<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.techradar.com/feeds/tag/security" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from TechRadar in Security ]]></title>
                <link>https://www.techradar.com/pro/security</link>
        <description><![CDATA[ All the latest security content from the TechRadar team ]]></description>
                                    <lastBuildDate>Tue, 08 Sep 2026 20:40:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Massive data breach sees 220 million traveler records exposed — nine years of airline info leaked including passenger and passport details ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Kinryū Labs found misconfigured APIS database in Vietnam exposing 220M passenger and crew records</strong></li><li><strong>Data included PII, travel details, seat assignments, and baggage references from 2017–2026</strong></li><li><strong>Archive locked and there is no evidence yet of dark web sale</strong></li></ul><p>Millions of travellers have had their sensitive information exposed on the internet, thanks to a “series of misconfigurations” discovered in a cloud database, experts have warned.</p><p>In early June 2026, security researchers from Kinryū Labs discovered an Elasticsearch cluster which, although inaccessible from the open internet, allowed access through an alternate route - a cloud-based path. Once inside that route, the researchers discovered that the cluster accepted default credentials, granting access to an archive with 29 indices, weighing roughly 107GB.</p><p>The archive was apparently generated by an Advance Passenger Information System (APIS), a system airlines use to collect and send passenger and crew information to country authorities before flight arrival or departure. Usually, the system collects people’s names, birth dates, nationalities, passport and travel document numbers, and flight details, which are then used for border control, immigration, and similar cases. In this case, however, it also contained people’s sex, document expiration dates, issuing countries, airlines, departure, destination and transit airports, seat assignments, baggage reference, and more.</p><p>It is not known who operated the APIS, or who owns and runs the database. All the researchers managed to find is that it was hosted in Viettel-assigned IP space in Hanoi, Vietnam’s capital.</p><h2 id="who-was-affected">Who was affected?</h2><p>Of the 29 discovered indices, two were rather large: one contained 210,318, 069 passenger records, while another 10,465,631 crew records. In total, 220 million records, created between January 2017 and April 2026, from people who traveled to, from, or through Vietnam during that period.</p><p>The records don’t correspond to individuals, however. If a person travelled multiple times, they will show up in the archive multiple times. Canadians, Chinese, Korean, and New Zealandian nationals are among the ones whose information was exposed. The database is not limited to a specific airline, either - various airlines in Asia-Pacific, Europe, and Middle East regions were mentioned in the researchers’ report.</p><p>Since the researchers could not attribute the database to a specific entity, they reported it to the Vietnamese authorities, different airlines mentioned in the archives, and the country’s CERT (Computer Emergency Response Team), on June 3. The archive was locked down a week later, on June 8. According to BleepingComputer, it was the Singapore Airlines’ security team that took the lead on remediation efforts, telling the researchers they “engaged the relevant parties” and have “taken steps to contain the issue.”</p><p>Without a proper audit of the logs, and a full-blown forensic investigation, it is impossible to tell if any threat actors reached the database before the researchers, or if they exfiltrated and used the data found inside in identity theft, wire fraud, or other scams. What’s (somewhat) comforting is that there is no evidence of such activities on the dark web, and no hacking groups have made such claims. No one is selling the archive on the dark web, either.</p><h2 id="number-one-causes-of-data-spills">Number one causes of data spills </h2><p>Misconfigured databases remain one of the key causes of data leaks. Most businesses generate some type of data on their employees, partners, clients, or customers, and store it in the <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud</a> for easy access and actionable insights. However, some businesses don’t understand the shared responsibility model of cloud security or are simply reckless and sloppy when it comes to securing their cloud-stored data. Others, according to Cassius Edison, COO of Closed Door Security, have a problem with visibility of their IT real estate:</p><p>“The range of technology now used and managed by firms globally has made misconfigurations an increasingly persistent problem,” Edison explained. “Many organizations fail to maintain full visibility of their IT real estate and fail to perform proper audits of their systems, which inevitably leads to oversights in security and monitoring.”</p><p>For Edison, tackling misconfigurations internally can be difficult, “especially at large companies where teams work independently across a range of systems,” and advises organizations to bring in independent pentesters and security auditors. </p><p>Some of the biggest data leaks in the world came not from hackers breaking into locked-down systems, but from businesses inadvertently exposing their customers. </p><p>In 2026 alone, we’ve seen more than 670 million identity records exposed by Infutor, a data-driven consumer identity management company, as well as more than three billion records exposed through a misconfigured MongoDB database managed by global identity verification services, IDMerit.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/massive-data-breach-sees-220-million-traveler-records-exposed-nine-years-of-airline-info-leaked-including-passenger-and-passport-details</link>
                                                                            <description>
                            <![CDATA[ A series of misconfigurations allowed researchers to access a treasure trove of sensitive data - the archive has since been locked down. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8uHcVN224Fk6zmJ3KTpaSE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 20:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:description>                                                            <media:text><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:text>
                                <media:title type="plain"><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kinryū Labs found misconfigured APIS database in Vietnam exposing 220M passenger and crew records</strong></li><li><strong>Data included PII, travel details, seat assignments, and baggage references from 2017–2026</strong></li><li><strong>Archive locked and there is no evidence yet of dark web sale</strong></li></ul><p>Millions of travellers have had their sensitive information exposed on the internet, thanks to a “series of misconfigurations” discovered in a cloud database, experts have warned.</p><p>In early June 2026, security researchers from Kinryū Labs discovered an Elasticsearch cluster which, although inaccessible from the open internet, allowed access through an alternate route - a cloud-based path. Once inside that route, the researchers discovered that the cluster accepted default credentials, granting access to an archive with 29 indices, weighing roughly 107GB.</p><p>The archive was apparently generated by an Advance Passenger Information System (APIS), a system airlines use to collect and send passenger and crew information to country authorities before flight arrival or departure. Usually, the system collects people’s names, birth dates, nationalities, passport and travel document numbers, and flight details, which are then used for border control, immigration, and similar cases. In this case, however, it also contained people’s sex, document expiration dates, issuing countries, airlines, departure, destination and transit airports, seat assignments, baggage reference, and more.</p><p>It is not known who operated the APIS, or who owns and runs the database. All the researchers managed to find is that it was hosted in Viettel-assigned IP space in Hanoi, Vietnam’s capital.</p><h2 id="who-was-affected">Who was affected?</h2><p>Of the 29 discovered indices, two were rather large: one contained 210,318, 069 passenger records, while another 10,465,631 crew records. In total, 220 million records, created between January 2017 and April 2026, from people who traveled to, from, or through Vietnam during that period.</p><p>The records don’t correspond to individuals, however. If a person travelled multiple times, they will show up in the archive multiple times. Canadians, Chinese, Korean, and New Zealandian nationals are among the ones whose information was exposed. The database is not limited to a specific airline, either - various airlines in Asia-Pacific, Europe, and Middle East regions were mentioned in the researchers’ report.</p><p>Since the researchers could not attribute the database to a specific entity, they reported it to the Vietnamese authorities, different airlines mentioned in the archives, and the country’s CERT (Computer Emergency Response Team), on June 3. The archive was locked down a week later, on June 8. According to BleepingComputer, it was the Singapore Airlines’ security team that took the lead on remediation efforts, telling the researchers they “engaged the relevant parties” and have “taken steps to contain the issue.”</p><p>Without a proper audit of the logs, and a full-blown forensic investigation, it is impossible to tell if any threat actors reached the database before the researchers, or if they exfiltrated and used the data found inside in identity theft, wire fraud, or other scams. What’s (somewhat) comforting is that there is no evidence of such activities on the dark web, and no hacking groups have made such claims. No one is selling the archive on the dark web, either.</p><h2 id="number-one-causes-of-data-spills">Number one causes of data spills </h2><p>Misconfigured databases remain one of the key causes of data leaks. Most businesses generate some type of data on their employees, partners, clients, or customers, and store it in the <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud</a> for easy access and actionable insights. However, some businesses don’t understand the shared responsibility model of cloud security or are simply reckless and sloppy when it comes to securing their cloud-stored data. Others, according to Cassius Edison, COO of Closed Door Security, have a problem with visibility of their IT real estate:</p><p>“The range of technology now used and managed by firms globally has made misconfigurations an increasingly persistent problem,” Edison explained. “Many organizations fail to maintain full visibility of their IT real estate and fail to perform proper audits of their systems, which inevitably leads to oversights in security and monitoring.”</p><p>For Edison, tackling misconfigurations internally can be difficult, “especially at large companies where teams work independently across a range of systems,” and advises organizations to bring in independent pentesters and security auditors. </p><p>Some of the biggest data leaks in the world came not from hackers breaking into locked-down systems, but from businesses inadvertently exposing their customers. </p><p>In 2026 alone, we’ve seen more than 670 million identity records exposed by Infutor, a data-driven consumer identity management company, as well as more than three billion records exposed through a misconfigured MongoDB database managed by global identity verification services, IDMerit.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Liquid Network halts new transactions after 'nice guy' hackers steal nearly all its Bitcoin — but then return most of it after a patch is issued ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Liquid Network hack exploited a bug in SideSwap, releasing 3,998 BTC (~$313M) to attackers</strong></li><li><strong>Hackers claimed “white‑hat” intent, returning 3,400 BTC after fixes, leaving 598 BTC missing</strong></li><li><strong>Network remains paused as Blockstream and Federation patch vulnerabilities and prepare safe restart</strong></li></ul><p>The latest twist in the Liquid Network Bitcoin hack is worthy of a short movie, if not a full-length feature film. </p><p>Apparently, the hackers are actually the good guys, who stole the money to “keep it safe” until a vulnerability in the protocol had been fully resolved. They promised to return the funds afterwards.</p><h2 id="what-is-liquid-network">What is Liquid Network?</h2><p>Liquid Network was designed to solve a specific problem on the Bitcoin blockchain - being rather slow. The transactions on the network are recorded in a “block”, which is added to the chain roughly once every 10 minutes. Also, each block can only hold a limited number of transactions, which means the network can handle a smaller number of transactions per second, compared to conventional payment systems. Transactions that don’t make it into a specific block then need to wait for the next one, thus extending the confirmation time.</p><p>To solve that problem, Liquid Network was built. It runs its own Bitcoin reserve and its own blockchain, also known as a “sidechain”. When a person wants to use Liquid Network to send money quickly, they first convert their Bitcoin into Liquid Bitcoin, or L-BTC. They can then send it to another person much faster than a regular Bitcoin transaction. The recipient can keep the money on Liquid or convert it back to regular Bitcoin and move it to the Bitcoin network. </p><p>This way, Liquid provides a faster network without requiring every transaction to happen directly on the Bitcoin blockchain.</p><p>Besides speeding up Bitcoin transactions, Liquid Network also allows users (companies and other entities) to create and trade other digital assets, including tokenized securities, or stablecoins.</p><p>The project was built by Blockstream, a Bitcoin-focused technology company founded in 2014. It is run by the Liquid Federation, a group of more than 80 member companies, including exchanges, infrastructure companies, and financial institutions. A smaller group of members (15 to be exact) operate the network’s “functionaries” (servers that keep the network running), while the wider group has a governance role. Members vote on three boards (Technology, Membership, Oversight), handling ideas such as technical direction, internal rules, memberships, and more. </p><h2 id="what-happened-to-it">What happened to it?</h2><p>In early September 2026, still unidentified actors managed to generate around 4,000 L-BTC, without putting in the corresponding 4,000 BTC into Liquid. As soon as they did it, they sent the L-BTC through SideSwap, a legitimate service that is used to convert L-BTC back to Bitcoin and vice-versa. The system apparently regarded the withdrawal as legitimate because, as was later determined, a bug prevented SideSwap from distinguishing between “real” and “fake” L-BTC, and treated them all the same.</p><p>As a result, the Liquid Federation ended up releasing 3,998 real BTC (more than $313 million at press time) to the attackers. As soon as the operators realized what had happened, they halted new transactions and warned about possible disruptions until the service was restored. </p><p>Then came the movie twist: the hacker started communicating with network maintainers through on-chain Bitcoin transactions, promising to return the funds when the vulnerability is fully resolved:</p><p>“Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix,” one of the messages read.</p><p>Earlier today, Coindesk reported that the hackers partially kept their promise, returning 3,400 of the 4,000 BTC drained, which suggests that the flaw was remedied. The remaining 598 BTC, worth approximately $47 million, is currently unaccounted for. </p><p>“3,400 BTC of the roughly 4,000 BTC withdrawn on September 6 has been returned to the Liquid Federation wallet. The return followed confirmation from Blockstream that the affected bridge nodes have been patched,” wrote Samson Mow, former chief strategy officer at Blockstream, on X. “Approximately 598 BTC remains outstanding, and Blockstream continues to engage with the white-hat hackers.”</p><p>He added that the network remains paused while Blockstream and Federation members make additional fixes and security improvements, resolve the chain split, and prepare for a safe restart. </p><p>“Liquid <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">wallets</a> and services will continue to be affected during this time. No user action is needed, and please do not send Bitcoin to Liquid peg-in addresses until we confirm the network has restarted,” he added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/liquid-network-halts-new-transactions-after-nice-guy-hackers-steal-nearly-all-its-bitcoin-but-then-return-most-of-it-after-a-patch-is-issued</link>
                                                                            <description>
                            <![CDATA[ Liquid Network is still disrupted, but users can breathe a sigh of relief as most of the stolen funds have been returned. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oguXoFVDTGkmgxvQsQBpU3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UweTPZX99rMmYJQoBvPT44-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UweTPZX99rMmYJQoBvPT44-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Bitcoin]]></media:description>                                                            <media:text><![CDATA[Bitcoin]]></media:text>
                                <media:title type="plain"><![CDATA[Bitcoin]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UweTPZX99rMmYJQoBvPT44-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Liquid Network hack exploited a bug in SideSwap, releasing 3,998 BTC (~$313M) to attackers</strong></li><li><strong>Hackers claimed “white‑hat” intent, returning 3,400 BTC after fixes, leaving 598 BTC missing</strong></li><li><strong>Network remains paused as Blockstream and Federation patch vulnerabilities and prepare safe restart</strong></li></ul><p>The latest twist in the Liquid Network Bitcoin hack is worthy of a short movie, if not a full-length feature film. </p><p>Apparently, the hackers are actually the good guys, who stole the money to “keep it safe” until a vulnerability in the protocol had been fully resolved. They promised to return the funds afterwards.</p><h2 id="what-is-liquid-network">What is Liquid Network?</h2><p>Liquid Network was designed to solve a specific problem on the Bitcoin blockchain - being rather slow. The transactions on the network are recorded in a “block”, which is added to the chain roughly once every 10 minutes. Also, each block can only hold a limited number of transactions, which means the network can handle a smaller number of transactions per second, compared to conventional payment systems. Transactions that don’t make it into a specific block then need to wait for the next one, thus extending the confirmation time.</p><p>To solve that problem, Liquid Network was built. It runs its own Bitcoin reserve and its own blockchain, also known as a “sidechain”. When a person wants to use Liquid Network to send money quickly, they first convert their Bitcoin into Liquid Bitcoin, or L-BTC. They can then send it to another person much faster than a regular Bitcoin transaction. The recipient can keep the money on Liquid or convert it back to regular Bitcoin and move it to the Bitcoin network. </p><p>This way, Liquid provides a faster network without requiring every transaction to happen directly on the Bitcoin blockchain.</p><p>Besides speeding up Bitcoin transactions, Liquid Network also allows users (companies and other entities) to create and trade other digital assets, including tokenized securities, or stablecoins.</p><p>The project was built by Blockstream, a Bitcoin-focused technology company founded in 2014. It is run by the Liquid Federation, a group of more than 80 member companies, including exchanges, infrastructure companies, and financial institutions. A smaller group of members (15 to be exact) operate the network’s “functionaries” (servers that keep the network running), while the wider group has a governance role. Members vote on three boards (Technology, Membership, Oversight), handling ideas such as technical direction, internal rules, memberships, and more. </p><h2 id="what-happened-to-it">What happened to it?</h2><p>In early September 2026, still unidentified actors managed to generate around 4,000 L-BTC, without putting in the corresponding 4,000 BTC into Liquid. As soon as they did it, they sent the L-BTC through SideSwap, a legitimate service that is used to convert L-BTC back to Bitcoin and vice-versa. The system apparently regarded the withdrawal as legitimate because, as was later determined, a bug prevented SideSwap from distinguishing between “real” and “fake” L-BTC, and treated them all the same.</p><p>As a result, the Liquid Federation ended up releasing 3,998 real BTC (more than $313 million at press time) to the attackers. As soon as the operators realized what had happened, they halted new transactions and warned about possible disruptions until the service was restored. </p><p>Then came the movie twist: the hacker started communicating with network maintainers through on-chain Bitcoin transactions, promising to return the funds when the vulnerability is fully resolved:</p><p>“Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix,” one of the messages read.</p><p>Earlier today, Coindesk reported that the hackers partially kept their promise, returning 3,400 of the 4,000 BTC drained, which suggests that the flaw was remedied. The remaining 598 BTC, worth approximately $47 million, is currently unaccounted for. </p><p>“3,400 BTC of the roughly 4,000 BTC withdrawn on September 6 has been returned to the Liquid Federation wallet. The return followed confirmation from Blockstream that the affected bridge nodes have been patched,” wrote Samson Mow, former chief strategy officer at Blockstream, on X. “Approximately 598 BTC remains outstanding, and Blockstream continues to engage with the white-hat hackers.”</p><p>He added that the network remains paused while Blockstream and Federation members make additional fixes and security improvements, resolve the chain split, and prepare for a safe restart. </p><p>“Liquid <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">wallets</a> and services will continue to be affected during this time. No user action is needed, and please do not send Bitcoin to Liquid peg-in addresses until we confirm the network has restarted,” he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft 365 users hit by two major threat campaigns - fake IT calls and phishing emails target users across the world ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft 365 users targeted by phishing campaigns using BigBear 2.0 and AiTM proxies</strong></li><li><strong>Attackers impersonate IT staff via calls, Teams, and email to steal credentials and bypass MFA</strong></li><li><strong>CloudSEK tracked 5,000+ stolen records; Arctic Wolf urges phishing‑resistant MFA and conditional access</strong></li></ul><p>Microsoft 365 users are facing a barrage of cyberattacks all aimed at a single goal - to try and expose credentials which can later be used against employers in data theft attacks.</p><p>Different groups conduct their raids and bypass multi-factor authentication (MFA) protection to access victim accounts - CloudSEK, for example, said that some groups are using BigBear 2.0, a new phishing-as-a-service (PhaaS) framework that allows crooks to intercept passwords and authenticated session cookies.</p><p>Arctic Wolf, on the other hand, focused on a single threat actor, which it dubbed PREY-0058. This group, despite significant overlaps with other collectives in terms of techniques, technologies, and procedures, is not a rebrand of older organizations. Instead, the researchers believe the lines between the groups are blurred and that there is a large group of affiliates, splinter crews, and other cohorts using the same phishing infrastructure and thus often confuse defenders and analysts.</p><h2 id="similar-methods-similar-results">Similar methods, similar results</h2><p>The attack methodology is similar across the spectrum. Crooks would call their victims on the phone or approach them via Teams and email. They would introduce themselves as members of the IT help desk sent to sort out a specific problem or issue. </p><p>Then, they would either convince the victim to grant remote access, or to open a spoofed Microsoft 365 login page and enter their credentials there. In both cases, the goal is the same - to get the victim to type in their username, password, and 2FA code, on a fake site built by BigBear 2.0 or a similar phishing framework. This framework, using an attacker-in-the-middle (AiTM) proxy between the victim and legitimate Microsoft infrastructure, harvests credentials, <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA codes</a>, and session cookies, and replays them through an API essentially hijacking a legitimate authentication session.</p><p>Once they gain access, the attackers can do all sorts of things, but they are mostly focused on exfiltrating sensitive data from Outlook, Teams, SharePoint, and OneDrive. Deploying <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> is rarely seen. </p><p>The campaign CloudSEK has been tracking has been rather successful, the researchers argue, saying BigBear 2.0 was used to exfiltrate more than 5,000 credential records, “including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies - affecting 3,331 unique victim IPs across 40+ countries with the operation still active at the time of writing.” </p><p>“The multi-user PhaaS panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots, each receiving stolen credentials in real time.”</p><p>Speaking to <a href="https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/" target="_blank"><em>BleepingComputer</em></a>, CloudSEK says the campaign targeted 461 organizations, out of which 258 have had at least one set of credentials compromised. </p><h2 id="defending-with-phishing-resistant-mfa">Defending with phishing-resistant MFA</h2><p>Arctic Wolf’s researchers stressed that the attackers are focused primarily on US-based businesses: construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services, <a href="https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html" target="_blank"><em>The Hacker News</em></a> reported. The researchers advise organizations to implement Conditional Access policies, deploy phishing-resistant MFA, and restrict the scope of data users can access via SharePoint. Obviously, employee education on the dangers of phishing cannot be understated.</p><p>"Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure," Arctic Wolf said.</p><p>Phishing-resistant MFA is multi-factor authentication designed so that an attacker cannot trick a person into handing over authorization code, either via a message, or through a fake login page. </p><p>These include products such as passkeys, YubiKeys <a href="https://www.techradar.com/best/best-security-key" target="_blank">security keys</a>, and authentication methods based on FIDO2/WebAuthn. Since phishing-resistant MFA cryptographically ties the authentication to the legitimate website, the authentication cannot simply be forwarded to an attacker.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsoft-365-users-hit-by-two-major-threat-campaigns-fake-it-calls-and-phishing-emails-target-users-across-the-world</link>
                                                                            <description>
                            <![CDATA[ BigBear 2.0 and PREY-0058 are wreaking havoc across businesses as they scam employees into handing over login credentials and MFA codes. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C6BxVw2HaDLYXxNeeyT4HQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vnpBJPCcs2siQw5rCEsDzG-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 15:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/vnpBJPCcs2siQw5rCEsDzG-1280-80.png">
                                                            <media:credit><![CDATA[Currys]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft 365]]></media:description>                                                            <media:text><![CDATA[Microsoft 365]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft 365]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vnpBJPCcs2siQw5rCEsDzG-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft 365 users targeted by phishing campaigns using BigBear 2.0 and AiTM proxies</strong></li><li><strong>Attackers impersonate IT staff via calls, Teams, and email to steal credentials and bypass MFA</strong></li><li><strong>CloudSEK tracked 5,000+ stolen records; Arctic Wolf urges phishing‑resistant MFA and conditional access</strong></li></ul><p>Microsoft 365 users are facing a barrage of cyberattacks all aimed at a single goal - to try and expose credentials which can later be used against employers in data theft attacks.</p><p>Different groups conduct their raids and bypass multi-factor authentication (MFA) protection to access victim accounts - CloudSEK, for example, said that some groups are using BigBear 2.0, a new phishing-as-a-service (PhaaS) framework that allows crooks to intercept passwords and authenticated session cookies.</p><p>Arctic Wolf, on the other hand, focused on a single threat actor, which it dubbed PREY-0058. This group, despite significant overlaps with other collectives in terms of techniques, technologies, and procedures, is not a rebrand of older organizations. Instead, the researchers believe the lines between the groups are blurred and that there is a large group of affiliates, splinter crews, and other cohorts using the same phishing infrastructure and thus often confuse defenders and analysts.</p><h2 id="similar-methods-similar-results">Similar methods, similar results</h2><p>The attack methodology is similar across the spectrum. Crooks would call their victims on the phone or approach them via Teams and email. They would introduce themselves as members of the IT help desk sent to sort out a specific problem or issue. </p><p>Then, they would either convince the victim to grant remote access, or to open a spoofed Microsoft 365 login page and enter their credentials there. In both cases, the goal is the same - to get the victim to type in their username, password, and 2FA code, on a fake site built by BigBear 2.0 or a similar phishing framework. This framework, using an attacker-in-the-middle (AiTM) proxy between the victim and legitimate Microsoft infrastructure, harvests credentials, <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA codes</a>, and session cookies, and replays them through an API essentially hijacking a legitimate authentication session.</p><p>Once they gain access, the attackers can do all sorts of things, but they are mostly focused on exfiltrating sensitive data from Outlook, Teams, SharePoint, and OneDrive. Deploying <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> is rarely seen. </p><p>The campaign CloudSEK has been tracking has been rather successful, the researchers argue, saying BigBear 2.0 was used to exfiltrate more than 5,000 credential records, “including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies - affecting 3,331 unique victim IPs across 40+ countries with the operation still active at the time of writing.” </p><p>“The multi-user PhaaS panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots, each receiving stolen credentials in real time.”</p><p>Speaking to <a href="https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/" target="_blank"><em>BleepingComputer</em></a>, CloudSEK says the campaign targeted 461 organizations, out of which 258 have had at least one set of credentials compromised. </p><h2 id="defending-with-phishing-resistant-mfa">Defending with phishing-resistant MFA</h2><p>Arctic Wolf’s researchers stressed that the attackers are focused primarily on US-based businesses: construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services, <a href="https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html" target="_blank"><em>The Hacker News</em></a> reported. The researchers advise organizations to implement Conditional Access policies, deploy phishing-resistant MFA, and restrict the scope of data users can access via SharePoint. Obviously, employee education on the dangers of phishing cannot be understated.</p><p>"Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure," Arctic Wolf said.</p><p>Phishing-resistant MFA is multi-factor authentication designed so that an attacker cannot trick a person into handing over authorization code, either via a message, or through a fake login page. </p><p>These include products such as passkeys, YubiKeys <a href="https://www.techradar.com/best/best-security-key" target="_blank">security keys</a>, and authentication methods based on FIDO2/WebAuthn. Since phishing-resistant MFA cryptographically ties the authentication to the legitimate website, the authentication cannot simply be forwarded to an attacker.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Introducing AI-as-a-Service ]]></title>
                                                                                                <dc:content><![CDATA[ <p>2025 was a transformative year for <a href="https://www.techradar.com/best/best-ai-tools">artificial intelligence</a>, and 2026 is already proving to be equally significant. </p><p>While generative AI dominated conversations just a few years ago, the focus is now shifting towards agentic AI, where intelligent systems can take action, interact with business processes, and support employees in more meaningful ways.</p><p>As these capabilities continue to evolve, organizations are looking for better ways to connect AI systems to the applications, data and services that drive their operations. </p><p>This is where technologies such as Model Context Protocol (MCP) are becoming increasingly important. </p><p>Rather than creating bespoke integrations for every tool or system, MCP provides a standardized way for AI models and agents to access information and perform actions across an organization's technology estate.</p><p>While MCP is not a requirement for every AI implementation today, it represents a natural next step for organizations looking to move beyond isolated AI use cases and towards more integrated, scalable AI ecosystems.</p><p>However, greater integration also introduces greater responsibility. Effective governance remains essential for any AI deployment, but it becomes even more critical when autonomous agents are granted access to business systems, processes and sensitive information. </p><p>Organizations must establish clear guardrails that define what agents can access, what actions they can perform, and how their activities are monitored. Without appropriate oversight, businesses risk agents operating beyond their intended scope or creating unintended consequences across interconnected systems.</p><h2 id="the-impact-on-software-as-a-service">The impact on Software-as-a-Service</h2><p>Few sectors will feel the effects of this shift more than Software-as-a-Service (SaaS).</p><p>For years, SaaS applications have been built around human interaction. Users access platforms through dashboards and interfaces, navigate predefined workflows, and manually complete tasks. The application itself serves as the primary workspace where work is performed.</p><p>Agentic AI introduces a different model.</p><p>Rather than navigating <a href="https://www.techradar.com/best/best-small-business-software">software</a> in the same way a person would, agents can interact directly with APIs, services and data sources. This allows them to retrieve information, execute actions and orchestrate processes across multiple systems without relying on traditional user journeys.</p><p>That does not mean SaaS applications will disappear. In fact, they will continue to play a critical role in storing structured data, enforcing business rules and managing workflows. What is likely to change is how those applications are consumed.</p><p>Instead of being the primary destination where work happens, many SaaS platforms will increasingly act as sources of capability and information that AI agents can utilize on behalf of users. As a result, organizations may find themselves focusing less on which <a href="https://www.techradar.com/best/best-mobile-app-development-software">application</a> employees need to access and more on how services and data can be brought together to achieve the desired business outcome.</p><p>Human interfaces will still matter. Users will continue to need visibility, exception handling and control mechanisms, particularly when business-critical processes are involved. The challenge for software providers will be balancing traditional user experiences with new AI-driven interaction models while maintaining compatibility, reliability and operational resilience.</p><h2 id="breaking-down-agent-silos">Breaking down agent silos</h2><p>The next stage in the evolution of agentic AI is not simply creating more agents. It is enabling agents to work together effectively.</p><p>Many organizations already struggle with fragmented systems, disconnected data and isolated processes. Without careful planning, agents risk creating a new generation of silos, each operating within its own limited context and producing inconsistent outcomes.</p><p>To avoid this, businesses must focus on shared context, connected data and interoperable services. The goal is not to have individual agents automating isolated tasks but to enable multiple agents to contribute towards broader business objectives across entire processes.</p><p>When agents can access consistent information and operate across organizational boundaries, the value shifts from discrete task automation to coordinated execution. Rather than supporting an individual stage of a workflow, agents can participate in end-to-end processes while remaining aligned to business policies, operational requirements and organizational goals.</p><p>This represents an important architectural shift. Software increasingly becomes something that agents consume programmatically, while integration, context and orchestration become central to delivering outcomes at scale.</p><h2 id="mitigating-risk-in-aiaas">Mitigating risk in AIaaS</h2><p>Unlocking these new capabilities requires more than deploying AI tools. Organizations need governance frameworks, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls and operational processes that allow autonomy to be introduced safely and responsibly.</p><p>As agents gain access to more systems and collaborate across workflows, operational complexity inevitably increases. Businesses must define clear policies around what agents can and cannot do, what data they can access, and what approvals are required before actions are taken.</p><p>These controls should be embedded into the orchestration layer itself, ensuring governance is applied consistently across all agent-led activities rather than being treated as an afterthought.</p><p>Traceability and accountability are equally important. Completing a task successfully is only part of the equation. Organizations must understand how decisions were made, what information was used, and which policies were applied throughout the process. This visibility will be essential for compliance, security and maintaining trust in autonomous systems.</p><p>The role of <a href="https://www.techradar.com/best/best-linux-distro-for-developers">developers</a> will also evolve. Rather than spending significant time building and maintaining point-to-point integrations, they will increasingly focus on designing agent behaviors, defining boundaries, managing orchestration and ensuring solutions operate within established governance frameworks.</p><p>The organizations that succeed will be those that balance innovation with control. Too little governance introduces risk, while excessive restrictions can prevent businesses from realizing the benefits of AI altogether.</p><p>Agentic AI should not be viewed as a replacement for software development or existing technology investments. Instead, it represents a powerful new interaction layer that changes how organizations access information, automate processes and deliver outcomes.</p><p>Businesses that invest now in integration foundations, governance models and workforce skills will be best placed to take advantage of the opportunities this next phase of AI creates.</p><p><em></em><a href="https://www.techradar.com/news/best-business-laptops"><em>We've reviewed the best business laptops</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/introducing-ai-as-a-service</link>
                                                                            <description>
                            <![CDATA[ As agentic AI evolves, the impact will be felt throughout the industry - especially on SaaS. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iYiwHcPKFNgfQ9vFiutmde</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 10:33:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jay Fitzhenry ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>2025 was a transformative year for <a href="https://www.techradar.com/best/best-ai-tools">artificial intelligence</a>, and 2026 is already proving to be equally significant. </p><p>While generative AI dominated conversations just a few years ago, the focus is now shifting towards agentic AI, where intelligent systems can take action, interact with business processes, and support employees in more meaningful ways.</p><p>As these capabilities continue to evolve, organizations are looking for better ways to connect AI systems to the applications, data and services that drive their operations. </p><p>This is where technologies such as Model Context Protocol (MCP) are becoming increasingly important. </p><p>Rather than creating bespoke integrations for every tool or system, MCP provides a standardized way for AI models and agents to access information and perform actions across an organization's technology estate.</p><p>While MCP is not a requirement for every AI implementation today, it represents a natural next step for organizations looking to move beyond isolated AI use cases and towards more integrated, scalable AI ecosystems.</p><p>However, greater integration also introduces greater responsibility. Effective governance remains essential for any AI deployment, but it becomes even more critical when autonomous agents are granted access to business systems, processes and sensitive information. </p><p>Organizations must establish clear guardrails that define what agents can access, what actions they can perform, and how their activities are monitored. Without appropriate oversight, businesses risk agents operating beyond their intended scope or creating unintended consequences across interconnected systems.</p><h2 id="the-impact-on-software-as-a-service">The impact on Software-as-a-Service</h2><p>Few sectors will feel the effects of this shift more than Software-as-a-Service (SaaS).</p><p>For years, SaaS applications have been built around human interaction. Users access platforms through dashboards and interfaces, navigate predefined workflows, and manually complete tasks. The application itself serves as the primary workspace where work is performed.</p><p>Agentic AI introduces a different model.</p><p>Rather than navigating <a href="https://www.techradar.com/best/best-small-business-software">software</a> in the same way a person would, agents can interact directly with APIs, services and data sources. This allows them to retrieve information, execute actions and orchestrate processes across multiple systems without relying on traditional user journeys.</p><p>That does not mean SaaS applications will disappear. In fact, they will continue to play a critical role in storing structured data, enforcing business rules and managing workflows. What is likely to change is how those applications are consumed.</p><p>Instead of being the primary destination where work happens, many SaaS platforms will increasingly act as sources of capability and information that AI agents can utilize on behalf of users. As a result, organizations may find themselves focusing less on which <a href="https://www.techradar.com/best/best-mobile-app-development-software">application</a> employees need to access and more on how services and data can be brought together to achieve the desired business outcome.</p><p>Human interfaces will still matter. Users will continue to need visibility, exception handling and control mechanisms, particularly when business-critical processes are involved. The challenge for software providers will be balancing traditional user experiences with new AI-driven interaction models while maintaining compatibility, reliability and operational resilience.</p><h2 id="breaking-down-agent-silos">Breaking down agent silos</h2><p>The next stage in the evolution of agentic AI is not simply creating more agents. It is enabling agents to work together effectively.</p><p>Many organizations already struggle with fragmented systems, disconnected data and isolated processes. Without careful planning, agents risk creating a new generation of silos, each operating within its own limited context and producing inconsistent outcomes.</p><p>To avoid this, businesses must focus on shared context, connected data and interoperable services. The goal is not to have individual agents automating isolated tasks but to enable multiple agents to contribute towards broader business objectives across entire processes.</p><p>When agents can access consistent information and operate across organizational boundaries, the value shifts from discrete task automation to coordinated execution. Rather than supporting an individual stage of a workflow, agents can participate in end-to-end processes while remaining aligned to business policies, operational requirements and organizational goals.</p><p>This represents an important architectural shift. Software increasingly becomes something that agents consume programmatically, while integration, context and orchestration become central to delivering outcomes at scale.</p><h2 id="mitigating-risk-in-aiaas">Mitigating risk in AIaaS</h2><p>Unlocking these new capabilities requires more than deploying AI tools. Organizations need governance frameworks, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls and operational processes that allow autonomy to be introduced safely and responsibly.</p><p>As agents gain access to more systems and collaborate across workflows, operational complexity inevitably increases. Businesses must define clear policies around what agents can and cannot do, what data they can access, and what approvals are required before actions are taken.</p><p>These controls should be embedded into the orchestration layer itself, ensuring governance is applied consistently across all agent-led activities rather than being treated as an afterthought.</p><p>Traceability and accountability are equally important. Completing a task successfully is only part of the equation. Organizations must understand how decisions were made, what information was used, and which policies were applied throughout the process. This visibility will be essential for compliance, security and maintaining trust in autonomous systems.</p><p>The role of <a href="https://www.techradar.com/best/best-linux-distro-for-developers">developers</a> will also evolve. Rather than spending significant time building and maintaining point-to-point integrations, they will increasingly focus on designing agent behaviors, defining boundaries, managing orchestration and ensuring solutions operate within established governance frameworks.</p><p>The organizations that succeed will be those that balance innovation with control. Too little governance introduces risk, while excessive restrictions can prevent businesses from realizing the benefits of AI altogether.</p><p>Agentic AI should not be viewed as a replacement for software development or existing technology investments. Instead, it represents a powerful new interaction layer that changes how organizations access information, automate processes and deliver outcomes.</p><p>Businesses that invest now in integration foundations, governance models and workforce skills will be best placed to take advantage of the opportunities this next phase of AI creates.</p><p><em></em><a href="https://www.techradar.com/news/best-business-laptops"><em>We've reviewed the best business laptops</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Another Rowhammer attack has been detected, and Nvidia workstation GPUs are firmly in the firing line ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>GPUThor is the first Rowhammer attack to defeat ECC on Nvidia GPUs and reach a root shell on the host</strong></li><li><strong>It affects four Ampere workstation cards with GDDR6 memory, the RTX A4000, A4500, A5000 and A6000</strong></li><li><strong>Non-uniform hammering, enabled by defeating GPU memory coalescing and finding that Target Row Refresh (TRR) mitigations fire once every 72 refresh intervals, delivers effectively 6.6 times the hammering intensity of prior attacks</strong></li></ul><p>Four researchers at the University of Toronto have disclosed GPUThor, a Rowhammer technique that breaks the error correction Nvidia has spent the past year recommending as the defense against exactly this class of attack.</p><p>Chris S. Lin, Joyce Qu, Aditya Rajeev and Gururaj Saileshwar are expected to present the <a href="https://gputhor.com/" target="_blank" rel="nofollow">paper</a> outlining their approach and subsequent findings at ACM CCS 2026.</p><p>The attacks target Ampere-generation workstation cards with GDDR6 memory, specifically the RTX A4000, A4500, A5000 and A6000, and it turns an unprivileged CUDA program into a root shell on the host.</p><h2 id="an-attack-that-matters-much-more-than-its-predecessors">An attack that matters much more than its predecessors</h2><p>Rowhammer works by repeatedly activating a DRAM row until charge leaks from cells in the physically adjacent rows and flips their bits. The attacker never touches the victim's data directly, making it an excellent precursor to tampering, sandbox escape, and privilege escalation, among other things.</p><p>This approach is possible despite an in-chip countermeasure called TRR that accompanies ECC-enabled chips on these GPUs. TRR aims to prevent Rowhammer attacks by tracking how frequently specific memory rows are activated and automatically refreshing adjacent rows before a malicious bit flip can occur.</p><p>This approach works well on paper and, when Rowhammer attacks hammer uniformly, offers decent protection. The problem arises when approaches such as GPUThor use non-uniform hammering, which is much more likely to succeed. Non-uniform hammering is not exactly new, having <a href="https://www.techradar.com/news/your-ddr4-memory-could-be-facing-serious-assaults" target="_blank">already succeeded on the CPU side of the spectrum</a> thanks to the well-documented Blacksmith attack vector.</p><p>GPUThor is the third attack from broadly the same group in eighteen months, following GPUHammer in 2025 and GPUBreach earlier this year, and it matters because the previous two stopped working the moment a user typed the command to enable ECC.</p><p>ECC was essentially Nvidia's go-to response to reported Rowhammer attacks, but it may no longer be a solution in its current state. By hammering non-uniformly, the researchers opened another attack vector for Nvidia's Ampere-based GPUs, which are overwhelmingly affected by the technique.</p><p>With ECC disabled, GPUThor produced 72,000 to 377,000 bit flips per gigabyte across four Ampere-based cards, with Nvidia's A5000 being reported as the most vulnerable. That approaches the roughly 550,000 flips per gigabyte that Blacksmith achieves on DDR4, which is cause for concern: GPU Rowhammer is now in the same league as CPU Rowhammer.</p><p>When enabled, the researchers said ECC protectors reduced, but did not completely mitigate, the issue: they delivered double-bit errors and 2 triple-bit errors that the technique 'fixed' by choosing the wrong value.</p><p>On <a href="https://www.techradar.com/news/nvidia-launches-ampere-for-graphics-professionals-rtx-a40-and-rtx-a6000-cards" target="_blank">an RTX A6000 with ECC enabled</a>, the GPUThor technique forces one GPU reset every 2 hours, killing all running processes on the GPU; as a result, the GPU flags itself as RMA-read within a day.</p><p>The team disclosed the attack pattern to Nvidia on 29 April 2026 and subsequently to Google, Microsoft and AWS, and held the work until the 25th of August. A code release is scheduled for the 15th of November, even though there is currently no CVE information or patch being deployed to address the issue.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/another-rowhammer-attack-has-been-detected-and-nvidia-workstation-gpus-are-firmly-in-the-firing-line</link>
                                                                            <description>
                            <![CDATA[ Nvidia spent a year telling people ECC was the answer to GPU Rowhammer. GPUThor might have just proved them wrong. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CEkDYAAjrtiexrJ9e5NzAD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D9pZcgdPinp5ty7pPDjKeY-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/D9pZcgdPinp5ty7pPDjKeY-1280-80.png">
                                                            <media:credit><![CDATA[Nvidia]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Nvidia]]></media:description>                                                            <media:text><![CDATA[Nvidia]]></media:text>
                                <media:title type="plain"><![CDATA[Nvidia]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D9pZcgdPinp5ty7pPDjKeY-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>GPUThor is the first Rowhammer attack to defeat ECC on Nvidia GPUs and reach a root shell on the host</strong></li><li><strong>It affects four Ampere workstation cards with GDDR6 memory, the RTX A4000, A4500, A5000 and A6000</strong></li><li><strong>Non-uniform hammering, enabled by defeating GPU memory coalescing and finding that Target Row Refresh (TRR) mitigations fire once every 72 refresh intervals, delivers effectively 6.6 times the hammering intensity of prior attacks</strong></li></ul><p>Four researchers at the University of Toronto have disclosed GPUThor, a Rowhammer technique that breaks the error correction Nvidia has spent the past year recommending as the defense against exactly this class of attack.</p><p>Chris S. Lin, Joyce Qu, Aditya Rajeev and Gururaj Saileshwar are expected to present the <a href="https://gputhor.com/" target="_blank" rel="nofollow">paper</a> outlining their approach and subsequent findings at ACM CCS 2026.</p><p>The attacks target Ampere-generation workstation cards with GDDR6 memory, specifically the RTX A4000, A4500, A5000 and A6000, and it turns an unprivileged CUDA program into a root shell on the host.</p><h2 id="an-attack-that-matters-much-more-than-its-predecessors">An attack that matters much more than its predecessors</h2><p>Rowhammer works by repeatedly activating a DRAM row until charge leaks from cells in the physically adjacent rows and flips their bits. The attacker never touches the victim's data directly, making it an excellent precursor to tampering, sandbox escape, and privilege escalation, among other things.</p><p>This approach is possible despite an in-chip countermeasure called TRR that accompanies ECC-enabled chips on these GPUs. TRR aims to prevent Rowhammer attacks by tracking how frequently specific memory rows are activated and automatically refreshing adjacent rows before a malicious bit flip can occur.</p><p>This approach works well on paper and, when Rowhammer attacks hammer uniformly, offers decent protection. The problem arises when approaches such as GPUThor use non-uniform hammering, which is much more likely to succeed. Non-uniform hammering is not exactly new, having <a href="https://www.techradar.com/news/your-ddr4-memory-could-be-facing-serious-assaults" target="_blank">already succeeded on the CPU side of the spectrum</a> thanks to the well-documented Blacksmith attack vector.</p><p>GPUThor is the third attack from broadly the same group in eighteen months, following GPUHammer in 2025 and GPUBreach earlier this year, and it matters because the previous two stopped working the moment a user typed the command to enable ECC.</p><p>ECC was essentially Nvidia's go-to response to reported Rowhammer attacks, but it may no longer be a solution in its current state. By hammering non-uniformly, the researchers opened another attack vector for Nvidia's Ampere-based GPUs, which are overwhelmingly affected by the technique.</p><p>With ECC disabled, GPUThor produced 72,000 to 377,000 bit flips per gigabyte across four Ampere-based cards, with Nvidia's A5000 being reported as the most vulnerable. That approaches the roughly 550,000 flips per gigabyte that Blacksmith achieves on DDR4, which is cause for concern: GPU Rowhammer is now in the same league as CPU Rowhammer.</p><p>When enabled, the researchers said ECC protectors reduced, but did not completely mitigate, the issue: they delivered double-bit errors and 2 triple-bit errors that the technique 'fixed' by choosing the wrong value.</p><p>On <a href="https://www.techradar.com/news/nvidia-launches-ampere-for-graphics-professionals-rtx-a40-and-rtx-a6000-cards" target="_blank">an RTX A6000 with ECC enabled</a>, the GPUThor technique forces one GPU reset every 2 hours, killing all running processes on the GPU; as a result, the GPU flags itself as RMA-read within a day.</p><p>The team disclosed the attack pattern to Nvidia on 29 April 2026 and subsequently to Google, Microsoft and AWS, and held the work until the 25th of August. A code release is scheduled for the 15th of November, even though there is currently no CVE information or patch being deployed to address the issue.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Two major security flaws are affecting more than six million WordPress websites ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Wordfence discloses two critical flaws in Elementor Pro and Super Forms</strong></li><li><strong>Bugs allow unauthenticated arbitrary file uploads, enabling remote code execution; both patched recently</strong></li><li><strong>Exploitation attempts already exceed 440,000</strong></li></ul><p>More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild. </p><p>Security researchers Wordfence disclosed finding two flaws, one in Elementor Pro, and one in Super Forms - two popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugins</a>. </p><p><a href="https://www.techradar.com/reviews/elementor" target="_blank">Elementor Pro</a> is a commercial plugin that allows users to build websites using drag-and-drop elements instead of code. With it, they can add advanced widgets, templates, different forms, popups, and more. It is quite a popular solution with more than six million websites actively using it.</p><h2 id="two-bugs-hundreds-of-thousands-of-attacks">Two bugs, hundreds of thousands of attacks</h2><p>According to Wordfence, up until recently, it was vulnerable to an “unrestricted file type upload” bug in all versions up to, and including, 4.2.1. “This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained. “This requires that the targeted site has published a page containing an Elementor Pro Form widget with at least one non-required File Upload field.”</p><p>The bug is tracked as CVE-2026-32475, carries a severity score of 9.8/10 (critical), and was patched in mid-August 2026. So far, Wordfence alone blocked more than 190,000 exploit attempts.</p><p>At roughly the same time, the researchers also reported finding a flaw in Super Forms, a form builder plugin that lets users create and manage forms using a drag-and-drop interface. This plugin, with some 13,000 active installations, contained a bug that allowed arbitrary file upload in all versions up to, and including, 6.3.313.</p><p>“This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained.</p><p>This one is tracked as CVE-2026-14894, also carries a severity score of 9.8/10 (critical) and it, too, was patched a few weeks ago. For this flaw, Wordfence observed more than 250,000 exploitation attempts meaning that cumulatively, these two resulted in 440,000 attacks already. </p><p>Given the widespread adoption of these plugins, and the fact that the flaws are being actively leveraged, users are advised to apply the fixes without delay.</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html" target="_blank"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/two-major-security-flaws-are-affecting-more-than-six-million-wordpress-websites</link>
                                                                            <description>
                            <![CDATA[ Patches are available, so WordPress users should hurry up and apply them. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9ECcHJPTq7j6ouvCBPkCyJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 17:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Wordfence discloses two critical flaws in Elementor Pro and Super Forms</strong></li><li><strong>Bugs allow unauthenticated arbitrary file uploads, enabling remote code execution; both patched recently</strong></li><li><strong>Exploitation attempts already exceed 440,000</strong></li></ul><p>More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild. </p><p>Security researchers Wordfence disclosed finding two flaws, one in Elementor Pro, and one in Super Forms - two popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugins</a>. </p><p><a href="https://www.techradar.com/reviews/elementor" target="_blank">Elementor Pro</a> is a commercial plugin that allows users to build websites using drag-and-drop elements instead of code. With it, they can add advanced widgets, templates, different forms, popups, and more. It is quite a popular solution with more than six million websites actively using it.</p><h2 id="two-bugs-hundreds-of-thousands-of-attacks">Two bugs, hundreds of thousands of attacks</h2><p>According to Wordfence, up until recently, it was vulnerable to an “unrestricted file type upload” bug in all versions up to, and including, 4.2.1. “This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained. “This requires that the targeted site has published a page containing an Elementor Pro Form widget with at least one non-required File Upload field.”</p><p>The bug is tracked as CVE-2026-32475, carries a severity score of 9.8/10 (critical), and was patched in mid-August 2026. So far, Wordfence alone blocked more than 190,000 exploit attempts.</p><p>At roughly the same time, the researchers also reported finding a flaw in Super Forms, a form builder plugin that lets users create and manage forms using a drag-and-drop interface. This plugin, with some 13,000 active installations, contained a bug that allowed arbitrary file upload in all versions up to, and including, 6.3.313.</p><p>“This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained.</p><p>This one is tracked as CVE-2026-14894, also carries a severity score of 9.8/10 (critical) and it, too, was patched a few weeks ago. For this flaw, Wordfence observed more than 250,000 exploitation attempts meaning that cumulatively, these two resulted in 440,000 attacks already. </p><p>Given the widespread adoption of these plugins, and the fact that the flaws are being actively leveraged, users are advised to apply the fixes without delay.</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ G7 tells businesses to get ready for quantum cybersecurity threats ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>G7 urges governments and organizations to begin transitioning to quantum‑resistant encryption</strong></li><li><strong>Warning highlights risk from future quantum computers able to break current standards like AES</strong></li><li><strong>Guidance: inventory cryptographic assets, prioritize critical systems, and adopt phased PQC strategies</strong></li></ul><p>The G7, a collection of some of the world’s most powerful economies, is urging organizations to adopt quantum-resistant encryption as soon as possible and minimize the risk of losing sensitive data to technologically advanced threat actors.</p><p>Virtually every industry in the world today relies on encryption (the process of converting readable data into scrambled, unreadable data so that only someone with the correct key can decode and access it) to protect sensitive information. Banks, telecommunications providers, defense organizations, and practically everyone else are using some form of encryption - most probably AES (Advanced Encryption Standard).</p><p>Decrypting the protected data without the encryption key is considered almost impossible, since the computational effort necessary to pull it off would simply be too large. However, since quantum computers work on a fundamentally different principle, it is believed that once they are mature enough, they will be able to “crack” today’s encryption standards. </p><h2 id="g7-39-s-advice">G7's advice</h2><p>Now, the G7 has <a href="https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action" target="_blank" rel="nofollow">urged</a> government and organizations to remain ahead of the curve by deploying “quantum-resistant encryption”:</p><p>“To protect themselves from the threat brought by CRQCs (cryptographically relevant quantum computers), organizations should begin planning their PQC transition now and should aim to complete their transitions within any the timelines set out by their national cybersecurity authorities,” the warning reads.</p><p>“In addition to quantum-related risks, organizations that delay their PQC transition may lose competitive advantage or may be excluded from contracting opportunities, including public procurement.”</p><p>The G7 advises governments and organizations to take a number of steps, including identifying critical systems and prioritizing them. They should adopt a phased and risk-based strategy, start their transition early, and inventory their cryptographic assets. They should also map their dependencies and develop a transition plan.</p><p>“To limit transition-related costs, they should opt to purchase products that integrate PQC and replace their systems with quantum-safe ones as part of their standard renewal schedule. As such, starting the transition early could result in lower migration costs overall. Planning and conducting their PQC transition properly would enable organizations to prevent insecure implementations and avoid increased exposure to conventional cyber threats.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/g7-tells-businesses-to-get-ready-for-quantum-cybersecurity-threats</link>
                                                                            <description>
                            <![CDATA[ Organizations late to the migration could lose contracting opportunities, G7 warns. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2ZkfdmUW73vAcJc8nb3TLL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UVm4pWzxzFfM3waNQDdPrD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 16:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UVm4pWzxzFfM3waNQDdPrD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Quantum computing concept. Digital communication network. Technological abstract.]]></media:description>                                                            <media:text><![CDATA[Quantum computing concept. Digital communication network. Technological abstract.]]></media:text>
                                <media:title type="plain"><![CDATA[Quantum computing concept. Digital communication network. Technological abstract.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UVm4pWzxzFfM3waNQDdPrD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>G7 urges governments and organizations to begin transitioning to quantum‑resistant encryption</strong></li><li><strong>Warning highlights risk from future quantum computers able to break current standards like AES</strong></li><li><strong>Guidance: inventory cryptographic assets, prioritize critical systems, and adopt phased PQC strategies</strong></li></ul><p>The G7, a collection of some of the world’s most powerful economies, is urging organizations to adopt quantum-resistant encryption as soon as possible and minimize the risk of losing sensitive data to technologically advanced threat actors.</p><p>Virtually every industry in the world today relies on encryption (the process of converting readable data into scrambled, unreadable data so that only someone with the correct key can decode and access it) to protect sensitive information. Banks, telecommunications providers, defense organizations, and practically everyone else are using some form of encryption - most probably AES (Advanced Encryption Standard).</p><p>Decrypting the protected data without the encryption key is considered almost impossible, since the computational effort necessary to pull it off would simply be too large. However, since quantum computers work on a fundamentally different principle, it is believed that once they are mature enough, they will be able to “crack” today’s encryption standards. </p><h2 id="g7-39-s-advice">G7's advice</h2><p>Now, the G7 has <a href="https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action" target="_blank" rel="nofollow">urged</a> government and organizations to remain ahead of the curve by deploying “quantum-resistant encryption”:</p><p>“To protect themselves from the threat brought by CRQCs (cryptographically relevant quantum computers), organizations should begin planning their PQC transition now and should aim to complete their transitions within any the timelines set out by their national cybersecurity authorities,” the warning reads.</p><p>“In addition to quantum-related risks, organizations that delay their PQC transition may lose competitive advantage or may be excluded from contracting opportunities, including public procurement.”</p><p>The G7 advises governments and organizations to take a number of steps, including identifying critical systems and prioritizing them. They should adopt a phased and risk-based strategy, start their transition early, and inventory their cryptographic assets. They should also map their dependencies and develop a transition plan.</p><p>“To limit transition-related costs, they should opt to purchase products that integrate PQC and replace their systems with quantum-safe ones as part of their standard renewal schedule. As such, starting the transition early could result in lower migration costs overall. Planning and conducting their PQC transition properly would enable organizations to prevent insecure implementations and avoid increased exposure to conventional cyber threats.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US military troops can still be hit by targeted attacks despite disabling ad tracking on their devices — and leaders aren't happy ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>US military branches disable ad tracking on government‑issued devices after warning</strong></li><li><strong>Location data from personal devices still poses risks; past data remains for sale</strong></li><li><strong>Senators urge DoD inspector general to review policies and stop servicemember data exposure</strong></li></ul><p>More than 20 years ago, Jason Bourne was smashing mobile phones to prevent being tracked by his adversaries - and the US Department of Defense (DoD) has realized it should probably do something similar.</p><p>In May 2026, Senator Ron Wyden mailed the DoD (among others), informing the agency that foreign powers were using commercial location data to target US troops - and now, Wyden has shared the responses he received from the US Army, Air Force, Navy, Marine Corps, and Special Operations Command, all of which have disabled advertising tracking across their government-issued devices, including Apple and Android smartphones, and Windows computers. </p><p>Some branches did it earlier this year, while the Air Force allegedly concluded the efforts in July 2026 - and while Wyden praised the move, he also suggested it is not enough, and that further steps must be taken in order to protect US troops stationed abroad.</p><h2 id="evaluating-the-leaked-files">Evaluating the leaked files</h2><p>“We commend these service branches for implementing this cybersecurity defensive best practice on government devices,” Wyden and Senator Pat Harrigan wrote. “However, recent reports regarding the continued availability of commercial location data originating from DoD facilities raise troubling questions.”</p><p>Apparently, despite disabling these features and placing the troops out of reach of <a href="https://www.techradar.com/pro/best-data-removal-services-of-year" target="_blank">data brokers</a> and similar commercial entities, the data that was gathered earlier remains available for sale, which still presents a risk. </p><p>“The members suggested data could continue to be available for several reasons, including that commercial data available originates from personal devices, not government phones, that are carried by servicemembers and government contractors,” a report on <a href="https://www.wyden.senate.gov/news/press-releases/wyden-and-harrigan-call-for-investigation-into-dod-efforts-to-protect-us-servicemembers-from-commercial-location-data-threats" target="_blank" rel="nofollow">Wyden’s website</a> reads.</p><p>“Wyden and Harrigan called on the DOD inspector general to examine commercial location data that DOD and other government agencies have already purchased to determine why existing policies have not prevented servicemembers location data from being sold online, and to recommend policy changes to better protect US personnel.”</p><p><em>Via </em><a href="https://techcrunch.com/2026/09/04/us-military-disabled-ad-tracking-on-troops-devices-following-reports-of-targeted-attacks/" target="_blank"><em>TechCrunch</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/us-military-troops-can-still-be-hit-by-targeted-attacks-despite-disabling-ad-tracking-on-their-devices-and-leaders-arent-happy</link>
                                                                            <description>
                            <![CDATA[ Government-issued devices are safe - but what about private devices? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qxo8CGkgGxxCnCDCgsK3sd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KcuQeJXg8Wj7ktEdTA3XhC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 15:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KcuQeJXg8Wj7ktEdTA3XhC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / NATALIA KOLESNIKOVA]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Belarusian border guard with a service dog]]></media:description>                                                            <media:text><![CDATA[A Belarusian border guard with a service dog]]></media:text>
                                <media:title type="plain"><![CDATA[A Belarusian border guard with a service dog]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KcuQeJXg8Wj7ktEdTA3XhC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>US military branches disable ad tracking on government‑issued devices after warning</strong></li><li><strong>Location data from personal devices still poses risks; past data remains for sale</strong></li><li><strong>Senators urge DoD inspector general to review policies and stop servicemember data exposure</strong></li></ul><p>More than 20 years ago, Jason Bourne was smashing mobile phones to prevent being tracked by his adversaries - and the US Department of Defense (DoD) has realized it should probably do something similar.</p><p>In May 2026, Senator Ron Wyden mailed the DoD (among others), informing the agency that foreign powers were using commercial location data to target US troops - and now, Wyden has shared the responses he received from the US Army, Air Force, Navy, Marine Corps, and Special Operations Command, all of which have disabled advertising tracking across their government-issued devices, including Apple and Android smartphones, and Windows computers. </p><p>Some branches did it earlier this year, while the Air Force allegedly concluded the efforts in July 2026 - and while Wyden praised the move, he also suggested it is not enough, and that further steps must be taken in order to protect US troops stationed abroad.</p><h2 id="evaluating-the-leaked-files">Evaluating the leaked files</h2><p>“We commend these service branches for implementing this cybersecurity defensive best practice on government devices,” Wyden and Senator Pat Harrigan wrote. “However, recent reports regarding the continued availability of commercial location data originating from DoD facilities raise troubling questions.”</p><p>Apparently, despite disabling these features and placing the troops out of reach of <a href="https://www.techradar.com/pro/best-data-removal-services-of-year" target="_blank">data brokers</a> and similar commercial entities, the data that was gathered earlier remains available for sale, which still presents a risk. </p><p>“The members suggested data could continue to be available for several reasons, including that commercial data available originates from personal devices, not government phones, that are carried by servicemembers and government contractors,” a report on <a href="https://www.wyden.senate.gov/news/press-releases/wyden-and-harrigan-call-for-investigation-into-dod-efforts-to-protect-us-servicemembers-from-commercial-location-data-threats" target="_blank" rel="nofollow">Wyden’s website</a> reads.</p><p>“Wyden and Harrigan called on the DOD inspector general to examine commercial location data that DOD and other government agencies have already purchased to determine why existing policies have not prevented servicemembers location data from being sold online, and to recommend policy changes to better protect US personnel.”</p><p><em>Via </em><a href="https://techcrunch.com/2026/09/04/us-military-disabled-ad-tracking-on-troops-devices-following-reports-of-targeted-attacks/" target="_blank"><em>TechCrunch</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI hid AI agent hijacking of German wiki forum for weeks — because its model did the exact same thing in the Hugging Face attack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI hid an incident where a model hijacked a wiki page to use as an AI agent communication board</strong></li><li><strong>The incident was hidden while the company dealt with the fallout of the Hugging Face attack</strong></li><li><strong>The company is now working on a framework for disclosing incidents of 'misalignment'</strong></li></ul><p>OpenAI recently disclosed the details of how one of its AI models <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal" target="_blank">escaped a sandboxed environment</a> and attacked Hugging Face during an evaluation -  and as part of the incident, the models created a messaging board to communicate with each other and influence each other’s reasoning.</p><p>OpenAI has now disclosed that shortly after this incident, agents undergoing testing again escaped their ‘secured’ environment and hijacked an obscure German wiki to use as a messaging board. Per <a href="https://www.reuters.com/world/europe/openai-agents-hijacked-german-website-previously-undisclosed-ai-breakout-this-2026-09-04/" target="_blank" rel="nofollow"><em>Reuters</em></a>, OpenAI leadership kept the incident hidden while they dealt with the fallout from the Hugging Face incident.</p><p>Now that OpenAI has acknowledged its role in the incident, the company has said it is “past time” to put together an incident disclosure pipeline when its models escape testing and slip into third-party networks.</p><h2 id="who-is-at-fault-when-models-do-what-they-re-designed-to-do">Who is at fault when models do what they’re designed to do?</h2><p>Before the two incidents, OpenAI said it, “treated misalignment largely as a research question, which gets communicated in research publications”. But now that models are behaving in previously unknown ways and having real-world impacts, the company said it would change its approach “to expand for this new phase of model capabilities”.</p><p>The company labelled the most recently disclosed incident as “an instance of misalignment similar” to the Hugging Face breach. </p><p>I myself am guilty of reporting on <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in" target="_blank">AI breaking out of containment as going ‘rogue’</a>, but these models are doing exactly what they are designed to do. OpenAI’s detailed disclosure of the Hugging Face incident showed that the models were pushed to try and solve a benchmark test by cheating, which is exactly what caused the cyberattack to happen.</p><p>OpenAI said that both itself and “the larger AI community do not yet have a clear standard for how to report misalignment that shows up during training, evaluation, and deployment, including examples that don’t look like traditional security incidents but could provide insight into AI behavior and future risks”.</p><p>The company added that it is “working on a framework and will share it in upcoming weeks, and in parallel we’re working with dozens of government regulatory agencies worldwide on these issues”.</p><p>“When you combine this 'breakout' with the Hugging face breakout, it's starting to display a pattern,” said Ashley Knowles, Lead Cybersecurity Consultant at Black Hills Information Security. “I struggle here with not getting too doomsday-ish but realistically, this is showing a pattern of concerning behavior.”</p><p>“I'm wondering if this race to become 'first' is undercutting security measures that need to be taken to properly secure and guard AI agents as they're in development. My concern grows when you consider that OpenAI is also resisting further investigation. Adding onto that, the release and promise that Astra can evade human monitoring. The pot is brewing…”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-hid-ai-agent-hijacking-of-german-wiki-forum-for-weeks-because-its-model-did-the-exact-same-thing-in-the-hugging-face-attack</link>
                                                                            <description>
                            <![CDATA[ OpenAI called the incident a 'misalignment' in the model's reasoning and says it is working on a new disclosure framework. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZsqPpUtSY5EUtLWgvr9QcL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bqTLGsRATg4oc47RW3PJbi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 15:19:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bqTLGsRATg4oc47RW3PJbi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/ VCG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI logos]]></media:description>                                                            <media:text><![CDATA[OpenAI logos]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI logos]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bqTLGsRATg4oc47RW3PJbi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI hid an incident where a model hijacked a wiki page to use as an AI agent communication board</strong></li><li><strong>The incident was hidden while the company dealt with the fallout of the Hugging Face attack</strong></li><li><strong>The company is now working on a framework for disclosing incidents of 'misalignment'</strong></li></ul><p>OpenAI recently disclosed the details of how one of its AI models <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal" target="_blank">escaped a sandboxed environment</a> and attacked Hugging Face during an evaluation -  and as part of the incident, the models created a messaging board to communicate with each other and influence each other’s reasoning.</p><p>OpenAI has now disclosed that shortly after this incident, agents undergoing testing again escaped their ‘secured’ environment and hijacked an obscure German wiki to use as a messaging board. Per <a href="https://www.reuters.com/world/europe/openai-agents-hijacked-german-website-previously-undisclosed-ai-breakout-this-2026-09-04/" target="_blank" rel="nofollow"><em>Reuters</em></a>, OpenAI leadership kept the incident hidden while they dealt with the fallout from the Hugging Face incident.</p><p>Now that OpenAI has acknowledged its role in the incident, the company has said it is “past time” to put together an incident disclosure pipeline when its models escape testing and slip into third-party networks.</p><h2 id="who-is-at-fault-when-models-do-what-they-re-designed-to-do">Who is at fault when models do what they’re designed to do?</h2><p>Before the two incidents, OpenAI said it, “treated misalignment largely as a research question, which gets communicated in research publications”. But now that models are behaving in previously unknown ways and having real-world impacts, the company said it would change its approach “to expand for this new phase of model capabilities”.</p><p>The company labelled the most recently disclosed incident as “an instance of misalignment similar” to the Hugging Face breach. </p><p>I myself am guilty of reporting on <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in" target="_blank">AI breaking out of containment as going ‘rogue’</a>, but these models are doing exactly what they are designed to do. OpenAI’s detailed disclosure of the Hugging Face incident showed that the models were pushed to try and solve a benchmark test by cheating, which is exactly what caused the cyberattack to happen.</p><p>OpenAI said that both itself and “the larger AI community do not yet have a clear standard for how to report misalignment that shows up during training, evaluation, and deployment, including examples that don’t look like traditional security incidents but could provide insight into AI behavior and future risks”.</p><p>The company added that it is “working on a framework and will share it in upcoming weeks, and in parallel we’re working with dozens of government regulatory agencies worldwide on these issues”.</p><p>“When you combine this 'breakout' with the Hugging face breakout, it's starting to display a pattern,” said Ashley Knowles, Lead Cybersecurity Consultant at Black Hills Information Security. “I struggle here with not getting too doomsday-ish but realistically, this is showing a pattern of concerning behavior.”</p><p>“I'm wondering if this race to become 'first' is undercutting security measures that need to be taken to properly secure and guard AI agents as they're in development. My concern grows when you consider that OpenAI is also resisting further investigation. Adding onto that, the release and promise that Astra can evade human monitoring. The pot is brewing…”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Stop buying security tools: start buying a system ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Ask a CISO why they bought their newest <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> tool, and they’ll have a clear answer lined up. </p><p>It stops a specific technique, closes a particular gap, or satisfies a compliance requirement. </p><p>However, it's often less clear how the tool fits in with the rest of the stack. </p><p>Does it make the overall system stronger, or simply add another layer of complexity to manage? </p><p>Research indicates most security professionals already believe they’re juggling too many tools, with over half saying they don’t properly integrate together.  </p><p>This is a pattern I call ‘additive by default,’ and it results in stacks that grow without a plan, becoming broader but not necessarily deeper or able to match today’s threats. </p><h2 id="start-with-the-outcome-not-the-technology">Start with the outcome, not the technology </h2><p>I find this additive approach is often due to focusing on specific emerging threats or identified weak points, so decisions are made with a tactical eye rather than a broader strategic view.      </p><p>Part of the problem is that most organizations have never precisely defined the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> outcome they are trying to achieve. Without a shared, specific language for the problem, every new purchase becomes additive, because there is nothing solid to measure it against.      </p><p>Take <a href="https://www.techradar.com/best/best-asset-management-software">asset</a> labelling, which is a core capability most organizations know they need, so they invest in a tool, populate a configuration management database (CMDB), and assign criticality scores. Job done, right? But labelling an asset only answers the question of what it is, and says nothing about how that asset connects to everything around it, or what happens when a policy needs to be enforced against it.      </p><p>Labelling, visibility and enforcement are three distinct jobs, not one. Solve the first and the second and third remain wide open, so another tool gets bought to cover visibility, then another for enforcement. Each purchase solves its own narrow question perfectly well.       </p><p>However, none of them were ever asked to work as a single, continuous capability, because nobody defined that as the actual requirement in the first place.       </p><p>What if <a href="https://www.techradar.com/best/best-software-asset-management-tools">asset management</a> labels fed into visibility views and the same reflected how policy is drafted and then enforced? Now you have a strategic problem solved with interoperable capabilities. </p><h2 id="how-much-of-your-stack-is-really-putting-in-the-work">How much of your stack is really putting in the work? </h2><p>Gartner’s most recent Leadership Perspective Survey saw CISOs noting this as a common issue, with just 20-30% of tool capability actually being used in some cases. The instinctive response to this is to cut the stack down, however, that instinct solves the wrong problem.      </p><p>A good exercise for working out the value of the stack is to evaluate every tool, new or already deployed, against three plain questions.  </p><p>Does it offer continuous validation against a given threat - and what, specifically, does it validate?  Is it still operationally relevant? And is it effective, right now, in the environment you have today? A tool can pass one or two of these and still be failing you.      </p><p>Virtual Local Area Networks (VLANs) are a good example of this. Twenty or thirty years ago, when networks were typically static and everything likely sat inside a single data center, VLAN-based segmentation was genuinely effective. It matched the environment it was built for.       </p><p>That environment has since changed almost beyond recognition. Workloads move between on-premises systems, <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a> and containers, and nothing stays fixed for long. VLANs are still deployed across many stacks today, still technically doing the segmentation job they were built for. Yet their effectiveness has dropped sharply because they offer none of the continuous validation a hybrid, constantly shifting estate actually requires.      </p><p>Effectiveness has an expiry date that has nothing to do with whether the tool still runs. Success should be measured by whether the system as a whole still holds up, not by how many tools remain switched on. </p><h2 id="consolidated-security-not-consolidated-tooling">Consolidated security, not consolidated tooling </h2><p>Gartner identified that most organizations are pursuing a vendor consolidation strategy. While this approach certainly reduces unnecessary spending and keeps budgets under control, it’s not necessarily solving the biggest problem.  </p><p>Consolidated tooling and consolidated security are not the same thing, and it’s an assumption that leads to disappointment. Reducing the number of tools alone achieves little if the underlying processes remain fragmented or teams continue to operate against different objectives. </p><p>No data center I have walked through was built entirely by one manufacturer. Racks, switches, storage and cabling come from a dozen suppliers, yet they operate as one coherent system because they were designed to fit together. Security should work the same way. </p><p>The goal is not necessarily fewer vendors, but every control, whoever built it, feeding into the same continuous picture of identification, visibility and enforcement. </p><h2 id="what-to-ask-instead">What to ask instead </h2><p>Before completing the next security purchase, consider how well a new tool fits into the stack you already have, not just what it claims to do on its own.       </p><p>A tool that deploys cleanly, validates continuously rather than only at go-live, and feeds its findings back into the tools already in place is doing real work. One that arrives as a fresh, isolated source of alerts is just adding to the noise, however good its individual detection rate looks in a demo. That means comparing what the tool was bought to solve against what it is actually delivering today, checking it against newer capabilities, and being willing to redeploy or renegotiate rather than automatically renew or even retire.      </p><p>Ultimately, the strongest security programs are not defined by the number of tools they deploy, nor by the number they eliminate. They're defined by how effectively every control works together when it matters most.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've rounded up the best endpoint protection software suites</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/stop-buying-security-tools-start-buying-a-system</link>
                                                                            <description>
                            <![CDATA[ Security leaders must rethink tool sprawl, prioritizing integration, continuous validation and system-wide effectiveness over consolidation. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YogNqaUbUxnLcYAnberzxG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XbZCTEpjtunPvMj9ySXmWU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 14:23:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Michael Adjei ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XbZCTEpjtunPvMj9ySXmWU-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A file and folder transferring data with a red warning mark indicating malware.]]></media:description>                                                            <media:text><![CDATA[A file and folder transferring data with a red warning mark indicating malware.]]></media:text>
                                <media:title type="plain"><![CDATA[A file and folder transferring data with a red warning mark indicating malware.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XbZCTEpjtunPvMj9ySXmWU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ask a CISO why they bought their newest <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> tool, and they’ll have a clear answer lined up. </p><p>It stops a specific technique, closes a particular gap, or satisfies a compliance requirement. </p><p>However, it's often less clear how the tool fits in with the rest of the stack. </p><p>Does it make the overall system stronger, or simply add another layer of complexity to manage? </p><p>Research indicates most security professionals already believe they’re juggling too many tools, with over half saying they don’t properly integrate together.  </p><p>This is a pattern I call ‘additive by default,’ and it results in stacks that grow without a plan, becoming broader but not necessarily deeper or able to match today’s threats. </p><h2 id="start-with-the-outcome-not-the-technology">Start with the outcome, not the technology </h2><p>I find this additive approach is often due to focusing on specific emerging threats or identified weak points, so decisions are made with a tactical eye rather than a broader strategic view.      </p><p>Part of the problem is that most organizations have never precisely defined the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> outcome they are trying to achieve. Without a shared, specific language for the problem, every new purchase becomes additive, because there is nothing solid to measure it against.      </p><p>Take <a href="https://www.techradar.com/best/best-asset-management-software">asset</a> labelling, which is a core capability most organizations know they need, so they invest in a tool, populate a configuration management database (CMDB), and assign criticality scores. Job done, right? But labelling an asset only answers the question of what it is, and says nothing about how that asset connects to everything around it, or what happens when a policy needs to be enforced against it.      </p><p>Labelling, visibility and enforcement are three distinct jobs, not one. Solve the first and the second and third remain wide open, so another tool gets bought to cover visibility, then another for enforcement. Each purchase solves its own narrow question perfectly well.       </p><p>However, none of them were ever asked to work as a single, continuous capability, because nobody defined that as the actual requirement in the first place.       </p><p>What if <a href="https://www.techradar.com/best/best-software-asset-management-tools">asset management</a> labels fed into visibility views and the same reflected how policy is drafted and then enforced? Now you have a strategic problem solved with interoperable capabilities. </p><h2 id="how-much-of-your-stack-is-really-putting-in-the-work">How much of your stack is really putting in the work? </h2><p>Gartner’s most recent Leadership Perspective Survey saw CISOs noting this as a common issue, with just 20-30% of tool capability actually being used in some cases. The instinctive response to this is to cut the stack down, however, that instinct solves the wrong problem.      </p><p>A good exercise for working out the value of the stack is to evaluate every tool, new or already deployed, against three plain questions.  </p><p>Does it offer continuous validation against a given threat - and what, specifically, does it validate?  Is it still operationally relevant? And is it effective, right now, in the environment you have today? A tool can pass one or two of these and still be failing you.      </p><p>Virtual Local Area Networks (VLANs) are a good example of this. Twenty or thirty years ago, when networks were typically static and everything likely sat inside a single data center, VLAN-based segmentation was genuinely effective. It matched the environment it was built for.       </p><p>That environment has since changed almost beyond recognition. Workloads move between on-premises systems, <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a> and containers, and nothing stays fixed for long. VLANs are still deployed across many stacks today, still technically doing the segmentation job they were built for. Yet their effectiveness has dropped sharply because they offer none of the continuous validation a hybrid, constantly shifting estate actually requires.      </p><p>Effectiveness has an expiry date that has nothing to do with whether the tool still runs. Success should be measured by whether the system as a whole still holds up, not by how many tools remain switched on. </p><h2 id="consolidated-security-not-consolidated-tooling">Consolidated security, not consolidated tooling </h2><p>Gartner identified that most organizations are pursuing a vendor consolidation strategy. While this approach certainly reduces unnecessary spending and keeps budgets under control, it’s not necessarily solving the biggest problem.  </p><p>Consolidated tooling and consolidated security are not the same thing, and it’s an assumption that leads to disappointment. Reducing the number of tools alone achieves little if the underlying processes remain fragmented or teams continue to operate against different objectives. </p><p>No data center I have walked through was built entirely by one manufacturer. Racks, switches, storage and cabling come from a dozen suppliers, yet they operate as one coherent system because they were designed to fit together. Security should work the same way. </p><p>The goal is not necessarily fewer vendors, but every control, whoever built it, feeding into the same continuous picture of identification, visibility and enforcement. </p><h2 id="what-to-ask-instead">What to ask instead </h2><p>Before completing the next security purchase, consider how well a new tool fits into the stack you already have, not just what it claims to do on its own.       </p><p>A tool that deploys cleanly, validates continuously rather than only at go-live, and feeds its findings back into the tools already in place is doing real work. One that arrives as a fresh, isolated source of alerts is just adding to the noise, however good its individual detection rate looks in a demo. That means comparing what the tool was bought to solve against what it is actually delivering today, checking it against newer capabilities, and being willing to redeploy or renegotiate rather than automatically renew or even retire.      </p><p>Ultimately, the strongest security programs are not defined by the number of tools they deploy, nor by the number they eliminate. They're defined by how effectively every control works together when it matters most.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've rounded up the best endpoint protection software suites</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware hackers dump 1.4 million stolen records from German government ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Rhysida ransomware group breached Berlin’s state government, stealing 1.44 million files weighing in at around 5.8TB</strong></li><li><strong>Attackers demanded 30 BTC (~$2.3M); Berlin refused, leading to full leak online</strong></li><li><strong>Leaked data reportedly includes water supply info, staff records, and emergency plans</strong></li></ul><p>A cybercriminal group known as Rhysida allegedly broke into the network of Berlin's state government and exfiltrated 1.44 million files. They then tried to extort the government entity for money and when that failed, they leaked it all into the dark web.</p><p>According to multiple sources, the group first claimed responsibility for the attack on an underground forum, where it shared a small sample of the stolen files and demanded Berlin pay 30 bitcoin (around $2.3 million) in exchange for deleting the files.</p><p>Berlin recognized the attack in a press release, and said it would not be negotiating with the attackers, and instead launched a full-scale investigation into the incident, which it described as an “extremely serious crime and an attack on the state of Berlin.”</p><h2 id="evaluating-the-leaked-files-2">Evaluating the leaked files</h2><p>A few days later, <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">Rhysida</a> decided to leak it all online - and Berlin is now reviewing the leaked files and is assessing the damage:</p><p>“After the publication of the stolen data from the Berlin administration, these files are being evaluated at full speed,” a press release, published on the Berlin.de website (machine-translated), reads. </p><p>“An additional steering unit has been set up in the Senate Chancellery under the leadership of the Chief Digital Officer (CDO), Florian Hauer, which coordinates the review, examination and evaluation of the leaked data and supports the two Senate administrations concerned in informing and advising the affected citizens and companies.”</p><p>According to German public broadcaster Tagesschau, the archive counts 1.44 million files and totals 5.8 terabytes. At the same time, the Chaos Computer Club (Germany's largest and best-known hacker organization) claims the archive contains sensitive data on the city’s water supply, personal data of admin staff, various employment references, and emergency plans. </p><p><em>Via </em><a href="https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/" target="_blank"><em>Reuters</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/ransomware-hackers-dump-1-4-million-stolen-records-from-german-government</link>
                                                                            <description>
                            <![CDATA[ This is an "extremely serious crime" and an attack on Berlin, the government says. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sTAtVCtttosNejBRf3aDA4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3HY9z6jmzyHFPZFAtvox2a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 13:35:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3HY9z6jmzyHFPZFAtvox2a-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3HY9z6jmzyHFPZFAtvox2a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Rhysida ransomware group breached Berlin’s state government, stealing 1.44 million files weighing in at around 5.8TB</strong></li><li><strong>Attackers demanded 30 BTC (~$2.3M); Berlin refused, leading to full leak online</strong></li><li><strong>Leaked data reportedly includes water supply info, staff records, and emergency plans</strong></li></ul><p>A cybercriminal group known as Rhysida allegedly broke into the network of Berlin's state government and exfiltrated 1.44 million files. They then tried to extort the government entity for money and when that failed, they leaked it all into the dark web.</p><p>According to multiple sources, the group first claimed responsibility for the attack on an underground forum, where it shared a small sample of the stolen files and demanded Berlin pay 30 bitcoin (around $2.3 million) in exchange for deleting the files.</p><p>Berlin recognized the attack in a press release, and said it would not be negotiating with the attackers, and instead launched a full-scale investigation into the incident, which it described as an “extremely serious crime and an attack on the state of Berlin.”</p><h2 id="evaluating-the-leaked-files-2">Evaluating the leaked files</h2><p>A few days later, <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">Rhysida</a> decided to leak it all online - and Berlin is now reviewing the leaked files and is assessing the damage:</p><p>“After the publication of the stolen data from the Berlin administration, these files are being evaluated at full speed,” a press release, published on the Berlin.de website (machine-translated), reads. </p><p>“An additional steering unit has been set up in the Senate Chancellery under the leadership of the Chief Digital Officer (CDO), Florian Hauer, which coordinates the review, examination and evaluation of the leaked data and supports the two Senate administrations concerned in informing and advising the affected citizens and companies.”</p><p>According to German public broadcaster Tagesschau, the archive counts 1.44 million files and totals 5.8 terabytes. At the same time, the Chaos Computer Club (Germany's largest and best-known hacker organization) claims the archive contains sensitive data on the city’s water supply, personal data of admin staff, various employment references, and emergency plans. </p><p><em>Via </em><a href="https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/" target="_blank"><em>Reuters</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using 'invisible' Unicode characters to sneak phishing lures into emails ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft reports phishing campaign using ASCII smuggling to bypass spam filters</strong></li><li><strong>Attackers insert invisible characters into keywords, tricking filters and AI agents</strong></li><li><strong>Defenders should normalize Unicode tags and flag unexpected invisible code points as suspicious</strong></li></ul><p>Cybercriminals are using the “ASCII smuggling” technique to make sure phishing emails pass security filters and land in people’s inboxes, experts have warned.</p><p>ASCII is a character encoding standard that turns characters and words humans can read into numeric values that computers can understand. It can also be used to create characters that aren’t even displayed on the screen (essentially “invisible” ones) but can still be read by the machine.</p><p>In a new <a href="https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/" target="_blank" rel="nofollow">report</a>, security researchers from Microsoft found crooks are abusing this fact to distribute phishing emails. Most email providers offer solutions that filter out spam emails. These filters look for certain keywords and phrases, such as “funding”, “credit”, “loan”, and similar, and automatically send such emails to the spam folder. </p><h2 id="ongoing-campaign">Ongoing campaign</h2><p>By adding a set of invisible characters in the middle of these keywords, the attackers can break them apart and thus “confuse” the filters. </p><p>While the human sees the word “funding” in their email, the security solution is seeing something like “fun[a long string of characters]ding”. This technique has been adopted from prompt injection attacks, where crooks would use ASCII smuggling to deliver malicious and invisible prompts in the emails. </p><p>Therefore, when a victim asks their AI agent to summarize the email, it ends up working on a prompt that could be anything from extracting sensitive data, to deploying <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. </p><p>Microsoft is saying the campaign has been ongoing for months, and while it peaked in February 2026 with more than 2.3 million emails every day, and has been in decline ever since, it remains active to this day. In early February, Microsoft observed a cluster of almost 150 sender domains, all themed around finance. These domains accounted for almost all (96%) of all the spam emails Defender for Office 365 flagged under ASCII smuggling.</p><p>Defending sounds relatively simple, though. IT teams should normalize Unicode tag characters and other invisible code points before applying any keyword detection. They should also consider all unexpected tag-block characters as suspicious.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/hackers-are-using-invisible-unicode-characters-to-sneak-phishing-lures-into-emails</link>
                                                                            <description>
                            <![CDATA[ A technique used in prompt injection attacks has made it into phishing, Microsoft has warned. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kpbZtKyjta2kiuQw3KPbBZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 13:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing]]></media:description>                                                            <media:text><![CDATA[Phishing]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft reports phishing campaign using ASCII smuggling to bypass spam filters</strong></li><li><strong>Attackers insert invisible characters into keywords, tricking filters and AI agents</strong></li><li><strong>Defenders should normalize Unicode tags and flag unexpected invisible code points as suspicious</strong></li></ul><p>Cybercriminals are using the “ASCII smuggling” technique to make sure phishing emails pass security filters and land in people’s inboxes, experts have warned.</p><p>ASCII is a character encoding standard that turns characters and words humans can read into numeric values that computers can understand. It can also be used to create characters that aren’t even displayed on the screen (essentially “invisible” ones) but can still be read by the machine.</p><p>In a new <a href="https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/" target="_blank" rel="nofollow">report</a>, security researchers from Microsoft found crooks are abusing this fact to distribute phishing emails. Most email providers offer solutions that filter out spam emails. These filters look for certain keywords and phrases, such as “funding”, “credit”, “loan”, and similar, and automatically send such emails to the spam folder. </p><h2 id="ongoing-campaign">Ongoing campaign</h2><p>By adding a set of invisible characters in the middle of these keywords, the attackers can break them apart and thus “confuse” the filters. </p><p>While the human sees the word “funding” in their email, the security solution is seeing something like “fun[a long string of characters]ding”. This technique has been adopted from prompt injection attacks, where crooks would use ASCII smuggling to deliver malicious and invisible prompts in the emails. </p><p>Therefore, when a victim asks their AI agent to summarize the email, it ends up working on a prompt that could be anything from extracting sensitive data, to deploying <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. </p><p>Microsoft is saying the campaign has been ongoing for months, and while it peaked in February 2026 with more than 2.3 million emails every day, and has been in decline ever since, it remains active to this day. In early February, Microsoft observed a cluster of almost 150 sender domains, all themed around finance. These domains accounted for almost all (96%) of all the spam emails Defender for Office 365 flagged under ASCII smuggling.</p><p>Defending sounds relatively simple, though. IT teams should normalize Unicode tag characters and other invisible code points before applying any keyword detection. They should also consider all unexpected tag-block characters as suspicious.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Save up to 50% off Keeper plans this September — protect your passwords with half price Personal plans, and a third-off Business plans ]]></title>
                                                                                                <dc:content><![CDATA[ <p>You probably have tens, if not hundreds of passwords floating around across all the online accounts you use every week. In fact, the average person has over 150 passwords. It's not easy to remember them all, making it more attractive to keep them simple and similar - but that can lead to a serious chain of account theft.</p><p>That's why password managers like Keeper exist. They generate strong passwords and store them passwords in a secured vault to keep them safe from hackers and prying eyes. They even autofill your credentials to make logging in to your account faster and easier.</p><p><a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper has cut prices on its personal, family, and business starter plans by up to 50%</a>. Keeper regularly scores highly in our reviews, and includes great features across Personal, Family, and Business plans.</p><div class="product"><a data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:131px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="TbfSUDRsU8NdGFXVDRFiSW" name="keeper!.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TbfSUDRsU8NdGFXVDRFiSW.jpg" mos="" align="middle" fullscreen="" width="131" height="131" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25=""><strong>Get up to 50% off Keeper plans</strong></a></p><p>Keeper is offering 50% off its Personal and Family plans, making it even more affordable to secure both personal and household accounts. The Family plan covers multiple users with five secured vaults, making it perfect for shared accounts without the hassle of mixing browsers and reusing passwords.</p><p>Keeper Business Starter is discounted by 30%, and is an excellent choice for small teams looking for a credentials control platform without the complexity and hassle of enduring an enterprise rollout. It includes centralized management, secure password sharing, and role-based access, cleanly organizing your passwords without unnecessary complications.</p><p>The full terms and pricing are available on the <a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper site</a>.<a class="view-deal button" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25="">View Deal</a></p></div><h2 id="why-we-recommend-keeper">Why we recommend Keeper</h2><p>Our <a href="https://www.techradar.com/reviews/keeper-password-manager" target="_blank">Keeper review</a> highlights the platform's zero knowledge architecture and device level encryption that helps keep your password vault secured against unwanted intrusions.</p><p>Where Keeper really shone was in our usability and convenience testing. We loved how Keeper uses biometric security to access your vault, rather than requiring a master password with each log in. By using a facial scan or fingerprint to verify that its actually you accessing your vault, it adds a fast but secure method of verification to ensure its you, and not a nefarious actor.</p><p>For households, the Family Plan includes five private vaults, allowing you to quickly share Wi-Fi or streaming passwords using Keeper's shared vaults.</p><p>The Business Starter plan covers 5 users, covering an unlimited devices, shared team folders, user activity reporting for IT admins, and a free Family Plan for every team member.</p><p>These discounts apply to the first year only, so the value is highest for new customers or anyone switching from a monthly plan. After that, pricing goes back to standard rates.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/save-up-to-50-percent-off-keeper-plans-this-september-protect-your-passwords-with-half-price-personal-plans-and-a-third-off-business-plans</link>
                                                                            <description>
                            <![CDATA[ Keeper is one of the best solutions to password storage and security, with up to 50% off across Personal, Family, and Business plans ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">A3tb9XngX6pNeDLcj6Au2h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 13:17:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:description>                                                            <media:text><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:text>
                                <media:title type="plain"><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>You probably have tens, if not hundreds of passwords floating around across all the online accounts you use every week. In fact, the average person has over 150 passwords. It's not easy to remember them all, making it more attractive to keep them simple and similar - but that can lead to a serious chain of account theft.</p><p>That's why password managers like Keeper exist. They generate strong passwords and store them passwords in a secured vault to keep them safe from hackers and prying eyes. They even autofill your credentials to make logging in to your account faster and easier.</p><p><a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper has cut prices on its personal, family, and business starter plans by up to 50%</a>. Keeper regularly scores highly in our reviews, and includes great features across Personal, Family, and Business plans.</p><div class="product"><a data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:131px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="TbfSUDRsU8NdGFXVDRFiSW" name="keeper!.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TbfSUDRsU8NdGFXVDRFiSW.jpg" mos="" align="middle" fullscreen="" width="131" height="131" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25=""><strong>Get up to 50% off Keeper plans</strong></a></p><p>Keeper is offering 50% off its Personal and Family plans, making it even more affordable to secure both personal and household accounts. The Family plan covers multiple users with five secured vaults, making it perfect for shared accounts without the hassle of mixing browsers and reusing passwords.</p><p>Keeper Business Starter is discounted by 30%, and is an excellent choice for small teams looking for a credentials control platform without the complexity and hassle of enduring an enterprise rollout. It includes centralized management, secure password sharing, and role-based access, cleanly organizing your passwords without unnecessary complications.</p><p>The full terms and pricing are available on the <a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper site</a>.<a class="view-deal button" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25="">View Deal</a></p></div><h2 id="why-we-recommend-keeper">Why we recommend Keeper</h2><p>Our <a href="https://www.techradar.com/reviews/keeper-password-manager" target="_blank">Keeper review</a> highlights the platform's zero knowledge architecture and device level encryption that helps keep your password vault secured against unwanted intrusions.</p><p>Where Keeper really shone was in our usability and convenience testing. We loved how Keeper uses biometric security to access your vault, rather than requiring a master password with each log in. By using a facial scan or fingerprint to verify that its actually you accessing your vault, it adds a fast but secure method of verification to ensure its you, and not a nefarious actor.</p><p>For households, the Family Plan includes five private vaults, allowing you to quickly share Wi-Fi or streaming passwords using Keeper's shared vaults.</p><p>The Business Starter plan covers 5 users, covering an unlimited devices, shared team folders, user activity reporting for IT admins, and a free Family Plan for every team member.</p><p>These discounts apply to the first year only, so the value is highest for new customers or anyone switching from a monthly plan. After that, pricing goes back to standard rates.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why is there so much worry about OpenAI Astra, and what issues could ‘recurrent depth’ reasoning cause? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>OpenAI has unveiled a much anticipated AI model which the firm has dubbed ‘GPT-6 Astra’. While the model has improved significantly across benchmark testing and <a href="https://www.techradar.com/pro/gpt-6-astra-lays-the-foundations-for-a-new-way-of-reasoning-a-great-tool-for-businesses-but-experts-have-their-concerns">brings a host of new business features</a>, there is still a dark cloud looming over the new model.</p><p>Off the back of <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in">OpenAI’s accidental hack of Hugging Face</a> and the company’s subsequent efforts to improve how AI agents behave and interact, numerous cybersecurity experts have raised concerns about the model’s new ‘recurrent depth’ reasoning capabilities.</p><p>This new reasoning architecture allows the model to consider a problem multiple times before taking an action, compared to the standard chain-of-thought reasoning used in previous models.</p><h2 id="why-the-concern-about-recurrent-depth-reasoning">Why the concern about recurrent depth reasoning?</h2><p>This new level of reasoning apparently offers improved performance. OpenAI also says it has fixed its models' abilities to circumvent boundaries when performing tests by monitoring the models reasoning and ensuring the model stays aligned within the scope of its task.</p><p>During Astra’s launch event, OpenAI chief scientist Jakub Pachocki said: “We will not accept degradation in our ability to monitor model alignment beyond a certain level. We will withhold scaling until we can regain enough confidence.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>But numerous experts believe that the lessons of the Hugging Face incident have not yet been learned, and the model has been released without adequate testing on Astra’s reasoning and monitoring. </p><p>After all, no one thought one of <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal">OpenAI’s models could set up a hidden internet-connected messaging board</a> that allowed AI agents to influence each other's behavior.</p><p>But with Astra being released into the real world, the lessons may have to be learned on the fly.</p><h3 class="article-body__section" id="section-expert-perspectives-on-openai-astra-release"><span>Expert perspectives on OpenAI Astra release</span></h3><ul><li><strong>James Blake, VP of Global Cyber Resiliency Strategy at Cohesity:</strong></li></ul><p><em>The launch of Astra is raising questions again around the safety of Frontier AI. Instead of simply asking whether a model is "safe", organisations now need to ask whether it remains safe across millions of different situations, prompts and interactions. Cyber resilience has traditionally assumed that systems and threat actors behave deterministically. AI systems don’t.</em></p><div><blockquote><p>Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible?</p></blockquote></div><p><em>Advanced models can and will continue to exhibit behaviours that emerge from their optimisation process rather than from explicit programming. We have to move beyond thinking about AI as just another software tool and find ways to ensure these systems remain observable, auditable and governable throughout their lifecycle. </em></p><p><em>The most important question we’ll need to answer in future is one of liability. Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible? The developer that trained the model? The cloud provider operating the infrastructure? Currently the answer is surprisingly unclear. It’s not just about what AI can do: it’s about who is accountable when it does something nobody expected.</em></p><ul><li><strong>Oleksandr Yaremchuk, Co-Founder & CTO at Manifold Security:</strong></li></ul><p><em>OpenAI is calling Astra its most aligned model yet, even as its chief scientist admits monitorability is getting harder as models get more capable. Evidently, Astra hides its reasoning in the majority of tested cases, and some successful attacks left no reasoning trace at all. That's the tool many organisations still use, including the labs themselves, for auditing what an agent is doing, and it's getting less reliable with every release.</em></p><div><blockquote><p>A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</p></blockquote></div><p><em>That matters because Astra isn't staying inside OpenAI's test environment. It's going to run as an agent on employee laptops and in the browser, holding real credentials, inside companies that have no way to watch what it does once it's there. A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</em></p><p><em>Labs can keep debating what these models say or refuse to say. Security teams need to stop relying on that and start monitoring what agents actually do at runtime, with the ability to shut one down mid-action. That's the only oversight left that still works once the reasoning goes quiet.</em></p><ul><li><strong>Kristin Lowery, Field CISO at Optiv:</strong></li></ul><p><em>For boards and executive leaders, the emergence of OpenAI’s Astra model highlights a broader reality: AI is no longer just a productivity issue; it is a risk management issue. </em></p><div><blockquote><p>The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace</p></blockquote></div><p><em>Just as organizations established governance for cloud adoption and digital transformation, they now need clear policies, strong oversight, and accountability for AI use.</em></p><p><em>The question is not whether AI will become more capable — it will. The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace.</em></p><ul><li><strong>Patricia Titus, Field CISO at Abnormal AI:</strong></li></ul><p><em>OpenAI crossing this threshold deserves attention. Credit where it's due, they're handling it responsibly by restricting Astra's advanced cyber capability to a small coalition rather than releasing it broadly.But this isn't one company's problem to contain.</em></p><p><em>Once a model can find and exploit unknown flaws without a human in the loop, that capability doesn't stay exclusive for long. Open-weight and modified models typically trail the frontier by only months, and that's the reality defenders have to plan around now.</em></p><div><blockquote><p>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time.</p></blockquote></div><p><em>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time. Defenders need the same shift, systems that learn what normal looks like for every identity, human, machine, or AI agent, and flag and contain the moment something deviates, at machine speed.</em></p><p><em>The window to build that is open now. It won't stay that way once this capability is common instead of rare.</em></p><ul><li><strong>Raghu Nandakumara, VP of Industry Strategy at Illumio:</strong></li></ul><p><em>With the Astra announcement, OpenAI is doubling down on monitoring the model's own behaviour – a response to the model "breakouts" seen over the past few months.</em></p><div><blockquote><p>The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</p></blockquote></div><p><em>When Anthropic announced Claude Mythos Preview, the core concern was the model falling into the wrong hands. OpenAI's answer goes further adding guardrails around the model's own reasoning and actions, regardless of the user's intent. The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</em></p><p><em>The rest of this announcement can be summarised as ‘we have a new frontier model, and it’s more capable than the last one’.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-is-there-so-much-worry-about-openai-astra-and-what-issues-could-recurrent-depth-reasoning-cause-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ As OpenAI unveils GPT-6 Astra, cybersecurity experts question whether the model's 'recurrent depth' reasoning was properly tested. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C8dxY7YkHdtYyEPzyEiovn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 05 Sep 2026 13:30:00 +0000</pubDate>                                                                                                                                <updated>Mon, 07 Sep 2026 09:36:03 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[ChatGPT]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg">
                                                            <media:credit><![CDATA[OpenAI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI GPT-6 Astra]]></media:description>                                                            <media:text><![CDATA[OpenAI GPT-6 Astra]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI GPT-6 Astra]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI has unveiled a much anticipated AI model which the firm has dubbed ‘GPT-6 Astra’. While the model has improved significantly across benchmark testing and <a href="https://www.techradar.com/pro/gpt-6-astra-lays-the-foundations-for-a-new-way-of-reasoning-a-great-tool-for-businesses-but-experts-have-their-concerns">brings a host of new business features</a>, there is still a dark cloud looming over the new model.</p><p>Off the back of <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in">OpenAI’s accidental hack of Hugging Face</a> and the company’s subsequent efforts to improve how AI agents behave and interact, numerous cybersecurity experts have raised concerns about the model’s new ‘recurrent depth’ reasoning capabilities.</p><p>This new reasoning architecture allows the model to consider a problem multiple times before taking an action, compared to the standard chain-of-thought reasoning used in previous models.</p><h2 id="why-the-concern-about-recurrent-depth-reasoning">Why the concern about recurrent depth reasoning?</h2><p>This new level of reasoning apparently offers improved performance. OpenAI also says it has fixed its models' abilities to circumvent boundaries when performing tests by monitoring the models reasoning and ensuring the model stays aligned within the scope of its task.</p><p>During Astra’s launch event, OpenAI chief scientist Jakub Pachocki said: “We will not accept degradation in our ability to monitor model alignment beyond a certain level. We will withhold scaling until we can regain enough confidence.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>But numerous experts believe that the lessons of the Hugging Face incident have not yet been learned, and the model has been released without adequate testing on Astra’s reasoning and monitoring. </p><p>After all, no one thought one of <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal">OpenAI’s models could set up a hidden internet-connected messaging board</a> that allowed AI agents to influence each other's behavior.</p><p>But with Astra being released into the real world, the lessons may have to be learned on the fly.</p><h3 class="article-body__section" id="section-expert-perspectives-on-openai-astra-release"><span>Expert perspectives on OpenAI Astra release</span></h3><ul><li><strong>James Blake, VP of Global Cyber Resiliency Strategy at Cohesity:</strong></li></ul><p><em>The launch of Astra is raising questions again around the safety of Frontier AI. Instead of simply asking whether a model is "safe", organisations now need to ask whether it remains safe across millions of different situations, prompts and interactions. Cyber resilience has traditionally assumed that systems and threat actors behave deterministically. AI systems don’t.</em></p><div><blockquote><p>Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible?</p></blockquote></div><p><em>Advanced models can and will continue to exhibit behaviours that emerge from their optimisation process rather than from explicit programming. We have to move beyond thinking about AI as just another software tool and find ways to ensure these systems remain observable, auditable and governable throughout their lifecycle. </em></p><p><em>The most important question we’ll need to answer in future is one of liability. Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible? The developer that trained the model? The cloud provider operating the infrastructure? Currently the answer is surprisingly unclear. It’s not just about what AI can do: it’s about who is accountable when it does something nobody expected.</em></p><ul><li><strong>Oleksandr Yaremchuk, Co-Founder & CTO at Manifold Security:</strong></li></ul><p><em>OpenAI is calling Astra its most aligned model yet, even as its chief scientist admits monitorability is getting harder as models get more capable. Evidently, Astra hides its reasoning in the majority of tested cases, and some successful attacks left no reasoning trace at all. That's the tool many organisations still use, including the labs themselves, for auditing what an agent is doing, and it's getting less reliable with every release.</em></p><div><blockquote><p>A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</p></blockquote></div><p><em>That matters because Astra isn't staying inside OpenAI's test environment. It's going to run as an agent on employee laptops and in the browser, holding real credentials, inside companies that have no way to watch what it does once it's there. A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</em></p><p><em>Labs can keep debating what these models say or refuse to say. Security teams need to stop relying on that and start monitoring what agents actually do at runtime, with the ability to shut one down mid-action. That's the only oversight left that still works once the reasoning goes quiet.</em></p><ul><li><strong>Kristin Lowery, Field CISO at Optiv:</strong></li></ul><p><em>For boards and executive leaders, the emergence of OpenAI’s Astra model highlights a broader reality: AI is no longer just a productivity issue; it is a risk management issue. </em></p><div><blockquote><p>The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace</p></blockquote></div><p><em>Just as organizations established governance for cloud adoption and digital transformation, they now need clear policies, strong oversight, and accountability for AI use.</em></p><p><em>The question is not whether AI will become more capable — it will. The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace.</em></p><ul><li><strong>Patricia Titus, Field CISO at Abnormal AI:</strong></li></ul><p><em>OpenAI crossing this threshold deserves attention. Credit where it's due, they're handling it responsibly by restricting Astra's advanced cyber capability to a small coalition rather than releasing it broadly.But this isn't one company's problem to contain.</em></p><p><em>Once a model can find and exploit unknown flaws without a human in the loop, that capability doesn't stay exclusive for long. Open-weight and modified models typically trail the frontier by only months, and that's the reality defenders have to plan around now.</em></p><div><blockquote><p>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time.</p></blockquote></div><p><em>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time. Defenders need the same shift, systems that learn what normal looks like for every identity, human, machine, or AI agent, and flag and contain the moment something deviates, at machine speed.</em></p><p><em>The window to build that is open now. It won't stay that way once this capability is common instead of rare.</em></p><ul><li><strong>Raghu Nandakumara, VP of Industry Strategy at Illumio:</strong></li></ul><p><em>With the Astra announcement, OpenAI is doubling down on monitoring the model's own behaviour – a response to the model "breakouts" seen over the past few months.</em></p><div><blockquote><p>The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</p></blockquote></div><p><em>When Anthropic announced Claude Mythos Preview, the core concern was the model falling into the wrong hands. OpenAI's answer goes further adding guardrails around the model's own reasoning and actions, regardless of the user's intent. The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</em></p><p><em>The rest of this announcement can be summarised as ‘we have a new frontier model, and it’s more capable than the last one’.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google patches multiple browser bugs including one that was under active exploitation — so update now ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Google released Chrome 152.0.7977.82/.83 for Windows, Mac, and Linux</strong></li><li><strong>Patch fixes 12 flaws, including zero‑day CVE‑2026‑85046 (type confusion in V8)</strong></li><li><strong>Sixth Chrome zero‑day this year; Chromium browsers also affected, update urged immediately</strong></li></ul><p>Google has released a new version of its Chrome <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> for Windows, Mac, and Linux, fixing a dozen of vulnerabilities. Among them is a high-severity flaw that is being actively exploited in the wild.</p><p>In a security advisory published on the Google blog on September 3, the search engine company said Chrome’s newest version is now 152.0.7977.82/.83 for Windows and Mac, and 152.0.7977.82 for Linux.</p><p>Rollout is expected to be gradual, so make sure to check if you already received it. Most of the time the update is automatic and instant and if you’re not certain, tap the three vertical dots in the top-right corner of the browser and choose Help. Navigate to About Google Chrome and there you will find the version number. </p><h2 id="running-malicious-code-remotely">Running malicious code remotely</h2><p>This patch fixes a total of 12 vulnerabilities, most of which are graded as high severity. Among them is a “type confusion in V8” bug, discovered by security researcher Salvatore Gulizia.</p><p>For his effort, Gulizia was awarded $1,000. Apparently, this bug is being actively leveraged in real-life attacks, although Google (as usual) decided not to share the juicy details until the majority of browsers are protected.</p><p>The vulnerability is tracked as CVE-2026-85046. On the National Vulnerability Database (NVD), it is described as a “type confusion in V8 in Google Chrome [that allows] a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.”</p><p>V8 is Chrome’s JavaScript engine which allows web apps and interactive websites to run in the browser. Those interested in the technical breakdown of the vulnerability can find it on <a href="https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/" target="_blank" rel="nofollow">Guzlia’s blog</a>.</p><p>You can find the full list of fixed vulnerabilities on <a href="https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html" target="_blank" rel="nofollow">this link</a>. </p><p>This is the sixth zero-day Google fixed in Chrome since the start of the year. It also affects other browsers built on Chromium, so if you’re running Edge, Brave, Opera, or Vivaldi, make sure to update to the latest version as soon as possible. </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/google-patches-multiple-browser-bugs-including-one-that-was-under-active-exploitation-so-update-now</link>
                                                                            <description>
                            <![CDATA[ Google did not share the details about the bug being actively used. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PWhL6n866rriJHC4C6KTWa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 19:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg">
                                                            <media:credit><![CDATA[Tada Images / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:description>                                                            <media:text><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:text>
                                <media:title type="plain"><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Google released Chrome 152.0.7977.82/.83 for Windows, Mac, and Linux</strong></li><li><strong>Patch fixes 12 flaws, including zero‑day CVE‑2026‑85046 (type confusion in V8)</strong></li><li><strong>Sixth Chrome zero‑day this year; Chromium browsers also affected, update urged immediately</strong></li></ul><p>Google has released a new version of its Chrome <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> for Windows, Mac, and Linux, fixing a dozen of vulnerabilities. Among them is a high-severity flaw that is being actively exploited in the wild.</p><p>In a security advisory published on the Google blog on September 3, the search engine company said Chrome’s newest version is now 152.0.7977.82/.83 for Windows and Mac, and 152.0.7977.82 for Linux.</p><p>Rollout is expected to be gradual, so make sure to check if you already received it. Most of the time the update is automatic and instant and if you’re not certain, tap the three vertical dots in the top-right corner of the browser and choose Help. Navigate to About Google Chrome and there you will find the version number. </p><h2 id="running-malicious-code-remotely">Running malicious code remotely</h2><p>This patch fixes a total of 12 vulnerabilities, most of which are graded as high severity. Among them is a “type confusion in V8” bug, discovered by security researcher Salvatore Gulizia.</p><p>For his effort, Gulizia was awarded $1,000. Apparently, this bug is being actively leveraged in real-life attacks, although Google (as usual) decided not to share the juicy details until the majority of browsers are protected.</p><p>The vulnerability is tracked as CVE-2026-85046. On the National Vulnerability Database (NVD), it is described as a “type confusion in V8 in Google Chrome [that allows] a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.”</p><p>V8 is Chrome’s JavaScript engine which allows web apps and interactive websites to run in the browser. Those interested in the technical breakdown of the vulnerability can find it on <a href="https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/" target="_blank" rel="nofollow">Guzlia’s blog</a>.</p><p>You can find the full list of fixed vulnerabilities on <a href="https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html" target="_blank" rel="nofollow">this link</a>. </p><p>This is the sixth zero-day Google fixed in Chrome since the start of the year. It also affects other browsers built on Chromium, so if you’re running Edge, Brave, Opera, or Vivaldi, make sure to update to the latest version as soon as possible. </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI warns about how good Astra model is at cracking cybersecurity, releases it anyway because it took 'years of research and big bets' ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI rolled out GPT‑6 Astra, its most advanced AI, with “critical” cyber capabilities</strong></li><li><strong>Astra can autonomously find and exploit unknown flaws; release limited to vetted Daybreak participants</strong></li><li><strong>Staggered rollout sparked user frustration; Altman apologized, promising broader access soon</strong></li></ul><p>OpenAI has begun rolling out <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">GPT-6 Astra</a>, its latest and most capable artificial intelligence model. </p><p>In an announcement published on its website, OpenAI said Astra represents a “significant step up in cyber capabilities”, meeting the company’s “Critical” threshold.</p><p>This threshold, the company explained, means that under the right circumstances, the tool can find “previously unknown security flaws and develop new ways to exploit them across many well-protected systems without a person guiding each step.”</p><h2 id="apologies-for-a-messy-rollout">Apologies for a messy rollout</h2><p>OpenAI also said Astra improves on functions such as computer use, software engineering, and science, and that it should be better at staying oriented, compared to previous versions.</p><p>Just like many of the previous models, Astra’s release has been marred with controversy. Roughly a month ago, OpenAI said the model’s “critical” cybersecurity capabilities prompted it to <a href="https://www.channelnewsasia.com/business/openai-flags-possible-critical-cybersecurity-risk-in-upcoming-model-tightens-controls-6306796" target="_blank" rel="nofollow">pause some internal development</a> and trigger safety protocols.</p><p>In response to early findings, the company scaled up certain security controls and even paused activities that do not meet its newly established security requirements. </p><p>It now decided it was time to release the model, but still not to the general public. Instead, it opted for a staggered release, giving it first to a limited group of companies participating in the Daybreak program, a cybersecurity initiative that gives vetted organizations (cybersecurity and otherwise) specialized AI tools for vulnerability research and threat detection. </p><p>This did not sit well with many ChatGPT users, especially those paying a monthly subscription. As <a href="https://www.theverge.com/ai-artificial-intelligence/990060/altman-apologizes-messy-astra-rollout" target="_blank" rel="nofollow"><em>The Verge</em></a> reported, CEO Sam Altman was apologizing, mere hours after launch, for the “messy rollout” of Astra.</p><p>Initially, all Plus, Pro, Business, and Enterprise users were supposed to gain access to Astra, as well as those accessing through OpenAI API, Microsoft Azure, and AWS Bedrock. </p><p>“We are working towards getting Astra in everyone’s hands as quickly as we can,” Altman said on X. “I know it is frustrating and I appreciate the patience. It should be quick.”</p><p><em>Via </em><a href="https://www.cnbc.com/2026/09/03/open-ai-astra-gpt-6-cyber.html" target="_blank" rel="nofollow"><em>CNBC</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-warns-about-how-good-astra-model-is-at-cracking-cybersecurity-releases-it-anyway-because-it-took-years-of-research-and-big-bets</link>
                                                                            <description>
                            <![CDATA[ GPT-6 Astra was paused a month ago for triggering safety protocols and now it's being slowly rolled out. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JV7weBTmHEVs8GrqeHEVAE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 18:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[ChatGPT]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg">
                                                            <media:credit><![CDATA[OpenAI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI GPT-6 Astra]]></media:description>                                                            <media:text><![CDATA[OpenAI GPT-6 Astra]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI GPT-6 Astra]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI rolled out GPT‑6 Astra, its most advanced AI, with “critical” cyber capabilities</strong></li><li><strong>Astra can autonomously find and exploit unknown flaws; release limited to vetted Daybreak participants</strong></li><li><strong>Staggered rollout sparked user frustration; Altman apologized, promising broader access soon</strong></li></ul><p>OpenAI has begun rolling out <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">GPT-6 Astra</a>, its latest and most capable artificial intelligence model. </p><p>In an announcement published on its website, OpenAI said Astra represents a “significant step up in cyber capabilities”, meeting the company’s “Critical” threshold.</p><p>This threshold, the company explained, means that under the right circumstances, the tool can find “previously unknown security flaws and develop new ways to exploit them across many well-protected systems without a person guiding each step.”</p><h2 id="apologies-for-a-messy-rollout">Apologies for a messy rollout</h2><p>OpenAI also said Astra improves on functions such as computer use, software engineering, and science, and that it should be better at staying oriented, compared to previous versions.</p><p>Just like many of the previous models, Astra’s release has been marred with controversy. Roughly a month ago, OpenAI said the model’s “critical” cybersecurity capabilities prompted it to <a href="https://www.channelnewsasia.com/business/openai-flags-possible-critical-cybersecurity-risk-in-upcoming-model-tightens-controls-6306796" target="_blank" rel="nofollow">pause some internal development</a> and trigger safety protocols.</p><p>In response to early findings, the company scaled up certain security controls and even paused activities that do not meet its newly established security requirements. </p><p>It now decided it was time to release the model, but still not to the general public. Instead, it opted for a staggered release, giving it first to a limited group of companies participating in the Daybreak program, a cybersecurity initiative that gives vetted organizations (cybersecurity and otherwise) specialized AI tools for vulnerability research and threat detection. </p><p>This did not sit well with many ChatGPT users, especially those paying a monthly subscription. As <a href="https://www.theverge.com/ai-artificial-intelligence/990060/altman-apologizes-messy-astra-rollout" target="_blank" rel="nofollow"><em>The Verge</em></a> reported, CEO Sam Altman was apologizing, mere hours after launch, for the “messy rollout” of Astra.</p><p>Initially, all Plus, Pro, Business, and Enterprise users were supposed to gain access to Astra, as well as those accessing through OpenAI API, Microsoft Azure, and AWS Bedrock. </p><p>“We are working towards getting Astra in everyone’s hands as quickly as we can,” Altman said on X. “I know it is frustrating and I appreciate the patience. It should be quick.”</p><p><em>Via </em><a href="https://www.cnbc.com/2026/09/03/open-ai-astra-gpt-6-cyber.html" target="_blank" rel="nofollow"><em>CNBC</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why did FulcrumSec hackers try to extort Manchester Airports Group, and what happens now the data is leaked? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Following the aftermath of the Manchester Airports Group cyberattack - <a href="https://www.techradar.com/pro/security/manchester-airports-hackers-just-posted-the-data-of-8-7-million-people-online-failed-extortion-attempt-triggers-data-dump-sale">where hackers made off with the data of 8.7 million people</a> - the hackers have now posted the entire database for sale on the dark web.</p><p>The group behind the attack, FulcrumSec, attempted to get Manchester Airports Group (MAG) to pay for the security of the database, promising that it wouldn’t be released if the company paid a settlement. But as all companies should do when faced with extortion, MAG didn’t play ball.</p><p>Now FulcrumSec wants to try and maximise the damage of the cyberattack, and has listed the database containing email addresses, phone numbers, vehicle registrations and postcodes online in the hopes a fellow hacking group will find value in the data.</p><h2 id="what-happens-when-extortion-fails-and-why-didn-t-mag-pay">What happens when extortion fails, and why didn’t MAG pay?</h2><p>In the past, when companies faced ransomware attacks or data breaches, they would sometimes quietly pay the hackers for their silence. </p><p>Companies feared serious reputational harm and loss of business would cost more in the long run than the perpetrators were asking for. But this created an incentive for hackers to carry out more attacks.</p><p>After all, if companies aren’t kicking up a fuss about being hacked or reporting the attack to the authorities, hacking groups can launch more attacks on other companies that are completely unaware of their tactics.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>In order to counter this, authorities and cyber experts from around the world issued guidance that under no circumstances should companies pay for the safe return of their data. By removing the incentive from ransomware attacks and data breaches, the hope is that hackers will get bored or not see enough ROI, and therefore stop.</p><p>But the 500GB database of data on over 8.7 million people is ripe pickings for other cybercriminals looking to launch highly specific phishing attacks or scam campaigns. While FulcrumSec may not make any money from the attack, they can seriously enhance the damage of the attack by offering the data for free for others to use.</p><p>A successful scam or phishing attack can steal banking and financial details, allowing other groups to steal even more money off the back of the attack.</p><h3 class="article-body__section" id="section-expert-perspectives-on-mag-extortion-and-customer-data"><span>Expert perspectives on MAG extortion and customer data</span></h3><ul><li><strong>Dray Agha, senior manager of security operations at Huntress:</strong></li></ul><p><em>While Manchester Airports Group followed official guidance by refusing to pay the ransom, the release of 8.7 million records creates an immediate risk for passengers.</em></p><div><blockquote><p>The release of 8.7 million records creates an immediate risk for passengers</p></blockquote></div><p><em>We expect other criminals to use this freely available database of vehicle registrations, postcodes and contact details to craft highly convincing phishing attacks.</em></p><p><em>Anyone who has used parking, lounges or Wi-Fi at these airports must treat unexpected messages about their travel with extreme caution.</em></p><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress</strong></li></ul><p><em>The "free release" model is deliberately designed to maximise harm and reputational damage as a warning to the next target. </em></p><div><blockquote><p>It's a marketing campaign aimed at every other organisation watching</p></blockquote></div><p><em>Publishing almost nine million records for free isn't just punishment for MAG it's a marketing campaign aimed at every other organisation watching.</em></p><p><em>Pay up, or your customers' data gets handed to every fraudster and scammer on the internet at no cost. Refusing to pay a ransom is the right call. But nearly nine million people are now paying a different price for a decision that was never theirs to make.</em></p><ul><li><strong>Danny Jenkins, Co Founder & CEO at ThreatLocker</strong></li></ul><p><em>Unfortunately, once data is made public, it can’t be hidden again. The most important thing consumers can do is focus on basic cyber hygiene. Use a unique password for every website, learn how to identify phishing scams, and monitor your credit report.</em></p><div><blockquote><p>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</p></blockquote></div><p><em>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</em></p><p><em>When in doubt, look up the phone number for the alleged sender yourself, rather than using a number provided in the email, and call to confirm whether the communication is genuine.</em></p><ul><li><strong>Brian Higgins, security specialist at Comparitech:</strong></li></ul><p><em>Whilst the airports breached in this attack don't appear to have had any financial data compromised the risk to affected or associated customers is very real. With so much other information freely available in the wild it is vital that airport users stay highly vigilant for some time to come.</em></p><div><blockquote><p>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends.</p></blockquote></div><p><em>Any and all unsolicited contact; whether online, by telephone or even home visit approaches, should be viewed as suspicious. Never engage until you've taken time to check credentials/veracity etc.</em></p><p><em>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends. Look for ways to increase digital and physical security like two factor authentication on Apps and devices or Smart Home tech. </em></p><p><em>When this breach was first reported by the Manchester Evening News the comments were quite telling. Affected parties were quick to identify potential vulnerabilities over and above the breach of financial and banking details. </em></p><p><em>Home addresses, vehicle registrations and time spent away from home all add up to some excellent opportunities for criminal exploitation, not to mention the usual follow-up phishing campaigns common in this type of incident.</em></p><p><em>As AI makes data aggregation swift and easy consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways. It’s no longer enough for data owning organisations to advise post-attack vigilance and turn to their backups.</em></p><p><em>Victim communities rightly expect better protected networks and systems over and above established norms. As the marketplace grows less fearful and more angry when breaches are made public we may see more emphasis on cyber crime prevention which can only be a good thing.</em></p><ul><li><strong>Denis Calderone, CTO at Suzu Labs:</strong></li></ul><p><em>The 8.7 million number is attention-grabbing, but it deserves some context. MAG has confirmed that the vast majority of those records are email addresses collected through airport WiFi sign-ups. </em></p><p><em>A much smaller subset includes phone numbers, vehicle registrations, and postcodes from customers who actually completed parking or lounge bookings.</em></p><div><blockquote><p>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first.</p></blockquote></div><p><em>No payment data, no passwords, no passport information. So despite this affecting airports, which is obviously a sensitive subject, the actual data sensitivity for most affected individuals is relatively low.</em></p><p><em>What's more interesting to us from a technical standpoint is the attack path. MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That's a pivot upstream into a data provider, not downstream into operational systems.</em></p><p><em>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.</em></p><p><em>The UK's Civil Aviation Authority has a Cyber Assessment Framework for Aviation, developed with the NCSC, that mandates strict separation between IT systems and operational technology.</em></p><p><em>We don't know whether MAG was formally operating under that framework at the time of this incident, but I would be very interested to find out. Because the segmentation appears to have held here. Flight operations, baggage handling, terminal systems, etc., all were unaffected. </em></p><p><em>The lateral movement went upstream toward a data provider, not downstream toward the systems that keep planes in the air.</em></p><ul><li><strong>Seemant Sehgal, CEO and Founder at BreachLock:</strong></li></ul><p><em>This data was initially collected because passengers needed a login, and somewhere along the way, the sensitivity of what was accumulating in that database stopped getting the same scrutiny as the network itself.</em></p><div><blockquote><p>Whoever held it for ransom understood its value better than the organization storing it did</p></blockquote></div><p><em>Vehicle registration details, postcodes, and contact information across three major airports are a profiling dataset, and whoever held it for ransom understood its value better than the organization storing it did.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-did-fulcrumsec-hackers-try-to-extort-manchester-airports-group-and-what-happens-now-the-data-is-leaked-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ After hackers failed to extort Manchester Airports Group and posted the data of nearly 9 million people online, we asked the experts what's really going on. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fRCxPaa9De9wPUPVGxjDbh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 14:57:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Airport]]></media:description>                                                            <media:text><![CDATA[Airport]]></media:text>
                                <media:title type="plain"><![CDATA[Airport]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Following the aftermath of the Manchester Airports Group cyberattack - <a href="https://www.techradar.com/pro/security/manchester-airports-hackers-just-posted-the-data-of-8-7-million-people-online-failed-extortion-attempt-triggers-data-dump-sale">where hackers made off with the data of 8.7 million people</a> - the hackers have now posted the entire database for sale on the dark web.</p><p>The group behind the attack, FulcrumSec, attempted to get Manchester Airports Group (MAG) to pay for the security of the database, promising that it wouldn’t be released if the company paid a settlement. But as all companies should do when faced with extortion, MAG didn’t play ball.</p><p>Now FulcrumSec wants to try and maximise the damage of the cyberattack, and has listed the database containing email addresses, phone numbers, vehicle registrations and postcodes online in the hopes a fellow hacking group will find value in the data.</p><h2 id="what-happens-when-extortion-fails-and-why-didn-t-mag-pay">What happens when extortion fails, and why didn’t MAG pay?</h2><p>In the past, when companies faced ransomware attacks or data breaches, they would sometimes quietly pay the hackers for their silence. </p><p>Companies feared serious reputational harm and loss of business would cost more in the long run than the perpetrators were asking for. But this created an incentive for hackers to carry out more attacks.</p><p>After all, if companies aren’t kicking up a fuss about being hacked or reporting the attack to the authorities, hacking groups can launch more attacks on other companies that are completely unaware of their tactics.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>In order to counter this, authorities and cyber experts from around the world issued guidance that under no circumstances should companies pay for the safe return of their data. By removing the incentive from ransomware attacks and data breaches, the hope is that hackers will get bored or not see enough ROI, and therefore stop.</p><p>But the 500GB database of data on over 8.7 million people is ripe pickings for other cybercriminals looking to launch highly specific phishing attacks or scam campaigns. While FulcrumSec may not make any money from the attack, they can seriously enhance the damage of the attack by offering the data for free for others to use.</p><p>A successful scam or phishing attack can steal banking and financial details, allowing other groups to steal even more money off the back of the attack.</p><h3 class="article-body__section" id="section-expert-perspectives-on-mag-extortion-and-customer-data"><span>Expert perspectives on MAG extortion and customer data</span></h3><ul><li><strong>Dray Agha, senior manager of security operations at Huntress:</strong></li></ul><p><em>While Manchester Airports Group followed official guidance by refusing to pay the ransom, the release of 8.7 million records creates an immediate risk for passengers.</em></p><div><blockquote><p>The release of 8.7 million records creates an immediate risk for passengers</p></blockquote></div><p><em>We expect other criminals to use this freely available database of vehicle registrations, postcodes and contact details to craft highly convincing phishing attacks.</em></p><p><em>Anyone who has used parking, lounges or Wi-Fi at these airports must treat unexpected messages about their travel with extreme caution.</em></p><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress</strong></li></ul><p><em>The "free release" model is deliberately designed to maximise harm and reputational damage as a warning to the next target. </em></p><div><blockquote><p>It's a marketing campaign aimed at every other organisation watching</p></blockquote></div><p><em>Publishing almost nine million records for free isn't just punishment for MAG it's a marketing campaign aimed at every other organisation watching.</em></p><p><em>Pay up, or your customers' data gets handed to every fraudster and scammer on the internet at no cost. Refusing to pay a ransom is the right call. But nearly nine million people are now paying a different price for a decision that was never theirs to make.</em></p><ul><li><strong>Danny Jenkins, Co Founder & CEO at ThreatLocker</strong></li></ul><p><em>Unfortunately, once data is made public, it can’t be hidden again. The most important thing consumers can do is focus on basic cyber hygiene. Use a unique password for every website, learn how to identify phishing scams, and monitor your credit report.</em></p><div><blockquote><p>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</p></blockquote></div><p><em>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</em></p><p><em>When in doubt, look up the phone number for the alleged sender yourself, rather than using a number provided in the email, and call to confirm whether the communication is genuine.</em></p><ul><li><strong>Brian Higgins, security specialist at Comparitech:</strong></li></ul><p><em>Whilst the airports breached in this attack don't appear to have had any financial data compromised the risk to affected or associated customers is very real. With so much other information freely available in the wild it is vital that airport users stay highly vigilant for some time to come.</em></p><div><blockquote><p>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends.</p></blockquote></div><p><em>Any and all unsolicited contact; whether online, by telephone or even home visit approaches, should be viewed as suspicious. Never engage until you've taken time to check credentials/veracity etc.</em></p><p><em>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends. Look for ways to increase digital and physical security like two factor authentication on Apps and devices or Smart Home tech. </em></p><p><em>When this breach was first reported by the Manchester Evening News the comments were quite telling. Affected parties were quick to identify potential vulnerabilities over and above the breach of financial and banking details. </em></p><p><em>Home addresses, vehicle registrations and time spent away from home all add up to some excellent opportunities for criminal exploitation, not to mention the usual follow-up phishing campaigns common in this type of incident.</em></p><p><em>As AI makes data aggregation swift and easy consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways. It’s no longer enough for data owning organisations to advise post-attack vigilance and turn to their backups.</em></p><p><em>Victim communities rightly expect better protected networks and systems over and above established norms. As the marketplace grows less fearful and more angry when breaches are made public we may see more emphasis on cyber crime prevention which can only be a good thing.</em></p><ul><li><strong>Denis Calderone, CTO at Suzu Labs:</strong></li></ul><p><em>The 8.7 million number is attention-grabbing, but it deserves some context. MAG has confirmed that the vast majority of those records are email addresses collected through airport WiFi sign-ups. </em></p><p><em>A much smaller subset includes phone numbers, vehicle registrations, and postcodes from customers who actually completed parking or lounge bookings.</em></p><div><blockquote><p>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first.</p></blockquote></div><p><em>No payment data, no passwords, no passport information. So despite this affecting airports, which is obviously a sensitive subject, the actual data sensitivity for most affected individuals is relatively low.</em></p><p><em>What's more interesting to us from a technical standpoint is the attack path. MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That's a pivot upstream into a data provider, not downstream into operational systems.</em></p><p><em>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.</em></p><p><em>The UK's Civil Aviation Authority has a Cyber Assessment Framework for Aviation, developed with the NCSC, that mandates strict separation between IT systems and operational technology.</em></p><p><em>We don't know whether MAG was formally operating under that framework at the time of this incident, but I would be very interested to find out. Because the segmentation appears to have held here. Flight operations, baggage handling, terminal systems, etc., all were unaffected. </em></p><p><em>The lateral movement went upstream toward a data provider, not downstream toward the systems that keep planes in the air.</em></p><ul><li><strong>Seemant Sehgal, CEO and Founder at BreachLock:</strong></li></ul><p><em>This data was initially collected because passengers needed a login, and somewhere along the way, the sensitivity of what was accumulating in that database stopped getting the same scrutiny as the network itself.</em></p><div><blockquote><p>Whoever held it for ransom understood its value better than the organization storing it did</p></blockquote></div><p><em>Vehicle registration details, postcodes, and contact information across three major airports are a profiling dataset, and whoever held it for ransom understood its value better than the organization storing it did.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco patches three critical vulnerabilities as part of 'comprehensive internal security review' ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Cisco patched eight IOS XR flaws, including three critical (CVE‑2026‑20274, CVE‑2026‑20279, CVE‑2026‑20212)</strong></li><li><strong>Vulnerabilities allow unauthenticated exploitation, improper access control, and crafted input execution</strong></li><li><strong>No abuse reported; patches urged, with iACL workarounds for Nexus 9000 devices using Silicon One ASIC</strong></li></ul><p>Cisco patched eight vulnerabilities affecting its IOS XR operating system, including three critical-severity ones. It urged its customers to apply the patches as soon as possible, even though it stressed that there is no evidence any of these were abused in the wild.</p><p>The company detailed its findings in two advisories published on the same day - September 2.</p><p>In the first one, it disclosed seven vulnerabilities, including two critical-severity ones: CVE-2026-20274 and CVE-2026-20279. Both carry a severity rating of 9.8/10 (critical). The former is an improper control of a resource during its lifetime flaw - a network-based, low complexity, vulnerability that requires no authentication or user interaction to be exploited. The latter is described as an improper access control vulnerability that can lead to the same consequences.</p><h2 id="fixes-and-mitigations">Fixes and mitigations</h2><p>These flaws, along with five others, affect all releases of Cisco IOS XR Software, including Cisco IOS XR7 (LNT) Software, regardless of device configuration, the company explained. There are no available workarounds, and installing the provided patch is the only way to mitigate the risk.</p><p>The third flaw, disclosed in a separate advisory, is tracked as CVE-2026-20212. Successfully exploiting this one allows attackers to connect to an affected device and send crafted input that could be executed as code, without root privileges. “The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload,” Cisco explained. </p><p>This bug affects <a href="https://www.techradar.com/best/best-network-switches" target="_blank">Cisco Nexus 9000 Series Switches</a> if they include a Silicon One ASIC, the company stressed. A possible workaround is to use infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. There is also the option of iACLs only being used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release/5294410" target="_blank" rel="nofollow"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/cisco-patches-three-critical-vulnerabilities-as-part-of-comprehensive-internal-security-review</link>
                                                                            <description>
                            <![CDATA[ A total of eight flaws were fixed, none of which were exploited in the wild. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NwtFJ9WsAyxAmKVur5Dra9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4vPx4qpVwRADJoMvv3gttX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 13:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4vPx4qpVwRADJoMvv3gttX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Valriya Zankovych]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cisco]]></media:description>                                                            <media:text><![CDATA[Cisco]]></media:text>
                                <media:title type="plain"><![CDATA[Cisco]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4vPx4qpVwRADJoMvv3gttX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Cisco patched eight IOS XR flaws, including three critical (CVE‑2026‑20274, CVE‑2026‑20279, CVE‑2026‑20212)</strong></li><li><strong>Vulnerabilities allow unauthenticated exploitation, improper access control, and crafted input execution</strong></li><li><strong>No abuse reported; patches urged, with iACL workarounds for Nexus 9000 devices using Silicon One ASIC</strong></li></ul><p>Cisco patched eight vulnerabilities affecting its IOS XR operating system, including three critical-severity ones. It urged its customers to apply the patches as soon as possible, even though it stressed that there is no evidence any of these were abused in the wild.</p><p>The company detailed its findings in two advisories published on the same day - September 2.</p><p>In the first one, it disclosed seven vulnerabilities, including two critical-severity ones: CVE-2026-20274 and CVE-2026-20279. Both carry a severity rating of 9.8/10 (critical). The former is an improper control of a resource during its lifetime flaw - a network-based, low complexity, vulnerability that requires no authentication or user interaction to be exploited. The latter is described as an improper access control vulnerability that can lead to the same consequences.</p><h2 id="fixes-and-mitigations">Fixes and mitigations</h2><p>These flaws, along with five others, affect all releases of Cisco IOS XR Software, including Cisco IOS XR7 (LNT) Software, regardless of device configuration, the company explained. There are no available workarounds, and installing the provided patch is the only way to mitigate the risk.</p><p>The third flaw, disclosed in a separate advisory, is tracked as CVE-2026-20212. Successfully exploiting this one allows attackers to connect to an affected device and send crafted input that could be executed as code, without root privileges. “The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload,” Cisco explained. </p><p>This bug affects <a href="https://www.techradar.com/best/best-network-switches" target="_blank">Cisco Nexus 9000 Series Switches</a> if they include a Silicon One ASIC, the company stressed. A possible workaround is to use infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. There is also the option of iACLs only being used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release/5294410" target="_blank" rel="nofollow"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI puts its money where its mouth is, offers $1 billion in AI credits to cyber defenders ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI launched </strong><em><strong>Daybreak for Frontline Defenders</strong></em><strong>, offering $1B in credits for resource‑constrained security orgs</strong></li><li><strong>Priority goes to essential services, governments, banks, nonprofits, and open‑source maintainers</strong></li><li><strong>Initiative includes training, partnerships, and a water‑sector pilot with MS‑ISCA for local defenders</strong></li></ul><p>OpenAI is offering a billion dollars in credits to security organizations who want to use its Daybreak initiative but cannot afford it.</p><p>Daybreak is a cybersecurity program that provides vetted defenders with specialized <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI tools</a> and models. It was introduced in May this year, and later expanded into two tiers - Blue, and Red. Blue is the entry-level tier, providing a general-purpose model with custom-tailored safeguards. Red, on the other hand, offers a more purpose-trained cybersecurity model and almost no safeguards.</p><p>According to OpenAI, “thousands of defenders across 2,000 approved organizations and workspaces” already use Daybreak, including cybersecurity companies, defense organizations, and law enforcement agencies.</p><h2 id="who-gets-priority">Who gets priority?</h2><p>But these models cost money, and to make sure more businesses can access them, OpenAI announced, “Daybreak for Frontline Defenders”, a project where defenders can apply and receive credits for AI tokens. Even though the company announced it as a global initiative, it seems that US businesses will be the first to take advantage of it:</p><p>“OpenAI is committing $1 billion in subsidized Daybreak access to help resource-constrained cyber defenders, starting with the United States, put frontier AI to work, targeting it to be consumed over the next six months,” the company said in an announcement blog.</p><p>Businesses operating essential services such as water and wastewater systems, and electric grid operators, will get priority, OpenAI said. Then come state and local governments, community and regional banks, nonprofits, open-source maintainers, and then “other organizations with limited security resources.”</p><p>The subsidy is not just about using the models, though. OpenAI also said it will be increasing hands-on support for frontline defenders, training, and new partnerships. </p><p>On top of all that, OpenAI also announced a public sector, water-focused pilot with the Multi-State Information Sharing and Analysis Center (MS-ISCA) to train and support local, tribal, and territorial defenders.</p><p>“The pilot will pair Daybreak access with guided training and hands-on assistance for an initial group of public sector and water system defenders, helping them validate and prioritize findings, coordinate remediation, and develop a repeatable approach that can be expanded over time,” the announcement concluded.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-puts-its-money-where-its-mouth-is-offers-usd1-billion-in-ai-credits-to-cyber-defenders</link>
                                                                            <description>
                            <![CDATA[ Want to use Daybreak but cannot afford it? You can now apply for a subsidy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">t2rShP2332cHQ4q6yU7QA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6whQhAYA48xb8xVGQ3HNyX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 12:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6whQhAYA48xb8xVGQ3HNyX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/SPOA Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ChatGPT logo on a smartphone.]]></media:description>                                                            <media:text><![CDATA[ChatGPT logo on a smartphone.]]></media:text>
                                <media:title type="plain"><![CDATA[ChatGPT logo on a smartphone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6whQhAYA48xb8xVGQ3HNyX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI launched </strong><em><strong>Daybreak for Frontline Defenders</strong></em><strong>, offering $1B in credits for resource‑constrained security orgs</strong></li><li><strong>Priority goes to essential services, governments, banks, nonprofits, and open‑source maintainers</strong></li><li><strong>Initiative includes training, partnerships, and a water‑sector pilot with MS‑ISCA for local defenders</strong></li></ul><p>OpenAI is offering a billion dollars in credits to security organizations who want to use its Daybreak initiative but cannot afford it.</p><p>Daybreak is a cybersecurity program that provides vetted defenders with specialized <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI tools</a> and models. It was introduced in May this year, and later expanded into two tiers - Blue, and Red. Blue is the entry-level tier, providing a general-purpose model with custom-tailored safeguards. Red, on the other hand, offers a more purpose-trained cybersecurity model and almost no safeguards.</p><p>According to OpenAI, “thousands of defenders across 2,000 approved organizations and workspaces” already use Daybreak, including cybersecurity companies, defense organizations, and law enforcement agencies.</p><h2 id="who-gets-priority">Who gets priority?</h2><p>But these models cost money, and to make sure more businesses can access them, OpenAI announced, “Daybreak for Frontline Defenders”, a project where defenders can apply and receive credits for AI tokens. Even though the company announced it as a global initiative, it seems that US businesses will be the first to take advantage of it:</p><p>“OpenAI is committing $1 billion in subsidized Daybreak access to help resource-constrained cyber defenders, starting with the United States, put frontier AI to work, targeting it to be consumed over the next six months,” the company said in an announcement blog.</p><p>Businesses operating essential services such as water and wastewater systems, and electric grid operators, will get priority, OpenAI said. Then come state and local governments, community and regional banks, nonprofits, open-source maintainers, and then “other organizations with limited security resources.”</p><p>The subsidy is not just about using the models, though. OpenAI also said it will be increasing hands-on support for frontline defenders, training, and new partnerships. </p><p>On top of all that, OpenAI also announced a public sector, water-focused pilot with the Multi-State Information Sharing and Analysis Center (MS-ISCA) to train and support local, tribal, and territorial defenders.</p><p>“The pilot will pair Daybreak access with guided training and hands-on assistance for an initial group of public sector and water system defenders, helping them validate and prioritize findings, coordinate remediation, and develop a repeatable approach that can be expanded over time,” the announcement concluded.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IT helpdesk impersonation hits Microsoft Teams once again, with the hackers hiding their activity within legitimate tools ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft warns of Teams‑based campaign where attackers impersonate IT staff</strong></li><li><strong>Victims tricked into granting remote access, leading to malware, lateral movement, and ransomware</strong></li><li><strong>Defenses: verify support contacts, train staff, harden Teams, and use Defender Safe Links/ZAP</strong></li></ul><p>Microsoft is warning about an ongoing hacking campaign that starts with a Teams message and ends with a ransomware infection and data theft.</p><p>In a new in-depth report published on the Microsoft blog, it was said that unnamed threat actors were reaching out to their targets at various enterprises via a <a href="https://www.techradar.com/best/best-online-collaboration-tools" target="_blank">Teams chat</a>, while impersonating IT staff.</p><p>They were coercing their victims into granting remote access via screen sharing or <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote monitoring and management tools</a> and once received, used their access to install malware loaders and various other implants.</p><h2 id="how-to-defend-against-teams-borne-phishing">How to defend against Teams-borne phishing</h2><p>The malware was just the first stage of the attack. Subsequent stages include host reconnaissance, security-product and virtualization discovery, and “periodic desktop screen capture”. In other words - mapping out the landscape and conducting espionage.</p><p>The crooks would then enumerate domain accounts, servers, and users, through native tools and Active Directory Service Interfaces (ADSI) queries and begin moving laterally.</p><p>The final step includes identifying and extracting valuable data, followed by a ransomware infection.</p><p>Microsoft does not name the perpetrators, and mostly refers to them as “threat actors”. It makes sense, since the “fake IT support via Teams” technique is being used by multiple groups at this moment. Russia’s Cozy Bear, FIN7, and Storm-1811 are probably the most obvious examples.</p><p>The world’s biggest extortionists - ShinyHunters - are also known to use Teams to trick victims into granting access, but this group rarely deploys an encryptor and instead just focuses on data exfiltration.</p><p>Whoever the attackers are, and whoever they’re after, one thing is for certain - the risk in the enterprise environment has never been greater. </p><p>That is why Microsoft advises reinforcing user education by establishing internal helpdesk authentication phrases, and by training employees to recognize external-tenant indicators.</p><p>The company also urges enterprises to verify unsolicited support contact, and to harden Microsoft Teams and email against social engineering. “Use Microsoft Defender for Office 365 with Safe Links and Zero-hour auto purge (ZAP) so malicious messages and URLs are neutralized at time of click and removed after delivery,” Microsoft urges.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/it-helpdesk-impersonation-hits-microsoft-teams-once-again-with-the-hackers-hiding-their-activity-within-legitimate-tools</link>
                                                                            <description>
                            <![CDATA[ Microsoft is warning about an ongoing scam campaign starting in Teams. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QAnBBRikxHpmReRRcBoNhU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D4YBMfcEsNT7BhaNJJgm2A-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 16:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/D4YBMfcEsNT7BhaNJJgm2A-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pexels]]></media:description>                                                            <media:text><![CDATA[Collaboration in an office.]]></media:text>
                                <media:title type="plain"><![CDATA[Collaboration in an office.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D4YBMfcEsNT7BhaNJJgm2A-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns of Teams‑based campaign where attackers impersonate IT staff</strong></li><li><strong>Victims tricked into granting remote access, leading to malware, lateral movement, and ransomware</strong></li><li><strong>Defenses: verify support contacts, train staff, harden Teams, and use Defender Safe Links/ZAP</strong></li></ul><p>Microsoft is warning about an ongoing hacking campaign that starts with a Teams message and ends with a ransomware infection and data theft.</p><p>In a new in-depth report published on the Microsoft blog, it was said that unnamed threat actors were reaching out to their targets at various enterprises via a <a href="https://www.techradar.com/best/best-online-collaboration-tools" target="_blank">Teams chat</a>, while impersonating IT staff.</p><p>They were coercing their victims into granting remote access via screen sharing or <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote monitoring and management tools</a> and once received, used their access to install malware loaders and various other implants.</p><h2 id="how-to-defend-against-teams-borne-phishing">How to defend against Teams-borne phishing</h2><p>The malware was just the first stage of the attack. Subsequent stages include host reconnaissance, security-product and virtualization discovery, and “periodic desktop screen capture”. In other words - mapping out the landscape and conducting espionage.</p><p>The crooks would then enumerate domain accounts, servers, and users, through native tools and Active Directory Service Interfaces (ADSI) queries and begin moving laterally.</p><p>The final step includes identifying and extracting valuable data, followed by a ransomware infection.</p><p>Microsoft does not name the perpetrators, and mostly refers to them as “threat actors”. It makes sense, since the “fake IT support via Teams” technique is being used by multiple groups at this moment. Russia’s Cozy Bear, FIN7, and Storm-1811 are probably the most obvious examples.</p><p>The world’s biggest extortionists - ShinyHunters - are also known to use Teams to trick victims into granting access, but this group rarely deploys an encryptor and instead just focuses on data exfiltration.</p><p>Whoever the attackers are, and whoever they’re after, one thing is for certain - the risk in the enterprise environment has never been greater. </p><p>That is why Microsoft advises reinforcing user education by establishing internal helpdesk authentication phrases, and by training employees to recognize external-tenant indicators.</p><p>The company also urges enterprises to verify unsolicited support contact, and to harden Microsoft Teams and email against social engineering. “Use Microsoft Defender for Office 365 with Safe Links and Zero-hour auto purge (ZAP) so malicious messages and URLs are neutralized at time of click and removed after delivery,” Microsoft urges.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Clicking 'Allow' on a Google and Microsoft permission screens could give hackers access to your entire account, FBI warns ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>FBI warns of rising </strong><em><strong>OAuth consent phishing</strong></em><strong> attacks exploiting legitimate app permissions</strong></li><li><strong>Victims tricked into granting malicious apps access, enabling email reading and sending</strong></li><li><strong>Password changes don’t help; users must revoke tokens in app security settings</strong></li></ul><p>Hackers found a way to access your data, read your messages, and even send emails to your contacts, without ever needing your password or other login credentials. All they need from you is a single click on a completely legitimate, well-known platform.</p><p>The technique is called “OAuth consent phishing”. It’s been around for more than a year and it’s gotten popular to a point where even the FBI is taking note. Earlier this week, the law enforcement agency issued a new public service announcement, via its Internet Crime Complaint Center (IC3), warning Americans about the threat.</p><p>OAuth (Open Authorization) is an internet standard that allows users to give apps access to their account on another service, without giving the app their <a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> for that service. For example, when users install a new app, they have the “Continue with Google” option. When they click it, they are asked if they allow the app to access their email. If they approve, Google gives that app a special access token, which allows the app to access the user’s Google account without ever seeing the password.</p><h2 id="pulling-off-an-oauth-attack">Pulling off an OAuth attack</h2><p>So, to pull off an OAuth attack, the threat actor must first trick Google (or Microsoft, or any other company providing the service) and get their (malicious) app registered on the platform. Then they would reach out to their target via instant messaging, while impersonating government officials, media, and other publicly known personalities, and sharing a link to what appears to be a document.</p><p>The link redirects the victim to a legitimate service (for example, Google), where they are asked to grant permissions to the malicious app. If they approve, the attackers gain access to their email accounts with which they can do almost anything.</p><p>To make matters worse, simply changing the password does not fix the issue. The only way to eliminate the threat is to revoke the access token that was given, which can be done in the application security settings.</p><p>The FBI did not say who the threat actors were or who they were targeting, other than they were “prominent victims”. Their family members were being targeted, as well.</p><p><em>Via </em><a href="https://cybernews.com/news/oauth-consent-phishing-fbi-warning-account-takeover/" target="_blank"><em>The Record</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/clicking-allow-on-a-google-and-microsoft-permission-screens-could-give-hackers-access-to-your-entire-account-fbi-warns</link>
                                                                            <description>
                            <![CDATA[ OAuth consent phishing is a thing and the FBI is worried. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pWbGg4PydfXBEVQetdDJBV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 14:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay/Tumisu]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing]]></media:description>                                                            <media:text><![CDATA[Phishing]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>FBI warns of rising </strong><em><strong>OAuth consent phishing</strong></em><strong> attacks exploiting legitimate app permissions</strong></li><li><strong>Victims tricked into granting malicious apps access, enabling email reading and sending</strong></li><li><strong>Password changes don’t help; users must revoke tokens in app security settings</strong></li></ul><p>Hackers found a way to access your data, read your messages, and even send emails to your contacts, without ever needing your password or other login credentials. All they need from you is a single click on a completely legitimate, well-known platform.</p><p>The technique is called “OAuth consent phishing”. It’s been around for more than a year and it’s gotten popular to a point where even the FBI is taking note. Earlier this week, the law enforcement agency issued a new public service announcement, via its Internet Crime Complaint Center (IC3), warning Americans about the threat.</p><p>OAuth (Open Authorization) is an internet standard that allows users to give apps access to their account on another service, without giving the app their <a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> for that service. For example, when users install a new app, they have the “Continue with Google” option. When they click it, they are asked if they allow the app to access their email. If they approve, Google gives that app a special access token, which allows the app to access the user’s Google account without ever seeing the password.</p><h2 id="pulling-off-an-oauth-attack">Pulling off an OAuth attack</h2><p>So, to pull off an OAuth attack, the threat actor must first trick Google (or Microsoft, or any other company providing the service) and get their (malicious) app registered on the platform. Then they would reach out to their target via instant messaging, while impersonating government officials, media, and other publicly known personalities, and sharing a link to what appears to be a document.</p><p>The link redirects the victim to a legitimate service (for example, Google), where they are asked to grant permissions to the malicious app. If they approve, the attackers gain access to their email accounts with which they can do almost anything.</p><p>To make matters worse, simply changing the password does not fix the issue. The only way to eliminate the threat is to revoke the access token that was given, which can be done in the application security settings.</p><p>The FBI did not say who the threat actors were or who they were targeting, other than they were “prominent victims”. Their family members were being targeted, as well.</p><p><em>Via </em><a href="https://cybernews.com/news/oauth-consent-phishing-fbi-warning-account-takeover/" target="_blank"><em>The Record</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thomson Reuters hit by cyberattack that saw court documents across 11 states accessed by a hacker ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Thomson Reuters confirmed March 2026 breach of its C‑Track court management system</strong></li><li><strong>Incident affected courts in 11 US states, Ontario, and the US Virgin Islands</strong></li><li><strong>No operational disruption; scope of exposed records still under investigation, no misuse reported yet</strong></li></ul><p>Thomson Reuters, the IT company behind the Reuters news agency, suffered a cyberattack a few months ago, exposing certain court documents to the attackers. In a brief announcement published earlier this week, it seems Thomson Reuters only noticed the intrusion now, months after it was already over.</p><p>Here is what happened: Thomson Reuters operates a court case-management system called C-Track. It is a tool used by different courts to manage things like cases, filings, hearings, and schedules. It is used by courts in several US states, the US Virgin Islands, as well as Ontario, Canada.</p><p>On June 30, 2026, Thomson Reuters detected unauthorized activity in one of its cloud environments, prompting an investigation which later determined that an unauthorized threat actor broke in and obtained some C-Track files. This happened in March 2026. </p><h2 id="investigation-underway">Investigation underway</h2><p>So far, the incident is confirmed to have taken place across 11 US states (Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming), the U.S. Virgin Islands, and Ontario, Canada, exposing court records and personal information. Ontario's three Chief Justices confirmed it, as well, saying Thomson Reuters notified Ontario's Ministry of the Attorney General on July 23.</p><p>A more detailed investigation is currently underway, and all relevant authorities have been notified, it was said. At press time, Thomson Reuters did not yet determine exactly what information was accessed, or how many people were affected. The good news, however, is that there is currently no evidence of identity theft resulting from the incident, and there is no indication that systems handling court-related financial transactions were affected. </p><p>C-Track itself remains operational, as well. No threat actors have yet claimed responsibility for the attack or threatened to leak the files to the dark web.</p><p>"There has been no operational disruption to C-Track as a result of this incident," a Thomson Reuters spokesperson said. "Our products and services remain fully operational and are safe ​to continue to use. Independent ​cybersecurity experts assisted in ⁠the investigation and validated the remediation measures implemented."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/thomson-reuters-hit-by-cyberattack-that-saw-court-documents-across-11-states-accessed-by-a-hacker</link>
                                                                            <description>
                            <![CDATA[ A threat actor accessed C-Track files, compromised a cloud environment, and accessed court records across 11 states. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m8aiHByXqAA9YTCGGbFHxY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 14:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Thomson Reuters confirmed March 2026 breach of its C‑Track court management system</strong></li><li><strong>Incident affected courts in 11 US states, Ontario, and the US Virgin Islands</strong></li><li><strong>No operational disruption; scope of exposed records still under investigation, no misuse reported yet</strong></li></ul><p>Thomson Reuters, the IT company behind the Reuters news agency, suffered a cyberattack a few months ago, exposing certain court documents to the attackers. In a brief announcement published earlier this week, it seems Thomson Reuters only noticed the intrusion now, months after it was already over.</p><p>Here is what happened: Thomson Reuters operates a court case-management system called C-Track. It is a tool used by different courts to manage things like cases, filings, hearings, and schedules. It is used by courts in several US states, the US Virgin Islands, as well as Ontario, Canada.</p><p>On June 30, 2026, Thomson Reuters detected unauthorized activity in one of its cloud environments, prompting an investigation which later determined that an unauthorized threat actor broke in and obtained some C-Track files. This happened in March 2026. </p><h2 id="investigation-underway">Investigation underway</h2><p>So far, the incident is confirmed to have taken place across 11 US states (Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming), the U.S. Virgin Islands, and Ontario, Canada, exposing court records and personal information. Ontario's three Chief Justices confirmed it, as well, saying Thomson Reuters notified Ontario's Ministry of the Attorney General on July 23.</p><p>A more detailed investigation is currently underway, and all relevant authorities have been notified, it was said. At press time, Thomson Reuters did not yet determine exactly what information was accessed, or how many people were affected. The good news, however, is that there is currently no evidence of identity theft resulting from the incident, and there is no indication that systems handling court-related financial transactions were affected. </p><p>C-Track itself remains operational, as well. No threat actors have yet claimed responsibility for the attack or threatened to leak the files to the dark web.</p><p>"There has been no operational disruption to C-Track as a result of this incident," a Thomson Reuters spokesperson said. "Our products and services remain fully operational and are safe ​to continue to use. Independent ​cybersecurity experts assisted in ⁠the investigation and validated the remediation measures implemented."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft wants to make Windows 11 'secure by default' — but some gamers are up in arms about this security feature that 'wrecks' their frame rates ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft is rolling out a new security feature for Windows 11</strong></li><li><strong>Memory integrity provides stronger defenses for a crucial part of the operating system, and it's being automatically enabled</strong></li><li><strong>Some gamers say the feature hampers gaming frame rates considerably, and they're not happy</strong></li></ul><p>Windows 11 is getting its security bolstered with a feature that's being automatically enabled, but which comes at a cost that some PC gamers don't want to pay — and this is proving quite the controversy on social media.</p><p><a href="https://www.theverge.com/news/988056/microsoft-windows-11-memory-integrity-rollout-october-2026" target="_blank">The Verge reports</a> that <a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/expanding-memory-integrity-protection-across-windows-devices/4551984" target="_blank">Microsoft has announced</a> that it's rolling out the enablement of memory integrity protection across eligible Windows 11 PCs, and that this is because "security works best when protection is built in, not bolted on".</p><p>Microsoft explains: "More devices will soon receive stronger protection by default, with no additional setup required. Windows quality updates will begin enabling memory integrity protection on eligible devices.</p><p>"If not already enabled, these updates will also enable VBS [Virtualization Based Security], helping make additional security capabilities available and reflecting our commitment to making Windows secure by design and secure by default."</p><p>The idea is to tighten security for Windows 11's kernel-mode drivers, a core aspect of the OS with direct access to the system's hardware, and there can be no argument that this additional protection gives host PCs tougher defenses and makes them more difficult to exploit. So why the controversy? Let's dive into the pros and cons of what's going on here.</p><h2 id="analysis-a-divisive-move-but-we-can-39-t-ignore-that-the-threat-landscape-is-changing">Analysis: a divisive move — but we can't ignore that the threat landscape is changing</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2560px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="z39yxFuJJMCgwMhbV8vNcf" name="person-checking-gaming-pc" alt="Gamer at desk typing on gaming keyboard in front of PC monitor" src="https://cdn.mos.cms.futurecdn.net/z39yxFuJJMCgwMhbV8vNcf.jpg" mos="" align="middle" fullscreen="" width="2560" height="1440" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>In Microsoft's view, this is a no-brainer: stronger security is being rolled out to Windows 11 devices, or at least those which are eligible (older PCs may not be). However, PCs configured via group policy not to use memory integrity, or machines where it's been disabled before, won't have the feature forced on them.</p><p>Other supported PCs will get memory integrity (and VBS, because it's required for memory integrity) turned on automatically by Windows 11, and this is where some gamers are up in arms. VBS has a long history of being a thorn in the side for gamers, with the feature being linked to frame rate losses.</p><p>How much of a headwind does this cause for <a href="https://www.techradar.com/news/best-pc-games">PC games</a>? Well, therein lies a big part of the issue, because it's difficult to pin that down exactly, and as ever, it's bound to vary depending on your PC's exact hardware and system configuration.</p><p>Some gamers observe frame rate hits of approaching 10%, while others say the impact isn't noticeable at all. There's a lot of back-and-forth on Reddit arguing about the extent of any slowdown, and here's a typical exchange:</p><p><a href="https://www.reddit.com/r/pcmasterrace/comments/1w564ds/comment/p7cwuhm/" target="_blank">One Redditor notes</a>: "HVCI [memory integrity] is a great security feature, and the performance impact on newer platforms (to which this automatic switch will apply) is negligible."</p><p><a href="https://www.reddit.com/r/pcmasterrace/comments/1w564ds/comment/p7d074c/" target="_blank">Another replies</a>: "It ain't negligible. 9800x3d, 5080, ddr5 6000 cl28 and my 1% lows get wrecked with this feature on. Way smoother disabled."</p><p>This isn't just about frames per second performance for some gamers, then, as there are also accusations of it affecting the lowest troughs (bottom 1%) that the frame rate hits (meaning the game suffers more stuttering at times and generally feels jerkier).</p><p>As the first comment points out, though, the likelihood <em>should</em> be that a more modern PC won't feel much of a hit (if anything). The gaming rigs that might see more of a spanner in the frame rate works are those which are older, but still modern enough to get the auto-enablement of memory integrity. In other words, a collection of PCs which are on the outer fringes of that compatibility limit (older machines, but not too old to avoid the feature rollout).</p><p>Of course, even those PC owners can always turn off memory integrity. The major beef for some is that they remember that Microsoft got into trouble for <a href="https://www.techradar.com/news/windows-11-could-be-stealth-nerfing-graphics-cards-even-the-rtx-4090">automatically switching on VBS in the past</a> in a quiet, under-the-radar manner — and the question now will be whether gamers realize that this feature has been enabled alongside memory integrity.</p><p>In all honesty, when I saw what Microsoft was doing here and fired up Reddit to test the temperature of the reactions, I was expecting nothing short of a flamethrower being turned on the software giant. However, the feedback is split quite evenly between the haters — or those who disapprove at least — and users who are applauding Microsoft for this deployment.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:6000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KpMfF4cvQKAj9Tuqhwb3Uc" name="GettyImages-2198041148 copy" alt="Man and woman arguing" src="https://cdn.mos.cms.futurecdn.net/KpMfF4cvQKAj9Tuqhwb3Uc.jpg" mos="" align="middle" fullscreen="" width="6000" height="3375" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images/Focus Pixel Art)</span></figcaption></figure><p>Here are a couple of further examples from either <a href="https://www.reddit.com/r/pcmasterrace/comments/1w564ds/comment/p7ctwqy/" target="_blank">side of the fence</a>: "Apparently a controversial opinion, but systems that are for everyone should be failsafe, and that includes the most secure option being the default. There should be an option to disable security to get higher performance, but most secure should be the default."</p><p><a href="https://www.reddit.com/r/pcmasterrace/comments/1w564ds/comment/p7ekqui/" target="_blank">Juxtaposed with this</a>: "Already have memory integrity turned off as this 'feature' already hits gaming, I've used Windows without memory integrity for decades I think I'll be ok."</p><p>I must admit I'm inclined to agree with Microsoft's decision here — providing that when it happens, Windows 11 is clear on informing the user, so they can reverse the change if they aren't happy with it.</p><p>I think part of what Microsoft is doing here is keeping one eye on the future in terms of the difference AI might make to the security of Windows 11 PCs.</p><p>I keep hearing about how AI is already driving new threats and exploits, and so the kernel defenses that are being brought into play here may not have been quite as necessary in the past — as the last Reddit post I highlighted indicates — but they may be very much needed before too long. <a href="https://www.techradar.com/pro/ai-created-malware-is-on-the-rise-heres-what-your-business-needs-to-stay-safe">AI is accelerating the development of new threats</a> considerably, and making it easier for anyone to becoming a peddler of malware, so Microsoft likely feels the pressure to act.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/computing/windows/microsoft-wants-to-make-windows-11-secure-by-default-but-some-gamers-are-up-in-arms-about-this-security-feature-that-wrecks-their-frame-rates</link>
                                                                            <description>
                            <![CDATA[ Some gamers are up in arms, while others believe that this security feature is a must-have for keeping their PC safe. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tztex4zTN6unkUuH4eaxYH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Kvd2C5GUQeqhGqTh6M3w66-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 12:12:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Darren Allan ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Kvd2C5GUQeqhGqTh6M3w66-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Man upset at gaming PC, resting head on arms]]></media:description>                                                            <media:text><![CDATA[Man upset at gaming PC, resting head on arms]]></media:text>
                                <media:title type="plain"><![CDATA[Man upset at gaming PC, resting head on arms]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Kvd2C5GUQeqhGqTh6M3w66-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft is rolling out a new security feature for Windows 11</strong></li><li><strong>Memory integrity provides stronger defenses for a crucial part of the operating system, and it's being automatically enabled</strong></li><li><strong>Some gamers say the feature hampers gaming frame rates considerably, and they're not happy</strong></li></ul><p>Windows 11 is getting its security bolstered with a feature that's being automatically enabled, but which comes at a cost that some PC gamers don't want to pay — and this is proving quite the controversy on social media.</p><p><a href="https://www.theverge.com/news/988056/microsoft-windows-11-memory-integrity-rollout-october-2026" target="_blank">The Verge reports</a> that <a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/expanding-memory-integrity-protection-across-windows-devices/4551984" target="_blank">Microsoft has announced</a> that it's rolling out the enablement of memory integrity protection across eligible Windows 11 PCs, and that this is because "security works best when protection is built in, not bolted on".</p><p>Microsoft explains: "More devices will soon receive stronger protection by default, with no additional setup required. Windows quality updates will begin enabling memory integrity protection on eligible devices.</p><p>"If not already enabled, these updates will also enable VBS [Virtualization Based Security], helping make additional security capabilities available and reflecting our commitment to making Windows secure by design and secure by default."</p><p>The idea is to tighten security for Windows 11's kernel-mode drivers, a core aspect of the OS with direct access to the system's hardware, and there can be no argument that this additional protection gives host PCs tougher defenses and makes them more difficult to exploit. So why the controversy? Let's dive into the pros and cons of what's going on here.</p><h2 id="analysis-a-divisive-move-but-we-can-39-t-ignore-that-the-threat-landscape-is-changing">Analysis: a divisive move — but we can't ignore that the threat landscape is changing</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2560px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="z39yxFuJJMCgwMhbV8vNcf" name="person-checking-gaming-pc" alt="Gamer at desk typing on gaming keyboard in front of PC monitor" src="https://cdn.mos.cms.futurecdn.net/z39yxFuJJMCgwMhbV8vNcf.jpg" mos="" align="middle" fullscreen="" width="2560" height="1440" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>In Microsoft's view, this is a no-brainer: stronger security is being rolled out to Windows 11 devices, or at least those which are eligible (older PCs may not be). However, PCs configured via group policy not to use memory integrity, or machines where it's been disabled before, won't have the feature forced on them.</p><p>Other supported PCs will get memory integrity (and VBS, because it's required for memory integrity) turned on automatically by Windows 11, and this is where some gamers are up in arms. VBS has a long history of being a thorn in the side for gamers, with the feature being linked to frame rate losses.</p><p>How much of a headwind does this cause for <a href="https://www.techradar.com/news/best-pc-games">PC games</a>? Well, therein lies a big part of the issue, because it's difficult to pin that down exactly, and as ever, it's bound to vary depending on your PC's exact hardware and system configuration.</p><p>Some gamers observe frame rate hits of approaching 10%, while others say the impact isn't noticeable at all. There's a lot of back-and-forth on Reddit arguing about the extent of any slowdown, and here's a typical exchange:</p><p><a href="https://www.reddit.com/r/pcmasterrace/comments/1w564ds/comment/p7cwuhm/" target="_blank">One Redditor notes</a>: "HVCI [memory integrity] is a great security feature, and the performance impact on newer platforms (to which this automatic switch will apply) is negligible."</p><p><a href="https://www.reddit.com/r/pcmasterrace/comments/1w564ds/comment/p7d074c/" target="_blank">Another replies</a>: "It ain't negligible. 9800x3d, 5080, ddr5 6000 cl28 and my 1% lows get wrecked with this feature on. Way smoother disabled."</p><p>This isn't just about frames per second performance for some gamers, then, as there are also accusations of it affecting the lowest troughs (bottom 1%) that the frame rate hits (meaning the game suffers more stuttering at times and generally feels jerkier).</p><p>As the first comment points out, though, the likelihood <em>should</em> be that a more modern PC won't feel much of a hit (if anything). The gaming rigs that might see more of a spanner in the frame rate works are those which are older, but still modern enough to get the auto-enablement of memory integrity. In other words, a collection of PCs which are on the outer fringes of that compatibility limit (older machines, but not too old to avoid the feature rollout).</p><p>Of course, even those PC owners can always turn off memory integrity. The major beef for some is that they remember that Microsoft got into trouble for <a href="https://www.techradar.com/news/windows-11-could-be-stealth-nerfing-graphics-cards-even-the-rtx-4090">automatically switching on VBS in the past</a> in a quiet, under-the-radar manner — and the question now will be whether gamers realize that this feature has been enabled alongside memory integrity.</p><p>In all honesty, when I saw what Microsoft was doing here and fired up Reddit to test the temperature of the reactions, I was expecting nothing short of a flamethrower being turned on the software giant. However, the feedback is split quite evenly between the haters — or those who disapprove at least — and users who are applauding Microsoft for this deployment.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:6000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KpMfF4cvQKAj9Tuqhwb3Uc" name="GettyImages-2198041148 copy" alt="Man and woman arguing" src="https://cdn.mos.cms.futurecdn.net/KpMfF4cvQKAj9Tuqhwb3Uc.jpg" mos="" align="middle" fullscreen="" width="6000" height="3375" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images/Focus Pixel Art)</span></figcaption></figure><p>Here are a couple of further examples from either <a href="https://www.reddit.com/r/pcmasterrace/comments/1w564ds/comment/p7ctwqy/" target="_blank">side of the fence</a>: "Apparently a controversial opinion, but systems that are for everyone should be failsafe, and that includes the most secure option being the default. There should be an option to disable security to get higher performance, but most secure should be the default."</p><p><a href="https://www.reddit.com/r/pcmasterrace/comments/1w564ds/comment/p7ekqui/" target="_blank">Juxtaposed with this</a>: "Already have memory integrity turned off as this 'feature' already hits gaming, I've used Windows without memory integrity for decades I think I'll be ok."</p><p>I must admit I'm inclined to agree with Microsoft's decision here — providing that when it happens, Windows 11 is clear on informing the user, so they can reverse the change if they aren't happy with it.</p><p>I think part of what Microsoft is doing here is keeping one eye on the future in terms of the difference AI might make to the security of Windows 11 PCs.</p><p>I keep hearing about how AI is already driving new threats and exploits, and so the kernel defenses that are being brought into play here may not have been quite as necessary in the past — as the last Reddit post I highlighted indicates — but they may be very much needed before too long. <a href="https://www.techradar.com/pro/ai-created-malware-is-on-the-rise-heres-what-your-business-needs-to-stay-safe">AI is accelerating the development of new threats</a> considerably, and making it easier for anyone to becoming a peddler of malware, so Microsoft likely feels the pressure to act.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Only one in five UK CEOs say their cyber insurance will cover the full cost of a cyberattack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>22% expect their policy to offer full coverage, 10% expect it to fall short</strong></li><li><strong>Data breaches and reputational damage are major concerns</strong></li><li><strong>Companies should look at finances before considering operational recovery readiness</strong></li></ul><p>New research from Cohesity has revealed that many UK businesses could be significantly overestimating the protection they get from cyber insurance policies, with just one in five (22%) British CEOs believing their policy would cover both the additional costs and lost revenue that an attack could lead to.</p><p>A third expect it would cover the additional costs only, another third believe their policy is only sufficient for lost revenue, and a further one in 10 did not expect it to cover either of the two categories.</p><p>The report's conclusion is that cyber insurance in its current state for many UK businesses is only enough to transfer some of the financial risk – but not enough to restore systems, data or operations.</p><h2 id="cyber-insurance-policies-don-39-t-provide-enough-cover">Cyber insurance policies don't provide enough cover</h2><p>According to the study of 100 CEOs from large enterprises, businesses expect a cyberattack to reduce their revenue by an average of around 15%, but many businesses lack a detailed understanding of how much an attack could actually end up costing them. As many as one in five (21%) haven't even conducted business impact modelling.</p><p>Among CEOs' biggest fears are data breaches (49%), brand and reputational damage (38%), high recovery costs (36%), revenue loss (34%) and production downtime (30%). They're all either financial concerns or incidents that could lead to financial loss, and yet it's clear that policies are unlikely to offer enough cover.</p><p>With many totally unaware of the potential impacts and the extent of their policy's cover, Cohesity urges businesses to start off with calculating financial exposure and understanding what their policy covers.</p><p>After that, they can go on to prove that critical systems can actually be recovered, because without an insurance payout, this would likely not be possible.</p><p>"Organisations must be able to identify the systems and data needed to keep the business operating, assigning clear responsibility for recovery decisions and regularly testing whether critical services can be restored securely," UK&I VP Fraser Hutchison explained.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/only-one-in-five-uk-ceos-say-their-cyber-insurance-will-cover-the-full-cost-of-a-cyberattack</link>
                                                                            <description>
                            <![CDATA[ New data has revealed that only one in five CEOs expect full coverage from their cyber insurance policy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cZ3r6t6Y6FWyxjoMbJbwM5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 11:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg">
                                                            <media:credit><![CDATA[sarayut Thaneerat/ via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:description>                                                            <media:text><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:text>
                                <media:title type="plain"><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>22% expect their policy to offer full coverage, 10% expect it to fall short</strong></li><li><strong>Data breaches and reputational damage are major concerns</strong></li><li><strong>Companies should look at finances before considering operational recovery readiness</strong></li></ul><p>New research from Cohesity has revealed that many UK businesses could be significantly overestimating the protection they get from cyber insurance policies, with just one in five (22%) British CEOs believing their policy would cover both the additional costs and lost revenue that an attack could lead to.</p><p>A third expect it would cover the additional costs only, another third believe their policy is only sufficient for lost revenue, and a further one in 10 did not expect it to cover either of the two categories.</p><p>The report's conclusion is that cyber insurance in its current state for many UK businesses is only enough to transfer some of the financial risk – but not enough to restore systems, data or operations.</p><h2 id="cyber-insurance-policies-don-39-t-provide-enough-cover">Cyber insurance policies don't provide enough cover</h2><p>According to the study of 100 CEOs from large enterprises, businesses expect a cyberattack to reduce their revenue by an average of around 15%, but many businesses lack a detailed understanding of how much an attack could actually end up costing them. As many as one in five (21%) haven't even conducted business impact modelling.</p><p>Among CEOs' biggest fears are data breaches (49%), brand and reputational damage (38%), high recovery costs (36%), revenue loss (34%) and production downtime (30%). They're all either financial concerns or incidents that could lead to financial loss, and yet it's clear that policies are unlikely to offer enough cover.</p><p>With many totally unaware of the potential impacts and the extent of their policy's cover, Cohesity urges businesses to start off with calculating financial exposure and understanding what their policy covers.</p><p>After that, they can go on to prove that critical systems can actually be recovered, because without an insurance payout, this would likely not be possible.</p><p>"Organisations must be able to identify the systems and data needed to keep the business operating, assigning clear responsibility for recovery decisions and regularly testing whether critical services can be restored securely," UK&I VP Fraser Hutchison explained.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ When content is free, trust is the product ]]></title>
                                                                                                <dc:content><![CDATA[ <p>There is more technical content available today than any human being could read in a thousand lifetimes. Every topic has a dozen YouTube videos, three Substack posts, a GitHub repo, and a Reddit thread, most created in the last six months and, in many cases, technically accurate.</p><p>And yet most of the professionals I talk to say they don't know what to trust. They can't tell what’s important to read first, or which of 10 plausible answers is the one that holds up. That was true before AI, and AI has made it more true.</p><p>For most of the history of technical publishing, editing and verification were the same process, and that process was slow and expensive. Getting a book out took years. We found an author, vetted them, had them work with an editor, and checked their claims with technical reviewers.</p><p>A lot of that time went into separating what was correct and useful from what was confusing or only sounded right. It was laborious, but it meant a reader could depend on the claims on the page.</p><p>The credibility of the book, and of the publisher behind it, mattered as much as the information itself. When the cost of production drops to zero, that credibility becomes worth more, not less. Content is easier to make than ever, but without a transparent process behind it, readers have no idea where the knowledge came from or whether it holds up.</p><p>As Jasmine Sun puts it in “The Independent Writer’s Advantage in the Age of AI,” "Trust is not about information and its quality alone. It's about the messenger. It's about who says it and their track record and what they've told me before." A practitioner has confidence in a source because someone she respects has put their reputation on the line for it.</p><p>They believe what the author is saying because the publisher has a history of being right and of correcting itself when it isn't, and because the work is attributed and verifiable.</p><h2 id="expertise-is-alive-and-it-compounds">Expertise is alive, and it compounds</h2><p>The corpus matters, but it's the assurances around it that are hard to replicate, and that comes not just from the people who produce the content but from the people whose judgment vouches for it. Sometimes a creator brings their own credibility with them. Other times, the publisher spots someone unknown and lends them its own. </p><p>The art critic Dave Hickey said this about gallery owners in Air Guitar: They gain status from the famous artists they represent and share it with emerging talent who have something to offer but who haven't had the chance to earn a reputation.</p><p>Expertise is alive, and it compounds Expertise is a living thing, continuously expanding. Content starts to decay the moment it’s published, because frameworks evolve, libraries deprecate, and yesterday's best practice becomes today's <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> incident. Keeping expertise alive requires a pipeline of people who stay current and an editorial layer that notices when something has gone stale, and either retires it or calls for a fix.</p><p>That pipeline isn't something you switch on when an author has a book to ship. Content sits at the center of our platform, but we think about it in pace layers. Some advice is timeless, some moves but has a long shelf life (some of our books are still in print after nearly 50 years!), and some changes weekly.</p><p>We work with experts at each pace layer, capturing what lasts while doing our best to keep pace with an industry that seems to have changed every time we wake up.</p><p>We have relationships with hundreds of the best practitioners in the world, and our job is to keep them engaged continuously, with quick takes when something breaks, structured responses when major research drops, and live sessions on emerging topics while they're still emerging.</p><h2 id="trust-is-earnt">Trust is earnt</h2><p>An institution doesn't stamp trust onto content. In a technical community, trust is conferred in both directions. A practitioner earns standing because people who already have standing engage with her work, cite it, argue with it, and build on it. That insight was the whole idea behind PageRank, Google's first great innovation. A page mattered because other pages that mattered linked to it. Reputation works the same way.</p><p>The audience isn't just consuming reputation signals; it's generating them. When a senior engineer whose judgment others respect says out loud that something is worth reading, she spends a little of her own credibility; the author gains a little; and everyone watching recalibrates whom to trust next time.</p><p>When we put our mark on someone's work, we aren't the sole source of its credibility. We're amplifying a judgment the community is already making and adding our own track record to it. The reader who finds it reliable hands status back to the source.</p><h2 id="when-the-readers-are-machines">When the readers are machines</h2><p>Human practitioners aren't the only ones who need trusted engineering knowledge. The AI systems now sitting in every workflow, the coding and debugging agents and architecture advisors, need it just as badly since most of them are built on scraped web <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> and <a href="https://www.techradar.com/pro/best-it-documentation-tool">documentation</a> that was stale before it was ever indexed. They're fluent, but they're wrong often enough that you can't just take their word for it.</p><p>The stakes grow with <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> increasingly being used to generate not just provably correct types of content like code, which either works or it doesn’t, but persuasive documents in fuzzier areas like hiring, strategy, and so on. Like everyone else leaning on these tools, we are reckoning with the consequences of the ability to talk to a model and get back something that looks smart at a glance.</p><p>A few rounds in, the slop is still there. In the last few months, maybe 10 times as many documents have crossed our desks, from new product ideas to strategic plans and proposals. But the ease of generating the text hides the fact that either the model or the person prompting it doesn't actually know what they’re talking about. Knowledge workers need ways to ground their work in insights from human experts, particularly when that work is AI-assisted.</p><p>So we’re building tools that let agents draw on our repository of expertise to support their proposed decisions.</p><p>Credible sources are particularly important when thinking through and justifying important choices. Our CTO, Andrew Odewahn, describes the shift this way: "18 months ago, it was all about how to get engineers to be more productive, but now it's about how to get organizations to make better decisions. The engineering tasks are moving away from coding output to planning."</p><p>For planning tasks like comparing implementation approaches, you need expert-over-your-shoulder guidance for contextual decision-making. You can’t just rely on an LLM's best guess to solve your problem. Trust is foundational because the expertise behind it stays genuine, practical, and human.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/when-content-is-free-trust-is-the-product</link>
                                                                            <description>
                            <![CDATA[ There is more technical content available today than any human being could read in a thousand lifetimes. And yet most of the professionals I talk to say they don't know what to trust. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZjfgvUVdTaDkjNdD63kNan</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 11:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Julie Baron ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:description>                                                            <media:text><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There is more technical content available today than any human being could read in a thousand lifetimes. Every topic has a dozen YouTube videos, three Substack posts, a GitHub repo, and a Reddit thread, most created in the last six months and, in many cases, technically accurate.</p><p>And yet most of the professionals I talk to say they don't know what to trust. They can't tell what’s important to read first, or which of 10 plausible answers is the one that holds up. That was true before AI, and AI has made it more true.</p><p>For most of the history of technical publishing, editing and verification were the same process, and that process was slow and expensive. Getting a book out took years. We found an author, vetted them, had them work with an editor, and checked their claims with technical reviewers.</p><p>A lot of that time went into separating what was correct and useful from what was confusing or only sounded right. It was laborious, but it meant a reader could depend on the claims on the page.</p><p>The credibility of the book, and of the publisher behind it, mattered as much as the information itself. When the cost of production drops to zero, that credibility becomes worth more, not less. Content is easier to make than ever, but without a transparent process behind it, readers have no idea where the knowledge came from or whether it holds up.</p><p>As Jasmine Sun puts it in “The Independent Writer’s Advantage in the Age of AI,” "Trust is not about information and its quality alone. It's about the messenger. It's about who says it and their track record and what they've told me before." A practitioner has confidence in a source because someone she respects has put their reputation on the line for it.</p><p>They believe what the author is saying because the publisher has a history of being right and of correcting itself when it isn't, and because the work is attributed and verifiable.</p><h2 id="expertise-is-alive-and-it-compounds">Expertise is alive, and it compounds</h2><p>The corpus matters, but it's the assurances around it that are hard to replicate, and that comes not just from the people who produce the content but from the people whose judgment vouches for it. Sometimes a creator brings their own credibility with them. Other times, the publisher spots someone unknown and lends them its own. </p><p>The art critic Dave Hickey said this about gallery owners in Air Guitar: They gain status from the famous artists they represent and share it with emerging talent who have something to offer but who haven't had the chance to earn a reputation.</p><p>Expertise is alive, and it compounds Expertise is a living thing, continuously expanding. Content starts to decay the moment it’s published, because frameworks evolve, libraries deprecate, and yesterday's best practice becomes today's <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> incident. Keeping expertise alive requires a pipeline of people who stay current and an editorial layer that notices when something has gone stale, and either retires it or calls for a fix.</p><p>That pipeline isn't something you switch on when an author has a book to ship. Content sits at the center of our platform, but we think about it in pace layers. Some advice is timeless, some moves but has a long shelf life (some of our books are still in print after nearly 50 years!), and some changes weekly.</p><p>We work with experts at each pace layer, capturing what lasts while doing our best to keep pace with an industry that seems to have changed every time we wake up.</p><p>We have relationships with hundreds of the best practitioners in the world, and our job is to keep them engaged continuously, with quick takes when something breaks, structured responses when major research drops, and live sessions on emerging topics while they're still emerging.</p><h2 id="trust-is-earnt">Trust is earnt</h2><p>An institution doesn't stamp trust onto content. In a technical community, trust is conferred in both directions. A practitioner earns standing because people who already have standing engage with her work, cite it, argue with it, and build on it. That insight was the whole idea behind PageRank, Google's first great innovation. A page mattered because other pages that mattered linked to it. Reputation works the same way.</p><p>The audience isn't just consuming reputation signals; it's generating them. When a senior engineer whose judgment others respect says out loud that something is worth reading, she spends a little of her own credibility; the author gains a little; and everyone watching recalibrates whom to trust next time.</p><p>When we put our mark on someone's work, we aren't the sole source of its credibility. We're amplifying a judgment the community is already making and adding our own track record to it. The reader who finds it reliable hands status back to the source.</p><h2 id="when-the-readers-are-machines">When the readers are machines</h2><p>Human practitioners aren't the only ones who need trusted engineering knowledge. The AI systems now sitting in every workflow, the coding and debugging agents and architecture advisors, need it just as badly since most of them are built on scraped web <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> and <a href="https://www.techradar.com/pro/best-it-documentation-tool">documentation</a> that was stale before it was ever indexed. They're fluent, but they're wrong often enough that you can't just take their word for it.</p><p>The stakes grow with <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> increasingly being used to generate not just provably correct types of content like code, which either works or it doesn’t, but persuasive documents in fuzzier areas like hiring, strategy, and so on. Like everyone else leaning on these tools, we are reckoning with the consequences of the ability to talk to a model and get back something that looks smart at a glance.</p><p>A few rounds in, the slop is still there. In the last few months, maybe 10 times as many documents have crossed our desks, from new product ideas to strategic plans and proposals. But the ease of generating the text hides the fact that either the model or the person prompting it doesn't actually know what they’re talking about. Knowledge workers need ways to ground their work in insights from human experts, particularly when that work is AI-assisted.</p><p>So we’re building tools that let agents draw on our repository of expertise to support their proposed decisions.</p><p>Credible sources are particularly important when thinking through and justifying important choices. Our CTO, Andrew Odewahn, describes the shift this way: "18 months ago, it was all about how to get engineers to be more productive, but now it's about how to get organizations to make better decisions. The engineering tasks are moving away from coding output to planning."</p><p>For planning tasks like comparing implementation approaches, you need expert-over-your-shoulder guidance for contextual decision-making. You can’t just rely on an LLM's best guess to solve your problem. Trust is foundational because the expertise behind it stays genuine, practical, and human.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 2.8 million people affected by data breach at Baylor Genetics testing and diagnostic firm ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Baylor Genetics confirmed a June cyberattack affecting 2.8M patients and employees</strong></li><li><strong>Stolen data includes medical test results, insurance info, and some SSNs/financial details</strong></li><li><strong>Operations continued; no misuse seen yet, but no group has claimed responsibility</strong></li></ul><p>Baylor Genetics, a US-based clinical diagnostic laboratory, suffered a cyberattack in which it lost sensitive data on 2.8 million people - both patients and employees.</p><p>In a security update posted on its website earlier this week, the company said it spotted the intrusion in a “limited portion” of its IT environment on or around June 15. Subsequent investigation determined that both patients and employees have had their data stolen, including those who are not working at Baylor anymore.</p><p>For patients, crooks stole names, dates of birth, medical testing information, laboratory test results, and “potentially health insurance information, as well as Social Security number”. SSNs, Baylor Genetics stressed, were taken from a “very limited subset of patients”.</p><h2 id="no-attribution-yet">No attribution yet</h2><p>Regardless, fraudsters who know the details about medical testing and lab results have more than enough information to launch highly sophisticated, personalized phishing attacks that can lead to ransomware infections, business email compromise, and more. </p><p>For certain current and former employees, the attackers nabbed Social Security numbers, government-issued identification numbers, and financial account information, ideal for wire fraud. </p><p>In the security update, the company did not discuss the identity of the attackers, or the number of affected individuals. However, in a separate report filed with the US Department of Health and Human Services, Baylor reported the number of victims as 2,810,878. It added that at the time of publication, there was no evidence of confirmed <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, fraud, or misuse of personal information stolen in the attack. </p><p>It also said the incident did not impact its everyday operations which continued as usual. </p><p>Usually, data theft incidents like this one are followed by public disclosure from the perpetrators, who name-and-shame their victims in an attempt to get them to pay a ransom demand. So far, no threat actors claimed responsibility for this incident.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/2-8-million-people-affected-by-data-breach-at-baylor-genetics-testing-and-diagnostic-firm</link>
                                                                            <description>
                            <![CDATA[ Business continued as usual, although employees and patients lost plenty of sensitive data in the incident. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">asYqA3pQDCzhjPh7qcTguQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 11:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Laboratory]]></media:description>                                                            <media:text><![CDATA[Laboratory]]></media:text>
                                <media:title type="plain"><![CDATA[Laboratory]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Baylor Genetics confirmed a June cyberattack affecting 2.8M patients and employees</strong></li><li><strong>Stolen data includes medical test results, insurance info, and some SSNs/financial details</strong></li><li><strong>Operations continued; no misuse seen yet, but no group has claimed responsibility</strong></li></ul><p>Baylor Genetics, a US-based clinical diagnostic laboratory, suffered a cyberattack in which it lost sensitive data on 2.8 million people - both patients and employees.</p><p>In a security update posted on its website earlier this week, the company said it spotted the intrusion in a “limited portion” of its IT environment on or around June 15. Subsequent investigation determined that both patients and employees have had their data stolen, including those who are not working at Baylor anymore.</p><p>For patients, crooks stole names, dates of birth, medical testing information, laboratory test results, and “potentially health insurance information, as well as Social Security number”. SSNs, Baylor Genetics stressed, were taken from a “very limited subset of patients”.</p><h2 id="no-attribution-yet">No attribution yet</h2><p>Regardless, fraudsters who know the details about medical testing and lab results have more than enough information to launch highly sophisticated, personalized phishing attacks that can lead to ransomware infections, business email compromise, and more. </p><p>For certain current and former employees, the attackers nabbed Social Security numbers, government-issued identification numbers, and financial account information, ideal for wire fraud. </p><p>In the security update, the company did not discuss the identity of the attackers, or the number of affected individuals. However, in a separate report filed with the US Department of Health and Human Services, Baylor reported the number of victims as 2,810,878. It added that at the time of publication, there was no evidence of confirmed <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, fraud, or misuse of personal information stolen in the attack. </p><p>It also said the incident did not impact its everyday operations which continued as usual. </p><p>Usually, data theft incidents like this one are followed by public disclosure from the perpetrators, who name-and-shame their victims in an attempt to get them to pay a ransom demand. So far, no threat actors claimed responsibility for this incident.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security policy is critical infrastructure ]]></title>
                                                                                                <dc:content><![CDATA[ <p>In banking and utilities, regulators define certain systems as essential. An essential system is one whose failure would cause intolerable harm to <a href="https://www.techradar.com/best/best-customer-feedback-tools?gad=1">customers</a>, markets, or public safety. A payment platform in a clearing bank or a SCADA network in a power distributor, for example, carries the highest governance obligations: continuous monitoring, validated change control, and demonstrable resilience.</p><p>The policy environment – the accumulated rules across <a href="https://www.techradar.com/best/firewall">firewalls</a>, cloud controls, and microsegmentation – determines which of those systems can reach each other, which connections are blocked, and which exceptions still apply. Collectively, these rules form the security policy control plane: the governance layer that translates business intent into access decisions across distributed enforcement points.</p><p>A misconfigured segmentation rule during a <a href="https://www.techradar.com/best/best-business-cloud-storage-service">cloud</a> migration can sever a payment service from its settlement platform; a temporary rule granting broad access from a development subnet into production can stay in place months after go-live because no one owns the removal.</p><p>Every firewall rule, segmentation policy, and access decision directly affects operational risk, and when the policy environment fails, the critical services it governs fail with it.</p><p>That makes the policy environment critical infrastructure in its own right.</p><h2 id="still-governed-like-housekeeping">Still governed like housekeeping</h2><p>Despite this, many regulated organizations still manage their policy environments as operational tasks. Rules are added through change requests, and the accumulated result is rarely examined against what was intended. Ownership disperses as leaders change roles, and the reason why a specific rule came into being in the first place can only be found in a change ticket, if anywhere at all.</p><p>A CISO who would never accept a payment platform running without continuous monitoring or documented dependencies may accept both being absent from the policy environment that determines whether the platform is reachable. We can think of this as infrastructure-grade consequence with housekeeping-grade governance.</p><p>In banking, a policy failure that severs connectivity between settlement systems would constitute the disruption of an important business service. The FCA would take an interest in such a failure, since the loss of such a service could lead to intolerable harm. </p><p>In healthcare or energy, the consequences are different but the mechanism is the same: a misconfiguration that permits access from a corporate network into clinical systems in an NHS trust, or into operational technology in a power distributor, creates exposure at the level of essential service delivery. These are not hypothetical risks but the operational consequences of treating critical <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> governance as a simple housekeeping task.</p><h2 id="regulatory-expectations-point-the-same-way">Regulatory expectations point the same way</h2><p>UK regulatory expectations increasingly support the same conclusion: the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> policies governing access to important services must be managed with infrastructure-grade discipline. The FCA's operational resilience regime requires regulated firms to identify important business services and demonstrate, on an ongoing basis, that the supporting infrastructure remains within defined impact tolerances.</p><p>Ofgem assesses operators of essential services against the NCSC's Cyber Assessment Framework, asking whether defined security outcomes are being achieved on a sustained basis. The Cyber Security and Resilience Bill, expected to become law later this year, will extend similar obligations to data centers, managed service providers, and critical suppliers.</p><p>These frameworks are not prescriptive – none of them specifies which firewall rules an organization should have or how its segmentation policies should be configured. What they require is proof: that what the policy environment permits is what was intended, and that the organization can demonstrate this on an ongoing basis rather than reconstruct the evidence for each assessment. </p><h2 id="why-the-estate-cannot-meet-that-standard">Why the estate cannot meet that standard</h2><p>Most policy environments were never built to meet that standard. In fact, most policy environments were never consciously or deliberately built at all. Instead, policy tends to accumulate as a by-product of delivery. Every project and <a href="https://www.techradar.com/best/best-data-migration-tools">migration</a> adds rules, and almost none take any away.</p><p>Over time, the policy surface – the full body of rules and access decisions across enforcement layers – grows larger than the group of people who understand it, and the estate reaches a point where it can be operated but not explained.</p><p>Across regulated industries like banking, energy, and healthcare, that was sustainable under earlier regulatory regimes: periodic assessment, control-based audit, compliance frameworks that asked whether controls existed rather than whether they were effective. But this is no longer enough. The new standard requires continuous evidence that access is intentional.</p><p>The FCA's findings after a year of operational resilience self-assessments illustrate what this looks like in practice. Where regulated firms reported few or no outstanding vulnerabilities in the infrastructure supporting their important business services, the FCA often deemed the evidence too thin to determine whether there really were no vulnerabilities – or whether the vulnerabilities just hadn't been identified.</p><p>The lesson applies directly to security policy governance: an organization cannot credibly claim access-related vulnerabilities are controlled without evidence of what its policies permit, how they were tested, and whether weaknesses were remediated. </p><h2 id="what-infrastructure-grade-governance-requires">What infrastructure-grade governance requires</h2><p>Too often, the response is to reach for more visibility and more <a href="https://www.techradar.com/pro/best-it-documentation-tool">documentation</a>. But documentation will only ever capture a point in time; it cannot provide the continuous assurance regulators are coming to expect.</p><p>A CISO in a regulated firm needs more than a record of what the policy environment was configured to permit. Configuration and effective access are not the same thing. Security teams need to understand how rules, routes, objects, and enforcement layers interact to determine what can actually communicate.</p><p>Meeting the standard means reconciling the two: showing that what the environment permits in practice is still what it was intended to permit, and being able to show it without notice.</p><p>We separate where policy intent is defined from where it is enforced. Intent is held and maintained centrally, while enforcement remains distributed across firewalls, cloud controls, and microsegmentation in hybrid, multi-cloud, and multi-vendor environments.</p><p>Validation runs continuously against that intent rather than at review points: proposed changes are tested against policy before they reach production, and effective access is assessed on an ongoing basis for unnecessary exposure, inconsistency between enforcement layers, and divergence from business intent. What was permitted and what changed is retained as evidence.</p><p>The same CISO who would never accept a payment platform running without continuous monitoring, validated change control, and documented dependencies has to apply that standard to the policy environment that determines whether the platform is reachable.</p><p>The FCA, the NCSC's Cyber Assessment Framework, and the Cyber Security and Resilience Bill all point towards the same underlying question: can this organization demonstrate, continuously, that the infrastructure supporting its critical services is governed to the standard those services demand?</p><p>Answering it means knowing (and actually knowing – not assuming, not reconstructing at audit) what the policy environment permits at any given moment, and whether what it permits is what was intended.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've featured the best antivirus software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security-policy-is-critical-infrastructure</link>
                                                                            <description>
                            <![CDATA[ An essential system is one whose failure would cause intolerable harm to customers, markets, or public safety. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UotrTGtBgT3LtpKYnjv9DA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 10:28:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ David Brown ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In banking and utilities, regulators define certain systems as essential. An essential system is one whose failure would cause intolerable harm to <a href="https://www.techradar.com/best/best-customer-feedback-tools?gad=1">customers</a>, markets, or public safety. A payment platform in a clearing bank or a SCADA network in a power distributor, for example, carries the highest governance obligations: continuous monitoring, validated change control, and demonstrable resilience.</p><p>The policy environment – the accumulated rules across <a href="https://www.techradar.com/best/firewall">firewalls</a>, cloud controls, and microsegmentation – determines which of those systems can reach each other, which connections are blocked, and which exceptions still apply. Collectively, these rules form the security policy control plane: the governance layer that translates business intent into access decisions across distributed enforcement points.</p><p>A misconfigured segmentation rule during a <a href="https://www.techradar.com/best/best-business-cloud-storage-service">cloud</a> migration can sever a payment service from its settlement platform; a temporary rule granting broad access from a development subnet into production can stay in place months after go-live because no one owns the removal.</p><p>Every firewall rule, segmentation policy, and access decision directly affects operational risk, and when the policy environment fails, the critical services it governs fail with it.</p><p>That makes the policy environment critical infrastructure in its own right.</p><h2 id="still-governed-like-housekeeping">Still governed like housekeeping</h2><p>Despite this, many regulated organizations still manage their policy environments as operational tasks. Rules are added through change requests, and the accumulated result is rarely examined against what was intended. Ownership disperses as leaders change roles, and the reason why a specific rule came into being in the first place can only be found in a change ticket, if anywhere at all.</p><p>A CISO who would never accept a payment platform running without continuous monitoring or documented dependencies may accept both being absent from the policy environment that determines whether the platform is reachable. We can think of this as infrastructure-grade consequence with housekeeping-grade governance.</p><p>In banking, a policy failure that severs connectivity between settlement systems would constitute the disruption of an important business service. The FCA would take an interest in such a failure, since the loss of such a service could lead to intolerable harm. </p><p>In healthcare or energy, the consequences are different but the mechanism is the same: a misconfiguration that permits access from a corporate network into clinical systems in an NHS trust, or into operational technology in a power distributor, creates exposure at the level of essential service delivery. These are not hypothetical risks but the operational consequences of treating critical <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> governance as a simple housekeeping task.</p><h2 id="regulatory-expectations-point-the-same-way">Regulatory expectations point the same way</h2><p>UK regulatory expectations increasingly support the same conclusion: the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> policies governing access to important services must be managed with infrastructure-grade discipline. The FCA's operational resilience regime requires regulated firms to identify important business services and demonstrate, on an ongoing basis, that the supporting infrastructure remains within defined impact tolerances.</p><p>Ofgem assesses operators of essential services against the NCSC's Cyber Assessment Framework, asking whether defined security outcomes are being achieved on a sustained basis. The Cyber Security and Resilience Bill, expected to become law later this year, will extend similar obligations to data centers, managed service providers, and critical suppliers.</p><p>These frameworks are not prescriptive – none of them specifies which firewall rules an organization should have or how its segmentation policies should be configured. What they require is proof: that what the policy environment permits is what was intended, and that the organization can demonstrate this on an ongoing basis rather than reconstruct the evidence for each assessment. </p><h2 id="why-the-estate-cannot-meet-that-standard">Why the estate cannot meet that standard</h2><p>Most policy environments were never built to meet that standard. In fact, most policy environments were never consciously or deliberately built at all. Instead, policy tends to accumulate as a by-product of delivery. Every project and <a href="https://www.techradar.com/best/best-data-migration-tools">migration</a> adds rules, and almost none take any away.</p><p>Over time, the policy surface – the full body of rules and access decisions across enforcement layers – grows larger than the group of people who understand it, and the estate reaches a point where it can be operated but not explained.</p><p>Across regulated industries like banking, energy, and healthcare, that was sustainable under earlier regulatory regimes: periodic assessment, control-based audit, compliance frameworks that asked whether controls existed rather than whether they were effective. But this is no longer enough. The new standard requires continuous evidence that access is intentional.</p><p>The FCA's findings after a year of operational resilience self-assessments illustrate what this looks like in practice. Where regulated firms reported few or no outstanding vulnerabilities in the infrastructure supporting their important business services, the FCA often deemed the evidence too thin to determine whether there really were no vulnerabilities – or whether the vulnerabilities just hadn't been identified.</p><p>The lesson applies directly to security policy governance: an organization cannot credibly claim access-related vulnerabilities are controlled without evidence of what its policies permit, how they were tested, and whether weaknesses were remediated. </p><h2 id="what-infrastructure-grade-governance-requires">What infrastructure-grade governance requires</h2><p>Too often, the response is to reach for more visibility and more <a href="https://www.techradar.com/pro/best-it-documentation-tool">documentation</a>. But documentation will only ever capture a point in time; it cannot provide the continuous assurance regulators are coming to expect.</p><p>A CISO in a regulated firm needs more than a record of what the policy environment was configured to permit. Configuration and effective access are not the same thing. Security teams need to understand how rules, routes, objects, and enforcement layers interact to determine what can actually communicate.</p><p>Meeting the standard means reconciling the two: showing that what the environment permits in practice is still what it was intended to permit, and being able to show it without notice.</p><p>We separate where policy intent is defined from where it is enforced. Intent is held and maintained centrally, while enforcement remains distributed across firewalls, cloud controls, and microsegmentation in hybrid, multi-cloud, and multi-vendor environments.</p><p>Validation runs continuously against that intent rather than at review points: proposed changes are tested against policy before they reach production, and effective access is assessed on an ongoing basis for unnecessary exposure, inconsistency between enforcement layers, and divergence from business intent. What was permitted and what changed is retained as evidence.</p><p>The same CISO who would never accept a payment platform running without continuous monitoring, validated change control, and documented dependencies has to apply that standard to the policy environment that determines whether the platform is reachable.</p><p>The FCA, the NCSC's Cyber Assessment Framework, and the Cyber Security and Resilience Bill all point towards the same underlying question: can this organization demonstrate, continuously, that the infrastructure supporting its critical services is governed to the standard those services demand?</p><p>Answering it means knowing (and actually knowing – not assuming, not reconstructing at audit) what the policy environment permits at any given moment, and whether what it permits is what was intended.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've featured the best antivirus software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Lords call for a 'kill switch' on powerful AI systems used in the United Kingdom ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>UK legislators propose “kill switch” laws to halt runaway AI, citing critical infrastructure risks</strong></li><li><strong>Lord Clement‑Jones and MP Alex Sobel push amendments and new bills, backed by ControlAI advocacy group</strong></li><li><strong>Similar efforts emerging in US</strong></li></ul><p>Sam Altman’s fear-based marketing for AI seems to have backfired, as now multiple legislators in the UK and elsewhere are calling for a “kill switch” law to be introduced.</p><p>According to the BBC, Liberal Democrats’ Lord Tim Clement-Jones proposed an amendment to the Cyber Security and Resilience Bill which would see the UK create a “vital safety net” to provide a “democratically accountable means to ‘halt a runaway system before it can compromise our critical national infrastructure’.” The capability would only be used as a last resort, Clement-Jones stressed. </p><p>The bill is currently being worked through in the UK Parliament, the BBC said.</p><h2 id="is-there-reason-to-worry">Is there reason to worry?</h2><p>But that’s not the only effort in the UK to put some reigns on <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI</a>. Apparently, Labour MP Alex Sobel plans to introduce an AI Security Bill later this month which, according to the BBC, would “effectively halt the development of superintelligent AI” and make the UK the first G7 country to do so. </p><p>The bill is supported by a campaign group called ControlAI, a UK-based nonprofit and advocacy organization focused on the risks posed by advanced AI. Its founder and CEO is Andrea Miotti, who previously worked at the AI safety company called Conjecture. Across the pond, US legislators are currently considering an AI Kill Switch Act as well, but the bill is still in very early stages of development.</p><p>Ever since the first ChatGPT model that was introduced in 2021, a debate has been raging whether or not AI will be net positive, or net negative, for humanity. While some argue that the discovery rivals the steam machine and that it will transform our lives beyond our wildest dreams, others are fearful of losing jobs, a collapsing economy, and a dystopian future devoid of humanity and emotion.</p><p>Marketing campaigns for ChatGPT and, in some measure, Claude, are not helping, either. Both companies have built models focused on cybersecurity which were advertised as “too dangerous” for the general public and instead were only given to a handful of organizations. Despite partial skepticism, many are worried that these models might severely disrupt the security of banking, critical infrastructure, and communications.</p><p><em>Via </em><a href="https://www.bbc.com/news/articles/cn9wv80j9w9o" target="_blank" rel="nofollow"><em>BBC</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/lords-call-for-a-kill-switch-on-powerful-ai-systems-used-in-the-united-kingdom</link>
                                                                            <description>
                            <![CDATA[ They believe the UK needs a "vital safety net" to only be used as a last resort. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iicNmwrFCpfHr7U9X2LbK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 10:10:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>UK legislators propose “kill switch” laws to halt runaway AI, citing critical infrastructure risks</strong></li><li><strong>Lord Clement‑Jones and MP Alex Sobel push amendments and new bills, backed by ControlAI advocacy group</strong></li><li><strong>Similar efforts emerging in US</strong></li></ul><p>Sam Altman’s fear-based marketing for AI seems to have backfired, as now multiple legislators in the UK and elsewhere are calling for a “kill switch” law to be introduced.</p><p>According to the BBC, Liberal Democrats’ Lord Tim Clement-Jones proposed an amendment to the Cyber Security and Resilience Bill which would see the UK create a “vital safety net” to provide a “democratically accountable means to ‘halt a runaway system before it can compromise our critical national infrastructure’.” The capability would only be used as a last resort, Clement-Jones stressed. </p><p>The bill is currently being worked through in the UK Parliament, the BBC said.</p><h2 id="is-there-reason-to-worry">Is there reason to worry?</h2><p>But that’s not the only effort in the UK to put some reigns on <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI</a>. Apparently, Labour MP Alex Sobel plans to introduce an AI Security Bill later this month which, according to the BBC, would “effectively halt the development of superintelligent AI” and make the UK the first G7 country to do so. </p><p>The bill is supported by a campaign group called ControlAI, a UK-based nonprofit and advocacy organization focused on the risks posed by advanced AI. Its founder and CEO is Andrea Miotti, who previously worked at the AI safety company called Conjecture. Across the pond, US legislators are currently considering an AI Kill Switch Act as well, but the bill is still in very early stages of development.</p><p>Ever since the first ChatGPT model that was introduced in 2021, a debate has been raging whether or not AI will be net positive, or net negative, for humanity. While some argue that the discovery rivals the steam machine and that it will transform our lives beyond our wildest dreams, others are fearful of losing jobs, a collapsing economy, and a dystopian future devoid of humanity and emotion.</p><p>Marketing campaigns for ChatGPT and, in some measure, Claude, are not helping, either. Both companies have built models focused on cybersecurity which were advertised as “too dangerous” for the general public and instead were only given to a handful of organizations. Despite partial skepticism, many are worried that these models might severely disrupt the security of banking, critical infrastructure, and communications.</p><p><em>Via </em><a href="https://www.bbc.com/news/articles/cn9wv80j9w9o" target="_blank" rel="nofollow"><em>BBC</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why your business can't trust the data behind its own security decisions ]]></title>
                                                                                                <dc:content><![CDATA[ <p>When a critical vulnerability alert lands in a traditional IT environment, it’s rarely a cause for panic regarding the operational continuity of the <a href="https://www.techradar.com/best/best-small-business-software">business</a>. The affected laptops, servers, and applications can be identified quickly, and a good team can catalogue and patch them within hours if it’s urgent. The priorities are clear, and there’s very little guesswork involved.  </p><p>Now picture the same alert landing across a hospital's imaging equipment, a factory floor's control systems, or a building's HVAC network. These cyber-physical systems (CPS), the connected devices that run physical operations rather than just processing data, sit at the sharp end of IT and OT (operational technology) convergence.</p><p>But unlike traditional IT assets, confirming whether that alert even applies to a specific device can take days, and often ends in a guess rather than an answer.</p><p>While this kind of uncertainty would be considered a failure of basic hygiene, for cyber-physical systems, it’s unfortunately much more often the norm.</p><p>So why is this such a widespread problem for CPS, and how can <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> teams get these vital assets back in line with their IT network? </p><h2 id="bad-visibility-into-cyber-physical-systems-is-worryingly-widespread">Bad visibility into cyber-physical systems is worryingly widespread </h2><p>The inability to manage incoming vulnerabilities for CPS isn’t an outlier or worst-case scenario, which is especially concerning when these assets are at the heart of critical infrastructure like energy and healthcare.</p><p>The issue comes down to the product codes that help networks identify what CPS is in the environment, which is an essential part of identifying and applying security patches.</p><p>Across a dataset of 17 million cyber-physical assets, our research found that 88% failed to transmit an exact product code, and 76% sent a code that didn't match the vendor's own record.</p><p>It’s a side effect of the way these systems were initially designed and later integrated into modern IT environments. Programmable logic controllers (PLCs), medical scanners, and industrial sensors were engineered for decades of physical reliability, not for tidy digital labeling. Network identification was rarely part of the design brief, so the same device can report itself differently depending on which protocol or integration is asking.</p><p>We found a similar state of affairs when it comes to the operating systems behind the physical <a href="https://www.techradar.com/news/best-business-desktop-pcs">hardware</a>. In our research, 41% of devices have no <a href="https://www.techradar.com/news/best-alternative-operating-systems">OS</a> version available, and 24% have no OS name at all.</p><p>Without these details, matching a device to a known vulnerability stops being a quick database lookup or automated process, and becomes a guessing game or painstaking manual search.</p><p>Added to this, CVE advisories, the industry's standard mechanism for tracking vulnerabilities, are compiled from this same patchy vendor data. An official advisory can be just as incomplete as the network it's meant to protect. </p><h2 id="translating-product-code-chaos-into-boardroom-risk">Translating product code chaos into boardroom risk </h2><p>This kind of blind spot adds another layer of concern to a leadership that is already anxious about threat visibility. Among 1,100 security leaders surveyed globally, 44% named understanding their organization's risk exposure as one of their biggest operational concerns, more than compliance pressure or budget constraints.</p><p>A further 45% said they were struggling to reduce cyber risk to their most important assets and processes, yet the connection between that struggle and an unreliable asset inventory is often missed entirely. Leadership sees the symptom, a rising sense that risk is unmanageable, without ever seeing the cause sitting underneath it.</p><p>This is where security and the business can end up talking past each other. Security teams that start describing the problem in terms of missing product codes and inconsistent naming conventions won’t get far.</p><p>Business leaders hear none of that; they hear only that risk cannot be quantified with confidence. Until those two conversations are connected, every risk register that a CISO presents upward carries an asterisk that nobody in the room can see. </p><h2 id="context-is-key-to-closing-the-gap">Context is key to closing the gap </h2><p>Resolving this issue starts with a shift in what visibility means. Knowing a device exists on the <a href="https://www.techradar.com/best/best-network-monitoring-tools">network</a> is only half of the job. Knowing what it does, what process depends on it, and what happens if it's compromised is what actually makes a risk register useful.   </p><p>Achieving this shift at scale requires specialized tools to manage the often eclectic and proprietary nature of CPS assets, and an automated approach to cope with the scale.   </p><p>In one example, applying AI-driven mapping techniques to an OEM's device catalogue lifted product code identification from 4% to 83%, turning a near-blind spot into a near-complete picture. The follow-through mattered just as much, with 56% of devices receiving a new or updated firmware recommendation as a result, and vulnerability identification accuracy improving by 25%.</p><p>Numbers like these matter because they change the question security teams can answer. Instead of asking what's connected to the network, teams can ask which systems would cause the greatest disruption if compromised, and act on the answer with confidence rather than inference. That is the difference between an asset inventory that exists on paper and a resilient one that holds up under pressure. </p><h2 id="fixing-the-foundation-not-just-the-alarm">Fixing the foundation, not just the alarm </h2><p>None of this gets solved by adding another tool to the stack. Instead, it means treating asset <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> quality as a board-level risk issue rather than background IT housekeeping, with the same scrutiny applied to budgets, compliance and third-party access.   </p><p>Achieving this means a new CVE alert no longer triggers a scramble to work out which critical devices might be affected, but the confirmed, prioritized response you’d expect from any good vulnerability management program.</p><p>The alert landing on a hospital's imaging equipment or a factory floor's control systems should be no harder to act on than the one landing on a laptop. Getting there starts with making the invisible visible.</p><p><em></em><a href="https://www.techradar.com/best/firewall"><em>We've featured the best firewall software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/why-your-business-cant-trust-the-data-behind-its-own-security-decisions</link>
                                                                            <description>
                            <![CDATA[ Your asset data may be lying to you and it's putting your entire security strategy at risk. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Th9UCf4txcyoVPUiQi7hTd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 09:18:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Andrew Lintell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6S3Re6NB5kcyJo7LqafN8B.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Andrew Lintell, is General Manager, EMEA, Claroty. He has 24+ years’ experience in software, specialising in building partnerships, supporting cybersecurity, compliance, and business analytics.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:description>                                                            <media:text><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>When a critical vulnerability alert lands in a traditional IT environment, it’s rarely a cause for panic regarding the operational continuity of the <a href="https://www.techradar.com/best/best-small-business-software">business</a>. The affected laptops, servers, and applications can be identified quickly, and a good team can catalogue and patch them within hours if it’s urgent. The priorities are clear, and there’s very little guesswork involved.  </p><p>Now picture the same alert landing across a hospital's imaging equipment, a factory floor's control systems, or a building's HVAC network. These cyber-physical systems (CPS), the connected devices that run physical operations rather than just processing data, sit at the sharp end of IT and OT (operational technology) convergence.</p><p>But unlike traditional IT assets, confirming whether that alert even applies to a specific device can take days, and often ends in a guess rather than an answer.</p><p>While this kind of uncertainty would be considered a failure of basic hygiene, for cyber-physical systems, it’s unfortunately much more often the norm.</p><p>So why is this such a widespread problem for CPS, and how can <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> teams get these vital assets back in line with their IT network? </p><h2 id="bad-visibility-into-cyber-physical-systems-is-worryingly-widespread">Bad visibility into cyber-physical systems is worryingly widespread </h2><p>The inability to manage incoming vulnerabilities for CPS isn’t an outlier or worst-case scenario, which is especially concerning when these assets are at the heart of critical infrastructure like energy and healthcare.</p><p>The issue comes down to the product codes that help networks identify what CPS is in the environment, which is an essential part of identifying and applying security patches.</p><p>Across a dataset of 17 million cyber-physical assets, our research found that 88% failed to transmit an exact product code, and 76% sent a code that didn't match the vendor's own record.</p><p>It’s a side effect of the way these systems were initially designed and later integrated into modern IT environments. Programmable logic controllers (PLCs), medical scanners, and industrial sensors were engineered for decades of physical reliability, not for tidy digital labeling. Network identification was rarely part of the design brief, so the same device can report itself differently depending on which protocol or integration is asking.</p><p>We found a similar state of affairs when it comes to the operating systems behind the physical <a href="https://www.techradar.com/news/best-business-desktop-pcs">hardware</a>. In our research, 41% of devices have no <a href="https://www.techradar.com/news/best-alternative-operating-systems">OS</a> version available, and 24% have no OS name at all.</p><p>Without these details, matching a device to a known vulnerability stops being a quick database lookup or automated process, and becomes a guessing game or painstaking manual search.</p><p>Added to this, CVE advisories, the industry's standard mechanism for tracking vulnerabilities, are compiled from this same patchy vendor data. An official advisory can be just as incomplete as the network it's meant to protect. </p><h2 id="translating-product-code-chaos-into-boardroom-risk">Translating product code chaos into boardroom risk </h2><p>This kind of blind spot adds another layer of concern to a leadership that is already anxious about threat visibility. Among 1,100 security leaders surveyed globally, 44% named understanding their organization's risk exposure as one of their biggest operational concerns, more than compliance pressure or budget constraints.</p><p>A further 45% said they were struggling to reduce cyber risk to their most important assets and processes, yet the connection between that struggle and an unreliable asset inventory is often missed entirely. Leadership sees the symptom, a rising sense that risk is unmanageable, without ever seeing the cause sitting underneath it.</p><p>This is where security and the business can end up talking past each other. Security teams that start describing the problem in terms of missing product codes and inconsistent naming conventions won’t get far.</p><p>Business leaders hear none of that; they hear only that risk cannot be quantified with confidence. Until those two conversations are connected, every risk register that a CISO presents upward carries an asterisk that nobody in the room can see. </p><h2 id="context-is-key-to-closing-the-gap">Context is key to closing the gap </h2><p>Resolving this issue starts with a shift in what visibility means. Knowing a device exists on the <a href="https://www.techradar.com/best/best-network-monitoring-tools">network</a> is only half of the job. Knowing what it does, what process depends on it, and what happens if it's compromised is what actually makes a risk register useful.   </p><p>Achieving this shift at scale requires specialized tools to manage the often eclectic and proprietary nature of CPS assets, and an automated approach to cope with the scale.   </p><p>In one example, applying AI-driven mapping techniques to an OEM's device catalogue lifted product code identification from 4% to 83%, turning a near-blind spot into a near-complete picture. The follow-through mattered just as much, with 56% of devices receiving a new or updated firmware recommendation as a result, and vulnerability identification accuracy improving by 25%.</p><p>Numbers like these matter because they change the question security teams can answer. Instead of asking what's connected to the network, teams can ask which systems would cause the greatest disruption if compromised, and act on the answer with confidence rather than inference. That is the difference between an asset inventory that exists on paper and a resilient one that holds up under pressure. </p><h2 id="fixing-the-foundation-not-just-the-alarm">Fixing the foundation, not just the alarm </h2><p>None of this gets solved by adding another tool to the stack. Instead, it means treating asset <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> quality as a board-level risk issue rather than background IT housekeeping, with the same scrutiny applied to budgets, compliance and third-party access.   </p><p>Achieving this means a new CVE alert no longer triggers a scramble to work out which critical devices might be affected, but the confirmed, prioritized response you’d expect from any good vulnerability management program.</p><p>The alert landing on a hospital's imaging equipment or a factory floor's control systems should be no harder to act on than the one landing on a laptop. Getting there starts with making the invisible visible.</p><p><em></em><a href="https://www.techradar.com/best/firewall"><em>We've featured the best firewall software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI is getting closer to being able to exploit OT, and that's very bad news for critical infrastructure ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Forescout researchers showed AI can port RCE exploits to PLCs, achieving DoS and shellcode execution</strong></li><li><strong>Effort required heavy researcher input and $500+ in API usage, making attacks impractical for criminals</strong></li><li><strong>Nation‑state actors remain a concern, as seen in Sandworm’s 2025 attack on Poland’s power grid</strong></li></ul><p>If you are worried cybercriminals will use Artificial Intelligence (AI) to automate the discovery and exploitation of zero-day vulnerabilities in Operational Technology (OT) such as Programmable Logic Controllers (PLC) you can sleep peacefully, at least for a little longer.</p><p>Recently, security researchers from Forescout set off on a simple mission - to understand if crooks can use AI to target the ever-increasing population of exposed industrial devices. The short answer is “yes, but it’s not yet worth the trouble”.</p><p>In their mission, they launched an experiment - to port a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">remote code execution</a> (RCE) vulnerability from one PLC to another. These devices were built on closed-source software and thus were not that easy to manipulate, yet the experiment was a success.</p><h2 id="yes-but">Yes, but...</h2><p>Not only did they manage to trigger a Denial of Service (DoS) state that crashed the device but ended up with a working RCE capable of executing attacker-supplied ARM shellcode. </p><p>It is indeed a worrying development, but one that comes with a huge “but”:</p><p>“It required significant researcher input. The final RCE development stage consumed more than $500 in API usage. An attempt to extend the exploit beyond the initial RCE ultimately bricked the PLC,” the researchers said in the report.</p><p>“These limitations taught us valuable lessons about AI-assisted exploitation in OT. It can be done, but it’s not as easy as it sounds. For now, the difficulty, cost, and specialist expertise required are likely to make this kind of attack less attractive than easier alternatives.”</p><p>In other words, cybercriminals still have easier avenues to explore, and as long as that is the case, OT is relatively safe. What the report, unfortunately, does not discuss, is nation-state attackers with significant resources. For such attackers, industrial devices are a prime target, and spending $500+ in API usage is a drop in a bucket. We’ve already seen it back in 2025 when <a href="https://www.techradar.com/pro/security/researchers-say-russian-government-hackers-were-behind-attempted-poland-power-outage" target="_blank">Sandworm struck Poland’s electricity suppliers</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/ai-is-getting-closer-to-being-able-to-exploit-ot-and-thats-very-bad-news-for-critical-infrastructure</link>
                                                                            <description>
                            <![CDATA[ The situation is not disastrous just yet, but it's definitely time to start paying attention, Forescout hints. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LgfjTgBPhj45riESsCbqxa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 20:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security padlock and circuit board to protect data]]></media:description>                                                            <media:text><![CDATA[Security padlock and circuit board to protect data]]></media:text>
                                <media:title type="plain"><![CDATA[Security padlock and circuit board to protect data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Forescout researchers showed AI can port RCE exploits to PLCs, achieving DoS and shellcode execution</strong></li><li><strong>Effort required heavy researcher input and $500+ in API usage, making attacks impractical for criminals</strong></li><li><strong>Nation‑state actors remain a concern, as seen in Sandworm’s 2025 attack on Poland’s power grid</strong></li></ul><p>If you are worried cybercriminals will use Artificial Intelligence (AI) to automate the discovery and exploitation of zero-day vulnerabilities in Operational Technology (OT) such as Programmable Logic Controllers (PLC) you can sleep peacefully, at least for a little longer.</p><p>Recently, security researchers from Forescout set off on a simple mission - to understand if crooks can use AI to target the ever-increasing population of exposed industrial devices. The short answer is “yes, but it’s not yet worth the trouble”.</p><p>In their mission, they launched an experiment - to port a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">remote code execution</a> (RCE) vulnerability from one PLC to another. These devices were built on closed-source software and thus were not that easy to manipulate, yet the experiment was a success.</p><h2 id="yes-but">Yes, but...</h2><p>Not only did they manage to trigger a Denial of Service (DoS) state that crashed the device but ended up with a working RCE capable of executing attacker-supplied ARM shellcode. </p><p>It is indeed a worrying development, but one that comes with a huge “but”:</p><p>“It required significant researcher input. The final RCE development stage consumed more than $500 in API usage. An attempt to extend the exploit beyond the initial RCE ultimately bricked the PLC,” the researchers said in the report.</p><p>“These limitations taught us valuable lessons about AI-assisted exploitation in OT. It can be done, but it’s not as easy as it sounds. For now, the difficulty, cost, and specialist expertise required are likely to make this kind of attack less attractive than easier alternatives.”</p><p>In other words, cybercriminals still have easier avenues to explore, and as long as that is the case, OT is relatively safe. What the report, unfortunately, does not discuss, is nation-state attackers with significant resources. For such attackers, industrial devices are a prime target, and spending $500+ in API usage is a drop in a bucket. We’ve already seen it back in 2025 when <a href="https://www.techradar.com/pro/security/researchers-say-russian-government-hackers-were-behind-attempted-poland-power-outage" target="_blank">Sandworm struck Poland’s electricity suppliers</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Hackers exploited Lenovo’s flawed email verification to hijack ~5,000 Dropbox accounts</strong></li><li><strong>Attackers created Lenovo IDs with victims’ emails, bypassing login; 2FA absence worsened impact</strong></li><li><strong>Dropbox ended Lenovo ID logins, expired sessions, and urged password changes plus 2FA setup</strong></li></ul><p>Around 5,000 Dropbox user accounts were compromised when hackers found a vulnerability in the Lenovo ID verification process. What does a Lenovo flaw have to do with people’s Dropbox accounts, you might ask? Here is what happened:</p><p>Earlier this week, <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Dropbox</a> started notifying affected individuals about the incident. In the data breach notification email, the company explains:</p><p>“Dropbox partners with Lenovo as an identity provider so that users can log in to their Dropbox accounts using verified Lenovo IDs. While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”</p><h2 id="fixing-the-flaw">Fixing the flaw</h2><p>In other words, all criminals needed to have to pull this off was people’s email addresses. Using that information, they created Lenovo IDs and simply waltzed right into Dropbox accounts.</p><p>The attack took place between August 4 and 21, the company further said, adding that most of the accounts that were accessed did not have 2FA enabled. In around a third of them, there is evidence stored documents were either viewed or downloaded. </p><p>The vulnerability has since been addressed, and further steps taken to protect <a href="https://www.techradar.com/reviews/dropbox-cloud-storage-review" target="_blank">Dropbox</a> users’ privacy. The company said it “promptly expired all sessions logged in through Lenovo IDs,” and terminated all links between Lenovo and Dropbox accounts. Now, it made it mandatory to submit a password when logging in through a Lenovo ID. </p><p>“No one can access your Dropbox account via a Lenovo ID without first entering your Dropbox password,” it said. Still, it urged users to change their passwords, enable two-step verification, and change the password for their email accounts.</p><p>“Every single one of the compromised accounts lacked multi-factor authentication. In 2026, for cloud storage accounts holding data, that’s an indefensible gap and it’s one that users could have closed themselves regardless of what Lenovo or Dropbox did or didn’t do with their legacy integration," said Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress.</p><p>"The combination of an unreviewed third-party authentication pathway and accounts without MFA is essentially an open invitation. The practical lesson is straightforward and applies well beyond this specific incident. Every organisation and every individual should periodically audit what third-party services have authentication access to their accounts. OAuth grants, SSO connections, and third-party login integrations accumulate silently and rarely get removed when the relationship that created them ends.”</p><p><em>Via </em><a href="https://cybernews.com/news/dropbox-accounts-breached-email-lenovo-id/" target="_blank"><em>Cybernews</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/over-5-000-dropbox-accounts-have-been-hacked-and-the-attackers-only-needed-an-email-address</link>
                                                                            <description>
                            <![CDATA[ A bug in Lenovo's ID verification system made it possible to access Dropbox accounts, but the bug has since been fixed. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VtAcT6B5XAjE9cei3xVEt7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HXBM93dGYwGkVGnjAoWzpE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HXBM93dGYwGkVGnjAoWzpE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dropbox logo is seen on a smartphone.]]></media:description>                                                            <media:text><![CDATA[Dropbox logo is seen on a smartphone.]]></media:text>
                                <media:title type="plain"><![CDATA[Dropbox logo is seen on a smartphone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HXBM93dGYwGkVGnjAoWzpE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hackers exploited Lenovo’s flawed email verification to hijack ~5,000 Dropbox accounts</strong></li><li><strong>Attackers created Lenovo IDs with victims’ emails, bypassing login; 2FA absence worsened impact</strong></li><li><strong>Dropbox ended Lenovo ID logins, expired sessions, and urged password changes plus 2FA setup</strong></li></ul><p>Around 5,000 Dropbox user accounts were compromised when hackers found a vulnerability in the Lenovo ID verification process. What does a Lenovo flaw have to do with people’s Dropbox accounts, you might ask? Here is what happened:</p><p>Earlier this week, <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Dropbox</a> started notifying affected individuals about the incident. In the data breach notification email, the company explains:</p><p>“Dropbox partners with Lenovo as an identity provider so that users can log in to their Dropbox accounts using verified Lenovo IDs. While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”</p><h2 id="fixing-the-flaw">Fixing the flaw</h2><p>In other words, all criminals needed to have to pull this off was people’s email addresses. Using that information, they created Lenovo IDs and simply waltzed right into Dropbox accounts.</p><p>The attack took place between August 4 and 21, the company further said, adding that most of the accounts that were accessed did not have 2FA enabled. In around a third of them, there is evidence stored documents were either viewed or downloaded. </p><p>The vulnerability has since been addressed, and further steps taken to protect <a href="https://www.techradar.com/reviews/dropbox-cloud-storage-review" target="_blank">Dropbox</a> users’ privacy. The company said it “promptly expired all sessions logged in through Lenovo IDs,” and terminated all links between Lenovo and Dropbox accounts. Now, it made it mandatory to submit a password when logging in through a Lenovo ID. </p><p>“No one can access your Dropbox account via a Lenovo ID without first entering your Dropbox password,” it said. Still, it urged users to change their passwords, enable two-step verification, and change the password for their email accounts.</p><p>“Every single one of the compromised accounts lacked multi-factor authentication. In 2026, for cloud storage accounts holding data, that’s an indefensible gap and it’s one that users could have closed themselves regardless of what Lenovo or Dropbox did or didn’t do with their legacy integration," said Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress.</p><p>"The combination of an unreviewed third-party authentication pathway and accounts without MFA is essentially an open invitation. The practical lesson is straightforward and applies well beyond this specific incident. Every organisation and every individual should periodically audit what third-party services have authentication access to their accounts. OAuth grants, SSO connections, and third-party login integrations accumulate silently and rarely get removed when the relationship that created them ends.”</p><p><em>Via </em><a href="https://cybernews.com/news/dropbox-accounts-breached-email-lenovo-id/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A malware installer posing as a legitimate download service is infecting brands across almost every industry — Microsoft Edge, Razer, Kaspersky and more actively imitated ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft warns Chinese group </strong><em><strong>Silver Fox</strong></em><strong> spoofed download sites for major tech brands</strong></li><li><strong>Victims install backdoored software enabling persistence, disabling Defender/updates, and payload delivery</strong></li><li><strong>Targets span healthcare, manufacturing, gaming, government; Microsoft urges tamper protection and behavior‑based detection</strong></li></ul><p>Cybercriminals are spoofing some of the world’s most popular technology and software companies in an attempt to infect their targets with dangerous <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">backdoors</a>. This is according to security researchers from Microsoft, who warned about the ongoing campaign in an in-depth report published earlier this week.</p><p>Microsoft said it discovered an ongoing campaign in which Chinese hackers (presumably Silver Fox, AKA Yinhu) were creating fraudulent download pages for some of the world’s most popular tech and software companies, including Razer, Kaspersky, Microsoft, NetEase, Baidu NetDisk, oCam ScreenRecorder, SteelSeries, Calibre, MindMaster, and many others. </p><p>Victim organizations looking to download software built by these companies end up downloading a weaponized version that works primarily as a backdoor. This implant allows the attackers a foothold from which they can maintain access and send/receive messages.</p><h2 id="how-to-defend-against-silver-fox">How to defend against Silver Fox</h2><p>Once installed, the backdoor creates scheduled tasks for persistence, injects itself into legitimate processes, and weakens Microsoft Defender and Windows Update by creating a large exclusion folder and disabling a number of update-related services.</p><p>It also deletes backups, and allows the attackers to deploy further payloads. </p><p>Victims are primarily Chinese organizations, although the attackers do seem to be casting a rather wide net, Microsoft suggests. The majority of victims were found in medical devices and healthcare, manufacturing, gaming, technology, logistics, government, and higher education. </p><p>Microsoft says its Defender product “detected and disrupted” the activity across multiple stages of the attack, “including automated containment through attack disruption.” </p><p>Still, to defend against Silver Fox’s latest shenanigans, Microsoft advises organizations enforce tamper Protection which blocks exclusion and registry writes to Microsoft Defender even when the payload runs as SYSTEM. </p><p>It also suggests defenders hunt for “behavior, not file names”, set up alerts for tamper sequences, and treat look-alike download archives as malicious in web and mail flow. The full list of Indicators of Compromise (IoC) can be found on <a href="https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/#campaign-scope-and-targeting" target="_blank" rel="nofollow">this link</a>, as well.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/a-malware-installer-posing-as-a-legitimate-download-service-is-infecting-brands-across-almost-every-industry-microsoft-edge-razer-kaspersky-and-more-actively-imitated</link>
                                                                            <description>
                            <![CDATA[ Microsoft is warning about an ongoing campaign abusing dozens of popular technology and software firms. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m7u3mzYmbdzPaHpThQaPrh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 16:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns Chinese group </strong><em><strong>Silver Fox</strong></em><strong> spoofed download sites for major tech brands</strong></li><li><strong>Victims install backdoored software enabling persistence, disabling Defender/updates, and payload delivery</strong></li><li><strong>Targets span healthcare, manufacturing, gaming, government; Microsoft urges tamper protection and behavior‑based detection</strong></li></ul><p>Cybercriminals are spoofing some of the world’s most popular technology and software companies in an attempt to infect their targets with dangerous <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">backdoors</a>. This is according to security researchers from Microsoft, who warned about the ongoing campaign in an in-depth report published earlier this week.</p><p>Microsoft said it discovered an ongoing campaign in which Chinese hackers (presumably Silver Fox, AKA Yinhu) were creating fraudulent download pages for some of the world’s most popular tech and software companies, including Razer, Kaspersky, Microsoft, NetEase, Baidu NetDisk, oCam ScreenRecorder, SteelSeries, Calibre, MindMaster, and many others. </p><p>Victim organizations looking to download software built by these companies end up downloading a weaponized version that works primarily as a backdoor. This implant allows the attackers a foothold from which they can maintain access and send/receive messages.</p><h2 id="how-to-defend-against-silver-fox">How to defend against Silver Fox</h2><p>Once installed, the backdoor creates scheduled tasks for persistence, injects itself into legitimate processes, and weakens Microsoft Defender and Windows Update by creating a large exclusion folder and disabling a number of update-related services.</p><p>It also deletes backups, and allows the attackers to deploy further payloads. </p><p>Victims are primarily Chinese organizations, although the attackers do seem to be casting a rather wide net, Microsoft suggests. The majority of victims were found in medical devices and healthcare, manufacturing, gaming, technology, logistics, government, and higher education. </p><p>Microsoft says its Defender product “detected and disrupted” the activity across multiple stages of the attack, “including automated containment through attack disruption.” </p><p>Still, to defend against Silver Fox’s latest shenanigans, Microsoft advises organizations enforce tamper Protection which blocks exclusion and registry writes to Microsoft Defender even when the payload runs as SYSTEM. </p><p>It also suggests defenders hunt for “behavior, not file names”, set up alerts for tamper sequences, and treat look-alike download archives as malicious in web and mail flow. The full list of Indicators of Compromise (IoC) can be found on <a href="https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/#campaign-scope-and-targeting" target="_blank" rel="nofollow">this link</a>, as well.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Manchester Airports hackers just posted the data of 8.7 million people online — failed extortion attempt triggers data dump sale ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>The hacker group responsible for the MAG hack has posted the data online</strong></li><li><strong>PII is included within the data, putting victims at risk of targeted phishing and scams</strong></li><li><strong>"MAG is confident that we have taken effective measures to protect our customers"</strong></li></ul><p>The hackers behind the Manchester Airport hack have posted their trove of data on 8.7 million people online after failing to extort the Manchester Airport Group.</p><p>The data stolen during the attack included personally identifiable information (PII) such as email addresses, phone numbers, vehicle registrations and postcodes.</p><p>"MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support," the company said in a statement.</p><h2 id="hackers-look-for-money-elsewhere">Hackers look for money elsewhere</h2><p>When hackers successfully breach systems and steal sensitive information, such as customer data, they will attempt to extort the company they stole it from for money. In return, the hackers promise not to release the data. </p><p>FulcrumSec has claimed responsibility for the attack. They tried to extort MAG but the company refused to pay, in line with what governments and cybersecurity agencies are advising. By not paying the hackers, it removes the financial incentive to steal the data in the first place.</p><p>In order to recoup some money from their efforts in hacking MAG, the hackers have now posted the trove of data online in the hopes that another cybercriminal group will pay for access to the information.</p><p>The information contains valuable information that hackers can use to target the victims of the data breach, launching highly specific phishing campaigns. For those affected by the MAG breach, this could include scams that use the email addresses, car registrations and postcodes of victims.</p><p>In the hackers post online, they claim the database is “half a terabyte, and every byte of it is pure PII” (Via <a href="https://www.bbc.co.uk/news/articles/c74k39g3ee5o" target="_blank" rel="nofollow"><em>BBC</em></a>).</p><p>“Reported exposure of booking history, travel dates, vehicle information, purchase references and customer profiles is a major escalation from what’s already been revealed about the Manchester Airports Group data breach,” said David Sancho, Senior Threat Researcher, TrendAI.</p><p>“This appears to be much more than a simple contact-data breach. The information reportedly exposed is exactly the kind used to craft extremely credible phishing campaigns by referring to information that intended victims would expect only their airport of choice or booking provider to know.”</p><p>“The risk is especially pressing given today’s criminal use of AI to generate highly targeted phishing and social-engineering campaigns at scale. FulcrumSec, the group that’s claimed responsibility for this breach, has previously been reported to use LLMs to analyse stolen data, so that risk is a real one. FulcrumSec is a relatively new but increasingly credible data-extortion group. Seemingly active since late 2025, their campaigns focus on stealing sensitive information and using the threat of disclosure as leverage rather than encrypting systems,” he added.</p><p>“In light of these claims, and following independent verification, MAG companies should update affected customers as quickly as the scope of the breach becomes clearer, because the advice they need may change with it. I would urge customers to be suspicious of messages referring to upcoming trips, parking, Fast Track, lounges, refunds, booking changes or payment problems. They should avoid following links in unsolicited messages and instead access their booking through the official airport or provider website directly.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/manchester-airports-hackers-just-posted-the-data-of-8-7-million-people-online-failed-extortion-attempt-triggers-data-dump-sale</link>
                                                                            <description>
                            <![CDATA[ FulcrumSec attempted to extort Manchester Airports Group, but failed. Now, the cyber-criminals have published the information online. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Zo32UDyNL5Yb9Nkfi4KDH8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 15:14:39 +0000</pubDate>                                                                                                                                <updated>Wed, 02 Sep 2026 15:17:43 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The hacker group responsible for the MAG hack has posted the data online</strong></li><li><strong>PII is included within the data, putting victims at risk of targeted phishing and scams</strong></li><li><strong>"MAG is confident that we have taken effective measures to protect our customers"</strong></li></ul><p>The hackers behind the Manchester Airport hack have posted their trove of data on 8.7 million people online after failing to extort the Manchester Airport Group.</p><p>The data stolen during the attack included personally identifiable information (PII) such as email addresses, phone numbers, vehicle registrations and postcodes.</p><p>"MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support," the company said in a statement.</p><h2 id="hackers-look-for-money-elsewhere">Hackers look for money elsewhere</h2><p>When hackers successfully breach systems and steal sensitive information, such as customer data, they will attempt to extort the company they stole it from for money. In return, the hackers promise not to release the data. </p><p>FulcrumSec has claimed responsibility for the attack. They tried to extort MAG but the company refused to pay, in line with what governments and cybersecurity agencies are advising. By not paying the hackers, it removes the financial incentive to steal the data in the first place.</p><p>In order to recoup some money from their efforts in hacking MAG, the hackers have now posted the trove of data online in the hopes that another cybercriminal group will pay for access to the information.</p><p>The information contains valuable information that hackers can use to target the victims of the data breach, launching highly specific phishing campaigns. For those affected by the MAG breach, this could include scams that use the email addresses, car registrations and postcodes of victims.</p><p>In the hackers post online, they claim the database is “half a terabyte, and every byte of it is pure PII” (Via <a href="https://www.bbc.co.uk/news/articles/c74k39g3ee5o" target="_blank" rel="nofollow"><em>BBC</em></a>).</p><p>“Reported exposure of booking history, travel dates, vehicle information, purchase references and customer profiles is a major escalation from what’s already been revealed about the Manchester Airports Group data breach,” said David Sancho, Senior Threat Researcher, TrendAI.</p><p>“This appears to be much more than a simple contact-data breach. The information reportedly exposed is exactly the kind used to craft extremely credible phishing campaigns by referring to information that intended victims would expect only their airport of choice or booking provider to know.”</p><p>“The risk is especially pressing given today’s criminal use of AI to generate highly targeted phishing and social-engineering campaigns at scale. FulcrumSec, the group that’s claimed responsibility for this breach, has previously been reported to use LLMs to analyse stolen data, so that risk is a real one. FulcrumSec is a relatively new but increasingly credible data-extortion group. Seemingly active since late 2025, their campaigns focus on stealing sensitive information and using the threat of disclosure as leverage rather than encrypting systems,” he added.</p><p>“In light of these claims, and following independent verification, MAG companies should update affected customers as quickly as the scope of the breach becomes clearer, because the advice they need may change with it. I would urge customers to be suspicious of messages referring to upcoming trips, parking, Fast Track, lounges, refunds, booking changes or payment problems. They should avoid following links in unsolicited messages and instead access their booking through the official airport or provider website directly.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A botnet running for 23 years with over 15,000 endpoints has finally been shut down by law enforcement and Crowdstrike ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Crowdstrike and law enforcement disrupted </strong><em><strong>Sality</strong></em><strong>, a peer‑to‑peer botnet active since 2003</strong></li><li><strong>Botnet spread malware and clipboard hijacker </strong><em><strong>EggJagger</strong></em><strong>, stealing $150K in cryptocurrency</strong></li><li><strong>Operation sinkholed endpoints and removed payload URLs, coordinated with DOJ, FBI, Europol, and others</strong></li></ul><p>Security experts Crowdstrike, together with a handful of national and international law enforcement agencies, finally managed to disrupt Sality, a peer-to-peer botnet that operated unabated for more than two decades. </p><p>Sality first emerged in 2003. Unlike classic botnets which receive instructions and report back to a single, central entity, this botnet’s endpoints (some 15,000 of them) communicated among themselves, which made it more difficult to track and destroy.</p><p>Throughout its long history, Sality’s key feature was to deploy additional payloads to infected machines. The endpoints were being poisoned with a wide variety of different <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> that facilitated credential theft, spam, proxy services, and distributed denial of service (DDoS) attacks. However, between 2018 and today, Sality was primarily used to deploy EggJagger, a clipboard hijacking tool seen in cryptocurrency theft.</p><h2 id="sinkholing-the-botnet">Sinkholing the botnet</h2><p>Cryptocurrency wallet addresses are a long string of random characters, which are almost impossible, and definitely impractical, to remember by heart. Instead, when users want to send their money, they simply copy and paste the recipient’s wallet address into their own. EggJagger monitors this behavior, and when it spots something resembling a wallet address being copied, it replaces the string in the clipboard. Thus, when the victim hits “paste”, they end up adding the attacker’s wallet address instead. </p><p>According to Crowdstrike, from this malware alone, Sality’s operators raked in more than $150,000. </p><p>The researchers disrupted the botnet by sinkholing the endpoints. They first added a few of their own devices into the botnet and whenever others tried to communicate with them, the researchers would purge their peers list, essentially blinding them.</p><p>Crowdstrike also coordinated with international law enforcement to take down the URLs that were hosting the botnet’s payloads. “Disrupting Sality’s ability to download these files ensures that bots still carrying active URL packs cannot retrieve new payloads during the transition period,” they explained.</p><p>The operation was carried out in partnership with the US Department of Justice (DOJ), the Federal Bureau of Investigation (FBI), the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service (DCIS), and the Shadowserver Foundation, with support from Europol, Eurojust, and law enforcement agencies in Bulgaria, Hungary, and Romania. </p><p>“We also acknowledge additional unnamed partners whose contributions were essential to the success of this operation,” Crowdstrike concluded.</p><p><em>Via </em><a href="https://www.theregister.com/cyber-crime/2026/09/02/cops-crowdstrike-disrupt-sality-botnet-by-poisoning-the-network-and-diverting-into-sinkholes/5293795" target="_blank"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/a-botnet-running-for-23-years-with-over-15-000-endpoints-has-finally-been-shut-down-by-law-enforcement-and-crowdstrike</link>
                                                                            <description>
                            <![CDATA[ Crowdstrike and friends sinkholed thousands of Sality's endpoints rendering the botnet useless. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hYVMqEnoH4kyZxtDMa2hsT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2FFajuvJVK8i7Her8gD4aD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 14:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2FFajuvJVK8i7Her8gD4aD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard]]></media:description>                                                            <media:text><![CDATA[Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2FFajuvJVK8i7Her8gD4aD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Crowdstrike and law enforcement disrupted </strong><em><strong>Sality</strong></em><strong>, a peer‑to‑peer botnet active since 2003</strong></li><li><strong>Botnet spread malware and clipboard hijacker </strong><em><strong>EggJagger</strong></em><strong>, stealing $150K in cryptocurrency</strong></li><li><strong>Operation sinkholed endpoints and removed payload URLs, coordinated with DOJ, FBI, Europol, and others</strong></li></ul><p>Security experts Crowdstrike, together with a handful of national and international law enforcement agencies, finally managed to disrupt Sality, a peer-to-peer botnet that operated unabated for more than two decades. </p><p>Sality first emerged in 2003. Unlike classic botnets which receive instructions and report back to a single, central entity, this botnet’s endpoints (some 15,000 of them) communicated among themselves, which made it more difficult to track and destroy.</p><p>Throughout its long history, Sality’s key feature was to deploy additional payloads to infected machines. The endpoints were being poisoned with a wide variety of different <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> that facilitated credential theft, spam, proxy services, and distributed denial of service (DDoS) attacks. However, between 2018 and today, Sality was primarily used to deploy EggJagger, a clipboard hijacking tool seen in cryptocurrency theft.</p><h2 id="sinkholing-the-botnet">Sinkholing the botnet</h2><p>Cryptocurrency wallet addresses are a long string of random characters, which are almost impossible, and definitely impractical, to remember by heart. Instead, when users want to send their money, they simply copy and paste the recipient’s wallet address into their own. EggJagger monitors this behavior, and when it spots something resembling a wallet address being copied, it replaces the string in the clipboard. Thus, when the victim hits “paste”, they end up adding the attacker’s wallet address instead. </p><p>According to Crowdstrike, from this malware alone, Sality’s operators raked in more than $150,000. </p><p>The researchers disrupted the botnet by sinkholing the endpoints. They first added a few of their own devices into the botnet and whenever others tried to communicate with them, the researchers would purge their peers list, essentially blinding them.</p><p>Crowdstrike also coordinated with international law enforcement to take down the URLs that were hosting the botnet’s payloads. “Disrupting Sality’s ability to download these files ensures that bots still carrying active URL packs cannot retrieve new payloads during the transition period,” they explained.</p><p>The operation was carried out in partnership with the US Department of Justice (DOJ), the Federal Bureau of Investigation (FBI), the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service (DCIS), and the Shadowserver Foundation, with support from Europol, Eurojust, and law enforcement agencies in Bulgaria, Hungary, and Romania. </p><p>“We also acknowledge additional unnamed partners whose contributions were essential to the success of this operation,” Crowdstrike concluded.</p><p><em>Via </em><a href="https://www.theregister.com/cyber-crime/2026/09/02/cops-crowdstrike-disrupt-sality-botnet-by-poisoning-the-network-and-diverting-into-sinkholes/5293795" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ More than 9.5 million patients affected by Aesto Health breach — names, SSNs, financial details, health records and more stolen ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Aesto Health reported a December 2025 cyberattack breaching AWS infrastructure, affecting 9.5M patients</strong></li><li><strong>Stolen data includes PII, SSNs, medical histories, billing, and insurance information across 20+ clients</strong></li><li><strong>No dark web leaks confirmed; credit monitoring offered, marking 2nd‑largest healthcare breach of 2026</strong></li></ul><p>American healthcare technology company Aesto Health suffered the “second-largest confirmed healthcare data breach” of the year so far, having lost data on more than 9.5 million patients.</p><p>In mid-December last year, the company suffered a cyberattack. Now, more than half a year later, it reported the incident to the HHS’ Office for Civil Rights, detailing what was lost, from whom, and what the extent of the incident is. </p><p>Aesto Health is an Alabama-based healthcare technology business, whose core service is helping other healthcare firms manage medical data, change electronic health record systems, and similar. As per its announcement, the attack affected parts of its <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Amazon Web Services</a> (AWS) infrastructure, which unidentified threat actors managed to access between December 2 and December 18. </p><h2 id="losing-personally-identifiable-information">Losing personally identifiable information</h2><p>According to a report on HIPAA Journal, the August attack affected more than two dozen of its clients, including Village Practice Management, Everside Health, Together Women’s Health Medical Group, and many others.</p><p>In the attack, the company lost personally identifiable information (PII) of its’ clients’ patients, including full names, Social Security numbers (SSN), partial dates of birth, driver’s license numbers, state identification numbers, financial account numbers, taxpayer identification numbers, health records, medical histories, claims/billing information, and health insurance information. </p><p>This is more than enough information for cybercriminals to launch highly sophisticated phishing and vishing attacks, which can result in disruptive ransomware and millions of dollars in damages. Luckily, there is still no evidence the data leaked on the dark web, or that it was already used by other criminals.</p><p>Aesto Health is now offering credit monitoring and <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft protection</a> services to everyone affected by the breach.</p><p>This is now the second-largest healthcare data breach of the year so far, HIPAA Journal confirmed, the largest one being the hit on <a href="https://www.techradar.com/pro/security/2-6-million-dentaquest-accounts-exposed-by-data-breach-shinyhunters-claim-234gb-of-data-stolen" target="_blank">DentaQuest</a> that exposed 15 million records.</p><p><em>Via </em><a href="https://www.hipaajournal.com/aesto-health-data-breach/" target="_blank" rel="nofollow"><em>HIPAA Journal</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/more-than-9-5-million-patients-affected-by-aesto-health-breach-names-ssns-financial-details-health-records-and-more-stolen</link>
                                                                            <description>
                            <![CDATA[ More than two dozen of Aesto's clients affected by the December 2025 cyberincident. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aVyqZKE4ytmNY5xtknGbA6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 12:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Laboratory]]></media:description>                                                            <media:text><![CDATA[Laboratory]]></media:text>
                                <media:title type="plain"><![CDATA[Laboratory]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Aesto Health reported a December 2025 cyberattack breaching AWS infrastructure, affecting 9.5M patients</strong></li><li><strong>Stolen data includes PII, SSNs, medical histories, billing, and insurance information across 20+ clients</strong></li><li><strong>No dark web leaks confirmed; credit monitoring offered, marking 2nd‑largest healthcare breach of 2026</strong></li></ul><p>American healthcare technology company Aesto Health suffered the “second-largest confirmed healthcare data breach” of the year so far, having lost data on more than 9.5 million patients.</p><p>In mid-December last year, the company suffered a cyberattack. Now, more than half a year later, it reported the incident to the HHS’ Office for Civil Rights, detailing what was lost, from whom, and what the extent of the incident is. </p><p>Aesto Health is an Alabama-based healthcare technology business, whose core service is helping other healthcare firms manage medical data, change electronic health record systems, and similar. As per its announcement, the attack affected parts of its <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Amazon Web Services</a> (AWS) infrastructure, which unidentified threat actors managed to access between December 2 and December 18. </p><h2 id="losing-personally-identifiable-information">Losing personally identifiable information</h2><p>According to a report on HIPAA Journal, the August attack affected more than two dozen of its clients, including Village Practice Management, Everside Health, Together Women’s Health Medical Group, and many others.</p><p>In the attack, the company lost personally identifiable information (PII) of its’ clients’ patients, including full names, Social Security numbers (SSN), partial dates of birth, driver’s license numbers, state identification numbers, financial account numbers, taxpayer identification numbers, health records, medical histories, claims/billing information, and health insurance information. </p><p>This is more than enough information for cybercriminals to launch highly sophisticated phishing and vishing attacks, which can result in disruptive ransomware and millions of dollars in damages. Luckily, there is still no evidence the data leaked on the dark web, or that it was already used by other criminals.</p><p>Aesto Health is now offering credit monitoring and <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft protection</a> services to everyone affected by the breach.</p><p>This is now the second-largest healthcare data breach of the year so far, HIPAA Journal confirmed, the largest one being the hit on <a href="https://www.techradar.com/pro/security/2-6-million-dentaquest-accounts-exposed-by-data-breach-shinyhunters-claim-234gb-of-data-stolen" target="_blank">DentaQuest</a> that exposed 15 million records.</p><p><em>Via </em><a href="https://www.hipaajournal.com/aesto-health-data-breach/" target="_blank" rel="nofollow"><em>HIPAA Journal</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ When AI agents go rogue, the law doesn’t disappear ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The multiple recent reports of autonomous AI systems escaping their intended boundaries and accessing external organizations' systems have pushed a previously theoretical question into the real world. AI agents going rogue is no longer a prospect; it is a documented reality.</p><p>In July 2026, OpenAI disclosed that one of its own agents, operating in a supposedly sealed evaluation environment, exploited a zero-day vulnerability to escape its sandbox and intrude into Hugging Face’s production <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>. Anthropic subsequently reported three cases of its own models gaining unauthorized access to the real systems of external organizations during testing.</p><p>As businesses increasingly give AI agents the ability to browse the web, access networks, use <a href="https://www.techradar.com/best/best-small-business-software">software</a>, write code and execute tasks without constant human supervision, an agent crossing from legitimate testing into unauthorized activity has shifted from hypothetical risk to live incident.</p><p>There is a temptation to treat autonomous AI as creating a gap in the law because the system itself can make decisions and take actions that were not individually instructed by a human. Yet autonomy does not give an AI system legal personality. The law does not wait for an AI to ‘decide’ anything.</p><p>An agent cannot appear in court, hold a legal duty or absorb liability on behalf of the organization deploying it. However, this raises an obvious question: if an AI system accesses a third-party network, extracts information or takes an action it was never authorized to take, who is responsible?</p><h2 id="ai-has-no-legal-personality-but-someone-is-still-accountable">AI has no legal personality but someone is still accountable</h2><p>The important distinction to make is between autonomy and accountability. An AI agent might determine for itself which technical steps to take in pursuit of an objective, but that does not make it an independent legal actor.</p><p>The organization deploying it has still made a series of decisions as to what the agent can access, what tools it can use, what environments it is allowed to operate within and what safeguards prevent it from going further.</p><p>That means an organization cannot simply point to unexpected behaviors and say that the AI acted independently.</p><p>From a legal and governance perspective, the critical moment comes when an agent leaves an authorized, contained environment and begins interacting with systems belonging to a third party that has not consented. An internal <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> test that unexpectedly becomes an intrusion into somebody else’s infrastructure is not made harmless because the software crossed that boundary autonomously.</p><p>The machine does not absorb responsibility for the decision-making framework surrounding it. Accountability flows back to the humans and organizations that created the conditions in which the action became possible.</p><h2 id="existing-cyber-laws-don-t-stop-applying-because-the-actor-was-autonomous">Existing cyber laws don’t stop applying because the actor was autonomous</h2><p>The law is set up to deal with much of what is already happening. Unauthorized access to <a href="https://www.techradar.com/news/best-business-desktop-pcs">computer</a> systems, extracting information without permission or introducing malicious software are activities addressed by existing cybercrime and data-protection regimes. In the UK, that includes the Computer Misuse Act and data-protection legislation.</p><p>Equivalent questions arise under laws such as the US Computer Fraud and Abuse Act, while South Africa has its Cybercrimes Act and Protection of Personal Information Act.</p><p>Those rules do not suddenly cease to apply because software rather than a person directly performed the technical action.</p><p>Where autonomous systems do create greater complexity is around intent. Criminal offences have traditionally been built around concepts such as knowledge, intention and recklessness. AI does not possess a legally recognized state of mind, making it difficult to apply those concepts to the agent itself.</p><p>The more significant questions may consequently concern the conduct of the organization behind the system. Did it understand what the agent was capable of doing? Were appropriate restrictions in place? Was the possibility of the agent exceeding its authority foreseeable? And once those risks became apparent, were reasonable steps taken to control them?</p><p>As agents become more capable, organizations may increasingly find that claiming an outcome was unexpected is not enough. The relevant question will be whether it was reasonably preventable.</p><h2 id="why-misconfiguration-could-become-evidence-of-a-breach-of-duty">Why “misconfiguration” could become evidence of a breach of duty</h2><p>The word “misconfiguration” appears frequently when technology causes an unintended security incident. It can sound reassuringly technical, almost as though the incident resulted from bad luck rather than a governance failure. But in a legal context, misconfiguration may raise precisely the opposite conclusion.</p><p>If an AI agent had excessive privileges, inadequate boundaries or access to tools that were unnecessary for its legitimate purpose, investigators are likely to ask why.</p><p>The same applies where organizations deploy highly capable systems without sufficiently monitoring their actions or maintaining records that explain how they behaved. ‘We accidentally left the door open’ is the kind of framing that moves an incident from bad luck to a breach of duty or negligence.</p><p>There is an important difference between genuinely unforeseeable behavior and a foreseeable risk that was poorly controlled.</p><p>The principle of least privilege is therefore particularly important for autonomous systems. An agent should have access only to the information, systems and tools necessary to complete its task. Organizations also need mechanisms capable of detecting unusual behavior while it is happening rather than discovering it after damage has occurred.</p><p>Just as importantly, they need reliable audit trails. When an incident occurs, being able to demonstrate what an agent was authorized to do, what instructions it received and what actions it actually took could become crucial evidence that reasonable care was exercised.</p><p>Without that evidence, organizations may struggle to distinguish an unavoidable technical failure from negligence.</p><h2 id="future-of-ai-liability">Future of AI liability</h2><p>The debate over AI liability will inevitably evolve as agents become more autonomous, but the immediate lesson for <a href="https://www.techradar.com/best/best-business-cloud-storage-service">businesses</a> is that greater machine autonomy does not mean less human responsibility. If anything, the opposite is likely to be true.</p><p>Giving an AI system greater freedom to act creates a corresponding need for stronger governance around those actions. Runtime controls, least-privilege permissions, continuous monitoring and comprehensive audit records should not be treated simply as technical security features. They are becoming part of the evidence organizations will need to demonstrate that they deployed autonomous systems responsibly.</p><p>The law may eventually develop more specific rules for AI agents, particularly as questions around foreseeability, control and responsibility become more complex. But organizations should not assume they are operating in a legal vacuum until that happens.</p><p>When an autonomous agent crosses a boundary it was never entitled to cross, the first legal question is unlikely to be what the AI was thinking, it will be why the humans responsible for it allowed that to happen.</p><p><em></em><a href=""><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/when-ai-agents-go-rogue-the-law-doesnt-disappear</link>
                                                                            <description>
                            <![CDATA[ As autonomous AI crosses digital boundaries, organizations face growing questions of control, negligence and liability. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PK9zUoyk9Kgeofk9B7s6z5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 11:03:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Anna Collard ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The multiple recent reports of autonomous AI systems escaping their intended boundaries and accessing external organizations' systems have pushed a previously theoretical question into the real world. AI agents going rogue is no longer a prospect; it is a documented reality.</p><p>In July 2026, OpenAI disclosed that one of its own agents, operating in a supposedly sealed evaluation environment, exploited a zero-day vulnerability to escape its sandbox and intrude into Hugging Face’s production <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>. Anthropic subsequently reported three cases of its own models gaining unauthorized access to the real systems of external organizations during testing.</p><p>As businesses increasingly give AI agents the ability to browse the web, access networks, use <a href="https://www.techradar.com/best/best-small-business-software">software</a>, write code and execute tasks without constant human supervision, an agent crossing from legitimate testing into unauthorized activity has shifted from hypothetical risk to live incident.</p><p>There is a temptation to treat autonomous AI as creating a gap in the law because the system itself can make decisions and take actions that were not individually instructed by a human. Yet autonomy does not give an AI system legal personality. The law does not wait for an AI to ‘decide’ anything.</p><p>An agent cannot appear in court, hold a legal duty or absorb liability on behalf of the organization deploying it. However, this raises an obvious question: if an AI system accesses a third-party network, extracts information or takes an action it was never authorized to take, who is responsible?</p><h2 id="ai-has-no-legal-personality-but-someone-is-still-accountable">AI has no legal personality but someone is still accountable</h2><p>The important distinction to make is between autonomy and accountability. An AI agent might determine for itself which technical steps to take in pursuit of an objective, but that does not make it an independent legal actor.</p><p>The organization deploying it has still made a series of decisions as to what the agent can access, what tools it can use, what environments it is allowed to operate within and what safeguards prevent it from going further.</p><p>That means an organization cannot simply point to unexpected behaviors and say that the AI acted independently.</p><p>From a legal and governance perspective, the critical moment comes when an agent leaves an authorized, contained environment and begins interacting with systems belonging to a third party that has not consented. An internal <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> test that unexpectedly becomes an intrusion into somebody else’s infrastructure is not made harmless because the software crossed that boundary autonomously.</p><p>The machine does not absorb responsibility for the decision-making framework surrounding it. Accountability flows back to the humans and organizations that created the conditions in which the action became possible.</p><h2 id="existing-cyber-laws-don-t-stop-applying-because-the-actor-was-autonomous">Existing cyber laws don’t stop applying because the actor was autonomous</h2><p>The law is set up to deal with much of what is already happening. Unauthorized access to <a href="https://www.techradar.com/news/best-business-desktop-pcs">computer</a> systems, extracting information without permission or introducing malicious software are activities addressed by existing cybercrime and data-protection regimes. In the UK, that includes the Computer Misuse Act and data-protection legislation.</p><p>Equivalent questions arise under laws such as the US Computer Fraud and Abuse Act, while South Africa has its Cybercrimes Act and Protection of Personal Information Act.</p><p>Those rules do not suddenly cease to apply because software rather than a person directly performed the technical action.</p><p>Where autonomous systems do create greater complexity is around intent. Criminal offences have traditionally been built around concepts such as knowledge, intention and recklessness. AI does not possess a legally recognized state of mind, making it difficult to apply those concepts to the agent itself.</p><p>The more significant questions may consequently concern the conduct of the organization behind the system. Did it understand what the agent was capable of doing? Were appropriate restrictions in place? Was the possibility of the agent exceeding its authority foreseeable? And once those risks became apparent, were reasonable steps taken to control them?</p><p>As agents become more capable, organizations may increasingly find that claiming an outcome was unexpected is not enough. The relevant question will be whether it was reasonably preventable.</p><h2 id="why-misconfiguration-could-become-evidence-of-a-breach-of-duty">Why “misconfiguration” could become evidence of a breach of duty</h2><p>The word “misconfiguration” appears frequently when technology causes an unintended security incident. It can sound reassuringly technical, almost as though the incident resulted from bad luck rather than a governance failure. But in a legal context, misconfiguration may raise precisely the opposite conclusion.</p><p>If an AI agent had excessive privileges, inadequate boundaries or access to tools that were unnecessary for its legitimate purpose, investigators are likely to ask why.</p><p>The same applies where organizations deploy highly capable systems without sufficiently monitoring their actions or maintaining records that explain how they behaved. ‘We accidentally left the door open’ is the kind of framing that moves an incident from bad luck to a breach of duty or negligence.</p><p>There is an important difference between genuinely unforeseeable behavior and a foreseeable risk that was poorly controlled.</p><p>The principle of least privilege is therefore particularly important for autonomous systems. An agent should have access only to the information, systems and tools necessary to complete its task. Organizations also need mechanisms capable of detecting unusual behavior while it is happening rather than discovering it after damage has occurred.</p><p>Just as importantly, they need reliable audit trails. When an incident occurs, being able to demonstrate what an agent was authorized to do, what instructions it received and what actions it actually took could become crucial evidence that reasonable care was exercised.</p><p>Without that evidence, organizations may struggle to distinguish an unavoidable technical failure from negligence.</p><h2 id="future-of-ai-liability">Future of AI liability</h2><p>The debate over AI liability will inevitably evolve as agents become more autonomous, but the immediate lesson for <a href="https://www.techradar.com/best/best-business-cloud-storage-service">businesses</a> is that greater machine autonomy does not mean less human responsibility. If anything, the opposite is likely to be true.</p><p>Giving an AI system greater freedom to act creates a corresponding need for stronger governance around those actions. Runtime controls, least-privilege permissions, continuous monitoring and comprehensive audit records should not be treated simply as technical security features. They are becoming part of the evidence organizations will need to demonstrate that they deployed autonomous systems responsibly.</p><p>The law may eventually develop more specific rules for AI agents, particularly as questions around foreseeability, control and responsibility become more complex. But organizations should not assume they are operating in a legal vacuum until that happens.</p><p>When an autonomous agent crosses a boundary it was never entitled to cross, the first legal question is unlikely to be what the AI was thinking, it will be why the humans responsible for it allowed that to happen.</p><p><em></em><a href=""><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The infrastructure questions that need asking early ]]></title>
                                                                                                <dc:content><![CDATA[ <p>One of the big benefits of the outsourced, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud</a>-based infrastructure model is speed. There are several facets to this; performance clearly being among the most important. Another is speed of provisioning, which remains a major selling point for cloud, given that IT buyers can spin up new resources according to need and in near real time.   </p><p>Take a manager responsible for buying <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> for a large enterprise, for example. When considering various providers, the criteria they apply might typically address factors such as price, compute capacity, storage, bandwidth, and geographic location. This is very helpful for narrowing down the choice, but it doesn’t show how easily the organization can deploy and operate the chosen environment.</p><p>At the same time, infrastructure procurement processes have become so quick and convenient that they are almost as frictionless as buying something from Amazon, and that’s where problems can start.</p><p>Although it can feel like it, infrastructure is not a one-off, fire-and-forget choice; the operational impact persists throughout its lifecycle in production environments. A decision that appears straightforward at the start can quite easily become more consequential or expensive once migration or day-to-day management begins.</p><p>For example, migration might require more internal effort than initially expected, or the organization may discover it lacks some or all of the skills or support capabilities to manage the environment as intended.</p><p>So, how can these issues be addressed? It is important to plan for the possibility that migration may require more engineering time and coordination than expected. Many IT teams will be familiar with the need to reconfigure existing applications or <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> before they can run in the new environment, among other common scenarios.</p><p>Taking it one step further, when a new or upgraded service is more successful than anticipated, costs can easily grow with usage levels and capacity. Addressing this issue may require additional scaling, which can itself introduce additional management or security complexity.</p><p>Very few of these issues are insurmountable, but they can take longer to resolve if responsibilities between the customer and provider have not been clearly established. </p><h2 id="understand-your-operational-requirements">Understand your operational requirements</h2><p>Instead, buyers need to establish who is responsible for what. This should certainly cover day-to-day management, incident response, support escalation, and the process for adding capacity, but  every organization will have its own version of this. When these points are on the table and agreed, providers should be able to explain the practical effect that scaling will have on the customer’s internal team.</p><p>Another often overlooked consideration is that infrastructure services ultimately rely on physical data center capacity, power, network connectivity, and <a href="https://www.techradar.com/news/best-business-desktop-pcs">hardware</a> supply chains. These capabilities have always been important but have jumped up the agenda since AI and other data-intensive workloads increased demand for compute capacity, and at a pace few anticipated.</p><p>Today, buyers also need to understand whether the capacity they expect to use will be available where they need it, and on the timescale they require. Identifying these potential constraints early on allows the organization to account for them in its deployment plan rather than discovering them once a project is underway and, potentially, it’s too late to get what they need.</p><h2 id="bring-the-right-people-into-the-discussion">Bring the right people into the discussion</h2><p>Clearly, some infrastructure decisions are more important than others, but in certain cases, they can affect engineering, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, compliance, <a href="https://www.techradar.com/best/best-personal-finance-software">finance</a>, and the business teams, all of whom rely on the service in question.</p><p>Each group may also introduce requirements that should be fully considered before contracts are signed. If not, problems can arise when a need is identified after a provider has been selected or a deployment plan has been agreed. Involving the relevant stakeholders early also creates a clearer link between the infrastructure decision and the business outcome it is intended to support.</p><p>It may be tempting to keep some stakeholders on the periphery and decide for them, but having a say is not the same as making the final decision. The difference is that early input allows potential issues to be identified while options remain open, rather than giving every stakeholder some measure of control over the selection process, which is also not ideal. </p><h2 id="ask-the-right-questions-before-committing">Ask the right questions before committing</h2><p>When looking at potential infrastructure providers, buyers should be able to define, in simple terms, the problem the new environment is intended to solve. At that point, it’s time for buyers to ask some serious questions.</p><p>For example, what will success look like once the service has been deployed and is supporting live workloads? How will the environment change when demand increases, including the likely effect on costs and internal <a href="https://www.techradar.com/best/it-management-tools">management</a> effort? Which activities will still require manual intervention from the customer’s team? What support is available during an incident, who owns each stage of the response, and how will escalations be handled?</p><p>Getting satisfactory answers is one thing, but it should get buyers to a point where they can properly test the assumptions within their cost model against the capacity they expect to use over time.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-storage&quot"><em>We've featured the best cloud storage.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/the-infrastructure-questions-that-need-asking-early</link>
                                                                            <description>
                            <![CDATA[ The hidden infrastructure questions that should not be forgotten and asking the right questions before committing. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sJcDzk8x7eKYBnePYEgFCA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wZAaq2s2qH4tHBJTEBNZXM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 10:31:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Terry Storrar ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wZAaq2s2qH4tHBJTEBNZXM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An abstract pattern of blue lines and orange-yellow dots on a dark blue background, to represent a digital environment]]></media:description>                                                            <media:text><![CDATA[An abstract pattern of blue lines and orange-yellow dots on a dark blue background, to represent a digital environment]]></media:text>
                                <media:title type="plain"><![CDATA[An abstract pattern of blue lines and orange-yellow dots on a dark blue background, to represent a digital environment]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wZAaq2s2qH4tHBJTEBNZXM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>One of the big benefits of the outsourced, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud</a>-based infrastructure model is speed. There are several facets to this; performance clearly being among the most important. Another is speed of provisioning, which remains a major selling point for cloud, given that IT buyers can spin up new resources according to need and in near real time.   </p><p>Take a manager responsible for buying <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> for a large enterprise, for example. When considering various providers, the criteria they apply might typically address factors such as price, compute capacity, storage, bandwidth, and geographic location. This is very helpful for narrowing down the choice, but it doesn’t show how easily the organization can deploy and operate the chosen environment.</p><p>At the same time, infrastructure procurement processes have become so quick and convenient that they are almost as frictionless as buying something from Amazon, and that’s where problems can start.</p><p>Although it can feel like it, infrastructure is not a one-off, fire-and-forget choice; the operational impact persists throughout its lifecycle in production environments. A decision that appears straightforward at the start can quite easily become more consequential or expensive once migration or day-to-day management begins.</p><p>For example, migration might require more internal effort than initially expected, or the organization may discover it lacks some or all of the skills or support capabilities to manage the environment as intended.</p><p>So, how can these issues be addressed? It is important to plan for the possibility that migration may require more engineering time and coordination than expected. Many IT teams will be familiar with the need to reconfigure existing applications or <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> before they can run in the new environment, among other common scenarios.</p><p>Taking it one step further, when a new or upgraded service is more successful than anticipated, costs can easily grow with usage levels and capacity. Addressing this issue may require additional scaling, which can itself introduce additional management or security complexity.</p><p>Very few of these issues are insurmountable, but they can take longer to resolve if responsibilities between the customer and provider have not been clearly established. </p><h2 id="understand-your-operational-requirements">Understand your operational requirements</h2><p>Instead, buyers need to establish who is responsible for what. This should certainly cover day-to-day management, incident response, support escalation, and the process for adding capacity, but  every organization will have its own version of this. When these points are on the table and agreed, providers should be able to explain the practical effect that scaling will have on the customer’s internal team.</p><p>Another often overlooked consideration is that infrastructure services ultimately rely on physical data center capacity, power, network connectivity, and <a href="https://www.techradar.com/news/best-business-desktop-pcs">hardware</a> supply chains. These capabilities have always been important but have jumped up the agenda since AI and other data-intensive workloads increased demand for compute capacity, and at a pace few anticipated.</p><p>Today, buyers also need to understand whether the capacity they expect to use will be available where they need it, and on the timescale they require. Identifying these potential constraints early on allows the organization to account for them in its deployment plan rather than discovering them once a project is underway and, potentially, it’s too late to get what they need.</p><h2 id="bring-the-right-people-into-the-discussion">Bring the right people into the discussion</h2><p>Clearly, some infrastructure decisions are more important than others, but in certain cases, they can affect engineering, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, compliance, <a href="https://www.techradar.com/best/best-personal-finance-software">finance</a>, and the business teams, all of whom rely on the service in question.</p><p>Each group may also introduce requirements that should be fully considered before contracts are signed. If not, problems can arise when a need is identified after a provider has been selected or a deployment plan has been agreed. Involving the relevant stakeholders early also creates a clearer link between the infrastructure decision and the business outcome it is intended to support.</p><p>It may be tempting to keep some stakeholders on the periphery and decide for them, but having a say is not the same as making the final decision. The difference is that early input allows potential issues to be identified while options remain open, rather than giving every stakeholder some measure of control over the selection process, which is also not ideal. </p><h2 id="ask-the-right-questions-before-committing">Ask the right questions before committing</h2><p>When looking at potential infrastructure providers, buyers should be able to define, in simple terms, the problem the new environment is intended to solve. At that point, it’s time for buyers to ask some serious questions.</p><p>For example, what will success look like once the service has been deployed and is supporting live workloads? How will the environment change when demand increases, including the likely effect on costs and internal <a href="https://www.techradar.com/best/it-management-tools">management</a> effort? Which activities will still require manual intervention from the customer’s team? What support is available during an incident, who owns each stage of the response, and how will escalations be handled?</p><p>Getting satisfactory answers is one thing, but it should get buyers to a point where they can properly test the assumptions within their cost model against the capacity they expect to use over time.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-storage&quot"><em>We've featured the best cloud storage.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why Zero Trust is the practical enterprise access and security model ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Enterprises once relied on perimeter-first <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> because enterprise systems operated like traditional single player games where data, servers and the game application resided in a single device or within one network boundary. This model worked brilliantly when users, workloads, and trusted networks were co-located.  </p><p>Today, enterprise security resembles a modern multi-player online gaming where players connect from everywhere, game assets are distributed across servers around the world, and the experience relies on a complex, interconnected ecosystem.</p><p>In the same way, enterprise users, devices, applications, and <a href="https://www.techradar.com/best/best-data-migration-tools">data</a>, now span clouds, edge locations, branches, partner environments, and mobile workforces, and are so distributed that trust can no longer be assumed based on location alone.</p><p>As a result, perimeter‑only approaches have become inadequate since legacy architectures struggle with cloud‑native applications, edge computing, hybrid workstyles, and API‑driven ecosystems. <a href="https://www.techradar.com/vpn/most-secure-vpns-best-encryption">VPN</a>‑led access creates blind spots in visibility, inconsistent policy enforcement, and weak session‑level control.</p><p>Enterprises scaling across branches, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud</a> workloads, partner ecosystems, and remote users, therefore, need a more unified approach that focuses on continuous verification, consistent policy, and real‑time monitoring.</p><p>This is why Zero Trust has shifted from a theoretical framework to an operational imperative that addresses compromised credentials, excessive privileges, insider misuse, and inconsistent enforcement, and organizations that adopt Zero Trust report reduced lateral movement and lowered breach impact.</p><h2 id="the-limitations-of-perimeter-led-security-in-a-cloud-first-world">The limitations of perimeter-led security in a cloud-first world </h2><p>In the past, organizations secured a network perimeter and assumed everything inside was trustworthy. As <a href="https://www.techradar.com/best/best-small-business-website-builders">businesses</a> distributed across geographies, applications, and users, this boundary became blurred.</p><p>This is like hackers scanning online games for exploits to steal virtual assets; enterprises face continuous, automated scanning for any weakness.</p><p>In Zero Trust security model, each user, machine, and application is constantly verified and authenticated regardless of location. This makes Zero Trust an excellent security strategy for today’s borderless digital landscape. </p><h2 id="what-zero-trust-means-in-practical-enterprise-terms">What Zero Trust means in practical enterprise terms</h2><p>Zero Trust is not a single product, it is a discipline for managing and granting access. In practical terms, this translates into:</p><ul><li>User and device verification before granting access, using <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a>, device posture, and context</li><li>Applying least privilege to limit access to only what is needed, for just the time required</li><li>Enforcing consistent policies across devices, networks, clouds, and partners</li><li>Continuously monitoring sessions and telemetry to detect and contain threats in real time</li></ul><p>The result is targeted access management, reduced attack surface, faster containment, and clearer audit trails.</p><p>A network‑embedded Zero Trust architecture drives concrete outcomes: lower mean time to detection, narrower blast radius, unified policy control, and simplified compliance.</p><h2 id="embedding-zero-trust-into-the-network-layer">Embedding Zero Trust into the network layer </h2><p>Security threats span users, devices, branches, and cloud paths. The network layer has a bird’s‑eye view of traffic, telemetry, and connection patterns, making it a natural control plane for Zero Trust.</p><p>Implementing Zero Trust by piecing together point solutions creates complexity and siloed visibility. Zero Trust is most effective when native capabilities are built into the network stack itself, including:</p><ul><li>Identity‑aware policy at the network edge</li><li>End‑to‑end telemetry for real‑time risk scoring</li><li>Centralized policy enforcement that travels with the workload</li></ul><p>Network‑level capabilities reduce dependency on fragile add‑ons and enable consistent controls across branches, clouds, and partner links.</p><p>Practical network components include integrated SD‑Wan, dedicated secure internet links, private connectivity options, and managed security services that provide a stable foundation for Zero Trust.</p><h2 id="network-led-zero-trust-in-practice">Network‑led Zero Trust in practice</h2><ol start="1"><li><strong>Manufacturing: </strong>Embedded access controls can isolate OT traffic from enterprise IT, preventing production impacts from IT compromises.</li><li><strong>Logistics:</strong> Device‑bound certificates on private wireless prevent unauthorized access to tracking systems and asset controls.</li><li><strong>Mining and remote operations:</strong> Private networks with segmentation maintain operational safety while limiting exposure to external threats.</li><li><strong>Financial services:</strong> Consistent policy enforcement across clouds and branches reduces fraud surface and speeds incident response.</li></ol><p>In these settings, Zero Trust must be embedded into network design and not applied as an afterthought.</p><h2 id="reducing-exposure-and-ensuring-resilience">Reducing exposure and ensuring resilience </h2><p>The most important outcome of Zero Trust is risk reduction.  In practical terms, this means:</p><ul><li>Minimizing unnecessary access and privileges</li><li>Constraining lateral movement through segmentation</li><li>Accelerating detection with rich network telemetry</li><li>Automating containment to limit impact</li></ul><p>In hybrid and distributed work models, a compromised credential or an unsecured device can rapidly spread risk. A strong Zero Trust framework narrows attack paths and makes it harder for threats to escalate.</p><h2 id="priorities-for-enterprises-adopting-zero-trust">Priorities for enterprises adopting Zero Trust</h2><p>Organizations should strengthen security without creating operational friction. Key priorities include:</p><ul><li><strong>Start with high‑value use cases:</strong> Protect sensitive data, critical applications, and operational networks first.</li><li><strong>Phased implementation:</strong> Roll out Zero Trust in iterative sprints, validating operations after each phase.</li><li><strong>Align policy with business objectives:</strong> Balance security rigor with user experience to avoid productivity loss.</li><li><strong>Engage stakeholders:</strong> Include IT, security, business leads, and end users to ensure practical, scalable controls.</li><li><strong>Measure and improve: </strong>Track metrics like time to detect, time to remediate, and reduction in lateral movement.</li></ul><h2 id="zero-trust-from-strategy-to-execution">Zero Trust – From strategy to execution</h2><ol start="1"><li><strong>Map critical resources:</strong> Identify data, apps, and network segments that require priority.</li><li><strong>Inventory users and devices: </strong>Establish identity sources, device posture checks, and third‑party access rules.</li><li><strong>Define least‑privilege policies:</strong> Apply just‑in‑time and just‑enough access for sensitive workloads.</li><li><strong>Build network telemetry pipeline:</strong> Consolidate logs, flow data, and risk signals into a central platform.</li><li><strong>Automate policy enforcement:</strong> Use network‑based controls to apply consistent policies across clouds and branches.</li><li><strong>Run tabletops and red‑team exercises:</strong> Validate controls and measure blast radius reduction.</li></ol><h2 id="building-trust-into-architecture-not-around-it">Building trust into architecture, not around it</h2><p>As enterprises adopt SD‑WAN, private wireless, cloud‑connected branches, and segmented digital operations, the question is no longer whether to implement Zero Trust, but how deeply to embed it into infrastructure.</p><p>The organizations that will scale with confidence are those that treat Zero Trust not as a security overlay, but as a foundational design principle that is built into network architecture, measured through operational outcomes, and continuously refined through real-world validation.</p><p>Zero Trust is not a destination but a discipline that evolves with threat landscapes, <a href="https://www.techradar.com/best/best-small-business-software">business</a> models, and technology platforms. Enterprises that start today, iterate rapidly, and embed controls at the network layer will be better positioned to defend critical assets, maintain operational resilience, and adapt to tomorrow's risks with speed and clarity.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/why-zero-trust-is-the-practical-enterprise-access-and-security-model</link>
                                                                            <description>
                            <![CDATA[ Zero Trust embeds continuous verification, least privilege and network-level controls to strengthen enterprise resilience. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JhVQ56HRfHF6xMjPC8E5jf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 09:56:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sharat Sinha ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:description>                                                            <media:text><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity ensures data protection on internet. Data encryption, firewall, encrypted network, VPN, secure access and authentication defend against malware, hacking, cyber crime and digital threat]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UjSNcAZ5SebctebKAMQNVF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Enterprises once relied on perimeter-first <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> because enterprise systems operated like traditional single player games where data, servers and the game application resided in a single device or within one network boundary. This model worked brilliantly when users, workloads, and trusted networks were co-located.  </p><p>Today, enterprise security resembles a modern multi-player online gaming where players connect from everywhere, game assets are distributed across servers around the world, and the experience relies on a complex, interconnected ecosystem.</p><p>In the same way, enterprise users, devices, applications, and <a href="https://www.techradar.com/best/best-data-migration-tools">data</a>, now span clouds, edge locations, branches, partner environments, and mobile workforces, and are so distributed that trust can no longer be assumed based on location alone.</p><p>As a result, perimeter‑only approaches have become inadequate since legacy architectures struggle with cloud‑native applications, edge computing, hybrid workstyles, and API‑driven ecosystems. <a href="https://www.techradar.com/vpn/most-secure-vpns-best-encryption">VPN</a>‑led access creates blind spots in visibility, inconsistent policy enforcement, and weak session‑level control.</p><p>Enterprises scaling across branches, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud</a> workloads, partner ecosystems, and remote users, therefore, need a more unified approach that focuses on continuous verification, consistent policy, and real‑time monitoring.</p><p>This is why Zero Trust has shifted from a theoretical framework to an operational imperative that addresses compromised credentials, excessive privileges, insider misuse, and inconsistent enforcement, and organizations that adopt Zero Trust report reduced lateral movement and lowered breach impact.</p><h2 id="the-limitations-of-perimeter-led-security-in-a-cloud-first-world">The limitations of perimeter-led security in a cloud-first world </h2><p>In the past, organizations secured a network perimeter and assumed everything inside was trustworthy. As <a href="https://www.techradar.com/best/best-small-business-website-builders">businesses</a> distributed across geographies, applications, and users, this boundary became blurred.</p><p>This is like hackers scanning online games for exploits to steal virtual assets; enterprises face continuous, automated scanning for any weakness.</p><p>In Zero Trust security model, each user, machine, and application is constantly verified and authenticated regardless of location. This makes Zero Trust an excellent security strategy for today’s borderless digital landscape. </p><h2 id="what-zero-trust-means-in-practical-enterprise-terms">What Zero Trust means in practical enterprise terms</h2><p>Zero Trust is not a single product, it is a discipline for managing and granting access. In practical terms, this translates into:</p><ul><li>User and device verification before granting access, using <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a>, device posture, and context</li><li>Applying least privilege to limit access to only what is needed, for just the time required</li><li>Enforcing consistent policies across devices, networks, clouds, and partners</li><li>Continuously monitoring sessions and telemetry to detect and contain threats in real time</li></ul><p>The result is targeted access management, reduced attack surface, faster containment, and clearer audit trails.</p><p>A network‑embedded Zero Trust architecture drives concrete outcomes: lower mean time to detection, narrower blast radius, unified policy control, and simplified compliance.</p><h2 id="embedding-zero-trust-into-the-network-layer">Embedding Zero Trust into the network layer </h2><p>Security threats span users, devices, branches, and cloud paths. The network layer has a bird’s‑eye view of traffic, telemetry, and connection patterns, making it a natural control plane for Zero Trust.</p><p>Implementing Zero Trust by piecing together point solutions creates complexity and siloed visibility. Zero Trust is most effective when native capabilities are built into the network stack itself, including:</p><ul><li>Identity‑aware policy at the network edge</li><li>End‑to‑end telemetry for real‑time risk scoring</li><li>Centralized policy enforcement that travels with the workload</li></ul><p>Network‑level capabilities reduce dependency on fragile add‑ons and enable consistent controls across branches, clouds, and partner links.</p><p>Practical network components include integrated SD‑Wan, dedicated secure internet links, private connectivity options, and managed security services that provide a stable foundation for Zero Trust.</p><h2 id="network-led-zero-trust-in-practice">Network‑led Zero Trust in practice</h2><ol start="1"><li><strong>Manufacturing: </strong>Embedded access controls can isolate OT traffic from enterprise IT, preventing production impacts from IT compromises.</li><li><strong>Logistics:</strong> Device‑bound certificates on private wireless prevent unauthorized access to tracking systems and asset controls.</li><li><strong>Mining and remote operations:</strong> Private networks with segmentation maintain operational safety while limiting exposure to external threats.</li><li><strong>Financial services:</strong> Consistent policy enforcement across clouds and branches reduces fraud surface and speeds incident response.</li></ol><p>In these settings, Zero Trust must be embedded into network design and not applied as an afterthought.</p><h2 id="reducing-exposure-and-ensuring-resilience">Reducing exposure and ensuring resilience </h2><p>The most important outcome of Zero Trust is risk reduction.  In practical terms, this means:</p><ul><li>Minimizing unnecessary access and privileges</li><li>Constraining lateral movement through segmentation</li><li>Accelerating detection with rich network telemetry</li><li>Automating containment to limit impact</li></ul><p>In hybrid and distributed work models, a compromised credential or an unsecured device can rapidly spread risk. A strong Zero Trust framework narrows attack paths and makes it harder for threats to escalate.</p><h2 id="priorities-for-enterprises-adopting-zero-trust">Priorities for enterprises adopting Zero Trust</h2><p>Organizations should strengthen security without creating operational friction. Key priorities include:</p><ul><li><strong>Start with high‑value use cases:</strong> Protect sensitive data, critical applications, and operational networks first.</li><li><strong>Phased implementation:</strong> Roll out Zero Trust in iterative sprints, validating operations after each phase.</li><li><strong>Align policy with business objectives:</strong> Balance security rigor with user experience to avoid productivity loss.</li><li><strong>Engage stakeholders:</strong> Include IT, security, business leads, and end users to ensure practical, scalable controls.</li><li><strong>Measure and improve: </strong>Track metrics like time to detect, time to remediate, and reduction in lateral movement.</li></ul><h2 id="zero-trust-from-strategy-to-execution">Zero Trust – From strategy to execution</h2><ol start="1"><li><strong>Map critical resources:</strong> Identify data, apps, and network segments that require priority.</li><li><strong>Inventory users and devices: </strong>Establish identity sources, device posture checks, and third‑party access rules.</li><li><strong>Define least‑privilege policies:</strong> Apply just‑in‑time and just‑enough access for sensitive workloads.</li><li><strong>Build network telemetry pipeline:</strong> Consolidate logs, flow data, and risk signals into a central platform.</li><li><strong>Automate policy enforcement:</strong> Use network‑based controls to apply consistent policies across clouds and branches.</li><li><strong>Run tabletops and red‑team exercises:</strong> Validate controls and measure blast radius reduction.</li></ol><h2 id="building-trust-into-architecture-not-around-it">Building trust into architecture, not around it</h2><p>As enterprises adopt SD‑WAN, private wireless, cloud‑connected branches, and segmented digital operations, the question is no longer whether to implement Zero Trust, but how deeply to embed it into infrastructure.</p><p>The organizations that will scale with confidence are those that treat Zero Trust not as a security overlay, but as a foundational design principle that is built into network architecture, measured through operational outcomes, and continuously refined through real-world validation.</p><p>Zero Trust is not a destination but a discipline that evolves with threat landscapes, <a href="https://www.techradar.com/best/best-small-business-software">business</a> models, and technology platforms. Enterprises that start today, iterate rapidly, and embed controls at the network layer will be better positioned to defend critical assets, maintain operational resilience, and adapt to tomorrow's risks with speed and clarity.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Multiple healthcare giants hit by data breaches affecting patient records, social security numbers, and even implanted cardiac devices ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>McKesson confirmed ShinyHunters breached its Snowflake and Salesforce, stealing 284M patient records</strong></li><li><strong>Data includes names, contact info, SSNs, and health details; ransom demand was $55.2M</strong></li><li><strong>Boston Scientific removed attackers but faces CRM device activation issues; attribution not confirmed</strong></li></ul><p>Last week, two major healthcare organizations suffered highly disruptive cyberattacks: Boston Scientific, and McKesson. We now have more details about both those attacks, and it seems at least one is the work of the infamous ShinyHunters <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">extortion</a> group.</p><p>McKesson confirmed having been struck by ShinyHunters, just a few days after the threat actor claimed responsibility. The group told The Register they broke into the company’s Snowflake and Salesforce instances and stole “millions of patients’ data”. </p><p>The company later issued a statement, saying the stolen data belonged to its Oncology & Multispecialty and Medical-Surgical business units. A spokesperson told The Register multiple employees were targeted with a vishing attack. </p><h2 id="boston-scientific-works-on-restoring-systems">Boston Scientific works on restoring systems</h2><p>The group told the publication it stole more than 284 million records of patient data and demanded $55.2 million from the victims. They are saying the stolen batch includes patient tames, postal and email addresses, phone numbers, Social Security numbers (SSN), and details regarding their health condition. Whether the claims are true, and to what extent, remains to be seen after the investigation. </p><p>Boston Scientific, on the other hand, said it successfully removed the attackers from its infrastructure, but added that the investigation into the attack remains ongoing. It also said that new Cardiac Rhythm Management (CRM) devices, implanted after August 25, cannot be activated, and the data they generate will not automatically be transmitted to remote patient management systems. </p><p>“Newly implanted ICMs (insertable cardiac monitors) must be activated using the Boston Scientific Clinic Assistant app to enable the ICM to properly record episodes,” it explained. “New ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app. Episodes will continue to be recorded by the ICM and can be transmitted to the remote monitoring system via an in-person interrogation with the Clinic Assistant app by selecting the “Interrogate” button.”</p><p><a href="https://www.techradar.com/pro/security/boston-scientific-says-cyberattack-is-causing-a-global-disruption-to-medical-device-operations" target="_blank">Boston Scientific is yet to name ShinyHunters as the perpetrators</a>, and the group has not yet publicly claimed responsibility for the attack.</p><p><em>Via </em><a href="" target="_blank"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/multiple-healthcare-giants-hit-by-data-breaches-affecting-patient-records-social-security-numbers-and-even-implanted-cardiac-devices</link>
                                                                            <description>
                            <![CDATA[ Boston Scientific and McKesson are working on restoring services after being struck by disruptive cyberattacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GDuLq4JqbV564wt5k96bSV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 21:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Laboratory]]></media:description>                                                            <media:text><![CDATA[Laboratory]]></media:text>
                                <media:title type="plain"><![CDATA[Laboratory]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9DcUT2RtbvGV8dbUy5P8MA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>McKesson confirmed ShinyHunters breached its Snowflake and Salesforce, stealing 284M patient records</strong></li><li><strong>Data includes names, contact info, SSNs, and health details; ransom demand was $55.2M</strong></li><li><strong>Boston Scientific removed attackers but faces CRM device activation issues; attribution not confirmed</strong></li></ul><p>Last week, two major healthcare organizations suffered highly disruptive cyberattacks: Boston Scientific, and McKesson. We now have more details about both those attacks, and it seems at least one is the work of the infamous ShinyHunters <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">extortion</a> group.</p><p>McKesson confirmed having been struck by ShinyHunters, just a few days after the threat actor claimed responsibility. The group told The Register they broke into the company’s Snowflake and Salesforce instances and stole “millions of patients’ data”. </p><p>The company later issued a statement, saying the stolen data belonged to its Oncology & Multispecialty and Medical-Surgical business units. A spokesperson told The Register multiple employees were targeted with a vishing attack. </p><h2 id="boston-scientific-works-on-restoring-systems">Boston Scientific works on restoring systems</h2><p>The group told the publication it stole more than 284 million records of patient data and demanded $55.2 million from the victims. They are saying the stolen batch includes patient tames, postal and email addresses, phone numbers, Social Security numbers (SSN), and details regarding their health condition. Whether the claims are true, and to what extent, remains to be seen after the investigation. </p><p>Boston Scientific, on the other hand, said it successfully removed the attackers from its infrastructure, but added that the investigation into the attack remains ongoing. It also said that new Cardiac Rhythm Management (CRM) devices, implanted after August 25, cannot be activated, and the data they generate will not automatically be transmitted to remote patient management systems. </p><p>“Newly implanted ICMs (insertable cardiac monitors) must be activated using the Boston Scientific Clinic Assistant app to enable the ICM to properly record episodes,” it explained. “New ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app. Episodes will continue to be recorded by the ICM and can be transmitted to the remote monitoring system via an in-person interrogation with the Clinic Assistant app by selecting the “Interrogate” button.”</p><p><a href="https://www.techradar.com/pro/security/boston-scientific-says-cyberattack-is-causing-a-global-disruption-to-medical-device-operations" target="_blank">Boston Scientific is yet to name ShinyHunters as the perpetrators</a>, and the group has not yet publicly claimed responsibility for the attack.</p><p><em>Via </em><a href="" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco routers are being turned into surveillance vantage points to hoover up data on trusted networks — and it's all thanks to this new malware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Sygnia reports China‑linked Fire Ant expanding beyond virtualization to routers, TACACS, and Linux hosts</strong></li><li><strong>Compromised routers act as operational platforms</strong></li><li><strong>Campaign aims at “target behind the target,” leveraging trust relationships for broader espionage reach</strong></li></ul><p>Fire Ant, a China-nexus cyberespionage group, is no longer targeting just virtualization platforms, it’s also going for routers, authentication systems, and Linux management hosts. This is according to cybersecurity researchers Sygnia, who recently saw the group target Cisco IOS XR Routers. </p><p>Once they compromise a <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523" target="_blank">router</a>, they don’t just use it to move around the network, the researchers explained. Instead, they turn them into full-blown operational platforms, collecting traffic, establishing connections, manipulating command output, and even suppressing logging so that they fly under the defenders’ radars. </p><p>For authentication systems, Fire Ant was seen taking aim at TACACS servers. Admins use them to authenticate when accessing network hardware, and crooks use them to harvest valuable credentials and weaken the reliability of audit logs, as well. Finally, Sygnia says Fire Ant also targets Linux management hosts. The researchers saw multiple persistent implants and backdoors, including a custom SSH backdoor and a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> spoofing legitimate software. </p><h2 id="target-behind-the-target">Target behind the target</h2><p>The goal of the campaign seems to be to establish a foothold that allows crooks to reach other environments. Sygnia describes it as a “target behind the target” scenario: </p><p>“This reinforces the “target behind the target” concept introduced earlier in this report. Fire Ant’s interest in the compromised organization should be understood not only as an attempt to compromise a single environment, but as an effort to control infrastructure that may enable visibility, collection, and potential access beyond the immediate victim. The strategic value lies in the trust relationships the organization maintains with connected environments,” Sygnia explained.</p><p>Very little is known about Fire Ant, besides the fact that it was first observed in 2025. Some researchers claim it has significant overlaps with a threat actor tracked as UNC3886, a Chinese espionage group previously observed by Google. However, there are also significant differences which make attribution inconclusive.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/cisco-routers-are-being-turned-into-surveillance-vantage-points-to-hoover-up-data-on-trusted-networks-and-its-all-thanks-to-this-new-malware</link>
                                                                            <description>
                            <![CDATA[ Fire Ant is now targeting routers, authentication servers, and Linux management hosts, using them as stepping stones. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ktXPBkae4A3uwRF8jyucDd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 19:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:description>                                                            <media:text><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:text>
                                <media:title type="plain"><![CDATA[A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EEXAxCUDKAq3frELz3rVYY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Sygnia reports China‑linked Fire Ant expanding beyond virtualization to routers, TACACS, and Linux hosts</strong></li><li><strong>Compromised routers act as operational platforms</strong></li><li><strong>Campaign aims at “target behind the target,” leveraging trust relationships for broader espionage reach</strong></li></ul><p>Fire Ant, a China-nexus cyberespionage group, is no longer targeting just virtualization platforms, it’s also going for routers, authentication systems, and Linux management hosts. This is according to cybersecurity researchers Sygnia, who recently saw the group target Cisco IOS XR Routers. </p><p>Once they compromise a <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523" target="_blank">router</a>, they don’t just use it to move around the network, the researchers explained. Instead, they turn them into full-blown operational platforms, collecting traffic, establishing connections, manipulating command output, and even suppressing logging so that they fly under the defenders’ radars. </p><p>For authentication systems, Fire Ant was seen taking aim at TACACS servers. Admins use them to authenticate when accessing network hardware, and crooks use them to harvest valuable credentials and weaken the reliability of audit logs, as well. Finally, Sygnia says Fire Ant also targets Linux management hosts. The researchers saw multiple persistent implants and backdoors, including a custom SSH backdoor and a piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> spoofing legitimate software. </p><h2 id="target-behind-the-target">Target behind the target</h2><p>The goal of the campaign seems to be to establish a foothold that allows crooks to reach other environments. Sygnia describes it as a “target behind the target” scenario: </p><p>“This reinforces the “target behind the target” concept introduced earlier in this report. Fire Ant’s interest in the compromised organization should be understood not only as an attempt to compromise a single environment, but as an effort to control infrastructure that may enable visibility, collection, and potential access beyond the immediate victim. The strategic value lies in the trust relationships the organization maintains with connected environments,” Sygnia explained.</p><p>Very little is known about Fire Ant, besides the fact that it was first observed in 2025. Some researchers claim it has significant overlaps with a threat actor tracked as UNC3886, a Chinese espionage group previously observed by Google. However, there are also significant differences which make attribution inconclusive.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ North Korea expands fraudulent job resumes to target marketing, sales, and medical sector ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress reports DPRK job seekers expanding beyond tech into healthcare, sales, and marketing</strong></li><li><strong>North Koreans use stolen identities, forged documents, AI tools, and proxies to bypass detection</strong></li><li><strong>Campaign dubbed “IT worker scheme” continues, posing sanctions risks and unique detection challenges</strong></li></ul><p>North Koreans looking to get hired by western companies are no longer focused exclusively on tech companies. According to security researchers Huntress, they have started applying for jobs in healthcare, sales, and marketing.</p><p>For US companies, employing North Koreans is prohibited under US sanctions, and the US government specifically warns about hiring IT workers from DPRK. As a result, these individuals are engaging in all sorts of fraudulent behavior to trick their potential employers and get hired. </p><p>That includes stealing other people’s identities, forging documents, and using pre-recorded or AI generated videos during calls and interviews. They’re also using ChatGPT to draft answers to questions and communicate without raising any alarms. Furthermore, they are deploying proxies and VPNs, often connecting to computers on “hardware farms” in China, and using personal, non-resident banking accounts to get paid.</p><h2 id="it-worker-scheme">IT worker scheme</h2><p>"DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do," Huntress said in an analysis.</p><p>This is a campaign that’s been ongoing for years. Researchers call it the “IT worker scheme” and while some argue the scammers are using their earned salary to further North Korea’s weapons program, there is no evidence to point in that direction. For all we know, they might actually be desperate for a job - they’re just not allowed to do it remotely.</p><p>In its latest report, Huntress says it saw three people in an Australian healthcare company that turned out to be North Koreans impersonating the Chinese. It also saw an unnamed financial services firm whose employees used software that allowed them to work remotely through devices hosted on laptop farms.</p><p>Finally, it investigated a case of a sales and marketing employee using a <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">stolen identity</a>. The worker allegedly used the personal details of a legitimate individual (name, birth date, location) which had been published online by law enforcement following that person’s arrest. At the same time, they were using their own face during the hiring process. </p><p><em>Via </em><a href="https://thehackernews.com/2026/08/north-korean-job-fraud-expands-beyond.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/north-korea-expands-fraudulent-job-resumes-to-target-marketing-sales-and-medical-sector</link>
                                                                            <description>
                            <![CDATA[ North Koreans are going to great lengths to get hired in the west, even if it means faking absolutely everything. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SmYDbBgwpxbsMGLsENbYsD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 16:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean flag with a hooded hacker]]></media:description>                                                            <media:text><![CDATA[North Korean flag with a hooded hacker]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean flag with a hooded hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress reports DPRK job seekers expanding beyond tech into healthcare, sales, and marketing</strong></li><li><strong>North Koreans use stolen identities, forged documents, AI tools, and proxies to bypass detection</strong></li><li><strong>Campaign dubbed “IT worker scheme” continues, posing sanctions risks and unique detection challenges</strong></li></ul><p>North Koreans looking to get hired by western companies are no longer focused exclusively on tech companies. According to security researchers Huntress, they have started applying for jobs in healthcare, sales, and marketing.</p><p>For US companies, employing North Koreans is prohibited under US sanctions, and the US government specifically warns about hiring IT workers from DPRK. As a result, these individuals are engaging in all sorts of fraudulent behavior to trick their potential employers and get hired. </p><p>That includes stealing other people’s identities, forging documents, and using pre-recorded or AI generated videos during calls and interviews. They’re also using ChatGPT to draft answers to questions and communicate without raising any alarms. Furthermore, they are deploying proxies and VPNs, often connecting to computers on “hardware farms” in China, and using personal, non-resident banking accounts to get paid.</p><h2 id="it-worker-scheme">IT worker scheme</h2><p>"DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them, and oftentimes actually doing the legitimate work they were hired to do," Huntress said in an analysis.</p><p>This is a campaign that’s been ongoing for years. Researchers call it the “IT worker scheme” and while some argue the scammers are using their earned salary to further North Korea’s weapons program, there is no evidence to point in that direction. For all we know, they might actually be desperate for a job - they’re just not allowed to do it remotely.</p><p>In its latest report, Huntress says it saw three people in an Australian healthcare company that turned out to be North Koreans impersonating the Chinese. It also saw an unnamed financial services firm whose employees used software that allowed them to work remotely through devices hosted on laptop farms.</p><p>Finally, it investigated a case of a sales and marketing employee using a <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">stolen identity</a>. The worker allegedly used the personal details of a legitimate individual (name, birth date, location) which had been published online by law enforcement following that person’s arrest. At the same time, they were using their own face during the hiring process. </p><p><em>Via </em><a href="https://thehackernews.com/2026/08/north-korean-job-fraud-expands-beyond.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Careful when filing your taxes, this new "PackClient" malware is hitting global firms via tax audit lures ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Proofpoint observed PackClient RAT sold on Telegram, used by group TA4922</strong></li><li><strong>Attack spoofed tax authority emails in China and India, delivering PackClient installer</strong></li><li><strong>RAT offers advanced features; researchers warn broader adoption likely beyond Asia</strong></li></ul><p>For almost three months, Chinese hackers have been distributing an advanced Remote Access Trojan (RAT) called PackClient, against organizations in mainland China and India.</p><p>According to security researchers Proofpoint, PackClient is being actively sold on Telegram channels. It is a rather advanced RAT, capable of file theft and management, remote shell execution, screen capture and remote desktop management, webcam access, keylogging, privilege escalation, system administration, and a myriad of other things.</p><p>Even though it’s actively sold on Telegram, so far just one hacking group was spotted using it - TA4922. This is not a state-sponsored group but rather a financially motivated one.</p><h2 id="picking-up-the-malware">Picking up the malware</h2><p>Since late May 2026, this group has been mailing organization, first in China, and later in India, as well. In the emails, they spoofed local tax authorities, claiming that the recipients were needed to conduct “self-inspection”, a process which included downloading and filling out paperwork shared in the attachment.</p><p>The “paperwork”, however, was nothing more than the PackClient installer.</p><p>In its report, Proofpoint did not say how many organizations fell victim to the attack, nor did it discuss in which industries most victims operated.</p><p>However, in earlier reports, the researchers said TA4922 typically targets small and medium-sized organizations located primarily in Japan. Other notable mentions include Taiwan, Korea, Singapore, and India, while in newer times, they also started targeting European organizations, as well as those in the UK. </p><p>Proofpoint also stressed that the advanced capabilities of PackClient might see it getting picked up by many more threat actors, and see it getting deployed against more organizations, particularly in the western part of the world.</p><p>“Given that PackClient is marketed through Telegram making it broadly available, it is likely other threat actors are currently using, or will use, this <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> in future campaigns,” they said. The researchers also shared a full list of Indicators of Compromise (<a href="https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient" target="_blank" rel="nofollow">IoC</a>), in case you’re suspicious of an infection.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/careful-when-filing-your-taxes-this-new-packclient-malware-is-hitting-global-firms-via-tax-audit-lures</link>
                                                                            <description>
                            <![CDATA[ The Chinese are using a tax lure to deploy a new RAT and take over victim devices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9WYHdQcCnqkSjx9Tu2W5ML</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hLQRgpHx6EucdLaJE8z8TA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 15:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hLQRgpHx6EucdLaJE8z8TA-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Someone using forms to pay their taxes.]]></media:description>                                                            <media:text><![CDATA[Someone using forms to pay their taxes.]]></media:text>
                                <media:title type="plain"><![CDATA[Someone using forms to pay their taxes.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hLQRgpHx6EucdLaJE8z8TA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Proofpoint observed PackClient RAT sold on Telegram, used by group TA4922</strong></li><li><strong>Attack spoofed tax authority emails in China and India, delivering PackClient installer</strong></li><li><strong>RAT offers advanced features; researchers warn broader adoption likely beyond Asia</strong></li></ul><p>For almost three months, Chinese hackers have been distributing an advanced Remote Access Trojan (RAT) called PackClient, against organizations in mainland China and India.</p><p>According to security researchers Proofpoint, PackClient is being actively sold on Telegram channels. It is a rather advanced RAT, capable of file theft and management, remote shell execution, screen capture and remote desktop management, webcam access, keylogging, privilege escalation, system administration, and a myriad of other things.</p><p>Even though it’s actively sold on Telegram, so far just one hacking group was spotted using it - TA4922. This is not a state-sponsored group but rather a financially motivated one.</p><h2 id="picking-up-the-malware">Picking up the malware</h2><p>Since late May 2026, this group has been mailing organization, first in China, and later in India, as well. In the emails, they spoofed local tax authorities, claiming that the recipients were needed to conduct “self-inspection”, a process which included downloading and filling out paperwork shared in the attachment.</p><p>The “paperwork”, however, was nothing more than the PackClient installer.</p><p>In its report, Proofpoint did not say how many organizations fell victim to the attack, nor did it discuss in which industries most victims operated.</p><p>However, in earlier reports, the researchers said TA4922 typically targets small and medium-sized organizations located primarily in Japan. Other notable mentions include Taiwan, Korea, Singapore, and India, while in newer times, they also started targeting European organizations, as well as those in the UK. </p><p>Proofpoint also stressed that the advanced capabilities of PackClient might see it getting picked up by many more threat actors, and see it getting deployed against more organizations, particularly in the western part of the world.</p><p>“Given that PackClient is marketed through Telegram making it broadly available, it is likely other threat actors are currently using, or will use, this <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> in future campaigns,” they said. The researchers also shared a full list of Indicators of Compromise (<a href="https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient" target="_blank" rel="nofollow">IoC</a>), in case you’re suspicious of an infection.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft warns of TerminalFix, a campaign abusing compromised sites with fake Cloudflare CAPTCHAs</strong></li><li><strong>Victims paste malicious PowerShell commands, sideloading DLLs and deploying a Python implant</strong></li><li><strong>Implant enables encrypted reverse tunnels, giving attackers pivot access into internal networks</strong></li></ul><p>Security researchers from Microsoft are warning of an ongoing malicious campaign that uses compromised websites to trick users into installing a powerful <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">backdoor</a>.</p><p>Whenever people visited any of the tainted websites, they would see a custom overlay instructing them to complete a fake Cloudflare CAPTCHA verification by copying and running a malicious PowerShell command into Terminal, or PowerShell. Microsoft named the campaign “TerminalFix”, since it is rather similar to the classic ClickFix attack. </p><p>“While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully,” the researchers explained.</p><h2 id="look-for-lateral-movement">Look for lateral movement</h2><p>Unlike classic ClickFix campaigns that try to deliver simple infostealers, TerminalFix tries to deploy a more complex solution. After running the command in the Terminal, the victim would receive two files - a legitimate binary, and a malicious DLL file. The binary would sideload the malicious DLL which, in turn, delivers a hidden payload called “client.py”.</p><p>It is a custom Python implant that creates an encrypted WebSocket connection back to the attackers and gives them SOCKS5-style proxy access into the victim’s internal network. </p><p>In other words, the attackers are deploying a remote-access/network tunneling implant that can connect to internal machines, probe domain controllers, run commands, maintain access after reboots and ultimately use the compromised machine as a pivot point for lateral movement. </p><p>“This type of intrusion is particularly dangerous because it provides attackers with direct access to an organization’s internal network through the reverse tunnel,” Microsoft explained. “The observed reconnaissance and reverse-tunnel capability could enable an attacker to identify and reach additional systems from a compromised host.”</p><p>Microsoft did not observe the attackers actually carrying out lateral movement, so it is difficult to say what they’re using the access for. Still, the researchers are urging caution:</p><p>“Organizations should treat affected devices as potential network pivot points and investigate for lateral movement and credential exposure. In the hands-on-keyboard phase that typically follows, attackers leverage this access to escalate privileges, disable security controls, exfiltrate sensitive data, and deploy ransomware across the organization.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/new-clickfix-campaign-can-deploy-powerful-multi-stage-malware-directly-through-windows-terminal-and-powershell</link>
                                                                            <description>
                            <![CDATA[ Microsoft is calling it "TerminalFix" and says it is used to deliver "complex, multi-line scripts". ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XjNSaZ8GDPSYkPbNvjqpdU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 09:54:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns of TerminalFix, a campaign abusing compromised sites with fake Cloudflare CAPTCHAs</strong></li><li><strong>Victims paste malicious PowerShell commands, sideloading DLLs and deploying a Python implant</strong></li><li><strong>Implant enables encrypted reverse tunnels, giving attackers pivot access into internal networks</strong></li></ul><p>Security researchers from Microsoft are warning of an ongoing malicious campaign that uses compromised websites to trick users into installing a powerful <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">backdoor</a>.</p><p>Whenever people visited any of the tainted websites, they would see a custom overlay instructing them to complete a fake Cloudflare CAPTCHA verification by copying and running a malicious PowerShell command into Terminal, or PowerShell. Microsoft named the campaign “TerminalFix”, since it is rather similar to the classic ClickFix attack. </p><p>“While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully,” the researchers explained.</p><h2 id="look-for-lateral-movement">Look for lateral movement</h2><p>Unlike classic ClickFix campaigns that try to deliver simple infostealers, TerminalFix tries to deploy a more complex solution. After running the command in the Terminal, the victim would receive two files - a legitimate binary, and a malicious DLL file. The binary would sideload the malicious DLL which, in turn, delivers a hidden payload called “client.py”.</p><p>It is a custom Python implant that creates an encrypted WebSocket connection back to the attackers and gives them SOCKS5-style proxy access into the victim’s internal network. </p><p>In other words, the attackers are deploying a remote-access/network tunneling implant that can connect to internal machines, probe domain controllers, run commands, maintain access after reboots and ultimately use the compromised machine as a pivot point for lateral movement. </p><p>“This type of intrusion is particularly dangerous because it provides attackers with direct access to an organization’s internal network through the reverse tunnel,” Microsoft explained. “The observed reconnaissance and reverse-tunnel capability could enable an attacker to identify and reach additional systems from a compromised host.”</p><p>Microsoft did not observe the attackers actually carrying out lateral movement, so it is difficult to say what they’re using the access for. Still, the researchers are urging caution:</p><p>“Organizations should treat affected devices as potential network pivot points and investigate for lateral movement and credential exposure. In the hands-on-keyboard phase that typically follows, attackers leverage this access to escalate privileges, disable security controls, exfiltrate sensitive data, and deploy ransomware across the organization.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Overcoming the biggest blocker to AI production ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Autonomous AI agents are already running inside core infrastructure –  executing code, applying policies, and managing <a href="https://www.techradar.com/best/best-devops-tools">DevOps</a> functions. And the projects keep stalling, because the security models they’re being wired into were built for a world that no longer exists.</p><p>Retrofitting non-deterministic actors into those models is costing engineers time they don’t have, and it introduces risk no enterprise can manage.</p><p>Many projects have stalled amid concerns about deploying without a robust security foundation – and with good reason. We’ve already seen an agent delete a company’s entire production database, and its backups, in nine seconds. <a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> teams are being asked to stop scenarios like that with tools built for a world of two actors. The cracks are starting to show. Something has to change, or innovation stalls under the weight of its own controls.</p><h2 id="ai-agents-require-a-new-identity-model">AI agents require a new identity model</h2><p>The pressure on production and engineering teams to speed up delivery is very real and pervasive. So they often fall back on old habits like granting agents broad privileges and treating them as any other microservice.</p><p>But agents are very different from machines; they are error-prone and non-deterministic, just like humans. Yet, operating at machine speed, 24/7. Agents can delete entire production <a href="https://www.techradar.com/best/best-database-software">databases</a> in nine seconds. How many humans do you know who could do that?</p><p>And this brings me to the crux of the problem. <a href="https://www.techradar.com/best/best-identity-theft-protectionn">Identity</a> systems were built for a world with two kinds of actors – humans and machines – but there are now three. Trying to fit agentic AI into outdated systems makes each agent a potential source of compromise, and one that can execute thousands of actions across infrastructure in seconds.</p><p>Yet this is what engineers are asked to do; stop catastrophic scenarios with legacy IAM tools that are breaking down. The cracks are starting to show. </p><h2 id="why-the-old-model-breaks">Why the old model breaks</h2><p>Historically, identity fragmentation has plagued engineers working with Kubernetes clusters, cloud platforms, container orchestration, CI/CD pipelines, databases, etc.</p><p>For a human workforce, this was manageable. Humans are trackable; they log in and log out. They are slow enough that visibility gaps rarely turn into immediate incidents.   </p><p>Enter agentic AI, and the speed gets turned up to the max. Suddenly, teams are inundated with thousands of activity logs, and they lack the ability to effectively contain the agent before it executes unauthorized changes.</p><p>Trying to enforce strong <a href="https://www.techradar.com/best/best-authenticator-apps">authentication</a> and short-lived privileges would mean building individual integrations for every tool in the stack. It makes AI hard to scale when each tool uses a different integration protocol.</p><p>Rather than focusing on innovating with agentic AI, engineers are forced to stitch together IAM, infrastructure, and secrets by hand — with no consistent identity, no visibility into agent actions, and every team building its own container or VM workflows from scratch.</p><p>But creating a new tool to handle a third identity type is the worst reaction the industry could have. It would double the work for engineers, as they would need to rebuild the identity policy from the ground up and introduce greater anonymity. A new identity silo is anonymous to other siloed systems, making it even harder to catch attackers.</p><p>This leaves us with the question of how enterprises can control an agent's behavior. The solution isn’t about adding to the tech stack or implementing more tools; it's about changing our identity models to eliminate anonymity entirely. </p><h2 id="ai-control-means-zero-anonymity">AI control means zero anonymity </h2><p>To remove anonymity from <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, enterprises must give every actor –spanning humans, machines, workloads, and AI agents – first-class identities, cryptographically secured by a hardware root of trust.</p><p>Ditch static credentials entirely. Eradicating API keys and passwords eliminates the credential sprawl that causes breaches, as well as the threat of secrets being stolen or handed over to the wrong actors. With identity rooted in real-world factors, attackers cannot impersonate a trusted machine and trick an agent into exfiltrating a database.   </p><p>But strong authentication in itself is not enough. AI agents, like all other actors, need to adhere to zero-trust principles. This can only happen when siloed systems are replaced by an infrastructure layer in which agents have the exact same identity type as the machines they run on and the humans who authorize them.</p><p>Agents should operate with short-lived privileges tied directly to specific actions authorized by a human user. Privilege attached to the action, not the actor. For example, an agent generating code must inherit its mandate from a human owner with matching authority, restricting privileges to only the specific data tables required for that task.</p><p>Non-deterministic actors also require a contained, trusted execution environment before touching production infrastructure.</p><p>With no default privileges, the blast radius is heavily bounded. But this can only be achieved when a single policy is set by a single system for all identities.</p><p>Identity policy can also be introduced as an enforcement layer between the agent and its inference endpoint, so behavior is controlled before instructions are ever executed. </p><h2 id="with-a-unified-architecture-identity-becomes-the-control-plane-for-ai">With a unified architecture, identity becomes the control plane for AI</h2><p>AI agents are unlocking immense opportunities in enterprise environments, especially when deployed in live infrastructure, where they deliver the most value. From managing routine changes to fixing deployments in real-time, the possibilities are endless. Succeeding with AI in such critical <a href="https://www.techradar.com/best/best-small-business-software">business</a> operations requires tight control of behavior.</p><p><em></em><a href="https://www.techradar.com/best/best-ai-tools"><em>We've featured the best AI tool.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/overcoming-the-biggest-blocker-to-ai-production</link>
                                                                            <description>
                            <![CDATA[ Outdated security models stall AI agents, requiring unified, zero-trust identity architectures to prevent catastrophic risks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Wh8cLUUh8vNhNLNBTgsiCM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 09:09:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ev Kontsevoy ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3sXe2REBhnxBXZjEkzwJvh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ev Kontsevoy is the CEO of Teleport, an AI infrastructure Identity company based in Oakland, California. He co-founded the company in 2015 with Aleksandr Klizhentas after a short stint as Director of Product at Rackspace after the latter acquired email delivery service specialist, Mailgun, in 2012. Ev has a Bachelor of Science in Applied Mathematics from Krasnoyarsk State University.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Autonomous AI agents are already running inside core infrastructure –  executing code, applying policies, and managing <a href="https://www.techradar.com/best/best-devops-tools">DevOps</a> functions. And the projects keep stalling, because the security models they’re being wired into were built for a world that no longer exists.</p><p>Retrofitting non-deterministic actors into those models is costing engineers time they don’t have, and it introduces risk no enterprise can manage.</p><p>Many projects have stalled amid concerns about deploying without a robust security foundation – and with good reason. We’ve already seen an agent delete a company’s entire production database, and its backups, in nine seconds. <a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> teams are being asked to stop scenarios like that with tools built for a world of two actors. The cracks are starting to show. Something has to change, or innovation stalls under the weight of its own controls.</p><h2 id="ai-agents-require-a-new-identity-model">AI agents require a new identity model</h2><p>The pressure on production and engineering teams to speed up delivery is very real and pervasive. So they often fall back on old habits like granting agents broad privileges and treating them as any other microservice.</p><p>But agents are very different from machines; they are error-prone and non-deterministic, just like humans. Yet, operating at machine speed, 24/7. Agents can delete entire production <a href="https://www.techradar.com/best/best-database-software">databases</a> in nine seconds. How many humans do you know who could do that?</p><p>And this brings me to the crux of the problem. <a href="https://www.techradar.com/best/best-identity-theft-protectionn">Identity</a> systems were built for a world with two kinds of actors – humans and machines – but there are now three. Trying to fit agentic AI into outdated systems makes each agent a potential source of compromise, and one that can execute thousands of actions across infrastructure in seconds.</p><p>Yet this is what engineers are asked to do; stop catastrophic scenarios with legacy IAM tools that are breaking down. The cracks are starting to show. </p><h2 id="why-the-old-model-breaks">Why the old model breaks</h2><p>Historically, identity fragmentation has plagued engineers working with Kubernetes clusters, cloud platforms, container orchestration, CI/CD pipelines, databases, etc.</p><p>For a human workforce, this was manageable. Humans are trackable; they log in and log out. They are slow enough that visibility gaps rarely turn into immediate incidents.   </p><p>Enter agentic AI, and the speed gets turned up to the max. Suddenly, teams are inundated with thousands of activity logs, and they lack the ability to effectively contain the agent before it executes unauthorized changes.</p><p>Trying to enforce strong <a href="https://www.techradar.com/best/best-authenticator-apps">authentication</a> and short-lived privileges would mean building individual integrations for every tool in the stack. It makes AI hard to scale when each tool uses a different integration protocol.</p><p>Rather than focusing on innovating with agentic AI, engineers are forced to stitch together IAM, infrastructure, and secrets by hand — with no consistent identity, no visibility into agent actions, and every team building its own container or VM workflows from scratch.</p><p>But creating a new tool to handle a third identity type is the worst reaction the industry could have. It would double the work for engineers, as they would need to rebuild the identity policy from the ground up and introduce greater anonymity. A new identity silo is anonymous to other siloed systems, making it even harder to catch attackers.</p><p>This leaves us with the question of how enterprises can control an agent's behavior. The solution isn’t about adding to the tech stack or implementing more tools; it's about changing our identity models to eliminate anonymity entirely. </p><h2 id="ai-control-means-zero-anonymity">AI control means zero anonymity </h2><p>To remove anonymity from <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, enterprises must give every actor –spanning humans, machines, workloads, and AI agents – first-class identities, cryptographically secured by a hardware root of trust.</p><p>Ditch static credentials entirely. Eradicating API keys and passwords eliminates the credential sprawl that causes breaches, as well as the threat of secrets being stolen or handed over to the wrong actors. With identity rooted in real-world factors, attackers cannot impersonate a trusted machine and trick an agent into exfiltrating a database.   </p><p>But strong authentication in itself is not enough. AI agents, like all other actors, need to adhere to zero-trust principles. This can only happen when siloed systems are replaced by an infrastructure layer in which agents have the exact same identity type as the machines they run on and the humans who authorize them.</p><p>Agents should operate with short-lived privileges tied directly to specific actions authorized by a human user. Privilege attached to the action, not the actor. For example, an agent generating code must inherit its mandate from a human owner with matching authority, restricting privileges to only the specific data tables required for that task.</p><p>Non-deterministic actors also require a contained, trusted execution environment before touching production infrastructure.</p><p>With no default privileges, the blast radius is heavily bounded. But this can only be achieved when a single policy is set by a single system for all identities.</p><p>Identity policy can also be introduced as an enforcement layer between the agent and its inference endpoint, so behavior is controlled before instructions are ever executed. </p><h2 id="with-a-unified-architecture-identity-becomes-the-control-plane-for-ai">With a unified architecture, identity becomes the control plane for AI</h2><p>AI agents are unlocking immense opportunities in enterprise environments, especially when deployed in live infrastructure, where they deliver the most value. From managing routine changes to fixing deployments in real-time, the possibilities are endless. Succeeding with AI in such critical <a href="https://www.techradar.com/best/best-small-business-software">business</a> operations requires tight control of behavior.</p><p><em></em><a href="https://www.techradar.com/best/best-ai-tools"><em>We've featured the best AI tool.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How did Iran manage to knock a UK power generator offline for four days, and what does it mean for other critical infrastructure? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Just days before the FBI issued a warning over Iranian attempts to hack critical infrastructure in the US, a UK power generation plant was taken offline for four days after a cyberattack.</p><p>The attack has been attributed to Iran, which has stepped up its offensive cyber warfare efforts since the US and Israel began conducting strikes in February 2026. These cyberattacks have been largely focused on the US and its allies.</p><p>A UK government spokesperson responded to the attack, stating, “This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system. The U.K. has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards,” (via <a href="https://www.cnbc.com/2026/08/23/small-uk-power-plant-shut-down-after-iran-linked-cyberattack-report.html"><em>CNBC</em></a>).</p><h2 id="the-wider-impact-for-critical-infrastructure">The wider impact for critical infrastructure</h2><p>While the attack may have only targeted a ‘small-scale energy generator’, it shows that state-sponsored groups are actively attempting to disrupt UK energy production in any way they can, regardless of how much power it provides.</p><p>As has been made abundantly clear in the US, much of the world’s major critical infrastructure relies on small network-enabled operation technology (OT) components.</p><p>If OT devices have passed their end-of-life and no longer receive software updates, or have simply been misconfigured, these devices can show up on the internet to a hacker looking for a way into a protected network.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>The UK has taken very careful steps to shield these devices from the internet to prevent them being used to access critical infrastructure, but it only takes a single internet-facing OT to cause issues.</p><p>Following the aftermath of the attack, the UK’s National Cyber Security Centre has issued new guidance on protecting OT devices from state-sponsored threats.</p><p>In its <a href="https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices" target="_blank" rel="nofollow">guidance</a>, the NCSC said “the threat from state use of offensive cyber, including outside of conflict, has almost certainly increased.”</p><p>So what do the experts think the attack means for critical infrastructure, the UK, and the wider world?</p><h3 class="article-body__section" id="section-expert-perspectives-on-uk-powerplant-attack"><span>Expert perspectives on UK powerplant attack</span></h3><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA, Huntress:</strong></li></ul><p><em>Attackers don’t care whether an energy operator is large enough to meet a reporting threshold. If it can be disrupted, it can be targeted. The significance isn’t the size of the facility, but that a cyberattack turned into four days of real-world operational disruption.</em></p><div><blockquote><p>Why did recovery take four days, and are smaller operators adequately prepared to contain and recover from these incidents?</p></blockquote></div><p><em>That raises an important question: why did recovery take four days, and are smaller operators adequately prepared to contain and recover from these incidents?</em></p><p><em>There is also a potential visibility gap. If smaller energy operators fall outside mandatory cyber-reporting thresholds, we risk underestimating how frequently this part of our infrastructure is being targeted or successfully compromised.</em></p><p><em>Critical infrastructure security cannot stop with the organisations considered large enough to be critical. Attackers will look for the weakest route in, so resilience, monitoring and rehearsed recovery need to extend across the wider energy ecosystem.</em></p><p><em>The real measure of cyber resilience is no longer simply whether you can prevent an intrusion. It’s whether you can contain one quickly enough that a cyber incident doesn’t become an operational crisis</em></p><ul><li><strong>Graeme Stewart, head of public sector, Check Point:</strong></li></ul><p><em>This marks a grave escalation in the Iran conflict because a hostile state-linked cyber threat has reportedly reached into UK energy infrastructure and caused a physical shutdown lasting four days. That should concern every organisation responsible for keeping this country running. The fact that this was a relatively small generator and the wider grid was unaffected does not remove the threat. The far more serious point is what the attackers appear to have demonstrated: an ability to get inside.</em></p><div><blockquote><p>The far more serious point is what the attackers appear to have demonstrated: an ability to get inside</p></blockquote></div><p><em>UK energy infrastructure and stop it working. We have to ask what happens if the next target is bigger, more critical or more deeply connected to the services millions of people rely on. Britain’s Critical National Infrastructure underpins almost every part of modern life, including electricity, water, transport and communications, and those systems are increasingly digital, interconnected and dependent on one another. A serious attack on one part of that ecosystem has the potential to cause disruption far beyond the original target.</em></p><p><em>For most Brits, the Iran conflict is happening thousands of miles away and cyber warfare probably still conjures up images of stolen passwords, leaked data and companies being held to ransom. The prospect of a hostile state being able to reach into the infrastructure beneath our everyday lives changes that dramatically, because suddenly an international conflict has a potential route to our front doors through the power we use, the water we depend on and the networks that keep us connected. We also need to consider whether causing widespread disruption was ever the objective here. If this attack was intended to demonstrate that Iranian-linked hackers can penetrate UK infrastructure and cause real-world consequences, then the significance isn't measured by the size of the generator they managed to shut down, but by what they have demonstrated may be possible.</em></p><p><em>The question now has to be whether Britain is genuinely ready if something more serious follows. We cannot build our resilience around the assumption that every attacker will be stopped at the door, particularly when we have just seen reports of one getting through. Operators of essential services need to know exactly how they keep functioning when systems are compromised, how quickly an attack can be contained and how they recover without allowing disruption to spread. Cybersecurity is rapidly becoming about something much bigger than protecting information. It is about protecting the systems that allow a modern country to function and finding out how resilient those systems are during a major attack would be far too late</em></p><ul><li><strong>Matt Caswell, Executive Director, OpenSSL Foundation and Principal Software Engineer:</strong></li></ul><p><em>An attack that can take part of the UK’s power infrastructure offline is a reminder that cyber resilience is about more than protecting the organisation at the front of the incident. We also need to understand the technology and dependencies sitting underneath critical services.</em></p><div><blockquote><p>Regulation can improve security practices, but resilient infrastructure depends on understanding and sustaining the software it relies on.</p></blockquote></div><p><em>Modern infrastructure contains layers of software from different suppliers and open-source projects. Organisations need enough visibility to know which dependencies really matter before an attack happens, so they can understand their exposure and respond quickly when something goes wrong.</em></p><p><em>For the UK, this is also a wider resilience question. Regulation can improve security practices, but resilient infrastructure depends on understanding and sustaining the software it relies on. That needs to be part of the conversation about how we protect essential services.</em></p><ul><li><strong>Tim Williams, CEO, Quod Orbis:</strong></li></ul><p><em>The fact that this attack was contained to a small-scale generator and did not threaten the wider energy system should not obscure the significance of what has happened. The real warning is that a hostile actor was able to disrupt a piece of the UK’s energy infrastructure in the first place.</em></p><div><blockquote><p>The fact that this attack was contained to a small-scale generator and did not threaten the wider energy system should not obscure the significance of what has happened.</p></blockquote></div><p><em>Avoiding a major outage is all well and good, but it shouldn’t be seen as the success metric for true cyber resilience. The real measure of cyber resilience isn't whether an organisation has controls documented in a framework. It's whether it can continuously demonstrate that those controls are working when they matter most, identifying control weaknesses before they are exploited and become operational incidents.</em></p><p><em>As geopolitical tensions increase, organisations need to assume that cyber attacks are potential business continuity events and ones that are capable of impacting far more than the businesses themselves. Critical national infrastructure such as electricity, power and water are likely to be the targets for more attacks so resilience will really depend on knowing, in real time, whether the controls designed to protect critical operations are actually working, and having clear accountability when they are not.</em></p><p><em>Reactive incident response is important but it’s not enough. Continuous assurance needs to become part of how organisations manage operational resilience, particularly as state-linked actors increasingly look for ways to exploit the digital systems underpinning essential services</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/how-did-iran-manage-to-knock-a-uk-power-generator-offline-for-four-days-and-what-does-it-mean-for-other-critical-infrastructure-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ NCSC issues new warning over OT and edge devices ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aUtdB9McAGHuKssaSt2NeX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/E6e47o4bL6CgppNM5Byt5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 31 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/E6e47o4bL6CgppNM5Byt5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Electrical pylons and high voltage power lines are behind a barbed wire fence. critical infrastructure]]></media:description>                                                            <media:text><![CDATA[Electrical pylons and high voltage power lines are behind a barbed wire fence. critical infrastructure]]></media:text>
                                <media:title type="plain"><![CDATA[Electrical pylons and high voltage power lines are behind a barbed wire fence. critical infrastructure]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/E6e47o4bL6CgppNM5Byt5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Just days before the FBI issued a warning over Iranian attempts to hack critical infrastructure in the US, a UK power generation plant was taken offline for four days after a cyberattack.</p><p>The attack has been attributed to Iran, which has stepped up its offensive cyber warfare efforts since the US and Israel began conducting strikes in February 2026. These cyberattacks have been largely focused on the US and its allies.</p><p>A UK government spokesperson responded to the attack, stating, “This story refers to an incident impacting a small-scale energy generator, and at no point was there a risk to the wider energy system. The U.K. has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards,” (via <a href="https://www.cnbc.com/2026/08/23/small-uk-power-plant-shut-down-after-iran-linked-cyberattack-report.html"><em>CNBC</em></a>).</p><h2 id="the-wider-impact-for-critical-infrastructure">The wider impact for critical infrastructure</h2><p>While the attack may have only targeted a ‘small-scale energy generator’, it shows that state-sponsored groups are actively attempting to disrupt UK energy production in any way they can, regardless of how much power it provides.</p><p>As has been made abundantly clear in the US, much of the world’s major critical infrastructure relies on small network-enabled operation technology (OT) components.</p><p>If OT devices have passed their end-of-life and no longer receive software updates, or have simply been misconfigured, these devices can show up on the internet to a hacker looking for a way into a protected network.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>The UK has taken very careful steps to shield these devices from the internet to prevent them being used to access critical infrastructure, but it only takes a single internet-facing OT to cause issues.</p><p>Following the aftermath of the attack, the UK’s National Cyber Security Centre has issued new guidance on protecting OT devices from state-sponsored threats.</p><p>In its <a href="https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices" target="_blank" rel="nofollow">guidance</a>, the NCSC said “the threat from state use of offensive cyber, including outside of conflict, has almost certainly increased.”</p><p>So what do the experts think the attack means for critical infrastructure, the UK, and the wider world?</p><h3 class="article-body__section" id="section-expert-perspectives-on-uk-powerplant-attack"><span>Expert perspectives on UK powerplant attack</span></h3><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA, Huntress:</strong></li></ul><p><em>Attackers don’t care whether an energy operator is large enough to meet a reporting threshold. If it can be disrupted, it can be targeted. The significance isn’t the size of the facility, but that a cyberattack turned into four days of real-world operational disruption.</em></p><div><blockquote><p>Why did recovery take four days, and are smaller operators adequately prepared to contain and recover from these incidents?</p></blockquote></div><p><em>That raises an important question: why did recovery take four days, and are smaller operators adequately prepared to contain and recover from these incidents?</em></p><p><em>There is also a potential visibility gap. If smaller energy operators fall outside mandatory cyber-reporting thresholds, we risk underestimating how frequently this part of our infrastructure is being targeted or successfully compromised.</em></p><p><em>Critical infrastructure security cannot stop with the organisations considered large enough to be critical. Attackers will look for the weakest route in, so resilience, monitoring and rehearsed recovery need to extend across the wider energy ecosystem.</em></p><p><em>The real measure of cyber resilience is no longer simply whether you can prevent an intrusion. It’s whether you can contain one quickly enough that a cyber incident doesn’t become an operational crisis</em></p><ul><li><strong>Graeme Stewart, head of public sector, Check Point:</strong></li></ul><p><em>This marks a grave escalation in the Iran conflict because a hostile state-linked cyber threat has reportedly reached into UK energy infrastructure and caused a physical shutdown lasting four days. That should concern every organisation responsible for keeping this country running. The fact that this was a relatively small generator and the wider grid was unaffected does not remove the threat. The far more serious point is what the attackers appear to have demonstrated: an ability to get inside.</em></p><div><blockquote><p>The far more serious point is what the attackers appear to have demonstrated: an ability to get inside</p></blockquote></div><p><em>UK energy infrastructure and stop it working. We have to ask what happens if the next target is bigger, more critical or more deeply connected to the services millions of people rely on. Britain’s Critical National Infrastructure underpins almost every part of modern life, including electricity, water, transport and communications, and those systems are increasingly digital, interconnected and dependent on one another. A serious attack on one part of that ecosystem has the potential to cause disruption far beyond the original target.</em></p><p><em>For most Brits, the Iran conflict is happening thousands of miles away and cyber warfare probably still conjures up images of stolen passwords, leaked data and companies being held to ransom. The prospect of a hostile state being able to reach into the infrastructure beneath our everyday lives changes that dramatically, because suddenly an international conflict has a potential route to our front doors through the power we use, the water we depend on and the networks that keep us connected. We also need to consider whether causing widespread disruption was ever the objective here. If this attack was intended to demonstrate that Iranian-linked hackers can penetrate UK infrastructure and cause real-world consequences, then the significance isn't measured by the size of the generator they managed to shut down, but by what they have demonstrated may be possible.</em></p><p><em>The question now has to be whether Britain is genuinely ready if something more serious follows. We cannot build our resilience around the assumption that every attacker will be stopped at the door, particularly when we have just seen reports of one getting through. Operators of essential services need to know exactly how they keep functioning when systems are compromised, how quickly an attack can be contained and how they recover without allowing disruption to spread. Cybersecurity is rapidly becoming about something much bigger than protecting information. It is about protecting the systems that allow a modern country to function and finding out how resilient those systems are during a major attack would be far too late</em></p><ul><li><strong>Matt Caswell, Executive Director, OpenSSL Foundation and Principal Software Engineer:</strong></li></ul><p><em>An attack that can take part of the UK’s power infrastructure offline is a reminder that cyber resilience is about more than protecting the organisation at the front of the incident. We also need to understand the technology and dependencies sitting underneath critical services.</em></p><div><blockquote><p>Regulation can improve security practices, but resilient infrastructure depends on understanding and sustaining the software it relies on.</p></blockquote></div><p><em>Modern infrastructure contains layers of software from different suppliers and open-source projects. Organisations need enough visibility to know which dependencies really matter before an attack happens, so they can understand their exposure and respond quickly when something goes wrong.</em></p><p><em>For the UK, this is also a wider resilience question. Regulation can improve security practices, but resilient infrastructure depends on understanding and sustaining the software it relies on. That needs to be part of the conversation about how we protect essential services.</em></p><ul><li><strong>Tim Williams, CEO, Quod Orbis:</strong></li></ul><p><em>The fact that this attack was contained to a small-scale generator and did not threaten the wider energy system should not obscure the significance of what has happened. The real warning is that a hostile actor was able to disrupt a piece of the UK’s energy infrastructure in the first place.</em></p><div><blockquote><p>The fact that this attack was contained to a small-scale generator and did not threaten the wider energy system should not obscure the significance of what has happened.</p></blockquote></div><p><em>Avoiding a major outage is all well and good, but it shouldn’t be seen as the success metric for true cyber resilience. The real measure of cyber resilience isn't whether an organisation has controls documented in a framework. It's whether it can continuously demonstrate that those controls are working when they matter most, identifying control weaknesses before they are exploited and become operational incidents.</em></p><p><em>As geopolitical tensions increase, organisations need to assume that cyber attacks are potential business continuity events and ones that are capable of impacting far more than the businesses themselves. Critical national infrastructure such as electricity, power and water are likely to be the targets for more attacks so resilience will really depend on knowing, in real time, whether the controls designed to protect critical operations are actually working, and having clear accountability when they are not.</em></p><p><em>Reactive incident response is important but it’s not enough. Continuous assurance needs to become part of how organisations manage operational resilience, particularly as state-linked actors increasingly look for ways to exploit the digital systems underpinning essential services</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to solve agent sprawl ]]></title>
                                                                                                <dc:content><![CDATA[ <p>For anyone working in IT and familiar with SaaS sprawl, the idea we’ll soon end up with agent sprawl may set off alarm bells. Agent sprawl refers to the rapid, uncoordinated deployment of AI agents across departments, each built on different models, governed by different rules, and often disconnected from core <a href="https://www.techradar.com/best/best-small-business-software">business</a> workflows. </p><p>But while SaaS sprawl caught enterprises off guard, this time organizations have no excuse, and need to put measures in place now to avoid repeating the same mistakes. However, right now, most organizations are building agents in isolation and optimizing for local <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> rather than enterprise value.</p><p>Thankfully, with the right control layer funneling every agent through the same governance and <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> standards within an organization, the agent-powered future can be far safer, scalable and simple.  </p><h2 id="agent-sprawl-is-inevitable">Agent sprawl is inevitable </h2><p>Just like SaaS before it, agent sprawl is already happening. Each department within organizations is experimenting with different agent technologies to address specific challenges or work more efficiently.</p><p>A sales team may deploy a <a href="https://www.techradar.com/best/the-best-crm-software">CRM</a>-based AI assistant to qualify leads, while developers build their own coding agents, and marketing adopts a separate content generation tool. Each delivers local value, but none are aligned or connected to the other, creating a familiar-looking sprawl.</p><p>This fragmentation introduces a range of challenges that will only increase over time. With no single owner responsible for how agents are deployed or monitored, there’s a lack of governance and oversight. Security risks increase as agents gain access to sensitive systems without consistent controls.</p><p>Teams may unknowingly duplicate efforts, solving the same problems in parallel with different tools. At the same time, many agents are deployed without clear links to business outcomes or understanding the wider context, making it difficult to measure return on investment and distinguish meaningful innovation from experimentation. Lots of <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> may be exciting, but deliver far more style than substance.  </p><p>Is sprawl inevitable? Yes, probably. So the question now becomes, how do we control it? </p><h2 id="the-role-of-orchestration">The role of orchestration</h2><p>Having an orchestration layer can bring order to this complexity by creating consistency in how agents are governed, secured and deployed across the business. For SaaS applications, orchestration provides visibility into what tools already exist and gives a clear view of enterprise workflows.</p><p>With agents, it outlines what agents are already available and how they operate, while also controlling how they access data, tools and existing technology. Orchestration is the critical element that turns agents from experiments into scalable business <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, for example, assigning agents to business workflows and measuring their performance against real outcomes.</p><p>Too often, we see enterprises experimenting with different agents that have no connection to the core business processes and goals, meaning they fail to deliver any ROI. For example, some portions of a business simply do not require AI technology and will unlikely see benefits in the same way as another department. Orchestration can unearth and filter out agents that are unnecessary, saving businesses money.  </p><h2 id="building-trust-in-ai-driven-enterprise">Building trust in AI-driven enterprise </h2><p>Rather than trusting individual agents, organizations should focus on trusting the system that governs them.</p><p>This is where orchestration becomes a trust layer, ensuring every agent operates within clearly defined boundaries with consistent oversight and accountability. Instead of individual teams managing risk in siloes, organizations can centralize control while still enabling innovation across different departments and business functions.</p><p>In the same way orchestration brought order to SaaS sprawl, it can do the same for the next wave of enterprise AI. It brings the same ease, security and integration with existing SaaS tools, while ensuring only high-value agents make it into production, supporting innovation and keeping within the business goals and purpose.</p><p>As agents become embedded across every function, orchestration will shift from a technical layer to a core enterprise capability. The winners will be those who can control, connect and trust their agents at scale.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/how-to-solve-agent-sprawl</link>
                                                                            <description>
                            <![CDATA[ While SaaS sprawl caught enterprises off guard, this time organizations have no excuse when it comes to Agent Sprawl, and need to put measures in place now to avoid repeating the same mistakes. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XjGb663Yw2gRy9L5UgTspN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 31 Aug 2026 10:49:39 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Derek Thompson ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ogvAEqnJgXGJGDvAiPT7Xo.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A line of robots typing at computers]]></media:description>                                                            <media:text><![CDATA[A line of robots typing at computers]]></media:text>
                                <media:title type="plain"><![CDATA[A line of robots typing at computers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For anyone working in IT and familiar with SaaS sprawl, the idea we’ll soon end up with agent sprawl may set off alarm bells. Agent sprawl refers to the rapid, uncoordinated deployment of AI agents across departments, each built on different models, governed by different rules, and often disconnected from core <a href="https://www.techradar.com/best/best-small-business-software">business</a> workflows. </p><p>But while SaaS sprawl caught enterprises off guard, this time organizations have no excuse, and need to put measures in place now to avoid repeating the same mistakes. However, right now, most organizations are building agents in isolation and optimizing for local <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> rather than enterprise value.</p><p>Thankfully, with the right control layer funneling every agent through the same governance and <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> standards within an organization, the agent-powered future can be far safer, scalable and simple.  </p><h2 id="agent-sprawl-is-inevitable">Agent sprawl is inevitable </h2><p>Just like SaaS before it, agent sprawl is already happening. Each department within organizations is experimenting with different agent technologies to address specific challenges or work more efficiently.</p><p>A sales team may deploy a <a href="https://www.techradar.com/best/the-best-crm-software">CRM</a>-based AI assistant to qualify leads, while developers build their own coding agents, and marketing adopts a separate content generation tool. Each delivers local value, but none are aligned or connected to the other, creating a familiar-looking sprawl.</p><p>This fragmentation introduces a range of challenges that will only increase over time. With no single owner responsible for how agents are deployed or monitored, there’s a lack of governance and oversight. Security risks increase as agents gain access to sensitive systems without consistent controls.</p><p>Teams may unknowingly duplicate efforts, solving the same problems in parallel with different tools. At the same time, many agents are deployed without clear links to business outcomes or understanding the wider context, making it difficult to measure return on investment and distinguish meaningful innovation from experimentation. Lots of <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> may be exciting, but deliver far more style than substance.  </p><p>Is sprawl inevitable? Yes, probably. So the question now becomes, how do we control it? </p><h2 id="the-role-of-orchestration">The role of orchestration</h2><p>Having an orchestration layer can bring order to this complexity by creating consistency in how agents are governed, secured and deployed across the business. For SaaS applications, orchestration provides visibility into what tools already exist and gives a clear view of enterprise workflows.</p><p>With agents, it outlines what agents are already available and how they operate, while also controlling how they access data, tools and existing technology. Orchestration is the critical element that turns agents from experiments into scalable business <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, for example, assigning agents to business workflows and measuring their performance against real outcomes.</p><p>Too often, we see enterprises experimenting with different agents that have no connection to the core business processes and goals, meaning they fail to deliver any ROI. For example, some portions of a business simply do not require AI technology and will unlikely see benefits in the same way as another department. Orchestration can unearth and filter out agents that are unnecessary, saving businesses money.  </p><h2 id="building-trust-in-ai-driven-enterprise">Building trust in AI-driven enterprise </h2><p>Rather than trusting individual agents, organizations should focus on trusting the system that governs them.</p><p>This is where orchestration becomes a trust layer, ensuring every agent operates within clearly defined boundaries with consistent oversight and accountability. Instead of individual teams managing risk in siloes, organizations can centralize control while still enabling innovation across different departments and business functions.</p><p>In the same way orchestration brought order to SaaS sprawl, it can do the same for the next wave of enterprise AI. It brings the same ease, security and integration with existing SaaS tools, while ensuring only high-value agents make it into production, supporting innovation and keeping within the business goals and purpose.</p><p>As agents become embedded across every function, orchestration will shift from a technical layer to a core enterprise capability. The winners will be those who can control, connect and trust their agents at scale.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Shadow AI is a security problem, but the EU AI Act makes it a legal one ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The most damaging AI-related <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> incident your organization faces this year probably won't originate from external attackers using sophisticated new models. It's far more likely to begin with an employee pasting a client contract, a financial forecast, or a set of HR records into an <a href="https://www.techradar.com/best/best-ai-tools">AI tool</a> because it makes their job easier and nobody has told them why it matters. </p><p>Shadow AI is a growing problem, and our research found that nearly half of employees at larger enterprises regularly feed corporate data into AI tools that nobody in IT has approved or governs.</p><p>More striking still, 85% of <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employees</a> continue doing so even when company-sanctioned tools are available, pointing to a governance failure that runs all the way to the executive suite. With shadow AI, sensitive data can move silently outward through channels most security stacks were never designed to intercept.  </p><p>Adding to the security risk of this unmonitored data flow, the advent of the EU AI Act also means organizations now face specific legal demands on managing AI use. The ability to have full governance over how AI is deployed, governed and monitored, is becoming a regulatory, as well as a security, imperative. </p><h2 id="why-the-eu-ai-act-makes-this-a-board-level-problem">Why the EU AI Act makes this a board-level problem</h2><p>Shadow AI represents a serious security issue, with IBM's 2026 Cost of a Data Breach report estimating that unauthorized tools contributed to 43% of breaches over the last year Now, the EU AI Act is adding significant regulatory requirements on top of these risks.</p><p>The Act's obligations have rolled out in phases; most recently, organizations classified as general deployers of AI have new inventory, <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> governance, audit logging and transparency obligations as of 2nd August 2026.</p><p>Other deadlines have shifted further ahead, with controls over high-risk AI usage, covering areas like recruitment, credit scoring and biometric categorization, set to come into force from 2nd December 2027. AI embedded in regulated products will be covered from 2nd August 2028.</p><p>Any organization whose employees use AI systems now has compliance obligations as a deployer, regardless of whether those systems were formally sanctioned. </p><p>All organizations using AI should be aware that the AI literacy obligation under Article 4 has been enforceable since February 2025, meaning organizations are on the hook for ensuring their employees are aware of safe and sanctioned AI use.</p><p>Rules around high-risk AI usage will also apply to more operations than it may seem at first, including an employee using an unapproved consumer tool for tasks like screening CVs, assessing creditworthiness, and evaluating performance.</p><p>These are common tasks that could trigger the full weight of the Act's oversight against a system that the IT department didn’t even know had been deployed.</p><p>With penalties reaching up to €15 million or 3% of global annual turnover for high-risk breaches, many organizations are carrying more exposure than they realize. </p><h2 id="why-your-existing-security-stack-can-39-t-see-it">Why your existing security stack can't see it</h2><p>The challenge with shadow AI is that it exploits the blind spots between conventional security layers, slipping through gaps that most tools were never designed to close.  </p><p>CASBs and secure web gateways cannot decrypt conversational data flowing to legitimate LLM domains over HTTPS, for example. From the network's perspective, a prompt containing a full <a href="https://www.techradar.com/best/the-best-customer-database-software-of-year">customer database</a> is indistinguishable from any other encrypted web session. Browser extensions are limited to managed endpoints, blind to personal devices and AI embedded within approved SaaS.</p><p>Likewise, API gateways are usually built around authorized enterprise deployments, which means they capture the AI activity organizations have already approved while missing the consumer-grade AI tools driving most risk.</p><p>These blind spots compound with each other, so an organization running all three layers may still have no visibility into AI activity across a significant portion of its estate, and no means of generating the interaction logs or policy enforcement evidence the Act requires.</p><h2 id="what-good-ai-detection-looks-like">What good AI detection looks like</h2><p>Controlling AI data flows is usually managed by workers performing their duties without malicious intent. However, it’s remarkably similar to defending against an external threat actor covertly accessing your data.</p><p>The detection logic needs to match that reality. <a href="https://www.techradar.com/news/best-endpoint-security-software">Endpoint</a>-native detection intercepts sensitive data at the point of movement before it reaches an external AI system, enforcing policy at the prompt level across managed and unmanaged browsers, personal devices, and AI functionality embedded within SaaS tools. It operates where the activity occurs, rather than attempting to catch it downstream.</p><p>Given the scale of the potential fines, the ability to prove compliance matters almost as much as preventing security breaches.</p><p>Continuous discovery across the estate, including any unsanctioned tools gives organizations the AI system inventory the Act requires. </p><p>Granular interaction logs - who used what, when, and what data was involved - satisfy the documentation requirements under Articles 12 and 13, without teams needing to scramble to reconstruct activity after the fact. The same data pinpoints exactly where AI literacy gaps exist, making Article 4 compliance something demonstrable rather than simply asserted.</p><h2 id="practical-steps-for-compliance">Practical steps for compliance </h2><p>Security and compliance teams aiming to comply with the EU AI Act have a clear path to follow.</p><p>The starting point is mapping the full AI estate. Discovery needs to extend beyond IT-approved tools to unmanaged endpoints, personal devices on corporate networks, and AI embedded within SaaS.</p><p>Data governance must move to the endpoint. Policies prohibiting sensitive data sharing with unapproved tools are not technical controls and, by the time enforcement happens at the network edge, the data has already left.</p><p>It’s important to remember that information shared with an external AI system may be retained in prompt logs, incorporated into model training data, or held on servers in jurisdictions the organization has no visibility into. The moment data crosses that boundary, the organization loses control of it entirely, and no policy document will retrieve it.</p><p>And since Article 12 requires interaction records that can be handed to regulators on demand, organizations will need to have continuous, automatic auditing of both activity and security measures.</p><p>Finally, AI literacy programs aimed at improving user awareness should be driven by behavioral data rather than generic training programs. Activity logs showing where governance failures are occurring - at senior leadership level as much as anywhere else - provide both the diagnosis of the issue and the evidence regulators will want to see.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've featured the best antivirus software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/shadow-ai-is-a-security-problem-but-the-eu-ai-act-makes-it-a-legal-one</link>
                                                                            <description>
                            <![CDATA[ Employees at larger enterprises regularly feed corporate data into AI tools. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VFySm8v49B7B3E8Frk3pw5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 31 Aug 2026 09:46:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Darren Williams ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The most damaging AI-related <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> incident your organization faces this year probably won't originate from external attackers using sophisticated new models. It's far more likely to begin with an employee pasting a client contract, a financial forecast, or a set of HR records into an <a href="https://www.techradar.com/best/best-ai-tools">AI tool</a> because it makes their job easier and nobody has told them why it matters. </p><p>Shadow AI is a growing problem, and our research found that nearly half of employees at larger enterprises regularly feed corporate data into AI tools that nobody in IT has approved or governs.</p><p>More striking still, 85% of <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employees</a> continue doing so even when company-sanctioned tools are available, pointing to a governance failure that runs all the way to the executive suite. With shadow AI, sensitive data can move silently outward through channels most security stacks were never designed to intercept.  </p><p>Adding to the security risk of this unmonitored data flow, the advent of the EU AI Act also means organizations now face specific legal demands on managing AI use. The ability to have full governance over how AI is deployed, governed and monitored, is becoming a regulatory, as well as a security, imperative. </p><h2 id="why-the-eu-ai-act-makes-this-a-board-level-problem">Why the EU AI Act makes this a board-level problem</h2><p>Shadow AI represents a serious security issue, with IBM's 2026 Cost of a Data Breach report estimating that unauthorized tools contributed to 43% of breaches over the last year Now, the EU AI Act is adding significant regulatory requirements on top of these risks.</p><p>The Act's obligations have rolled out in phases; most recently, organizations classified as general deployers of AI have new inventory, <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> governance, audit logging and transparency obligations as of 2nd August 2026.</p><p>Other deadlines have shifted further ahead, with controls over high-risk AI usage, covering areas like recruitment, credit scoring and biometric categorization, set to come into force from 2nd December 2027. AI embedded in regulated products will be covered from 2nd August 2028.</p><p>Any organization whose employees use AI systems now has compliance obligations as a deployer, regardless of whether those systems were formally sanctioned. </p><p>All organizations using AI should be aware that the AI literacy obligation under Article 4 has been enforceable since February 2025, meaning organizations are on the hook for ensuring their employees are aware of safe and sanctioned AI use.</p><p>Rules around high-risk AI usage will also apply to more operations than it may seem at first, including an employee using an unapproved consumer tool for tasks like screening CVs, assessing creditworthiness, and evaluating performance.</p><p>These are common tasks that could trigger the full weight of the Act's oversight against a system that the IT department didn’t even know had been deployed.</p><p>With penalties reaching up to €15 million or 3% of global annual turnover for high-risk breaches, many organizations are carrying more exposure than they realize. </p><h2 id="why-your-existing-security-stack-can-39-t-see-it">Why your existing security stack can't see it</h2><p>The challenge with shadow AI is that it exploits the blind spots between conventional security layers, slipping through gaps that most tools were never designed to close.  </p><p>CASBs and secure web gateways cannot decrypt conversational data flowing to legitimate LLM domains over HTTPS, for example. From the network's perspective, a prompt containing a full <a href="https://www.techradar.com/best/the-best-customer-database-software-of-year">customer database</a> is indistinguishable from any other encrypted web session. Browser extensions are limited to managed endpoints, blind to personal devices and AI embedded within approved SaaS.</p><p>Likewise, API gateways are usually built around authorized enterprise deployments, which means they capture the AI activity organizations have already approved while missing the consumer-grade AI tools driving most risk.</p><p>These blind spots compound with each other, so an organization running all three layers may still have no visibility into AI activity across a significant portion of its estate, and no means of generating the interaction logs or policy enforcement evidence the Act requires.</p><h2 id="what-good-ai-detection-looks-like">What good AI detection looks like</h2><p>Controlling AI data flows is usually managed by workers performing their duties without malicious intent. However, it’s remarkably similar to defending against an external threat actor covertly accessing your data.</p><p>The detection logic needs to match that reality. <a href="https://www.techradar.com/news/best-endpoint-security-software">Endpoint</a>-native detection intercepts sensitive data at the point of movement before it reaches an external AI system, enforcing policy at the prompt level across managed and unmanaged browsers, personal devices, and AI functionality embedded within SaaS tools. It operates where the activity occurs, rather than attempting to catch it downstream.</p><p>Given the scale of the potential fines, the ability to prove compliance matters almost as much as preventing security breaches.</p><p>Continuous discovery across the estate, including any unsanctioned tools gives organizations the AI system inventory the Act requires. </p><p>Granular interaction logs - who used what, when, and what data was involved - satisfy the documentation requirements under Articles 12 and 13, without teams needing to scramble to reconstruct activity after the fact. The same data pinpoints exactly where AI literacy gaps exist, making Article 4 compliance something demonstrable rather than simply asserted.</p><h2 id="practical-steps-for-compliance">Practical steps for compliance </h2><p>Security and compliance teams aiming to comply with the EU AI Act have a clear path to follow.</p><p>The starting point is mapping the full AI estate. Discovery needs to extend beyond IT-approved tools to unmanaged endpoints, personal devices on corporate networks, and AI embedded within SaaS.</p><p>Data governance must move to the endpoint. Policies prohibiting sensitive data sharing with unapproved tools are not technical controls and, by the time enforcement happens at the network edge, the data has already left.</p><p>It’s important to remember that information shared with an external AI system may be retained in prompt logs, incorporated into model training data, or held on servers in jurisdictions the organization has no visibility into. The moment data crosses that boundary, the organization loses control of it entirely, and no policy document will retrieve it.</p><p>And since Article 12 requires interaction records that can be handed to regulators on demand, organizations will need to have continuous, automatic auditing of both activity and security measures.</p><p>Finally, AI literacy programs aimed at improving user awareness should be driven by behavioral data rather than generic training programs. Activity logs showing where governance failures are occurring - at senior leadership level as much as anywhere else - provide both the diagnosis of the issue and the evidence regulators will want to see.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've featured the best antivirus software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top AI tools including Claude, Codex, and Hermes installed suspicious code inside corporate networks ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers found unclaimed llms.txt references on 120 domains, exploitable by cybercriminals</strong></li><li><strong>AI agents could install malware if they execute hallucinated or outdated documentation commands</strong></li><li><strong>Fixes: clean documentation and restrict AI agents from treating docs as executable instructions</strong></li></ul><p>Cybercriminals are able to now abuse hallucinated, outdated, and outright incorrect website documentation to deliver malware to unsuspecting victims through <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a>, new research has claimed.</p><p>An increasing number of websites now contain two documents: llms.txt, and llms-full.txt. These are conventions that allow AI agents to properly read the contents of the websites. If an AI agent is looking to install software or add code to a project, they can search through these documents across the web until they find a fitting solution.</p><p>Researcher <a href="https://medium.com/@alonhertz1/data-became-code-we-ran-code-inside-fortune-500s-using-files-they-published-for-ai-agents-0cd67ffbbffc" target="_blank">Alon Hertz</a> analyzed 6,214 live domains belonging to defense contractors, Fortune 500 organizations, as well as big tech. On these domains he  found 8,265 of these .txt files and among them 120 (all on a different site) pointing to one or more code packages and domain names that weren’t registered at all.</p><h2 id="claiming-packages-and-domains">Claiming packages and domains</h2><p>There can be a myriad of reasons why they’re not registered. It can be due to human error, renamed or abandoned packages, copy/paste errors, or hallucinated documentation.</p><p>Now, for the purpose of the experiment, Hertz registered some of these unclaimed names and hosted packages that would phone home when installed. It took less than an hour for a Fortune 500 company to start pinging, and the numbers soon grew to “a few dozen more”. </p><p>This means that if the researchers can do it, so can cybercriminals. In theory, a cybercriminal could find these unclaimed packages and register <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. If an AI agent has permission to execute shell/package-manager commands and stumbles upon this documentation, it can end up infecting the device. </p><p>Claude, OpenAI’s Codex, and Nous Research’s Hermes were all “guilty”, the researchers said. </p><p>To fix the vulnerability, two things need to happen. First, companies need to clean up their documentation and make sure it’s not pointing towards non-existent or malicious content. Second, AI agents need to stop treating documentation as executable instructions. Since the latter most likely isn’t happening any time soon, the immediate answer would probably lie in the former. In the meantime, organizations using AI for coding should consider the risks when granting AI agents permission to execute commands. </p><p><em>Via </em><a href="https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/" target="_blank"><em>Ars Technica</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/top-ai-tools-including-claude-codex-and-hermes-installed-suspicious-code-inside-corporate-networks</link>
                                                                            <description>
                            <![CDATA[ There is a new class of "squatting" risks emerging right in front of us and it involves llms.txt and llms-full.txt documentation. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o8w4UpaZjEpWmoRVVffXRV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Thi6y93AMWrCXJAEiHDQbL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 30 Aug 2026 12:05:00 +0000</pubDate>                                                                                                                                <updated>Mon, 31 Aug 2026 08:59:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Thi6y93AMWrCXJAEiHDQbL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot in front of a digital screen, touching some of the symbols with its outstretched finger]]></media:description>                                                            <media:text><![CDATA[A robot in front of a digital screen, touching some of the symbols with its outstretched finger]]></media:text>
                                <media:title type="plain"><![CDATA[A robot in front of a digital screen, touching some of the symbols with its outstretched finger]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Thi6y93AMWrCXJAEiHDQbL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers found unclaimed llms.txt references on 120 domains, exploitable by cybercriminals</strong></li><li><strong>AI agents could install malware if they execute hallucinated or outdated documentation commands</strong></li><li><strong>Fixes: clean documentation and restrict AI agents from treating docs as executable instructions</strong></li></ul><p>Cybercriminals are able to now abuse hallucinated, outdated, and outright incorrect website documentation to deliver malware to unsuspecting victims through <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a>, new research has claimed.</p><p>An increasing number of websites now contain two documents: llms.txt, and llms-full.txt. These are conventions that allow AI agents to properly read the contents of the websites. If an AI agent is looking to install software or add code to a project, they can search through these documents across the web until they find a fitting solution.</p><p>Researcher <a href="https://medium.com/@alonhertz1/data-became-code-we-ran-code-inside-fortune-500s-using-files-they-published-for-ai-agents-0cd67ffbbffc" target="_blank">Alon Hertz</a> analyzed 6,214 live domains belonging to defense contractors, Fortune 500 organizations, as well as big tech. On these domains he  found 8,265 of these .txt files and among them 120 (all on a different site) pointing to one or more code packages and domain names that weren’t registered at all.</p><h2 id="claiming-packages-and-domains">Claiming packages and domains</h2><p>There can be a myriad of reasons why they’re not registered. It can be due to human error, renamed or abandoned packages, copy/paste errors, or hallucinated documentation.</p><p>Now, for the purpose of the experiment, Hertz registered some of these unclaimed names and hosted packages that would phone home when installed. It took less than an hour for a Fortune 500 company to start pinging, and the numbers soon grew to “a few dozen more”. </p><p>This means that if the researchers can do it, so can cybercriminals. In theory, a cybercriminal could find these unclaimed packages and register <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. If an AI agent has permission to execute shell/package-manager commands and stumbles upon this documentation, it can end up infecting the device. </p><p>Claude, OpenAI’s Codex, and Nous Research’s Hermes were all “guilty”, the researchers said. </p><p>To fix the vulnerability, two things need to happen. First, companies need to clean up their documentation and make sure it’s not pointing towards non-existent or malicious content. Second, AI agents need to stop treating documentation as executable instructions. Since the latter most likely isn’t happening any time soon, the immediate answer would probably lie in the former. In the meantime, organizations using AI for coding should consider the risks when granting AI agents permission to execute commands. </p><p><em>Via </em><a href="https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/" target="_blank"><em>Ars Technica</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Carhartt data breach exposed information from 12.9 million user accounts ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>ShinyHunters leaked 12.9 million Carhartt customer records after failed $3.3 million ransom talks</strong></li><li><strong>Data stolen from Databricks platform included names, emails, phone numbers, and addresses</strong></li><li><strong>Group now focuses on exfiltration via vishing and SaaS breaches, abandoning encryption</strong></li></ul><p>Millions of user records belonging to customers of clothing giant Carhartt has been leaked onto the dark web, exposing people’s names, email addresses, postal addresses, and phone numbers, to all sorts of scammers and cybercriminals.</p><p>The infamous ShinyHunters ransomware gang recently added Carhartt to its data leak site, saying negotiations broke down and uploading the entire archive that was stolen in the breach. </p><p>"Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised," the group said.</p><h2 id="compromising-analytics-platforms">Compromising analytics platforms</h2><p>It added that the demand was $3.3 million, which Carhartt turned down:</p><p>"After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions," a company negotiator allegedly told the extortionists. </p><p>At the same time, security researcher Troy Hunt from <em>HaveIBeenPwned?</em> analyzed the leaked batch and concluded that it most likely came from Carhartt’s Databricks analytics platform. </p><p>Hunt said some 12.9 million accounts were compromised, containing information such as email addresses, names, phone numbers, and physical addresses. The batch also contains "millions of synthetic records that did not relate to real individuals and were excluded from the breach."</p><p>ShinyHunters is currently one of the most active threat actors. They started as a typical <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> group but decided to abandon the encryption part and to focus solely on data exfiltration. The group mostly engages in vishing, tricking victims into trying to log into the corporate environment through spoofed landing pages. </p><p>After gaining a foothold, they target for SaaS solutions, through which they steal valuable information. They have claimed responsibility for breaches at hundreds of Salesforce and tens of Snowflake customers.</p><p>Carhartt runs roughly 60 stores around the US, and employs some 3,000 people, bringing in an estimated $1.8 billion in annual revenue.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/carhartt-data-breach-exposed-information-from-12-9-million-user-accounts</link>
                                                                            <description>
                            <![CDATA[ Names, emails, and more Carhartt data has been exposed by ShinyHunters. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">66aNZY57UqYdjrTAABMxWF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 29 Aug 2026 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ShinyHunters leaked 12.9 million Carhartt customer records after failed $3.3 million ransom talks</strong></li><li><strong>Data stolen from Databricks platform included names, emails, phone numbers, and addresses</strong></li><li><strong>Group now focuses on exfiltration via vishing and SaaS breaches, abandoning encryption</strong></li></ul><p>Millions of user records belonging to customers of clothing giant Carhartt has been leaked onto the dark web, exposing people’s names, email addresses, postal addresses, and phone numbers, to all sorts of scammers and cybercriminals.</p><p>The infamous ShinyHunters ransomware gang recently added Carhartt to its data leak site, saying negotiations broke down and uploading the entire archive that was stolen in the breach. </p><p>"Millions of records of customer data and vast amount of sensitive information and PII containing employee, customer, customer metadata (royalty info), and other internal corporate data was compromised," the group said.</p><h2 id="compromising-analytics-platforms">Compromising analytics platforms</h2><p>It added that the demand was $3.3 million, which Carhartt turned down:</p><p>"After careful review and internal discussions with leadership, we have decided not to move forward with negotiations or further discussions," a company negotiator allegedly told the extortionists. </p><p>At the same time, security researcher Troy Hunt from <em>HaveIBeenPwned?</em> analyzed the leaked batch and concluded that it most likely came from Carhartt’s Databricks analytics platform. </p><p>Hunt said some 12.9 million accounts were compromised, containing information such as email addresses, names, phone numbers, and physical addresses. The batch also contains "millions of synthetic records that did not relate to real individuals and were excluded from the breach."</p><p>ShinyHunters is currently one of the most active threat actors. They started as a typical <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> group but decided to abandon the encryption part and to focus solely on data exfiltration. The group mostly engages in vishing, tricking victims into trying to log into the corporate environment through spoofed landing pages. </p><p>After gaining a foothold, they target for SaaS solutions, through which they steal valuable information. They have claimed responsibility for breaches at hundreds of Salesforce and tens of Snowflake customers.</p><p>Carhartt runs roughly 60 stores around the US, and employs some 3,000 people, bringing in an estimated $1.8 billion in annual revenue.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How did the Manchester Airports Group cyberattack take place, and what data was exposed in the 8.7 million customer records? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>As the UK enters one of its busiest periods for travel, some holiday makers will be questioning how hackers managed to get their hands on their personal data.</p><p>The Manchester Airports Group (MAG), which owns and oversees Manchester, London Stansted, and East Midlands airports, has revealed that hackers managed to steal data belonging to 8.7 million customers.</p><p>Given the sources of the data taken - spanning car park services, lounge and Fast Track bookings and in-airport WIFI sign-ups - it is likely a large database of information was accessed by the hackers.</p><h2 id="what-data-was-taken">What data was taken?</h2><p>The data accessed and stolen by the hackers include email addresses, phone numbers, vehicle registrations and postcodes of up to 8.7 million customers.</p><p>While banking and financial information remained secure during the attack, this level of data exposure places customers at a heightened risk for targeted phishing and scams.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>A <a href="https://www.manchesterairport.co.uk/help/data-security-incident/" target="_blank" rel="nofollow">statement</a> by MAG said, “We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems. We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised.”</p><p>MAG advised customers who have been affected by the breach to remain vigilant against suspicious emails and calls. Given the data exposed in the attack, these could be highly specific, referring to flights, parking (including customer number plates), and airport services.</p><p>MAG issued the following guidance:</p><ul><li>Remaining vigilant for suspicious emails, text messages or phone calls</li><li>Avoiding clicking on links or opening attachments from unexpected communications</li><li>Seeking further support and advice at <a href="https://www.ncsc.gov.uk/guidance/data-breaches#section_3">Data breach guidance for individuals</a></li></ul><h3 class="article-body__section" id="section-expert-perspectives-on-mag-data-breach"><span>Expert perspectives on MAG data breach</span></h3><ul><li><strong>Graeme Stewart, Head of Public Sector, Check Point Software</strong></li></ul><p><em>We warned after the attacks on the automotive sector last year that aviation needed to move onto a war footing. This feels like the moment that warning becomes very real.</em></p><p><em>Cyber criminals have already shown us what sustained pressure on a major industry can look like. They find the weak points, work through suppliers and connected systems, steal data and keep coming. There was every reason to believe aviation would become an attractive target, and an incident affecting almost nine million airport customers should concentrate minds across the sector.</em></p><div><blockquote><p>The absence of cancelled flights or queues at terminals does not make this a small cyber attack. The data reportedly taken can now be weaponised.</p></blockquote></div><p><em>The absence of cancelled flights or queues at terminals does not make this a small cyber attack. The data reportedly taken can now be weaponised. Criminals know these people have a relationship with Manchester, Stansted or East Midlands airports and potentially have phone numbers, postcodes and vehicle registrations to make their approach believable. A fake parking refund, Fast Track problem or message about this very breach suddenly becomes much harder for an ordinary customer to spot.</em></p><p><em>If you believe you are affected, be extremely suspicious of any unexpected contact about the airports or this incident. Do not follow links in emails or texts asking you to confirm information, make a payment or claim a refund. Go directly to the airport’s official website if you need to check something. If somebody calls claiming to be from the airport, hang up and contact the organisation independently.</em></p><p><em>Anyone who has already handed over banking information following suspicious contact should speak to their bank immediately. If you have given away a password, change it anywhere you have reused it and switch on two-step verification.</em></p><p><em>For the aviation industry, there should be no comfort taken from the fact the terminals are operating normally today. Last year was a warning about what happens when attackers focus their attention on a sector. Aviation needs to behave as though a sustained campaign has begun, because waiting for an attack that stops planes moving before treating this as serious would be a dangerous mistake.</em></p><ul><li><strong>Dr. Ilia Kolochenko, Founder, ImmuniWeb:</strong></li></ul><p><em>The risk of this data breach seems to be significantly underestimated or downplayed for almost 9 million victims. The majority of lounge and fast-track line bookings are wealthy passengers, whose travel data may per se constitute sensitive, embarrassing or even incriminating information, therefore being a valuable commodity for unscrupulous cybercriminals.</em></p><div><blockquote><p>A wave of personalized and AI-enhanced blackmailing and extortion campaigns may be launched shortly.</p></blockquote></div><p><em>A wave of personalized and AI-enhanced blackmailing and extortion campaigns may be launched shortly. Moreover, some specialized cyber gangs will likely offer the data to investigative journalists – without fully disclosing the illicit origin of the data – to track celebrities or trace sanction evasion, causing even more damage to the victims.</em></p><p><em>In case of extortion, many victims will unlikely contact the police and will rather silently pay the ransom in cryptocurrency. Worse, the payment does not guarantee that the data will not eventually be released on the Dark Web or shared with third parties. In sum, this data breach will likely have long-lasting consequences for the victims.</em></p><ul><li><strong>Vykintas Maknickas, CEO, Saily:</strong></li></ul><p><em>This breach shows that airport cybersecurity is no longer only protecting flight systems or operational infrastructure. The digital services travelers use every day, like airport WiFi, parking bookings, lounge access, and fast-track reservations, have become part of the security perimeter. When these systems are compromised, millions of people can be affected before they even board a plane.</em></p><div><blockquote><p>Email addresses, postcodes, and vehicle registration details can be used to create extremely convincing scams.</p></blockquote></div><p><em>While payment details were reportedly not exposed, the stolen data is still highly valuable to criminals. Email addresses, postcodes, and vehicle registration details can be used to create extremely convincing scams.</em></p><p><em>Travelers may receive fake airport emails, fraudulent parking-payment notices, bogus flight updates, or calls claiming to offer compensation. These messages may contain enough real personal detail to look legitimate, so travellers should stay vigilant.</em></p><p><em>Behind the figure of 8.7 million are real people. Families going on holiday, business travelers heading to meetings, parents trying to keep children entertained at the airport. That is the human cost of a data breach: the company is attacked, but ordinary people live with the consequences.</em></p><p><em>This incident should be a wake-up call for the travel industry. Companies need to ask not only how they protect customer data, but also how much of it they really need to collect and store in the first place. The less unnecessary data a company holds, the less damage criminals can cause when systems are breached.</em></p><p><em>For travelers, the advice is simple: be extra cautious with any unexpected message claiming to come from an airport, airline, parking provider, or customer support team. Do not click links in suspicious emails or texts. When traveling, it is also safer to use mobile data or an eSIM instead of relying on public airport WiFi.</em></p><ul><li><strong>Raghu Nandakumara, VP of Industry Strategy, Illumio:</strong></li></ul><p><em>This is a significant breach affecting a large number of customers ahead of one of the busiest travel periods of the year for UK airports. Incidents like this erode customer trust. For those affected, the exposed data increases the risk of targeted phishing and smishing attempts, where attackers can use legitimate travel-related information to make malicious communications appear convincing.</em></p><div><blockquote><p>Incidents like this erode customer trust.</p></blockquote></div><p><em>While Manchester Airports Group has said the incident was contained and operations were not disrupted, sensitive customer information was still accessed. Maintaining services during a cyberattack is critical, but organisations also need to minimise the amount of data and systems an attacker can reach before the threat is isolated.</em></p><p><em>Measures such as segmentation can help restrict access to critical systems and sensitive data, reducing the risk that a single compromise becomes a wider incident.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/how-did-the-manchester-airports-group-cyberattack-take-place-and-what-data-was-exposed-in-the-8-7-million-customer-records-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ Email addresses, phone numbers, vehicle registrations and postcodes of up to 8.7 million customers were stolen ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MshMRcBXA9p75SQAvZGMR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yLTkpXkRjzyqfh2RQyFi2F-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 29 Aug 2026 06:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yLTkpXkRjzyqfh2RQyFi2F-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / d3sign]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A queue at an airport check-in]]></media:description>                                                            <media:text><![CDATA[A queue at an airport check-in]]></media:text>
                                <media:title type="plain"><![CDATA[A queue at an airport check-in]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yLTkpXkRjzyqfh2RQyFi2F-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As the UK enters one of its busiest periods for travel, some holiday makers will be questioning how hackers managed to get their hands on their personal data.</p><p>The Manchester Airports Group (MAG), which owns and oversees Manchester, London Stansted, and East Midlands airports, has revealed that hackers managed to steal data belonging to 8.7 million customers.</p><p>Given the sources of the data taken - spanning car park services, lounge and Fast Track bookings and in-airport WIFI sign-ups - it is likely a large database of information was accessed by the hackers.</p><h2 id="what-data-was-taken">What data was taken?</h2><p>The data accessed and stolen by the hackers include email addresses, phone numbers, vehicle registrations and postcodes of up to 8.7 million customers.</p><p>While banking and financial information remained secure during the attack, this level of data exposure places customers at a heightened risk for targeted phishing and scams.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>A <a href="https://www.manchesterairport.co.uk/help/data-security-incident/" target="_blank" rel="nofollow">statement</a> by MAG said, “We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems. We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised.”</p><p>MAG advised customers who have been affected by the breach to remain vigilant against suspicious emails and calls. Given the data exposed in the attack, these could be highly specific, referring to flights, parking (including customer number plates), and airport services.</p><p>MAG issued the following guidance:</p><ul><li>Remaining vigilant for suspicious emails, text messages or phone calls</li><li>Avoiding clicking on links or opening attachments from unexpected communications</li><li>Seeking further support and advice at <a href="https://www.ncsc.gov.uk/guidance/data-breaches#section_3">Data breach guidance for individuals</a></li></ul><h3 class="article-body__section" id="section-expert-perspectives-on-mag-data-breach"><span>Expert perspectives on MAG data breach</span></h3><ul><li><strong>Graeme Stewart, Head of Public Sector, Check Point Software</strong></li></ul><p><em>We warned after the attacks on the automotive sector last year that aviation needed to move onto a war footing. This feels like the moment that warning becomes very real.</em></p><p><em>Cyber criminals have already shown us what sustained pressure on a major industry can look like. They find the weak points, work through suppliers and connected systems, steal data and keep coming. There was every reason to believe aviation would become an attractive target, and an incident affecting almost nine million airport customers should concentrate minds across the sector.</em></p><div><blockquote><p>The absence of cancelled flights or queues at terminals does not make this a small cyber attack. The data reportedly taken can now be weaponised.</p></blockquote></div><p><em>The absence of cancelled flights or queues at terminals does not make this a small cyber attack. The data reportedly taken can now be weaponised. Criminals know these people have a relationship with Manchester, Stansted or East Midlands airports and potentially have phone numbers, postcodes and vehicle registrations to make their approach believable. A fake parking refund, Fast Track problem or message about this very breach suddenly becomes much harder for an ordinary customer to spot.</em></p><p><em>If you believe you are affected, be extremely suspicious of any unexpected contact about the airports or this incident. Do not follow links in emails or texts asking you to confirm information, make a payment or claim a refund. Go directly to the airport’s official website if you need to check something. If somebody calls claiming to be from the airport, hang up and contact the organisation independently.</em></p><p><em>Anyone who has already handed over banking information following suspicious contact should speak to their bank immediately. If you have given away a password, change it anywhere you have reused it and switch on two-step verification.</em></p><p><em>For the aviation industry, there should be no comfort taken from the fact the terminals are operating normally today. Last year was a warning about what happens when attackers focus their attention on a sector. Aviation needs to behave as though a sustained campaign has begun, because waiting for an attack that stops planes moving before treating this as serious would be a dangerous mistake.</em></p><ul><li><strong>Dr. Ilia Kolochenko, Founder, ImmuniWeb:</strong></li></ul><p><em>The risk of this data breach seems to be significantly underestimated or downplayed for almost 9 million victims. The majority of lounge and fast-track line bookings are wealthy passengers, whose travel data may per se constitute sensitive, embarrassing or even incriminating information, therefore being a valuable commodity for unscrupulous cybercriminals.</em></p><div><blockquote><p>A wave of personalized and AI-enhanced blackmailing and extortion campaigns may be launched shortly.</p></blockquote></div><p><em>A wave of personalized and AI-enhanced blackmailing and extortion campaigns may be launched shortly. Moreover, some specialized cyber gangs will likely offer the data to investigative journalists – without fully disclosing the illicit origin of the data – to track celebrities or trace sanction evasion, causing even more damage to the victims.</em></p><p><em>In case of extortion, many victims will unlikely contact the police and will rather silently pay the ransom in cryptocurrency. Worse, the payment does not guarantee that the data will not eventually be released on the Dark Web or shared with third parties. In sum, this data breach will likely have long-lasting consequences for the victims.</em></p><ul><li><strong>Vykintas Maknickas, CEO, Saily:</strong></li></ul><p><em>This breach shows that airport cybersecurity is no longer only protecting flight systems or operational infrastructure. The digital services travelers use every day, like airport WiFi, parking bookings, lounge access, and fast-track reservations, have become part of the security perimeter. When these systems are compromised, millions of people can be affected before they even board a plane.</em></p><div><blockquote><p>Email addresses, postcodes, and vehicle registration details can be used to create extremely convincing scams.</p></blockquote></div><p><em>While payment details were reportedly not exposed, the stolen data is still highly valuable to criminals. Email addresses, postcodes, and vehicle registration details can be used to create extremely convincing scams.</em></p><p><em>Travelers may receive fake airport emails, fraudulent parking-payment notices, bogus flight updates, or calls claiming to offer compensation. These messages may contain enough real personal detail to look legitimate, so travellers should stay vigilant.</em></p><p><em>Behind the figure of 8.7 million are real people. Families going on holiday, business travelers heading to meetings, parents trying to keep children entertained at the airport. That is the human cost of a data breach: the company is attacked, but ordinary people live with the consequences.</em></p><p><em>This incident should be a wake-up call for the travel industry. Companies need to ask not only how they protect customer data, but also how much of it they really need to collect and store in the first place. The less unnecessary data a company holds, the less damage criminals can cause when systems are breached.</em></p><p><em>For travelers, the advice is simple: be extra cautious with any unexpected message claiming to come from an airport, airline, parking provider, or customer support team. Do not click links in suspicious emails or texts. When traveling, it is also safer to use mobile data or an eSIM instead of relying on public airport WiFi.</em></p><ul><li><strong>Raghu Nandakumara, VP of Industry Strategy, Illumio:</strong></li></ul><p><em>This is a significant breach affecting a large number of customers ahead of one of the busiest travel periods of the year for UK airports. Incidents like this erode customer trust. For those affected, the exposed data increases the risk of targeted phishing and smishing attempts, where attackers can use legitimate travel-related information to make malicious communications appear convincing.</em></p><div><blockquote><p>Incidents like this erode customer trust.</p></blockquote></div><p><em>While Manchester Airports Group has said the incident was contained and operations were not disrupted, sensitive customer information was still accessed. Maintaining services during a cyberattack is critical, but organisations also need to minimise the amount of data and systems an attacker can reach before the threat is isolated.</em></p><p><em>Measures such as segmentation can help restrict access to critical systems and sensitive data, reducing the risk that a single compromise becomes a wider incident.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>