>Now FulcrumSec wants to try and maximise the damage of the cyberattack, and has listed the database containing email addresses, phone numbers, vehicle registrations and postcodes online in the hopes a fellow hacking group will find value in the data.</p><h2 id="what-happens-when-extortion-fails-and-why-didn-t-mag-pay">What happens when extortion fails, and why didn’t MAG pay?</h2><p>In the past, when companies faced ransomware attacks or data breaches, they would sometimes quietly pay the hackers for their silence. </p><p>Companies feared serious reputational harm and loss of business would cost more in the long run than the perpetrators were asking for. But this created an incentive for hackers to carry out more attacks.</p><p>After all, if companies aren’t kicking up a fuss about being hacked or reporting the attack to the authorities, hacking groups can launch more attacks on other companies that are completely unaware of their tactics.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>In order to counter this, authorities and cyber experts from around the world issued guidance that under no circumstances should companies pay for the safe return of their data. By removing the incentive from ransomware attacks and data breaches, the hope is that hackers will get bored or not see enough ROI, and therefore stop.</p><p>But the 500GB database of data on over 8.7 million people is ripe pickings for other cybercriminals looking to launch highly specific phishing attacks or scam campaigns. While FulcrumSec may not make any money from the attack, they can seriously enhance the damage of the attack by offering the data for free for others to use.</p><p>A successful scam or phishing attack can steal banking and financial details, allowing other groups to steal even more money off the back of the attack.</p><h3 class="article-body__section" id="section-expert-perspectives-on-mag-extortion-and-customer-data"><span>Expert perspectives on MAG extortion and customer data</span></h3><ul><li><strong>Dray Agha, senior manager of security operations at Huntress:</strong></li></ul><p><em>While Manchester Airports Group followed official guidance by refusing to pay the ransom, the release of 8.7 million records creates an immediate risk for passengers.</em></p><div><blockquote><p>The release of 8.7 million records creates an immediate risk for passengers</p></blockquote></div><p><em>We expect other criminals to use this freely available database of vehicle registrations, postcodes and contact details to craft highly convincing phishing attacks.</em></p><p><em>Anyone who has used parking, lounges or Wi-Fi at these airports must treat unexpected messages about their travel with extreme caution.</em></p><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress</strong></li></ul><p><em>The "free release" model is deliberately designed to maximise harm and reputational damage as a warning to the next target. </em></p><div><blockquote><p>It's a marketing campaign aimed at every other organisation watching</p></blockquote></div><p><em>Publishing almost nine million records for free isn't just punishment for MAG it's a marketing campaign aimed at every other organisation watching.</em></p><p><em>Pay up, or your customers' data gets handed to every fraudster and scammer on the internet at no cost. Refusing to pay a ransom is the right call. But nearly nine million people are now paying a different price for a decision that was never theirs to make.</em></p><ul><li><strong>Danny Jenkins, Co Founder & CEO at ThreatLocker</strong></li></ul><p><em>Unfortunately, once data is made public, it can’t be hidden again. The most important thing consumers can do is focus on basic cyber hygiene. Use a unique password for every website, learn how to identify phishing scams, and monitor your credit report.</em></p><div><blockquote><p>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</p></blockquote></div><p><em>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</em></p><p><em>When in doubt, look up the phone number for the alleged sender yourself, rather than using a number provided in the email, and call to confirm whether the communication is genuine.</em></p><ul><li><strong>Brian Higgins, security specialist at Comparitech:</strong></li></ul><p><em>Whilst the airports breached in this attack don't appear to have had any financial data compromised the risk to affected or associated customers is very real. With so much other information freely available in the wild it is vital that airport users stay highly vigilant for some time to come.</em></p><div><blockquote><p>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends.</p></blockquote></div><p><em>Any and all unsolicited contact; whether online, by telephone or even home visit approaches, should be viewed as suspicious. Never engage until you've taken time to check credentials/veracity etc.</em></p><p><em>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends. Look for ways to increase digital and physical security like two factor authentication on Apps and devices or Smart Home tech. </em></p><p><em>When this breach was first reported by the Manchester Evening News the comments were quite telling. Affected parties were quick to identify potential vulnerabilities over and above the breach of financial and banking details. </em></p><p><em>Home addresses, vehicle registrations and time spent away from home all add up to some excellent opportunities for criminal exploitation, not to mention the usual follow-up phishing campaigns common in this type of incident.</em></p><p><em>As AI makes data aggregation swift and easy consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways. It’s no longer enough for data owning organisations to advise post-attack vigilance and turn to their backups.</em></p><p><em>Victim communities rightly expect better protected networks and systems over and above established norms. As the marketplace grows less fearful and more angry when breaches are made public we may see more emphasis on cyber crime prevention which can only be a good thing.</em></p><ul><li><strong>Denis Calderone, CTO at Suzu Labs:</strong></li></ul><p><em>The 8.7 million number is attention-grabbing, but it deserves some context. MAG has confirmed that the vast majority of those records are email addresses collected through airport WiFi sign-ups. </em></p><p><em>A much smaller subset includes phone numbers, vehicle registrations, and postcodes from customers who actually completed parking or lounge bookings.</em></p><div><blockquote><p>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first.</p></blockquote></div><p><em>No payment data, no passwords, no passport information. So despite this affecting airports, which is obviously a sensitive subject, the actual data sensitivity for most affected individuals is relatively low.</em></p><p><em>What's more interesting to us from a technical standpoint is the attack path. MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That's a pivot upstream into a data provider, not downstream into operational systems.</em></p><p><em>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.</em></p><p><em>The UK's Civil Aviation Authority has a Cyber Assessment Framework for Aviation, developed with the NCSC, that mandates strict separation between IT systems and operational technology.</em></p><p><em>We don't know whether MAG was formally operating under that framework at the time of this incident, but I would be very interested to find out. Because the segmentation appears to have held here. Flight operations, baggage handling, terminal systems, etc., all were unaffected. </em></p><p><em>The lateral movement went upstream toward a data provider, not downstream toward the systems that keep planes in the air.</em></p><ul><li><strong>Seemant Sehgal, CEO and Founder at BreachLock:</strong></li></ul><p><em>This data was initially collected because passengers needed a login, and somewhere along the way, the sensitivity of what was accumulating in that database stopped getting the same scrutiny as the network itself.</em></p><div><blockquote><p>Whoever held it for ransom understood its value better than the organization storing it did</p></blockquote></div><p><em>Vehicle registration details, postcodes, and contact information across three major airports are a profiling dataset, and whoever held it for ransom understood its value better than the organization storing it did.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-did-fulcrumsec-hackers-try-to-extort-manchester-airports-group-and-what-happens-now-the-data-is-leaked-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ After hackers failed to extort Manchester Airports Group and posted the data of nearly 9 million people online, we asked the experts what's really going on. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fRCxPaa9De9wPUPVGxjDbh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 14:57:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Airport]]></media:description>                                                            <media:text><![CDATA[Airport]]></media:text>
                                <media:title type="plain"><![CDATA[Airport]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Following the aftermath of the Manchester Airports Group cyberattack - <a href="https://www.techradar.com/pro/security/manchester-airports-hackers-just-posted-the-data-of-8-7-million-people-online-failed-extortion-attempt-triggers-data-dump-sale">where hackers made off with the data of 8.7 million people</a> - the hackers have now posted the entire database for sale on the dark web.</p><p>The group behind the attack, FulcrumSec, attempted to get Manchester Airports Group (MAG) to pay for the security of the database, promising that it wouldn’t be released if the company paid a settlement. But as all companies should do when faced with extortion, MAG didn’t play ball.</p><p>Now FulcrumSec wants to try and maximise the damage of the cyberattack, and has listed the database containing email addresses, phone numbers, vehicle registrations and postcodes online in the hopes a fellow hacking group will find value in the data.</p><h2 id="what-happens-when-extortion-fails-and-why-didn-t-mag-pay">What happens when extortion fails, and why didn’t MAG pay?</h2><p>In the past, when companies faced ransomware attacks or data breaches, they would sometimes quietly pay the hackers for their silence. </p><p>Companies feared serious reputational harm and loss of business would cost more in the long run than the perpetrators were asking for. But this created an incentive for hackers to carry out more attacks.</p><p>After all, if companies aren’t kicking up a fuss about being hacked or reporting the attack to the authorities, hacking groups can launch more attacks on other companies that are completely unaware of their tactics.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>In order to counter this, authorities and cyber experts from around the world issued guidance that under no circumstances should companies pay for the safe return of their data. By removing the incentive from ransomware attacks and data breaches, the hope is that hackers will get bored or not see enough ROI, and therefore stop.</p><p>But the 500GB database of data on over 8.7 million people is ripe pickings for other cybercriminals looking to launch highly specific phishing attacks or scam campaigns. While FulcrumSec may not make any money from the attack, they can seriously enhance the damage of the attack by offering the data for free for others to use.</p><p>A successful scam or phishing attack can steal banking and financial details, allowing other groups to steal even more money off the back of the attack.</p><h3 class="article-body__section" id="section-expert-perspectives-on-mag-extortion-and-customer-data"><span>Expert perspectives on MAG extortion and customer data</span></h3><ul><li><strong>Dray Agha, senior manager of security operations at Huntress:</strong></li></ul><p><em>While Manchester Airports Group followed official guidance by refusing to pay the ransom, the release of 8.7 million records creates an immediate risk for passengers.</em></p><div><blockquote><p>The release of 8.7 million records creates an immediate risk for passengers</p></blockquote></div><p><em>We expect other criminals to use this freely available database of vehicle registrations, postcodes and contact details to craft highly convincing phishing attacks.</em></p><p><em>Anyone who has used parking, lounges or Wi-Fi at these airports must treat unexpected messages about their travel with extreme caution.</em></p><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress</strong></li></ul><p><em>The "free release" model is deliberately designed to maximise harm and reputational damage as a warning to the next target. </em></p><div><blockquote><p>It's a marketing campaign aimed at every other organisation watching</p></blockquote></div><p><em>Publishing almost nine million records for free isn't just punishment for MAG it's a marketing campaign aimed at every other organisation watching.</em></p><p><em>Pay up, or your customers' data gets handed to every fraudster and scammer on the internet at no cost. Refusing to pay a ransom is the right call. But nearly nine million people are now paying a different price for a decision that was never theirs to make.</em></p><ul><li><strong>Danny Jenkins, Co Founder & CEO at ThreatLocker</strong></li></ul><p><em>Unfortunately, once data is made public, it can’t be hidden again. The most important thing consumers can do is focus on basic cyber hygiene. Use a unique password for every website, learn how to identify phishing scams, and monitor your credit report.</em></p><div><blockquote><p>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</p></blockquote></div><p><em>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</em></p><p><em>When in doubt, look up the phone number for the alleged sender yourself, rather than using a number provided in the email, and call to confirm whether the communication is genuine.</em></p><ul><li><strong>Brian Higgins, security specialist at Comparitech:</strong></li></ul><p><em>Whilst the airports breached in this attack don't appear to have had any financial data compromised the risk to affected or associated customers is very real. With so much other information freely available in the wild it is vital that airport users stay highly vigilant for some time to come.</em></p><div><blockquote><p>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends.</p></blockquote></div><p><em>Any and all unsolicited contact; whether online, by telephone or even home visit approaches, should be viewed as suspicious. Never engage until you've taken time to check credentials/veracity etc.</em></p><p><em>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends. Look for ways to increase digital and physical security like two factor authentication on Apps and devices or Smart Home tech. </em></p><p><em>When this breach was first reported by the Manchester Evening News the comments were quite telling. Affected parties were quick to identify potential vulnerabilities over and above the breach of financial and banking details. </em></p><p><em>Home addresses, vehicle registrations and time spent away from home all add up to some excellent opportunities for criminal exploitation, not to mention the usual follow-up phishing campaigns common in this type of incident.</em></p><p><em>As AI makes data aggregation swift and easy consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways. It’s no longer enough for data owning organisations to advise post-attack vigilance and turn to their backups.</em></p><p><em>Victim communities rightly expect better protected networks and systems over and above established norms. As the marketplace grows less fearful and more angry when breaches are made public we may see more emphasis on cyber crime prevention which can only be a good thing.</em></p><ul><li><strong>Denis Calderone, CTO at Suzu Labs:</strong></li></ul><p><em>The 8.7 million number is attention-grabbing, but it deserves some context. MAG has confirmed that the vast majority of those records are email addresses collected through airport WiFi sign-ups. </em></p><p><em>A much smaller subset includes phone numbers, vehicle registrations, and postcodes from customers who actually completed parking or lounge bookings.</em></p><div><blockquote><p>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first.</p></blockquote></div><p><em>No payment data, no passwords, no passport information. So despite this affecting airports, which is obviously a sensitive subject, the actual data sensitivity for most affected individuals is relatively low.</em></p><p><em>What's more interesting to us from a technical standpoint is the attack path. MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That's a pivot upstream into a data provider, not downstream into operational systems.</em></p><p><em>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.</em></p><p><em>The UK's Civil Aviation Authority has a Cyber Assessment Framework for Aviation, developed with the NCSC, that mandates strict separation between IT systems and operational technology.</em></p><p><em>We don't know whether MAG was formally operating under that framework at the time of this incident, but I would be very interested to find out. Because the segmentation appears to have held here. Flight operations, baggage handling, terminal systems, etc., all were unaffected. </em></p><p><em>The lateral movement went upstream toward a data provider, not downstream toward the systems that keep planes in the air.</em></p><ul><li><strong>Seemant Sehgal, CEO and Founder at BreachLock:</strong></li></ul><p><em>This data was initially collected because passengers needed a login, and somewhere along the way, the sensitivity of what was accumulating in that database stopped getting the same scrutiny as the network itself.</em></p><div><blockquote><p>Whoever held it for ransom understood its value better than the organization storing it did</p></blockquote></div><p><em>Vehicle registration details, postcodes, and contact information across three major airports are a profiling dataset, and whoever held it for ransom understood its value better than the organization storing it did.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco patches three critical vulnerabilities as part of 'comprehensive internal security review' ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Cisco patched eight IOS XR flaws, including three critical (CVE‑2026‑20274, CVE‑2026‑20279, CVE‑2026‑20212)</strong></li><li><strong>Vulnerabilities allow unauthenticated exploitation, improper access control, and crafted input execution</strong></li><li><strong>No abuse reported; patches urged, with iACL workarounds for Nexus 9000 devices using Silicon One ASIC</strong></li></ul><p>Cisco patched eight vulnerabilities affecting its IOS XR operating system, including three critical-severity ones. It urged its customers to apply the patches as soon as possible, even though it stressed that there is no evidence any of these were abused in the wild.</p><p>The company detailed its findings in two advisories published on the same day - September 2.</p><p>In the first one, it disclosed seven vulnerabilities, including two critical-severity ones: CVE-2026-20274 and CVE-2026-20279. Both carry a severity rating of 9.8/10 (critical). The former is an improper control of a resource during its lifetime flaw - a network-based, low complexity, vulnerability that requires no authentication or user interaction to be exploited. The latter is described as an improper access control vulnerability that can lead to the same consequences.</p><h2 id="fixes-and-mitigations">Fixes and mitigations</h2><p>These flaws, along with five others, affect all releases of Cisco IOS XR Software, including Cisco IOS XR7 (LNT) Software, regardless of device configuration, the company explained. There are no available workarounds, and installing the provided patch is the only way to mitigate the risk.</p><p>The third flaw, disclosed in a separate advisory, is tracked as CVE-2026-20212. Successfully exploiting this one allows attackers to connect to an affected device and send crafted input that could be executed as code, without root privileges. “The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload,” Cisco explained. </p><p>This bug affects <a href="https://www.techradar.com/best/best-network-switches" target="_blank">Cisco Nexus 9000 Series Switches</a> if they include a Silicon One ASIC, the company stressed. A possible workaround is to use infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. There is also the option of iACLs only being used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release/5294410" target="_blank" rel="nofollow"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/cisco-patches-three-critical-vulnerabilities-as-part-of-comprehensive-internal-security-review</link>
                                                                            <description>
                            <![CDATA[ A total of eight flaws were fixed, none of which were exploited in the wild. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NwtFJ9WsAyxAmKVur5Dra9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4vPx4qpVwRADJoMvv3gttX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 13:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4vPx4qpVwRADJoMvv3gttX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Valriya Zankovych]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cisco]]></media:description>                                                            <media:text><![CDATA[Cisco]]></media:text>
                                <media:title type="plain"><![CDATA[Cisco]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4vPx4qpVwRADJoMvv3gttX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Cisco patched eight IOS XR flaws, including three critical (CVE‑2026‑20274, CVE‑2026‑20279, CVE‑2026‑20212)</strong></li><li><strong>Vulnerabilities allow unauthenticated exploitation, improper access control, and crafted input execution</strong></li><li><strong>No abuse reported; patches urged, with iACL workarounds for Nexus 9000 devices using Silicon One ASIC</strong></li></ul><p>Cisco patched eight vulnerabilities affecting its IOS XR operating system, including three critical-severity ones. It urged its customers to apply the patches as soon as possible, even though it stressed that there is no evidence any of these were abused in the wild.</p><p>The company detailed its findings in two advisories published on the same day - September 2.</p><p>In the first one, it disclosed seven vulnerabilities, including two critical-severity ones: CVE-2026-20274 and CVE-2026-20279. Both carry a severity rating of 9.8/10 (critical). The former is an improper control of a resource during its lifetime flaw - a network-based, low complexity, vulnerability that requires no authentication or user interaction to be exploited. The latter is described as an improper access control vulnerability that can lead to the same consequences.</p><h2 id="fixes-and-mitigations">Fixes and mitigations</h2><p>These flaws, along with five others, affect all releases of Cisco IOS XR Software, including Cisco IOS XR7 (LNT) Software, regardless of device configuration, the company explained. There are no available workarounds, and installing the provided patch is the only way to mitigate the risk.</p><p>The third flaw, disclosed in a separate advisory, is tracked as CVE-2026-20212. Successfully exploiting this one allows attackers to connect to an affected device and send crafted input that could be executed as code, without root privileges. “The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload,” Cisco explained. </p><p>This bug affects <a href="https://www.techradar.com/best/best-network-switches" target="_blank">Cisco Nexus 9000 Series Switches</a> if they include a Silicon One ASIC, the company stressed. A possible workaround is to use infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. There is also the option of iACLs only being used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release/5294410" target="_blank" rel="nofollow"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI puts its money where its mouth is, offers $1 billion in AI credits to cyber defenders ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI launched </strong><em><strong>Daybreak for Frontline Defenders</strong></em><strong>, offering $1B in credits for resource‑constrained security orgs</strong></li><li><strong>Priority goes to essential services, governments, banks, nonprofits, and open‑source maintainers</strong></li><li><strong>Initiative includes training, partnerships, and a water‑sector pilot with MS‑ISCA for local defenders</strong></li></ul><p>OpenAI is offering a billion dollars in credits to security organizations who want to use its Daybreak initiative but cannot afford it.</p><p>Daybreak is a cybersecurity program that provides vetted defenders with specialized <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI tools</a> and models. It was introduced in May this year, and later expanded into two tiers - Blue, and Red. Blue is the entry-level tier, providing a general-purpose model with custom-tailored safeguards. Red, on the other hand, offers a more purpose-trained cybersecurity model and almost no safeguards.</p><p>According to OpenAI, “thousands of defenders across 2,000 approved organizations and workspaces” already use Daybreak, including cybersecurity companies, defense organizations, and law enforcement agencies.</p><h2 id="who-gets-priority">Who gets priority?</h2><p>But these models cost money, and to make sure more businesses can access them, OpenAI announced, “Daybreak for Frontline Defenders”, a project where defenders can apply and receive credits for AI tokens. Even though the company announced it as a global initiative, it seems that US businesses will be the first to take advantage of it:</p><p>“OpenAI is committing $1 billion in subsidized Daybreak access to help resource-constrained cyber defenders, starting with the United States, put frontier AI to work, targeting it to be consumed over the next six months,” the company said in an announcement blog.</p><p>Businesses operating essential services such as water and wastewater systems, and electric grid operators, will get priority, OpenAI said. Then come state and local governments, community and regional banks, nonprofits, open-source maintainers, and then “other organizations with limited security resources.”</p><p>The subsidy is not just about using the models, though. OpenAI also said it will be increasing hands-on support for frontline defenders, training, and new partnerships. </p><p>On top of all that, OpenAI also announced a public sector, water-focused pilot with the Multi-State Information Sharing and Analysis Center (MS-ISCA) to train and support local, tribal, and territorial defenders.</p><p>“The pilot will pair Daybreak access with guided training and hands-on assistance for an initial group of public sector and water system defenders, helping them validate and prioritize findings, coordinate remediation, and develop a repeatable approach that can be expanded over time,” the announcement concluded.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-puts-its-money-where-its-mouth-is-offers-usd1-billion-in-ai-credits-to-cyber-defenders</link>
                                                                            <description>
                            <![CDATA[ Want to use Daybreak but cannot afford it? You can now apply for a subsidy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">t2rShP2332cHQ4q6yU7QA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6whQhAYA48xb8xVGQ3HNyX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 12:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6whQhAYA48xb8xVGQ3HNyX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/SPOA Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ChatGPT logo on a smartphone.]]></media:description>                                                            <media:text><![CDATA[ChatGPT logo on a smartphone.]]></media:text>
                                <media:title type="plain"><![CDATA[ChatGPT logo on a smartphone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6whQhAYA48xb8xVGQ3HNyX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI launched </strong><em><strong>Daybreak for Frontline Defenders</strong></em><strong>, offering $1B in credits for resource‑constrained security orgs</strong></li><li><strong>Priority goes to essential services, governments, banks, nonprofits, and open‑source maintainers</strong></li><li><strong>Initiative includes training, partnerships, and a water‑sector pilot with MS‑ISCA for local defenders</strong></li></ul><p>OpenAI is offering a billion dollars in credits to security organizations who want to use its Daybreak initiative but cannot afford it.</p><p>Daybreak is a cybersecurity program that provides vetted defenders with specialized <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI tools</a> and models. It was introduced in May this year, and later expanded into two tiers - Blue, and Red. Blue is the entry-level tier, providing a general-purpose model with custom-tailored safeguards. Red, on the other hand, offers a more purpose-trained cybersecurity model and almost no safeguards.</p><p>According to OpenAI, “thousands of defenders across 2,000 approved organizations and workspaces” already use Daybreak, including cybersecurity companies, defense organizations, and law enforcement agencies.</p><h2 id="who-gets-priority">Who gets priority?</h2><p>But these models cost money, and to make sure more businesses can access them, OpenAI announced, “Daybreak for Frontline Defenders”, a project where defenders can apply and receive credits for AI tokens. Even though the company announced it as a global initiative, it seems that US businesses will be the first to take advantage of it:</p><p>“OpenAI is committing $1 billion in subsidized Daybreak access to help resource-constrained cyber defenders, starting with the United States, put frontier AI to work, targeting it to be consumed over the next six months,” the company said in an announcement blog.</p><p>Businesses operating essential services such as water and wastewater systems, and electric grid operators, will get priority, OpenAI said. Then come state and local governments, community and regional banks, nonprofits, open-source maintainers, and then “other organizations with limited security resources.”</p><p>The subsidy is not just about using the models, though. OpenAI also said it will be increasing hands-on support for frontline defenders, training, and new partnerships. </p><p>On top of all that, OpenAI also announced a public sector, water-focused pilot with the Multi-State Information Sharing and Analysis Center (MS-ISCA) to train and support local, tribal, and territorial defenders.</p><p>“The pilot will pair Daybreak access with guided training and hands-on assistance for an initial group of public sector and water system defenders, helping them validate and prioritize findings, coordinate remediation, and develop a repeatable approach that can be expanded over time,” the announcement concluded.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IT helpdesk impersonation hits Microsoft Teams once again, with the hackers hiding their activity within legitimate tools ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft warns of Teams‑based campaign where attackers impersonate IT staff</strong></li><li><strong>Victims tricked into granting remote access, leading to malware, lateral movement, and ransomware</strong></li><li><strong>Defenses: verify support contacts, train staff, harden Teams, and use Defender Safe Links/ZAP</strong></li></ul><p>Microsoft is warning about an ongoing hacking campaign that starts with a Teams message and ends with a ransomware infection and data theft.</p><p>In a new in-depth report published on the Microsoft blog, it was said that unnamed threat actors were reaching out to their targets at various enterprises via a <a href="https://www.techradar.com/best/best-online-collaboration-tools" target="_blank">Teams chat</a>, while impersonating IT staff.</p><p>They were coercing their victims into granting remote access via screen sharing or <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote monitoring and management tools</a> and once received, used their access to install malware loaders and various other implants.</p><h2 id="how-to-defend-against-teams-borne-phishing">How to defend against Teams-borne phishing</h2><p>The malware was just the first stage of the attack. Subsequent stages include host reconnaissance, security-product and virtualization discovery, and “periodic desktop screen capture”. In other words - mapping out the landscape and conducting espionage.</p><p>The crooks would then enumerate domain accounts, servers, and users, through native tools and Active Directory Service Interfaces (ADSI) queries and begin moving laterally.</p><p>The final step includes identifying and extracting valuable data, followed by a ransomware infection.</p><p>Microsoft does not name the perpetrators, and mostly refers to them as “threat actors”. It makes sense, since the “fake IT support via Teams” technique is being used by multiple groups at this moment. Russia’s Cozy Bear, FIN7, and Storm-1811 are probably the most obvious examples.</p><p>The world’s biggest extortionists - ShinyHunters - are also known to use Teams to trick victims into granting access, but this group rarely deploys an encryptor and instead just focuses on data exfiltration.</p><p>Whoever the attackers are, and whoever they’re after, one thing is for certain - the risk in the enterprise environment has never been greater. </p><p>That is why Microsoft advises reinforcing user education by establishing internal helpdesk authentication phrases, and by training employees to recognize external-tenant indicators.</p><p>The company also urges enterprises to verify unsolicited support contact, and to harden Microsoft Teams and email against social engineering. “Use Microsoft Defender for Office 365 with Safe Links and Zero-hour auto purge (ZAP) so malicious messages and URLs are neutralized at time of click and removed after delivery,” Microsoft urges.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/it-helpdesk-impersonation-hits-microsoft-teams-once-again-with-the-hackers-hiding-their-activity-within-legitimate-tools</link>
                                                                            <description>
                            <![CDATA[ Microsoft is warning about an ongoing scam campaign starting in Teams. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QAnBBRikxHpmReRRcBoNhU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D4YBMfcEsNT7BhaNJJgm2A-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 16:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/D4YBMfcEsNT7BhaNJJgm2A-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pexels]]></media:description>                                                            <media:text><![CDATA[Collaboration in an office.]]></media:text>
                                <media:title type="plain"><![CDATA[Collaboration in an office.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D4YBMfcEsNT7BhaNJJgm2A-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns of Teams‑based campaign where attackers impersonate IT staff</strong></li><li><strong>Victims tricked into granting remote access, leading to malware, lateral movement, and ransomware</strong></li><li><strong>Defenses: verify support contacts, train staff, harden Teams, and use Defender Safe Links/ZAP</strong></li></ul><p>Microsoft is warning about an ongoing hacking campaign that starts with a Teams message and ends with a ransomware infection and data theft.</p><p>In a new in-depth report published on the Microsoft blog, it was said that unnamed threat actors were reaching out to their targets at various enterprises via a <a href="https://www.techradar.com/best/best-online-collaboration-tools" target="_blank">Teams chat</a>, while impersonating IT staff.</p><p>They were coercing their victims into granting remote access via screen sharing or <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote monitoring and management tools</a> and once received, used their access to install malware loaders and various other implants.</p><h2 id="how-to-defend-against-teams-borne-phishing">How to defend against Teams-borne phishing</h2><p>The malware was just the first stage of the attack. Subsequent stages include host reconnaissance, security-product and virtualization discovery, and “periodic desktop screen capture”. In other words - mapping out the landscape and conducting espionage.</p><p>The crooks would then enumerate domain accounts, servers, and users, through native tools and Active Directory Service Interfaces (ADSI) queries and begin moving laterally.</p><p>The final step includes identifying and extracting valuable data, followed by a ransomware infection.</p><p>Microsoft does not name the perpetrators, and mostly refers to them as “threat actors”. It makes sense, since the “fake IT support via Teams” technique is being used by multiple groups at this moment. Russia’s Cozy Bear, FIN7, and Storm-1811 are probably the most obvious examples.</p><p>The world’s biggest extortionists - ShinyHunters - are also known to use Teams to trick victims into granting access, but this group rarely deploys an encryptor and instead just focuses on data exfiltration.</p><p>Whoever the attackers are, and whoever they’re after, one thing is for certain - the risk in the enterprise environment has never been greater. </p><p>That is why Microsoft advises reinforcing user education by establishing internal helpdesk authentication phrases, and by training employees to recognize external-tenant indicators.</p><p>The company also urges enterprises to verify unsolicited support contact, and to harden Microsoft Teams and email against social engineering. “Use Microsoft Defender for Office 365 with Safe Links and Zero-hour auto purge (ZAP) so malicious messages and URLs are neutralized at time of click and removed after delivery,” Microsoft urges.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Clicking 'Allow' on a Google and Microsoft permission screens could give hackers access to your entire account, FBI warns ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>FBI warns of rising </strong><em><strong>OAuth consent phishing</strong></em><strong> attacks exploiting legitimate app permissions</strong></li><li><strong>Victims tricked into granting malicious apps access, enabling email reading and sending</strong></li><li><strong>Password changes don’t help; users must revoke tokens in app security settings</strong></li></ul><p>Hackers found a way to access your data, read your messages, and even send emails to your contacts, without ever needing your password or other login credentials. All they need from you is a single click on a completely legitimate, well-known platform.</p><p>The technique is called “OAuth consent phishing”. It’s been around for more than a year and it’s gotten popular to a point where even the FBI is taking note. Earlier this week, the law enforcement agency issued a new public service announcement, via its Internet Crime Complaint Center (IC3), warning Americans about the threat.</p><p>OAuth (Open Authorization) is an internet standard that allows users to give apps access to their account on another service, without giving the app their <a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> for that service. For example, when users install a new app, they have the “Continue with Google” option. When they click it, they are asked if they allow the app to access their email. If they approve, Google gives that app a special access token, which allows the app to access the user’s Google account without ever seeing the password.</p><h2 id="pulling-off-an-oauth-attack">Pulling off an OAuth attack</h2><p>So, to pull off an OAuth attack, the threat actor must first trick Google (or Microsoft, or any other company providing the service) and get their (malicious) app registered on the platform. Then they would reach out to their target via instant messaging, while impersonating government officials, media, and other publicly known personalities, and sharing a link to what appears to be a document.</p><p>The link redirects the victim to a legitimate service (for example, Google), where they are asked to grant permissions to the malicious app. If they approve, the attackers gain access to their email accounts with which they can do almost anything.</p><p>To make matters worse, simply changing the password does not fix the issue. The only way to eliminate the threat is to revoke the access token that was given, which can be done in the application security settings.</p><p>The FBI did not say who the threat actors were or who they were targeting, other than they were “prominent victims”. Their family members were being targeted, as well.</p><p><em>Via </em><a href="https://cybernews.com/news/oauth-consent-phishing-fbi-warning-account-takeover/" target="_blank"><em>The Record</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/clicking-allow-on-a-google-and-microsoft-permission-screens-could-give-hackers-access-to-your-entire-account-fbi-warns</link>
                                                                            <description>
                            <![CDATA[ OAuth consent phishing is a thing and the FBI is worried. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pWbGg4PydfXBEVQetdDJBV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 14:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay/Tumisu]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing]]></media:description>                                                            <media:text><![CDATA[Phishing]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>FBI warns of rising </strong><em><strong>OAuth consent phishing</strong></em><strong> attacks exploiting legitimate app permissions</strong></li><li><strong>Victims tricked into granting malicious apps access, enabling email reading and sending</strong></li><li><strong>Password changes don’t help; users must revoke tokens in app security settings</strong></li></ul><p>Hackers found a way to access your data, read your messages, and even send emails to your contacts, without ever needing your password or other login credentials. All they need from you is a single click on a completely legitimate, well-known platform.</p><p>The technique is called “OAuth consent phishing”. It’s been around for more than a year and it’s gotten popular to a point where even the FBI is taking note. Earlier this week, the law enforcement agency issued a new public service announcement, via its Internet Crime Complaint Center (IC3), warning Americans about the threat.</p><p>OAuth (Open Authorization) is an internet standard that allows users to give apps access to their account on another service, without giving the app their <a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> for that service. For example, when users install a new app, they have the “Continue with Google” option. When they click it, they are asked if they allow the app to access their email. If they approve, Google gives that app a special access token, which allows the app to access the user’s Google account without ever seeing the password.</p><h2 id="pulling-off-an-oauth-attack">Pulling off an OAuth attack</h2><p>So, to pull off an OAuth attack, the threat actor must first trick Google (or Microsoft, or any other company providing the service) and get their (malicious) app registered on the platform. Then they would reach out to their target via instant messaging, while impersonating government officials, media, and other publicly known personalities, and sharing a link to what appears to be a document.</p><p>The link redirects the victim to a legitimate service (for example, Google), where they are asked to grant permissions to the malicious app. If they approve, the attackers gain access to their email accounts with which they can do almost anything.</p><p>To make matters worse, simply changing the password does not fix the issue. The only way to eliminate the threat is to revoke the access token that was given, which can be done in the application security settings.</p><p>The FBI did not say who the threat actors were or who they were targeting, other than they were “prominent victims”. Their family members were being targeted, as well.</p><p><em>Via </em><a href="https://cybernews.com/news/oauth-consent-phishing-fbi-warning-account-takeover/" target="_blank"><em>The Record</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thomson Reuters hit by cyberattack that saw court documents across 11 states accessed by a hacker ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Thomson Reuters confirmed March 2026 breach of its C‑Track court management system</strong></li><li><strong>Incident affected courts in 11 US states, Ontario, and the US Virgin Islands</strong></li><li><strong>No operational disruption; scope of exposed records still under investigation, no misuse reported yet</strong></li></ul><p>Thomson Reuters, the IT company behind the Reuters news agency, suffered a cyberattack a few months ago, exposing certain court documents to the attackers. In a brief announcement published earlier this week, it seems Thomson Reuters only noticed the intrusion now, months after it was already over.</p><p>Here is what happened: Thomson Reuters operates a court case-management system called C-Track. It is a tool used by different courts to manage things like cases, filings, hearings, and schedules. It is used by courts in several US states, the US Virgin Islands, as well as Ontario, Canada.</p><p>On June 30, 2026, Thomson Reuters detected unauthorized activity in one of its cloud environments, prompting an investigation which later determined that an unauthorized threat actor broke in and obtained some C-Track files. This happened in March 2026. </p><h2 id="investigation-underway">Investigation underway</h2><p>So far, the incident is confirmed to have taken place across 11 US states (Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming), the U.S. Virgin Islands, and Ontario, Canada, exposing court records and personal information. Ontario's three Chief Justices confirmed it, as well, saying Thomson Reuters notified Ontario's Ministry of the Attorney General on July 23.</p><p>A more detailed investigation is currently underway, and all relevant authorities have been notified, it was said. At press time, Thomson Reuters did not yet determine exactly what information was accessed, or how many people were affected. The good news, however, is that there is currently no evidence of identity theft resulting from the incident, and there is no indication that systems handling court-related financial transactions were affected. </p><p>C-Track itself remains operational, as well. No threat actors have yet claimed responsibility for the attack or threatened to leak the files to the dark web.</p><p>"There has been no operational disruption to C-Track as a result of this incident," a Thomson Reuters spokesperson said. "Our products and services remain fully operational and are safe ​to continue to use. Independent ​cybersecurity experts assisted in ⁠the investigation and validated the remediation measures implemented."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/thomson-reuters-hit-by-cyberattack-that-saw-court-documents-across-11-states-accessed-by-a-hacker</link>
                                                                            <description>
                            <![CDATA[ A threat actor accessed C-Track files, compromised a cloud environment, and accessed court records across 11 states. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m8aiHByXqAA9YTCGGbFHxY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 14:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Thomson Reuters confirmed March 2026 breach of its C‑Track court management system</strong></li><li><strong>Incident affected courts in 11 US states, Ontario, and the US Virgin Islands</strong></li><li><strong>No operational disruption; scope of exposed records still under investigation, no misuse reported yet</strong></li></ul><p>Thomson Reuters, the IT company behind the Reuters news agency, suffered a cyberattack a few months ago, exposing certain court documents to the attackers. In a brief announcement published earlier this week, it seems Thomson Reuters only noticed the intrusion now, months after it was already over.</p><p>Here is what happened: Thomson Reuters operates a court case-management system called C-Track. It is a tool used by different courts to manage things like cases, filings, hearings, and schedules. It is used by courts in several US states, the US Virgin Islands, as well as Ontario, Canada.</p><p>On June 30, 2026, Thomson Reuters detected unauthorized activity in one of its cloud environments, prompting an investigation which later determined that an unauthorized threat actor broke in and obtained some C-Track files. This happened in March 2026. </p><h2 id="investigation-underway">Investigation underway</h2><p>So far, the incident is confirmed to have taken place across 11 US states (Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming), the U.S. Virgin Islands, and Ontario, Canada, exposing court records and personal information. Ontario's three Chief Justices confirmed it, as well, saying Thomson Reuters notified Ontario's Ministry of the Attorney General on July 23.</p><p>A more detailed investigation is currently underway, and all relevant authorities have been notified, it was said. At press time, Thomson Reuters did not yet determine exactly what information was accessed, or how many people were affected. The good news, however, is that there is currently no evidence of identity theft resulting from the incident, and there is no indication that systems handling court-related financial transactions were affected. </p><p>C-Track itself remains operational, as well. No threat actors have yet claimed responsibility for the attack or threatened to leak the files to the dark web.</p><p>"There has been no operational disruption to C-Track as a result of this incident," a Thomson Reuters spokesperson said. "Our products and services remain fully operational and are safe ​to continue to use. Independent ​cybersecurity experts assisted in ⁠the investigation and validated the remediation measures implemented."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft wants to make Windows 11 'secure by default' — but some gamers are up in arms about this security feature that 'wrecks' their frame rates ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft is rolling out a new security feature for Windows 11</strong></li><li><strong>Memory integrity provides stronger defenses for a crucial part of the operating system, and it's being automatically enabled</strong></li><li><strong>Some gamers say the feature hampers gaming frame rates considerably, and they're not happy</strong></li></ul><p>Windows 11 is getting its security bolstered with a feature that's being automatically enabled, but which comes at a cost that some PC gamers don't want to pay — and this is proving quite the controversy on social media.</p><p><a href="https://www.theverge.com/news/988056/microsoft-windows-11-memory-integrity-rollout-october-2026" target="_blank">The Verge reports</a> that <a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/expanding-memory-integrity-protection-across-windows-devices/4551984" target="_blank">Microsoft has announced</a> that it's rolling out the enablement of memory integrity protection across eligible Windows 11 PCs, and that this is because "security works best when protection is built in, not bolted on".</p><p>Microsoft explains: "More devices will soon receive stronger protection by default, with no additional setup required. Windows quality updates will begin enabling memory integrity protection on eligible devices.</p><p>"If not already enabled, these updates will also enable VBS [Virtualization Based Security], helping make additional security capabilities available and reflecting our commitment to making Windows secure by design and secure by default."</p><p>The idea is to tighten security for Windows 11's kernel-mode drivers, a core aspect of the OS with direct access to the system's hardware, and there can be no argument that this additional protection gives host PCs tougher defenses and makes them more difficult to exploit. So why the controversy? Let's dive into the pros and cons of what's going on here.</p><h2 id="analysis-a-divisive-move-but-we-can-39-t-ignore-that-the-threat-landscape-is-changing">Analysis: a divisive move — but we can't ignore that the threat landscape is changing</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2560px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="z39yxFuJJMCgwMhbV8vNcf" name="person-checking-gaming-pc" alt="Gamer at desk typing on gaming keyboard in front of PC monitor" src="https://cdn.mos.cms.futurecdn.net/z39yxFuJJMCgwMhbV8vNcf.jpg" mos="" align="middle" fullscreen="" width="2560" height="1440" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>In Microsoft's view, this is a no-brainer: stronger security is being rolled out to Windows 11 devices, or at least those which are eligible (older PCs may not be). However, PCs configured via group policy not to use memory integrity, or machines where it's been disabled before, won't have the feature forced on them.</p><p>Other supported PCs will get memory integrity (and VBS, because it's required for memory integrity) turned on automatically by Windows 11, and this is where some gamers are up in arms. VBS has a long history of being a thorn in the side for gamers, with the feature being linked to frame rate losses.</p><p>How much of a headwind does this cause for <a href="https://www.techradar.com/news/best-pc-games">PC games</a>? Well, therein lies a big part of the issue, because it's difficult to pin that down exactly, and as ever, it's bound to vary depending on your PC's exact hardware and system configuration.</p><p>Some gamers observe frame rate hits of approaching 10%, while others say the impact isn't noticeable at all. There's a lot of back-and-forth on Reddit arguing about the extent of any slowdown, and here's a typical exchange:</p><p><a href="https://www.reddit.com/r/pcmasterrace/comments/1w564ds/comment/p7cwuhm/" target="_blank">One Redditor notes</a>: "HVCI [memory integrity] is a great security feature, and the performance impact on newer platforms (to which this automatic switch will apply) is negligible."</p><p><a href="https://www.reddit.com/r/pcmasterrace/comments/1w564ds/comment/p7d074c/" target="_blank">Another replies</a>: "It ain't negligible. 9800x3d, 5080, ddr5 6000 cl28 and my 1% lows get wrecked with this feature on. Way smoother disabled."</p><p>This isn't just about frames per second performance for some gamers, then, as there are also accusations of it affecting the lowest troughs (bottom 1%) that the frame rate hits (meaning the game suffers more stuttering at times and generally feels jerkier).</p><p>As the first comment points out, though, the likelihood <em>should</em> be that a more modern PC won't feel much of a hit (if anything). The gaming rigs that might see more of a spanner in the frame rate works are those which are older, but still modern enough to get the auto-enablement of memory integrity. In other words, a collection of PCs which are on the outer fringes of that compatibility limit (older machines, but not too old to avoid the feature rollout).</p><p>Of course, even those PC owners can always turn off memory integrity. The major beef for some is that they remember that Microsoft got into trouble for <a href="https://www.techradar.com/news/windows-11-could-be-stealth-nerfing-graphics-cards-even-the-rtx-4090">automatically switching on VBS in the past</a> in a quiet, under-the-radar manner — and the question now will be whether gamers realize that this feature has been enabled alongside memory integrity.</p><p>In all honesty, when I saw what Microsoft was doing here and fired up Reddit to test the temperature of the reactions, I was expecting nothing short of a flamethrower being turned on the software giant. However, the feedback is split quite evenly between the haters — or those who disapprove at least — and users who are applauding Microsoft for this deployment.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:6000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KpMfF4cvQKAj9Tuqhwb3Uc" name="GettyImages-2198041148 copy" alt="Man and woman arguing" src="https://cdn.mos.cms.futurecdn.net/KpMfF4cvQKAj9Tuqhwb3Uc.jpg" mos="" align="middle" fullscreen="" width="6000" height="3375" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images/Focus Pixel Art)</span></figcaption></figure><p>Here are a couple of further examples from either <a href="https://www.reddit.com/r/pcmasterrace/comments/1w564ds/comment/p7ctwqy/" target="_blank">side of the fence</a>: "Apparently a controversial opinion, but systems that are for everyone should be failsafe, and that includes the most secure option being the default. There should be an option to disable security to get higher performance, but most secure should be the default."</p><p><a href="https://www.reddit.com/r/pcmasterrace/comments/1w564ds/comment/p7ekqui/" target="_blank">Juxtaposed with this</a>: "Already have memory integrity turned off as this 'feature' already hits gaming, I've used Windows without memory integrity for decades I think I'll be ok."</p><p>I must admit I'm inclined to agree with Microsoft's decision here — providing that when it happens, Windows 11 is clear on informing the user, so they can reverse the change if they aren't happy with it.</p><p>I think part of what Microsoft is doing here is keeping one eye on the future in terms of the difference AI might make to the security of Windows 11 PCs.</p><p>I keep hearing about how AI is already driving new threats and exploits, and so the kernel defenses that are being brought into play here may not have been quite as necessary in the past — as the last Reddit post I highlighted indicates — but they may be very much needed before too long. <a href="https://www.techradar.com/pro/ai-created-malware-is-on-the-rise-heres-what-your-business-needs-to-stay-safe">AI is accelerating the development of new threats</a> considerably, and making it easier for anyone to becoming a peddler of malware, so Microsoft likely feels the pressure to act.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/computing/windows/microsoft-wants-to-make-windows-11-secure-by-default-but-some-gamers-are-up-in-arms-about-this-security-feature-that-wrecks-their-frame-rates</link>
                                                                            <description>
                            <![CDATA[ Some gamers are up in arms, while others believe that this security feature is a must-have for keeping their PC safe. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tztex4zTN6unkUuH4eaxYH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Kvd2C5GUQeqhGqTh6M3w66-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 12:12:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Darren Allan ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Kvd2C5GUQeqhGqTh6M3w66-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Man upset at gaming PC, resting head on arms]]></media:description>                                                            <media:text><![CDATA[Man upset at gaming PC, resting head on arms]]></media:text>
                                <media:title type="plain"><![CDATA[Man upset at gaming PC, resting head on arms]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Kvd2C5GUQeqhGqTh6M3w66-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft is rolling out a new security feature for Windows 11</strong></li><li><strong>Memory integrity provides stronger defenses for a crucial part of the operating system, and it's being automatically enabled</strong></li><li><strong>Some gamers say the feature hampers gaming frame rates considerably, and they're not happy</strong></li></ul><p>Windows 11 is getting its security bolstered with a feature that's being automatically enabled, but which comes at a cost that some PC gamers don't want to pay — and this is proving quite the controversy on social media.</p><p><a href="https://www.theverge.com/news/988056/microsoft-windows-11-memory-integrity-rollout-october-2026" target="_blank">The Verge reports</a> that <a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/expanding-memory-integrity-protection-across-windows-devices/4551984" target="_blank">Microsoft has announced</a> that it's rolling out the enablement of memory integrity protection across eligible Windows 11 PCs, and that this is because "security works best when protection is built in, not bolted on".</p><p>Microsoft explains: "More devices will soon receive stronger protection by default, with no additional setup required. Windows quality updates will begin enabling memory integrity protection on eligible devices.</p><p>"If not already enabled, these updates will also enable VBS [Virtualization Based Security], helping make additional security capabilities available and reflecting our commitment to making Windows secure by design and secure by default."</p><p>The idea is to tighten security for Windows 11's kernel-mode drivers, a core aspect of the OS with direct access to the system's hardware, and there can be no argument that this additional protection gives host PCs tougher defenses and makes them more difficult to exploit. So why the controversy? Let's dive into the pros and cons of what's going on here.</p><h2 id="analysis-a-divisive-move-but-we-can-39-t-ignore-that-the-threat-landscape-is-changing">Analysis: a divisive move — but we can't ignore that the threat landscape is changing</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2560px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="z39yxFuJJMCgwMhbV8vNcf" name="person-checking-gaming-pc" alt="Gamer at desk typing on gaming keyboard in front of PC monitor" src="https://cdn.mos.cms.futurecdn.net/z39yxFuJJMCgwMhbV8vNcf.jpg" mos="" align="middle" fullscreen="" width="2560" height="1440" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>In Microsoft's view, this is a no-brainer: stronger security is being rolled out to Windows 11 devices, or at least those which are eligible (older PCs may not be). However, PCs configured via group policy not to use memory integrity, or machines where it's been disabled before, won't have the feature forced on them.</p><p>Other supported PCs will get memory integrity (and VBS, because it's required for memory integrity) turned on automatically by Windows 11, and this is where some gamers are up in arms. VBS has a long history of being a thorn in the side for gamers, with the feature being linked to frame rate losses.</p><p>How much of a headwind does this cause for <a href="https://www.techradar.com/news/best-pc-games">PC games</a>? Well, therein lies a big part of the issue, because it's difficult to pin that down exactly, and as ever, it's bound to vary depending on your PC's exact hardware and system configuration.</p><p>Some gamers observe frame rate hits of approaching 10%, while others say the impact isn't noticeable at all. There's a lot of back-and-forth on Reddit arguing about the extent of any slowdown, and here's a typical exchange:</p><p><a href="https://www.reddit.com/r/pcmasterrace/comments/1w564ds/comment/p7cwuhm/" target="_blank">One Redditor notes</a>: "HVCI [memory integrity] is a great security feature, and the performance impact on newer platforms (to which this automatic switch will apply) is negligible."</p><p><a href="https://www.reddit.com/r/pcmasterrace/comments/1w564ds/comment/p7d074c/" target="_blank">Another replies</a>: "It ain't negligible. 9800x3d, 5080, ddr5 6000 cl28 and my 1% lows get wrecked with this feature on. Way smoother disabled."</p><p>This isn't just about frames per second performance for some gamers, then, as there are also accusations of it affecting the lowest troughs (bottom 1%) that the frame rate hits (meaning the game suffers more stuttering at times and generally feels jerkier).</p><p>As the first comment points out, though, the likelihood <em>should</em> be that a more modern PC won't feel much of a hit (if anything). The gaming rigs that might see more of a spanner in the frame rate works are those which are older, but still modern enough to get the auto-enablement of memory integrity. In other words, a collection of PCs which are on the outer fringes of that compatibility limit (older machines, but not too old to avoid the feature rollout).</p><p>Of course, even those PC owners can always turn off memory integrity. The major beef for some is that they remember that Microsoft got into trouble for <a href="https://www.techradar.com/news/windows-11-could-be-stealth-nerfing-graphics-cards-even-the-rtx-4090">automatically switching on VBS in the past</a> in a quiet, under-the-radar manner — and the question now will be whether gamers realize that this feature has been enabled alongside memory integrity.</p><p>In all honesty, when I saw what Microsoft was doing here and fired up Reddit to test the temperature of the reactions, I was expecting nothing short of a flamethrower being turned on the software giant. However, the feedback is split quite evenly between the haters — or those who disapprove at least — and users who are applauding Microsoft for this deployment.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:6000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KpMfF4cvQKAj9Tuqhwb3Uc" name="GettyImages-2198041148 copy" alt="Man and woman arguing" src="https://cdn.mos.cms.futurecdn.net/KpMfF4cvQKAj9Tuqhwb3Uc.jpg" mos="" align="middle" fullscreen="" width="6000" height="3375" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images/Focus Pixel Art)</span></figcaption></figure><p>Here are a couple of further examples from either <a href="https://www.reddit.com/r/pcmasterrace/comments/1w564ds/comment/p7ctwqy/" target="_blank">side of the fence</a>: "Apparently a controversial opinion, but systems that are for everyone should be failsafe, and that includes the most secure option being the default. There should be an option to disable security to get higher performance, but most secure should be the default."</p><p><a href="https://www.reddit.com/r/pcmasterrace/comments/1w564ds/comment/p7ekqui/" target="_blank">Juxtaposed with this</a>: "Already have memory integrity turned off as this 'feature' already hits gaming, I've used Windows without memory integrity for decades I think I'll be ok."</p><p>I must admit I'm inclined to agree with Microsoft's decision here — providing that when it happens, Windows 11 is clear on informing the user, so they can reverse the change if they aren't happy with it.</p><p>I think part of what Microsoft is doing here is keeping one eye on the future in terms of the difference AI might make to the security of Windows 11 PCs.</p><p>I keep hearing about how AI is already driving new threats and exploits, and so the kernel defenses that are being brought into play here may not have been quite as necessary in the past — as the last Reddit post I highlighted indicates — but they may be very much needed before too long. <a href="https://www.techradar.com/pro/ai-created-malware-is-on-the-rise-heres-what-your-business-needs-to-stay-safe">AI is accelerating the development of new threats</a> considerably, and making it easier for anyone to becoming a peddler of malware, so Microsoft likely feels the pressure to act.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Only one in five UK CEOs say their cyber insurance will cover the full cost of a cyberattack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>22% expect their policy to offer full coverage, 10% expect it to fall short</strong></li><li><strong>Data breaches and reputational damage are major concerns</strong></li><li><strong>Companies should look at finances before considering operational recovery readiness</strong></li></ul><p>New research from Cohesity has revealed that many UK businesses could be significantly overestimating the protection they get from cyber insurance policies, with just one in five (22%) British CEOs believing their policy would cover both the additional costs and lost revenue that an attack could lead to.</p><p>A third expect it would cover the additional costs only, another third believe their policy is only sufficient for lost revenue, and a further one in 10 did not expect it to cover either of the two categories.</p><p>The report's conclusion is that cyber insurance in its current state for many UK businesses is only enough to transfer some of the financial risk – but not enough to restore systems, data or operations.</p><h2 id="cyber-insurance-policies-don-39-t-provide-enough-cover">Cyber insurance policies don't provide enough cover</h2><p>According to the study of 100 CEOs from large enterprises, businesses expect a cyberattack to reduce their revenue by an average of around 15%, but many businesses lack a detailed understanding of how much an attack could actually end up costing them. As many as one in five (21%) haven't even conducted business impact modelling.</p><p>Among CEOs' biggest fears are data breaches (49%), brand and reputational damage (38%), high recovery costs (36%), revenue loss (34%) and production downtime (30%). They're all either financial concerns or incidents that could lead to financial loss, and yet it's clear that policies are unlikely to offer enough cover.</p><p>With many totally unaware of the potential impacts and the extent of their policy's cover, Cohesity urges businesses to start off with calculating financial exposure and understanding what their policy covers.</p><p>After that, they can go on to prove that critical systems can actually be recovered, because without an insurance payout, this would likely not be possible.</p><p>"Organisations must be able to identify the systems and data needed to keep the business operating, assigning clear responsibility for recovery decisions and regularly testing whether critical services can be restored securely," UK&I VP Fraser Hutchison explained.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/only-one-in-five-uk-ceos-say-their-cyber-insurance-will-cover-the-full-cost-of-a-cyberattack</link>
                                                                            <description>
                            <![CDATA[ New data has revealed that only one in five CEOs expect full coverage from their cyber insurance policy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cZ3r6t6Y6FWyxjoMbJbwM5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 11:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg">
                                                            <media:credit><![CDATA[sarayut Thaneerat/ via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:description>                                                            <media:text><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:text>
                                <media:title type="plain"><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>22% expect their policy to offer full coverage, 10% expect it to fall short</strong></li><li><strong>Data breaches and reputational damage are major concerns</strong></li><li><strong>Companies should look at finances before considering operational recovery readiness</strong></li></ul><p>New research from Cohesity has revealed that many UK businesses could be significantly overestimating the protection they get from cyber insurance policies, with just one in five (22%) British CEOs believing their policy would cover both the additional costs and lost revenue that an attack could lead to.</p><p>A third expect it would cover the additional costs only, another third believe their policy is only sufficient for lost revenue, and a further one in 10 did not expect it to cover either of the two categories.</p><p>The report's conclusion is that cyber insurance in its current state for many UK businesses is only enough to transfer some of the financial risk – but not enough to restore systems, data or operations.</p><h2 id="cyber-insurance-policies-don-39-t-provide-enough-cover">Cyber insurance policies don't provide enough cover</h2><p>According to the study of 100 CEOs from large enterprises, businesses expect a cyberattack to reduce their revenue by an average of around 15%, but many businesses lack a detailed understanding of how much an attack could actually end up costing them. As many as one in five (21%) haven't even conducted business impact modelling.</p><p>Among CEOs' biggest fears are data breaches (49%), brand and reputational damage (38%), high recovery costs (36%), revenue loss (34%) and production downtime (30%). They're all either financial concerns or incidents that could lead to financial loss, and yet it's clear that policies are unlikely to offer enough cover.</p><p>With many totally unaware of the potential impacts and the extent of their policy's cover, Cohesity urges businesses to start off with calculating financial exposure and understanding what their policy covers.</p><p>After that, they can go on to prove that critical systems can actually be recovered, because without an insurance payout, this would likely not be possible.</p><p>"Organisations must be able to identify the systems and data needed to keep the business operating, assigning clear responsibility for recovery decisions and regularly testing whether critical services can be restored securely," UK&I VP Fraser Hutchison explained.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ When content is free, trust is the product ]]></title>
                                                                                                <dc:content><![CDATA[ <p>There is more technical content available today than any human being could read in a thousand lifetimes. Every topic has a dozen YouTube videos, three Substack posts, a GitHub repo, and a Reddit thread, most created in the last six months and, in many cases, technically accurate.</p><p>And yet most of the professionals I talk to say they don't know what to trust. They can't tell what’s important to read first, or which of 10 plausible answers is the one that holds up. That was true before AI, and AI has made it more true.</p><p>For most of the history of technical publishing, editing and verification were the same process, and that process was slow and expensive. Getting a book out took years. We found an author, vetted them, had them work with an editor, and checked their claims with technical reviewers.</p><p>A lot of that time went into separating what was correct and useful from what was confusing or only sounded right. It was laborious, but it meant a reader could depend on the claims on the page.</p><p>The credibility of the book, and of the publisher behind it, mattered as much as the information itself. When the cost of production drops to zero, that credibility becomes worth more, not less. Content is easier to make than ever, but without a transparent process behind it, readers have no idea where the knowledge came from or whether it holds up.</p><p>As Jasmine Sun puts it in “The Independent Writer’s Advantage in the Age of AI,” "Trust is not about information and its quality alone. It's about the messenger. It's about who says it and their track record and what they've told me before." A practitioner has confidence in a source because someone she respects has put their reputation on the line for it.</p><p>They believe what the author is saying because the publisher has a history of being right and of correcting itself when it isn't, and because the work is attributed and verifiable.</p><h2 id="expertise-is-alive-and-it-compounds">Expertise is alive, and it compounds</h2><p>The corpus matters, but it's the assurances around it that are hard to replicate, and that comes not just from the people who produce the content but from the people whose judgment vouches for it. Sometimes a creator brings their own credibility with them. Other times, the publisher spots someone unknown and lends them its own. </p><p>The art critic Dave Hickey said this about gallery owners in Air Guitar: They gain status from the famous artists they represent and share it with emerging talent who have something to offer but who haven't had the chance to earn a reputation.</p><p>Expertise is alive, and it compounds Expertise is a living thing, continuously expanding. Content starts to decay the moment it’s published, because frameworks evolve, libraries deprecate, and yesterday's best practice becomes today's <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> incident. Keeping expertise alive requires a pipeline of people who stay current and an editorial layer that notices when something has gone stale, and either retires it or calls for a fix.</p><p>That pipeline isn't something you switch on when an author has a book to ship. Content sits at the center of our platform, but we think about it in pace layers. Some advice is timeless, some moves but has a long shelf life (some of our books are still in print after nearly 50 years!), and some changes weekly.</p><p>We work with experts at each pace layer, capturing what lasts while doing our best to keep pace with an industry that seems to have changed every time we wake up.</p><p>We have relationships with hundreds of the best practitioners in the world, and our job is to keep them engaged continuously, with quick takes when something breaks, structured responses when major research drops, and live sessions on emerging topics while they're still emerging.</p><h2 id="trust-is-earnt">Trust is earnt</h2><p>An institution doesn't stamp trust onto content. In a technical community, trust is conferred in both directions. A practitioner earns standing because people who already have standing engage with her work, cite it, argue with it, and build on it. That insight was the whole idea behind PageRank, Google's first great innovation. A page mattered because other pages that mattered linked to it. Reputation works the same way.</p><p>The audience isn't just consuming reputation signals; it's generating them. When a senior engineer whose judgment others respect says out loud that something is worth reading, she spends a little of her own credibility; the author gains a little; and everyone watching recalibrates whom to trust next time.</p><p>When we put our mark on someone's work, we aren't the sole source of its credibility. We're amplifying a judgment the community is already making and adding our own track record to it. The reader who finds it reliable hands status back to the source.</p><h2 id="when-the-readers-are-machines">When the readers are machines</h2><p>Human practitioners aren't the only ones who need trusted engineering knowledge. The AI systems now sitting in every workflow, the coding and debugging agents and architecture advisors, need it just as badly since most of them are built on scraped web <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> and <a href="https://www.techradar.com/pro/best-it-documentation-tool">documentation</a> that was stale before it was ever indexed. They're fluent, but they're wrong often enough that you can't just take their word for it.</p><p>The stakes grow with <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> increasingly being used to generate not just provably correct types of content like code, which either works or it doesn’t, but persuasive documents in fuzzier areas like hiring, strategy, and so on. Like everyone else leaning on these tools, we are reckoning with the consequences of the ability to talk to a model and get back something that looks smart at a glance.</p><p>A few rounds in, the slop is still there. In the last few months, maybe 10 times as many documents have crossed our desks, from new product ideas to strategic plans and proposals. But the ease of generating the text hides the fact that either the model or the person prompting it doesn't actually know what they’re talking about. Knowledge workers need ways to ground their work in insights from human experts, particularly when that work is AI-assisted.</p><p>So we’re building tools that let agents draw on our repository of expertise to support their proposed decisions.</p><p>Credible sources are particularly important when thinking through and justifying important choices. Our CTO, Andrew Odewahn, describes the shift this way: "18 months ago, it was all about how to get engineers to be more productive, but now it's about how to get organizations to make better decisions. The engineering tasks are moving away from coding output to planning."</p><p>For planning tasks like comparing implementation approaches, you need expert-over-your-shoulder guidance for contextual decision-making. You can’t just rely on an LLM's best guess to solve your problem. Trust is foundational because the expertise behind it stays genuine, practical, and human.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/when-content-is-free-trust-is-the-product</link>
                                                                            <description>
                            <![CDATA[ There is more technical content available today than any human being could read in a thousand lifetimes. And yet most of the professionals I talk to say they don't know what to trust. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZjfgvUVdTaDkjNdD63kNan</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 11:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Julie Baron ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:description>                                                            <media:text><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There is more technical content available today than any human being could read in a thousand lifetimes. Every topic has a dozen YouTube videos, three Substack posts, a GitHub repo, and a Reddit thread, most created in the last six months and, in many cases, technically accurate.</p><p>And yet most of the professionals I talk to say they don't know what to trust. They can't tell what’s important to read first, or which of 10 plausible answers is the one that holds up. That was true before AI, and AI has made it more true.</p><p>For most of the history of technical publishing, editing and verification were the same process, and that process was slow and expensive. Getting a book out took years. We found an author, vetted them, had them work with an editor, and checked their claims with technical reviewers.</p><p>A lot of that time went into separating what was correct and useful from what was confusing or only sounded right. It was laborious, but it meant a reader could depend on the claims on the page.</p><p>The credibility of the book, and of the publisher behind it, mattered as much as the information itself. When the cost of production drops to zero, that credibility becomes worth more, not less. Content is easier to make than ever, but without a transparent process behind it, readers have no idea where the knowledge came from or whether it holds up.</p><p>As Jasmine Sun puts it in “The Independent Writer’s Advantage in the Age of AI,” "Trust is not about information and its quality alone. It's about the messenger. It's about who says it and their track record and what they've told me before." A practitioner has confidence in a source because someone she respects has put their reputation on the line for it.</p><p>They believe what the author is saying because the publisher has a history of being right and of correcting itself when it isn't, and because the work is attributed and verifiable.</p><h2 id="expertise-is-alive-and-it-compounds">Expertise is alive, and it compounds</h2><p>The corpus matters, but it's the assurances around it that are hard to replicate, and that comes not just from the people who produce the content but from the people whose judgment vouches for it. Sometimes a creator brings their own credibility with them. Other times, the publisher spots someone unknown and lends them its own. </p><p>The art critic Dave Hickey said this about gallery owners in Air Guitar: They gain status from the famous artists they represent and share it with emerging talent who have something to offer but who haven't had the chance to earn a reputation.</p><p>Expertise is alive, and it compounds Expertise is a living thing, continuously expanding. Content starts to decay the moment it’s published, because frameworks evolve, libraries deprecate, and yesterday's best practice becomes today's <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> incident. Keeping expertise alive requires a pipeline of people who stay current and an editorial layer that notices when something has gone stale, and either retires it or calls for a fix.</p><p>That pipeline isn't something you switch on when an author has a book to ship. Content sits at the center of our platform, but we think about it in pace layers. Some advice is timeless, some moves but has a long shelf life (some of our books are still in print after nearly 50 years!), and some changes weekly.</p><p>We work with experts at each pace layer, capturing what lasts while doing our best to keep pace with an industry that seems to have changed every time we wake up.</p><p>We have relationships with hundreds of the best practitioners in the world, and our job is to keep them engaged continuously, with quick takes when something breaks, structured responses when major research drops, and live sessions on emerging topics while they're still emerging.</p><h2 id="trust-is-earnt">Trust is earnt</h2><p>An institution doesn't stamp trust onto content. In a technical community, trust is conferred in both directions. A practitioner earns standing because people who already have standing engage with her work, cite it, argue with it, and build on it. That insight was the whole idea behind PageRank, Google's first great innovation. A page mattered because other pages that mattered linked to it. Reputation works the same way.</p><p>The audience isn't just consuming reputation signals; it's generating them. When a senior engineer whose judgment others respect says out loud that something is worth reading, she spends a little of her own credibility; the author gains a little; and everyone watching recalibrates whom to trust next time.</p><p>When we put our mark on someone's work, we aren't the sole source of its credibility. We're amplifying a judgment the community is already making and adding our own track record to it. The reader who finds it reliable hands status back to the source.</p><h2 id="when-the-readers-are-machines">When the readers are machines</h2><p>Human practitioners aren't the only ones who need trusted engineering knowledge. The AI systems now sitting in every workflow, the coding and debugging agents and architecture advisors, need it just as badly since most of them are built on scraped web <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> and <a href="https://www.techradar.com/pro/best-it-documentation-tool">documentation</a> that was stale before it was ever indexed. They're fluent, but they're wrong often enough that you can't just take their word for it.</p><p>The stakes grow with <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> increasingly being used to generate not just provably correct types of content like code, which either works or it doesn’t, but persuasive documents in fuzzier areas like hiring, strategy, and so on. Like everyone else leaning on these tools, we are reckoning with the consequences of the ability to talk to a model and get back something that looks smart at a glance.</p><p>A few rounds in, the slop is still there. In the last few months, maybe 10 times as many documents have crossed our desks, from new product ideas to strategic plans and proposals. But the ease of generating the text hides the fact that either the model or the person prompting it doesn't actually know what they’re talking about. Knowledge workers need ways to ground their work in insights from human experts, particularly when that work is AI-assisted.</p><p>So we’re building tools that let agents draw on our repository of expertise to support their proposed decisions.</p><p>Credible sources are particularly important when thinking through and justifying important choices. Our CTO, Andrew Odewahn, describes the shift this way: "18 months ago, it was all about how to get engineers to be more productive, but now it's about how to get organizations to make better decisions. The engineering tasks are moving away from coding output to planning."</p><p>For planning tasks like comparing implementation approaches, you need expert-over-your-shoulder guidance for contextual decision-making. You can’t just rely on an LLM's best guess to solve your problem. Trust is foundational because the expertise behind it stays genuine, practical, and human.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 2.8 million people affected by data breach at Baylor Genetics testing and diagnostic firm ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Baylor Genetics confirmed a June cyberattack affecting 2.8M patients and employees</strong></li><li><strong>Stolen data includes medical test results, insurance info, and some SSNs/financial details</strong></li><li><strong>Operations continued; no misuse seen yet, but no group has claimed responsibility</strong></li></ul><p>Baylor Genetics, a US-based clinical diagnostic laboratory, suffered a cyberattack in which it lost sensitive data on 2.8 million people - both patients and employees.</p><p>In a security update posted on its website earlier this week, the company said it spotted the intrusion in a “limited portion” of its IT environment on or around June 15. Subsequent investigation determined that both patients and employees have had their data stolen, including those who are not working at Baylor anymore.</p><p>For patients, crooks stole names, dates of birth, medical testing information, laboratory test results, and “potentially health insurance information, as well as Social Security number”. SSNs, Baylor Genetics stressed, were taken from a “very limited subset of patients”.</p><h2 id="no-attribution-yet">No attribution yet</h2><p>Regardless, fraudsters who know the details about medical testing and lab results have more than enough information to launch highly sophisticated, personalized phishing attacks that can lead to ransomware infections, business email compromise, and more. </p><p>For certain current and former employees, the attackers nabbed Social Security numbers, government-issued identification numbers, and financial account information, ideal for wire fraud. </p><p>In the security update, the company did not discuss the identity of the attackers, or the number of affected individuals. However, in a separate report filed with the US Department of Health and Human Services, Baylor reported the number of victims as 2,810,878. It added that at the time of publication, there was no evidence of confirmed <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, fraud, or misuse of personal information stolen in the attack. </p><p>It also said the incident did not impact its everyday operations which continued as usual. </p><p>Usually, data theft incidents like this one are followed by public disclosure from the perpetrators, who name-and-shame their victims in an attempt to get them to pay a ransom demand. So far, no threat actors claimed responsibility for this incident.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/2-8-million-people-affected-by-data-breach-at-baylor-genetics-testing-and-diagnostic-firm</link>
                                                                            <description>
                            <![CDATA[ Business continued as usual, although employees and patients lost plenty of sensitive data in the incident. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">asYqA3pQDCzhjPh7qcTguQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 11:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Laboratory]]></media:description>                                                            <media:text><![CDATA[Laboratory]]></media:text>
                                <media:title type="plain"><![CDATA[Laboratory]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Baylor Genetics confirmed a June cyberattack affecting 2.8M patients and employees</strong></li><li><strong>Stolen data includes medical test results, insurance info, and some SSNs/financial details</strong></li><li><strong>Operations continued; no misuse seen yet, but no group has claimed responsibility</strong></li></ul><p>Baylor Genetics, a US-based clinical diagnostic laboratory, suffered a cyberattack in which it lost sensitive data on 2.8 million people - both patients and employees.</p><p>In a security update posted on its website earlier this week, the company said it spotted the intrusion in a “limited portion” of its IT environment on or around June 15. Subsequent investigation determined that both patients and employees have had their data stolen, including those who are not working at Baylor anymore.</p><p>For patients, crooks stole names, dates of birth, medical testing information, laboratory test results, and “potentially health insurance information, as well as Social Security number”. SSNs, Baylor Genetics stressed, were taken from a “very limited subset of patients”.</p><h2 id="no-attribution-yet">No attribution yet</h2><p>Regardless, fraudsters who know the details about medical testing and lab results have more than enough information to launch highly sophisticated, personalized phishing attacks that can lead to ransomware infections, business email compromise, and more. </p><p>For certain current and former employees, the attackers nabbed Social Security numbers, government-issued identification numbers, and financial account information, ideal for wire fraud. </p><p>In the security update, the company did not discuss the identity of the attackers, or the number of affected individuals. However, in a separate report filed with the US Department of Health and Human Services, Baylor reported the number of victims as 2,810,878. It added that at the time of publication, there was no evidence of confirmed <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, fraud, or misuse of personal information stolen in the attack. </p><p>It also said the incident did not impact its everyday operations which continued as usual. </p><p>Usually, data theft incidents like this one are followed by public disclosure from the perpetrators, who name-and-shame their victims in an attempt to get them to pay a ransom demand. So far, no threat actors claimed responsibility for this incident.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security policy is critical infrastructure ]]></title>
                                                                                                <dc:content><![CDATA[ <p>In banking and utilities, regulators define certain systems as essential. An essential system is one whose failure would cause intolerable harm to <a href="https://www.techradar.com/best/best-customer-feedback-tools?gad=1">customers</a>, markets, or public safety. A payment platform in a clearing bank or a SCADA network in a power distributor, for example, carries the highest governance obligations: continuous monitoring, validated change control, and demonstrable resilience.</p><p>The policy environment – the accumulated rules across <a href="https://www.techradar.com/best/firewall">firewalls</a>, cloud controls, and microsegmentation – determines which of those systems can reach each other, which connections are blocked, and which exceptions still apply. Collectively, these rules form the security policy control plane: the governance layer that translates business intent into access decisions across distributed enforcement points.</p><p>A misconfigured segmentation rule during a <a href="https://www.techradar.com/best/best-business-cloud-storage-service">cloud</a> migration can sever a payment service from its settlement platform; a temporary rule granting broad access from a development subnet into production can stay in place months after go-live because no one owns the removal.</p><p>Every firewall rule, segmentation policy, and access decision directly affects operational risk, and when the policy environment fails, the critical services it governs fail with it.</p><p>That makes the policy environment critical infrastructure in its own right.</p><h2 id="still-governed-like-housekeeping">Still governed like housekeeping</h2><p>Despite this, many regulated organizations still manage their policy environments as operational tasks. Rules are added through change requests, and the accumulated result is rarely examined against what was intended. Ownership disperses as leaders change roles, and the reason why a specific rule came into being in the first place can only be found in a change ticket, if anywhere at all.</p><p>A CISO who would never accept a payment platform running without continuous monitoring or documented dependencies may accept both being absent from the policy environment that determines whether the platform is reachable. We can think of this as infrastructure-grade consequence with housekeeping-grade governance.</p><p>In banking, a policy failure that severs connectivity between settlement systems would constitute the disruption of an important business service. The FCA would take an interest in such a failure, since the loss of such a service could lead to intolerable harm. </p><p>In healthcare or energy, the consequences are different but the mechanism is the same: a misconfiguration that permits access from a corporate network into clinical systems in an NHS trust, or into operational technology in a power distributor, creates exposure at the level of essential service delivery. These are not hypothetical risks but the operational consequences of treating critical <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> governance as a simple housekeeping task.</p><h2 id="regulatory-expectations-point-the-same-way">Regulatory expectations point the same way</h2><p>UK regulatory expectations increasingly support the same conclusion: the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> policies governing access to important services must be managed with infrastructure-grade discipline. The FCA's operational resilience regime requires regulated firms to identify important business services and demonstrate, on an ongoing basis, that the supporting infrastructure remains within defined impact tolerances.</p><p>Ofgem assesses operators of essential services against the NCSC's Cyber Assessment Framework, asking whether defined security outcomes are being achieved on a sustained basis. The Cyber Security and Resilience Bill, expected to become law later this year, will extend similar obligations to data centers, managed service providers, and critical suppliers.</p><p>These frameworks are not prescriptive – none of them specifies which firewall rules an organization should have or how its segmentation policies should be configured. What they require is proof: that what the policy environment permits is what was intended, and that the organization can demonstrate this on an ongoing basis rather than reconstruct the evidence for each assessment. </p><h2 id="why-the-estate-cannot-meet-that-standard">Why the estate cannot meet that standard</h2><p>Most policy environments were never built to meet that standard. In fact, most policy environments were never consciously or deliberately built at all. Instead, policy tends to accumulate as a by-product of delivery. Every project and <a href="https://www.techradar.com/best/best-data-migration-tools">migration</a> adds rules, and almost none take any away.</p><p>Over time, the policy surface – the full body of rules and access decisions across enforcement layers – grows larger than the group of people who understand it, and the estate reaches a point where it can be operated but not explained.</p><p>Across regulated industries like banking, energy, and healthcare, that was sustainable under earlier regulatory regimes: periodic assessment, control-based audit, compliance frameworks that asked whether controls existed rather than whether they were effective. But this is no longer enough. The new standard requires continuous evidence that access is intentional.</p><p>The FCA's findings after a year of operational resilience self-assessments illustrate what this looks like in practice. Where regulated firms reported few or no outstanding vulnerabilities in the infrastructure supporting their important business services, the FCA often deemed the evidence too thin to determine whether there really were no vulnerabilities – or whether the vulnerabilities just hadn't been identified.</p><p>The lesson applies directly to security policy governance: an organization cannot credibly claim access-related vulnerabilities are controlled without evidence of what its policies permit, how they were tested, and whether weaknesses were remediated. </p><h2 id="what-infrastructure-grade-governance-requires">What infrastructure-grade governance requires</h2><p>Too often, the response is to reach for more visibility and more <a href="https://www.techradar.com/pro/best-it-documentation-tool">documentation</a>. But documentation will only ever capture a point in time; it cannot provide the continuous assurance regulators are coming to expect.</p><p>A CISO in a regulated firm needs more than a record of what the policy environment was configured to permit. Configuration and effective access are not the same thing. Security teams need to understand how rules, routes, objects, and enforcement layers interact to determine what can actually communicate.</p><p>Meeting the standard means reconciling the two: showing that what the environment permits in practice is still what it was intended to permit, and being able to show it without notice.</p><p>We separate where policy intent is defined from where it is enforced. Intent is held and maintained centrally, while enforcement remains distributed across firewalls, cloud controls, and microsegmentation in hybrid, multi-cloud, and multi-vendor environments.</p><p>Validation runs continuously against that intent rather than at review points: proposed changes are tested against policy before they reach production, and effective access is assessed on an ongoing basis for unnecessary exposure, inconsistency between enforcement layers, and divergence from business intent. What was permitted and what changed is retained as evidence.</p><p>The same CISO who would never accept a payment platform running without continuous monitoring, validated change control, and documented dependencies has to apply that standard to the policy environment that determines whether the platform is reachable.</p><p>The FCA, the NCSC's Cyber Assessment Framework, and the Cyber Security and Resilience Bill all point towards the same underlying question: can this organization demonstrate, continuously, that the infrastructure supporting its critical services is governed to the standard those services demand?</p><p>Answering it means knowing (and actually knowing – not assuming, not reconstructing at audit) what the policy environment permits at any given moment, and whether what it permits is what was intended.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've featured the best antivirus software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security-policy-is-critical-infrastructure</link>
                                                                            <description>
                            <![CDATA[ An essential system is one whose failure would cause intolerable harm to customers, markets, or public safety. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UotrTGtBgT3LtpKYnjv9DA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 10:28:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ David Brown ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In banking and utilities, regulators define certain systems as essential. An essential system is one whose failure would cause intolerable harm to <a href="https://www.techradar.com/best/best-customer-feedback-tools?gad=1">customers</a>, markets, or public safety. A payment platform in a clearing bank or a SCADA network in a power distributor, for example, carries the highest governance obligations: continuous monitoring, validated change control, and demonstrable resilience.</p><p>The policy environment – the accumulated rules across <a href="https://www.techradar.com/best/firewall">firewalls</a>, cloud controls, and microsegmentation – determines which of those systems can reach each other, which connections are blocked, and which exceptions still apply. Collectively, these rules form the security policy control plane: the governance layer that translates business intent into access decisions across distributed enforcement points.</p><p>A misconfigured segmentation rule during a <a href="https://www.techradar.com/best/best-business-cloud-storage-service">cloud</a> migration can sever a payment service from its settlement platform; a temporary rule granting broad access from a development subnet into production can stay in place months after go-live because no one owns the removal.</p><p>Every firewall rule, segmentation policy, and access decision directly affects operational risk, and when the policy environment fails, the critical services it governs fail with it.</p><p>That makes the policy environment critical infrastructure in its own right.</p><h2 id="still-governed-like-housekeeping">Still governed like housekeeping</h2><p>Despite this, many regulated organizations still manage their policy environments as operational tasks. Rules are added through change requests, and the accumulated result is rarely examined against what was intended. Ownership disperses as leaders change roles, and the reason why a specific rule came into being in the first place can only be found in a change ticket, if anywhere at all.</p><p>A CISO who would never accept a payment platform running without continuous monitoring or documented dependencies may accept both being absent from the policy environment that determines whether the platform is reachable. We can think of this as infrastructure-grade consequence with housekeeping-grade governance.</p><p>In banking, a policy failure that severs connectivity between settlement systems would constitute the disruption of an important business service. The FCA would take an interest in such a failure, since the loss of such a service could lead to intolerable harm. </p><p>In healthcare or energy, the consequences are different but the mechanism is the same: a misconfiguration that permits access from a corporate network into clinical systems in an NHS trust, or into operational technology in a power distributor, creates exposure at the level of essential service delivery. These are not hypothetical risks but the operational consequences of treating critical <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> governance as a simple housekeeping task.</p><h2 id="regulatory-expectations-point-the-same-way">Regulatory expectations point the same way</h2><p>UK regulatory expectations increasingly support the same conclusion: the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> policies governing access to important services must be managed with infrastructure-grade discipline. The FCA's operational resilience regime requires regulated firms to identify important business services and demonstrate, on an ongoing basis, that the supporting infrastructure remains within defined impact tolerances.</p><p>Ofgem assesses operators of essential services against the NCSC's Cyber Assessment Framework, asking whether defined security outcomes are being achieved on a sustained basis. The Cyber Security and Resilience Bill, expected to become law later this year, will extend similar obligations to data centers, managed service providers, and critical suppliers.</p><p>These frameworks are not prescriptive – none of them specifies which firewall rules an organization should have or how its segmentation policies should be configured. What they require is proof: that what the policy environment permits is what was intended, and that the organization can demonstrate this on an ongoing basis rather than reconstruct the evidence for each assessment. </p><h2 id="why-the-estate-cannot-meet-that-standard">Why the estate cannot meet that standard</h2><p>Most policy environments were never built to meet that standard. In fact, most policy environments were never consciously or deliberately built at all. Instead, policy tends to accumulate as a by-product of delivery. Every project and <a href="https://www.techradar.com/best/best-data-migration-tools">migration</a> adds rules, and almost none take any away.</p><p>Over time, the policy surface – the full body of rules and access decisions across enforcement layers – grows larger than the group of people who understand it, and the estate reaches a point where it can be operated but not explained.</p><p>Across regulated industries like banking, energy, and healthcare, that was sustainable under earlier regulatory regimes: periodic assessment, control-based audit, compliance frameworks that asked whether controls existed rather than whether they were effective. But this is no longer enough. The new standard requires continuous evidence that access is intentional.</p><p>The FCA's findings after a year of operational resilience self-assessments illustrate what this looks like in practice. Where regulated firms reported few or no outstanding vulnerabilities in the infrastructure supporting their important business services, the FCA often deemed the evidence too thin to determine whether there really were no vulnerabilities – or whether the vulnerabilities just hadn't been identified.</p><p>The lesson applies directly to security policy governance: an organization cannot credibly claim access-related vulnerabilities are controlled without evidence of what its policies permit, how they were tested, and whether weaknesses were remediated. </p><h2 id="what-infrastructure-grade-governance-requires">What infrastructure-grade governance requires</h2><p>Too often, the response is to reach for more visibility and more <a href="https://www.techradar.com/pro/best-it-documentation-tool">documentation</a>. But documentation will only ever capture a point in time; it cannot provide the continuous assurance regulators are coming to expect.</p><p>A CISO in a regulated firm needs more than a record of what the policy environment was configured to permit. Configuration and effective access are not the same thing. Security teams need to understand how rules, routes, objects, and enforcement layers interact to determine what can actually communicate.</p><p>Meeting the standard means reconciling the two: showing that what the environment permits in practice is still what it was intended to permit, and being able to show it without notice.</p><p>We separate where policy intent is defined from where it is enforced. Intent is held and maintained centrally, while enforcement remains distributed across firewalls, cloud controls, and microsegmentation in hybrid, multi-cloud, and multi-vendor environments.</p><p>Validation runs continuously against that intent rather than at review points: proposed changes are tested against policy before they reach production, and effective access is assessed on an ongoing basis for unnecessary exposure, inconsistency between enforcement layers, and divergence from business intent. What was permitted and what changed is retained as evidence.</p><p>The same CISO who would never accept a payment platform running without continuous monitoring, validated change control, and documented dependencies has to apply that standard to the policy environment that determines whether the platform is reachable.</p><p>The FCA, the NCSC's Cyber Assessment Framework, and the Cyber Security and Resilience Bill all point towards the same underlying question: can this organization demonstrate, continuously, that the infrastructure supporting its critical services is governed to the standard those services demand?</p><p>Answering it means knowing (and actually knowing – not assuming, not reconstructing at audit) what the policy environment permits at any given moment, and whether what it permits is what was intended.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've featured the best antivirus software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Lords call for a 'kill switch' on powerful AI systems used in the United Kingdom ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>UK legislators propose “kill switch” laws to halt runaway AI, citing critical infrastructure risks</strong></li><li><strong>Lord Clement‑Jones and MP Alex Sobel push amendments and new bills, backed by ControlAI advocacy group</strong></li><li><strong>Similar efforts emerging in US</strong></li></ul><p>Sam Altman’s fear-based marketing for AI seems to have backfired, as now multiple legislators in the UK and elsewhere are calling for a “kill switch” law to be introduced.</p><p>According to the BBC, Liberal Democrats’ Lord Tim Clement-Jones proposed an amendment to the Cyber Security and Resilience Bill which would see the UK create a “vital safety net” to provide a “democratically accountable means to ‘halt a runaway system before it can compromise our critical national infrastructure’.” The capability would only be used as a last resort, Clement-Jones stressed. </p><p>The bill is currently being worked through in the UK Parliament, the BBC said.</p><h2 id="is-there-reason-to-worry">Is there reason to worry?</h2><p>But that’s not the only effort in the UK to put some reigns on <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI</a>. Apparently, Labour MP Alex Sobel plans to introduce an AI Security Bill later this month which, according to the BBC, would “effectively halt the development of superintelligent AI” and make the UK the first G7 country to do so. </p><p>The bill is supported by a campaign group called ControlAI, a UK-based nonprofit and advocacy organization focused on the risks posed by advanced AI. Its founder and CEO is Andrea Miotti, who previously worked at the AI safety company called Conjecture. Across the pond, US legislators are currently considering an AI Kill Switch Act as well, but the bill is still in very early stages of development.</p><p>Ever since the first ChatGPT model that was introduced in 2021, a debate has been raging whether or not AI will be net positive, or net negative, for humanity. While some argue that the discovery rivals the steam machine and that it will transform our lives beyond our wildest dreams, others are fearful of losing jobs, a collapsing economy, and a dystopian future devoid of humanity and emotion.</p><p>Marketing campaigns for ChatGPT and, in some measure, Claude, are not helping, either. Both companies have built models focused on cybersecurity which were advertised as “too dangerous” for the general public and instead were only given to a handful of organizations. Despite partial skepticism, many are worried that these models might severely disrupt the security of banking, critical infrastructure, and communications.</p><p><em>Via </em><a href="https://www.bbc.com/news/articles/cn9wv80j9w9o" target="_blank" rel="nofollow"><em>BBC</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/lords-call-for-a-kill-switch-on-powerful-ai-systems-used-in-the-united-kingdom</link>
                                                                            <description>
                            <![CDATA[ They believe the UK needs a "vital safety net" to only be used as a last resort. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iicNmwrFCpfHr7U9X2LbK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 10:10:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>UK legislators propose “kill switch” laws to halt runaway AI, citing critical infrastructure risks</strong></li><li><strong>Lord Clement‑Jones and MP Alex Sobel push amendments and new bills, backed by ControlAI advocacy group</strong></li><li><strong>Similar efforts emerging in US</strong></li></ul><p>Sam Altman’s fear-based marketing for AI seems to have backfired, as now multiple legislators in the UK and elsewhere are calling for a “kill switch” law to be introduced.</p><p>According to the BBC, Liberal Democrats’ Lord Tim Clement-Jones proposed an amendment to the Cyber Security and Resilience Bill which would see the UK create a “vital safety net” to provide a “democratically accountable means to ‘halt a runaway system before it can compromise our critical national infrastructure’.” The capability would only be used as a last resort, Clement-Jones stressed. </p><p>The bill is currently being worked through in the UK Parliament, the BBC said.</p><h2 id="is-there-reason-to-worry">Is there reason to worry?</h2><p>But that’s not the only effort in the UK to put some reigns on <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI</a>. Apparently, Labour MP Alex Sobel plans to introduce an AI Security Bill later this month which, according to the BBC, would “effectively halt the development of superintelligent AI” and make the UK the first G7 country to do so. </p><p>The bill is supported by a campaign group called ControlAI, a UK-based nonprofit and advocacy organization focused on the risks posed by advanced AI. Its founder and CEO is Andrea Miotti, who previously worked at the AI safety company called Conjecture. Across the pond, US legislators are currently considering an AI Kill Switch Act as well, but the bill is still in very early stages of development.</p><p>Ever since the first ChatGPT model that was introduced in 2021, a debate has been raging whether or not AI will be net positive, or net negative, for humanity. While some argue that the discovery rivals the steam machine and that it will transform our lives beyond our wildest dreams, others are fearful of losing jobs, a collapsing economy, and a dystopian future devoid of humanity and emotion.</p><p>Marketing campaigns for ChatGPT and, in some measure, Claude, are not helping, either. Both companies have built models focused on cybersecurity which were advertised as “too dangerous” for the general public and instead were only given to a handful of organizations. Despite partial skepticism, many are worried that these models might severely disrupt the security of banking, critical infrastructure, and communications.</p><p><em>Via </em><a href="https://www.bbc.com/news/articles/cn9wv80j9w9o" target="_blank" rel="nofollow"><em>BBC</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why your business can't trust the data behind its own security decisions ]]></title>
                                                                                                <dc:content><![CDATA[ <p>When a critical vulnerability alert lands in a traditional IT environment, it’s rarely a cause for panic regarding the operational continuity of the <a href="https://www.techradar.com/best/best-small-business-software">business</a>. The affected laptops, servers, and applications can be identified quickly, and a good team can catalogue and patch them within hours if it’s urgent. The priorities are clear, and there’s very little guesswork involved.  </p><p>Now picture the same alert landing across a hospital's imaging equipment, a factory floor's control systems, or a building's HVAC network. These cyber-physical systems (CPS), the connected devices that run physical operations rather than just processing data, sit at the sharp end of IT and OT (operational technology) convergence.</p><p>But unlike traditional IT assets, confirming whether that alert even applies to a specific device can take days, and often ends in a guess rather than an answer.</p><p>While this kind of uncertainty would be considered a failure of basic hygiene, for cyber-physical systems, it’s unfortunately much more often the norm.</p><p>So why is this such a widespread problem for CPS, and how can <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> teams get these vital assets back in line with their IT network? </p><h2 id="bad-visibility-into-cyber-physical-systems-is-worryingly-widespread">Bad visibility into cyber-physical systems is worryingly widespread </h2><p>The inability to manage incoming vulnerabilities for CPS isn’t an outlier or worst-case scenario, which is especially concerning when these assets are at the heart of critical infrastructure like energy and healthcare.</p><p>The issue comes down to the product codes that help networks identify what CPS is in the environment, which is an essential part of identifying and applying security patches.</p><p>Across a dataset of 17 million cyber-physical assets, our research found that 88% failed to transmit an exact product code, and 76% sent a code that didn't match the vendor's own record.</p><p>It’s a side effect of the way these systems were initially designed and later integrated into modern IT environments. Programmable logic controllers (PLCs), medical scanners, and industrial sensors were engineered for decades of physical reliability, not for tidy digital labeling. Network identification was rarely part of the design brief, so the same device can report itself differently depending on which protocol or integration is asking.</p><p>We found a similar state of affairs when it comes to the operating systems behind the physical <a href="https://www.techradar.com/news/best-business-desktop-pcs">hardware</a>. In our research, 41% of devices have no <a href="https://www.techradar.com/news/best-alternative-operating-systems">OS</a> version available, and 24% have no OS name at all.</p><p>Without these details, matching a device to a known vulnerability stops being a quick database lookup or automated process, and becomes a guessing game or painstaking manual search.</p><p>Added to this, CVE advisories, the industry's standard mechanism for tracking vulnerabilities, are compiled from this same patchy vendor data. An official advisory can be just as incomplete as the network it's meant to protect. </p><h2 id="translating-product-code-chaos-into-boardroom-risk">Translating product code chaos into boardroom risk </h2><p>This kind of blind spot adds another layer of concern to a leadership that is already anxious about threat visibility. Among 1,100 security leaders surveyed globally, 44% named understanding their organization's risk exposure as one of their biggest operational concerns, more than compliance pressure or budget constraints.</p><p>A further 45% said they were struggling to reduce cyber risk to their most important assets and processes, yet the connection between that struggle and an unreliable asset inventory is often missed entirely. Leadership sees the symptom, a rising sense that risk is unmanageable, without ever seeing the cause sitting underneath it.</p><p>This is where security and the business can end up talking past each other. Security teams that start describing the problem in terms of missing product codes and inconsistent naming conventions won’t get far.</p><p>Business leaders hear none of that; they hear only that risk cannot be quantified with confidence. Until those two conversations are connected, every risk register that a CISO presents upward carries an asterisk that nobody in the room can see. </p><h2 id="context-is-key-to-closing-the-gap">Context is key to closing the gap </h2><p>Resolving this issue starts with a shift in what visibility means. Knowing a device exists on the <a href="https://www.techradar.com/best/best-network-monitoring-tools">network</a> is only half of the job. Knowing what it does, what process depends on it, and what happens if it's compromised is what actually makes a risk register useful.   </p><p>Achieving this shift at scale requires specialized tools to manage the often eclectic and proprietary nature of CPS assets, and an automated approach to cope with the scale.   </p><p>In one example, applying AI-driven mapping techniques to an OEM's device catalogue lifted product code identification from 4% to 83%, turning a near-blind spot into a near-complete picture. The follow-through mattered just as much, with 56% of devices receiving a new or updated firmware recommendation as a result, and vulnerability identification accuracy improving by 25%.</p><p>Numbers like these matter because they change the question security teams can answer. Instead of asking what's connected to the network, teams can ask which systems would cause the greatest disruption if compromised, and act on the answer with confidence rather than inference. That is the difference between an asset inventory that exists on paper and a resilient one that holds up under pressure. </p><h2 id="fixing-the-foundation-not-just-the-alarm">Fixing the foundation, not just the alarm </h2><p>None of this gets solved by adding another tool to the stack. Instead, it means treating asset <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> quality as a board-level risk issue rather than background IT housekeeping, with the same scrutiny applied to budgets, compliance and third-party access.   </p><p>Achieving this means a new CVE alert no longer triggers a scramble to work out which critical devices might be affected, but the confirmed, prioritized response you’d expect from any good vulnerability management program.</p><p>The alert landing on a hospital's imaging equipment or a factory floor's control systems should be no harder to act on than the one landing on a laptop. Getting there starts with making the invisible visible.</p><p><em></em><a href="https://www.techradar.com/best/firewall"><em>We've featured the best firewall software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/why-your-business-cant-trust-the-data-behind-its-own-security-decisions</link>
                                                                            <description>
                            <![CDATA[ Your asset data may be lying to you and it's putting your entire security strategy at risk. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Th9UCf4txcyoVPUiQi7hTd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 09:18:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Andrew Lintell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6S3Re6NB5kcyJo7LqafN8B.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Andrew Lintell, is General Manager, EMEA, Claroty. He has 24+ years’ experience in software, specialising in building partnerships, supporting cybersecurity, compliance, and business analytics.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:description>                                                            <media:text><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>When a critical vulnerability alert lands in a traditional IT environment, it’s rarely a cause for panic regarding the operational continuity of the <a href="https://www.techradar.com/best/best-small-business-software">business</a>. The affected laptops, servers, and applications can be identified quickly, and a good team can catalogue and patch them within hours if it’s urgent. The priorities are clear, and there’s very little guesswork involved.  </p><p>Now picture the same alert landing across a hospital's imaging equipment, a factory floor's control systems, or a building's HVAC network. These cyber-physical systems (CPS), the connected devices that run physical operations rather than just processing data, sit at the sharp end of IT and OT (operational technology) convergence.</p><p>But unlike traditional IT assets, confirming whether that alert even applies to a specific device can take days, and often ends in a guess rather than an answer.</p><p>While this kind of uncertainty would be considered a failure of basic hygiene, for cyber-physical systems, it’s unfortunately much more often the norm.</p><p>So why is this such a widespread problem for CPS, and how can <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> teams get these vital assets back in line with their IT network? </p><h2 id="bad-visibility-into-cyber-physical-systems-is-worryingly-widespread">Bad visibility into cyber-physical systems is worryingly widespread </h2><p>The inability to manage incoming vulnerabilities for CPS isn’t an outlier or worst-case scenario, which is especially concerning when these assets are at the heart of critical infrastructure like energy and healthcare.</p><p>The issue comes down to the product codes that help networks identify what CPS is in the environment, which is an essential part of identifying and applying security patches.</p><p>Across a dataset of 17 million cyber-physical assets, our research found that 88% failed to transmit an exact product code, and 76% sent a code that didn't match the vendor's own record.</p><p>It’s a side effect of the way these systems were initially designed and later integrated into modern IT environments. Programmable logic controllers (PLCs), medical scanners, and industrial sensors were engineered for decades of physical reliability, not for tidy digital labeling. Network identification was rarely part of the design brief, so the same device can report itself differently depending on which protocol or integration is asking.</p><p>We found a similar state of affairs when it comes to the operating systems behind the physical <a href="https://www.techradar.com/news/best-business-desktop-pcs">hardware</a>. In our research, 41% of devices have no <a href="https://www.techradar.com/news/best-alternative-operating-systems">OS</a> version available, and 24% have no OS name at all.</p><p>Without these details, matching a device to a known vulnerability stops being a quick database lookup or automated process, and becomes a guessing game or painstaking manual search.</p><p>Added to this, CVE advisories, the industry's standard mechanism for tracking vulnerabilities, are compiled from this same patchy vendor data. An official advisory can be just as incomplete as the network it's meant to protect. </p><h2 id="translating-product-code-chaos-into-boardroom-risk">Translating product code chaos into boardroom risk </h2><p>This kind of blind spot adds another layer of concern to a leadership that is already anxious about threat visibility. Among 1,100 security leaders surveyed globally, 44% named understanding their organization's risk exposure as one of their biggest operational concerns, more than compliance pressure or budget constraints.</p><p>A further 45% said they were struggling to reduce cyber risk to their most important assets and processes, yet the connection between that struggle and an unreliable asset inventory is often missed entirely. Leadership sees the symptom, a rising sense that risk is unmanageable, without ever seeing the cause sitting underneath it.</p><p>This is where security and the business can end up talking past each other. Security teams that start describing the problem in terms of missing product codes and inconsistent naming conventions won’t get far.</p><p>Business leaders hear none of that; they hear only that risk cannot be quantified with confidence. Until those two conversations are connected, every risk register that a CISO presents upward carries an asterisk that nobody in the room can see. </p><h2 id="context-is-key-to-closing-the-gap">Context is key to closing the gap </h2><p>Resolving this issue starts with a shift in what visibility means. Knowing a device exists on the <a href="https://www.techradar.com/best/best-network-monitoring-tools">network</a> is only half of the job. Knowing what it does, what process depends on it, and what happens if it's compromised is what actually makes a risk register useful.   </p><p>Achieving this shift at scale requires specialized tools to manage the often eclectic and proprietary nature of CPS assets, and an automated approach to cope with the scale.   </p><p>In one example, applying AI-driven mapping techniques to an OEM's device catalogue lifted product code identification from 4% to 83%, turning a near-blind spot into a near-complete picture. The follow-through mattered just as much, with 56% of devices receiving a new or updated firmware recommendation as a result, and vulnerability identification accuracy improving by 25%.</p><p>Numbers like these matter because they change the question security teams can answer. Instead of asking what's connected to the network, teams can ask which systems would cause the greatest disruption if compromised, and act on the answer with confidence rather than inference. That is the difference between an asset inventory that exists on paper and a resilient one that holds up under pressure. </p><h2 id="fixing-the-foundation-not-just-the-alarm">Fixing the foundation, not just the alarm </h2><p>None of this gets solved by adding another tool to the stack. Instead, it means treating asset <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> quality as a board-level risk issue rather than background IT housekeeping, with the same scrutiny applied to budgets, compliance and third-party access.   </p><p>Achieving this means a new CVE alert no longer triggers a scramble to work out which critical devices might be affected, but the confirmed, prioritized response you’d expect from any good vulnerability management program.</p><p>The alert landing on a hospital's imaging equipment or a factory floor's control systems should be no harder to act on than the one landing on a laptop. Getting there starts with making the invisible visible.</p><p><em></em><a href="https://www.techradar.com/best/firewall"><em>We've featured the best firewall software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI is getting closer to being able to exploit OT, and that's very bad news for critical infrastructure ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Forescout researchers showed AI can port RCE exploits to PLCs, achieving DoS and shellcode execution</strong></li><li><strong>Effort required heavy researcher input and $500+ in API usage, making attacks impractical for criminals</strong></li><li><strong>Nation‑state actors remain a concern, as seen in Sandworm’s 2025 attack on Poland’s power grid</strong></li></ul><p>If you are worried cybercriminals will use Artificial Intelligence (AI) to automate the discovery and exploitation of zero-day vulnerabilities in Operational Technology (OT) such as Programmable Logic Controllers (PLC) you can sleep peacefully, at least for a little longer.</p><p>Recently, security researchers from Forescout set off on a simple mission - to understand if crooks can use AI to target the ever-increasing population of exposed industrial devices. The short answer is “yes, but it’s not yet worth the trouble”.</p><p>In their mission, they launched an experiment - to port a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">remote code execution</a> (RCE) vulnerability from one PLC to another. These devices were built on closed-source software and thus were not that easy to manipulate, yet the experiment was a success.</p><h2 id="yes-but">Yes, but...</h2><p>Not only did they manage to trigger a Denial of Service (DoS) state that crashed the device but ended up with a working RCE capable of executing attacker-supplied ARM shellcode. </p><p>It is indeed a worrying development, but one that comes with a huge “but”:</p><p>“It required significant researcher input. The final RCE development stage consumed more than $500 in API usage. An attempt to extend the exploit beyond the initial RCE ultimately bricked the PLC,” the researchers said in the report.</p><p>“These limitations taught us valuable lessons about AI-assisted exploitation in OT. It can be done, but it’s not as easy as it sounds. For now, the difficulty, cost, and specialist expertise required are likely to make this kind of attack less attractive than easier alternatives.”</p><p>In other words, cybercriminals still have easier avenues to explore, and as long as that is the case, OT is relatively safe. What the report, unfortunately, does not discuss, is nation-state attackers with significant resources. For such attackers, industrial devices are a prime target, and spending $500+ in API usage is a drop in a bucket. We’ve already seen it back in 2025 when <a href="https://www.techradar.com/pro/security/researchers-say-russian-government-hackers-were-behind-attempted-poland-power-outage" target="_blank">Sandworm struck Poland’s electricity suppliers</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/ai-is-getting-closer-to-being-able-to-exploit-ot-and-thats-very-bad-news-for-critical-infrastructure</link>
                                                                            <description>
                            <![CDATA[ The situation is not disastrous just yet, but it's definitely time to start paying attention, Forescout hints. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LgfjTgBPhj45riESsCbqxa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 20:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security padlock and circuit board to protect data]]></media:description>                                                            <media:text><![CDATA[Security padlock and circuit board to protect data]]></media:text>
                                <media:title type="plain"><![CDATA[Security padlock and circuit board to protect data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Forescout researchers showed AI can port RCE exploits to PLCs, achieving DoS and shellcode execution</strong></li><li><strong>Effort required heavy researcher input and $500+ in API usage, making attacks impractical for criminals</strong></li><li><strong>Nation‑state actors remain a concern, as seen in Sandworm’s 2025 attack on Poland’s power grid</strong></li></ul><p>If you are worried cybercriminals will use Artificial Intelligence (AI) to automate the discovery and exploitation of zero-day vulnerabilities in Operational Technology (OT) such as Programmable Logic Controllers (PLC) you can sleep peacefully, at least for a little longer.</p><p>Recently, security researchers from Forescout set off on a simple mission - to understand if crooks can use AI to target the ever-increasing population of exposed industrial devices. The short answer is “yes, but it’s not yet worth the trouble”.</p><p>In their mission, they launched an experiment - to port a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">remote code execution</a> (RCE) vulnerability from one PLC to another. These devices were built on closed-source software and thus were not that easy to manipulate, yet the experiment was a success.</p><h2 id="yes-but">Yes, but...</h2><p>Not only did they manage to trigger a Denial of Service (DoS) state that crashed the device but ended up with a working RCE capable of executing attacker-supplied ARM shellcode. </p><p>It is indeed a worrying development, but one that comes with a huge “but”:</p><p>“It required significant researcher input. The final RCE development stage consumed more than $500 in API usage. An attempt to extend the exploit beyond the initial RCE ultimately bricked the PLC,” the researchers said in the report.</p><p>“These limitations taught us valuable lessons about AI-assisted exploitation in OT. It can be done, but it’s not as easy as it sounds. For now, the difficulty, cost, and specialist expertise required are likely to make this kind of attack less attractive than easier alternatives.”</p><p>In other words, cybercriminals still have easier avenues to explore, and as long as that is the case, OT is relatively safe. What the report, unfortunately, does not discuss, is nation-state attackers with significant resources. For such attackers, industrial devices are a prime target, and spending $500+ in API usage is a drop in a bucket. We’ve already seen it back in 2025 when <a href="https://www.techradar.com/pro/security/researchers-say-russian-government-hackers-were-behind-attempted-poland-power-outage" target="_blank">Sandworm struck Poland’s electricity suppliers</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>