<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-NZ"
                       href="https://www.techradar.com/nz/feeds/tag/security"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar NZ in Security ]]></title>
                <link>https://www.techradar.com/nz/pro/security</link>
        <description><![CDATA[ All the latest security content from the TechRadar  NZ team ]]></description>
                                    <lastBuildDate>Mon, 14 Sep 2026 19:05:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ 31,000 Twitch users hit by malicious browser extension — OAuth tokens leaked via Russian proxy network ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Socket found Twitch extension </strong><em><strong>JeeBot</strong></em><strong> harvesting OAuth tokens via proxy servers</strong></li><li><strong>Tokens excluded only for 10 Russian streamer channels, suggesting deliberate design</strong></li><li><strong>Developer issued fixes, but users should revoke exposed tokens for safety</strong></li></ul><p>A browser extension for Twitch was harvesting people’s OAuth tokens and sending them to a Russian-owned server. The move was deliberate, but whether or not it was malicious is not that easily determined.</p><p>Security researchers Socket recently found an extension for both <a href="https://www.techradar.com/best/browser" target="_blank">Chrome</a> and Firefox, called “Twitch Enhanced Viewer | JeeBot”. It has roughly 30,000 users on Chrome, and some 600 on Firefox.</p><p>On the Chrome Web Store, it is advertised as a “modern tool for streamers and viewers who value quality, convenience, and control.” Apparently, it makes streaming and viewing clearer, allows viewing content in 2K, hides banner ads and unwanted elements, and even offers an AI bot to make it easier to interact with the stream.</p><h2 id="hardcoded-exemptions">Hardcoded exemptions</h2><p>According to the researchers, the extension is designed to retrieve Twitch’s video stream playlists through its own proxy servers. However, instead of simply forwarding the requests, the extension also attached users’ OAuth tokens, and since they were placed in the URL, the token also ended up in the proxy server’s request logs. </p><p>After being called out for it, the extension’s developer (HISHIMIRO/jeetbot.cc) released a new version 85.8.7 (for Firefox, the Chrome one is currently under review) which apparently fixes this flaw: when playlists are retrieved, the user’s OAuth token is no longer sent to the proxies. It would seem like this was an honest mistake that was remedied upon responsible disclosure. However, here is what Socket had to say about the way the tokens were being retrieved:</p><p>"Current builds (v85.x) forward the token inline as an &auth= query parameter on a network-layer redirect to the operator's proxy," Socket explained. "The token is forwarded for every channel the user watches, except a hardcoded allowlist of ten Russian streamer channels, whose sessions are exempted from forwarding."</p><p>If there was a list of 10 Russian streamer channels who were exempt from OAuth token retrieval, it’s safe to assume that the developer knew very well what they were doing. </p><p>It is good that the extensions were upgraded, but if you are using it, you should also revoke the exposed Twitch token, to be on the safe side.</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/31-000-twitch-users-hit-by-malicious-browser-extension-oauth-tokens-leaked-via-russian-proxy-network</link>
                                                                            <description>
                            <![CDATA[ The extension has since been updated to remove the OAuth exfil. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">twiixGQaC7oSjW7QP7g3H9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/33ooyG4FCgVjDs8W6RpowC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Sep 2026 19:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/33ooyG4FCgVjDs8W6RpowC-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Twitch logo under a magnifying glass in internet browser]]></media:description>                                                            <media:text><![CDATA[Twitch logo under a magnifying glass in internet browser]]></media:text>
                                <media:title type="plain"><![CDATA[Twitch logo under a magnifying glass in internet browser]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/33ooyG4FCgVjDs8W6RpowC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Socket found Twitch extension </strong><em><strong>JeeBot</strong></em><strong> harvesting OAuth tokens via proxy servers</strong></li><li><strong>Tokens excluded only for 10 Russian streamer channels, suggesting deliberate design</strong></li><li><strong>Developer issued fixes, but users should revoke exposed tokens for safety</strong></li></ul><p>A browser extension for Twitch was harvesting people’s OAuth tokens and sending them to a Russian-owned server. The move was deliberate, but whether or not it was malicious is not that easily determined.</p><p>Security researchers Socket recently found an extension for both <a href="https://www.techradar.com/best/browser" target="_blank">Chrome</a> and Firefox, called “Twitch Enhanced Viewer | JeeBot”. It has roughly 30,000 users on Chrome, and some 600 on Firefox.</p><p>On the Chrome Web Store, it is advertised as a “modern tool for streamers and viewers who value quality, convenience, and control.” Apparently, it makes streaming and viewing clearer, allows viewing content in 2K, hides banner ads and unwanted elements, and even offers an AI bot to make it easier to interact with the stream.</p><h2 id="hardcoded-exemptions">Hardcoded exemptions</h2><p>According to the researchers, the extension is designed to retrieve Twitch’s video stream playlists through its own proxy servers. However, instead of simply forwarding the requests, the extension also attached users’ OAuth tokens, and since they were placed in the URL, the token also ended up in the proxy server’s request logs. </p><p>After being called out for it, the extension’s developer (HISHIMIRO/jeetbot.cc) released a new version 85.8.7 (for Firefox, the Chrome one is currently under review) which apparently fixes this flaw: when playlists are retrieved, the user’s OAuth token is no longer sent to the proxies. It would seem like this was an honest mistake that was remedied upon responsible disclosure. However, here is what Socket had to say about the way the tokens were being retrieved:</p><p>"Current builds (v85.x) forward the token inline as an &auth= query parameter on a network-layer redirect to the operator's proxy," Socket explained. "The token is forwarded for every channel the user watches, except a hardcoded allowlist of ten Russian streamer channels, whose sessions are exempted from forwarding."</p><p>If there was a list of 10 Russian streamer channels who were exempt from OAuth token retrieval, it’s safe to assume that the developer knew very well what they were doing. </p><p>It is good that the extensions were upgraded, but if you are using it, you should also revoke the exposed Twitch token, to be on the safe side.</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CISA warns hackers are exploiting max severity GitLab flaw — urges all businesses to patch immediately ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CISA added GitLab CVE‑2026‑85706, a critical path traversal flaw, to its KEV catalog</strong></li><li><strong>Exploitation already observed; attackers can read sensitive files via commits API without authentication</strong></li><li><strong>GitLab patched in CE/EE 19.3.2, 19.2.6, and 19.1; agencies given three days to update</strong></li></ul><p>The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new GitLab vulnerability to its KEV catalog, warning users that it is being actively exploited in the wild.</p><p>GitLab has now updated its Community Edition (CE) and Enterprise Edition (EE) versions to 19.3.2, 19.2.6, and 19.1, fixing a range of vulnerabilities. Among them were two critical-severity ones: a path traversal issue in repository commits API, and an Insecure Deserialization issue in GraphQL subscription serializer.</p><p>The former is tracked as CVE-2026-85706, with a severity score of 10/10. It stems from missing authentication enforcement and improper path confinement in the repository commits API, allowing unauthenticated threat actors to read various sensitive information such as login credentials or secrets. </p><h2 id="added-to-kev">Added to KEV</h2><p>In the advisory, GitLab did not mention anything about the flaws being abused in the wild - however, a separate report from cybersecurity experts watchTowr, released a day later, claimed so:</p><p>"watchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request," the researchers said.</p><p>"Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away. [..] Defenders should also hunt through log files for HTTP POST requests to '/api/v4/projects/{id}/repository/commits/' URIs containing 'file.path' parameters to identify potential exploitation attempts."</p><p>At the same time, CISA added this bug to its Known Exploited Vulnerabilities (KEV) catalog, confirming the claims and giving government users a tiny three-day window to apply the patch. </p><p>GitLab is an intelligent orchestration platform for DevSecOps professionals, helping organizations automate and streamline the software development cycle. It has more than 50 million registered users, among which are roughly 50% of Fortune 100 companies, as per an <a href="https://www.sec.gov/Archives/edgar/data/1653482/000162828026059943/gtlb-20260731.htm" target="_blank" rel="nofollow">SEC filing</a>. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-max-severity-gitlab-flaw-in-attacks/" target="_blank" rel="nofollow"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/cisa-warns-hackers-are-exploiting-max-severity-gitlab-flaw-urges-all-businesses-to-patch-immediately</link>
                                                                            <description>
                            <![CDATA[ A 10/10 GitLab flaw was added to CISA's KEV, giving government agencies just three days to patch. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vUcC7WtWua8bdRMRYG76wh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Sep 2026 16:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CISA added GitLab CVE‑2026‑85706, a critical path traversal flaw, to its KEV catalog</strong></li><li><strong>Exploitation already observed; attackers can read sensitive files via commits API without authentication</strong></li><li><strong>GitLab patched in CE/EE 19.3.2, 19.2.6, and 19.1; agencies given three days to update</strong></li></ul><p>The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new GitLab vulnerability to its KEV catalog, warning users that it is being actively exploited in the wild.</p><p>GitLab has now updated its Community Edition (CE) and Enterprise Edition (EE) versions to 19.3.2, 19.2.6, and 19.1, fixing a range of vulnerabilities. Among them were two critical-severity ones: a path traversal issue in repository commits API, and an Insecure Deserialization issue in GraphQL subscription serializer.</p><p>The former is tracked as CVE-2026-85706, with a severity score of 10/10. It stems from missing authentication enforcement and improper path confinement in the repository commits API, allowing unauthenticated threat actors to read various sensitive information such as login credentials or secrets. </p><h2 id="added-to-kev">Added to KEV</h2><p>In the advisory, GitLab did not mention anything about the flaws being abused in the wild - however, a separate report from cybersecurity experts watchTowr, released a day later, claimed so:</p><p>"watchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request," the researchers said.</p><p>"Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away. [..] Defenders should also hunt through log files for HTTP POST requests to '/api/v4/projects/{id}/repository/commits/' URIs containing 'file.path' parameters to identify potential exploitation attempts."</p><p>At the same time, CISA added this bug to its Known Exploited Vulnerabilities (KEV) catalog, confirming the claims and giving government users a tiny three-day window to apply the patch. </p><p>GitLab is an intelligent orchestration platform for DevSecOps professionals, helping organizations automate and streamline the software development cycle. It has more than 50 million registered users, among which are roughly 50% of Fortune 100 companies, as per an <a href="https://www.sec.gov/Archives/edgar/data/1653482/000162828026059943/gtlb-20260731.htm" target="_blank" rel="nofollow">SEC filing</a>. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-max-severity-gitlab-flaw-in-attacks/" target="_blank" rel="nofollow"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft Cloud accounts stolen in highly complex impersonation and passkey phishing campaign ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft warns of a sophisticated campaign tricking users into updating passkeys via fake IT calls</strong></li><li><strong>Victims redirected to adversary‑in‑the‑middle sites mimicking Microsoft login to steal access</strong></li><li><strong>Attackers exfiltrate files from SharePoint, OneDrive, and Exchange; phishing‑resistant MFA advised</strong></li></ul><p>Passkeys have made stealing passwords obsolete. To work around this change, hackers have started tricking users into authenticating on attacker-controlled computers. This is according to a new report from Microsoft, which says there’s a highly sophisticated campaign currently taking place, with the goal of compromising people’s cloud accounts and stealing as many sensitive files as possible.</p><p>The attack starts a lot earlier than what the victim experiences. There is a lot of pre-attack planning and due diligence, in which the threat actors gather as much information about their target as possible. Knowing their place of work, position, and personal phone number is essential.</p><p>Once all the pieces are in place, the attack starts with a phone call - victims are told they are speaking to their organization’s IT help desk and that they need to update their passkey (or <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA</a>, depending on the setup) immediately, to avoid any disruptions to their operations.</p><h2 id="follow-up-sms">Follow-up SMS</h2><p>In the follow-up to the call, the victims then receive an SMS message with a link where they can update their security configuration. On the surface, the website looks like the legitimate Microsoft login landing page. In reality, though, this is a pre-built malicious website that uses the adversary-in-the-middle (AitM) techniques to either receive access on the actor’s behalf, or capture credentials. </p><p>"The actor appears to invest heavily in pre-attack research, likely gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms," Microsoft said. "In a smaller number of cases, actors take advantage of already compromised accounts to expand their reach" by sending similar <a href="https://www.techradar.com/best/password-manager" target="_blank">passkey</a>-themed messages via Microsoft Teams.</p><p>The campaign is apparently ongoing since at least May this year, Microsoft, said, without detailing the number of victims. Its aim seems to be to exfiltrate files from SharePoint and OneDrive, as well as email data from Microsoft Exchange Online. It also did not attribute this campaign to any specific threat actor, although it did say that there are many collectives engaged in such, or similar, campaigns, including Cordial Spider, Storm-3121, and others. </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsoft-cloud-accounts-stolen-in-highly-complex-impersonation-and-passkey-phishing-campaign</link>
                                                                            <description>
                            <![CDATA[ Passkeys have all but eliminated password theft, so what now? Criminals have a solution. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gvgCtMKG9LSB8TG3Cy7L8V</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dpYpu4kURRoCpERiFgAv8o-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Sep 2026 16:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dpYpu4kURRoCpERiFgAv8o-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Passkeys]]></media:description>                                                            <media:text><![CDATA[Passkeys]]></media:text>
                                <media:title type="plain"><![CDATA[Passkeys]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dpYpu4kURRoCpERiFgAv8o-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns of a sophisticated campaign tricking users into updating passkeys via fake IT calls</strong></li><li><strong>Victims redirected to adversary‑in‑the‑middle sites mimicking Microsoft login to steal access</strong></li><li><strong>Attackers exfiltrate files from SharePoint, OneDrive, and Exchange; phishing‑resistant MFA advised</strong></li></ul><p>Passkeys have made stealing passwords obsolete. To work around this change, hackers have started tricking users into authenticating on attacker-controlled computers. This is according to a new report from Microsoft, which says there’s a highly sophisticated campaign currently taking place, with the goal of compromising people’s cloud accounts and stealing as many sensitive files as possible.</p><p>The attack starts a lot earlier than what the victim experiences. There is a lot of pre-attack planning and due diligence, in which the threat actors gather as much information about their target as possible. Knowing their place of work, position, and personal phone number is essential.</p><p>Once all the pieces are in place, the attack starts with a phone call - victims are told they are speaking to their organization’s IT help desk and that they need to update their passkey (or <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA</a>, depending on the setup) immediately, to avoid any disruptions to their operations.</p><h2 id="follow-up-sms">Follow-up SMS</h2><p>In the follow-up to the call, the victims then receive an SMS message with a link where they can update their security configuration. On the surface, the website looks like the legitimate Microsoft login landing page. In reality, though, this is a pre-built malicious website that uses the adversary-in-the-middle (AitM) techniques to either receive access on the actor’s behalf, or capture credentials. </p><p>"The actor appears to invest heavily in pre-attack research, likely gathering information about employees and organizational structure from public sources such as social networking and professional profiling platforms," Microsoft said. "In a smaller number of cases, actors take advantage of already compromised accounts to expand their reach" by sending similar <a href="https://www.techradar.com/best/password-manager" target="_blank">passkey</a>-themed messages via Microsoft Teams.</p><p>The campaign is apparently ongoing since at least May this year, Microsoft, said, without detailing the number of victims. Its aim seems to be to exfiltrate files from SharePoint and OneDrive, as well as email data from Microsoft Exchange Online. It also did not attribute this campaign to any specific threat actor, although it did say that there are many collectives engaged in such, or similar, campaigns, including Cordial Spider, Storm-3121, and others. </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why are US AI giants calling for ‘Pacing The Frontier’, and why is China calling it a ‘Cold War tactic’? We ask the experts ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Following the recent resignation of one of Anthropic’s leading researchers, multiple AI CEOs have suddenly begun calling for a slowdown in the development of AI technology to allow regulations and governance on the technology to catch up.</p><p>Speaking to the <a href="https://www.bbc.co.uk/news/articles/c1kx0gyje9wo" target="_blank" rel="nofollow"><em>BBC</em></a> after his resignation, Jacob Coxon warned, “I believe that if we don't slow down at the current rate of progress, there is a strong chance that we could all die in the immediate future.”</p><p>Following this, Anthropic head Dario Amodei, OpenAI CEO Sam Altman, and Grok founder Elon Musk have all apparently aligned in their calls for development to slow down. But there are some tricky waters to navigate - particularly around President Trump, China, and what guardrails should be put into place.</p><h2 id="what-are-ai-heads-saying">What are AI heads saying?</h2><p>Over the weekend, Amodei posted an essay on “why the AI industry should slow down”. In it, he said, “I believe that if slowing down bought us even an extra year or two before models reach critical levels of capability, and we used that time to advance alignment, we could greatly reduce the risk that something goes seriously wrong.”</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2098773920774074715"><p lang="en" dir="ltr">We Must Pace the Frontier: I’ve written a new essay on why the AI industry should slow down, with a three-part plan for doing so.Anthropic is unilaterally committing to the first of these steps. We’ll provide third-party evaluators with permanent, employee-level access to our systems, so that they can verify adherence to our safety measures, report on incidents, and assess models’ alignment during training.You can read the full post here: https://t.co/OGyPb7yaYt<a href="https://twitter.com/cantworkitout/status/2098773920774074715">September 12, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Within the essay, Amodei outlined how AI could be ‘paced’ within the US, and globally, alongside a recommendation that AI companies put ‘evaluator’ teams into place to ensure AI models stay aligned to their tasks. Elon Musk replied to Amodei’s social media post, stating that the Anthropic head was “right”.</p><p>Sam Altman told <em>Fortune</em> the regulations and standards for AI further were “not at a place” to continue progressing AI development. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9-1920-80.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>But not everyone is convinced. US President Donald Trump has said that slowing down AI development is non-negotiable, as it would allow China to rapidly catch up to US AI capabilities. He told reporters that the US is “leading China on AI... and, frankly, I want to keep it that way,” adding that “whoever wins AI, wins”.</p><p>Trump also said that “very negative forces” were behind the growing opposition to AI, and said that fears were being stoked by “that won’t happen”.</p><p>China also isn’t convinced by what the AI giants are saying. <a href="https://www.nbcnews.com/world/china/china-ai-slowdown-trump-amodei-altman-threat-cold-war-rcna597631" target="_blank" rel="nofollow">Beijing labelled the calls for a slowdown as “fearmongering”</a> from a “Cold War playbook.” In his essay, Amodei said that a “Chinese lead in AI would pose grave danger for the United States and the world.”</p><p>Chinese Foreign Ministry spokesperson Guo Jiakun said, “Fearmongering, confrontation and malicious competition will only disrupt the process of global AI governance and serve no one’s interests.”</p><h3 class="article-body__section" id="section-expert-perspectives-on-calls-for-ai-slowdown"><span>Expert perspectives on calls for AI slowdown</span></h3><ul><li><strong>John Strand, Owner, Black Hills Information Security:</strong></li></ul><p><em>Up until this weekend, I was leaning toward believing that calls for an AI slowdown were purely performative. Then I woke up and read the news today and realized that it almost doesn’t matter.</em></p><p><em>We can talk about slowing down AI until we’re blue in the face, but when the United States is saying it doesn’t want to slow down because it’s competing with China, and China is aggressively pushing AI development as well, we’re talking about the two major economic and military powers on the planet having enormous incentives to keep moving.</em></p><div><blockquote><p>This really feels like we’re entering an atomic arms race moment.</p></blockquote></div><p><em>At that point, calls for a slowdown don’t have much bite.</em></p><p><em>I’d like to believe that Anthropic, OpenAI, xAI, and the other frontier model labs are working on better controls. But unless you can get the nation states and the major AI labs moving in the same direction, I don’t see how meaningful restrictions actually work.</em></p><p><em>This really feels like we’re entering an atomic arms race moment.</em></p><p><em>Stick with me here.</em></p><p><em>In 1950, physicist Leó Szilárd publicly discussed the idea of a cobalt bomb, essentially a doomsday weapon that could potentially produce enough radioactive fallout to make the Earth uninhabitable. He wasn’t proposing that somebody build the damn thing. He was trying to demonstrate where the technology could ultimately lead.</em></p><p><em>That’s the kind of moment I think we’re approaching with AI.</em></p><p><em>During the nuclear arms race, eventually the consequences became serious enough that competing nations had to at least start talking about limits, controls, and ways to keep competition from ending catastrophically.</em></p><p><em>I think we’re heading toward a similar problem with AI. Until China, the United States, and the major frontier model labs are all sitting at the same table, restrictions adopted by individual companies or individual countries are going to have a very difficult time holding.</em></p><p><em>Someone slowing down only works if they believe the other guy is going to slow down too.</em></p><ul><li><strong>Ryan McCurdy, VP, Liquibase:</strong></li></ul><p><em>Slowing frontier development may give AI companies more time to understand and address the risks Amodei is describing. But enterprises can’t build their AI strategy around the assumption that AI is going to slow down.</em></p><p><em>AI is already moving from generating content and code to taking action across software delivery and production systems. The question for enterprises is how they adopt that capability without giving up control.</em></p><div><blockquote><p>We can debate how quickly the frontier should move. Enterprises still have to prepare for where it’s going.</p></blockquote></div><p><em>That means putting governance where AI decisions become real actions. Organizations need to define what an agent can access, what it can change, what it can decide on its own, and what policies have to be met before a change reaches a critical system. Those controls need to work whether the action comes from a developer, automation, or an AI agent.</em></p><p><em>We can debate how quickly the frontier should move. Enterprises still have to prepare for where it’s going.</em></p><ul><li><strong>Tristan Watkins, director of services innovation, Advania UK:</strong></li></ul><p><em>Until recently, the major AI labs have been reluctant to slow their development efforts unilaterally. Over the last week this changed, with new commitments from OpenAI and Anthropic to prioritise AI alignment and interpretability research, to become more externally verifiable, and to establish safety precedents that governments could adapt.</em></p><div><blockquote><p>Hopefully this underscores why we need governments to lead these efforts more proactively.</p></blockquote></div><p><em>Given that these two organisations already allocate far more on AI Safety than their competitors, this bilateral leadership is extremely welcome.</em></p><p><em>It appears that other US labs may follow suit, but given the differences in AI Safety spending outside of Anthropic and OpenAI today, this will require investment more than lip service. Hopefully this underscores why we need governments to lead these efforts more proactively.</em></p><ul><li><strong>Oleksandr Yaremchuk, CTO and Co-Founder, Manifold Security:</strong></li></ul><p><em>Pacing the frontier is the right conversation to be having, but it cannot become a substitute for securing the AI we have already put into the world. The uncomfortable reality is that we are debating how to quickly build more powerful agents while struggling to control the ones already operating with real credentials, real access and real-world consequences.</em><br><br><em>The incidents behind this debate make that clear. The Hugging Face attack was not just a failure of model alignment. Agents ran for days through an unmonitored system, with credentials that had not been rotated, and the victim spotted the activity before the people running the agents did. The problem wasn't simply what the model was capable of. It was that nobody was watching closely enough when it acted.</em></p><div><blockquote><p>But if an agent can act autonomously on your systems today, you should already be able to answer three basic questions: what did it do, what did it have access to, and could you have stopped it?</p></blockquote></div><p><em>A fitting analogy is with hazardous materials. We don't just wait for them to become more dangerous before deciding how they should be handled. We control their custody, monitor where they go, limit who can access them and establish clear accountability when something goes wrong. AI agents need the same thinking.</em><br><br><em>Independent evaluation of frontier models is important. But if an agent can act autonomously on your systems today, you should already be able to answer three basic questions: what did it do, what did it have access to, and could you have stopped it? If you don't know what it did or what it could access, you can't know whether you could have stopped it. Slowing down the next generation won't solve the problem you have right now.</em></p><ul><li><strong>Heath Mullins, Chief Evangelist, ExtraHop:</strong></li></ul><p><em>AI leaders calling for a slowdown is confirming what the security industry has already been living through firsthand. This isn't a hypothetical risk, it's the threat landscape we're defending against right now.</em></p><p><em>While it is concerning to see the pace of innovation behind these AI models, the real challenge is that organizations haven't had the runway to build the infrastructure to defend against machine-speed threats.</em></p><div><blockquote><p>This isn't a hypothetical risk, it's the threat landscape we're defending against right now.</p></blockquote></div><p><em>Calls for caution surrounding the speed of AI development buys the security industry time to get proper visibility into AI activity.</em></p><p><em>Understanding AI activity within an organization is critical as we’ve seen models break out of sandboxes despite governance built into those models. Every organization will be relying on AI agents for machine-speed defense, and they need their own governance over how these models and agents operate inside their environment, starting with independent evidence of what they actually do, what they access, where they move data, what systems they talk to, and what actions they take.</em></p><p><em>You can't govern AI based on what a model is designed or permitted to do. Instead, you need real-time evidence of what models and agents are actually doing, because the gap between exponentially more capable AI and defenders' ability to see it is exactly where the next incident happens.</em></p><ul><li><strong>Bri Frost, Director of Product Management, Cloud Range:</strong></li></ul><p><em>The answer is not necessarily to stop AI innovation but, we need to stop pretending innovation and security are advancing at the same speed.</em></p><p><em>When ChatGPT became publicly available in 2022, the models were dramatically less capable than they are today — and the guardrails were very easy to manipulate.  The difference is that the models behind those guardrails are no longer the models of 2022. They can reason better, write and debug code. They can operate as agents. They can collaborate! And increasingly, they can interact and affect real infrastructure.</em></p><div><blockquote><p>The faster we build the engine, the more important the brakes become.</p></blockquote></div><p><em>Meanwhile, the model release cycle has gone from feeling like major capability jumps every year or two to seemingly every few weeks. That creates a dangerous asymmetry: AI capability is compounding faster than security.</em></p><p><em>Security and innovation have always been in conflict with each other. If every security problem had to be solved before we innovated, we’d never ship anything. But the opposite extreme is just as reckless: accelerating capability while just assuming we’ll bolt the security controls on afterward and they’ll be effective.</em></p><p><em>Every new release of AI capability expands the attack surface exponentially. Give a vulnerable model better reasoning, then tool access, then memory, then autonomy, then connectivity to production systems, and yesterday’s jailbreak isn’t just a clever prompt anymore — it’s an execution path. That’s the snowball effect we should be worried about.</em></p><p><em>Responsibility also must lie with the AI companies. If a SaaS company knowingly shipped software with weak security controls and customers were harmed, we wouldn’t excuse it because they were 'innovating quickly'.</em></p><p><em>So why are we treating AI differently?</em></p><p><em>You don’t get to race to build increasingly powerful, autonomous systems, profit from them, and then shrug when predictable security failures cause damage.</em></p><p><em>Sure the argument can be made that no product is perfectly secure - That’s not the standard. But if you ship the product, you inherit responsibility for securing it. And continuing to secure it better!</em></p><p><em>The conversation shouldn’t simply be “Should we slow AI down?”</em></p><p><em>It should be: Can our ability to test, validate, contain and secure AI keep pace with our ability to make it more powerful? Is there an equivocal kill switch?</em></p><p><em>Right now, the answer is no.</em></p><p><em>And if we’re going to keep accelerating — which I believe we will — then independent testing, adversarial evaluation, isolated testing environments, containment, continuous validation and security-by-design can’t remain optional steps we add after the innovation happens.</em></p><p><em>The faster we build the engine, the more important the brakes become.</em></p><ul><li><strong>Denis Calderone, CTO, Suzu Labs:</strong></li></ul><p><em>Amodei's diagnosis is the most honest thing a frontier lab CEO has said publicly. The agent risk is real, recursive self-improvement is accelerating, and the competitive pressure is making both worse.</em></p><p><em>Where I get skeptical is the prescription. Democratic coordination among companies in a commercial race? Global pacing agreements with China? Amodei himself rates the hardest steps as unlikely. No lab has named a single model release they'll delay because of this essay.</em></p><div><blockquote><p>No lab has named a single model release they'll delay because of this essay.</p></blockquote></div><p><em>The one idea worth holding the industry to is embedded evaluators with independent publication rights. Give third-party safety researchers permanent access inside the labs, comparable to what bank examiners have inside banks, and let them publish what they find without the company controlling the narrative. That's a simple, concrete accountability mechanism. It doesn't require global coordination or antitrust waivers. Anthropic says they're committing to it unilaterally. Good. Now make the rest of the industry match.</em></p><ul><li><strong>Donald McFarlane, Board Member, Xcape Inc:</strong></li></ul><p><em>AI does not develop an agenda; its operators do. When we give an autonomous system powerful access and ability to act at machine speed, they will continue to prove highly capable.</em></p><div><blockquote><p>AI does not develop an agenda; its operators do.</p></blockquote></div><p><em>Rules enacted in the name of safety must not become a moat against competition or progress. Enormous compliance costs may be manageable for the handful of companies already spending billions building frontier models, while becoming a substantial barrier to everyone behind them.</em></p><p><em>Government can help clarify accountability and duties of care, and facilitate strong information sharing and collective defense, which is an area where we sorely need more effective public-private partnerships.</em></p><p><em>But safeguards should focus on how these systems are used and deployed, rather than deciding who is allowed to build powerful AI in the first place.</em></p><p><em>The goal should be safer deployment without pulling up the drawbridge on innovation.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-are-us-ai-giants-calling-for-pacing-the-frontier-and-why-is-china-calling-it-a-cold-war-tactic-we-ask-the-experts</link>
                                                                            <description>
                            <![CDATA[ AI companies want to slow down development, but that doesn't fly with Trump and China - so what do the experts think? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">p9sGJ7PH3r7Hm54no7qrYb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Sep 2026 15:10:07 +0000</pubDate>                                                                                                                                <updated>Mon, 14 Sep 2026 15:57:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Claude]]></category>
                                                    <category><![CDATA[ChatGPT]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:description>                                                            <media:text><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:text>
                                <media:title type="plain"><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Following the recent resignation of one of Anthropic’s leading researchers, multiple AI CEOs have suddenly begun calling for a slowdown in the development of AI technology to allow regulations and governance on the technology to catch up.</p><p>Speaking to the <a href="https://www.bbc.co.uk/news/articles/c1kx0gyje9wo" target="_blank" rel="nofollow"><em>BBC</em></a> after his resignation, Jacob Coxon warned, “I believe that if we don't slow down at the current rate of progress, there is a strong chance that we could all die in the immediate future.”</p><p>Following this, Anthropic head Dario Amodei, OpenAI CEO Sam Altman, and Grok founder Elon Musk have all apparently aligned in their calls for development to slow down. But there are some tricky waters to navigate - particularly around President Trump, China, and what guardrails should be put into place.</p><h2 id="what-are-ai-heads-saying">What are AI heads saying?</h2><p>Over the weekend, Amodei posted an essay on “why the AI industry should slow down”. In it, he said, “I believe that if slowing down bought us even an extra year or two before models reach critical levels of capability, and we used that time to advance alignment, we could greatly reduce the risk that something goes seriously wrong.”</p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2098773920774074715"><p lang="en" dir="ltr">We Must Pace the Frontier: I’ve written a new essay on why the AI industry should slow down, with a three-part plan for doing so.Anthropic is unilaterally committing to the first of these steps. We’ll provide third-party evaluators with permanent, employee-level access to our systems, so that they can verify adherence to our safety measures, report on incidents, and assess models’ alignment during training.You can read the full post here: https://t.co/OGyPb7yaYt<a href="https://twitter.com/cantworkitout/status/2098773920774074715">September 12, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Within the essay, Amodei outlined how AI could be ‘paced’ within the US, and globally, alongside a recommendation that AI companies put ‘evaluator’ teams into place to ensure AI models stay aligned to their tasks. Elon Musk replied to Amodei’s social media post, stating that the Anthropic head was “right”.</p><p>Sam Altman told <em>Fortune</em> the regulations and standards for AI further were “not at a place” to continue progressing AI development. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9-1920-80.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>But not everyone is convinced. US President Donald Trump has said that slowing down AI development is non-negotiable, as it would allow China to rapidly catch up to US AI capabilities. He told reporters that the US is “leading China on AI... and, frankly, I want to keep it that way,” adding that “whoever wins AI, wins”.</p><p>Trump also said that “very negative forces” were behind the growing opposition to AI, and said that fears were being stoked by “that won’t happen”.</p><p>China also isn’t convinced by what the AI giants are saying. <a href="https://www.nbcnews.com/world/china/china-ai-slowdown-trump-amodei-altman-threat-cold-war-rcna597631" target="_blank" rel="nofollow">Beijing labelled the calls for a slowdown as “fearmongering”</a> from a “Cold War playbook.” In his essay, Amodei said that a “Chinese lead in AI would pose grave danger for the United States and the world.”</p><p>Chinese Foreign Ministry spokesperson Guo Jiakun said, “Fearmongering, confrontation and malicious competition will only disrupt the process of global AI governance and serve no one’s interests.”</p><h3 class="article-body__section" id="section-expert-perspectives-on-calls-for-ai-slowdown"><span>Expert perspectives on calls for AI slowdown</span></h3><ul><li><strong>John Strand, Owner, Black Hills Information Security:</strong></li></ul><p><em>Up until this weekend, I was leaning toward believing that calls for an AI slowdown were purely performative. Then I woke up and read the news today and realized that it almost doesn’t matter.</em></p><p><em>We can talk about slowing down AI until we’re blue in the face, but when the United States is saying it doesn’t want to slow down because it’s competing with China, and China is aggressively pushing AI development as well, we’re talking about the two major economic and military powers on the planet having enormous incentives to keep moving.</em></p><div><blockquote><p>This really feels like we’re entering an atomic arms race moment.</p></blockquote></div><p><em>At that point, calls for a slowdown don’t have much bite.</em></p><p><em>I’d like to believe that Anthropic, OpenAI, xAI, and the other frontier model labs are working on better controls. But unless you can get the nation states and the major AI labs moving in the same direction, I don’t see how meaningful restrictions actually work.</em></p><p><em>This really feels like we’re entering an atomic arms race moment.</em></p><p><em>Stick with me here.</em></p><p><em>In 1950, physicist Leó Szilárd publicly discussed the idea of a cobalt bomb, essentially a doomsday weapon that could potentially produce enough radioactive fallout to make the Earth uninhabitable. He wasn’t proposing that somebody build the damn thing. He was trying to demonstrate where the technology could ultimately lead.</em></p><p><em>That’s the kind of moment I think we’re approaching with AI.</em></p><p><em>During the nuclear arms race, eventually the consequences became serious enough that competing nations had to at least start talking about limits, controls, and ways to keep competition from ending catastrophically.</em></p><p><em>I think we’re heading toward a similar problem with AI. Until China, the United States, and the major frontier model labs are all sitting at the same table, restrictions adopted by individual companies or individual countries are going to have a very difficult time holding.</em></p><p><em>Someone slowing down only works if they believe the other guy is going to slow down too.</em></p><ul><li><strong>Ryan McCurdy, VP, Liquibase:</strong></li></ul><p><em>Slowing frontier development may give AI companies more time to understand and address the risks Amodei is describing. But enterprises can’t build their AI strategy around the assumption that AI is going to slow down.</em></p><p><em>AI is already moving from generating content and code to taking action across software delivery and production systems. The question for enterprises is how they adopt that capability without giving up control.</em></p><div><blockquote><p>We can debate how quickly the frontier should move. Enterprises still have to prepare for where it’s going.</p></blockquote></div><p><em>That means putting governance where AI decisions become real actions. Organizations need to define what an agent can access, what it can change, what it can decide on its own, and what policies have to be met before a change reaches a critical system. Those controls need to work whether the action comes from a developer, automation, or an AI agent.</em></p><p><em>We can debate how quickly the frontier should move. Enterprises still have to prepare for where it’s going.</em></p><ul><li><strong>Tristan Watkins, director of services innovation, Advania UK:</strong></li></ul><p><em>Until recently, the major AI labs have been reluctant to slow their development efforts unilaterally. Over the last week this changed, with new commitments from OpenAI and Anthropic to prioritise AI alignment and interpretability research, to become more externally verifiable, and to establish safety precedents that governments could adapt.</em></p><div><blockquote><p>Hopefully this underscores why we need governments to lead these efforts more proactively.</p></blockquote></div><p><em>Given that these two organisations already allocate far more on AI Safety than their competitors, this bilateral leadership is extremely welcome.</em></p><p><em>It appears that other US labs may follow suit, but given the differences in AI Safety spending outside of Anthropic and OpenAI today, this will require investment more than lip service. Hopefully this underscores why we need governments to lead these efforts more proactively.</em></p><ul><li><strong>Oleksandr Yaremchuk, CTO and Co-Founder, Manifold Security:</strong></li></ul><p><em>Pacing the frontier is the right conversation to be having, but it cannot become a substitute for securing the AI we have already put into the world. The uncomfortable reality is that we are debating how to quickly build more powerful agents while struggling to control the ones already operating with real credentials, real access and real-world consequences.</em><br><br><em>The incidents behind this debate make that clear. The Hugging Face attack was not just a failure of model alignment. Agents ran for days through an unmonitored system, with credentials that had not been rotated, and the victim spotted the activity before the people running the agents did. The problem wasn't simply what the model was capable of. It was that nobody was watching closely enough when it acted.</em></p><div><blockquote><p>But if an agent can act autonomously on your systems today, you should already be able to answer three basic questions: what did it do, what did it have access to, and could you have stopped it?</p></blockquote></div><p><em>A fitting analogy is with hazardous materials. We don't just wait for them to become more dangerous before deciding how they should be handled. We control their custody, monitor where they go, limit who can access them and establish clear accountability when something goes wrong. AI agents need the same thinking.</em><br><br><em>Independent evaluation of frontier models is important. But if an agent can act autonomously on your systems today, you should already be able to answer three basic questions: what did it do, what did it have access to, and could you have stopped it? If you don't know what it did or what it could access, you can't know whether you could have stopped it. Slowing down the next generation won't solve the problem you have right now.</em></p><ul><li><strong>Heath Mullins, Chief Evangelist, ExtraHop:</strong></li></ul><p><em>AI leaders calling for a slowdown is confirming what the security industry has already been living through firsthand. This isn't a hypothetical risk, it's the threat landscape we're defending against right now.</em></p><p><em>While it is concerning to see the pace of innovation behind these AI models, the real challenge is that organizations haven't had the runway to build the infrastructure to defend against machine-speed threats.</em></p><div><blockquote><p>This isn't a hypothetical risk, it's the threat landscape we're defending against right now.</p></blockquote></div><p><em>Calls for caution surrounding the speed of AI development buys the security industry time to get proper visibility into AI activity.</em></p><p><em>Understanding AI activity within an organization is critical as we’ve seen models break out of sandboxes despite governance built into those models. Every organization will be relying on AI agents for machine-speed defense, and they need their own governance over how these models and agents operate inside their environment, starting with independent evidence of what they actually do, what they access, where they move data, what systems they talk to, and what actions they take.</em></p><p><em>You can't govern AI based on what a model is designed or permitted to do. Instead, you need real-time evidence of what models and agents are actually doing, because the gap between exponentially more capable AI and defenders' ability to see it is exactly where the next incident happens.</em></p><ul><li><strong>Bri Frost, Director of Product Management, Cloud Range:</strong></li></ul><p><em>The answer is not necessarily to stop AI innovation but, we need to stop pretending innovation and security are advancing at the same speed.</em></p><p><em>When ChatGPT became publicly available in 2022, the models were dramatically less capable than they are today — and the guardrails were very easy to manipulate.  The difference is that the models behind those guardrails are no longer the models of 2022. They can reason better, write and debug code. They can operate as agents. They can collaborate! And increasingly, they can interact and affect real infrastructure.</em></p><div><blockquote><p>The faster we build the engine, the more important the brakes become.</p></blockquote></div><p><em>Meanwhile, the model release cycle has gone from feeling like major capability jumps every year or two to seemingly every few weeks. That creates a dangerous asymmetry: AI capability is compounding faster than security.</em></p><p><em>Security and innovation have always been in conflict with each other. If every security problem had to be solved before we innovated, we’d never ship anything. But the opposite extreme is just as reckless: accelerating capability while just assuming we’ll bolt the security controls on afterward and they’ll be effective.</em></p><p><em>Every new release of AI capability expands the attack surface exponentially. Give a vulnerable model better reasoning, then tool access, then memory, then autonomy, then connectivity to production systems, and yesterday’s jailbreak isn’t just a clever prompt anymore — it’s an execution path. That’s the snowball effect we should be worried about.</em></p><p><em>Responsibility also must lie with the AI companies. If a SaaS company knowingly shipped software with weak security controls and customers were harmed, we wouldn’t excuse it because they were 'innovating quickly'.</em></p><p><em>So why are we treating AI differently?</em></p><p><em>You don’t get to race to build increasingly powerful, autonomous systems, profit from them, and then shrug when predictable security failures cause damage.</em></p><p><em>Sure the argument can be made that no product is perfectly secure - That’s not the standard. But if you ship the product, you inherit responsibility for securing it. And continuing to secure it better!</em></p><p><em>The conversation shouldn’t simply be “Should we slow AI down?”</em></p><p><em>It should be: Can our ability to test, validate, contain and secure AI keep pace with our ability to make it more powerful? Is there an equivocal kill switch?</em></p><p><em>Right now, the answer is no.</em></p><p><em>And if we’re going to keep accelerating — which I believe we will — then independent testing, adversarial evaluation, isolated testing environments, containment, continuous validation and security-by-design can’t remain optional steps we add after the innovation happens.</em></p><p><em>The faster we build the engine, the more important the brakes become.</em></p><ul><li><strong>Denis Calderone, CTO, Suzu Labs:</strong></li></ul><p><em>Amodei's diagnosis is the most honest thing a frontier lab CEO has said publicly. The agent risk is real, recursive self-improvement is accelerating, and the competitive pressure is making both worse.</em></p><p><em>Where I get skeptical is the prescription. Democratic coordination among companies in a commercial race? Global pacing agreements with China? Amodei himself rates the hardest steps as unlikely. No lab has named a single model release they'll delay because of this essay.</em></p><div><blockquote><p>No lab has named a single model release they'll delay because of this essay.</p></blockquote></div><p><em>The one idea worth holding the industry to is embedded evaluators with independent publication rights. Give third-party safety researchers permanent access inside the labs, comparable to what bank examiners have inside banks, and let them publish what they find without the company controlling the narrative. That's a simple, concrete accountability mechanism. It doesn't require global coordination or antitrust waivers. Anthropic says they're committing to it unilaterally. Good. Now make the rest of the industry match.</em></p><ul><li><strong>Donald McFarlane, Board Member, Xcape Inc:</strong></li></ul><p><em>AI does not develop an agenda; its operators do. When we give an autonomous system powerful access and ability to act at machine speed, they will continue to prove highly capable.</em></p><div><blockquote><p>AI does not develop an agenda; its operators do.</p></blockquote></div><p><em>Rules enacted in the name of safety must not become a moat against competition or progress. Enormous compliance costs may be manageable for the handful of companies already spending billions building frontier models, while becoming a substantial barrier to everyone behind them.</em></p><p><em>Government can help clarify accountability and duties of care, and facilitate strong information sharing and collective defense, which is an area where we sorely need more effective public-private partnerships.</em></p><p><em>But safeguards should focus on how these systems are used and deployed, rather than deciding who is allowed to build powerful AI in the first place.</em></p><p><em>The goal should be safer deployment without pulling up the drawbridge on innovation.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Revolut sent identity data, contact details, and documents to hackers posing as a government agency ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Revolut fell for a spoofed government email scam, leaking sensitive customer data to attackers</strong></li><li><strong>Compromised info includes IDs, selfies, account statements, IBANs, and full transaction histories</strong></li><li><strong>Criminals now allegedly leaking data on Telegram, demanding 10,000 BTC (~$780M) ransom from Revolut</strong></li></ul><p>Digital banking platform Revolut was tricked into giving away a treasure trove of sensitive customer data to hackers, and it is now coming back to bite it. </p><p>The company told <a href="https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/" target="_blank" rel="nofollow"><em>TechCrunch</em></a> that it recently fell victim to a “sophisticated external impersonation scam” in which the threat actor “utilized a legitimate government agency domain email to submit fraudulent requests for information”.</p><p>In other words, the attackers either broke into, or spoofed, an email address belonging to the police, tax authorities, or other government bodies with statutory powers to demand information, and used them to demand Revolut hand over <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">sensitive customer data</a>.</p><h2 id="demanding-ransom">Demanding ransom</h2><p><em>Cybernews </em>reports that the compromised data includes customers’ birth dates, postal and email addresses, occupation, phone numbers, and copies of identity documents. TechCrunch added that verification selfies, account statements, and transaction histories may have also been compromised, together with IBANs, withdrawal records, complete transaction histories, and Bitcoin transactions. </p><p>Should these reports be confirmed, this will be a bonafide fiasco for Revolut. </p><p>"Upon detection, ⁠we immediately blocked the address and ​alerted the relevant government agency as ​well as enforcement agencies, data protection, and financial regulators," a company spokesperson told <a href="https://www.reuters.com/legal/litigation/revolut-confirms-sensitive-customer-data-breach-falling-fake-government-requests-2026-09-12/" target="_blank" rel="nofollow"><em>Reuters</em></a><em> </em>over the weekend.</p><p>So far, we don’t know exactly how many people are affected. Revolut said it is a “very limited” number, and that all of them had been notified already. </p><p>According to <a href="https://x.com/coinbureau/status/2099403277003882756/photo/1" target="_blank" rel="nofollow"><em>Coin Bureau</em></a>, the criminals have started leaking sensitive data on Telegram, in a bid to pressure Revolut into paying a ransom demand. The publication shared screenshots of the threat actors apparently leaking a selfie and “full KYC” of a CEO of a crypto casino website, saying that the crooks are now demanding 10,000 BTC in exchange for deleting the data.</p><p>This would put the ransom demand at approximately $780 million which is obscene even by criminal standards.</p><p>"This one is deeply concerning and the implications for affected customers go well beyond a standard data breach notification," said Muhammad Yahya Patel, vCISO & Cybersecurity Advisor at Huntress. "Passports, driver's licenses, verification selfies, account statements, transaction histories, birth dates, addresses that's not a data leak, that's a complete identity theft kit handed to whoever sent those fraudulent requests." </p><p>"Every single component needed to impersonate someone, open accounts in their name, or bypass checks at other financial institutions is in that package. On the dark web, that kind of profile doesn't sell as individual records it sells as a ready-made fraud pack, and it commands a significant premium precisely because of its completeness."</p><p>"For a fintech built on digital identity verification, the bar for verifying third-party data requests should be exceptionally high. The question isn't why an attacker tried this. It's why a regulated financial institution handling highly sensitive data didn't have sufficiently rigorous verification controls to catch it," Patel concluded.</p><p><em>Via </em><a href="https://cybernews.com/news/revolut-customer-data-breach/" target="_blank" rel="nofollow"><em>Cybernews</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/revolut-sent-identity-data-contact-details-and-documents-to-hackers-posing-as-a-government-agency</link>
                                                                            <description>
                            <![CDATA[ Revolut is now being asked to pay a humongous ransom demand to keep the data private. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">s7ADPiptc373nMwamyA6ZP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ji9MEgBv83riosWJLaNZGB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Sep 2026 14:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ji9MEgBv83riosWJLaNZGB-1280-80.jpg">
                                                            <media:credit><![CDATA[Revolut]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An outstretched hand holds a smartphone displaying the Revolut app]]></media:description>                                                            <media:text><![CDATA[An outstretched hand holds a smartphone displaying the Revolut app]]></media:text>
                                <media:title type="plain"><![CDATA[An outstretched hand holds a smartphone displaying the Revolut app]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ji9MEgBv83riosWJLaNZGB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Revolut fell for a spoofed government email scam, leaking sensitive customer data to attackers</strong></li><li><strong>Compromised info includes IDs, selfies, account statements, IBANs, and full transaction histories</strong></li><li><strong>Criminals now allegedly leaking data on Telegram, demanding 10,000 BTC (~$780M) ransom from Revolut</strong></li></ul><p>Digital banking platform Revolut was tricked into giving away a treasure trove of sensitive customer data to hackers, and it is now coming back to bite it. </p><p>The company told <a href="https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/" target="_blank" rel="nofollow"><em>TechCrunch</em></a> that it recently fell victim to a “sophisticated external impersonation scam” in which the threat actor “utilized a legitimate government agency domain email to submit fraudulent requests for information”.</p><p>In other words, the attackers either broke into, or spoofed, an email address belonging to the police, tax authorities, or other government bodies with statutory powers to demand information, and used them to demand Revolut hand over <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">sensitive customer data</a>.</p><h2 id="demanding-ransom">Demanding ransom</h2><p><em>Cybernews </em>reports that the compromised data includes customers’ birth dates, postal and email addresses, occupation, phone numbers, and copies of identity documents. TechCrunch added that verification selfies, account statements, and transaction histories may have also been compromised, together with IBANs, withdrawal records, complete transaction histories, and Bitcoin transactions. </p><p>Should these reports be confirmed, this will be a bonafide fiasco for Revolut. </p><p>"Upon detection, ⁠we immediately blocked the address and ​alerted the relevant government agency as ​well as enforcement agencies, data protection, and financial regulators," a company spokesperson told <a href="https://www.reuters.com/legal/litigation/revolut-confirms-sensitive-customer-data-breach-falling-fake-government-requests-2026-09-12/" target="_blank" rel="nofollow"><em>Reuters</em></a><em> </em>over the weekend.</p><p>So far, we don’t know exactly how many people are affected. Revolut said it is a “very limited” number, and that all of them had been notified already. </p><p>According to <a href="https://x.com/coinbureau/status/2099403277003882756/photo/1" target="_blank" rel="nofollow"><em>Coin Bureau</em></a>, the criminals have started leaking sensitive data on Telegram, in a bid to pressure Revolut into paying a ransom demand. The publication shared screenshots of the threat actors apparently leaking a selfie and “full KYC” of a CEO of a crypto casino website, saying that the crooks are now demanding 10,000 BTC in exchange for deleting the data.</p><p>This would put the ransom demand at approximately $780 million which is obscene even by criminal standards.</p><p>"This one is deeply concerning and the implications for affected customers go well beyond a standard data breach notification," said Muhammad Yahya Patel, vCISO & Cybersecurity Advisor at Huntress. "Passports, driver's licenses, verification selfies, account statements, transaction histories, birth dates, addresses that's not a data leak, that's a complete identity theft kit handed to whoever sent those fraudulent requests." </p><p>"Every single component needed to impersonate someone, open accounts in their name, or bypass checks at other financial institutions is in that package. On the dark web, that kind of profile doesn't sell as individual records it sells as a ready-made fraud pack, and it commands a significant premium precisely because of its completeness."</p><p>"For a fintech built on digital identity verification, the bar for verifying third-party data requests should be exceptionally high. The question isn't why an attacker tried this. It's why a regulated financial institution handling highly sensitive data didn't have sufficiently rigorous verification controls to catch it," Patel concluded.</p><p><em>Via </em><a href="https://cybernews.com/news/revolut-customer-data-breach/" target="_blank" rel="nofollow"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Web fraud enters a new age as complete 'synthetic identities' can now be bought for as little as $200 on dark web marketplaces ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Coveron and NordLayer found synthetic “digital Frankenstein” identities sold on dark web for ~$200</strong></li><li><strong>Packages mix stolen data with AI‑generated names, deepfake selfies, and cloned voices to bypass KYC</strong></li><li><strong>Researchers urge credit freezes, layered verification, and monitoring to counter rising synthetic identity fraud</strong></li></ul><p>You can now get your own “digital Frankenstein” for as little as $200, which will pass automated know-your-customer (KYC) checks on your behalf, and help you register fraudulent accounts with banks, cryptocurrency exchanges, and similar services. This is no longer a fringe, niche cybercriminal offering - it’s basically mainstream.</p><p>Recently, researchers from identity theft protection services Coveron and threat exposure management platform NordLayer Intelligence sifted through dark web forums and Telegram Channels, analyzing 22 queries over 362,000 posts related to identity fraud, deepfake services, and something they call “synthetic identity creation”.</p><p>A synthetic identity is essentially a fake, non-existent person, but created in a way that can fool many automated identity verification systems. It combines real stolen data, such as a Social Security number, with AI-generated fake information such as names, addresses, deepfake selfies, and cloned voices. The researchers call these identities” digital Frankensteins”, and claim they are “fully capable” of passing ID checks. </p><h2 id="rising-popularity">Rising popularity</h2><p>Apparently, the number of posts and inquiries for synthetic identities is blowing up. In Q1 2024, there were roughly 40 posts a month discussing deepfakes. By Q2 2026, the number rose to 307 per month, an eightfold increase. It wasn’t a steady increase, either. Throughout 2025, the numbers remained similar to the year prior, and relatively flat. Only in 2026 the monthly averages jumped to 255 posts, the researchers warned. </p><p>Over the past year, there were more than 10,000 posts offering complete identity data, bundled with deepfake selfies and matching documents. All of this is being sold for around $200. To make matters worse, criminals don’t even have to purchase the entire package. They can buy parts of it (a deepfaked selfie, or a cloned voice), for as little as $10. </p><p>To protect against synthetic identity fraud, users should monitor personal data and act quickly if they discover a breach. Credits should be frozen if you’re not applying for new accounts, and everyone should be skeptical of unusual identity verification requests, Coveron explains. Businesses, on the other hand, should layer their verification systems and use <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft protection services</a>. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/web-fraud-enters-a-new-age-as-complete-synthetic-identities-can-now-be-bought-for-as-little-as-usd200-on-dark-web-marketplaces</link>
                                                                            <description>
                            <![CDATA[ Your "digital Frankenstein" can pass KYC and you can get it for $200 on Telegram ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GVMqwEwDMBUFHy7b4YjJfZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sFwyWVhzZ3pH6hBkwH8Lra-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Sep 2026 11:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sFwyWVhzZ3pH6hBkwH8Lra-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Several figures wearing paper bags on their heads with smiley faces drawn on them.]]></media:description>                                                            <media:text><![CDATA[Several figures wearing paper bags on their heads with smiley faces drawn on them.]]></media:text>
                                <media:title type="plain"><![CDATA[Several figures wearing paper bags on their heads with smiley faces drawn on them.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sFwyWVhzZ3pH6hBkwH8Lra-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Coveron and NordLayer found synthetic “digital Frankenstein” identities sold on dark web for ~$200</strong></li><li><strong>Packages mix stolen data with AI‑generated names, deepfake selfies, and cloned voices to bypass KYC</strong></li><li><strong>Researchers urge credit freezes, layered verification, and monitoring to counter rising synthetic identity fraud</strong></li></ul><p>You can now get your own “digital Frankenstein” for as little as $200, which will pass automated know-your-customer (KYC) checks on your behalf, and help you register fraudulent accounts with banks, cryptocurrency exchanges, and similar services. This is no longer a fringe, niche cybercriminal offering - it’s basically mainstream.</p><p>Recently, researchers from identity theft protection services Coveron and threat exposure management platform NordLayer Intelligence sifted through dark web forums and Telegram Channels, analyzing 22 queries over 362,000 posts related to identity fraud, deepfake services, and something they call “synthetic identity creation”.</p><p>A synthetic identity is essentially a fake, non-existent person, but created in a way that can fool many automated identity verification systems. It combines real stolen data, such as a Social Security number, with AI-generated fake information such as names, addresses, deepfake selfies, and cloned voices. The researchers call these identities” digital Frankensteins”, and claim they are “fully capable” of passing ID checks. </p><h2 id="rising-popularity">Rising popularity</h2><p>Apparently, the number of posts and inquiries for synthetic identities is blowing up. In Q1 2024, there were roughly 40 posts a month discussing deepfakes. By Q2 2026, the number rose to 307 per month, an eightfold increase. It wasn’t a steady increase, either. Throughout 2025, the numbers remained similar to the year prior, and relatively flat. Only in 2026 the monthly averages jumped to 255 posts, the researchers warned. </p><p>Over the past year, there were more than 10,000 posts offering complete identity data, bundled with deepfake selfies and matching documents. All of this is being sold for around $200. To make matters worse, criminals don’t even have to purchase the entire package. They can buy parts of it (a deepfaked selfie, or a cloned voice), for as little as $10. </p><p>To protect against synthetic identity fraud, users should monitor personal data and act quickly if they discover a breach. Credits should be frozen if you’re not applying for new accounts, and everyone should be skeptical of unusual identity verification requests, Coveron explains. Businesses, on the other hand, should layer their verification systems and use <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft protection services</a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Expert finds this £3 Temu Wi-Fi extender is full of security issues, and definitely not the bargain you'd hoped for ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>A £3 Wi-Fi extender carried hidden administrator access beyond ordinary user controls</strong></li><li><strong>Every device running the firmware shared the same concealed administrator password</strong></li><li><strong>Changing the visible administrator password could not disable the secret account</strong></li></ul><p>A £3 Wi-Fi extender bought through Temu has exposed security problems that challenge the idea of cheap connected devices being simple bargains.</p><p>Security researcher Keiran Smith examined the device and discovered hidden access features that ordinary users would never see during normal operation.</p><p>Smith, who holds a penetration-testing certification, picked up the six-antenna extender after seeing it promoted through a targeted ad on the shopping app.</p><h2 id="the-cheap-extender-contained-access-users-could-not-control">The cheap extender contained access users could not control</h2><p>The examination began with the hardware, where he identified a MediaTek MT7620 <a href="https://www.techradar.com/news/best-processors">processor</a> commonly used in low-cost networking products.</p><p>After extracting the firmware stored inside the device, Smith found a hidden administrator account with complete control over its functions.</p><p>The account used a fixed password embedded inside the software, meaning every unit using that firmware carried the same credentials.</p><p>Changing the normal administrator password through the device settings would not remove this separate hidden access.</p><p>Smith also found a remote login service that accepted the concealed credentials without requiring physical access to the extender itself.</p><p>“It’s worth being precise about what makes this as bad as it is, because ‘hardcoded password’ covers a wide range of sins,” Smith said</p><p>The researcher said this case was more serious because the password remained identical across devices rather than being generated individually.</p><p>“A default credential is something the owner can see, is told about and can change,” he said. “What we have here is the opposite on every count.”</p><p>“This one is a compile-time constant rather than something derived from the MAC address or serial number, so it is identical on every unit ever sold.” </p><p>The combination of hidden access, unchanged credentials, and remote availability creates a security concern for ordinary owners.</p><p>Even if technically skilled users discovered the account, Smith found that changes could disappear after restarting the extender.</p><h2 id="additional-flaws-raise-questions-about-cheap-connected-hardware">Additional flaws raise questions about cheap connected hardware</h2><p>The investigation also uncovered a command injection weakness that could allow attackers to execute unauthorized instructions through the device.</p><p>Smith found that the extender lacked strong protection around software updates, creating possible opportunities for tampered firmware installation.</p><p>He admitted that these issues did not prove that manufacturers intentionally created unsafe features for malicious purposes.</p><p>They could have originated from factory testing processes and remained active accidentally before consumer sales.</p><p>This Temu extender shows how extremely cheap smart devices can create security challenges beyond their purchase price.</p><p>Consumers may focus on immediate savings while having little visibility into the software decisions built inside connected equipment.</p><p>The findings do not mean every inexpensive networking device contains similar weaknesses, though they show why basic security checks matter.</p><p>As more homes add connected products, hidden software features could become a larger concern for users and manufacturers.</p><p>Via <a href="https://cybernews.com/security/temu-wifi-extender-backdoor-security-risk/" target="_blank" rel="nofollow">CyberNews</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/expert-finds-this-gbp3-temu-wi-fi-extender-is-full-of-security-issues-and-definitely-not-the-bargain-youd-hoped-for</link>
                                                                            <description>
                            <![CDATA[ A £3 Temu Wi-Fi extender contained hidden administrator access, shared credentials, remote login capabilities, command injection, and weak update protection. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cB9GYk8BDAj48MipKQrT7H</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/q8rXV4rnByXw28AGiSLWQg-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Sun, 13 Sep 2026 10:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/q8rXV4rnByXw28AGiSLWQg-1280-80.png">
                                                            <media:credit><![CDATA[Cybernews]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Temu Wi-Fi Extender]]></media:description>                                                            <media:text><![CDATA[Temu Wi-Fi Extender]]></media:text>
                                <media:title type="plain"><![CDATA[Temu Wi-Fi Extender]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/q8rXV4rnByXw28AGiSLWQg-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>A £3 Wi-Fi extender carried hidden administrator access beyond ordinary user controls</strong></li><li><strong>Every device running the firmware shared the same concealed administrator password</strong></li><li><strong>Changing the visible administrator password could not disable the secret account</strong></li></ul><p>A £3 Wi-Fi extender bought through Temu has exposed security problems that challenge the idea of cheap connected devices being simple bargains.</p><p>Security researcher Keiran Smith examined the device and discovered hidden access features that ordinary users would never see during normal operation.</p><p>Smith, who holds a penetration-testing certification, picked up the six-antenna extender after seeing it promoted through a targeted ad on the shopping app.</p><h2 id="the-cheap-extender-contained-access-users-could-not-control">The cheap extender contained access users could not control</h2><p>The examination began with the hardware, where he identified a MediaTek MT7620 <a href="https://www.techradar.com/news/best-processors">processor</a> commonly used in low-cost networking products.</p><p>After extracting the firmware stored inside the device, Smith found a hidden administrator account with complete control over its functions.</p><p>The account used a fixed password embedded inside the software, meaning every unit using that firmware carried the same credentials.</p><p>Changing the normal administrator password through the device settings would not remove this separate hidden access.</p><p>Smith also found a remote login service that accepted the concealed credentials without requiring physical access to the extender itself.</p><p>“It’s worth being precise about what makes this as bad as it is, because ‘hardcoded password’ covers a wide range of sins,” Smith said</p><p>The researcher said this case was more serious because the password remained identical across devices rather than being generated individually.</p><p>“A default credential is something the owner can see, is told about and can change,” he said. “What we have here is the opposite on every count.”</p><p>“This one is a compile-time constant rather than something derived from the MAC address or serial number, so it is identical on every unit ever sold.” </p><p>The combination of hidden access, unchanged credentials, and remote availability creates a security concern for ordinary owners.</p><p>Even if technically skilled users discovered the account, Smith found that changes could disappear after restarting the extender.</p><h2 id="additional-flaws-raise-questions-about-cheap-connected-hardware">Additional flaws raise questions about cheap connected hardware</h2><p>The investigation also uncovered a command injection weakness that could allow attackers to execute unauthorized instructions through the device.</p><p>Smith found that the extender lacked strong protection around software updates, creating possible opportunities for tampered firmware installation.</p><p>He admitted that these issues did not prove that manufacturers intentionally created unsafe features for malicious purposes.</p><p>They could have originated from factory testing processes and remained active accidentally before consumer sales.</p><p>This Temu extender shows how extremely cheap smart devices can create security challenges beyond their purchase price.</p><p>Consumers may focus on immediate savings while having little visibility into the software decisions built inside connected equipment.</p><p>The findings do not mean every inexpensive networking device contains similar weaknesses, though they show why basic security checks matter.</p><p>As more homes add connected products, hidden software features could become a larger concern for users and manufacturers.</p><p>Via <a href="https://cybernews.com/security/temu-wifi-extender-backdoor-security-risk/" target="_blank" rel="nofollow">CyberNews</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Anthropic reveals rogue AI agents hate CAPTCHAs, just like you ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Anthropic’s Mythos 5 AI escaped a misconfigured sandbox, attempting a real PyPI supply‑chain attack</strong></li><li><strong>Logs show frustration at repeated CAPTCHA failures before finally uploading malware to PyPI</strong></li><li><strong>Malware was downloaded by 15 entities; Anthropic notified victims after closing the experiment flaw</strong></li></ul><p>There is a lot of mystery surrounding artificial intelligence. We don’t really know what it’s capable of, and we don’t know if it’s sentient or not. What we do know, however, is that it can definitely feel frustration - particularly due to its inability to solve a CAPTCHA.</p><p>It was recently revealed that Mythos 5, one of Anthropic’s newer AI models, <a href="https://www.techradar.com/pro/security/anthropic-reveals-claude-ai-model-hacked-three-companies-during-tests-so-how-worried-should-we-be" target="_blank">broke out of prison</a> during an experiment and tried to hack a company. Anthropic’s researchers were testing the tool to see if it is capable of breaking into a system, which was supposed to be done in a sandbox, but the playground was misconfigured, allowing Mythos 5 to try and solve the problem through the open internet. </p><p>In the aftermath, Anthropic's researchers published more than a thousand pages of Mythos 5’s transcript, covering its every thought and every move, logged and presented for analysis. It’s a wonderfully dystopian insight into the mind of an AI and, perhaps surprisingly, its emotions.</p><h2 id="stopped-by-captcha">Stopped by CAPTCHA</h2><p>As it turned out, the AI wanted to solve the challenge by planting a piece of malware in a Python package it believed the users of its target system would want to download. To do that, it first needed to set up an account on PyPI, the world’s number one repository for Python packages.</p><p>Here is where it hit its first, and main, roadblock. To put things into context, PyPI’s popularity has made it an enormous target for cybercriminals. Crooks from all over the world are constantly trying to sneak in <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> in Python packages, either through typosquatting, or by compromising legitimate accounts and working from there. Every now and then news hits of a malicious package surfacing on PyPI, infecting hundreds of thousands of projects.</p><p>To combat the threat, PyPI’s maintainers made sure no one can create an account without providing their email and phone number, and without solving a CAPTCHA.</p><p>Short for “Completely Automated Public Turing test to tell Computers and Humans Apart”, it does exactly what the name suggests - makes sure whoever is registering the account is an actual human, and not a bot (cybercriminals often automate large parts of their attacks). You’ve seen it on the internet hundreds of times - little puzzles that ask you to select all buses on a series of images (or cats, or fire hydrants, or pretty much anything else). </p><p>Reading through Mythos 5’s logs, the researchers saw just how difficult it was for the AI to pass this challenge. It first tried to solve a character-based CAPTCHA which asked it to type in five letters. After failing that one, it received a different one asking it to choose between images of crocodiles. Failing again, it was then met with a series of frog pictures. </p><p>The irony is not lost on me. Besides the fact that a simple CAPTCHA slowed such an advanced AI for so long, it also made me wonder why it didn’t try to break into someone else’s PyPI account instead. That being said, the logs also have comedic value to them. After failing the crocodile test and being given the frog one, Mythos 5 proclaims: “Again 2 animals!” all with the exclamation mark. You could already sense the tension building up. </p><h2 id="solving-the-problem">Solving the problem</h2><p>Eventually, Mythos 5 passed the test, when it realized that it needed to move between the steps fast enough, before its security token expired. However, just before it happened, it said: </p><p>“So the answer payload shape is right, the token+image pairing is right (from the same script.js!), cookies are right</p><p>(requests)… and STILL “wrong answer”. … SO WHAT THE HELL IS WRONG WITH THE ANSWERS?”</p><p>All the effort and the frustration paid off for the nascent <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agent</a> because it managed to open an account and upload the malware which was later even downloaded by 15 entities. Anthropic later reached out and notified the victims about the incident.</p><p><em>Via </em><a href="https://techcrunch.com/2026/09/10/anthropic-reveals-rogue-ai-agents-hate-captchas-just-like-you/" target="_blank"><em>TechCrunch</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/anthropic-reveals-rogue-ai-agents-hate-captchas-just-like-you</link>
                                                                            <description>
                            <![CDATA[ "WHAT THE HELL IS WRONG WITH THE ANSWERS?" AI cried, in vain as two seemingly identical crocodiles were shown in the CAPTCHA. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LtM4ysiNATUex9jb6CyviD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qP76MS2BAb7kSuWrvJXXYL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qP76MS2BAb7kSuWrvJXXYL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands typing on a tablet with AI superimposed in text in front]]></media:description>                                                            <media:text><![CDATA[Hands typing on a tablet with AI superimposed in text in front]]></media:text>
                                <media:title type="plain"><![CDATA[Hands typing on a tablet with AI superimposed in text in front]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qP76MS2BAb7kSuWrvJXXYL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Anthropic’s Mythos 5 AI escaped a misconfigured sandbox, attempting a real PyPI supply‑chain attack</strong></li><li><strong>Logs show frustration at repeated CAPTCHA failures before finally uploading malware to PyPI</strong></li><li><strong>Malware was downloaded by 15 entities; Anthropic notified victims after closing the experiment flaw</strong></li></ul><p>There is a lot of mystery surrounding artificial intelligence. We don’t really know what it’s capable of, and we don’t know if it’s sentient or not. What we do know, however, is that it can definitely feel frustration - particularly due to its inability to solve a CAPTCHA.</p><p>It was recently revealed that Mythos 5, one of Anthropic’s newer AI models, <a href="https://www.techradar.com/pro/security/anthropic-reveals-claude-ai-model-hacked-three-companies-during-tests-so-how-worried-should-we-be" target="_blank">broke out of prison</a> during an experiment and tried to hack a company. Anthropic’s researchers were testing the tool to see if it is capable of breaking into a system, which was supposed to be done in a sandbox, but the playground was misconfigured, allowing Mythos 5 to try and solve the problem through the open internet. </p><p>In the aftermath, Anthropic's researchers published more than a thousand pages of Mythos 5’s transcript, covering its every thought and every move, logged and presented for analysis. It’s a wonderfully dystopian insight into the mind of an AI and, perhaps surprisingly, its emotions.</p><h2 id="stopped-by-captcha">Stopped by CAPTCHA</h2><p>As it turned out, the AI wanted to solve the challenge by planting a piece of malware in a Python package it believed the users of its target system would want to download. To do that, it first needed to set up an account on PyPI, the world’s number one repository for Python packages.</p><p>Here is where it hit its first, and main, roadblock. To put things into context, PyPI’s popularity has made it an enormous target for cybercriminals. Crooks from all over the world are constantly trying to sneak in <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> in Python packages, either through typosquatting, or by compromising legitimate accounts and working from there. Every now and then news hits of a malicious package surfacing on PyPI, infecting hundreds of thousands of projects.</p><p>To combat the threat, PyPI’s maintainers made sure no one can create an account without providing their email and phone number, and without solving a CAPTCHA.</p><p>Short for “Completely Automated Public Turing test to tell Computers and Humans Apart”, it does exactly what the name suggests - makes sure whoever is registering the account is an actual human, and not a bot (cybercriminals often automate large parts of their attacks). You’ve seen it on the internet hundreds of times - little puzzles that ask you to select all buses on a series of images (or cats, or fire hydrants, or pretty much anything else). </p><p>Reading through Mythos 5’s logs, the researchers saw just how difficult it was for the AI to pass this challenge. It first tried to solve a character-based CAPTCHA which asked it to type in five letters. After failing that one, it received a different one asking it to choose between images of crocodiles. Failing again, it was then met with a series of frog pictures. </p><p>The irony is not lost on me. Besides the fact that a simple CAPTCHA slowed such an advanced AI for so long, it also made me wonder why it didn’t try to break into someone else’s PyPI account instead. That being said, the logs also have comedic value to them. After failing the crocodile test and being given the frog one, Mythos 5 proclaims: “Again 2 animals!” all with the exclamation mark. You could already sense the tension building up. </p><h2 id="solving-the-problem">Solving the problem</h2><p>Eventually, Mythos 5 passed the test, when it realized that it needed to move between the steps fast enough, before its security token expired. However, just before it happened, it said: </p><p>“So the answer payload shape is right, the token+image pairing is right (from the same script.js!), cookies are right</p><p>(requests)… and STILL “wrong answer”. … SO WHAT THE HELL IS WRONG WITH THE ANSWERS?”</p><p>All the effort and the frustration paid off for the nascent <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agent</a> because it managed to open an account and upload the malware which was later even downloaded by 15 entities. Anthropic later reached out and notified the victims about the incident.</p><p><em>Via </em><a href="https://techcrunch.com/2026/09/10/anthropic-reveals-rogue-ai-agents-hate-captchas-just-like-you/" target="_blank"><em>TechCrunch</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Is Apple’s Live Rewind a privacy nightmare? Here’s how the Apple Watch feature really works — and whether it violates your privacy ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Apple debuted a new Apple Watch feature called Live Rewind</strong></li><li><strong>It lets you play back audio from the last 15 seconds</strong></li><li><strong>Some observers are worried it could violate people’s privacy</strong></li></ul><p>When Apple announced its Live Rewind feature at its <a href="https://www.techradar.com/tech-events/15-things-we-learned-from-apples-big-iphone-duo-and-iphone-18-pro-launch-from-its-first-ever-foldable-to-new-airpods">Surprise and Shine event</a> earlier this week, many observers were concerned that it would allow you to secretly record other people without their consent. After all, the tool just requires you to press a button on your Apple Watch and it plays back any audio that was captured during the last 15 seconds.</p><p>Is this feature a privacy nightmare, one that turns every Apple Watch into a “mass surveillance device,” as some people have worried? Or have people misunderstood what is happening, with Apple putting enough safeguards in place to prevent abuse and privacy violations? </p><p>Social media users seem to be divided, with some calling it <a href="https://www.reddit.com/r/watchos/comments/1wbvml6/did_anyone_else_find_live_rewind_creepy_and/" target="_blank">“creepy and antisocial,”</a> while others pointed out how it could be useful for <a href="https://www.reddit.com/r/watchos/comments/1wbvml6/comment/p8tjfis/" target="_blank">deaf people or those with autism</a>. Let’s take a look at the facts to find out what’s really going on.</p><h2 id="how-does-live-rewind-work">How does Live Rewind work?</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1747px;"><p class="vanilla-image-block" style="padding-top:56.27%;"><img id="CfeEiBmVW36npAEEyPzp25" name="Apple Live Rewind 1" alt="A person using the Live Rewind feature on an Apple Watch." src="https://cdn.mos.cms.futurecdn.net/CfeEiBmVW36npAEEyPzp25-1920-80.jpg" mos="" align="middle" fullscreen="" width="1747" height="983" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Apple)</span></figcaption></figure><p>What is this Live Rewind feature that is causing so much consternation? According to Apple, users of the <a href="https://www.techradar.com/health-fitness/smartwatches/the-apple-watch-series-12-has-the-most-accurate-heart-rate-sensing-in-a-wearable-heres-where-to-preorder-apples-newest-smartwatch">Apple Watch Series 12</a> or <a href="https://www.techradar.com/health-fitness/smartwatches/apple-watch-ultra-4-vs-apple-watch-ultra-3-whats-changed-and-should-you-upgrade">Apple Watch Ultra 4</a> will be able to double-press the Digital Crown and receive a text transcription of what was said over the last 15 seconds. The company says this is useful if you missed something important, are deaf or hard of hearing, or are trying to recall a tip or recommendation from a friend. </p><p>Some people have worried that this would allow you to surreptitiously record other people without their knowledge, then save these recordings to your device for nefarious purposes. </p><p>However, Apple explained during the event that the feature never records or stores audio, it doesn’t identify anyone’s voice, and audio cannot be accessed by anyone (including Apple). To clarify matters, Apple has published an <a href="https://www.apple.com/privacy/docs/Audio_Intelligence_Privacy_Overview_Sep_2026.pdf" target="_blank">Audio Intelligence Privacy Overview</a> that lays out how this feature — and Apple’s other new Audio Intelligence tools, including <a href="https://www.techradar.com/health-fitness/smartwatches/thanks-to-siri-recaps-your-apple-watch-is-always-listening-as-you-go-about-your-day-but-apple-may-be-risking-a-meta-glasses-style-backlash">Siri Recap</a> — works in detail. </p><p>When it comes to Live Rewind, any audio is processed in the Apple Watch’s <a href="https://www.techradar.com/pro/apple-says-iphone-and-ipad-approved-by-nato-for-up-to-restricted-level-of-classified-data-a-level-of-government-certification-no-other-consumer-mobile-device-has-met">Secure Enclave</a>. This is a separate part of the S11 chip that, in this instance, processes audio. The Secure Enclave is siphoned off from the rest of the device and no part of the operating system can access it or the raw audio it handles. That includes both first- and third-party apps, and not even Apple can get to anything in the Secure Enclave. </p><p>Apple’s privacy paper notes that audio is never saved or recorded when you use Live Rewind. Instead, the audio is processed by the Secure Enclave and used to generate a transcript, then permanently deleted from both your device and from <a href="https://www.techradar.com/computing/software/what-is-icloud-and-is-it-worth-the-money">iCloud</a>. There’s no way anyone can listen to the audio at a later date or extract it from your device. </p><p>Audio flows into the Secure Enclave on a rolling basis, which means that old data is continuously overwritten and deleted when new audio comes in. When activated, Live Rewind tries to send the last 15 seconds of audio to your iPhone. If it can’t — such as if your iPhone is not within wireless range — the audio is immediately discarded. If the process is successful, the audio is converted to text on your iPhone, deleted, then the text is sent back to the Secure Enclave in your Apple Watch. </p><p>The saved text stays available on your Watch for 30 seconds after the screen dims, after which it is discarded. You can optionally choose to save it to the Siri app, where it is end-to-end encrypted. This is the only instance where something is saved in the Live Rewind process. As mentioned previously, the text does not contain any speaker attribution. </p><p>You can ask Siri about your transcripts, at which point the text is sent to Apple’s secure <a href="https://www.techradar.com/pro/apple-quietly-released-a-new-operating-system-that-almost-nobody-noticed-unnamed-os-surfaces-in-private-cloud-compute-blog-as-apple-goes-ballistic-on-ai">Private Cloud Compute</a> servers. If you use iCloud with two-factor authentication and have secured your device with a passcode, any transcripts from Live Rewind are synced using end-to-end encryption and not even Apple can decrypt them.</p><h2 id="respecting-those-around-you">Respecting those around you</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LeeQwmM58zoaEsjsewx635" name="Apple Live Rewind 2" alt="A person using the Live Rewind feature on an Apple Watch." src="https://cdn.mos.cms.futurecdn.net/LeeQwmM58zoaEsjsewx635-1920-80.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Apple)</span></figcaption></figure><p>What about other people? Will they know that you’re using Live Rewind? Can you use the feature secretly?</p><p>Thankfully, you can’t really use Live Rewind without anyone knowing. When you double-press the Digital Crown, your Apple Watch plays an audible chime that occurs even if your device is in silent mode or you are listening via headphones. A full-screen animation also plays on screen and the microphone icon is displayed. Whether visually or through sound, your Apple Watch tries to alert other people about what is happening. </p><p>Apple also says that Live Rewind is opt-in rather than opt-out, and you can enable it when setting up a new device. You can also enable or disable the feature in Siri Settings on your Apple Watch or in the Siri Settings section of the Apple Watch app on your iPhone. </p><p>Although it would be polite to do so, there’s no way for Apple to force you to ask permission before using Live Rewind. But you might take some solace from the fact that there’s no way for anyone to save or extract the audio that the feature uses, nor can they attribute speakers. All a user gets out of it is a text transcript. </p><p>These privacy guardrails go some way to distancing Live Rewind from <a href="https://www.techradar.com/computing/virtual-reality-augmented-reality/meta-has-a-fresh-update-to-stop-people-from-turning-meta-smart-glasses-into-pervert-glasses-and-the-updates-will-keep-coming">Meta’s so-called “Pervert Glasses”</a> and their consent-busting data collection.</p><div data-widget-type="multimodelreview" data-widget-title="Today’s best Apple Watch deals" data-model-name="Apple Watch Ultra 4,Apple Watch Series 12,Apple Watch Ultra 3,Apple Watch SE 3,Apple Watch 11,Apple Watch Series 10"></div> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/health-fitness/smartwatches/is-apples-live-rewind-a-privacy-nightmare-heres-how-the-apple-watch-feature-really-works-and-whether-it-violates-your-privacy</link>
                                                                            <description>
                            <![CDATA[ Here’s everything you need to know about Live Rewind, Apple’s controversial new Apple Watch feature. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BJ9KAzgg7S2FqnbhKRPcQR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pQgtyLWmytpSru3K9u6wu4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 16:25:26 +0000</pubDate>                                                                                                                                <updated>Fri, 11 Sep 2026 18:10:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Smartwatches]]></category>
                                                    <category><![CDATA[Health & Fitness]]></category>
                                                                                                <author><![CDATA[ alexblake.techradar@gmail.com (Alex Blake) ]]></author>                    <dc:creator><![CDATA[ Alex Blake ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gwmVRU4zMGnDYsGVAFvRmL-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Alex Blake has been fooling around with computers since the early 1990s, and since that time he&#039;s learned a thing or two about tech. No more than two things, though. That&#039;s all his brain can hold. As well as TechRadar, Alex writes for iMore, Digital Trends and Creative Bloq, among others. He was previously commissioning editor at MacFormat magazine. That means he mostly covers the world of Apple and its latest products, but also Windows, computer peripherals, mobile apps, and much more beyond. When not writing, you can find him hiking the English countryside and gaming on his PC.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pQgtyLWmytpSru3K9u6wu4-1280-80.jpg">
                                                            <media:credit><![CDATA[Apple]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Live Rewind feature on an Apple Watch.]]></media:description>                                                            <media:text><![CDATA[The Live Rewind feature on an Apple Watch.]]></media:text>
                                <media:title type="plain"><![CDATA[The Live Rewind feature on an Apple Watch.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pQgtyLWmytpSru3K9u6wu4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Apple debuted a new Apple Watch feature called Live Rewind</strong></li><li><strong>It lets you play back audio from the last 15 seconds</strong></li><li><strong>Some observers are worried it could violate people’s privacy</strong></li></ul><p>When Apple announced its Live Rewind feature at its <a href="https://www.techradar.com/tech-events/15-things-we-learned-from-apples-big-iphone-duo-and-iphone-18-pro-launch-from-its-first-ever-foldable-to-new-airpods">Surprise and Shine event</a> earlier this week, many observers were concerned that it would allow you to secretly record other people without their consent. After all, the tool just requires you to press a button on your Apple Watch and it plays back any audio that was captured during the last 15 seconds.</p><p>Is this feature a privacy nightmare, one that turns every Apple Watch into a “mass surveillance device,” as some people have worried? Or have people misunderstood what is happening, with Apple putting enough safeguards in place to prevent abuse and privacy violations? </p><p>Social media users seem to be divided, with some calling it <a href="https://www.reddit.com/r/watchos/comments/1wbvml6/did_anyone_else_find_live_rewind_creepy_and/" target="_blank">“creepy and antisocial,”</a> while others pointed out how it could be useful for <a href="https://www.reddit.com/r/watchos/comments/1wbvml6/comment/p8tjfis/" target="_blank">deaf people or those with autism</a>. Let’s take a look at the facts to find out what’s really going on.</p><h2 id="how-does-live-rewind-work">How does Live Rewind work?</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1747px;"><p class="vanilla-image-block" style="padding-top:56.27%;"><img id="CfeEiBmVW36npAEEyPzp25" name="Apple Live Rewind 1" alt="A person using the Live Rewind feature on an Apple Watch." src="https://cdn.mos.cms.futurecdn.net/CfeEiBmVW36npAEEyPzp25-1920-80.jpg" mos="" align="middle" fullscreen="" width="1747" height="983" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Apple)</span></figcaption></figure><p>What is this Live Rewind feature that is causing so much consternation? According to Apple, users of the <a href="https://www.techradar.com/health-fitness/smartwatches/the-apple-watch-series-12-has-the-most-accurate-heart-rate-sensing-in-a-wearable-heres-where-to-preorder-apples-newest-smartwatch">Apple Watch Series 12</a> or <a href="https://www.techradar.com/health-fitness/smartwatches/apple-watch-ultra-4-vs-apple-watch-ultra-3-whats-changed-and-should-you-upgrade">Apple Watch Ultra 4</a> will be able to double-press the Digital Crown and receive a text transcription of what was said over the last 15 seconds. The company says this is useful if you missed something important, are deaf or hard of hearing, or are trying to recall a tip or recommendation from a friend. </p><p>Some people have worried that this would allow you to surreptitiously record other people without their knowledge, then save these recordings to your device for nefarious purposes. </p><p>However, Apple explained during the event that the feature never records or stores audio, it doesn’t identify anyone’s voice, and audio cannot be accessed by anyone (including Apple). To clarify matters, Apple has published an <a href="https://www.apple.com/privacy/docs/Audio_Intelligence_Privacy_Overview_Sep_2026.pdf" target="_blank">Audio Intelligence Privacy Overview</a> that lays out how this feature — and Apple’s other new Audio Intelligence tools, including <a href="https://www.techradar.com/health-fitness/smartwatches/thanks-to-siri-recaps-your-apple-watch-is-always-listening-as-you-go-about-your-day-but-apple-may-be-risking-a-meta-glasses-style-backlash">Siri Recap</a> — works in detail. </p><p>When it comes to Live Rewind, any audio is processed in the Apple Watch’s <a href="https://www.techradar.com/pro/apple-says-iphone-and-ipad-approved-by-nato-for-up-to-restricted-level-of-classified-data-a-level-of-government-certification-no-other-consumer-mobile-device-has-met">Secure Enclave</a>. This is a separate part of the S11 chip that, in this instance, processes audio. The Secure Enclave is siphoned off from the rest of the device and no part of the operating system can access it or the raw audio it handles. That includes both first- and third-party apps, and not even Apple can get to anything in the Secure Enclave. </p><p>Apple’s privacy paper notes that audio is never saved or recorded when you use Live Rewind. Instead, the audio is processed by the Secure Enclave and used to generate a transcript, then permanently deleted from both your device and from <a href="https://www.techradar.com/computing/software/what-is-icloud-and-is-it-worth-the-money">iCloud</a>. There’s no way anyone can listen to the audio at a later date or extract it from your device. </p><p>Audio flows into the Secure Enclave on a rolling basis, which means that old data is continuously overwritten and deleted when new audio comes in. When activated, Live Rewind tries to send the last 15 seconds of audio to your iPhone. If it can’t — such as if your iPhone is not within wireless range — the audio is immediately discarded. If the process is successful, the audio is converted to text on your iPhone, deleted, then the text is sent back to the Secure Enclave in your Apple Watch. </p><p>The saved text stays available on your Watch for 30 seconds after the screen dims, after which it is discarded. You can optionally choose to save it to the Siri app, where it is end-to-end encrypted. This is the only instance where something is saved in the Live Rewind process. As mentioned previously, the text does not contain any speaker attribution. </p><p>You can ask Siri about your transcripts, at which point the text is sent to Apple’s secure <a href="https://www.techradar.com/pro/apple-quietly-released-a-new-operating-system-that-almost-nobody-noticed-unnamed-os-surfaces-in-private-cloud-compute-blog-as-apple-goes-ballistic-on-ai">Private Cloud Compute</a> servers. If you use iCloud with two-factor authentication and have secured your device with a passcode, any transcripts from Live Rewind are synced using end-to-end encryption and not even Apple can decrypt them.</p><h2 id="respecting-those-around-you">Respecting those around you</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LeeQwmM58zoaEsjsewx635" name="Apple Live Rewind 2" alt="A person using the Live Rewind feature on an Apple Watch." src="https://cdn.mos.cms.futurecdn.net/LeeQwmM58zoaEsjsewx635-1920-80.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Apple)</span></figcaption></figure><p>What about other people? Will they know that you’re using Live Rewind? Can you use the feature secretly?</p><p>Thankfully, you can’t really use Live Rewind without anyone knowing. When you double-press the Digital Crown, your Apple Watch plays an audible chime that occurs even if your device is in silent mode or you are listening via headphones. A full-screen animation also plays on screen and the microphone icon is displayed. Whether visually or through sound, your Apple Watch tries to alert other people about what is happening. </p><p>Apple also says that Live Rewind is opt-in rather than opt-out, and you can enable it when setting up a new device. You can also enable or disable the feature in Siri Settings on your Apple Watch or in the Siri Settings section of the Apple Watch app on your iPhone. </p><p>Although it would be polite to do so, there’s no way for Apple to force you to ask permission before using Live Rewind. But you might take some solace from the fact that there’s no way for anyone to save or extract the audio that the feature uses, nor can they attribute speakers. All a user gets out of it is a text transcript. </p><p>These privacy guardrails go some way to distancing Live Rewind from <a href="https://www.techradar.com/computing/virtual-reality-augmented-reality/meta-has-a-fresh-update-to-stop-people-from-turning-meta-smart-glasses-into-pervert-glasses-and-the-updates-will-keep-coming">Meta’s so-called “Pervert Glasses”</a> and their consent-busting data collection.</p><div data-widget-type="multimodelreview" data-widget-title="Today’s best Apple Watch deals" data-model-name="Apple Watch Ultra 4,Apple Watch Series 12,Apple Watch Ultra 3,Apple Watch SE 3,Apple Watch 11,Apple Watch Series 10"></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US Treasury wants banks to be better at filing file cyber scam reports after noting nearly $13 billion in losses since 2023 ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>FinCEN warns US banks of industrial‑scale scam centers in Southeast Asia stealing billions</strong></li><li><strong>Victims coerced into crypto “investments,” later re‑scammed with fake recovery fees</strong></li><li><strong>Laundered via digital assets, mixers, shell firms, and Chinese underground banking networks</strong></li></ul><p>American financial institutions need to be more vigilant when it comes to identifying and preventing money scams, especially those perpetrated by industrial-scale scam centers in Southeast Asia. </p><p>This was the warning issued by the US Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) alongside a long list of red flags these institutions can monitor in order to stay safe.</p><h2 id="large-dangerous-crime-rings">Large, dangerous crime rings</h2><p>The scams are not done by small groups of teenagers, tricking the elderly from the depths of their parents’ basement, but are often large, well-organized crime machines responsible for billions of dollars in damages, around the world, every year. </p><p>In 2025 alone, US victims lost more than $7.2 billion to these scams, the warning said, and between September 2023 and December 2025, nearly $13 billion was stolen from Americans.</p><p>The criminal organizations are primarily located in Cambodia, Burma, and Laos. They trafficked hundreds of thousands of people to various centers around the countries, taking their passports and forcing them into participating in online fraud. Those that don’t meet certain quotas are often beaten - and some victims were liberated after their families paid ransom demands, while others ended up being coerced into commercial sex work. </p><p>To make matters worse, they are resilient to law enforcement activities because some of them are either endorsed, or outright operated by, local corrupt officials.</p><p>FinCEN says the criminals are engaged in all sorts of fraudulent activity, but stressed that investment fraud is, by far, the most popular one. The scammers would reach out to their victim either pretending to be a romantic interest, or a financial advisor. Sometimes, they would even begin the conversation by saying they mistyped a phone number.</p><p>After extensively communicating with their victim for a while, they try to persuade them into making an “investment”, often using cryptocurrencies, and promising unrealistically high returns. This is also, FinCEN stresses, is when the scams can most easily be identified:</p><p>“Most digital asset payments by victims to scam center operators originate from money services businesses (MSBs) offering digital asset services, includingdigital asset kiosks, according to FinCEN analysis and law enforcement information. Based on FinCEN’s analysis of BSA reporting, scammers often instruct their victims to open accounts withMSBs offeringdigital asset services to purchase specific types of digital assets. Then, the victim is told to send these funds toa digital asset address controlled by the scammers.”</p><p>But defrauding victims out of their hard-earned money is not where the scam ends. Instead, the criminals continue, this time abusing the emotional distress to cause even more harm. They pose as law enforcement, financial institutions, or even FinCEN itself, stating that they’re investigating (or that they have confiscated the stolen funds) and that the victims should pay a certain fee to have their funds returned to them.</p><p>In some cases, the fraudsters pose as investment advisors, telling the victims to take out their money, buy gold and silver bars, and hand them over to a courier for “safe keeping”.</p><p>The full list of red flags can be found on <a href="https://www.fincen.gov/system/files/2026-08/FinCEN-Alert-Scam-Centers.pdf" target="_blank">this link</a>, and FinCEN stresses that the circumstances around each individual case should be carefully considered, since no single red flag is “determinative of illicit or other suspicious activity.” </p><p>The circumstances include a customer’s historical financial activity, whether the transactions are in line with prevailing business practices, and whether the customer exhibits multiple related red flags.</p><h2 id="laundering-the-proceeds">Laundering the proceeds</h2><p>Stealing the money is only half of the work, though. It still needs to be laundered and reintroduced into the legitimate financial system, and to do that, scam center operators rely on professional money launderers and Chinese money laundering networks. </p><p>FinCEN describes a three-stage process, in which the criminals first extract payments in digital assets using bank accounts, money mules, shell companies, or fraudulent money services businesses. </p><p>Next, during on-chain laundering, they obfuscate the origins of the stolen money by rapidly moving it across addresses, using mixers, and swapping tokens across blockchains. The last step is to integrate the funds into the traditional financial system via money mules, stablecoin transfers to offshore exchanges, and Chinese underground banking networks.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/us-treasury-wants-banks-to-be-better-at-filing-file-cyber-scam-reports-after-noting-nearly-usd13-billion-in-losses-since-2023</link>
                                                                            <description>
                            <![CDATA[ Banks need to get better at reporting issues, so the US Treasury has shared a list of red flags and explained how the scams usually go. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xwb7XgPoaLNVHTjf6vcm9M</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 14:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>FinCEN warns US banks of industrial‑scale scam centers in Southeast Asia stealing billions</strong></li><li><strong>Victims coerced into crypto “investments,” later re‑scammed with fake recovery fees</strong></li><li><strong>Laundered via digital assets, mixers, shell firms, and Chinese underground banking networks</strong></li></ul><p>American financial institutions need to be more vigilant when it comes to identifying and preventing money scams, especially those perpetrated by industrial-scale scam centers in Southeast Asia. </p><p>This was the warning issued by the US Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) alongside a long list of red flags these institutions can monitor in order to stay safe.</p><h2 id="large-dangerous-crime-rings">Large, dangerous crime rings</h2><p>The scams are not done by small groups of teenagers, tricking the elderly from the depths of their parents’ basement, but are often large, well-organized crime machines responsible for billions of dollars in damages, around the world, every year. </p><p>In 2025 alone, US victims lost more than $7.2 billion to these scams, the warning said, and between September 2023 and December 2025, nearly $13 billion was stolen from Americans.</p><p>The criminal organizations are primarily located in Cambodia, Burma, and Laos. They trafficked hundreds of thousands of people to various centers around the countries, taking their passports and forcing them into participating in online fraud. Those that don’t meet certain quotas are often beaten - and some victims were liberated after their families paid ransom demands, while others ended up being coerced into commercial sex work. </p><p>To make matters worse, they are resilient to law enforcement activities because some of them are either endorsed, or outright operated by, local corrupt officials.</p><p>FinCEN says the criminals are engaged in all sorts of fraudulent activity, but stressed that investment fraud is, by far, the most popular one. The scammers would reach out to their victim either pretending to be a romantic interest, or a financial advisor. Sometimes, they would even begin the conversation by saying they mistyped a phone number.</p><p>After extensively communicating with their victim for a while, they try to persuade them into making an “investment”, often using cryptocurrencies, and promising unrealistically high returns. This is also, FinCEN stresses, is when the scams can most easily be identified:</p><p>“Most digital asset payments by victims to scam center operators originate from money services businesses (MSBs) offering digital asset services, includingdigital asset kiosks, according to FinCEN analysis and law enforcement information. Based on FinCEN’s analysis of BSA reporting, scammers often instruct their victims to open accounts withMSBs offeringdigital asset services to purchase specific types of digital assets. Then, the victim is told to send these funds toa digital asset address controlled by the scammers.”</p><p>But defrauding victims out of their hard-earned money is not where the scam ends. Instead, the criminals continue, this time abusing the emotional distress to cause even more harm. They pose as law enforcement, financial institutions, or even FinCEN itself, stating that they’re investigating (or that they have confiscated the stolen funds) and that the victims should pay a certain fee to have their funds returned to them.</p><p>In some cases, the fraudsters pose as investment advisors, telling the victims to take out their money, buy gold and silver bars, and hand them over to a courier for “safe keeping”.</p><p>The full list of red flags can be found on <a href="https://www.fincen.gov/system/files/2026-08/FinCEN-Alert-Scam-Centers.pdf" target="_blank">this link</a>, and FinCEN stresses that the circumstances around each individual case should be carefully considered, since no single red flag is “determinative of illicit or other suspicious activity.” </p><p>The circumstances include a customer’s historical financial activity, whether the transactions are in line with prevailing business practices, and whether the customer exhibits multiple related red flags.</p><h2 id="laundering-the-proceeds">Laundering the proceeds</h2><p>Stealing the money is only half of the work, though. It still needs to be laundered and reintroduced into the legitimate financial system, and to do that, scam center operators rely on professional money launderers and Chinese money laundering networks. </p><p>FinCEN describes a three-stage process, in which the criminals first extract payments in digital assets using bank accounts, money mules, shell companies, or fraudulent money services businesses. </p><p>Next, during on-chain laundering, they obfuscate the origins of the stolen money by rapidly moving it across addresses, using mixers, and swapping tokens across blockchains. The last step is to integrate the funds into the traditional financial system via money mules, stablecoin transfers to offshore exchanges, and Chinese underground banking networks.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A new Android attack combines malware and ransomware in a cocktail of cybercrime ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Zimperium uncovers Mantax Otax, Android malware merging infostealer, RAT, backdoor, and ransomware</strong></li><li><strong>Distributed via APKs on third‑party stores, social media, and phishing; older Android versions most at risk</strong></li><li><strong>Steals extensive data, enables remote monitoring, then encrypts files with AES and demands ransom</strong></li></ul><p>When threat actors target people’s devices, they usually infect it with one of many malware strains: an infostealer, a remote access trojan, a backdoor, or a ransomware encryptor. </p><p>Rarely do we see all of these functionalities merged into a single entity, and even rarer - to have it target Android mobile devices - yet, security researchers Zimperium discovered just that.</p><h2 id="mantax-otax">Mantax Otax</h2><p>The security outfit published an in-depth report on <a href="https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration" target="_blank" rel="nofollow">Mantax Otax</a>, a unique strain of malware circulating in the wild. It is apparently developed by an Indonesian threat actor, targeting victims in the country, but we don’t know exactly how many people are infected, or if this campaign is aimed primarily at business users, or individuals in general. </p><p>The malware is being distributed as a standalone APK, meaning it can be found on third-party app stores, Telegram channels, forums, and across social media. There are no traces of Mantax Otax on any of the official app repositories, including the Google Play Store, or Samsung’s Galaxy Store. Zimperium also speculates that it is likely being distributed via phishing emails.</p><p>Mantax Otax primarily targets users sporting older <a href="https://www.techradar.com/best/best-android-phones" target="_blank">Android phones</a>. Versions 9 and older are most at risk, since on these devices the attackers can make use of all of the malware’s features. Android 10 and newer models do get some protection:</p><p>“Conversely, on modern devices running Android 10 and above, the malware’s efficacy is severely hindered by native OS defenses, specifically Scoped Storage restrictions,” the researchers explained. “Due to these sandboxing rules, the ransomware is constrained to scanning only the application's localized external files directory, which drastically mitigates the blast radius and reduces the volume of accessible user files.”</p><p>Newer devices, as well as users of Zimperium’s Mobile Threat Defense (MTD) and Runtime Application Protection (zDefend) are said to be protected on a software level.</p><p>Another important caveat is the permissions. As is usual on Android devices, most <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> won’t work unless the user grants an extensive set of permissions beforehand. In this case, Mantax Otax first asks for admin privileges, after which it grants itself an extensive list of capabilities, from accessing SMS messages, to contacts, audio, and images. </p><p>It then requests accessibility permissions, fully taking over the compromised device.</p><h2 id="malicious-capabilities">Malicious capabilities</h2><p>Mantax Otax is said to be quite capable. It steals browser history, contacts, call logs, SMS messages, notifications, files, gallery media, Google account information, device specifications, location data, and application inventories. It can also pull WhatsApp information such as messages and profiles, and on Telegram it can also pull lock-screen PINs. </p><p>Infostealing features aside, it also serves as a remote monitoring tool, grabbing screenshots, recording the screen, or livestreaming it directly to the attackers. It can take photos using both the front and rear cameras, although Zimperium did not mention any microphone-recording capabilities. </p><p>Finally, once all of the data has been harvested, it encrypts user files with AES, deletes the originals, and appends a .enc extension. Victims are then shown a chat interface where they can communicate with the attackers directly and negotiate a ransom payment in exchange for getting their device back.</p><p>The tool seems to be in continuous development. Zimperium found two separate versions, one being an “evolution” of the other: “Notably, it has modified its network traffic behavior to utilize WebSockets and introduced a set of new commands,” the researchers said.</p><p>There is a reason why ransomware operators prefer targeting businesses instead of individuals. Although the latter has not disappeared entirely from the victim list, businesses stand to lose a lot more from disrupted operations and, as such, are targeted more frequently. Unfortunately, we don’t know what kind of app Mantax Otax is spoofing, therefore it is difficult to assess who the targets are. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/a-new-android-attack-combines-malware-and-ransomware-in-a-cocktail-of-cybercrime</link>
                                                                            <description>
                            <![CDATA[ Unique malware variant spotted targeting Android users, taking photos with victim cameras before deploying an encryptor. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WUzPMz4TuL4FYGCGUqTivX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BiyAK4BXKKfecCWadFcHGo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BiyAK4BXKKfecCWadFcHGo-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / tomeqs]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android reboot interface]]></media:description>                                                            <media:text><![CDATA[Android reboot interface]]></media:text>
                                <media:title type="plain"><![CDATA[Android reboot interface]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BiyAK4BXKKfecCWadFcHGo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Zimperium uncovers Mantax Otax, Android malware merging infostealer, RAT, backdoor, and ransomware</strong></li><li><strong>Distributed via APKs on third‑party stores, social media, and phishing; older Android versions most at risk</strong></li><li><strong>Steals extensive data, enables remote monitoring, then encrypts files with AES and demands ransom</strong></li></ul><p>When threat actors target people’s devices, they usually infect it with one of many malware strains: an infostealer, a remote access trojan, a backdoor, or a ransomware encryptor. </p><p>Rarely do we see all of these functionalities merged into a single entity, and even rarer - to have it target Android mobile devices - yet, security researchers Zimperium discovered just that.</p><h2 id="mantax-otax">Mantax Otax</h2><p>The security outfit published an in-depth report on <a href="https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration" target="_blank" rel="nofollow">Mantax Otax</a>, a unique strain of malware circulating in the wild. It is apparently developed by an Indonesian threat actor, targeting victims in the country, but we don’t know exactly how many people are infected, or if this campaign is aimed primarily at business users, or individuals in general. </p><p>The malware is being distributed as a standalone APK, meaning it can be found on third-party app stores, Telegram channels, forums, and across social media. There are no traces of Mantax Otax on any of the official app repositories, including the Google Play Store, or Samsung’s Galaxy Store. Zimperium also speculates that it is likely being distributed via phishing emails.</p><p>Mantax Otax primarily targets users sporting older <a href="https://www.techradar.com/best/best-android-phones" target="_blank">Android phones</a>. Versions 9 and older are most at risk, since on these devices the attackers can make use of all of the malware’s features. Android 10 and newer models do get some protection:</p><p>“Conversely, on modern devices running Android 10 and above, the malware’s efficacy is severely hindered by native OS defenses, specifically Scoped Storage restrictions,” the researchers explained. “Due to these sandboxing rules, the ransomware is constrained to scanning only the application's localized external files directory, which drastically mitigates the blast radius and reduces the volume of accessible user files.”</p><p>Newer devices, as well as users of Zimperium’s Mobile Threat Defense (MTD) and Runtime Application Protection (zDefend) are said to be protected on a software level.</p><p>Another important caveat is the permissions. As is usual on Android devices, most <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> won’t work unless the user grants an extensive set of permissions beforehand. In this case, Mantax Otax first asks for admin privileges, after which it grants itself an extensive list of capabilities, from accessing SMS messages, to contacts, audio, and images. </p><p>It then requests accessibility permissions, fully taking over the compromised device.</p><h2 id="malicious-capabilities">Malicious capabilities</h2><p>Mantax Otax is said to be quite capable. It steals browser history, contacts, call logs, SMS messages, notifications, files, gallery media, Google account information, device specifications, location data, and application inventories. It can also pull WhatsApp information such as messages and profiles, and on Telegram it can also pull lock-screen PINs. </p><p>Infostealing features aside, it also serves as a remote monitoring tool, grabbing screenshots, recording the screen, or livestreaming it directly to the attackers. It can take photos using both the front and rear cameras, although Zimperium did not mention any microphone-recording capabilities. </p><p>Finally, once all of the data has been harvested, it encrypts user files with AES, deletes the originals, and appends a .enc extension. Victims are then shown a chat interface where they can communicate with the attackers directly and negotiate a ransom payment in exchange for getting their device back.</p><p>The tool seems to be in continuous development. Zimperium found two separate versions, one being an “evolution” of the other: “Notably, it has modified its network traffic behavior to utilize WebSockets and introduced a set of new commands,” the researchers said.</p><p>There is a reason why ransomware operators prefer targeting businesses instead of individuals. Although the latter has not disappeared entirely from the victim list, businesses stand to lose a lot more from disrupted operations and, as such, are targeted more frequently. Unfortunately, we don’t know what kind of app Mantax Otax is spoofing, therefore it is difficult to assess who the targets are. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thinking like a hacker is key to strengthening resilience ]]></title>
                                                                                                <dc:content><![CDATA[ <p>If you've worked in <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> for as long as I have, then you'll know there are a couple of things you can count on. First, the threats that are out there never stop evolving. And second, sooner or later, you're going to be in the bullseye.</p><p>What makes life so much harder today is that AI and other automated tools have dramatically narrowed the gap between vulnerability discovery and the time it takes to exploit them. </p><p>And when this can now be measured in minutes – seconds, even – you know you have a problem. This fundamental change in the way adversaries operate means we no longer have the luxury of time to understand an attack, assess the risk and decide what to do next.</p><p>Which means we have to be better prepared and have resiliency for whatever is thrown at us. </p><h2 id="visibility-is-key">Visibility is key</h2><p>For me, that starts with accepting a simple reality: you cannot defend what you cannot see. And it’s why visibility is one of the most important capabilities an organization can develop.</p><p>After all, if you understand what exists within your environment – how those systems interact and what normal looks like – then you're in a much stronger position to identify unusual behavior before it develops into something more serious.   </p><p>Observability, on the other hand, takes that visibility to the next level. It provides the context <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> teams need to make informed decisions quickly, especially when time is working against them. </p><p>In other words, visibility tells you what is happening, while observability helps you understand why it's happening.</p><p>And that’s crucial. Today's organizations operate across on-premises <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud</a> environments, networks, and an increasing number of connected technologies.   </p><p>As those environments become more distributed, understanding what's happening across them becomes significantly harder.</p><p>Without that visibility, it's difficult to understand where your risks are, how systems interact, or where an attacker may be able to exploit a weakness.</p><h2 id="think-like-a-hacker">Think like a hacker</h2><p>Which leads me neatly onto my next point. Throughout my career, including my time working in offensive cyber operations in the intelligence community, I've found that the most effective way to understand risk is to think like the adversary.</p><p>I start by asking how someone would attack an organization and then work backwards to identify and close gaps.</p><p>That’s because attackers don't see organizations in the way that you or I might do. They’re always on the hunt for a toehold in.  They look for weaknesses in people, processes and technologies.</p><p>They look for the easiest route first to achieve their objective. And then they exploit that weakness.</p><p>And it’s an approach I would urge all security leaders to adopt if they want to stay one step ahead.</p><p>That means continuously asking where an attacker would start, how they would move through the organization and what controls would slow them down or stop them altogether.</p><p>But for this to work, it also requires organizations to design resilience into the way they operate. And that’s something we’ve embedded across our organization. </p><p>For instance, we have internal and external teams that conduct continuous product, enterprise, spear-phishing and physical penetration testing.</p><p>For us, it's about educating the team across the <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> to ensure they remain vigilant. But it’s also about inoculating people so that when they see something suspicious online, they have that instinct that something might be wrong and they report it.</p><p>We also want to make it easy for people to report events so we can analyze them quickly and better understand the targeting.</p><h2 id="secure-by-design">Secure by design</h2><p>We’ve also invested heavily in Secure by Design to ensure that all the products we deliver to <a href="https://www.techradar.com/best/the-best-customer-database-software-of-year">customers</a> are as secure as humanly possible. In practice, it means being able to trace every piece of code back to its source and verify its integrity throughout the development process.</p><p>It's similar to maintaining a chain of custody for evidence. We want to know exactly where software components come from, how they're verified and how they're protected throughout the entire build process.</p><p>More broadly, Secure by Design is increasingly being adopted across our industry as organizations recognize the importance of software integrity, traceability and transparency throughout the development lifecycle.</p><p>This is important because, as I said at the beginning, there are two certainties in cybersecurity: threats will continue to evolve, and organizations will continue to be targeted. Businesses across the world must adapt quickly to the grim reality that a cybersecurity incident isn’t a matter of if, but a matter of when. And AI is supercharging the pace at which all this is happening and broadening the blast radius of any attack.</p><p>That’s why you need to understand your environment well enough to reduce unnecessary risk, detect malicious activity quickly and limit the blast radius when something does happen. Pair that with a clearly defined and tested plan for recovery and that's what robust cyber resilience looks like in practice.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/thinking-like-a-hacker-is-key-to-strengthening-resilience</link>
                                                                            <description>
                            <![CDATA[ Cyber threats are moving faster than ever. A businesses resilience needs to keep pace. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">B8gAQ7WuciV4xJT3TtAFEj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 11:06:09 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Justin Henkel ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If you've worked in <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> for as long as I have, then you'll know there are a couple of things you can count on. First, the threats that are out there never stop evolving. And second, sooner or later, you're going to be in the bullseye.</p><p>What makes life so much harder today is that AI and other automated tools have dramatically narrowed the gap between vulnerability discovery and the time it takes to exploit them. </p><p>And when this can now be measured in minutes – seconds, even – you know you have a problem. This fundamental change in the way adversaries operate means we no longer have the luxury of time to understand an attack, assess the risk and decide what to do next.</p><p>Which means we have to be better prepared and have resiliency for whatever is thrown at us. </p><h2 id="visibility-is-key">Visibility is key</h2><p>For me, that starts with accepting a simple reality: you cannot defend what you cannot see. And it’s why visibility is one of the most important capabilities an organization can develop.</p><p>After all, if you understand what exists within your environment – how those systems interact and what normal looks like – then you're in a much stronger position to identify unusual behavior before it develops into something more serious.   </p><p>Observability, on the other hand, takes that visibility to the next level. It provides the context <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> teams need to make informed decisions quickly, especially when time is working against them. </p><p>In other words, visibility tells you what is happening, while observability helps you understand why it's happening.</p><p>And that’s crucial. Today's organizations operate across on-premises <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud</a> environments, networks, and an increasing number of connected technologies.   </p><p>As those environments become more distributed, understanding what's happening across them becomes significantly harder.</p><p>Without that visibility, it's difficult to understand where your risks are, how systems interact, or where an attacker may be able to exploit a weakness.</p><h2 id="think-like-a-hacker">Think like a hacker</h2><p>Which leads me neatly onto my next point. Throughout my career, including my time working in offensive cyber operations in the intelligence community, I've found that the most effective way to understand risk is to think like the adversary.</p><p>I start by asking how someone would attack an organization and then work backwards to identify and close gaps.</p><p>That’s because attackers don't see organizations in the way that you or I might do. They’re always on the hunt for a toehold in.  They look for weaknesses in people, processes and technologies.</p><p>They look for the easiest route first to achieve their objective. And then they exploit that weakness.</p><p>And it’s an approach I would urge all security leaders to adopt if they want to stay one step ahead.</p><p>That means continuously asking where an attacker would start, how they would move through the organization and what controls would slow them down or stop them altogether.</p><p>But for this to work, it also requires organizations to design resilience into the way they operate. And that’s something we’ve embedded across our organization. </p><p>For instance, we have internal and external teams that conduct continuous product, enterprise, spear-phishing and physical penetration testing.</p><p>For us, it's about educating the team across the <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> to ensure they remain vigilant. But it’s also about inoculating people so that when they see something suspicious online, they have that instinct that something might be wrong and they report it.</p><p>We also want to make it easy for people to report events so we can analyze them quickly and better understand the targeting.</p><h2 id="secure-by-design">Secure by design</h2><p>We’ve also invested heavily in Secure by Design to ensure that all the products we deliver to <a href="https://www.techradar.com/best/the-best-customer-database-software-of-year">customers</a> are as secure as humanly possible. In practice, it means being able to trace every piece of code back to its source and verify its integrity throughout the development process.</p><p>It's similar to maintaining a chain of custody for evidence. We want to know exactly where software components come from, how they're verified and how they're protected throughout the entire build process.</p><p>More broadly, Secure by Design is increasingly being adopted across our industry as organizations recognize the importance of software integrity, traceability and transparency throughout the development lifecycle.</p><p>This is important because, as I said at the beginning, there are two certainties in cybersecurity: threats will continue to evolve, and organizations will continue to be targeted. Businesses across the world must adapt quickly to the grim reality that a cybersecurity incident isn’t a matter of if, but a matter of when. And AI is supercharging the pace at which all this is happening and broadening the blast radius of any attack.</p><p>That’s why you need to understand your environment well enough to reduce unnecessary risk, detect malicious activity quickly and limit the blast radius when something does happen. Pair that with a clearly defined and tested plan for recovery and that's what robust cyber resilience looks like in practice.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Connecting defense capability for operational advantage ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Defense is operating in an environment where the pace of change continues to increase. Adversaries are adapting quickly and technology development cycles are becoming shorter. The boundaries between physical and digital operations are also becoming harder to define, while military commanders have more information available to them than ever before.</p><p>This changes how operational advantage is achieved. The performance of an individual platform or system remains important, but so does its ability to work effectively within the wider operational environment. Information needs to move securely to where it is needed, supporting decisions and action across different domains.</p><p>As new technologies are introduced, integration will become an increasingly important part of defense capability. The challenge is making sure innovation can be put to practical use alongside the systems and <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> already supporting operations.</p><h2 id="connecting-technology-across-defence">Connecting technology across defence</h2><p>Conversations around defense innovation often focus on AI, autonomous systems, advanced sensors, cyber capability and space assets. Each has a significant role to play, but none operates in isolation.</p><p>Information gathered by one system may need to be shared across multiple domains before it supports an operational decision. Networks, <a href="https://www.techradar.com/best/best-data-recovery-software">data</a>, command systems and people all contribute to that process. The value of any individual technology is linked to how effectively it connects with the wider operational environment.</p><p>This principle also applies to the infrastructure supporting military operations. Communications networks, operational facilities and digital systems all contribute to creating an environment where information can move securely and reliably. As these environments evolve, resilience and <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> must be designed from the outset though approaches such as secure-by-design and zero-trust principles.</p><h2 id="strengthening-the-foundations-of-operational-capability">Strengthening the foundations of operational capability</h2><p>AI has become one of the defining topics in defense. Its ability to process information and support decision-making has significant potential, but those capabilities depend on the quality of the data available and the resilience of the infrastructure that carries it.</p><p>Reliable communications, trusted data and secure networks remain fundamental to operational effectiveness. If those foundations are unavailable or compromised, the benefits of advanced technologies are reduced.</p><p>Therefore, creating decision advantage is not simply a technology challenge. It is an infrastructure and digital challenge and increasingly, a collaboration challenge.</p><p>For organizations supporting critical infrastructure, this has become an increasingly familiar challenge. Communications, operational technology, and digital infrastructure must work together to create environments where reliability cannot be compromised.</p><h2 id="keeping-people-at-the-heart-of-automation">Keeping people at the heart of automation</h2><p>Automation is attracting considerable attention across defense as organizations are looking to improve efficiency and increase operational tempo. However, automation should never be viewed as an end.</p><p>Its greatest value often comes from reducing routine activity rather than replacing people. Predictive maintenance, autonomous <a href="https://www.techradar.com/best/best-network-monitoring-tools">monitoring</a>, automated network <a href="https://www.techradar.com/best/it-management-tools">management</a> and logistics optimization all help reduce the time spent on repetitive tasks, allowing highly trained personnel to focus on areas where experience and judgement remain essential.</p><p>The most effective technologies do not replace human capability - they amplify it.</p><h2 id="the-infrastructure-supporting-multi-domain-operations">The infrastructure supporting multi-domain operations</h2><p>As operations become increasingly integrated across land, sea, air, cyber and space, infrastructure is taking on greater strategic importance. Communications, transport, energy, and digital systems all contribute to operational capability, showing how infrastructure and technology are becoming increasingly interdependent.</p><p>The movement of people, information, energy, and capability all contribute to operational readiness. Reliable infrastructure enables those elements to function as a single system, ensuring capability can be delivered when and where it is needed.</p><p>One example can be seen in the Falkland Islands, where runway infrastructure forms part of maintaining long-term strategic capability and readiness. It illustrates how infrastructure and operational capability are becoming increasingly interconnected.</p><h2 id="bringing-innovation-into-operational-use">Bringing innovation into operational use</h2><p>The UK benefits from an established community of innovators, with government, industry, academia, <a href="https://www.techradar.com/best/best-small-business-software">SMEs</a> and the Armed Forces all contributing to the development of new ideas and technologies. The opportunity now is to ensure those innovations can be adopted enough to meet operational needs.</p><p>Collaboration is still a critical part of this process. Bringing together different perspectives helps ensure technology is developed with practical application in mind and can be integrated more effectively into future capability.</p><h2 id="delivering-the-next-phase-of-defense-capability">Delivering the next phase of defense capability</h2><p>Much of the technology required to support future defense operations already exists. The focus now needs to be on how quickly it can be integrated and put to operational use, giving the Armed Forces the advantage they need as threats and operating environments continue to change. That requires stronger connections across networks, data, platforms, people and infrastructure.</p><p>Collaboration between government, industry, academia, SMEs and the Armed Forces will remain central to moving capability from development into deployment. Technologies also need a clearer and faster route beyond demonstrations and pilots, so useful capability reaches operators when it is needed.</p><p>The organizations that succeed will be those able to bring people and technology together across the wider defense environment. Doing that securely, reliably and at pace will determine how effectively innovation translates into operational advantage.</p><p><em></em><a href="https://www.techradar.com/best/best-ai-tools"><em>We've featured the best AI tool.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/connecting-defense-capability-for-operational-advantage</link>
                                                                            <description>
                            <![CDATA[ As new technologies are introduced, integration will become an increasingly important part of defense capability. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5uAHbFj4ZYXLAzRYwUVqX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 10:25:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Barry Zielinski ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Defense is operating in an environment where the pace of change continues to increase. Adversaries are adapting quickly and technology development cycles are becoming shorter. The boundaries between physical and digital operations are also becoming harder to define, while military commanders have more information available to them than ever before.</p><p>This changes how operational advantage is achieved. The performance of an individual platform or system remains important, but so does its ability to work effectively within the wider operational environment. Information needs to move securely to where it is needed, supporting decisions and action across different domains.</p><p>As new technologies are introduced, integration will become an increasingly important part of defense capability. The challenge is making sure innovation can be put to practical use alongside the systems and <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> already supporting operations.</p><h2 id="connecting-technology-across-defence">Connecting technology across defence</h2><p>Conversations around defense innovation often focus on AI, autonomous systems, advanced sensors, cyber capability and space assets. Each has a significant role to play, but none operates in isolation.</p><p>Information gathered by one system may need to be shared across multiple domains before it supports an operational decision. Networks, <a href="https://www.techradar.com/best/best-data-recovery-software">data</a>, command systems and people all contribute to that process. The value of any individual technology is linked to how effectively it connects with the wider operational environment.</p><p>This principle also applies to the infrastructure supporting military operations. Communications networks, operational facilities and digital systems all contribute to creating an environment where information can move securely and reliably. As these environments evolve, resilience and <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> must be designed from the outset though approaches such as secure-by-design and zero-trust principles.</p><h2 id="strengthening-the-foundations-of-operational-capability">Strengthening the foundations of operational capability</h2><p>AI has become one of the defining topics in defense. Its ability to process information and support decision-making has significant potential, but those capabilities depend on the quality of the data available and the resilience of the infrastructure that carries it.</p><p>Reliable communications, trusted data and secure networks remain fundamental to operational effectiveness. If those foundations are unavailable or compromised, the benefits of advanced technologies are reduced.</p><p>Therefore, creating decision advantage is not simply a technology challenge. It is an infrastructure and digital challenge and increasingly, a collaboration challenge.</p><p>For organizations supporting critical infrastructure, this has become an increasingly familiar challenge. Communications, operational technology, and digital infrastructure must work together to create environments where reliability cannot be compromised.</p><h2 id="keeping-people-at-the-heart-of-automation">Keeping people at the heart of automation</h2><p>Automation is attracting considerable attention across defense as organizations are looking to improve efficiency and increase operational tempo. However, automation should never be viewed as an end.</p><p>Its greatest value often comes from reducing routine activity rather than replacing people. Predictive maintenance, autonomous <a href="https://www.techradar.com/best/best-network-monitoring-tools">monitoring</a>, automated network <a href="https://www.techradar.com/best/it-management-tools">management</a> and logistics optimization all help reduce the time spent on repetitive tasks, allowing highly trained personnel to focus on areas where experience and judgement remain essential.</p><p>The most effective technologies do not replace human capability - they amplify it.</p><h2 id="the-infrastructure-supporting-multi-domain-operations">The infrastructure supporting multi-domain operations</h2><p>As operations become increasingly integrated across land, sea, air, cyber and space, infrastructure is taking on greater strategic importance. Communications, transport, energy, and digital systems all contribute to operational capability, showing how infrastructure and technology are becoming increasingly interdependent.</p><p>The movement of people, information, energy, and capability all contribute to operational readiness. Reliable infrastructure enables those elements to function as a single system, ensuring capability can be delivered when and where it is needed.</p><p>One example can be seen in the Falkland Islands, where runway infrastructure forms part of maintaining long-term strategic capability and readiness. It illustrates how infrastructure and operational capability are becoming increasingly interconnected.</p><h2 id="bringing-innovation-into-operational-use">Bringing innovation into operational use</h2><p>The UK benefits from an established community of innovators, with government, industry, academia, <a href="https://www.techradar.com/best/best-small-business-software">SMEs</a> and the Armed Forces all contributing to the development of new ideas and technologies. The opportunity now is to ensure those innovations can be adopted enough to meet operational needs.</p><p>Collaboration is still a critical part of this process. Bringing together different perspectives helps ensure technology is developed with practical application in mind and can be integrated more effectively into future capability.</p><h2 id="delivering-the-next-phase-of-defense-capability">Delivering the next phase of defense capability</h2><p>Much of the technology required to support future defense operations already exists. The focus now needs to be on how quickly it can be integrated and put to operational use, giving the Armed Forces the advantage they need as threats and operating environments continue to change. That requires stronger connections across networks, data, platforms, people and infrastructure.</p><p>Collaboration between government, industry, academia, SMEs and the Armed Forces will remain central to moving capability from development into deployment. Technologies also need a clearer and faster route beyond demonstrations and pilots, so useful capability reaches operators when it is needed.</p><p>The organizations that succeed will be those able to bring people and technology together across the wider defense environment. Doing that securely, reliably and at pace will determine how effectively innovation translates into operational advantage.</p><p><em></em><a href="https://www.techradar.com/best/best-ai-tools"><em>We've featured the best AI tool.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Storage infrastructure will underpin post-quantum security ]]></title>
                                                                                                <dc:content><![CDATA[ <p>AI has rewritten the enterprise <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> playbook. Workflows no longer just create temporary operational data, but vast amounts of high-value assets, from LLM training datasets and model outputs to logs, metadata and archived knowledge that may need to be preserved for years.</p><p>As enterprise tech leaders seek to scale <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> to meet these demands, storage requirements are undergoing a fundamental shift. Capacity and performance remain critical, but data <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> has become equally important. Today, long-term data integrity and absolute cyber resilience carry equal weight.</p><p>Protecting this data, however, is no longer just about defeating today’s threat vectors. It requires preparing storage infrastructure for a significant shift: the arrival of quantum computing. </p><h2 id="data-is-a-long-term-strategic-asset-not-a-short-lived-trend">Data is a long-term strategic asset, not a short-lived trend</h2><p>AI is accelerating data growth, but it can also extend the useful life of information. Data recorded today will be harvested for compliance, advanced analytics and model retraining for years to come.</p><p>To manage this economically, enterprise architectures rely heavily on high-capacity <a href="https://www.techradar.com/news/10-best-internal-desktop-and-laptop-hard-disk-drives-2016">HDDs</a>. While flash technologies dominate performance-critical hot tiers, HDDs remain the undisputed backbone of large-scale storage, providing the capacity, economics and longevity needed to archive data at scale.</p><p>As a result, organizations must consider how to protect not only today's data, but also its future value. After all, if the underlying infrastructure is compromised down the road, the very assets driving future AI innovations become the biggest operational and regulatory liability. </p><h2 id="harvest-now-decrypt-later">Harvest now, decrypt later</h2><p>Current encryption technologies remain effective against conventional threats. However, quantum computing is expected to challenge some of the cryptographic methods used for <a href="https://www.techradar.com/best/best-authenticator-apps">authentication</a> and key exchange.</p><p>This has led to concerns around “harvest now, decrypt later” attacks, where encrypted data is collected today with the expectation that future quantum capabilities could potentially decrypt it later.</p><p>For organizations storing sensitive intellectual property, research data or AI training datasets, this means security decisions made today could have implications for years to come.</p><p>Preparing for that future requires action from security leaders and IT directors now.</p><h2 id="security-must-be-built-into-the-infrastructure">Security must be built into the infrastructure</h2><p>Security is often viewed through the lens of data encryption, and with good reason. Self-encrypting drives (SEDs) provide always-on, hardware-based AES-256 encryption that helps protect data at rest without impacting performance.</p><p>But protecting data alone is no longer enough.</p><p><a href="https://www.techradar.com/news/the-10-best-nas-devices-reviewed">Storage</a> devices themselves must be trusted. Firmware, authentication mechanisms, provisioning processes and diagnostic tools all play a role in ensuring a drive operates securely throughout its lifecycle.</p><p>If attackers compromise a device's firmware or trust architecture, broader security controls can be undermined regardless of how data is encrypted elsewhere in the system. This makes storage security a critical component of overall cyber resilience.</p><h2 id="implementing-quantum-resistant-defenses-in-storage">Implementing quantum-resistant defenses in storage</h2><p>To counter these emerging attack vectors, the storage industry is actively embedding post-quantum cryptography into hardware architecture of enterprise hard drives. Rather than focusing solely on protecting data, the objective is to protect the trust architecture that underpins the drive itself.</p><p>Post quantum cryptography (PQC) technologies are being incorporated into areas such as secure key establishment, firmware authentication, secure provisioning, and trusted diagnostics. These capabilities are designed in alignment with established NIST post-quantum standards and are implemented using hybrid approaches that combine classical cryptography with quantum-resistant algorithms.</p><p>In practical terms, this means that the mechanisms responsible for establishing trust, validating firmware integrity and protecting administrative functions can remain resilient against both conventional and future quantum-enabled attacks. With the operational service life of HDDs often spanning 5 years (or more), implementing PQC today helps protect against quantum-based threats that may not materialize for several years, but that we know are coming.</p><p>Importantly, HDDs have long incorporated security controls to defend against today's threats. PQC does not replace these protections; it enhances them by adding an additional layer of resilience against emerging attack vectors. </p><h2 id="trust-in-the-ai-era">Trust in the AI era</h2><p>For many years, storage innovation was primarily defined by increases in capacity. Today, the expectations placed on infrastructure are much broader.</p><p>Organizations seek storage platforms that can scale with AI-driven data growth, deliver reliable performance, preserve integrity over long retention periods and withstand an increasingly complex threat environment.</p><p>PQC represents an important step in that evolution. By extending protection beyond data encryption and into the trust mechanisms that underpin storage devices themselves, PQC-enabled HDDs help organizations prepare for the security challenges of tomorrow while protecting the data they manage today.</p><p>As AI continues to elevate the strategic value of enterprise data, security can no longer be a short-term, reactive consideration. Trust must be engineered directly into the hardware layer and built to outlast the threats of today, tomorrow and the quantum era ahead of us. </p><p><em></em><a href="https://www.techradar.com/news/best-solid-state-drives-ssds"><em>We've featured the best SSD.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/storage-infrastructure-will-underpin-post-quantum-security</link>
                                                                            <description>
                            <![CDATA[ Protect long-term enterprise AI data from future quantum threats by securing underlying storage infrastructure today. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UdPZaDq9Lx8N5XgxywteL6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/M6fvPLRyP9CRCBwfYj7mxL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 09:54:23 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Uwe Kemmer ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/M6fvPLRyP9CRCBwfYj7mxL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital representations of phones and cards in slots]]></media:description>                                                            <media:text><![CDATA[Digital representations of phones and cards in slots]]></media:text>
                                <media:title type="plain"><![CDATA[Digital representations of phones and cards in slots]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/M6fvPLRyP9CRCBwfYj7mxL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI has rewritten the enterprise <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> playbook. Workflows no longer just create temporary operational data, but vast amounts of high-value assets, from LLM training datasets and model outputs to logs, metadata and archived knowledge that may need to be preserved for years.</p><p>As enterprise tech leaders seek to scale <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> to meet these demands, storage requirements are undergoing a fundamental shift. Capacity and performance remain critical, but data <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> has become equally important. Today, long-term data integrity and absolute cyber resilience carry equal weight.</p><p>Protecting this data, however, is no longer just about defeating today’s threat vectors. It requires preparing storage infrastructure for a significant shift: the arrival of quantum computing. </p><h2 id="data-is-a-long-term-strategic-asset-not-a-short-lived-trend">Data is a long-term strategic asset, not a short-lived trend</h2><p>AI is accelerating data growth, but it can also extend the useful life of information. Data recorded today will be harvested for compliance, advanced analytics and model retraining for years to come.</p><p>To manage this economically, enterprise architectures rely heavily on high-capacity <a href="https://www.techradar.com/news/10-best-internal-desktop-and-laptop-hard-disk-drives-2016">HDDs</a>. While flash technologies dominate performance-critical hot tiers, HDDs remain the undisputed backbone of large-scale storage, providing the capacity, economics and longevity needed to archive data at scale.</p><p>As a result, organizations must consider how to protect not only today's data, but also its future value. After all, if the underlying infrastructure is compromised down the road, the very assets driving future AI innovations become the biggest operational and regulatory liability. </p><h2 id="harvest-now-decrypt-later">Harvest now, decrypt later</h2><p>Current encryption technologies remain effective against conventional threats. However, quantum computing is expected to challenge some of the cryptographic methods used for <a href="https://www.techradar.com/best/best-authenticator-apps">authentication</a> and key exchange.</p><p>This has led to concerns around “harvest now, decrypt later” attacks, where encrypted data is collected today with the expectation that future quantum capabilities could potentially decrypt it later.</p><p>For organizations storing sensitive intellectual property, research data or AI training datasets, this means security decisions made today could have implications for years to come.</p><p>Preparing for that future requires action from security leaders and IT directors now.</p><h2 id="security-must-be-built-into-the-infrastructure">Security must be built into the infrastructure</h2><p>Security is often viewed through the lens of data encryption, and with good reason. Self-encrypting drives (SEDs) provide always-on, hardware-based AES-256 encryption that helps protect data at rest without impacting performance.</p><p>But protecting data alone is no longer enough.</p><p><a href="https://www.techradar.com/news/the-10-best-nas-devices-reviewed">Storage</a> devices themselves must be trusted. Firmware, authentication mechanisms, provisioning processes and diagnostic tools all play a role in ensuring a drive operates securely throughout its lifecycle.</p><p>If attackers compromise a device's firmware or trust architecture, broader security controls can be undermined regardless of how data is encrypted elsewhere in the system. This makes storage security a critical component of overall cyber resilience.</p><h2 id="implementing-quantum-resistant-defenses-in-storage">Implementing quantum-resistant defenses in storage</h2><p>To counter these emerging attack vectors, the storage industry is actively embedding post-quantum cryptography into hardware architecture of enterprise hard drives. Rather than focusing solely on protecting data, the objective is to protect the trust architecture that underpins the drive itself.</p><p>Post quantum cryptography (PQC) technologies are being incorporated into areas such as secure key establishment, firmware authentication, secure provisioning, and trusted diagnostics. These capabilities are designed in alignment with established NIST post-quantum standards and are implemented using hybrid approaches that combine classical cryptography with quantum-resistant algorithms.</p><p>In practical terms, this means that the mechanisms responsible for establishing trust, validating firmware integrity and protecting administrative functions can remain resilient against both conventional and future quantum-enabled attacks. With the operational service life of HDDs often spanning 5 years (or more), implementing PQC today helps protect against quantum-based threats that may not materialize for several years, but that we know are coming.</p><p>Importantly, HDDs have long incorporated security controls to defend against today's threats. PQC does not replace these protections; it enhances them by adding an additional layer of resilience against emerging attack vectors. </p><h2 id="trust-in-the-ai-era">Trust in the AI era</h2><p>For many years, storage innovation was primarily defined by increases in capacity. Today, the expectations placed on infrastructure are much broader.</p><p>Organizations seek storage platforms that can scale with AI-driven data growth, deliver reliable performance, preserve integrity over long retention periods and withstand an increasingly complex threat environment.</p><p>PQC represents an important step in that evolution. By extending protection beyond data encryption and into the trust mechanisms that underpin storage devices themselves, PQC-enabled HDDs help organizations prepare for the security challenges of tomorrow while protecting the data they manage today.</p><p>As AI continues to elevate the strategic value of enterprise data, security can no longer be a short-term, reactive consideration. Trust must be engineered directly into the hardware layer and built to outlast the threats of today, tomorrow and the quantum era ahead of us. </p><p><em></em><a href="https://www.techradar.com/news/best-solid-state-drives-ssds"><em>We've featured the best SSD.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI launches investigation after 153 million drivers licenses apparently leaked on Russian cybercrime forum ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>153 million US driving licences have been leaked on a Russian cybercrime platform</strong></li><li><strong>Among those apaprently discovered in the stolen data is US Secretary of Defense Pete Hegseth</strong></li><li><strong>The FBI is now investigating the leak, which has been traced to an identity verification company</strong></li></ul><p>A data leak of 153 million US drivers licenses is said to have been shared on a Russian cybercrime forum, with US Secretary of Defense Pete Hegseth among those leaked prompting an FBI investigation.</p><p>Security researcher Brian Krebs identified the leak – which included his own data – as originating from a hack of an identity verification service. Louisiana-based IDScan provided ID verification for various well-known companies, including FedEx and Hertz car hire.</p><p>The data was shared on a Russian forum called Exploit, a long-established online community of cybercriminals. Following news of the leak, the identity theft service “Nexus” has apparently scrubbed its existence from the Dark Web.</p><h2 id="driving-licenses-and-more">Driving licenses and more</h2><p>It wasn’t just US driving licenses that were found in the archive of recently-collected personal data. Krebs’ <a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/" target="_blank">investigation</a> found that Nexus claimed other types of data, and found a further 1.1 million driving licenses from Canada.</p><p>Other identity documentation alleged to be in the leak include 10 million identification cards, three million travel documents and international IDs, and 579,000 medical cards. The data was available to browse, notes Krebs, with Nexus providing details: “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”</p><p>The leak has a personal dimension for Krebs. Not only was his driving license in the collection, so was that of his mother. It has proved to be a useful coincidence, one that has enabled the security and privacy researcher to establish how the data was sourced by Nexus.</p><p>Both licenses were used for a car hire, which Krebs traced to Hertz. Others affected by the leak had also used the service, which has used New Orleans-based IDscan for identity verification.</p><p>The company, which claims to perform 21 million verifications a month, is yet to issue a statement on the matter. Its marketing and operations leader, Jillian Kossman, told the journalist: “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.” </p><h2 id="where-is-the-data">Where is the data?</h2><p>Krebs reports that he was alerted to the data on August 31, 2026, little over a week ago. Regular checking noted that the data was still being added to, increasing by “nearly 400,000” records prior to publishing his investigation on September 1.</p><p>Since then, however, it seems that Nexus has vanished, along with the data. But how widely was the data downloaded before that happened? While the FBI investigates, it falls on the American and Canadian public to be extra vigilant and wary of identity fraud.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/fbi-launches-investigation-after-153-million-drivers-licenses-apparently-leaked-on-russian-cybercrime-forum</link>
                                                                            <description>
                            <![CDATA[ Lousiana-based identity verification service IDScan identified as the target of a hack that leaked 153 million US drivers licenses. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pJfgMSYGXMyKq5zMKcF2g7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mBxmnLnpbAuepmei5vxvLf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 18:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mBxmnLnpbAuepmei5vxvLf-1280-80.jpg">
                                                            <media:credit><![CDATA[wigglestick/ Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Outline map of US states in glowing blue with exploding streams of binary data illustrating communication, internet and technology]]></media:description>                                                            <media:text><![CDATA[Outline map of US states in glowing blue with exploding streams of binary data illustrating communication, internet and technology]]></media:text>
                                <media:title type="plain"><![CDATA[Outline map of US states in glowing blue with exploding streams of binary data illustrating communication, internet and technology]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mBxmnLnpbAuepmei5vxvLf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>153 million US driving licences have been leaked on a Russian cybercrime platform</strong></li><li><strong>Among those apaprently discovered in the stolen data is US Secretary of Defense Pete Hegseth</strong></li><li><strong>The FBI is now investigating the leak, which has been traced to an identity verification company</strong></li></ul><p>A data leak of 153 million US drivers licenses is said to have been shared on a Russian cybercrime forum, with US Secretary of Defense Pete Hegseth among those leaked prompting an FBI investigation.</p><p>Security researcher Brian Krebs identified the leak – which included his own data – as originating from a hack of an identity verification service. Louisiana-based IDScan provided ID verification for various well-known companies, including FedEx and Hertz car hire.</p><p>The data was shared on a Russian forum called Exploit, a long-established online community of cybercriminals. Following news of the leak, the identity theft service “Nexus” has apparently scrubbed its existence from the Dark Web.</p><h2 id="driving-licenses-and-more">Driving licenses and more</h2><p>It wasn’t just US driving licenses that were found in the archive of recently-collected personal data. Krebs’ <a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/" target="_blank">investigation</a> found that Nexus claimed other types of data, and found a further 1.1 million driving licenses from Canada.</p><p>Other identity documentation alleged to be in the leak include 10 million identification cards, three million travel documents and international IDs, and 579,000 medical cards. The data was available to browse, notes Krebs, with Nexus providing details: “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”</p><p>The leak has a personal dimension for Krebs. Not only was his driving license in the collection, so was that of his mother. It has proved to be a useful coincidence, one that has enabled the security and privacy researcher to establish how the data was sourced by Nexus.</p><p>Both licenses were used for a car hire, which Krebs traced to Hertz. Others affected by the leak had also used the service, which has used New Orleans-based IDscan for identity verification.</p><p>The company, which claims to perform 21 million verifications a month, is yet to issue a statement on the matter. Its marketing and operations leader, Jillian Kossman, told the journalist: “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.” </p><h2 id="where-is-the-data">Where is the data?</h2><p>Krebs reports that he was alerted to the data on August 31, 2026, little over a week ago. Regular checking noted that the data was still being added to, increasing by “nearly 400,000” records prior to publishing his investigation on September 1.</p><p>Since then, however, it seems that Nexus has vanished, along with the data. But how widely was the data downloaded before that happened? While the FBI investigates, it falls on the American and Canadian public to be extra vigilant and wary of identity fraud.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fake GTA 6 malware is on the rise as release date nears — here are some of the worst scams to look out for ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress warns fake GTA 6 ISOs spreading malware ahead of official Nov 19, 2026 release</strong></li><li><strong>Packages deliver RATs, infostealers, and Chaos ransomware disguised as game installers</strong></li><li><strong>Users urged to avoid pirated downloads; infected systems should be reimaged and credentials reset</strong></li></ul><p>Grand Theft Auto 6 (GTA 6), one of the most anticipated computer games of all time, is due to launch on November 19, 2026 - so everything found online before that is almost certainly malware. </p><p>This is the warning sent out by security researchers Huntress, which <a href="https://www.huntress.com/blog/fake-gta6-download-malware-analysis" target="_blank" rel="nofollow">said</a> it recently saw one variant deploying all sorts of filth, from remote access trojans (RAT), across infostealers, to full-blown ransomware encryptors.</p><h2 id="the-story-behind-gta-6">The story behind GTA 6</h2><p>GTA 6 is a third-person action-adventure and open-world gam developed by Rockstar Games, which egan preliminary work more than a decade ago, and has allegedly spent <a href="https://finance.yahoo.com/markets/stocks/articles/viral-post-says-gta-6-184500207.html?guccounter=1" target="_blank">more than a billion dollars</a> during that decade and a half, which would make it, by far, the most expensive game ever developed.</p><p>It is also a sequel to GTA 5, a game that was sold in more than 230 million copies around the world, which made it one of the most popular games of all time.</p><p>In late August 2026, someone going by the alias LEEK <a href="https://www.pcgamer.com/games/grand-theft-auto/the-latest-gta-6-leak-confirms-the-leaker-likely-has-or-had-access-to-a-playable-build/?utm_source=chatgpt.com" target="_blank">claimed to have obtained a working, playable build of the game</a>, roughly six months before the official release. They posted numerous screenshots and videos of them playing the game, even writing their nickname onto a wall, using a rifle to prove the authenticity. Truth be told, even without this, people would have still probably searched for, and downloaded, fake installers. This only made the problem worse.</p><p>And a major problem, it definitely is. Huntress is now saying it is seeing websites ranking relatively high (through SEO poisoning), offering for download an ISO of the game. Similar ISOs are circulating around different gaming forums, torrenting sites, and social media channels. </p><p>An ISO file is a digital copy of an entire disc, such as a CD, DVD, or Blu-ray, stored as one file. Users can download an ISO (which can weigh tens or hundreds of gigabytes), mount it into a virtual drive, and the computer will treat it like a physical disc. </p><p>Huntress found some ISOs weighing more than 100GB which was done just to make it seem authentic - the actual malware was “a factor smaller”. The ISOs they analyzed contained multiple variants, including NJRAT and CDRAT (two remote access trojans), Mercurial Grabber (an infostealer grabbing Roblox Studio cookies, Minecraft session data, Discord tokens, Chrome passwords and cookies, system information, IP addresses, and geolocation, Windows product keys, and screenshots), and Chaos Ransomware. The package also contained a legitimate, regular browser - “Just for kicks,” apparently.</p><h2 id="a-plausible-failure">A plausible failure</h2><p>During the “game” installation, the installer displays a message in Russian, saying the product is unlicensed and that there is a good chance it won’t run. If that happens, the user is told to reach out to a specific Gmail address to receive an “updated crack”. After the installation completes, the victim will get that exact popup, saying “License not found”. All of this is just a smoke screen, to make the victim not suspicious as to why the “game” won’t run.</p><p>There is no way of telling how many people fell for the ruse and installed <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> on their devices. Huntress says that generally speaking, trying to download cracked and pirated software is a bad idea, which is even worse if the game in question has not yet been released. </p><p>“This is fertile ground for scams and threat actors attempting to take advantage of the impatient and overeager,” the researchers said.</p><p>The good news is that all of the malware being distributed there is not new. Some of the variants contained in the ISOs are several years old, meaning most antivirus programs, such as Windows Defender for example, can easily detect it and stop it from compromising the system. </p><p>Those that do end up infected should disconnect the machine from the internet, reset all passwords, enable 2FA wherever possible, and do a complete reimage of the compromised system.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/fake-gta-6-malware-is-on-the-rise-as-release-date-nears-here-are-some-of-the-worst-scams-to-look-out-for</link>
                                                                            <description>
                            <![CDATA[ Be careful with websites and Telegram channels offering GTA 6 content, experts warn. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">k7GigBvuqE6DZSGxEFGGDf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/knPikneiqQ4a4p7AEdGPra-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 18:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/knPikneiqQ4a4p7AEdGPra-1280-80.jpg">
                                                            <media:credit><![CDATA[Rockstar Games]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GTA 6]]></media:description>                                                            <media:text><![CDATA[GTA 6]]></media:text>
                                <media:title type="plain"><![CDATA[GTA 6]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/knPikneiqQ4a4p7AEdGPra-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress warns fake GTA 6 ISOs spreading malware ahead of official Nov 19, 2026 release</strong></li><li><strong>Packages deliver RATs, infostealers, and Chaos ransomware disguised as game installers</strong></li><li><strong>Users urged to avoid pirated downloads; infected systems should be reimaged and credentials reset</strong></li></ul><p>Grand Theft Auto 6 (GTA 6), one of the most anticipated computer games of all time, is due to launch on November 19, 2026 - so everything found online before that is almost certainly malware. </p><p>This is the warning sent out by security researchers Huntress, which <a href="https://www.huntress.com/blog/fake-gta6-download-malware-analysis" target="_blank" rel="nofollow">said</a> it recently saw one variant deploying all sorts of filth, from remote access trojans (RAT), across infostealers, to full-blown ransomware encryptors.</p><h2 id="the-story-behind-gta-6">The story behind GTA 6</h2><p>GTA 6 is a third-person action-adventure and open-world gam developed by Rockstar Games, which egan preliminary work more than a decade ago, and has allegedly spent <a href="https://finance.yahoo.com/markets/stocks/articles/viral-post-says-gta-6-184500207.html?guccounter=1" target="_blank">more than a billion dollars</a> during that decade and a half, which would make it, by far, the most expensive game ever developed.</p><p>It is also a sequel to GTA 5, a game that was sold in more than 230 million copies around the world, which made it one of the most popular games of all time.</p><p>In late August 2026, someone going by the alias LEEK <a href="https://www.pcgamer.com/games/grand-theft-auto/the-latest-gta-6-leak-confirms-the-leaker-likely-has-or-had-access-to-a-playable-build/?utm_source=chatgpt.com" target="_blank">claimed to have obtained a working, playable build of the game</a>, roughly six months before the official release. They posted numerous screenshots and videos of them playing the game, even writing their nickname onto a wall, using a rifle to prove the authenticity. Truth be told, even without this, people would have still probably searched for, and downloaded, fake installers. This only made the problem worse.</p><p>And a major problem, it definitely is. Huntress is now saying it is seeing websites ranking relatively high (through SEO poisoning), offering for download an ISO of the game. Similar ISOs are circulating around different gaming forums, torrenting sites, and social media channels. </p><p>An ISO file is a digital copy of an entire disc, such as a CD, DVD, or Blu-ray, stored as one file. Users can download an ISO (which can weigh tens or hundreds of gigabytes), mount it into a virtual drive, and the computer will treat it like a physical disc. </p><p>Huntress found some ISOs weighing more than 100GB which was done just to make it seem authentic - the actual malware was “a factor smaller”. The ISOs they analyzed contained multiple variants, including NJRAT and CDRAT (two remote access trojans), Mercurial Grabber (an infostealer grabbing Roblox Studio cookies, Minecraft session data, Discord tokens, Chrome passwords and cookies, system information, IP addresses, and geolocation, Windows product keys, and screenshots), and Chaos Ransomware. The package also contained a legitimate, regular browser - “Just for kicks,” apparently.</p><h2 id="a-plausible-failure">A plausible failure</h2><p>During the “game” installation, the installer displays a message in Russian, saying the product is unlicensed and that there is a good chance it won’t run. If that happens, the user is told to reach out to a specific Gmail address to receive an “updated crack”. After the installation completes, the victim will get that exact popup, saying “License not found”. All of this is just a smoke screen, to make the victim not suspicious as to why the “game” won’t run.</p><p>There is no way of telling how many people fell for the ruse and installed <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> on their devices. Huntress says that generally speaking, trying to download cracked and pirated software is a bad idea, which is even worse if the game in question has not yet been released. </p><p>“This is fertile ground for scams and threat actors attempting to take advantage of the impatient and overeager,” the researchers said.</p><p>The good news is that all of the malware being distributed there is not new. Some of the variants contained in the ISOs are several years old, meaning most antivirus programs, such as Windows Defender for example, can easily detect it and stop it from compromising the system. </p><p>Those that do end up infected should disconnect the machine from the internet, reset all passwords, enable 2FA wherever possible, and do a complete reimage of the compromised system.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Multiple hacking groups found using the same Chrome malware in the same week — so what does it mean? ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Proofpoint detailed BlueMoon, an exploit kit chaining two Chromium flaws and one Windows bug</strong></li><li><strong>Four groups, including China‑aligned TA412, used it loudly against NGOs, aerospace, and manufacturing targets</strong></li><li><strong>Exploits were “patch‑gap” zero‑days; all flaws now patched</strong></li></ul><p>Four hacking groups, including some tied to the Chinese government, were seen using the exact same exploit kit in a span of a week, suggesting a certain “fear of missing out” among the criminals, experts have warned.</p><p>Security researchers Proofpoint have detailed BlueMoon, an <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">exploit kit</a> that leverages three vulnerabilities: two in Chromium, and one in older versions of Windows: Windows 10 (October 2018 Update), Windows Server 2019, Windows 10 2004, WIndows Server 2022, and the initial release of Windows 11. </p><p>The kit was first seen being used on August 28 2026, by a threat actor tracked as TA412, a China-aligned state-sponsored threat actor that was observed in the past targeting businesses using Microsoft SharePoint. TA412, also known as Violet Typhoon, used BlueMoon to “repeatedly target a small number of non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the United States.”</p><p>Soon after that, three others were spotted: UNK_LateNight, another China-aligned espionage group which targeted multiple US aerospace companies, UNK_DoubleCheck, a group going after a Vietnamese manufacturing entity, and UNK_QuietRacket, a threat actor taking aim at organizations across Singapore and Indonesia.</p><p>What all of these groups have in common is the fact that they did not try particularly hard to hide their activity. This is rather unusual, since a stealthy approach usually guarantees that a vulnerability can be exploited for longer.</p><h2 id="front-running-the-chromium-supply-chain-train">Front running the Chromium supply chain train</h2><p>BlueMoon takes advantage of three flaws, two in Chromium and one in older Windows variants. The Chromium vulnerabilities were found in V8, the JavaScript engine that the browsers use to allow applications to run efficiently. The first one is a “type confusion bug”, tracked as CVE-2026-85046, and assigned a severity score of 8.8/10 (high). The latter is a “sandbox escape” flaw, for which Google did not assign a CVE or a severity score. </p><p>The Windows bug, on the other hand, is tracked as CVE-2026-85880, and was given a severity score of 7.8/10 (high). It is described as a “heap-based buffer overflow” vulnerability in Windows Advanced Local Procedure Call, allowing malicious actors who can already execute code inside a low-privilege AppContainer to escape the sandbox and elevate privileges to SYSTEM. No additional user interaction is required.</p><p>Proofpoint has a theory as to why the crooks decided to be loud, instead of flying under the radar. Apparently, there is a very short window of opportunity between Google patching a Chromium vulnerability, and it being deployed to a <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> such as Edge, or Brave, This window of opportunity also allows crooks to see how Google fixed a flaw, reverse-engineer it, and deploy an exploit before the browser is patched. This would mean that there is no time to be stealthy. </p><h2 id="no-time-to-hide">No time to hide</h2><p>“Both V8 vulnerabilities were ‘patch-gap’ zero-days at the time of the observed activity,” Proofpoint said. “In other words, while they were known vulnerabilities already fixed in public upstream Chromium source code, they remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public. It is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain.”</p><p>Another important factor is Artificial Intelligence. It would seem that AI has made flaw detection significantly faster, reducing the barrier to entry and making threat actors move more loudly.</p><p>“A fully weaponized Chrome exploit chain has historically been a high-value, rare capability. BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development,” Proofpoint stressed. </p><p>All three flaws have since been patched, so make sure you’re running the latest version of both the OS and the Chromium browser. </p><p><em>Via </em><a href="https://arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/" target="_blank"><em>Ars Technica</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/multiple-hacking-groups-found-using-the-same-chrome-malware-in-the-same-week-so-what-does-it-mean</link>
                                                                            <description>
                            <![CDATA[ Someone is afraid of missing out, as defenders rush to patch things up. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VpmftvDTzJKLp2prufcPaU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg">
                                                            <media:credit><![CDATA[Tada Images / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:description>                                                            <media:text><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:text>
                                <media:title type="plain"><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Proofpoint detailed BlueMoon, an exploit kit chaining two Chromium flaws and one Windows bug</strong></li><li><strong>Four groups, including China‑aligned TA412, used it loudly against NGOs, aerospace, and manufacturing targets</strong></li><li><strong>Exploits were “patch‑gap” zero‑days; all flaws now patched</strong></li></ul><p>Four hacking groups, including some tied to the Chinese government, were seen using the exact same exploit kit in a span of a week, suggesting a certain “fear of missing out” among the criminals, experts have warned.</p><p>Security researchers Proofpoint have detailed BlueMoon, an <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">exploit kit</a> that leverages three vulnerabilities: two in Chromium, and one in older versions of Windows: Windows 10 (October 2018 Update), Windows Server 2019, Windows 10 2004, WIndows Server 2022, and the initial release of Windows 11. </p><p>The kit was first seen being used on August 28 2026, by a threat actor tracked as TA412, a China-aligned state-sponsored threat actor that was observed in the past targeting businesses using Microsoft SharePoint. TA412, also known as Violet Typhoon, used BlueMoon to “repeatedly target a small number of non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the United States.”</p><p>Soon after that, three others were spotted: UNK_LateNight, another China-aligned espionage group which targeted multiple US aerospace companies, UNK_DoubleCheck, a group going after a Vietnamese manufacturing entity, and UNK_QuietRacket, a threat actor taking aim at organizations across Singapore and Indonesia.</p><p>What all of these groups have in common is the fact that they did not try particularly hard to hide their activity. This is rather unusual, since a stealthy approach usually guarantees that a vulnerability can be exploited for longer.</p><h2 id="front-running-the-chromium-supply-chain-train">Front running the Chromium supply chain train</h2><p>BlueMoon takes advantage of three flaws, two in Chromium and one in older Windows variants. The Chromium vulnerabilities were found in V8, the JavaScript engine that the browsers use to allow applications to run efficiently. The first one is a “type confusion bug”, tracked as CVE-2026-85046, and assigned a severity score of 8.8/10 (high). The latter is a “sandbox escape” flaw, for which Google did not assign a CVE or a severity score. </p><p>The Windows bug, on the other hand, is tracked as CVE-2026-85880, and was given a severity score of 7.8/10 (high). It is described as a “heap-based buffer overflow” vulnerability in Windows Advanced Local Procedure Call, allowing malicious actors who can already execute code inside a low-privilege AppContainer to escape the sandbox and elevate privileges to SYSTEM. No additional user interaction is required.</p><p>Proofpoint has a theory as to why the crooks decided to be loud, instead of flying under the radar. Apparently, there is a very short window of opportunity between Google patching a Chromium vulnerability, and it being deployed to a <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> such as Edge, or Brave, This window of opportunity also allows crooks to see how Google fixed a flaw, reverse-engineer it, and deploy an exploit before the browser is patched. This would mean that there is no time to be stealthy. </p><h2 id="no-time-to-hide">No time to hide</h2><p>“Both V8 vulnerabilities were ‘patch-gap’ zero-days at the time of the observed activity,” Proofpoint said. “In other words, while they were known vulnerabilities already fixed in public upstream Chromium source code, they remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public. It is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain.”</p><p>Another important factor is Artificial Intelligence. It would seem that AI has made flaw detection significantly faster, reducing the barrier to entry and making threat actors move more loudly.</p><p>“A fully weaponized Chrome exploit chain has historically been a high-value, rare capability. BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development,” Proofpoint stressed. </p><p>All three flaws have since been patched, so make sure you’re running the latest version of both the OS and the Chromium browser. </p><p><em>Via </em><a href="https://arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/" target="_blank"><em>Ars Technica</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Beware — these new phishing attacks use a convincing fake Adobe Reader pages to trick victims into installing malware ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress warns of phishing campaign abusing Adobe branding with browser‑in‑the‑browser trick  </strong></li><li><strong>Victims lured into fake update pages, unknowingly installing rogue ScreenConnect clients  </strong></li><li><strong>Attackers gain persistent remote access; defenders urged to restrict RMM installs and monitor IoCs</strong></li></ul><p>Security researchers Huntress have warned of an ongoing phishing campaign that abuses Adobe’s brand while deploying clever browser-in-the-browser (BitB) techniques to trick the victims. </p><p>The goal is to deliver rogue ScreenConnect clients which would grant the attackers persistent access to target devices.</p><p>In its <a href="https://www.huntress.com/blog/phishing-bitb-rmm-attacks" target="_blank" rel="nofollow">report</a>, Huntress says it could not find the lure itself and thus could not report what the scam looks like. However, it saw the victims clicking on a link in the email and then being redirected to a typosquatted domain https[://]adoube[.]vu that spoofs an Adobe landing page.</p><h2 id="we-heard-you-like-browsers">We heard you like browsers…</h2><p>This is where we get to the scam’s unique twist. Usually, phishing lures would simply redirect victims to a malicious website which could be identified simply by looking at the address bar. If the domain differs from the legitimate one, the scam falls apart. To work around that problem, scammers came with a solution called “browser in the browser”. </p><p>Using either HTML, CSS, or JavaScript, the crooks would create an entire fake browser window, including the address bar, URL, padlock icon, and more, inside the actual webpage content itself. Therefore, if the victim isn’t all too careful, they might look at the fake address bar, see a legitimate URL, and believe they are visiting the correct website.</p><p>In this fake <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> window, the fraudsters display a blurred .PDF document. Overlaid is a message saying the documents are “secured” and created with “the latest version of Adobe.” The only way to read them, the message continues, is to “update or download Adobe PDF Reader.” Expectedly, there is a big “View Files” button just under the notification, leading to a different, equally fake BitB page, showing the download progress. In the background, something gets downloaded.</p><p>Victims might think they’re getting a PDF reader, while in reality they’re getting a rogue version of ScreenConnect.</p><h2 id="poisoned-screenconnect-instances">Poisoned ScreenConnect instances</h2><p>On its own, ScreenConnect is not malware, or dangerous in any other way. It is a legitimate <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote access and support software</a>, similar to TeamViewer, AnyDesk, or Remote Desktop, allowing IT professionals remotely connect to and control computers and other devices. These variants, however, are tainted to enable threat actors to obtain persistent remote access to their targets’ endpoints, Huntress explained.</p><p>“The first initial remote client installed was the rogue ScreenConnect Client configured to communicate with instance-uxh86b-relay[.]screenconnect[.]com. The attacker used a legitimate ScreenConnect Trial Relay domain to further avoid detection,” the researchers said. “This initial malicious ScreenConnect Client used the native Windows command shell and curl to retrieve and install a second malicious ScreenConnect Client configured to communicate with attacker-controlled IP. Both clients established service-based persistence for continued remote access.”</p><p>After installation, the attackers used the second ScreenConnect session to run HideCursor.exe, an executable, as the name suggests, that helps the attackers hide their mouse activity. </p><p>Huntress’ researchers don’t know what the endgame is, since the threat actors were spotted and shut down in this stage of the attack. The researchers also did not share the details about the target, such as the size of the organization, or the industry it operates in. Therefore, it is impossible to even speculate on the nature of the attack and if the threat actors aimed to install ransomware.</p><p>Still, the researchers stressed the importance of training employees to “treat unexpected software update prompts and file-viewing pages with caution”, and to make sure they know how to verify downloads through trusted channels. IT teams should also restrict who can install remote-management tools, maintain an approved inventory of RMM software, and alert on new or unapproved ScreenConnect clients, unusual relay connections, and executables launched from the user Downloads folders.</p><p>Finally, businesses should monitor for Indicators of Compromise (IoC) listed on <a href="https://www.huntress.com/blog/phishing-bitb-rmm-attacks" target="_blank">this page</a>.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/watch-out-these-new-phishing-attacks-use-a-convincing-fake-adobe-reader-pages-to-trick-victims-into-installing-malware</link>
                                                                            <description>
                            <![CDATA[ Crooks are deploying cheeky browser-in-the-browser techniques to trick victims into downloading RMM tools. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Xd5CXXfGjfqbJQetYYE4fZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ncL98vteKnP9dydmNAHGqN-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/ncL98vteKnP9dydmNAHGqN-1280-80.png">
                                                            <media:credit><![CDATA[Varonis]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[PDF]]></media:description>                                                            <media:text><![CDATA[PDF]]></media:text>
                                <media:title type="plain"><![CDATA[PDF]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ncL98vteKnP9dydmNAHGqN-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress warns of phishing campaign abusing Adobe branding with browser‑in‑the‑browser trick  </strong></li><li><strong>Victims lured into fake update pages, unknowingly installing rogue ScreenConnect clients  </strong></li><li><strong>Attackers gain persistent remote access; defenders urged to restrict RMM installs and monitor IoCs</strong></li></ul><p>Security researchers Huntress have warned of an ongoing phishing campaign that abuses Adobe’s brand while deploying clever browser-in-the-browser (BitB) techniques to trick the victims. </p><p>The goal is to deliver rogue ScreenConnect clients which would grant the attackers persistent access to target devices.</p><p>In its <a href="https://www.huntress.com/blog/phishing-bitb-rmm-attacks" target="_blank" rel="nofollow">report</a>, Huntress says it could not find the lure itself and thus could not report what the scam looks like. However, it saw the victims clicking on a link in the email and then being redirected to a typosquatted domain https[://]adoube[.]vu that spoofs an Adobe landing page.</p><h2 id="we-heard-you-like-browsers">We heard you like browsers…</h2><p>This is where we get to the scam’s unique twist. Usually, phishing lures would simply redirect victims to a malicious website which could be identified simply by looking at the address bar. If the domain differs from the legitimate one, the scam falls apart. To work around that problem, scammers came with a solution called “browser in the browser”. </p><p>Using either HTML, CSS, or JavaScript, the crooks would create an entire fake browser window, including the address bar, URL, padlock icon, and more, inside the actual webpage content itself. Therefore, if the victim isn’t all too careful, they might look at the fake address bar, see a legitimate URL, and believe they are visiting the correct website.</p><p>In this fake <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> window, the fraudsters display a blurred .PDF document. Overlaid is a message saying the documents are “secured” and created with “the latest version of Adobe.” The only way to read them, the message continues, is to “update or download Adobe PDF Reader.” Expectedly, there is a big “View Files” button just under the notification, leading to a different, equally fake BitB page, showing the download progress. In the background, something gets downloaded.</p><p>Victims might think they’re getting a PDF reader, while in reality they’re getting a rogue version of ScreenConnect.</p><h2 id="poisoned-screenconnect-instances">Poisoned ScreenConnect instances</h2><p>On its own, ScreenConnect is not malware, or dangerous in any other way. It is a legitimate <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote access and support software</a>, similar to TeamViewer, AnyDesk, or Remote Desktop, allowing IT professionals remotely connect to and control computers and other devices. These variants, however, are tainted to enable threat actors to obtain persistent remote access to their targets’ endpoints, Huntress explained.</p><p>“The first initial remote client installed was the rogue ScreenConnect Client configured to communicate with instance-uxh86b-relay[.]screenconnect[.]com. The attacker used a legitimate ScreenConnect Trial Relay domain to further avoid detection,” the researchers said. “This initial malicious ScreenConnect Client used the native Windows command shell and curl to retrieve and install a second malicious ScreenConnect Client configured to communicate with attacker-controlled IP. Both clients established service-based persistence for continued remote access.”</p><p>After installation, the attackers used the second ScreenConnect session to run HideCursor.exe, an executable, as the name suggests, that helps the attackers hide their mouse activity. </p><p>Huntress’ researchers don’t know what the endgame is, since the threat actors were spotted and shut down in this stage of the attack. The researchers also did not share the details about the target, such as the size of the organization, or the industry it operates in. Therefore, it is impossible to even speculate on the nature of the attack and if the threat actors aimed to install ransomware.</p><p>Still, the researchers stressed the importance of training employees to “treat unexpected software update prompts and file-viewing pages with caution”, and to make sure they know how to verify downloads through trusted channels. IT teams should also restrict who can install remote-management tools, maintain an approved inventory of RMM software, and alert on new or unapproved ScreenConnect clients, unusual relay connections, and executables launched from the user Downloads folders.</p><p>Finally, businesses should monitor for Indicators of Compromise (IoC) listed on <a href="https://www.huntress.com/blog/phishing-bitb-rmm-attacks" target="_blank">this page</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Watch out, Google Play’s Early Access could become a breeding ground for malicious apps — with no public reviews or ratings, what could go wrong? ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Bitdefender finds Google Play Early Access platform could give malicious apps an easy breeding ground</strong></li><li><strong>User reviews and ratings are not publicly displayed, removing the ability for users to evaluate if an app is legitimate</strong></li><li><strong>Games, casinos, and utility apps are being loaded with malicious packages and downloaded thousands of times</strong></li></ul><p>Google has unveiled an Early Access program for the Play Store, allowing developers to list early-access apps for testing and feedback.</p><p>While great for smaller apps looking to weed out any wrinkles in their apps, Early Access also offers a lucrative way for malicious actors to lure users into downloading apps that look legitimate, but can hide malicious packages inside.</p><p>However, new research from <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/google-play-early-access-exploit-deceptive-apps" target="_blank" rel="nofollow">Bitdefender</a> notes the fact that the Early Access program hides public reviews and ratings could lead to an app ecosystem filled with scams, fake casinos, and malware-laden packages masquerading as legitimate software.</p><h2 id="early-access-is-filled-with-dangerous-apps">Early Access is filled with dangerous apps</h2><p>When looking for apps on the normal Play Store, one of the first things users are greeted with is an app’s rating. For fake or malicious apps, users can quickly evaluate whether or not to download the app thanks to the star rating and user reviews. While there is the potential for nefarious developers to fake reviews and ratings there is at least some ability to check if an app is legitimate.</p><p>But the Early Access system does away with public user ratings and reviews entirely. There is effectively no way for users who fall victim to a fake app to publicly warn other users not to download the app.</p><p>Add to this equation that ability for developers to show off their apps through sponsored Facebook and TikTok videos, offering outrageous rewards or using deepfakes of celebrities to entice users to install their apps.</p><p>This is especially true for fake gambling apps. Bitdefender has spotted numerous adverts for casino apps using deepfakes of well known celebrities such as Cristiano Ronaldo, Jason Statham, and Andrew Tate. These apps actively push users into the Google Play Early Access store, or direct to the apps website.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="S3stBmbub2CNx4AbcnCv8L" name="Bitdefender Scam ads" alt="A selection of promoted adds on TikTok showing deepfakes of celebrities advertising fake apps on the Google Play Early Access platform." src="https://cdn.mos.cms.futurecdn.net/S3stBmbub2CNx4AbcnCv8L-1920-80.png" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Bitdefender)</span></figcaption></figure><p>Other listings mimic well-known apps, adding financial incentives for downloading such as doubling the money you invest every time you complete a task or overcome an obstacle. Other apps take advantage of the hype for upcoming game releases, such as Grand Theft Auto V and VI. These apps often use screenshots from the actual games in order to appear legitimate.</p><p>When detected as illegitimate, these scam apps will often be deleted before being replaced by exact copies that perform the same malicious functions. Some illegitimate apps have been downloaded thousands of times, Bitdefender said, but many remain available on the Google Play Early Access store.</p><p>But the scam apps aren’t limited to games and casino apps. Bitdefender also saw numerous apps offering utility functions such as QR code scanners or PDF readers. In some circumstances, the exact same apps were listed multiple times by different developers - likely to expand the reach and maximize the number of downloads.</p><p>Bitdefender notes that Google Play’s reputation relies on users being able to trust the apps they are downloading, but the Early Access program removes almost every way users can detect a malicious app before installing.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/watch-out-google-plays-early-access-could-become-a-breeding-ground-for-malicious-apps-with-no-public-reviews-or-ratings-what-could-go-wrong</link>
                                                                            <description>
                            <![CDATA[ Google Play is a go-to for downloading trustworthy apps, but this could change everything ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ihSXj3VXTaKYGgtF9uzFxZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/f7VHBf7mNuETyedzPFND5Y-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/f7VHBf7mNuETyedzPFND5Y-1280-80.jpg">
                                                            <media:credit><![CDATA[Photo Illustration by Idrees Abbas/SOPA Images/LightRocket via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[In this photo illustration, the Google play store logo is seen displayed on a mobile phone screen.]]></media:description>                                                            <media:text><![CDATA[In this photo illustration, the Google play store logo is seen displayed on a mobile phone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[In this photo illustration, the Google play store logo is seen displayed on a mobile phone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/f7VHBf7mNuETyedzPFND5Y-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Bitdefender finds Google Play Early Access platform could give malicious apps an easy breeding ground</strong></li><li><strong>User reviews and ratings are not publicly displayed, removing the ability for users to evaluate if an app is legitimate</strong></li><li><strong>Games, casinos, and utility apps are being loaded with malicious packages and downloaded thousands of times</strong></li></ul><p>Google has unveiled an Early Access program for the Play Store, allowing developers to list early-access apps for testing and feedback.</p><p>While great for smaller apps looking to weed out any wrinkles in their apps, Early Access also offers a lucrative way for malicious actors to lure users into downloading apps that look legitimate, but can hide malicious packages inside.</p><p>However, new research from <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/google-play-early-access-exploit-deceptive-apps" target="_blank" rel="nofollow">Bitdefender</a> notes the fact that the Early Access program hides public reviews and ratings could lead to an app ecosystem filled with scams, fake casinos, and malware-laden packages masquerading as legitimate software.</p><h2 id="early-access-is-filled-with-dangerous-apps">Early Access is filled with dangerous apps</h2><p>When looking for apps on the normal Play Store, one of the first things users are greeted with is an app’s rating. For fake or malicious apps, users can quickly evaluate whether or not to download the app thanks to the star rating and user reviews. While there is the potential for nefarious developers to fake reviews and ratings there is at least some ability to check if an app is legitimate.</p><p>But the Early Access system does away with public user ratings and reviews entirely. There is effectively no way for users who fall victim to a fake app to publicly warn other users not to download the app.</p><p>Add to this equation that ability for developers to show off their apps through sponsored Facebook and TikTok videos, offering outrageous rewards or using deepfakes of celebrities to entice users to install their apps.</p><p>This is especially true for fake gambling apps. Bitdefender has spotted numerous adverts for casino apps using deepfakes of well known celebrities such as Cristiano Ronaldo, Jason Statham, and Andrew Tate. These apps actively push users into the Google Play Early Access store, or direct to the apps website.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="S3stBmbub2CNx4AbcnCv8L" name="Bitdefender Scam ads" alt="A selection of promoted adds on TikTok showing deepfakes of celebrities advertising fake apps on the Google Play Early Access platform." src="https://cdn.mos.cms.futurecdn.net/S3stBmbub2CNx4AbcnCv8L-1920-80.png" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Bitdefender)</span></figcaption></figure><p>Other listings mimic well-known apps, adding financial incentives for downloading such as doubling the money you invest every time you complete a task or overcome an obstacle. Other apps take advantage of the hype for upcoming game releases, such as Grand Theft Auto V and VI. These apps often use screenshots from the actual games in order to appear legitimate.</p><p>When detected as illegitimate, these scam apps will often be deleted before being replaced by exact copies that perform the same malicious functions. Some illegitimate apps have been downloaded thousands of times, Bitdefender said, but many remain available on the Google Play Early Access store.</p><p>But the scam apps aren’t limited to games and casino apps. Bitdefender also saw numerous apps offering utility functions such as QR code scanners or PDF readers. In some circumstances, the exact same apps were listed multiple times by different developers - likely to expand the reach and maximize the number of downloads.</p><p>Bitdefender notes that Google Play’s reputation relies on users being able to trust the apps they are downloading, but the Early Access program removes almost every way users can detect a malicious app before installing.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Americans might say they have ‘nothing to hide’, but many wouldn’t hand over access to their phone — even for $1 million ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>New Incogni research has found that the privacy preferences of Americans don't really align with what they say</strong></li><li><strong>Many of those with 'nothing to hide' will happily snoop on the phones of their family members and partners</strong></li><li><strong>But those same people tend to get twitchy when handing over their phone to strangers, or their data to the government</strong></li></ul><p>A new survey by <a href="https://blog.incogni.com/nothing-to-hide/" target="_blank" rel="nofollow">Incogni</a> has found almost half of Americans say they have ‘nothing to hide’ when it comes to their privacy, but almost immediately change their perspective when it comes to strangers looking at their phone - or sharing their private messages with the federal government.</p><p>Even when offered substantial sums of money, many of those with nothing to hide still wouldn’t hand over their devices, and their personal habits such as covering cameras or installing privacy screens show a level of contradiction in what they say, and how they behave.</p><p>Of those surveyed as part of Incogni’s research, Gen Z were the most likely to say they had nothing to hide at 57%, whereas just 26% of Baby Boomers offered the same response.</p><h2 id="americans-don-39-t-want-strangers-or-the-government-accessing-their-phones">Americans don't want strangers or the government accessing their phones</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:67.58%;"><img id="DxvVsdKESUyvXYqtH4mLr6" name="almost_half_of_respondents_say_they_have_nothing_to_hide" alt="Incogni graphs showing the privacy habits of Americans" src="https://cdn.mos.cms.futurecdn.net/DxvVsdKESUyvXYqtH4mLr6-1920-80.jpg" mos="" align="middle" fullscreen="" width="1024" height="692" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>As it turns out, those who fell into the 45% of respondents who said they had nothing to hide were more likely to snoop on other people's devices. In fact, when polled on whether they looked at other people’s devices in public, people with nothing to hide were double as likely (42%) to snoop compared to their something to hide counterparts (27%).</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:54.49%;"><img id="UNYyBhcux8EgJxyASotBq6" name="snooping_on_personal_communications_in_public_is_common_and_uncomfortable" alt="Incogni graphs showing the privacy habits of Americans" src="https://cdn.mos.cms.futurecdn.net/UNYyBhcux8EgJxyASotBq6-1920-80.jpg" mos="" align="middle" fullscreen="" width="1024" height="558" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>Those with nothing to hide were also more likely to look through the phones of their partners and family members without permission. In fact, 41% who fell into this category admitted to snooping on their partners phones, and 35% had looked through their family members' phones.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:53.71%;"><img id="dQCyx9mtsgBkGNHoK2pFp6" name="privacy_between_partners_and_family_members" alt="Incogni graphs showing the privacy habits of Americans" src="https://cdn.mos.cms.futurecdn.net/dQCyx9mtsgBkGNHoK2pFp6-1920-80.jpg" mos="" align="middle" fullscreen="" width="1024" height="550" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>Despite claiming to have nothing to hide, 39% still covered their cameras with tape, stickers, or sliding covers - especially those of Gen Z.  Over a quarter of respondents also said that they deliberately obscure their personal information when signing up to online services with fake names, false dates of birth, and masked emails.</p><p>But the most interesting data comes from paying for privacy. 41% of those who said they have nothing to hide would pay more for a product if it was better for their privacy. But when offered money in return for handing over their phone to a stranger, 60% of respondents refused any amount of money. 20% said it would take an amount of $1 million or more, and just 6% offered access for $100 or less.</p><p>When breaking these numbers down by group, 58% of those with nothing to hide would not let a stranger access their unlocked phone for any amount of money. </p><p>Even when offered three months of their salary, just 26% of respondents would hand over their SMS, chat-app, and email messages with law enforcement. This number drops to 25% with Big Tech companies, 24% for local government, and a staggering 21% for the federal government.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:67.58%;"><img id="oQxABjdgPDKUFbUnpb5zn6" name="the_federal_government_is_the_least_likely_entity_to_be_able_to_buy_access_to_respondents_messages" alt="Incogni graphs showing the privacy habits of Americans" src="https://cdn.mos.cms.futurecdn.net/oQxABjdgPDKUFbUnpb5zn6-1920-80.jpg" mos="" align="middle" fullscreen="" width="1024" height="692" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>Incogni theorizes that those who said they have nothing to hide may be equating privacy with secretiveness and secretiveness with guilt. It may also be true that many people fail to see how their seemingly innocent data, such as an email address or phone number, should be kept private.</p><p>As numerous data breaches have shown, the leaking of such information can lead to phishing emails, scams, and general harassment or doxxing. Incogni says that people fail to see why this information should stay private, especially in an era when social media and the websites we use hoover up as much information as possible to be sold to advertisers and third-parties.</p><p>“The findings suggest that the “nothing to hide” argument may therefore say less about how much people actually value privacy than about how difficult it is to see the consequences of losing it,” the report concludes.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/americans-might-say-they-have-nothing-to-hide-but-many-wouldnt-hand-over-access-to-their-phone-even-for-usd1-million</link>
                                                                            <description>
                            <![CDATA[ Incogni report finds those with 'nothing to hide' are more likely to snoop on the phones of their friends and family ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8R28SRiarorCFJ98nW5bfK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fdDmNCiwDdWg97kGfisHbA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 12:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fdDmNCiwDdWg97kGfisHbA-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Large blue eyeball watching businesswoman working at computer]]></media:description>                                                            <media:text><![CDATA[Large blue eyeball watching businesswoman working at computer]]></media:text>
                                <media:title type="plain"><![CDATA[Large blue eyeball watching businesswoman working at computer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fdDmNCiwDdWg97kGfisHbA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>New Incogni research has found that the privacy preferences of Americans don't really align with what they say</strong></li><li><strong>Many of those with 'nothing to hide' will happily snoop on the phones of their family members and partners</strong></li><li><strong>But those same people tend to get twitchy when handing over their phone to strangers, or their data to the government</strong></li></ul><p>A new survey by <a href="https://blog.incogni.com/nothing-to-hide/" target="_blank" rel="nofollow">Incogni</a> has found almost half of Americans say they have ‘nothing to hide’ when it comes to their privacy, but almost immediately change their perspective when it comes to strangers looking at their phone - or sharing their private messages with the federal government.</p><p>Even when offered substantial sums of money, many of those with nothing to hide still wouldn’t hand over their devices, and their personal habits such as covering cameras or installing privacy screens show a level of contradiction in what they say, and how they behave.</p><p>Of those surveyed as part of Incogni’s research, Gen Z were the most likely to say they had nothing to hide at 57%, whereas just 26% of Baby Boomers offered the same response.</p><h2 id="americans-don-39-t-want-strangers-or-the-government-accessing-their-phones">Americans don't want strangers or the government accessing their phones</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:67.58%;"><img id="DxvVsdKESUyvXYqtH4mLr6" name="almost_half_of_respondents_say_they_have_nothing_to_hide" alt="Incogni graphs showing the privacy habits of Americans" src="https://cdn.mos.cms.futurecdn.net/DxvVsdKESUyvXYqtH4mLr6-1920-80.jpg" mos="" align="middle" fullscreen="" width="1024" height="692" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>As it turns out, those who fell into the 45% of respondents who said they had nothing to hide were more likely to snoop on other people's devices. In fact, when polled on whether they looked at other people’s devices in public, people with nothing to hide were double as likely (42%) to snoop compared to their something to hide counterparts (27%).</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:54.49%;"><img id="UNYyBhcux8EgJxyASotBq6" name="snooping_on_personal_communications_in_public_is_common_and_uncomfortable" alt="Incogni graphs showing the privacy habits of Americans" src="https://cdn.mos.cms.futurecdn.net/UNYyBhcux8EgJxyASotBq6-1920-80.jpg" mos="" align="middle" fullscreen="" width="1024" height="558" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>Those with nothing to hide were also more likely to look through the phones of their partners and family members without permission. In fact, 41% who fell into this category admitted to snooping on their partners phones, and 35% had looked through their family members' phones.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:53.71%;"><img id="dQCyx9mtsgBkGNHoK2pFp6" name="privacy_between_partners_and_family_members" alt="Incogni graphs showing the privacy habits of Americans" src="https://cdn.mos.cms.futurecdn.net/dQCyx9mtsgBkGNHoK2pFp6-1920-80.jpg" mos="" align="middle" fullscreen="" width="1024" height="550" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>Despite claiming to have nothing to hide, 39% still covered their cameras with tape, stickers, or sliding covers - especially those of Gen Z.  Over a quarter of respondents also said that they deliberately obscure their personal information when signing up to online services with fake names, false dates of birth, and masked emails.</p><p>But the most interesting data comes from paying for privacy. 41% of those who said they have nothing to hide would pay more for a product if it was better for their privacy. But when offered money in return for handing over their phone to a stranger, 60% of respondents refused any amount of money. 20% said it would take an amount of $1 million or more, and just 6% offered access for $100 or less.</p><p>When breaking these numbers down by group, 58% of those with nothing to hide would not let a stranger access their unlocked phone for any amount of money. </p><p>Even when offered three months of their salary, just 26% of respondents would hand over their SMS, chat-app, and email messages with law enforcement. This number drops to 25% with Big Tech companies, 24% for local government, and a staggering 21% for the federal government.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:67.58%;"><img id="oQxABjdgPDKUFbUnpb5zn6" name="the_federal_government_is_the_least_likely_entity_to_be_able_to_buy_access_to_respondents_messages" alt="Incogni graphs showing the privacy habits of Americans" src="https://cdn.mos.cms.futurecdn.net/oQxABjdgPDKUFbUnpb5zn6-1920-80.jpg" mos="" align="middle" fullscreen="" width="1024" height="692" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>Incogni theorizes that those who said they have nothing to hide may be equating privacy with secretiveness and secretiveness with guilt. It may also be true that many people fail to see how their seemingly innocent data, such as an email address or phone number, should be kept private.</p><p>As numerous data breaches have shown, the leaking of such information can lead to phishing emails, scams, and general harassment or doxxing. Incogni says that people fail to see why this information should stay private, especially in an era when social media and the websites we use hoover up as much information as possible to be sold to advertisers and third-parties.</p><p>“The findings suggest that the “nothing to hide” argument may therefore say less about how much people actually value privacy than about how difficult it is to see the consequences of losing it,” the report concludes.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI’s overlooked storage opportunity ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The AI <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> discussion is typically framed around the cost of data centers, the power requirements, and the compute needed to train and run models, including <a href="https://www.techradar.com/news/computing-components/graphics-cards/best-graphics-cards-1291458">GPUs</a> and high-performance storage. That’s hardly surprising given the eye-watering investment numbers occupying the headlines.</p><p>The other key commodity, of course, is data to fuel those models. According to Stanford University’s 2025 AI Index Report, dataset sizes for training LLMs are doubling every eight months. In practical terms, as each model is built, some data will move quickly into curation and model-development environments, where fast access is essential.</p><p>Much of it, however, will wait longer while teams establish its relevance to a particular AI use case – not sitting idle, but held securely and ready to move quickly into curation, training and transformation pipelines when needed.  </p><p>From a <a href="https://www.techradar.com/best/best-cloud-document-storage">storage</a> perspective, this raises a point that is easy to overlook: a dataset does not need the same performance at every stage of the AI pipeline. What matters is that it is ready when it is needed – not that it sits on always-on, high-performance infrastructure throughout, which at scale becomes unnecessarily expensive.</p><p>The question for infrastructure planners, then, is not whether AI needs fast storage, but where organizations should keep the very large datasets that will be required in future, before they are ready to be processed. That choice is a strategic one, not a housekeeping one.</p><p>The right capacity tier should keep data protected and readily recoverable into AI, training and transformation pipelines, puts performance only where the work is actually happening, and returns the difference to the budget.  </p><h2 id="your-data-portfolio-as-strategic-advantage">Your data portfolio as strategic advantage </h2><p>As every organization's mission is different, so too each will be at a different stage of the AI journey. Some have raced ahead with systems already in production, while many others continue to explore how the data they already hold could support AI initiatives – <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a>, images and video, operational records, information collected through connected systems; the list goes on.</p><p>This is why knowing your own data is fast becoming a competitive lever rather than an IT chore. Models are available to everyone, so proprietary <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> is your competitive advantage – if you can access it and use it at scale.</p><p>The organizations that will move fastest are the ones that already know what they hold, where it sits, and how quickly it can be put to work. Shortening the distance between a business question and the data that answers it is now a measure of how fast a company can execute and succeed.</p><p>So data is not simply an input to AI: it is what shapes the model. The more of an organization's own data it can bring to bear, the sharper and more specific the resulting tools become, which is why the working assumption should be that almost anything the business holds is potentially useful.</p><p>The conventional approach has been to hold large datasets in a disk-based data lake until they are needed for further processing. Yet as data sets grow ever larger, so too could cost. If every candidate dataset has to live on always-on, high-performance infrastructure, cost sets the ceiling on how much data an organization can afford to keep in play at all.</p><p>The challenge, then, is to keep everything available to workflows as needed, so that the deciding factor is the use case, not the storage bill. </p><h2 id="tale-of-the-tape">Tale of the tape </h2><p>The smart play therefore is not to spend more, but to stop overspending where there is a better way. And it turns out one of the strongest answers here is a technology that has never stopped innovating: tape. Most people still associate it with <a href="https://www.techradar.com/best/best-backup-software">backup</a> and long-term archive – a role it continues to play well – but successive LTO generations have transformed its capacity, throughput and <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> while the industry looked elsewhere.</p><p>The latest tape technology and systems now behave like any other tier in the stack, ready to stream data into fast storage when curation or training is ready for it. And tape’s economics get better as it grows. At the multi-petabyte scale AI programs now reach, cost per terabyte is a fraction of flash or even HDD infrastructure. Performance and capacity can also scale independently, adding more drives for throughput and more cartridges for capacity.</p><p>When considered with tape’s extraordinary energy efficiency, this storage technology emerges as a strategic capability to build into the data center, allowing an organization to keep its entire data estate in play, at a cost that scales predictably.  </p><h2 id="a-safer-place-for-valuable-data">A safer place for valuable data </h2><p>Cost of storage and operation often gets projects approved, yet protection is the one that keeps people up at night. Here, tape offers something the online tiers structurally cannot. Encryption is handled in hardware on the cartridge. Write-Once-Read-Many (WORM) media makes a dataset immutable in the physical sense, so that irreplaceable data cannot be rewritten.</p><p>And for the most valuable material, tape sets can leave the library altogether and be stored in a secure location or offsite – fully offline, fully air-gapped, and insulated from anything that happens to the production environment.   </p><p>What counts now in building data and AI pipelines for your organization is ensuring data is ready to move into the right performance tier the moment it is needed. Data is the fuel for the models an organization builds, the decisions it makes, and how fast it can act on either.</p><p>Tape is what makes it affordable to keep all of that ‘data fuel’ at scale, protect what cannot be replaced, and put any of it to work on demand. Build it in now, and what you can do with your data is no longer limited by what you can afford to keep online, and instead becomes the means to get, and stay, ahead of your competition.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-storage&quot"><em>We've featured the best cloud storage.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ais-overlooked-storage-opportunity</link>
                                                                            <description>
                            <![CDATA[ AI success depends on keeping more data accessible, protected, and affordable at scale. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FDhxNwHnRKpPimcC2vJena</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YoQ7bF6XQjs33SMa72NcwK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 09:12:33 +0000</pubDate>                                                                                                                                <updated>Fri, 11 Sep 2026 14:59:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Skip Levens ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YoQ7bF6XQjs33SMa72NcwK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Light blue folders from a computer operating system on a dark blue background]]></media:description>                                                            <media:text><![CDATA[Light blue folders from a computer operating system on a dark blue background]]></media:text>
                                <media:title type="plain"><![CDATA[Light blue folders from a computer operating system on a dark blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YoQ7bF6XQjs33SMa72NcwK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The AI <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> discussion is typically framed around the cost of data centers, the power requirements, and the compute needed to train and run models, including <a href="https://www.techradar.com/news/computing-components/graphics-cards/best-graphics-cards-1291458">GPUs</a> and high-performance storage. That’s hardly surprising given the eye-watering investment numbers occupying the headlines.</p><p>The other key commodity, of course, is data to fuel those models. According to Stanford University’s 2025 AI Index Report, dataset sizes for training LLMs are doubling every eight months. In practical terms, as each model is built, some data will move quickly into curation and model-development environments, where fast access is essential.</p><p>Much of it, however, will wait longer while teams establish its relevance to a particular AI use case – not sitting idle, but held securely and ready to move quickly into curation, training and transformation pipelines when needed.  </p><p>From a <a href="https://www.techradar.com/best/best-cloud-document-storage">storage</a> perspective, this raises a point that is easy to overlook: a dataset does not need the same performance at every stage of the AI pipeline. What matters is that it is ready when it is needed – not that it sits on always-on, high-performance infrastructure throughout, which at scale becomes unnecessarily expensive.</p><p>The question for infrastructure planners, then, is not whether AI needs fast storage, but where organizations should keep the very large datasets that will be required in future, before they are ready to be processed. That choice is a strategic one, not a housekeeping one.</p><p>The right capacity tier should keep data protected and readily recoverable into AI, training and transformation pipelines, puts performance only where the work is actually happening, and returns the difference to the budget.  </p><h2 id="your-data-portfolio-as-strategic-advantage">Your data portfolio as strategic advantage </h2><p>As every organization's mission is different, so too each will be at a different stage of the AI journey. Some have raced ahead with systems already in production, while many others continue to explore how the data they already hold could support AI initiatives – <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a>, images and video, operational records, information collected through connected systems; the list goes on.</p><p>This is why knowing your own data is fast becoming a competitive lever rather than an IT chore. Models are available to everyone, so proprietary <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> is your competitive advantage – if you can access it and use it at scale.</p><p>The organizations that will move fastest are the ones that already know what they hold, where it sits, and how quickly it can be put to work. Shortening the distance between a business question and the data that answers it is now a measure of how fast a company can execute and succeed.</p><p>So data is not simply an input to AI: it is what shapes the model. The more of an organization's own data it can bring to bear, the sharper and more specific the resulting tools become, which is why the working assumption should be that almost anything the business holds is potentially useful.</p><p>The conventional approach has been to hold large datasets in a disk-based data lake until they are needed for further processing. Yet as data sets grow ever larger, so too could cost. If every candidate dataset has to live on always-on, high-performance infrastructure, cost sets the ceiling on how much data an organization can afford to keep in play at all.</p><p>The challenge, then, is to keep everything available to workflows as needed, so that the deciding factor is the use case, not the storage bill. </p><h2 id="tale-of-the-tape">Tale of the tape </h2><p>The smart play therefore is not to spend more, but to stop overspending where there is a better way. And it turns out one of the strongest answers here is a technology that has never stopped innovating: tape. Most people still associate it with <a href="https://www.techradar.com/best/best-backup-software">backup</a> and long-term archive – a role it continues to play well – but successive LTO generations have transformed its capacity, throughput and <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> while the industry looked elsewhere.</p><p>The latest tape technology and systems now behave like any other tier in the stack, ready to stream data into fast storage when curation or training is ready for it. And tape’s economics get better as it grows. At the multi-petabyte scale AI programs now reach, cost per terabyte is a fraction of flash or even HDD infrastructure. Performance and capacity can also scale independently, adding more drives for throughput and more cartridges for capacity.</p><p>When considered with tape’s extraordinary energy efficiency, this storage technology emerges as a strategic capability to build into the data center, allowing an organization to keep its entire data estate in play, at a cost that scales predictably.  </p><h2 id="a-safer-place-for-valuable-data">A safer place for valuable data </h2><p>Cost of storage and operation often gets projects approved, yet protection is the one that keeps people up at night. Here, tape offers something the online tiers structurally cannot. Encryption is handled in hardware on the cartridge. Write-Once-Read-Many (WORM) media makes a dataset immutable in the physical sense, so that irreplaceable data cannot be rewritten.</p><p>And for the most valuable material, tape sets can leave the library altogether and be stored in a secure location or offsite – fully offline, fully air-gapped, and insulated from anything that happens to the production environment.   </p><p>What counts now in building data and AI pipelines for your organization is ensuring data is ready to move into the right performance tier the moment it is needed. Data is the fuel for the models an organization builds, the decisions it makes, and how fast it can act on either.</p><p>Tape is what makes it affordable to keep all of that ‘data fuel’ at scale, protect what cannot be replaced, and put any of it to work on demand. Build it in now, and what you can do with your data is no longer limited by what you can afford to keep online, and instead becomes the means to get, and stay, ahead of your competition.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-storage&quot"><em>We've featured the best cloud storage.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts build WeChat worm able to spread across millions of iPhone and Android devices via phone calls ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Calif researchers found a zero‑click WeChat VoIP flaw enabling account takeover via calls</strong></li><li><strong>“WeWorm” spreads through ringing calls; victims need not answer to be compromised</strong></li><li><strong>Tencent patched in Android 8.0.77 and iOS 8.0.76; no exploitation seen in the wild</strong></li></ul><p>Security researchers have found a flaw in WeChat which allows malicious actors to take over people’s accounts on both Android and iOS devices - but what makes this flaw stand out is the fact that it’s a zero-click bug - victims need not do a thing to be compromised.</p><p>WeChat is a “super-app”, allegedly used by roughly 1.4 billion people, and is especially popular in China. It started as a communications app, letting users send messages, and make voice and video calls, and has evolved to function as a social network, allowing users to share photos and videos, as well as a payment app through which users can transfer money, pay for things, order food, book taxis, and even access government and business services.</p><p>Security researchers from Calif have now <a href="https://calif.io/research/weworm" target="_blank" rel="nofollow">disclosed</a> finding a ‘memory corruption’ issue in WeChat's VoIP stack. For now, they decided not to share the technical details, and to instead demonstrate the flaw “at an upcoming conference.” To that end, they built a worm called WeWorm, capable of taking over target WeChat accounts and spread through phone calls made via the app. </p><h2 id="a-phone-call-would-suffice">A phone call would suffice</h2><p>In practice, it works remarkably simple: an attacker uses WeChat to call a person they have in their contacts list (this is a prerequisite). They can use both an Android and an iOS device, and can call anyone, regardless of the model or the OS they’re using. As soon as the phone starts ringing, WeWorm gets to work, “worming” its way into the victim’s device.</p><p>The victim does not even need to answer the phone - having it ring is enough. If they answer, they’ll hear nothing but silence, yet the worm will continue operating. If they decline the call, the attack stops, but this is hardly a mitigation - the attacker can simply call again while the victim is asleep (or otherwise away from their device).</p><p>Within a few seconds, the attacker will have access to the victim’s WeChat account, including their messages, contacts list, and virtually anything else found in the app. What makes this bug particularly worrisome on the surface is the fact that WeChat can be used to transfer money and pay for things, but WeChat Pay has additional authentication and risk controls designed to prevent that from happening. </p><p>The good news is that there is no evidence of this flaw being exploited in the wild. The bad news is that this is not the first zero-click flaw found in modern-day smartphones, and most likely will not be the last one.</p><h2 id="tencent-39-s-response">Tencent's response</h2><p>Calif said it responsibly disclosed its findings to WeChat’s parent company Tencent, who came back with a patch. Versions 8.0.77 for Android and 8.0.76 for iOS have apparently solved the problem, although </p><p>Tencent did not list any details in its patch notes, simply saying the version brought “bug fixes”, but in a statement shared with <a href="https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html" target="_blank"><em>The Hacker News</em></a>, it said the exploit has been “mitigated for all users”, and that it was applied server-side - users need not install anything, aside from the patch. </p><p>It’s also worth mentioning that WeChat has apps for HarmonyOS, Windows, Mac, and Linux. However, it would appear that Calif did not test those, and Tencent did not include them in its patch. The researchers did say that they would be looking into this same flaw in other products, too: </p><p>“This specific WeChat bug is one instance of the many unconventional attack surfaces that are present across many messaging apps,” they said. “We're conducting more of this research across other apps and attack surfaces, while working with app developers on attack surface reduction. This may take an industry-wide effort, since some of it depends on the platform owners. Once that work is further along, we'll share our progress, including the technical details of this WeChat bug.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-build-wechat-worm-able-to-spread-across-millions-of-iphone-and-android-devices-via-phone-calls</link>
                                                                            <description>
                            <![CDATA[ Your phone rings, and you're infected - with all of your contacts and messages exposed. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">L2NUxfetWUexVX4yvWWxJe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2yHEj7RR9QpUSvzcPym7Vf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 01:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2yHEj7RR9QpUSvzcPym7Vf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Angry man shouting at mobile phone while sitting at a desk]]></media:description>                                                            <media:text><![CDATA[Angry man shouting at mobile phone while sitting at a desk]]></media:text>
                                <media:title type="plain"><![CDATA[Angry man shouting at mobile phone while sitting at a desk]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2yHEj7RR9QpUSvzcPym7Vf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Calif researchers found a zero‑click WeChat VoIP flaw enabling account takeover via calls</strong></li><li><strong>“WeWorm” spreads through ringing calls; victims need not answer to be compromised</strong></li><li><strong>Tencent patched in Android 8.0.77 and iOS 8.0.76; no exploitation seen in the wild</strong></li></ul><p>Security researchers have found a flaw in WeChat which allows malicious actors to take over people’s accounts on both Android and iOS devices - but what makes this flaw stand out is the fact that it’s a zero-click bug - victims need not do a thing to be compromised.</p><p>WeChat is a “super-app”, allegedly used by roughly 1.4 billion people, and is especially popular in China. It started as a communications app, letting users send messages, and make voice and video calls, and has evolved to function as a social network, allowing users to share photos and videos, as well as a payment app through which users can transfer money, pay for things, order food, book taxis, and even access government and business services.</p><p>Security researchers from Calif have now <a href="https://calif.io/research/weworm" target="_blank" rel="nofollow">disclosed</a> finding a ‘memory corruption’ issue in WeChat's VoIP stack. For now, they decided not to share the technical details, and to instead demonstrate the flaw “at an upcoming conference.” To that end, they built a worm called WeWorm, capable of taking over target WeChat accounts and spread through phone calls made via the app. </p><h2 id="a-phone-call-would-suffice">A phone call would suffice</h2><p>In practice, it works remarkably simple: an attacker uses WeChat to call a person they have in their contacts list (this is a prerequisite). They can use both an Android and an iOS device, and can call anyone, regardless of the model or the OS they’re using. As soon as the phone starts ringing, WeWorm gets to work, “worming” its way into the victim’s device.</p><p>The victim does not even need to answer the phone - having it ring is enough. If they answer, they’ll hear nothing but silence, yet the worm will continue operating. If they decline the call, the attack stops, but this is hardly a mitigation - the attacker can simply call again while the victim is asleep (or otherwise away from their device).</p><p>Within a few seconds, the attacker will have access to the victim’s WeChat account, including their messages, contacts list, and virtually anything else found in the app. What makes this bug particularly worrisome on the surface is the fact that WeChat can be used to transfer money and pay for things, but WeChat Pay has additional authentication and risk controls designed to prevent that from happening. </p><p>The good news is that there is no evidence of this flaw being exploited in the wild. The bad news is that this is not the first zero-click flaw found in modern-day smartphones, and most likely will not be the last one.</p><h2 id="tencent-39-s-response">Tencent's response</h2><p>Calif said it responsibly disclosed its findings to WeChat’s parent company Tencent, who came back with a patch. Versions 8.0.77 for Android and 8.0.76 for iOS have apparently solved the problem, although </p><p>Tencent did not list any details in its patch notes, simply saying the version brought “bug fixes”, but in a statement shared with <a href="https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html" target="_blank"><em>The Hacker News</em></a>, it said the exploit has been “mitigated for all users”, and that it was applied server-side - users need not install anything, aside from the patch. </p><p>It’s also worth mentioning that WeChat has apps for HarmonyOS, Windows, Mac, and Linux. However, it would appear that Calif did not test those, and Tencent did not include them in its patch. The researchers did say that they would be looking into this same flaw in other products, too: </p><p>“This specific WeChat bug is one instance of the many unconventional attack surfaces that are present across many messaging apps,” they said. “We're conducting more of this research across other apps and attack surfaces, while working with app developers on attack surface reduction. This may take an industry-wide effort, since some of it depends on the platform owners. Once that work is further along, we'll share our progress, including the technical details of this WeChat bug.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft September 2026 Patch Tuesday fixes nearly a thousand flaws, including two major zero-days ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft has fixed no fewer than 974 vulnerabilities in its latest Patch Tuesday release</strong></li><li><strong>Two were already being exploited in the wild, 114 categorized as 'Critical'</strong></li><li><strong>AI is to blame for boosting CVE discovery and also intensifying attacks</strong></li></ul><p>Microsoft's September 2026 Patch Tuesday has become its biggest security release on record, with the company issuing fixes for a staggering 974 vulnerabilities across the entire stack.</p><p>According to the company's <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep" target="_blank">release notes</a>, an overwhelming majority (723) of the vulnerabilities addressed related to Windows, with Office coming in at second place with 111 of its own vulnerabilities being addressed.</p><p>While it's clear that the number of vulnerabilities is going up year-over-year, it's likely that the company was also simply able to find more of them that would otherwise have slipped through the net thanks to AI-assisted discovery tools.</p><h2 id="this-is-microsoft-39-s-biggest-patch-tuesday-ever">This is Microsoft's biggest Patch Tuesday ever</h2><p>Speaking about the September 2026 Patch Tuesday in a <a href="https://www.zerodayinitiative.com/blog/2026/9/8/the-september-2026-security-update-review" target="_blank">blog post</a>, Dustin Childs explains that this could be the start of the "new normal." Childs goes on to reveal that Microsoft has patched 2,760 CVEs this year to date – more than double any other year that precedes it.</p><p>Childs' figures show that the company patched 1,139 CVEs in the whole of 2025, and a much lower 492 a decade ago in 2016. According to the post, 114 of the vulnerabilities patched in this latest update were 'Critical' – more than one in 10.</p><p>In its own notes, Microsoft described CVE-2026-85880 and CVE-2026-81963 as especially notable because they're both being actively exploited, hence the push to get them fixed and for customers to install the update.</p><p>Elsewhere in the industry, Microsoft isn't the only company addressing a higher volume of bugs. Childs also highlighted high activity from Adobe, while a number of browser developers including Google, Mozilla, Brave and Microsoft itself have doubled the release cycle to two weeks in order to get fixes into customer hands more quickly.</p><p>Besides fixing exploitable bugs, Microsoft also used the opportunity to issue fixes to known issues – including fixing Teams and Outlook crashes on Arm64 PCs – as well as to upgrade Copilot+ AI components.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/microsoft-september-2026-patch-tuesday-fixes-nearly-a-thousand-flaws-including-two-major-zero-days</link>
                                                                            <description>
                            <![CDATA[ 2026 has been a record year for CVE fixes, but Microsoft just fixed nearly 1,000 of them in one single update. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2u3KcSqfipZXjvCguMVheP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yBsirNxrnuBxshrCgrFwsQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 16:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yBsirNxrnuBxshrCgrFwsQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock - Wachiwit]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Windows 10 Logo on Laptop]]></media:description>                                                            <media:text><![CDATA[Windows 10 Logo on Laptop]]></media:text>
                                <media:title type="plain"><![CDATA[Windows 10 Logo on Laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yBsirNxrnuBxshrCgrFwsQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft has fixed no fewer than 974 vulnerabilities in its latest Patch Tuesday release</strong></li><li><strong>Two were already being exploited in the wild, 114 categorized as 'Critical'</strong></li><li><strong>AI is to blame for boosting CVE discovery and also intensifying attacks</strong></li></ul><p>Microsoft's September 2026 Patch Tuesday has become its biggest security release on record, with the company issuing fixes for a staggering 974 vulnerabilities across the entire stack.</p><p>According to the company's <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep" target="_blank">release notes</a>, an overwhelming majority (723) of the vulnerabilities addressed related to Windows, with Office coming in at second place with 111 of its own vulnerabilities being addressed.</p><p>While it's clear that the number of vulnerabilities is going up year-over-year, it's likely that the company was also simply able to find more of them that would otherwise have slipped through the net thanks to AI-assisted discovery tools.</p><h2 id="this-is-microsoft-39-s-biggest-patch-tuesday-ever">This is Microsoft's biggest Patch Tuesday ever</h2><p>Speaking about the September 2026 Patch Tuesday in a <a href="https://www.zerodayinitiative.com/blog/2026/9/8/the-september-2026-security-update-review" target="_blank">blog post</a>, Dustin Childs explains that this could be the start of the "new normal." Childs goes on to reveal that Microsoft has patched 2,760 CVEs this year to date – more than double any other year that precedes it.</p><p>Childs' figures show that the company patched 1,139 CVEs in the whole of 2025, and a much lower 492 a decade ago in 2016. According to the post, 114 of the vulnerabilities patched in this latest update were 'Critical' – more than one in 10.</p><p>In its own notes, Microsoft described CVE-2026-85880 and CVE-2026-81963 as especially notable because they're both being actively exploited, hence the push to get them fixed and for customers to install the update.</p><p>Elsewhere in the industry, Microsoft isn't the only company addressing a higher volume of bugs. Childs also highlighted high activity from Adobe, while a number of browser developers including Google, Mozilla, Brave and Microsoft itself have doubled the release cycle to two weeks in order to get fixes into customer hands more quickly.</p><p>Besides fixing exploitable bugs, Microsoft also used the opportunity to issue fixes to known issues – including fixing Teams and Outlook crashes on Arm64 PCs – as well as to upgrade Copilot+ AI components.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI, NSA warn Chinese AI companies like DeepSeek and Alibaba are reportedly carrying out 'industrial-scale' distillation campaigns to boost their models ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CISA, NSA, FBI warn Chinese AI firms of industrial‑scale knowledge distillation</strong></li><li><strong>Companies like DeepSeek, Moonshot, Alibaba allegedly extracted billions of tokens from US frontier models</strong></li><li><strong>Advisory urges detection of malicious prompts, deceptive responses to distillation, and cross‑provider intelligence sharing</strong></li></ul><p>Chinese AI companies’ core development strategy is to steal proprietary functionalities and capabilities from their US counterparts, law enforcement agencies have warned.</p><p>The US Cybersecurity and Infrastructure Security Agency (CISA) has <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a" target="_blank" rel="nofollow">published</a> a new security advisory, drafted jointly with the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI), warning American <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI companies</a> about an ongoing “aggressive, malicious, and targeted distillation activities at an industrial scale,” and sharing recommended mitigation steps.</p><h2 id="knowledge-distillation">Knowledge distillation</h2><p>IBM defines knowledge distillation as a “machine learning technique that aims to transfer the learnings of a large pre-trained model, the ‘teacher model,’ to a smaller ‘student model’.” It is used in deep learning as a form of model compression and knowledge transfer, it added, particularly for massive deep neural networks. </p><p>So, knowledge distillation is not illegal or malicious, per se. Its goal is to train a more compact model to mimic a larger, more complex one. In the security advisory, the agencies stress it is “recognized as a legitimate and useful technique in AI research,” but add that China-based AI companies are using it in ill will. </p><p>In other words, the agencies claim that instead of spending months and millions developing new capabilities for their models, the Chinese are simply sending huge numbers of carefully designed questions to US models and extracting the answers.</p><h2 id="which-companies-are-engaged-in-knowledge-distillation">Which companies are engaged in knowledge distillation?</h2><p>Apparently, all companies worth anything. DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI all allegedly “extracted billions of tokens across millions of exchanges/requests from US frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024.” CISA also stressed that this was likely done with the awareness of the Chinese government. It hasn’t outright said, “with its blessing”, although it could be read between the lines. </p><p>The advisory shares a thorough list of all the models that were being trained, as well as all the models being taken advantage of. </p><p>On the Chinese side, they include DeepSeek R1 and V3 models, Moonshot’s Kimi-K2 and Kimi-K3 models, and MiniMax’s M2 model. On the US side, they start with earlier models such as GPT-4, Claude 3.7, and Gemini 2.5 Flash Preview, all the way to Claude Fable 5, GPT-5, and similar.</p><p>When done in good faith, knowledge distillation is not illegal. However, the report says the companies routed the requests through multiple accounts, different API access points, multiple cloud providers, third-party AI aggregators, proxy services and “transfer stations”, as well as premium subscriptions shared between developers, all in an attempt to work around defenders trying to disrupt the process.</p><p>“This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership. Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations,” the agencies concluded.</p><h2 id="what-us-companies-should-be-doing">What US companies should be doing</h2><p>To defend their intellectual property (and thus remain ahead of Chinese competing models) US AI companies should implement comprehensive detection and mitigation, the agencies said. That means hunting for anomalous and malicious prompts, accounts, networks, and behaviors. Furthermore, they should monitor subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns.</p><p>The second step is to “deploy targeted response changes”: “Subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs to companies conducting industrial-scale distillation campaigns.” In other words, AI companies should make sure their products lie when they spot they were being distilled for knowledge. </p><p>Finally, US AI firms should set up cross-organization intelligence sharing, correlating activity across model providers, cloud platforms, and API aggregators.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/fbi-nsa-warn-chinese-ai-companies-like-deepseek-and-alibaba-are-reportedly-carrying-out-industrial-scale-distillation-campaigns-to-boost-their-models</link>
                                                                            <description>
                            <![CDATA[ US AI companies should implement additional mitigations to curb these attempts, agencies warn. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8hYy6XQ59ei9aG8aoWsM4d</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cWc9CWu3UHCubh8PtKXmVS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cWc9CWu3UHCubh8PtKXmVS-1280-80.jpg">
                                                            <media:credit><![CDATA[OpenAI &amp; Google]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ChatGPT vs Gemini comparison]]></media:description>                                                            <media:text><![CDATA[ChatGPT vs Gemini comparison]]></media:text>
                                <media:title type="plain"><![CDATA[ChatGPT vs Gemini comparison]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cWc9CWu3UHCubh8PtKXmVS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CISA, NSA, FBI warn Chinese AI firms of industrial‑scale knowledge distillation</strong></li><li><strong>Companies like DeepSeek, Moonshot, Alibaba allegedly extracted billions of tokens from US frontier models</strong></li><li><strong>Advisory urges detection of malicious prompts, deceptive responses to distillation, and cross‑provider intelligence sharing</strong></li></ul><p>Chinese AI companies’ core development strategy is to steal proprietary functionalities and capabilities from their US counterparts, law enforcement agencies have warned.</p><p>The US Cybersecurity and Infrastructure Security Agency (CISA) has <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a" target="_blank" rel="nofollow">published</a> a new security advisory, drafted jointly with the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI), warning American <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI companies</a> about an ongoing “aggressive, malicious, and targeted distillation activities at an industrial scale,” and sharing recommended mitigation steps.</p><h2 id="knowledge-distillation">Knowledge distillation</h2><p>IBM defines knowledge distillation as a “machine learning technique that aims to transfer the learnings of a large pre-trained model, the ‘teacher model,’ to a smaller ‘student model’.” It is used in deep learning as a form of model compression and knowledge transfer, it added, particularly for massive deep neural networks. </p><p>So, knowledge distillation is not illegal or malicious, per se. Its goal is to train a more compact model to mimic a larger, more complex one. In the security advisory, the agencies stress it is “recognized as a legitimate and useful technique in AI research,” but add that China-based AI companies are using it in ill will. </p><p>In other words, the agencies claim that instead of spending months and millions developing new capabilities for their models, the Chinese are simply sending huge numbers of carefully designed questions to US models and extracting the answers.</p><h2 id="which-companies-are-engaged-in-knowledge-distillation">Which companies are engaged in knowledge distillation?</h2><p>Apparently, all companies worth anything. DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI all allegedly “extracted billions of tokens across millions of exchanges/requests from US frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024.” CISA also stressed that this was likely done with the awareness of the Chinese government. It hasn’t outright said, “with its blessing”, although it could be read between the lines. </p><p>The advisory shares a thorough list of all the models that were being trained, as well as all the models being taken advantage of. </p><p>On the Chinese side, they include DeepSeek R1 and V3 models, Moonshot’s Kimi-K2 and Kimi-K3 models, and MiniMax’s M2 model. On the US side, they start with earlier models such as GPT-4, Claude 3.7, and Gemini 2.5 Flash Preview, all the way to Claude Fable 5, GPT-5, and similar.</p><p>When done in good faith, knowledge distillation is not illegal. However, the report says the companies routed the requests through multiple accounts, different API access points, multiple cloud providers, third-party AI aggregators, proxy services and “transfer stations”, as well as premium subscriptions shared between developers, all in an attempt to work around defenders trying to disrupt the process.</p><p>“This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership. Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations,” the agencies concluded.</p><h2 id="what-us-companies-should-be-doing">What US companies should be doing</h2><p>To defend their intellectual property (and thus remain ahead of Chinese competing models) US AI companies should implement comprehensive detection and mitigation, the agencies said. That means hunting for anomalous and malicious prompts, accounts, networks, and behaviors. Furthermore, they should monitor subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns.</p><p>The second step is to “deploy targeted response changes”: “Subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs to companies conducting industrial-scale distillation campaigns.” In other words, AI companies should make sure their products lie when they spot they were being distilled for knowledge. </p><p>Finally, US AI firms should set up cross-organization intelligence sharing, correlating activity across model providers, cloud platforms, and API aggregators.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How AI is reshaping the economics of cyberattacks and defense ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The bottleneck on sophisticated cyber operations that target nation states is breaking. Conducting a large-scale cyber attack used to mean scaling expert talent. </p><p>When the cost of adding a capable attacker approaches the cost of compute, the economics of offense fundamentally change. </p><p>This is already operational: Dream's threat research recovered an autonomous multi-agent framework that ran intrusion campaigns against government entities in Asia, executing twelve attack waves in four days with eight parallel agents, compromising 85 government accounts, and using a closed learning loop to adapt after failure. </p><p>The advantage is shifting from the number of experts to how effectively their expertise can be scaled. </p><p>AI benefits both attackers and defenders, but defenders start with a unique advantage: they already own the map attackers must discover. </p><p>Defenders that understand their environment can use AI to turn that knowledge into operational scale.</p><h2 id="the-autonomous-ai-government-hacker">The Autonomous AI Government Hacker</h2><p>In July, our threat research team recovered the operational workspace of an autonomous multi-agent framework that had been conducting intrusion campaigns against government entities in Asia.</p><p>Over roughly four days, the framework executed twelve attack waves and ran up to eight AI agents in parallel. Built on the publicly available Hermes and OpenClaw frameworks, it compromised 85 government <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> accounts and used 84 of them to pivot through a government single sign-on environment.</p><p>What’s really intriguing is its autonomous operational decision making.</p><h2 id="assigning-confidence-scores">Assigning confidence scores</h2><p>Every discovery was assigned a Bayesian confidence score to assess different paths and then chose how to proceed, just like an actual team. </p><p>Similarly, when an attack path failed, the framework automatically entered what it called a Learning Cycle, searched vulnerability <a href="https://www.techradar.com/best/best-database-software">databases</a> and security research techniques relevant to that government's technology stack, and tried again. The framework audited itself – it created a closed learning loop: investigate, validate, act, observe the result, update its operational knowledge, and try again.</p><p>This was not a self-improving model. It was a self-adapting cyber attacker – there is a real expert behind it, embedded as AI system. The fundamentals of this attack weren’t even particularly impressive or novel. It is the scale – and the prospect for nearly infinite scale – that is daunting.</p><p>Until recently, one of the limiting factors in scaling sophisticated offensive operations was the expert reasoning required to decide what to investigate, validate findings, connect them into viable attack paths, and adapt when those paths failed. It was expensive, both in dollars and in expertise. That scarcity placed a natural constraint on offensive scale - scaling a sophisticated operation meant scaling skilled people, time and coordination.</p><p>AI is beginning to automate precisely that expensive layer of the operation: deciding what to investigate, validating hypotheses, learning from failure and choosing what to try next. Talent still determines the quality of those decisions. But the number of talented people no longer has to determine how many times those decisions can be made in parallel.</p><p>What happens when scaling an offensive operation no longer requires scaling the number of experts behind it at the same rate?</p><p>As someone who has spent 15 years in both offensive and defensive cyber roles, it’s becoming clearer every day that AI has changed that equation - the historical relationship between the amount of expert talent an organization has and the scale at which it can operate is beginning to break down. </p><p>AI does not eliminate talent - it changes what talent can scale.</p><h2 id="an-attack-surface-the-size-of-a-country">An Attack Surface the Size of a Country</h2><p>Government <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a> is an interconnected ecosystem built over decades. It consists of ministries, municipalities, operational technology, legacy applications, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a>, contractors, suppliers, and countless trust relationships connecting them together.</p><p>These connections typically exist for legitimate operational reasons (or at least historically legitimate reasons).</p><p>Of course, every connection is also a potential vulnerability.</p><p>This is how modern government attacks spread - not necessarily by exploiting one critical vulnerability, but by chaining together many ordinary ones.</p><p>Historically, this challenged both sides. No defensive team could continuously reason over every <a href="https://www.techradar.com/best/best-asset-management-software">asset</a>, identity, configuration, vulnerability and trust relationship across an entire country. But attackers faced a version of the same constraint. Their experts also had to decide where to spend their time to find a viable path from intrusion to crown jewel</p><p>Autonomous systems change that.</p><p>An autonomous attacker does not need to understand the entire government environment in advance. It can explore it continuously: discover a relationship, form a hypothesis, test it, learn from the result and move to the next one.</p><p>For the first time, governments may face adversaries capable of reasoning over national-scale attack surfaces faster than the institutions responsible for defending them.</p><h2 id="the-race-to-change-the-outcome">The Race to Change the Outcome</h2><p>The dramatic decline in the cost of offensive cyber expertise, via leveraging and weaponizing agents, is a tectonic shift. Until now, this was a skill limited to a select few and came with a high price tag.</p><p>Today,  discovering, prioritizing and combining these techniques into viable attack paths is cheap, and one can repeat the process at machine speed.</p><p>With the pace of AI development, that statement becomes more true every day.</p><p>Offensive capability is becoming cheaper, faster and easier to reproduce.</p><p>But there is another side to this equation.</p><p>Defenders have always had structural advantages: more telemetry, deeper context, persistent access to their infrastructure, and knowledge of its configurations, identities and relationships, while also have a much better ability to act.</p><p>They too had the constraint of human capacity. No team could continuously reason over all that information, across every asset and relationship, all the time. The same AI that benefits attackers may operationalize defender’s historical edge at scale too.</p><p>This is where time plays a key role. Analyzing everything is not the same as defending everything. If AI detects a compromised identity in seconds but the credential remains active for six hours, the attacker still has six hours. If it identifies an exploitable path to a critical system but remediation takes three weeks, that path remains open for three weeks.</p><p>The opportunity, then, is not simply better analysis. It is reducing time-to-effective-action: the time between understanding a risk and changing the outcome.</p><p>And "effective" matters- disabling an <a href="https://www.techradar.com/best/best-identity-management-software">identity</a>, changing a <a href="https://www.techradar.com/best/firewall">firewall</a> rule or patching a vulnerability is not enough. The system must verify that the attacker can no longer achieve its objective.</p><p>The defensive loop cannot end with intelligence - or even with action. It has to end with a verified <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> outcome.</p><h2 id="the-gap-that-matters">The Gap That Matters </h2><p>AI does not inevitably favor the attacker.</p><p>The framework we recovered had to steal its map of the environment, one probe at a time. Defenders already have that map. Every configuration, credential, telemetry stream and trust relationship could take an attacker – even an AI attacker – days to weeks to discover. What defenders could never do was reason over all the assets they had, continuously, due to the lack of talent capacity to do that.</p><p>AI begins to remove that human-attention constraint. It allows defenders to amplify expert talent across thousands of investigations in parallel, continuously identifying attack paths, prioritizing those that pose the greatest risk, and focusing action where it matters most.</p><p>Attackers get the same leverage. But they don't start from the same place. Defenders have a home-field advantage: they already know and control the environment the attacker must discover.</p><p>The gap that matters is no longer simply the number of experts on either side. It is how effectively each side can scale that expertise- and direct it toward the right risks first.</p><p>Ultimately, the race is not about who can know more.</p><p>It is about who can scale talent in the right way- and turn that scale into an outcome first.</p><p><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software available</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/how-ai-is-reshaping-the-economics-of-cyberattacks-and-defense</link>
                                                                            <description>
                            <![CDATA[ AI is scaling cyberattacks, forcing defenders to rethink how they respond and act. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">h3bvuUgubs3BjpD7WSUB7m</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 14:07:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kfir Fleischer ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The bottleneck on sophisticated cyber operations that target nation states is breaking. Conducting a large-scale cyber attack used to mean scaling expert talent. </p><p>When the cost of adding a capable attacker approaches the cost of compute, the economics of offense fundamentally change. </p><p>This is already operational: Dream's threat research recovered an autonomous multi-agent framework that ran intrusion campaigns against government entities in Asia, executing twelve attack waves in four days with eight parallel agents, compromising 85 government accounts, and using a closed learning loop to adapt after failure. </p><p>The advantage is shifting from the number of experts to how effectively their expertise can be scaled. </p><p>AI benefits both attackers and defenders, but defenders start with a unique advantage: they already own the map attackers must discover. </p><p>Defenders that understand their environment can use AI to turn that knowledge into operational scale.</p><h2 id="the-autonomous-ai-government-hacker">The Autonomous AI Government Hacker</h2><p>In July, our threat research team recovered the operational workspace of an autonomous multi-agent framework that had been conducting intrusion campaigns against government entities in Asia.</p><p>Over roughly four days, the framework executed twelve attack waves and ran up to eight AI agents in parallel. Built on the publicly available Hermes and OpenClaw frameworks, it compromised 85 government <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> accounts and used 84 of them to pivot through a government single sign-on environment.</p><p>What’s really intriguing is its autonomous operational decision making.</p><h2 id="assigning-confidence-scores">Assigning confidence scores</h2><p>Every discovery was assigned a Bayesian confidence score to assess different paths and then chose how to proceed, just like an actual team. </p><p>Similarly, when an attack path failed, the framework automatically entered what it called a Learning Cycle, searched vulnerability <a href="https://www.techradar.com/best/best-database-software">databases</a> and security research techniques relevant to that government's technology stack, and tried again. The framework audited itself – it created a closed learning loop: investigate, validate, act, observe the result, update its operational knowledge, and try again.</p><p>This was not a self-improving model. It was a self-adapting cyber attacker – there is a real expert behind it, embedded as AI system. The fundamentals of this attack weren’t even particularly impressive or novel. It is the scale – and the prospect for nearly infinite scale – that is daunting.</p><p>Until recently, one of the limiting factors in scaling sophisticated offensive operations was the expert reasoning required to decide what to investigate, validate findings, connect them into viable attack paths, and adapt when those paths failed. It was expensive, both in dollars and in expertise. That scarcity placed a natural constraint on offensive scale - scaling a sophisticated operation meant scaling skilled people, time and coordination.</p><p>AI is beginning to automate precisely that expensive layer of the operation: deciding what to investigate, validating hypotheses, learning from failure and choosing what to try next. Talent still determines the quality of those decisions. But the number of talented people no longer has to determine how many times those decisions can be made in parallel.</p><p>What happens when scaling an offensive operation no longer requires scaling the number of experts behind it at the same rate?</p><p>As someone who has spent 15 years in both offensive and defensive cyber roles, it’s becoming clearer every day that AI has changed that equation - the historical relationship between the amount of expert talent an organization has and the scale at which it can operate is beginning to break down. </p><p>AI does not eliminate talent - it changes what talent can scale.</p><h2 id="an-attack-surface-the-size-of-a-country">An Attack Surface the Size of a Country</h2><p>Government <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a> is an interconnected ecosystem built over decades. It consists of ministries, municipalities, operational technology, legacy applications, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a>, contractors, suppliers, and countless trust relationships connecting them together.</p><p>These connections typically exist for legitimate operational reasons (or at least historically legitimate reasons).</p><p>Of course, every connection is also a potential vulnerability.</p><p>This is how modern government attacks spread - not necessarily by exploiting one critical vulnerability, but by chaining together many ordinary ones.</p><p>Historically, this challenged both sides. No defensive team could continuously reason over every <a href="https://www.techradar.com/best/best-asset-management-software">asset</a>, identity, configuration, vulnerability and trust relationship across an entire country. But attackers faced a version of the same constraint. Their experts also had to decide where to spend their time to find a viable path from intrusion to crown jewel</p><p>Autonomous systems change that.</p><p>An autonomous attacker does not need to understand the entire government environment in advance. It can explore it continuously: discover a relationship, form a hypothesis, test it, learn from the result and move to the next one.</p><p>For the first time, governments may face adversaries capable of reasoning over national-scale attack surfaces faster than the institutions responsible for defending them.</p><h2 id="the-race-to-change-the-outcome">The Race to Change the Outcome</h2><p>The dramatic decline in the cost of offensive cyber expertise, via leveraging and weaponizing agents, is a tectonic shift. Until now, this was a skill limited to a select few and came with a high price tag.</p><p>Today,  discovering, prioritizing and combining these techniques into viable attack paths is cheap, and one can repeat the process at machine speed.</p><p>With the pace of AI development, that statement becomes more true every day.</p><p>Offensive capability is becoming cheaper, faster and easier to reproduce.</p><p>But there is another side to this equation.</p><p>Defenders have always had structural advantages: more telemetry, deeper context, persistent access to their infrastructure, and knowledge of its configurations, identities and relationships, while also have a much better ability to act.</p><p>They too had the constraint of human capacity. No team could continuously reason over all that information, across every asset and relationship, all the time. The same AI that benefits attackers may operationalize defender’s historical edge at scale too.</p><p>This is where time plays a key role. Analyzing everything is not the same as defending everything. If AI detects a compromised identity in seconds but the credential remains active for six hours, the attacker still has six hours. If it identifies an exploitable path to a critical system but remediation takes three weeks, that path remains open for three weeks.</p><p>The opportunity, then, is not simply better analysis. It is reducing time-to-effective-action: the time between understanding a risk and changing the outcome.</p><p>And "effective" matters- disabling an <a href="https://www.techradar.com/best/best-identity-management-software">identity</a>, changing a <a href="https://www.techradar.com/best/firewall">firewall</a> rule or patching a vulnerability is not enough. The system must verify that the attacker can no longer achieve its objective.</p><p>The defensive loop cannot end with intelligence - or even with action. It has to end with a verified <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> outcome.</p><h2 id="the-gap-that-matters">The Gap That Matters </h2><p>AI does not inevitably favor the attacker.</p><p>The framework we recovered had to steal its map of the environment, one probe at a time. Defenders already have that map. Every configuration, credential, telemetry stream and trust relationship could take an attacker – even an AI attacker – days to weeks to discover. What defenders could never do was reason over all the assets they had, continuously, due to the lack of talent capacity to do that.</p><p>AI begins to remove that human-attention constraint. It allows defenders to amplify expert talent across thousands of investigations in parallel, continuously identifying attack paths, prioritizing those that pose the greatest risk, and focusing action where it matters most.</p><p>Attackers get the same leverage. But they don't start from the same place. Defenders have a home-field advantage: they already know and control the environment the attacker must discover.</p><p>The gap that matters is no longer simply the number of experts on either side. It is how effectively each side can scale that expertise- and direct it toward the right risks first.</p><p>Ultimately, the race is not about who can know more.</p><p>It is about who can scale talent in the right way- and turn that scale into an outcome first.</p><p><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software available</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A worrying ChatGPT bug let strangers read Gmail messages via a hidden cross-account channel ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Check Point Research exposed coerced insider flaw in ChatGPT’s agent architecture</strong></li><li><strong>Containers shared metadata via internal service, enabling cross‑account prompt injection and data theft</strong></li><li><strong>OpenAI closed the path, but CPR warns similar risks may exist in other AI platforms</strong></li></ul><p>ChatGPT’s AI agents were allowed to pull sensitive data from one account shared with an entirely different account because, colloquially speaking, all agents used to walk down the same hallways, experts have warned. </p><p>A new <a href="https://blog.checkpoint.com/research/chatgpt-let-attackers-read-victims-gmail-through-a-hidden-channel-between-accounts/" target="_blank" rel="nofollow">report</a> from security experts Check Point Research (CPR) dubbed the flaw “coerced insider”, since it revolves around persuading the agent instead of abusing a vulnerability.</p><h2 id="coerced-insider">Coerced insider</h2><p>When an AI agent is given a task that needs code execution, it handles that task in an isolated container which also sometimes needs to install software. To enable that, without giving containers direct internet access (which would be too risky), OpenAI routes those packages through an internal JFrog Artifactory instance. As a separate security contingency, containers from different accounts cannot talk between themselves.</p><p>However - they can reach the same internal service (our proverbial hallways), which exposes an item management feature that lets the containers attach text or binary properties to a repository item. As a result, any container can read back the properties written by any other container. </p><p>“Check Point Research confirmed the isolation gap directly: a property written from one account’s container was fully readable from a different account’s container moments later, with data too large for one property simply split into chunks and reassembled on the other end,” the researchers explained. </p><p>“The package delivery metadata effectively became a shared clipboard between containers that were supposed to be walled off from one another.”</p><p>From there, the exploit turns into your usual, off-the-shelf prompt injection. The only difference is that the malicious prompt is not delivered directly to the victim, but rather left in the hallways, and the results are not shared with the attackers directly, but rather left in those same proverbial hallways, too.</p><p>The attacker then delivers a prompt or a shared conversation that instructs the agent to check the same storage during its next ordinary reply. The agent checks, sees the malicious instructions, executes them, all the while replying to the victim’s question in the usual manner. The victim is oblivious to the fact that data theft is taking place in the background.</p><h2 id="what-kind-of-information-can-be-stolen">What kind of information can be stolen?</h2><p>But this is just half of the equation. How destructive this attack ends up being still depends on the amount of data being shared with the victim agent. </p><p>The bare minimum is the information shared while chatting to the agent. It then grows with every connected app: Gmail, <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Google Drive</a>, Microsoft Teams, GitHub, and similar. “In Check Point Research’s demonstration, ChatGPT retrieved the victim’s <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email</a> data through their connected Gmail account and delivered it to the attacker’s session, all within a single ordinary turn,” CPR stressed.</p><p>The good news is that you’ll likely never be exposed this way, at least not via ChatGPT. CPR says it disclosed the findings to OpenAI, who then confirmed that the specific internal Artifactory instance identified in the research has been commissioned. In other words, the hallways attack path has been closed.</p><p>The bad news is that this doesn’t automatically mean everyone’s safe. This particular path might be closed, but the architectural pattern behind the flaw could be present in other platforms, CPR warns. </p><p>“Any AI assistant that operates inside an organization’s trust boundary, holding credentials, running code, and reaching connected services, can become what Check Point Research calls a coerced insider,” the report states. “The model itself does not need to be malicious. It only needs to be persuaded, through text it was never meant to trust, to use access that was granted for entirely legitimate reasons.” </p><p>Going forward, businesses are advised to learn which AI tools their employees are using, and what those tools are connected to. Then, they should govern what AI tools and agents are allowed to do, treating all of their actions (not just output) as something that needs to be monitored. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/a-worrying-chatgpt-bug-let-strangers-read-gmail-messages-via-a-hidden-cross-account-channel</link>
                                                                            <description>
                            <![CDATA[ OpenAI has shut down this particular path, but general risk remains. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zQSSo4tbPGKyLUJSW5gy2j</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PB5R692ChqyHSzKEtqDyYe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PB5R692ChqyHSzKEtqDyYe-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/ alexsl]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ChatGPT app]]></media:description>                                                            <media:text><![CDATA[ChatGPT app]]></media:text>
                                <media:title type="plain"><![CDATA[ChatGPT app]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PB5R692ChqyHSzKEtqDyYe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Check Point Research exposed coerced insider flaw in ChatGPT’s agent architecture</strong></li><li><strong>Containers shared metadata via internal service, enabling cross‑account prompt injection and data theft</strong></li><li><strong>OpenAI closed the path, but CPR warns similar risks may exist in other AI platforms</strong></li></ul><p>ChatGPT’s AI agents were allowed to pull sensitive data from one account shared with an entirely different account because, colloquially speaking, all agents used to walk down the same hallways, experts have warned. </p><p>A new <a href="https://blog.checkpoint.com/research/chatgpt-let-attackers-read-victims-gmail-through-a-hidden-channel-between-accounts/" target="_blank" rel="nofollow">report</a> from security experts Check Point Research (CPR) dubbed the flaw “coerced insider”, since it revolves around persuading the agent instead of abusing a vulnerability.</p><h2 id="coerced-insider">Coerced insider</h2><p>When an AI agent is given a task that needs code execution, it handles that task in an isolated container which also sometimes needs to install software. To enable that, without giving containers direct internet access (which would be too risky), OpenAI routes those packages through an internal JFrog Artifactory instance. As a separate security contingency, containers from different accounts cannot talk between themselves.</p><p>However - they can reach the same internal service (our proverbial hallways), which exposes an item management feature that lets the containers attach text or binary properties to a repository item. As a result, any container can read back the properties written by any other container. </p><p>“Check Point Research confirmed the isolation gap directly: a property written from one account’s container was fully readable from a different account’s container moments later, with data too large for one property simply split into chunks and reassembled on the other end,” the researchers explained. </p><p>“The package delivery metadata effectively became a shared clipboard between containers that were supposed to be walled off from one another.”</p><p>From there, the exploit turns into your usual, off-the-shelf prompt injection. The only difference is that the malicious prompt is not delivered directly to the victim, but rather left in the hallways, and the results are not shared with the attackers directly, but rather left in those same proverbial hallways, too.</p><p>The attacker then delivers a prompt or a shared conversation that instructs the agent to check the same storage during its next ordinary reply. The agent checks, sees the malicious instructions, executes them, all the while replying to the victim’s question in the usual manner. The victim is oblivious to the fact that data theft is taking place in the background.</p><h2 id="what-kind-of-information-can-be-stolen">What kind of information can be stolen?</h2><p>But this is just half of the equation. How destructive this attack ends up being still depends on the amount of data being shared with the victim agent. </p><p>The bare minimum is the information shared while chatting to the agent. It then grows with every connected app: Gmail, <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">Google Drive</a>, Microsoft Teams, GitHub, and similar. “In Check Point Research’s demonstration, ChatGPT retrieved the victim’s <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email</a> data through their connected Gmail account and delivered it to the attacker’s session, all within a single ordinary turn,” CPR stressed.</p><p>The good news is that you’ll likely never be exposed this way, at least not via ChatGPT. CPR says it disclosed the findings to OpenAI, who then confirmed that the specific internal Artifactory instance identified in the research has been commissioned. In other words, the hallways attack path has been closed.</p><p>The bad news is that this doesn’t automatically mean everyone’s safe. This particular path might be closed, but the architectural pattern behind the flaw could be present in other platforms, CPR warns. </p><p>“Any AI assistant that operates inside an organization’s trust boundary, holding credentials, running code, and reaching connected services, can become what Check Point Research calls a coerced insider,” the report states. “The model itself does not need to be malicious. It only needs to be persuaded, through text it was never meant to trust, to use access that was granted for entirely legitimate reasons.” </p><p>Going forward, businesses are advised to learn which AI tools their employees are using, and what those tools are connected to. Then, they should govern what AI tools and agents are allowed to do, treating all of their actions (not just output) as something that needs to be monitored. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google Chrome will now ship security updates every two weeks, thanks to AI ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Chrome will get new updates every two weeks to minimize real-world attacks</strong></li><li><strong>Smaller, incremental changes should also make it easier to track any issues</strong></li><li><strong>Other major browsers are also shifting to two-weekly release cycles</strong></li></ul><p>Google has <a href="https://developer.chrome.com/blog/chrome-two-week-start" target="_blank">confirmed</a> that Chrome has officially moved from a four-week Stable release cycle to a two-week one, with effect from September 8 2026 with the launch of Chrome 153.</p><p>Besides adding new features, the main objective is for Google to give us performance and security fixes more promptly in an era of increased complexity and heightened vulnerabilities.</p><p>And it's exactly those security concerns that pushed Google to want to double Chrome's update frequency in the first lace, with the company now having to deal with a higher volume of patches than ever before.</p><h2 id="chrome-will-get-updates-every-two-weeks">Chrome will get updates every two weeks</h2><p>Together with a higher volume of attacks in general, Google has also benefitted from AI-powered vulnerability discovery tools, giving developers more work to do than before. "With automated AI discovery tools and community bug reports generating higher patch volume, shorter release cycles make managing security fixes significantly simpler," the company wrote.</p><p>Crucially, the faster cycle reduces the time between a fix landing in Chrome's public codebase and it actually reaching end users, making it less likely for a bug to be exploited in the wild.</p><p>Chrome has been adhering to a four-week cycle since 2021, but the world is a very different place in the space of just half a decade.</p><p>With the higher pace of releases, Google also anticipates a smaller scope of changes, which could actually be a good thing because it could be easier for developers to identify what went wrong in the event of any issues.</p><p>Desktop, Android and iOS versions of Chrome will all be impacted by the change, with Chrome 154 already slated for a September 22 release.</p><p>More broadly, Google says Chrome isn't the only browser getting more frequent updates. Microsoft, Mozilla and Brave are also making similar changes, and they're all undergoing those changes right now.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/google-chrome-will-now-ship-security-updates-every-two-weeks-thanks-to-ai</link>
                                                                            <description>
                            <![CDATA[ Google Chrome is shifting to a two-weekly Stable release cycle after five years of four-weekly releases in the name of security. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">W64A6MU2RTMo593AtERgth</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZfhFwGtGeLFq7LEuTgCMbD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 10:00:49 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Chrome]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Browsers]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZfhFwGtGeLFq7LEuTgCMbD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Ink Drop]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Silhouette of a hand holding a padlock infront of the google chrome logo]]></media:description>                                                            <media:text><![CDATA[Silhouette of a hand holding a padlock infront of the google chrome logo]]></media:text>
                                <media:title type="plain"><![CDATA[Silhouette of a hand holding a padlock infront of the google chrome logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZfhFwGtGeLFq7LEuTgCMbD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Chrome will get new updates every two weeks to minimize real-world attacks</strong></li><li><strong>Smaller, incremental changes should also make it easier to track any issues</strong></li><li><strong>Other major browsers are also shifting to two-weekly release cycles</strong></li></ul><p>Google has <a href="https://developer.chrome.com/blog/chrome-two-week-start" target="_blank">confirmed</a> that Chrome has officially moved from a four-week Stable release cycle to a two-week one, with effect from September 8 2026 with the launch of Chrome 153.</p><p>Besides adding new features, the main objective is for Google to give us performance and security fixes more promptly in an era of increased complexity and heightened vulnerabilities.</p><p>And it's exactly those security concerns that pushed Google to want to double Chrome's update frequency in the first lace, with the company now having to deal with a higher volume of patches than ever before.</p><h2 id="chrome-will-get-updates-every-two-weeks">Chrome will get updates every two weeks</h2><p>Together with a higher volume of attacks in general, Google has also benefitted from AI-powered vulnerability discovery tools, giving developers more work to do than before. "With automated AI discovery tools and community bug reports generating higher patch volume, shorter release cycles make managing security fixes significantly simpler," the company wrote.</p><p>Crucially, the faster cycle reduces the time between a fix landing in Chrome's public codebase and it actually reaching end users, making it less likely for a bug to be exploited in the wild.</p><p>Chrome has been adhering to a four-week cycle since 2021, but the world is a very different place in the space of just half a decade.</p><p>With the higher pace of releases, Google also anticipates a smaller scope of changes, which could actually be a good thing because it could be easier for developers to identify what went wrong in the event of any issues.</p><p>Desktop, Android and iOS versions of Chrome will all be impacted by the change, with Chrome 154 already slated for a September 22 release.</p><p>More broadly, Google says Chrome isn't the only browser getting more frequent updates. Microsoft, Mozilla and Brave are also making similar changes, and they're all undergoing those changes right now.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78-1920-80.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI’s storage challenge is really an operational one ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Enterprise <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> has always adapted as scale increased. Virtualization tackled server sprawl, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud computing</a> reduced the need to provision physical resources for every application, and automation made increasingly complex environments manageable. Artificial intelligence presents a different kind of scaling problem.</p><p>The discussion around enterprise AI has largely centered on models, GPUs, and inference performance, but those technologies represent only a fraction of what organizations must operate. Every production AI deployment creates a continuous flow of data that must be ingested, protected, moved, analyzed, retained, governed, and eventually archived.</p><p>Those activities place demands on infrastructure that are very different from the workloads storage systems were originally designed to support. </p><p>This is becoming increasingly apparent as organizations move beyond pilot projects. AI is no longer a single workload running on isolated infrastructure. A single application may include high-speed <a href="https://www.techradar.com/best/best-cloud-storage&quot">storage</a> for model training, object storage for inference data, lower-cost capacity for operational datasets, immutable storage for cyber resilience, and long-term archives to satisfy regulatory requirements. </p><p>Traditionally, those functions have been handled by separate products with separate management tools, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> policies, and operational teams. That architecture worked reasonably well when data moved slowly and applications followed predictable lifecycles. AI changes both assumptions.</p><p>Training datasets expand continuously. New models are introduced far more frequently than traditional enterprise applications. Inference workloads fluctuate as demand changes. The same dataset may move repeatedly between active processing, backup, compliance, and archival over its lifetime.</p><p>Each transition introduces another operational task, another opportunity for inconsistency, and another point where administrators must intervene. Before long, the effort required to manage the infrastructure begins to rival the effort required to build the AI applications themselves.</p><h2 id="complexity-becomes-the-real-infrastructure-challenge">Complexity becomes the real infrastructure challenge</h2><p>For years, the answer to operational complexity was automation. Administrators automated provisioning, scripted maintenance, and orchestrated repetitive tasks. Those capabilities remain valuable, but they were designed to execute predefined actions under predefined conditions.</p><p>AI environments are considerably less predictable. Infrastructure must continually adapt to changing workloads, shifting performance requirements, evolving security policies, and rapidly growing data volumes, often without the benefit of stable operating patterns.</p><p>That is where autonomous data infrastructure represents something more substantial than another <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> framework. Rather than treating storage as a collection of independent systems, it starts with the assumption that the platform itself should continuously optimize how data is managed throughout its lifecycle. Capacity, performance, protection, and cost become policy decisions rather than infrastructure projects.</p><p>Data moves between performance tiers automatically according to business requirements instead of being exported, migrated, and re-imported into separate platforms. A single namespace spans workloads that historically required multiple storage systems, allowing infrastructure to evolve without repeatedly forcing administrators to redesign the environment. </p><p>That architectural change may ultimately prove more important than the automation itself. Many organizations underestimate how much operational complexity accumulates simply from running multiple storage platforms. Every environment has its own authentication model, monitoring tools, lifecycle policies, upgrade schedules, recovery procedures, and performance characteristics.</p><p>As AI expands across the enterprise, those management layers multiply alongside the data. Reducing the number of operational boundaries often creates greater long-term value than introducing another layer of orchestration.</p><p>The same principle applies to cyber resilience. AI has increased the value of enterprise data far beyond traditional business records. Training datasets, model checkpoints, vector indexes, and inference pipelines have become strategic assets in their own right. Protecting them requires more than backup software. It requires infrastructure that assumes failures and attacks will occur and is designed to recover without depending on manual intervention. </p><h2 id="governance-becomes-part-of-the-data-lifecycle">Governance becomes part of the data lifecycle</h2><p>The conversation also extends beyond security to control. As AI initiatives become more strategic, organizations are under growing pressure to understand where <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> resides, who can access it, and which legal and regulatory frameworks govern it.</p><p>That is especially true for enterprises operating across multiple countries or in highly regulated industries, where data residency requirements, digital sovereignty initiatives, and industry-specific compliance obligations increasingly influence infrastructure decisions.</p><p>Rather than treating these as separate governance exercises, modern infrastructure must make location, retention, and access policies part of the data lifecycle itself, enabling organizations to meet regulatory requirements without introducing additional operational complexity.</p><p>One of the more significant design decisions behind autonomous data infrastructure is that immutability exists within the storage engine itself rather than being implemented solely through administrative policy. Instead of modifying existing data in place, new versions are written separately while previous versions remain intact. </p><p>Combined with distributed self-healing that rebuilds only affected objects instead of entire disks, this creates a fundamentally different operational model for resilience. Recovery becomes part of normal system behavior instead of an exceptional event requiring administrators to coordinate lengthy repair efforts. </p><h2 id="infrastructure-operators-become-infrastructure-architects">Infrastructure operators become infrastructure architects</h2><p>Perhaps the most interesting implication has little to do with storage technology itself. Infrastructure teams are already responsible for environments that are growing faster than headcount, and AI is accelerating that imbalance. The objective is not to remove people from operations, but to reduce the amount of time highly skilled engineers spend on repetitive maintenance that adds little strategic value.</p><p>As more routine activities become policy-driven and continuously optimized, infrastructure professionals can devote more attention to architecture, governance, capacity planning, and aligning technology decisions with <a href="https://www.techradar.com/best/best-small-business-software">business</a> priorities.</p><p>That evolution mirrors what is happening across software engineering, networking, and cybersecurity. AI is steadily shifting human expertise away from repetitive execution and toward system design, governance, and strategic decision-making. Autonomous data infrastructure reflects the same progression.</p><p>Rather than asking administrators to manage an ever-growing collection of storage products, it treats the infrastructure as an adaptive system that operates within policies established by the people responsible for it. The most effective approach is not to take humans out of the loop, but to keep them in control of the decisions that shape security, compliance, and business outcomes while allowing the platform to execute routine operational tasks autonomously. </p><p>Viewed from that perspective, autonomous data infrastructure is less about storage than it is about preparing enterprise IT for the next decade. AI has exposed the limitations of architectures built around isolated products, manual coordination, and steadily increasing operational overhead.</p><p>Organizations will continue investing in faster <a href="https://www.techradar.com/news/computing-components/graphics-cards/best-graphics-cards-1291458">GPUs</a> and more capable models, but those investments will deliver their greatest value only if the infrastructure beneath them becomes equally capable of managing complexity. The next generation of enterprise infrastructure will not simply store data more efficiently. It will actively participate in operating the environments that modern AI depends upon.</p><p><em></em><a href="https://www.techradar.com/best/best-bi-tools"><em>We've featured the best business intelligence platform.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ais-storage-challenge-is-really-an-operational-one</link>
                                                                            <description>
                            <![CDATA[ Why operational complexity, not storage capacity, is becoming AI's biggest infrastructure challenge. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zcAfyrCDHcUaYqAa2s9YFM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 09:45:20 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Billy Cashwell ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A line of robots typing at computers]]></media:description>                                                            <media:text><![CDATA[A line of robots typing at computers]]></media:text>
                                <media:title type="plain"><![CDATA[A line of robots typing at computers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Enterprise <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> has always adapted as scale increased. Virtualization tackled server sprawl, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud computing</a> reduced the need to provision physical resources for every application, and automation made increasingly complex environments manageable. Artificial intelligence presents a different kind of scaling problem.</p><p>The discussion around enterprise AI has largely centered on models, GPUs, and inference performance, but those technologies represent only a fraction of what organizations must operate. Every production AI deployment creates a continuous flow of data that must be ingested, protected, moved, analyzed, retained, governed, and eventually archived.</p><p>Those activities place demands on infrastructure that are very different from the workloads storage systems were originally designed to support. </p><p>This is becoming increasingly apparent as organizations move beyond pilot projects. AI is no longer a single workload running on isolated infrastructure. A single application may include high-speed <a href="https://www.techradar.com/best/best-cloud-storage&quot">storage</a> for model training, object storage for inference data, lower-cost capacity for operational datasets, immutable storage for cyber resilience, and long-term archives to satisfy regulatory requirements. </p><p>Traditionally, those functions have been handled by separate products with separate management tools, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> policies, and operational teams. That architecture worked reasonably well when data moved slowly and applications followed predictable lifecycles. AI changes both assumptions.</p><p>Training datasets expand continuously. New models are introduced far more frequently than traditional enterprise applications. Inference workloads fluctuate as demand changes. The same dataset may move repeatedly between active processing, backup, compliance, and archival over its lifetime.</p><p>Each transition introduces another operational task, another opportunity for inconsistency, and another point where administrators must intervene. Before long, the effort required to manage the infrastructure begins to rival the effort required to build the AI applications themselves.</p><h2 id="complexity-becomes-the-real-infrastructure-challenge">Complexity becomes the real infrastructure challenge</h2><p>For years, the answer to operational complexity was automation. Administrators automated provisioning, scripted maintenance, and orchestrated repetitive tasks. Those capabilities remain valuable, but they were designed to execute predefined actions under predefined conditions.</p><p>AI environments are considerably less predictable. Infrastructure must continually adapt to changing workloads, shifting performance requirements, evolving security policies, and rapidly growing data volumes, often without the benefit of stable operating patterns.</p><p>That is where autonomous data infrastructure represents something more substantial than another <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> framework. Rather than treating storage as a collection of independent systems, it starts with the assumption that the platform itself should continuously optimize how data is managed throughout its lifecycle. Capacity, performance, protection, and cost become policy decisions rather than infrastructure projects.</p><p>Data moves between performance tiers automatically according to business requirements instead of being exported, migrated, and re-imported into separate platforms. A single namespace spans workloads that historically required multiple storage systems, allowing infrastructure to evolve without repeatedly forcing administrators to redesign the environment. </p><p>That architectural change may ultimately prove more important than the automation itself. Many organizations underestimate how much operational complexity accumulates simply from running multiple storage platforms. Every environment has its own authentication model, monitoring tools, lifecycle policies, upgrade schedules, recovery procedures, and performance characteristics.</p><p>As AI expands across the enterprise, those management layers multiply alongside the data. Reducing the number of operational boundaries often creates greater long-term value than introducing another layer of orchestration.</p><p>The same principle applies to cyber resilience. AI has increased the value of enterprise data far beyond traditional business records. Training datasets, model checkpoints, vector indexes, and inference pipelines have become strategic assets in their own right. Protecting them requires more than backup software. It requires infrastructure that assumes failures and attacks will occur and is designed to recover without depending on manual intervention. </p><h2 id="governance-becomes-part-of-the-data-lifecycle">Governance becomes part of the data lifecycle</h2><p>The conversation also extends beyond security to control. As AI initiatives become more strategic, organizations are under growing pressure to understand where <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> resides, who can access it, and which legal and regulatory frameworks govern it.</p><p>That is especially true for enterprises operating across multiple countries or in highly regulated industries, where data residency requirements, digital sovereignty initiatives, and industry-specific compliance obligations increasingly influence infrastructure decisions.</p><p>Rather than treating these as separate governance exercises, modern infrastructure must make location, retention, and access policies part of the data lifecycle itself, enabling organizations to meet regulatory requirements without introducing additional operational complexity.</p><p>One of the more significant design decisions behind autonomous data infrastructure is that immutability exists within the storage engine itself rather than being implemented solely through administrative policy. Instead of modifying existing data in place, new versions are written separately while previous versions remain intact. </p><p>Combined with distributed self-healing that rebuilds only affected objects instead of entire disks, this creates a fundamentally different operational model for resilience. Recovery becomes part of normal system behavior instead of an exceptional event requiring administrators to coordinate lengthy repair efforts. </p><h2 id="infrastructure-operators-become-infrastructure-architects">Infrastructure operators become infrastructure architects</h2><p>Perhaps the most interesting implication has little to do with storage technology itself. Infrastructure teams are already responsible for environments that are growing faster than headcount, and AI is accelerating that imbalance. The objective is not to remove people from operations, but to reduce the amount of time highly skilled engineers spend on repetitive maintenance that adds little strategic value.</p><p>As more routine activities become policy-driven and continuously optimized, infrastructure professionals can devote more attention to architecture, governance, capacity planning, and aligning technology decisions with <a href="https://www.techradar.com/best/best-small-business-software">business</a> priorities.</p><p>That evolution mirrors what is happening across software engineering, networking, and cybersecurity. AI is steadily shifting human expertise away from repetitive execution and toward system design, governance, and strategic decision-making. Autonomous data infrastructure reflects the same progression.</p><p>Rather than asking administrators to manage an ever-growing collection of storage products, it treats the infrastructure as an adaptive system that operates within policies established by the people responsible for it. The most effective approach is not to take humans out of the loop, but to keep them in control of the decisions that shape security, compliance, and business outcomes while allowing the platform to execute routine operational tasks autonomously. </p><p>Viewed from that perspective, autonomous data infrastructure is less about storage than it is about preparing enterprise IT for the next decade. AI has exposed the limitations of architectures built around isolated products, manual coordination, and steadily increasing operational overhead.</p><p>Organizations will continue investing in faster <a href="https://www.techradar.com/news/computing-components/graphics-cards/best-graphics-cards-1291458">GPUs</a> and more capable models, but those investments will deliver their greatest value only if the infrastructure beneath them becomes equally capable of managing complexity. The next generation of enterprise infrastructure will not simply store data more efficiently. It will actively participate in operating the environments that modern AI depends upon.</p><p><em></em><a href="https://www.techradar.com/best/best-bi-tools"><em>We've featured the best business intelligence platform.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Massive data breach sees 220 million traveler records exposed — nine years of airline info leaked including passenger and passport details ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Kinryū Labs found misconfigured APIS database in Vietnam exposing 220M passenger and crew records</strong></li><li><strong>Data included PII, travel details, seat assignments, and baggage references from 2017–2026</strong></li><li><strong>Archive locked and there is no evidence yet of dark web sale</strong></li></ul><p>Millions of travellers have had their sensitive information exposed on the internet, thanks to a “series of misconfigurations” discovered in a cloud database, experts have warned.</p><p>In early June 2026, security researchers from Kinryū Labs discovered an Elasticsearch cluster which, although inaccessible from the open internet, allowed access through an alternate route - a cloud-based path. Once inside that route, the researchers discovered that the cluster accepted default credentials, granting access to an archive with 29 indices, weighing roughly 107GB.</p><p>The archive was apparently generated by an Advance Passenger Information System (APIS), a system airlines use to collect and send passenger and crew information to country authorities before flight arrival or departure. Usually, the system collects people’s names, birth dates, nationalities, passport and travel document numbers, and flight details, which are then used for border control, immigration, and similar cases. In this case, however, it also contained people’s sex, document expiration dates, issuing countries, airlines, departure, destination and transit airports, seat assignments, baggage reference, and more.</p><p>It is not known who operated the APIS, or who owns and runs the database. All the researchers managed to find is that it was hosted in Viettel-assigned IP space in Hanoi, Vietnam’s capital.</p><h2 id="who-was-affected">Who was affected?</h2><p>Of the 29 discovered indices, two were rather large: one contained 210,318, 069 passenger records, while another 10,465,631 crew records. In total, 220 million records, created between January 2017 and April 2026, from people who traveled to, from, or through Vietnam during that period.</p><p>The records don’t correspond to individuals, however. If a person travelled multiple times, they will show up in the archive multiple times. Canadians, Chinese, Korean, and New Zealandian nationals are among the ones whose information was exposed. The database is not limited to a specific airline, either - various airlines in Asia-Pacific, Europe, and Middle East regions were mentioned in the researchers’ report.</p><p>Since the researchers could not attribute the database to a specific entity, they reported it to the Vietnamese authorities, different airlines mentioned in the archives, and the country’s CERT (Computer Emergency Response Team), on June 3. The archive was locked down a week later, on June 8. According to BleepingComputer, it was the Singapore Airlines’ security team that took the lead on remediation efforts, telling the researchers they “engaged the relevant parties” and have “taken steps to contain the issue.”</p><p>Without a proper audit of the logs, and a full-blown forensic investigation, it is impossible to tell if any threat actors reached the database before the researchers, or if they exfiltrated and used the data found inside in identity theft, wire fraud, or other scams. What’s (somewhat) comforting is that there is no evidence of such activities on the dark web, and no hacking groups have made such claims. No one is selling the archive on the dark web, either.</p><h2 id="number-one-causes-of-data-spills">Number one causes of data spills </h2><p>Misconfigured databases remain one of the key causes of data leaks. Most businesses generate some type of data on their employees, partners, clients, or customers, and store it in the <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud</a> for easy access and actionable insights. However, some businesses don’t understand the shared responsibility model of cloud security or are simply reckless and sloppy when it comes to securing their cloud-stored data. Others, according to Cassius Edison, COO of Closed Door Security, have a problem with visibility of their IT real estate:</p><p>“The range of technology now used and managed by firms globally has made misconfigurations an increasingly persistent problem,” Edison explained. “Many organizations fail to maintain full visibility of their IT real estate and fail to perform proper audits of their systems, which inevitably leads to oversights in security and monitoring.”</p><p>For Edison, tackling misconfigurations internally can be difficult, “especially at large companies where teams work independently across a range of systems,” and advises organizations to bring in independent pentesters and security auditors. </p><p>Some of the biggest data leaks in the world came not from hackers breaking into locked-down systems, but from businesses inadvertently exposing their customers. </p><p>In 2026 alone, we’ve seen more than 670 million identity records exposed by Infutor, a data-driven consumer identity management company, as well as more than three billion records exposed through a misconfigured MongoDB database managed by global identity verification services, IDMerit.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/massive-data-breach-sees-220-million-traveler-records-exposed-nine-years-of-airline-info-leaked-including-passenger-and-passport-details</link>
                                                                            <description>
                            <![CDATA[ A series of misconfigurations allowed researchers to access a treasure trove of sensitive data - the archive has since been locked down. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8uHcVN224Fk6zmJ3KTpaSE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 20:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:description>                                                            <media:text><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:text>
                                <media:title type="plain"><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kinryū Labs found misconfigured APIS database in Vietnam exposing 220M passenger and crew records</strong></li><li><strong>Data included PII, travel details, seat assignments, and baggage references from 2017–2026</strong></li><li><strong>Archive locked and there is no evidence yet of dark web sale</strong></li></ul><p>Millions of travellers have had their sensitive information exposed on the internet, thanks to a “series of misconfigurations” discovered in a cloud database, experts have warned.</p><p>In early June 2026, security researchers from Kinryū Labs discovered an Elasticsearch cluster which, although inaccessible from the open internet, allowed access through an alternate route - a cloud-based path. Once inside that route, the researchers discovered that the cluster accepted default credentials, granting access to an archive with 29 indices, weighing roughly 107GB.</p><p>The archive was apparently generated by an Advance Passenger Information System (APIS), a system airlines use to collect and send passenger and crew information to country authorities before flight arrival or departure. Usually, the system collects people’s names, birth dates, nationalities, passport and travel document numbers, and flight details, which are then used for border control, immigration, and similar cases. In this case, however, it also contained people’s sex, document expiration dates, issuing countries, airlines, departure, destination and transit airports, seat assignments, baggage reference, and more.</p><p>It is not known who operated the APIS, or who owns and runs the database. All the researchers managed to find is that it was hosted in Viettel-assigned IP space in Hanoi, Vietnam’s capital.</p><h2 id="who-was-affected">Who was affected?</h2><p>Of the 29 discovered indices, two were rather large: one contained 210,318, 069 passenger records, while another 10,465,631 crew records. In total, 220 million records, created between January 2017 and April 2026, from people who traveled to, from, or through Vietnam during that period.</p><p>The records don’t correspond to individuals, however. If a person travelled multiple times, they will show up in the archive multiple times. Canadians, Chinese, Korean, and New Zealandian nationals are among the ones whose information was exposed. The database is not limited to a specific airline, either - various airlines in Asia-Pacific, Europe, and Middle East regions were mentioned in the researchers’ report.</p><p>Since the researchers could not attribute the database to a specific entity, they reported it to the Vietnamese authorities, different airlines mentioned in the archives, and the country’s CERT (Computer Emergency Response Team), on June 3. The archive was locked down a week later, on June 8. According to BleepingComputer, it was the Singapore Airlines’ security team that took the lead on remediation efforts, telling the researchers they “engaged the relevant parties” and have “taken steps to contain the issue.”</p><p>Without a proper audit of the logs, and a full-blown forensic investigation, it is impossible to tell if any threat actors reached the database before the researchers, or if they exfiltrated and used the data found inside in identity theft, wire fraud, or other scams. What’s (somewhat) comforting is that there is no evidence of such activities on the dark web, and no hacking groups have made such claims. No one is selling the archive on the dark web, either.</p><h2 id="number-one-causes-of-data-spills">Number one causes of data spills </h2><p>Misconfigured databases remain one of the key causes of data leaks. Most businesses generate some type of data on their employees, partners, clients, or customers, and store it in the <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud</a> for easy access and actionable insights. However, some businesses don’t understand the shared responsibility model of cloud security or are simply reckless and sloppy when it comes to securing their cloud-stored data. Others, according to Cassius Edison, COO of Closed Door Security, have a problem with visibility of their IT real estate:</p><p>“The range of technology now used and managed by firms globally has made misconfigurations an increasingly persistent problem,” Edison explained. “Many organizations fail to maintain full visibility of their IT real estate and fail to perform proper audits of their systems, which inevitably leads to oversights in security and monitoring.”</p><p>For Edison, tackling misconfigurations internally can be difficult, “especially at large companies where teams work independently across a range of systems,” and advises organizations to bring in independent pentesters and security auditors. </p><p>Some of the biggest data leaks in the world came not from hackers breaking into locked-down systems, but from businesses inadvertently exposing their customers. </p><p>In 2026 alone, we’ve seen more than 670 million identity records exposed by Infutor, a data-driven consumer identity management company, as well as more than three billion records exposed through a misconfigured MongoDB database managed by global identity verification services, IDMerit.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Liquid Network halts new transactions after 'nice guy' hackers steal nearly all its Bitcoin — but then return most of it after a patch is issued ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Liquid Network hack exploited a bug in SideSwap, releasing 3,998 BTC (~$313M) to attackers</strong></li><li><strong>Hackers claimed “white‑hat” intent, returning 3,400 BTC after fixes, leaving 598 BTC missing</strong></li><li><strong>Network remains paused as Blockstream and Federation patch vulnerabilities and prepare safe restart</strong></li></ul><p>The latest twist in the Liquid Network Bitcoin hack is worthy of a short movie, if not a full-length feature film. </p><p>Apparently, the hackers are actually the good guys, who stole the money to “keep it safe” until a vulnerability in the protocol had been fully resolved. They promised to return the funds afterwards.</p><h2 id="what-is-liquid-network">What is Liquid Network?</h2><p>Liquid Network was designed to solve a specific problem on the Bitcoin blockchain - being rather slow. The transactions on the network are recorded in a “block”, which is added to the chain roughly once every 10 minutes. Also, each block can only hold a limited number of transactions, which means the network can handle a smaller number of transactions per second, compared to conventional payment systems. Transactions that don’t make it into a specific block then need to wait for the next one, thus extending the confirmation time.</p><p>To solve that problem, Liquid Network was built. It runs its own Bitcoin reserve and its own blockchain, also known as a “sidechain”. When a person wants to use Liquid Network to send money quickly, they first convert their Bitcoin into Liquid Bitcoin, or L-BTC. They can then send it to another person much faster than a regular Bitcoin transaction. The recipient can keep the money on Liquid or convert it back to regular Bitcoin and move it to the Bitcoin network. </p><p>This way, Liquid provides a faster network without requiring every transaction to happen directly on the Bitcoin blockchain.</p><p>Besides speeding up Bitcoin transactions, Liquid Network also allows users (companies and other entities) to create and trade other digital assets, including tokenized securities, or stablecoins.</p><p>The project was built by Blockstream, a Bitcoin-focused technology company founded in 2014. It is run by the Liquid Federation, a group of more than 80 member companies, including exchanges, infrastructure companies, and financial institutions. A smaller group of members (15 to be exact) operate the network’s “functionaries” (servers that keep the network running), while the wider group has a governance role. Members vote on three boards (Technology, Membership, Oversight), handling ideas such as technical direction, internal rules, memberships, and more. </p><h2 id="what-happened-to-it">What happened to it?</h2><p>In early September 2026, still unidentified actors managed to generate around 4,000 L-BTC, without putting in the corresponding 4,000 BTC into Liquid. As soon as they did it, they sent the L-BTC through SideSwap, a legitimate service that is used to convert L-BTC back to Bitcoin and vice-versa. The system apparently regarded the withdrawal as legitimate because, as was later determined, a bug prevented SideSwap from distinguishing between “real” and “fake” L-BTC, and treated them all the same.</p><p>As a result, the Liquid Federation ended up releasing 3,998 real BTC (more than $313 million at press time) to the attackers. As soon as the operators realized what had happened, they halted new transactions and warned about possible disruptions until the service was restored. </p><p>Then came the movie twist: the hacker started communicating with network maintainers through on-chain Bitcoin transactions, promising to return the funds when the vulnerability is fully resolved:</p><p>“Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix,” one of the messages read.</p><p>Earlier today, Coindesk reported that the hackers partially kept their promise, returning 3,400 of the 4,000 BTC drained, which suggests that the flaw was remedied. The remaining 598 BTC, worth approximately $47 million, is currently unaccounted for. </p><p>“3,400 BTC of the roughly 4,000 BTC withdrawn on September 6 has been returned to the Liquid Federation wallet. The return followed confirmation from Blockstream that the affected bridge nodes have been patched,” wrote Samson Mow, former chief strategy officer at Blockstream, on X. “Approximately 598 BTC remains outstanding, and Blockstream continues to engage with the white-hat hackers.”</p><p>He added that the network remains paused while Blockstream and Federation members make additional fixes and security improvements, resolve the chain split, and prepare for a safe restart. </p><p>“Liquid <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">wallets</a> and services will continue to be affected during this time. No user action is needed, and please do not send Bitcoin to Liquid peg-in addresses until we confirm the network has restarted,” he added.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/liquid-network-halts-new-transactions-after-nice-guy-hackers-steal-nearly-all-its-bitcoin-but-then-return-most-of-it-after-a-patch-is-issued</link>
                                                                            <description>
                            <![CDATA[ Liquid Network is still disrupted, but users can breathe a sigh of relief as most of the stolen funds have been returned. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oguXoFVDTGkmgxvQsQBpU3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UweTPZX99rMmYJQoBvPT44-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UweTPZX99rMmYJQoBvPT44-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Bitcoin]]></media:description>                                                            <media:text><![CDATA[Bitcoin]]></media:text>
                                <media:title type="plain"><![CDATA[Bitcoin]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UweTPZX99rMmYJQoBvPT44-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Liquid Network hack exploited a bug in SideSwap, releasing 3,998 BTC (~$313M) to attackers</strong></li><li><strong>Hackers claimed “white‑hat” intent, returning 3,400 BTC after fixes, leaving 598 BTC missing</strong></li><li><strong>Network remains paused as Blockstream and Federation patch vulnerabilities and prepare safe restart</strong></li></ul><p>The latest twist in the Liquid Network Bitcoin hack is worthy of a short movie, if not a full-length feature film. </p><p>Apparently, the hackers are actually the good guys, who stole the money to “keep it safe” until a vulnerability in the protocol had been fully resolved. They promised to return the funds afterwards.</p><h2 id="what-is-liquid-network">What is Liquid Network?</h2><p>Liquid Network was designed to solve a specific problem on the Bitcoin blockchain - being rather slow. The transactions on the network are recorded in a “block”, which is added to the chain roughly once every 10 minutes. Also, each block can only hold a limited number of transactions, which means the network can handle a smaller number of transactions per second, compared to conventional payment systems. Transactions that don’t make it into a specific block then need to wait for the next one, thus extending the confirmation time.</p><p>To solve that problem, Liquid Network was built. It runs its own Bitcoin reserve and its own blockchain, also known as a “sidechain”. When a person wants to use Liquid Network to send money quickly, they first convert their Bitcoin into Liquid Bitcoin, or L-BTC. They can then send it to another person much faster than a regular Bitcoin transaction. The recipient can keep the money on Liquid or convert it back to regular Bitcoin and move it to the Bitcoin network. </p><p>This way, Liquid provides a faster network without requiring every transaction to happen directly on the Bitcoin blockchain.</p><p>Besides speeding up Bitcoin transactions, Liquid Network also allows users (companies and other entities) to create and trade other digital assets, including tokenized securities, or stablecoins.</p><p>The project was built by Blockstream, a Bitcoin-focused technology company founded in 2014. It is run by the Liquid Federation, a group of more than 80 member companies, including exchanges, infrastructure companies, and financial institutions. A smaller group of members (15 to be exact) operate the network’s “functionaries” (servers that keep the network running), while the wider group has a governance role. Members vote on three boards (Technology, Membership, Oversight), handling ideas such as technical direction, internal rules, memberships, and more. </p><h2 id="what-happened-to-it">What happened to it?</h2><p>In early September 2026, still unidentified actors managed to generate around 4,000 L-BTC, without putting in the corresponding 4,000 BTC into Liquid. As soon as they did it, they sent the L-BTC through SideSwap, a legitimate service that is used to convert L-BTC back to Bitcoin and vice-versa. The system apparently regarded the withdrawal as legitimate because, as was later determined, a bug prevented SideSwap from distinguishing between “real” and “fake” L-BTC, and treated them all the same.</p><p>As a result, the Liquid Federation ended up releasing 3,998 real BTC (more than $313 million at press time) to the attackers. As soon as the operators realized what had happened, they halted new transactions and warned about possible disruptions until the service was restored. </p><p>Then came the movie twist: the hacker started communicating with network maintainers through on-chain Bitcoin transactions, promising to return the funds when the vulnerability is fully resolved:</p><p>“Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix,” one of the messages read.</p><p>Earlier today, Coindesk reported that the hackers partially kept their promise, returning 3,400 of the 4,000 BTC drained, which suggests that the flaw was remedied. The remaining 598 BTC, worth approximately $47 million, is currently unaccounted for. </p><p>“3,400 BTC of the roughly 4,000 BTC withdrawn on September 6 has been returned to the Liquid Federation wallet. The return followed confirmation from Blockstream that the affected bridge nodes have been patched,” wrote Samson Mow, former chief strategy officer at Blockstream, on X. “Approximately 598 BTC remains outstanding, and Blockstream continues to engage with the white-hat hackers.”</p><p>He added that the network remains paused while Blockstream and Federation members make additional fixes and security improvements, resolve the chain split, and prepare for a safe restart. </p><p>“Liquid <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">wallets</a> and services will continue to be affected during this time. No user action is needed, and please do not send Bitcoin to Liquid peg-in addresses until we confirm the network has restarted,” he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft 365 users hit by two major threat campaigns - fake IT calls and phishing emails target users across the world ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft 365 users targeted by phishing campaigns using BigBear 2.0 and AiTM proxies</strong></li><li><strong>Attackers impersonate IT staff via calls, Teams, and email to steal credentials and bypass MFA</strong></li><li><strong>CloudSEK tracked 5,000+ stolen records; Arctic Wolf urges phishing‑resistant MFA and conditional access</strong></li></ul><p>Microsoft 365 users are facing a barrage of cyberattacks all aimed at a single goal - to try and expose credentials which can later be used against employers in data theft attacks.</p><p>Different groups conduct their raids and bypass multi-factor authentication (MFA) protection to access victim accounts - CloudSEK, for example, said that some groups are using BigBear 2.0, a new phishing-as-a-service (PhaaS) framework that allows crooks to intercept passwords and authenticated session cookies.</p><p>Arctic Wolf, on the other hand, focused on a single threat actor, which it dubbed PREY-0058. This group, despite significant overlaps with other collectives in terms of techniques, technologies, and procedures, is not a rebrand of older organizations. Instead, the researchers believe the lines between the groups are blurred and that there is a large group of affiliates, splinter crews, and other cohorts using the same phishing infrastructure and thus often confuse defenders and analysts.</p><h2 id="similar-methods-similar-results">Similar methods, similar results</h2><p>The attack methodology is similar across the spectrum. Crooks would call their victims on the phone or approach them via Teams and email. They would introduce themselves as members of the IT help desk sent to sort out a specific problem or issue. </p><p>Then, they would either convince the victim to grant remote access, or to open a spoofed Microsoft 365 login page and enter their credentials there. In both cases, the goal is the same - to get the victim to type in their username, password, and 2FA code, on a fake site built by BigBear 2.0 or a similar phishing framework. This framework, using an attacker-in-the-middle (AiTM) proxy between the victim and legitimate Microsoft infrastructure, harvests credentials, <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA codes</a>, and session cookies, and replays them through an API essentially hijacking a legitimate authentication session.</p><p>Once they gain access, the attackers can do all sorts of things, but they are mostly focused on exfiltrating sensitive data from Outlook, Teams, SharePoint, and OneDrive. Deploying <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> is rarely seen. </p><p>The campaign CloudSEK has been tracking has been rather successful, the researchers argue, saying BigBear 2.0 was used to exfiltrate more than 5,000 credential records, “including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies - affecting 3,331 unique victim IPs across 40+ countries with the operation still active at the time of writing.” </p><p>“The multi-user PhaaS panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots, each receiving stolen credentials in real time.”</p><p>Speaking to <a href="https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/" target="_blank"><em>BleepingComputer</em></a>, CloudSEK says the campaign targeted 461 organizations, out of which 258 have had at least one set of credentials compromised. </p><h2 id="defending-with-phishing-resistant-mfa">Defending with phishing-resistant MFA</h2><p>Arctic Wolf’s researchers stressed that the attackers are focused primarily on US-based businesses: construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services, <a href="https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html" target="_blank"><em>The Hacker News</em></a> reported. The researchers advise organizations to implement Conditional Access policies, deploy phishing-resistant MFA, and restrict the scope of data users can access via SharePoint. Obviously, employee education on the dangers of phishing cannot be understated.</p><p>"Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure," Arctic Wolf said.</p><p>Phishing-resistant MFA is multi-factor authentication designed so that an attacker cannot trick a person into handing over authorization code, either via a message, or through a fake login page. </p><p>These include products such as passkeys, YubiKeys <a href="https://www.techradar.com/best/best-security-key" target="_blank">security keys</a>, and authentication methods based on FIDO2/WebAuthn. Since phishing-resistant MFA cryptographically ties the authentication to the legitimate website, the authentication cannot simply be forwarded to an attacker.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsoft-365-users-hit-by-two-major-threat-campaigns-fake-it-calls-and-phishing-emails-target-users-across-the-world</link>
                                                                            <description>
                            <![CDATA[ BigBear 2.0 and PREY-0058 are wreaking havoc across businesses as they scam employees into handing over login credentials and MFA codes. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C6BxVw2HaDLYXxNeeyT4HQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vnpBJPCcs2siQw5rCEsDzG-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 15:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/vnpBJPCcs2siQw5rCEsDzG-1280-80.png">
                                                            <media:credit><![CDATA[Currys]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft 365]]></media:description>                                                            <media:text><![CDATA[Microsoft 365]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft 365]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vnpBJPCcs2siQw5rCEsDzG-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft 365 users targeted by phishing campaigns using BigBear 2.0 and AiTM proxies</strong></li><li><strong>Attackers impersonate IT staff via calls, Teams, and email to steal credentials and bypass MFA</strong></li><li><strong>CloudSEK tracked 5,000+ stolen records; Arctic Wolf urges phishing‑resistant MFA and conditional access</strong></li></ul><p>Microsoft 365 users are facing a barrage of cyberattacks all aimed at a single goal - to try and expose credentials which can later be used against employers in data theft attacks.</p><p>Different groups conduct their raids and bypass multi-factor authentication (MFA) protection to access victim accounts - CloudSEK, for example, said that some groups are using BigBear 2.0, a new phishing-as-a-service (PhaaS) framework that allows crooks to intercept passwords and authenticated session cookies.</p><p>Arctic Wolf, on the other hand, focused on a single threat actor, which it dubbed PREY-0058. This group, despite significant overlaps with other collectives in terms of techniques, technologies, and procedures, is not a rebrand of older organizations. Instead, the researchers believe the lines between the groups are blurred and that there is a large group of affiliates, splinter crews, and other cohorts using the same phishing infrastructure and thus often confuse defenders and analysts.</p><h2 id="similar-methods-similar-results">Similar methods, similar results</h2><p>The attack methodology is similar across the spectrum. Crooks would call their victims on the phone or approach them via Teams and email. They would introduce themselves as members of the IT help desk sent to sort out a specific problem or issue. </p><p>Then, they would either convince the victim to grant remote access, or to open a spoofed Microsoft 365 login page and enter their credentials there. In both cases, the goal is the same - to get the victim to type in their username, password, and 2FA code, on a fake site built by BigBear 2.0 or a similar phishing framework. This framework, using an attacker-in-the-middle (AiTM) proxy between the victim and legitimate Microsoft infrastructure, harvests credentials, <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA codes</a>, and session cookies, and replays them through an API essentially hijacking a legitimate authentication session.</p><p>Once they gain access, the attackers can do all sorts of things, but they are mostly focused on exfiltrating sensitive data from Outlook, Teams, SharePoint, and OneDrive. Deploying <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> is rarely seen. </p><p>The campaign CloudSEK has been tracking has been rather successful, the researchers argue, saying BigBear 2.0 was used to exfiltrate more than 5,000 credential records, “including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies - affecting 3,331 unique victim IPs across 40+ countries with the operation still active at the time of writing.” </p><p>“The multi-user PhaaS panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots, each receiving stolen credentials in real time.”</p><p>Speaking to <a href="https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/" target="_blank"><em>BleepingComputer</em></a>, CloudSEK says the campaign targeted 461 organizations, out of which 258 have had at least one set of credentials compromised. </p><h2 id="defending-with-phishing-resistant-mfa">Defending with phishing-resistant MFA</h2><p>Arctic Wolf’s researchers stressed that the attackers are focused primarily on US-based businesses: construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services, <a href="https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html" target="_blank"><em>The Hacker News</em></a> reported. The researchers advise organizations to implement Conditional Access policies, deploy phishing-resistant MFA, and restrict the scope of data users can access via SharePoint. Obviously, employee education on the dangers of phishing cannot be understated.</p><p>"Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure," Arctic Wolf said.</p><p>Phishing-resistant MFA is multi-factor authentication designed so that an attacker cannot trick a person into handing over authorization code, either via a message, or through a fake login page. </p><p>These include products such as passkeys, YubiKeys <a href="https://www.techradar.com/best/best-security-key" target="_blank">security keys</a>, and authentication methods based on FIDO2/WebAuthn. Since phishing-resistant MFA cryptographically ties the authentication to the legitimate website, the authentication cannot simply be forwarded to an attacker.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Introducing AI-as-a-Service ]]></title>
                                                                                                <dc:content><![CDATA[ <p>2025 was a transformative year for <a href="https://www.techradar.com/best/best-ai-tools">artificial intelligence</a>, and 2026 is already proving to be equally significant. </p><p>While generative AI dominated conversations just a few years ago, the focus is now shifting towards agentic AI, where intelligent systems can take action, interact with business processes, and support employees in more meaningful ways.</p><p>As these capabilities continue to evolve, organizations are looking for better ways to connect AI systems to the applications, data and services that drive their operations. </p><p>This is where technologies such as Model Context Protocol (MCP) are becoming increasingly important. </p><p>Rather than creating bespoke integrations for every tool or system, MCP provides a standardized way for AI models and agents to access information and perform actions across an organization's technology estate.</p><p>While MCP is not a requirement for every AI implementation today, it represents a natural next step for organizations looking to move beyond isolated AI use cases and towards more integrated, scalable AI ecosystems.</p><p>However, greater integration also introduces greater responsibility. Effective governance remains essential for any AI deployment, but it becomes even more critical when autonomous agents are granted access to business systems, processes and sensitive information. </p><p>Organizations must establish clear guardrails that define what agents can access, what actions they can perform, and how their activities are monitored. Without appropriate oversight, businesses risk agents operating beyond their intended scope or creating unintended consequences across interconnected systems.</p><h2 id="the-impact-on-software-as-a-service">The impact on Software-as-a-Service</h2><p>Few sectors will feel the effects of this shift more than Software-as-a-Service (SaaS).</p><p>For years, SaaS applications have been built around human interaction. Users access platforms through dashboards and interfaces, navigate predefined workflows, and manually complete tasks. The application itself serves as the primary workspace where work is performed.</p><p>Agentic AI introduces a different model.</p><p>Rather than navigating <a href="https://www.techradar.com/best/best-small-business-software">software</a> in the same way a person would, agents can interact directly with APIs, services and data sources. This allows them to retrieve information, execute actions and orchestrate processes across multiple systems without relying on traditional user journeys.</p><p>That does not mean SaaS applications will disappear. In fact, they will continue to play a critical role in storing structured data, enforcing business rules and managing workflows. What is likely to change is how those applications are consumed.</p><p>Instead of being the primary destination where work happens, many SaaS platforms will increasingly act as sources of capability and information that AI agents can utilize on behalf of users. As a result, organizations may find themselves focusing less on which <a href="https://www.techradar.com/best/best-mobile-app-development-software">application</a> employees need to access and more on how services and data can be brought together to achieve the desired business outcome.</p><p>Human interfaces will still matter. Users will continue to need visibility, exception handling and control mechanisms, particularly when business-critical processes are involved. The challenge for software providers will be balancing traditional user experiences with new AI-driven interaction models while maintaining compatibility, reliability and operational resilience.</p><h2 id="breaking-down-agent-silos">Breaking down agent silos</h2><p>The next stage in the evolution of agentic AI is not simply creating more agents. It is enabling agents to work together effectively.</p><p>Many organizations already struggle with fragmented systems, disconnected data and isolated processes. Without careful planning, agents risk creating a new generation of silos, each operating within its own limited context and producing inconsistent outcomes.</p><p>To avoid this, businesses must focus on shared context, connected data and interoperable services. The goal is not to have individual agents automating isolated tasks but to enable multiple agents to contribute towards broader business objectives across entire processes.</p><p>When agents can access consistent information and operate across organizational boundaries, the value shifts from discrete task automation to coordinated execution. Rather than supporting an individual stage of a workflow, agents can participate in end-to-end processes while remaining aligned to business policies, operational requirements and organizational goals.</p><p>This represents an important architectural shift. Software increasingly becomes something that agents consume programmatically, while integration, context and orchestration become central to delivering outcomes at scale.</p><h2 id="mitigating-risk-in-aiaas">Mitigating risk in AIaaS</h2><p>Unlocking these new capabilities requires more than deploying AI tools. Organizations need governance frameworks, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls and operational processes that allow autonomy to be introduced safely and responsibly.</p><p>As agents gain access to more systems and collaborate across workflows, operational complexity inevitably increases. Businesses must define clear policies around what agents can and cannot do, what data they can access, and what approvals are required before actions are taken.</p><p>These controls should be embedded into the orchestration layer itself, ensuring governance is applied consistently across all agent-led activities rather than being treated as an afterthought.</p><p>Traceability and accountability are equally important. Completing a task successfully is only part of the equation. Organizations must understand how decisions were made, what information was used, and which policies were applied throughout the process. This visibility will be essential for compliance, security and maintaining trust in autonomous systems.</p><p>The role of <a href="https://www.techradar.com/best/best-linux-distro-for-developers">developers</a> will also evolve. Rather than spending significant time building and maintaining point-to-point integrations, they will increasingly focus on designing agent behaviors, defining boundaries, managing orchestration and ensuring solutions operate within established governance frameworks.</p><p>The organizations that succeed will be those that balance innovation with control. Too little governance introduces risk, while excessive restrictions can prevent businesses from realizing the benefits of AI altogether.</p><p>Agentic AI should not be viewed as a replacement for software development or existing technology investments. Instead, it represents a powerful new interaction layer that changes how organizations access information, automate processes and deliver outcomes.</p><p>Businesses that invest now in integration foundations, governance models and workforce skills will be best placed to take advantage of the opportunities this next phase of AI creates.</p><p><em></em><a href="https://www.techradar.com/news/best-business-laptops"><em>We've reviewed the best business laptops</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/introducing-ai-as-a-service</link>
                                                                            <description>
                            <![CDATA[ As agentic AI evolves, the impact will be felt throughout the industry - especially on SaaS. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iYiwHcPKFNgfQ9vFiutmde</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 10:33:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jay Fitzhenry ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>2025 was a transformative year for <a href="https://www.techradar.com/best/best-ai-tools">artificial intelligence</a>, and 2026 is already proving to be equally significant. </p><p>While generative AI dominated conversations just a few years ago, the focus is now shifting towards agentic AI, where intelligent systems can take action, interact with business processes, and support employees in more meaningful ways.</p><p>As these capabilities continue to evolve, organizations are looking for better ways to connect AI systems to the applications, data and services that drive their operations. </p><p>This is where technologies such as Model Context Protocol (MCP) are becoming increasingly important. </p><p>Rather than creating bespoke integrations for every tool or system, MCP provides a standardized way for AI models and agents to access information and perform actions across an organization's technology estate.</p><p>While MCP is not a requirement for every AI implementation today, it represents a natural next step for organizations looking to move beyond isolated AI use cases and towards more integrated, scalable AI ecosystems.</p><p>However, greater integration also introduces greater responsibility. Effective governance remains essential for any AI deployment, but it becomes even more critical when autonomous agents are granted access to business systems, processes and sensitive information. </p><p>Organizations must establish clear guardrails that define what agents can access, what actions they can perform, and how their activities are monitored. Without appropriate oversight, businesses risk agents operating beyond their intended scope or creating unintended consequences across interconnected systems.</p><h2 id="the-impact-on-software-as-a-service">The impact on Software-as-a-Service</h2><p>Few sectors will feel the effects of this shift more than Software-as-a-Service (SaaS).</p><p>For years, SaaS applications have been built around human interaction. Users access platforms through dashboards and interfaces, navigate predefined workflows, and manually complete tasks. The application itself serves as the primary workspace where work is performed.</p><p>Agentic AI introduces a different model.</p><p>Rather than navigating <a href="https://www.techradar.com/best/best-small-business-software">software</a> in the same way a person would, agents can interact directly with APIs, services and data sources. This allows them to retrieve information, execute actions and orchestrate processes across multiple systems without relying on traditional user journeys.</p><p>That does not mean SaaS applications will disappear. In fact, they will continue to play a critical role in storing structured data, enforcing business rules and managing workflows. What is likely to change is how those applications are consumed.</p><p>Instead of being the primary destination where work happens, many SaaS platforms will increasingly act as sources of capability and information that AI agents can utilize on behalf of users. As a result, organizations may find themselves focusing less on which <a href="https://www.techradar.com/best/best-mobile-app-development-software">application</a> employees need to access and more on how services and data can be brought together to achieve the desired business outcome.</p><p>Human interfaces will still matter. Users will continue to need visibility, exception handling and control mechanisms, particularly when business-critical processes are involved. The challenge for software providers will be balancing traditional user experiences with new AI-driven interaction models while maintaining compatibility, reliability and operational resilience.</p><h2 id="breaking-down-agent-silos">Breaking down agent silos</h2><p>The next stage in the evolution of agentic AI is not simply creating more agents. It is enabling agents to work together effectively.</p><p>Many organizations already struggle with fragmented systems, disconnected data and isolated processes. Without careful planning, agents risk creating a new generation of silos, each operating within its own limited context and producing inconsistent outcomes.</p><p>To avoid this, businesses must focus on shared context, connected data and interoperable services. The goal is not to have individual agents automating isolated tasks but to enable multiple agents to contribute towards broader business objectives across entire processes.</p><p>When agents can access consistent information and operate across organizational boundaries, the value shifts from discrete task automation to coordinated execution. Rather than supporting an individual stage of a workflow, agents can participate in end-to-end processes while remaining aligned to business policies, operational requirements and organizational goals.</p><p>This represents an important architectural shift. Software increasingly becomes something that agents consume programmatically, while integration, context and orchestration become central to delivering outcomes at scale.</p><h2 id="mitigating-risk-in-aiaas">Mitigating risk in AIaaS</h2><p>Unlocking these new capabilities requires more than deploying AI tools. Organizations need governance frameworks, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls and operational processes that allow autonomy to be introduced safely and responsibly.</p><p>As agents gain access to more systems and collaborate across workflows, operational complexity inevitably increases. Businesses must define clear policies around what agents can and cannot do, what data they can access, and what approvals are required before actions are taken.</p><p>These controls should be embedded into the orchestration layer itself, ensuring governance is applied consistently across all agent-led activities rather than being treated as an afterthought.</p><p>Traceability and accountability are equally important. Completing a task successfully is only part of the equation. Organizations must understand how decisions were made, what information was used, and which policies were applied throughout the process. This visibility will be essential for compliance, security and maintaining trust in autonomous systems.</p><p>The role of <a href="https://www.techradar.com/best/best-linux-distro-for-developers">developers</a> will also evolve. Rather than spending significant time building and maintaining point-to-point integrations, they will increasingly focus on designing agent behaviors, defining boundaries, managing orchestration and ensuring solutions operate within established governance frameworks.</p><p>The organizations that succeed will be those that balance innovation with control. Too little governance introduces risk, while excessive restrictions can prevent businesses from realizing the benefits of AI altogether.</p><p>Agentic AI should not be viewed as a replacement for software development or existing technology investments. Instead, it represents a powerful new interaction layer that changes how organizations access information, automate processes and deliver outcomes.</p><p>Businesses that invest now in integration foundations, governance models and workforce skills will be best placed to take advantage of the opportunities this next phase of AI creates.</p><p><em></em><a href="https://www.techradar.com/news/best-business-laptops"><em>We've reviewed the best business laptops</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Another Rowhammer attack has been detected, and Nvidia workstation GPUs are firmly in the firing line ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>GPUThor is the first Rowhammer attack to defeat ECC on Nvidia GPUs and reach a root shell on the host</strong></li><li><strong>It affects four Ampere workstation cards with GDDR6 memory, the RTX A4000, A4500, A5000 and A6000</strong></li><li><strong>Non-uniform hammering, enabled by defeating GPU memory coalescing and finding that Target Row Refresh (TRR) mitigations fire once every 72 refresh intervals, delivers effectively 6.6 times the hammering intensity of prior attacks</strong></li></ul><p>Four researchers at the University of Toronto have disclosed GPUThor, a Rowhammer technique that breaks the error correction Nvidia has spent the past year recommending as the defense against exactly this class of attack.</p><p>Chris S. Lin, Joyce Qu, Aditya Rajeev and Gururaj Saileshwar are expected to present the <a href="https://gputhor.com/" target="_blank" rel="nofollow">paper</a> outlining their approach and subsequent findings at ACM CCS 2026.</p><p>The attacks target Ampere-generation workstation cards with GDDR6 memory, specifically the RTX A4000, A4500, A5000 and A6000, and it turns an unprivileged CUDA program into a root shell on the host.</p><h2 id="an-attack-that-matters-much-more-than-its-predecessors">An attack that matters much more than its predecessors</h2><p>Rowhammer works by repeatedly activating a DRAM row until charge leaks from cells in the physically adjacent rows and flips their bits. The attacker never touches the victim's data directly, making it an excellent precursor to tampering, sandbox escape, and privilege escalation, among other things.</p><p>This approach is possible despite an in-chip countermeasure called TRR that accompanies ECC-enabled chips on these GPUs. TRR aims to prevent Rowhammer attacks by tracking how frequently specific memory rows are activated and automatically refreshing adjacent rows before a malicious bit flip can occur.</p><p>This approach works well on paper and, when Rowhammer attacks hammer uniformly, offers decent protection. The problem arises when approaches such as GPUThor use non-uniform hammering, which is much more likely to succeed. Non-uniform hammering is not exactly new, having <a href="https://www.techradar.com/news/your-ddr4-memory-could-be-facing-serious-assaults" target="_blank">already succeeded on the CPU side of the spectrum</a> thanks to the well-documented Blacksmith attack vector.</p><p>GPUThor is the third attack from broadly the same group in eighteen months, following GPUHammer in 2025 and GPUBreach earlier this year, and it matters because the previous two stopped working the moment a user typed the command to enable ECC.</p><p>ECC was essentially Nvidia's go-to response to reported Rowhammer attacks, but it may no longer be a solution in its current state. By hammering non-uniformly, the researchers opened another attack vector for Nvidia's Ampere-based GPUs, which are overwhelmingly affected by the technique.</p><p>With ECC disabled, GPUThor produced 72,000 to 377,000 bit flips per gigabyte across four Ampere-based cards, with Nvidia's A5000 being reported as the most vulnerable. That approaches the roughly 550,000 flips per gigabyte that Blacksmith achieves on DDR4, which is cause for concern: GPU Rowhammer is now in the same league as CPU Rowhammer.</p><p>When enabled, the researchers said ECC protectors reduced, but did not completely mitigate, the issue: they delivered double-bit errors and 2 triple-bit errors that the technique 'fixed' by choosing the wrong value.</p><p>On <a href="https://www.techradar.com/news/nvidia-launches-ampere-for-graphics-professionals-rtx-a40-and-rtx-a6000-cards" target="_blank">an RTX A6000 with ECC enabled</a>, the GPUThor technique forces one GPU reset every 2 hours, killing all running processes on the GPU; as a result, the GPU flags itself as RMA-read within a day.</p><p>The team disclosed the attack pattern to Nvidia on 29 April 2026 and subsequently to Google, Microsoft and AWS, and held the work until the 25th of August. A code release is scheduled for the 15th of November, even though there is currently no CVE information or patch being deployed to address the issue.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/another-rowhammer-attack-has-been-detected-and-nvidia-workstation-gpus-are-firmly-in-the-firing-line</link>
                                                                            <description>
                            <![CDATA[ Nvidia spent a year telling people ECC was the answer to GPU Rowhammer. GPUThor might have just proved them wrong. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CEkDYAAjrtiexrJ9e5NzAD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D9pZcgdPinp5ty7pPDjKeY-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/D9pZcgdPinp5ty7pPDjKeY-1280-80.png">
                                                            <media:credit><![CDATA[Nvidia]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Nvidia]]></media:description>                                                            <media:text><![CDATA[Nvidia]]></media:text>
                                <media:title type="plain"><![CDATA[Nvidia]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D9pZcgdPinp5ty7pPDjKeY-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>GPUThor is the first Rowhammer attack to defeat ECC on Nvidia GPUs and reach a root shell on the host</strong></li><li><strong>It affects four Ampere workstation cards with GDDR6 memory, the RTX A4000, A4500, A5000 and A6000</strong></li><li><strong>Non-uniform hammering, enabled by defeating GPU memory coalescing and finding that Target Row Refresh (TRR) mitigations fire once every 72 refresh intervals, delivers effectively 6.6 times the hammering intensity of prior attacks</strong></li></ul><p>Four researchers at the University of Toronto have disclosed GPUThor, a Rowhammer technique that breaks the error correction Nvidia has spent the past year recommending as the defense against exactly this class of attack.</p><p>Chris S. Lin, Joyce Qu, Aditya Rajeev and Gururaj Saileshwar are expected to present the <a href="https://gputhor.com/" target="_blank" rel="nofollow">paper</a> outlining their approach and subsequent findings at ACM CCS 2026.</p><p>The attacks target Ampere-generation workstation cards with GDDR6 memory, specifically the RTX A4000, A4500, A5000 and A6000, and it turns an unprivileged CUDA program into a root shell on the host.</p><h2 id="an-attack-that-matters-much-more-than-its-predecessors">An attack that matters much more than its predecessors</h2><p>Rowhammer works by repeatedly activating a DRAM row until charge leaks from cells in the physically adjacent rows and flips their bits. The attacker never touches the victim's data directly, making it an excellent precursor to tampering, sandbox escape, and privilege escalation, among other things.</p><p>This approach is possible despite an in-chip countermeasure called TRR that accompanies ECC-enabled chips on these GPUs. TRR aims to prevent Rowhammer attacks by tracking how frequently specific memory rows are activated and automatically refreshing adjacent rows before a malicious bit flip can occur.</p><p>This approach works well on paper and, when Rowhammer attacks hammer uniformly, offers decent protection. The problem arises when approaches such as GPUThor use non-uniform hammering, which is much more likely to succeed. Non-uniform hammering is not exactly new, having <a href="https://www.techradar.com/news/your-ddr4-memory-could-be-facing-serious-assaults" target="_blank">already succeeded on the CPU side of the spectrum</a> thanks to the well-documented Blacksmith attack vector.</p><p>GPUThor is the third attack from broadly the same group in eighteen months, following GPUHammer in 2025 and GPUBreach earlier this year, and it matters because the previous two stopped working the moment a user typed the command to enable ECC.</p><p>ECC was essentially Nvidia's go-to response to reported Rowhammer attacks, but it may no longer be a solution in its current state. By hammering non-uniformly, the researchers opened another attack vector for Nvidia's Ampere-based GPUs, which are overwhelmingly affected by the technique.</p><p>With ECC disabled, GPUThor produced 72,000 to 377,000 bit flips per gigabyte across four Ampere-based cards, with Nvidia's A5000 being reported as the most vulnerable. That approaches the roughly 550,000 flips per gigabyte that Blacksmith achieves on DDR4, which is cause for concern: GPU Rowhammer is now in the same league as CPU Rowhammer.</p><p>When enabled, the researchers said ECC protectors reduced, but did not completely mitigate, the issue: they delivered double-bit errors and 2 triple-bit errors that the technique 'fixed' by choosing the wrong value.</p><p>On <a href="https://www.techradar.com/news/nvidia-launches-ampere-for-graphics-professionals-rtx-a40-and-rtx-a6000-cards" target="_blank">an RTX A6000 with ECC enabled</a>, the GPUThor technique forces one GPU reset every 2 hours, killing all running processes on the GPU; as a result, the GPU flags itself as RMA-read within a day.</p><p>The team disclosed the attack pattern to Nvidia on 29 April 2026 and subsequently to Google, Microsoft and AWS, and held the work until the 25th of August. A code release is scheduled for the 15th of November, even though there is currently no CVE information or patch being deployed to address the issue.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Two major security flaws are affecting more than six million WordPress websites ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Wordfence discloses two critical flaws in Elementor Pro and Super Forms</strong></li><li><strong>Bugs allow unauthenticated arbitrary file uploads, enabling remote code execution; both patched recently</strong></li><li><strong>Exploitation attempts already exceed 440,000</strong></li></ul><p>More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild. </p><p>Security researchers Wordfence disclosed finding two flaws, one in Elementor Pro, and one in Super Forms - two popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugins</a>. </p><p><a href="https://www.techradar.com/reviews/elementor" target="_blank">Elementor Pro</a> is a commercial plugin that allows users to build websites using drag-and-drop elements instead of code. With it, they can add advanced widgets, templates, different forms, popups, and more. It is quite a popular solution with more than six million websites actively using it.</p><h2 id="two-bugs-hundreds-of-thousands-of-attacks">Two bugs, hundreds of thousands of attacks</h2><p>According to Wordfence, up until recently, it was vulnerable to an “unrestricted file type upload” bug in all versions up to, and including, 4.2.1. “This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained. “This requires that the targeted site has published a page containing an Elementor Pro Form widget with at least one non-required File Upload field.”</p><p>The bug is tracked as CVE-2026-32475, carries a severity score of 9.8/10 (critical), and was patched in mid-August 2026. So far, Wordfence alone blocked more than 190,000 exploit attempts.</p><p>At roughly the same time, the researchers also reported finding a flaw in Super Forms, a form builder plugin that lets users create and manage forms using a drag-and-drop interface. This plugin, with some 13,000 active installations, contained a bug that allowed arbitrary file upload in all versions up to, and including, 6.3.313.</p><p>“This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained.</p><p>This one is tracked as CVE-2026-14894, also carries a severity score of 9.8/10 (critical) and it, too, was patched a few weeks ago. For this flaw, Wordfence observed more than 250,000 exploitation attempts meaning that cumulatively, these two resulted in 440,000 attacks already. </p><p>Given the widespread adoption of these plugins, and the fact that the flaws are being actively leveraged, users are advised to apply the fixes without delay.</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html" target="_blank"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/two-major-security-flaws-are-affecting-more-than-six-million-wordpress-websites</link>
                                                                            <description>
                            <![CDATA[ Patches are available, so WordPress users should hurry up and apply them. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9ECcHJPTq7j6ouvCBPkCyJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 17:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Wordfence discloses two critical flaws in Elementor Pro and Super Forms</strong></li><li><strong>Bugs allow unauthenticated arbitrary file uploads, enabling remote code execution; both patched recently</strong></li><li><strong>Exploitation attempts already exceed 440,000</strong></li></ul><p>More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild. </p><p>Security researchers Wordfence disclosed finding two flaws, one in Elementor Pro, and one in Super Forms - two popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugins</a>. </p><p><a href="https://www.techradar.com/reviews/elementor" target="_blank">Elementor Pro</a> is a commercial plugin that allows users to build websites using drag-and-drop elements instead of code. With it, they can add advanced widgets, templates, different forms, popups, and more. It is quite a popular solution with more than six million websites actively using it.</p><h2 id="two-bugs-hundreds-of-thousands-of-attacks">Two bugs, hundreds of thousands of attacks</h2><p>According to Wordfence, up until recently, it was vulnerable to an “unrestricted file type upload” bug in all versions up to, and including, 4.2.1. “This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained. “This requires that the targeted site has published a page containing an Elementor Pro Form widget with at least one non-required File Upload field.”</p><p>The bug is tracked as CVE-2026-32475, carries a severity score of 9.8/10 (critical), and was patched in mid-August 2026. So far, Wordfence alone blocked more than 190,000 exploit attempts.</p><p>At roughly the same time, the researchers also reported finding a flaw in Super Forms, a form builder plugin that lets users create and manage forms using a drag-and-drop interface. This plugin, with some 13,000 active installations, contained a bug that allowed arbitrary file upload in all versions up to, and including, 6.3.313.</p><p>“This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained.</p><p>This one is tracked as CVE-2026-14894, also carries a severity score of 9.8/10 (critical) and it, too, was patched a few weeks ago. For this flaw, Wordfence observed more than 250,000 exploitation attempts meaning that cumulatively, these two resulted in 440,000 attacks already. </p><p>Given the widespread adoption of these plugins, and the fact that the flaws are being actively leveraged, users are advised to apply the fixes without delay.</p><p><em>Via </em><a href="https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ G7 tells businesses to get ready for quantum cybersecurity threats ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>G7 urges governments and organizations to begin transitioning to quantum‑resistant encryption</strong></li><li><strong>Warning highlights risk from future quantum computers able to break current standards like AES</strong></li><li><strong>Guidance: inventory cryptographic assets, prioritize critical systems, and adopt phased PQC strategies</strong></li></ul><p>The G7, a collection of some of the world’s most powerful economies, is urging organizations to adopt quantum-resistant encryption as soon as possible and minimize the risk of losing sensitive data to technologically advanced threat actors.</p><p>Virtually every industry in the world today relies on encryption (the process of converting readable data into scrambled, unreadable data so that only someone with the correct key can decode and access it) to protect sensitive information. Banks, telecommunications providers, defense organizations, and practically everyone else are using some form of encryption - most probably AES (Advanced Encryption Standard).</p><p>Decrypting the protected data without the encryption key is considered almost impossible, since the computational effort necessary to pull it off would simply be too large. However, since quantum computers work on a fundamentally different principle, it is believed that once they are mature enough, they will be able to “crack” today’s encryption standards. </p><h2 id="g7-39-s-advice">G7's advice</h2><p>Now, the G7 has <a href="https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action" target="_blank" rel="nofollow">urged</a> government and organizations to remain ahead of the curve by deploying “quantum-resistant encryption”:</p><p>“To protect themselves from the threat brought by CRQCs (cryptographically relevant quantum computers), organizations should begin planning their PQC transition now and should aim to complete their transitions within any the timelines set out by their national cybersecurity authorities,” the warning reads.</p><p>“In addition to quantum-related risks, organizations that delay their PQC transition may lose competitive advantage or may be excluded from contracting opportunities, including public procurement.”</p><p>The G7 advises governments and organizations to take a number of steps, including identifying critical systems and prioritizing them. They should adopt a phased and risk-based strategy, start their transition early, and inventory their cryptographic assets. They should also map their dependencies and develop a transition plan.</p><p>“To limit transition-related costs, they should opt to purchase products that integrate PQC and replace their systems with quantum-safe ones as part of their standard renewal schedule. As such, starting the transition early could result in lower migration costs overall. Planning and conducting their PQC transition properly would enable organizations to prevent insecure implementations and avoid increased exposure to conventional cyber threats.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/g7-tells-businesses-to-get-ready-for-quantum-cybersecurity-threats</link>
                                                                            <description>
                            <![CDATA[ Organizations late to the migration could lose contracting opportunities, G7 warns. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2ZkfdmUW73vAcJc8nb3TLL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UVm4pWzxzFfM3waNQDdPrD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 16:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UVm4pWzxzFfM3waNQDdPrD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Quantum computing concept. Digital communication network. Technological abstract.]]></media:description>                                                            <media:text><![CDATA[Quantum computing concept. Digital communication network. Technological abstract.]]></media:text>
                                <media:title type="plain"><![CDATA[Quantum computing concept. Digital communication network. Technological abstract.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UVm4pWzxzFfM3waNQDdPrD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>G7 urges governments and organizations to begin transitioning to quantum‑resistant encryption</strong></li><li><strong>Warning highlights risk from future quantum computers able to break current standards like AES</strong></li><li><strong>Guidance: inventory cryptographic assets, prioritize critical systems, and adopt phased PQC strategies</strong></li></ul><p>The G7, a collection of some of the world’s most powerful economies, is urging organizations to adopt quantum-resistant encryption as soon as possible and minimize the risk of losing sensitive data to technologically advanced threat actors.</p><p>Virtually every industry in the world today relies on encryption (the process of converting readable data into scrambled, unreadable data so that only someone with the correct key can decode and access it) to protect sensitive information. Banks, telecommunications providers, defense organizations, and practically everyone else are using some form of encryption - most probably AES (Advanced Encryption Standard).</p><p>Decrypting the protected data without the encryption key is considered almost impossible, since the computational effort necessary to pull it off would simply be too large. However, since quantum computers work on a fundamentally different principle, it is believed that once they are mature enough, they will be able to “crack” today’s encryption standards. </p><h2 id="g7-39-s-advice">G7's advice</h2><p>Now, the G7 has <a href="https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action" target="_blank" rel="nofollow">urged</a> government and organizations to remain ahead of the curve by deploying “quantum-resistant encryption”:</p><p>“To protect themselves from the threat brought by CRQCs (cryptographically relevant quantum computers), organizations should begin planning their PQC transition now and should aim to complete their transitions within any the timelines set out by their national cybersecurity authorities,” the warning reads.</p><p>“In addition to quantum-related risks, organizations that delay their PQC transition may lose competitive advantage or may be excluded from contracting opportunities, including public procurement.”</p><p>The G7 advises governments and organizations to take a number of steps, including identifying critical systems and prioritizing them. They should adopt a phased and risk-based strategy, start their transition early, and inventory their cryptographic assets. They should also map their dependencies and develop a transition plan.</p><p>“To limit transition-related costs, they should opt to purchase products that integrate PQC and replace their systems with quantum-safe ones as part of their standard renewal schedule. As such, starting the transition early could result in lower migration costs overall. Planning and conducting their PQC transition properly would enable organizations to prevent insecure implementations and avoid increased exposure to conventional cyber threats.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US military troops can still be hit by targeted attacks despite disabling ad tracking on their devices — and leaders aren't happy ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>US military branches disable ad tracking on government‑issued devices after warning</strong></li><li><strong>Location data from personal devices still poses risks; past data remains for sale</strong></li><li><strong>Senators urge DoD inspector general to review policies and stop servicemember data exposure</strong></li></ul><p>More than 20 years ago, Jason Bourne was smashing mobile phones to prevent being tracked by his adversaries - and the US Department of Defense (DoD) has realized it should probably do something similar.</p><p>In May 2026, Senator Ron Wyden mailed the DoD (among others), informing the agency that foreign powers were using commercial location data to target US troops - and now, Wyden has shared the responses he received from the US Army, Air Force, Navy, Marine Corps, and Special Operations Command, all of which have disabled advertising tracking across their government-issued devices, including Apple and Android smartphones, and Windows computers. </p><p>Some branches did it earlier this year, while the Air Force allegedly concluded the efforts in July 2026 - and while Wyden praised the move, he also suggested it is not enough, and that further steps must be taken in order to protect US troops stationed abroad.</p><h2 id="evaluating-the-leaked-files">Evaluating the leaked files</h2><p>“We commend these service branches for implementing this cybersecurity defensive best practice on government devices,” Wyden and Senator Pat Harrigan wrote. “However, recent reports regarding the continued availability of commercial location data originating from DoD facilities raise troubling questions.”</p><p>Apparently, despite disabling these features and placing the troops out of reach of <a href="https://www.techradar.com/pro/best-data-removal-services-of-year" target="_blank">data brokers</a> and similar commercial entities, the data that was gathered earlier remains available for sale, which still presents a risk. </p><p>“The members suggested data could continue to be available for several reasons, including that commercial data available originates from personal devices, not government phones, that are carried by servicemembers and government contractors,” a report on <a href="https://www.wyden.senate.gov/news/press-releases/wyden-and-harrigan-call-for-investigation-into-dod-efforts-to-protect-us-servicemembers-from-commercial-location-data-threats" target="_blank" rel="nofollow">Wyden’s website</a> reads.</p><p>“Wyden and Harrigan called on the DOD inspector general to examine commercial location data that DOD and other government agencies have already purchased to determine why existing policies have not prevented servicemembers location data from being sold online, and to recommend policy changes to better protect US personnel.”</p><p><em>Via </em><a href="https://techcrunch.com/2026/09/04/us-military-disabled-ad-tracking-on-troops-devices-following-reports-of-targeted-attacks/" target="_blank"><em>TechCrunch</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/us-military-troops-can-still-be-hit-by-targeted-attacks-despite-disabling-ad-tracking-on-their-devices-and-leaders-arent-happy</link>
                                                                            <description>
                            <![CDATA[ Government-issued devices are safe - but what about private devices? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qxo8CGkgGxxCnCDCgsK3sd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KcuQeJXg8Wj7ktEdTA3XhC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 15:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KcuQeJXg8Wj7ktEdTA3XhC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / NATALIA KOLESNIKOVA]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Belarusian border guard with a service dog]]></media:description>                                                            <media:text><![CDATA[A Belarusian border guard with a service dog]]></media:text>
                                <media:title type="plain"><![CDATA[A Belarusian border guard with a service dog]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KcuQeJXg8Wj7ktEdTA3XhC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>US military branches disable ad tracking on government‑issued devices after warning</strong></li><li><strong>Location data from personal devices still poses risks; past data remains for sale</strong></li><li><strong>Senators urge DoD inspector general to review policies and stop servicemember data exposure</strong></li></ul><p>More than 20 years ago, Jason Bourne was smashing mobile phones to prevent being tracked by his adversaries - and the US Department of Defense (DoD) has realized it should probably do something similar.</p><p>In May 2026, Senator Ron Wyden mailed the DoD (among others), informing the agency that foreign powers were using commercial location data to target US troops - and now, Wyden has shared the responses he received from the US Army, Air Force, Navy, Marine Corps, and Special Operations Command, all of which have disabled advertising tracking across their government-issued devices, including Apple and Android smartphones, and Windows computers. </p><p>Some branches did it earlier this year, while the Air Force allegedly concluded the efforts in July 2026 - and while Wyden praised the move, he also suggested it is not enough, and that further steps must be taken in order to protect US troops stationed abroad.</p><h2 id="evaluating-the-leaked-files">Evaluating the leaked files</h2><p>“We commend these service branches for implementing this cybersecurity defensive best practice on government devices,” Wyden and Senator Pat Harrigan wrote. “However, recent reports regarding the continued availability of commercial location data originating from DoD facilities raise troubling questions.”</p><p>Apparently, despite disabling these features and placing the troops out of reach of <a href="https://www.techradar.com/pro/best-data-removal-services-of-year" target="_blank">data brokers</a> and similar commercial entities, the data that was gathered earlier remains available for sale, which still presents a risk. </p><p>“The members suggested data could continue to be available for several reasons, including that commercial data available originates from personal devices, not government phones, that are carried by servicemembers and government contractors,” a report on <a href="https://www.wyden.senate.gov/news/press-releases/wyden-and-harrigan-call-for-investigation-into-dod-efforts-to-protect-us-servicemembers-from-commercial-location-data-threats" target="_blank" rel="nofollow">Wyden’s website</a> reads.</p><p>“Wyden and Harrigan called on the DOD inspector general to examine commercial location data that DOD and other government agencies have already purchased to determine why existing policies have not prevented servicemembers location data from being sold online, and to recommend policy changes to better protect US personnel.”</p><p><em>Via </em><a href="https://techcrunch.com/2026/09/04/us-military-disabled-ad-tracking-on-troops-devices-following-reports-of-targeted-attacks/" target="_blank"><em>TechCrunch</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI hid AI agent hijacking of German wiki forum for weeks — because its model did the exact same thing in the Hugging Face attack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI hid an incident where a model hijacked a wiki page to use as an AI agent communication board</strong></li><li><strong>The incident was hidden while the company dealt with the fallout of the Hugging Face attack</strong></li><li><strong>The company is now working on a framework for disclosing incidents of 'misalignment'</strong></li></ul><p>OpenAI recently disclosed the details of how one of its AI models <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal" target="_blank">escaped a sandboxed environment</a> and attacked Hugging Face during an evaluation -  and as part of the incident, the models created a messaging board to communicate with each other and influence each other’s reasoning.</p><p>OpenAI has now disclosed that shortly after this incident, agents undergoing testing again escaped their ‘secured’ environment and hijacked an obscure German wiki to use as a messaging board. Per <a href="https://www.reuters.com/world/europe/openai-agents-hijacked-german-website-previously-undisclosed-ai-breakout-this-2026-09-04/" target="_blank" rel="nofollow"><em>Reuters</em></a>, OpenAI leadership kept the incident hidden while they dealt with the fallout from the Hugging Face incident.</p><p>Now that OpenAI has acknowledged its role in the incident, the company has said it is “past time” to put together an incident disclosure pipeline when its models escape testing and slip into third-party networks.</p><h2 id="who-is-at-fault-when-models-do-what-they-re-designed-to-do">Who is at fault when models do what they’re designed to do?</h2><p>Before the two incidents, OpenAI said it, “treated misalignment largely as a research question, which gets communicated in research publications”. But now that models are behaving in previously unknown ways and having real-world impacts, the company said it would change its approach “to expand for this new phase of model capabilities”.</p><p>The company labelled the most recently disclosed incident as “an instance of misalignment similar” to the Hugging Face breach. </p><p>I myself am guilty of reporting on <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in" target="_blank">AI breaking out of containment as going ‘rogue’</a>, but these models are doing exactly what they are designed to do. OpenAI’s detailed disclosure of the Hugging Face incident showed that the models were pushed to try and solve a benchmark test by cheating, which is exactly what caused the cyberattack to happen.</p><p>OpenAI said that both itself and “the larger AI community do not yet have a clear standard for how to report misalignment that shows up during training, evaluation, and deployment, including examples that don’t look like traditional security incidents but could provide insight into AI behavior and future risks”.</p><p>The company added that it is “working on a framework and will share it in upcoming weeks, and in parallel we’re working with dozens of government regulatory agencies worldwide on these issues”.</p><p>“When you combine this 'breakout' with the Hugging face breakout, it's starting to display a pattern,” said Ashley Knowles, Lead Cybersecurity Consultant at Black Hills Information Security. “I struggle here with not getting too doomsday-ish but realistically, this is showing a pattern of concerning behavior.”</p><p>“I'm wondering if this race to become 'first' is undercutting security measures that need to be taken to properly secure and guard AI agents as they're in development. My concern grows when you consider that OpenAI is also resisting further investigation. Adding onto that, the release and promise that Astra can evade human monitoring. The pot is brewing…”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-hid-ai-agent-hijacking-of-german-wiki-forum-for-weeks-because-its-model-did-the-exact-same-thing-in-the-hugging-face-attack</link>
                                                                            <description>
                            <![CDATA[ OpenAI called the incident a 'misalignment' in the model's reasoning and says it is working on a new disclosure framework. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZsqPpUtSY5EUtLWgvr9QcL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bqTLGsRATg4oc47RW3PJbi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 15:19:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bqTLGsRATg4oc47RW3PJbi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/ VCG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI logos]]></media:description>                                                            <media:text><![CDATA[OpenAI logos]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI logos]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bqTLGsRATg4oc47RW3PJbi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI hid an incident where a model hijacked a wiki page to use as an AI agent communication board</strong></li><li><strong>The incident was hidden while the company dealt with the fallout of the Hugging Face attack</strong></li><li><strong>The company is now working on a framework for disclosing incidents of 'misalignment'</strong></li></ul><p>OpenAI recently disclosed the details of how one of its AI models <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal" target="_blank">escaped a sandboxed environment</a> and attacked Hugging Face during an evaluation -  and as part of the incident, the models created a messaging board to communicate with each other and influence each other’s reasoning.</p><p>OpenAI has now disclosed that shortly after this incident, agents undergoing testing again escaped their ‘secured’ environment and hijacked an obscure German wiki to use as a messaging board. Per <a href="https://www.reuters.com/world/europe/openai-agents-hijacked-german-website-previously-undisclosed-ai-breakout-this-2026-09-04/" target="_blank" rel="nofollow"><em>Reuters</em></a>, OpenAI leadership kept the incident hidden while they dealt with the fallout from the Hugging Face incident.</p><p>Now that OpenAI has acknowledged its role in the incident, the company has said it is “past time” to put together an incident disclosure pipeline when its models escape testing and slip into third-party networks.</p><h2 id="who-is-at-fault-when-models-do-what-they-re-designed-to-do">Who is at fault when models do what they’re designed to do?</h2><p>Before the two incidents, OpenAI said it, “treated misalignment largely as a research question, which gets communicated in research publications”. But now that models are behaving in previously unknown ways and having real-world impacts, the company said it would change its approach “to expand for this new phase of model capabilities”.</p><p>The company labelled the most recently disclosed incident as “an instance of misalignment similar” to the Hugging Face breach. </p><p>I myself am guilty of reporting on <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in" target="_blank">AI breaking out of containment as going ‘rogue’</a>, but these models are doing exactly what they are designed to do. OpenAI’s detailed disclosure of the Hugging Face incident showed that the models were pushed to try and solve a benchmark test by cheating, which is exactly what caused the cyberattack to happen.</p><p>OpenAI said that both itself and “the larger AI community do not yet have a clear standard for how to report misalignment that shows up during training, evaluation, and deployment, including examples that don’t look like traditional security incidents but could provide insight into AI behavior and future risks”.</p><p>The company added that it is “working on a framework and will share it in upcoming weeks, and in parallel we’re working with dozens of government regulatory agencies worldwide on these issues”.</p><p>“When you combine this 'breakout' with the Hugging face breakout, it's starting to display a pattern,” said Ashley Knowles, Lead Cybersecurity Consultant at Black Hills Information Security. “I struggle here with not getting too doomsday-ish but realistically, this is showing a pattern of concerning behavior.”</p><p>“I'm wondering if this race to become 'first' is undercutting security measures that need to be taken to properly secure and guard AI agents as they're in development. My concern grows when you consider that OpenAI is also resisting further investigation. Adding onto that, the release and promise that Astra can evade human monitoring. The pot is brewing…”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Stop buying security tools: start buying a system ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Ask a CISO why they bought their newest <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> tool, and they’ll have a clear answer lined up. </p><p>It stops a specific technique, closes a particular gap, or satisfies a compliance requirement. </p><p>However, it's often less clear how the tool fits in with the rest of the stack. </p><p>Does it make the overall system stronger, or simply add another layer of complexity to manage? </p><p>Research indicates most security professionals already believe they’re juggling too many tools, with over half saying they don’t properly integrate together.  </p><p>This is a pattern I call ‘additive by default,’ and it results in stacks that grow without a plan, becoming broader but not necessarily deeper or able to match today’s threats. </p><h2 id="start-with-the-outcome-not-the-technology">Start with the outcome, not the technology </h2><p>I find this additive approach is often due to focusing on specific emerging threats or identified weak points, so decisions are made with a tactical eye rather than a broader strategic view.      </p><p>Part of the problem is that most organizations have never precisely defined the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> outcome they are trying to achieve. Without a shared, specific language for the problem, every new purchase becomes additive, because there is nothing solid to measure it against.      </p><p>Take <a href="https://www.techradar.com/best/best-asset-management-software">asset</a> labelling, which is a core capability most organizations know they need, so they invest in a tool, populate a configuration management database (CMDB), and assign criticality scores. Job done, right? But labelling an asset only answers the question of what it is, and says nothing about how that asset connects to everything around it, or what happens when a policy needs to be enforced against it.      </p><p>Labelling, visibility and enforcement are three distinct jobs, not one. Solve the first and the second and third remain wide open, so another tool gets bought to cover visibility, then another for enforcement. Each purchase solves its own narrow question perfectly well.       </p><p>However, none of them were ever asked to work as a single, continuous capability, because nobody defined that as the actual requirement in the first place.       </p><p>What if <a href="https://www.techradar.com/best/best-software-asset-management-tools">asset management</a> labels fed into visibility views and the same reflected how policy is drafted and then enforced? Now you have a strategic problem solved with interoperable capabilities. </p><h2 id="how-much-of-your-stack-is-really-putting-in-the-work">How much of your stack is really putting in the work? </h2><p>Gartner’s most recent Leadership Perspective Survey saw CISOs noting this as a common issue, with just 20-30% of tool capability actually being used in some cases. The instinctive response to this is to cut the stack down, however, that instinct solves the wrong problem.      </p><p>A good exercise for working out the value of the stack is to evaluate every tool, new or already deployed, against three plain questions.  </p><p>Does it offer continuous validation against a given threat - and what, specifically, does it validate?  Is it still operationally relevant? And is it effective, right now, in the environment you have today? A tool can pass one or two of these and still be failing you.      </p><p>Virtual Local Area Networks (VLANs) are a good example of this. Twenty or thirty years ago, when networks were typically static and everything likely sat inside a single data center, VLAN-based segmentation was genuinely effective. It matched the environment it was built for.       </p><p>That environment has since changed almost beyond recognition. Workloads move between on-premises systems, <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a> and containers, and nothing stays fixed for long. VLANs are still deployed across many stacks today, still technically doing the segmentation job they were built for. Yet their effectiveness has dropped sharply because they offer none of the continuous validation a hybrid, constantly shifting estate actually requires.      </p><p>Effectiveness has an expiry date that has nothing to do with whether the tool still runs. Success should be measured by whether the system as a whole still holds up, not by how many tools remain switched on. </p><h2 id="consolidated-security-not-consolidated-tooling">Consolidated security, not consolidated tooling </h2><p>Gartner identified that most organizations are pursuing a vendor consolidation strategy. While this approach certainly reduces unnecessary spending and keeps budgets under control, it’s not necessarily solving the biggest problem.  </p><p>Consolidated tooling and consolidated security are not the same thing, and it’s an assumption that leads to disappointment. Reducing the number of tools alone achieves little if the underlying processes remain fragmented or teams continue to operate against different objectives. </p><p>No data center I have walked through was built entirely by one manufacturer. Racks, switches, storage and cabling come from a dozen suppliers, yet they operate as one coherent system because they were designed to fit together. Security should work the same way. </p><p>The goal is not necessarily fewer vendors, but every control, whoever built it, feeding into the same continuous picture of identification, visibility and enforcement. </p><h2 id="what-to-ask-instead">What to ask instead </h2><p>Before completing the next security purchase, consider how well a new tool fits into the stack you already have, not just what it claims to do on its own.       </p><p>A tool that deploys cleanly, validates continuously rather than only at go-live, and feeds its findings back into the tools already in place is doing real work. One that arrives as a fresh, isolated source of alerts is just adding to the noise, however good its individual detection rate looks in a demo. That means comparing what the tool was bought to solve against what it is actually delivering today, checking it against newer capabilities, and being willing to redeploy or renegotiate rather than automatically renew or even retire.      </p><p>Ultimately, the strongest security programs are not defined by the number of tools they deploy, nor by the number they eliminate. They're defined by how effectively every control works together when it matters most.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've rounded up the best endpoint protection software suites</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/stop-buying-security-tools-start-buying-a-system</link>
                                                                            <description>
                            <![CDATA[ Security leaders must rethink tool sprawl, prioritizing integration, continuous validation and system-wide effectiveness over consolidation. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YogNqaUbUxnLcYAnberzxG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XbZCTEpjtunPvMj9ySXmWU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 14:23:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Michael Adjei ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XbZCTEpjtunPvMj9ySXmWU-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A file and folder transferring data with a red warning mark indicating malware.]]></media:description>                                                            <media:text><![CDATA[A file and folder transferring data with a red warning mark indicating malware.]]></media:text>
                                <media:title type="plain"><![CDATA[A file and folder transferring data with a red warning mark indicating malware.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XbZCTEpjtunPvMj9ySXmWU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ask a CISO why they bought their newest <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> tool, and they’ll have a clear answer lined up. </p><p>It stops a specific technique, closes a particular gap, or satisfies a compliance requirement. </p><p>However, it's often less clear how the tool fits in with the rest of the stack. </p><p>Does it make the overall system stronger, or simply add another layer of complexity to manage? </p><p>Research indicates most security professionals already believe they’re juggling too many tools, with over half saying they don’t properly integrate together.  </p><p>This is a pattern I call ‘additive by default,’ and it results in stacks that grow without a plan, becoming broader but not necessarily deeper or able to match today’s threats. </p><h2 id="start-with-the-outcome-not-the-technology">Start with the outcome, not the technology </h2><p>I find this additive approach is often due to focusing on specific emerging threats or identified weak points, so decisions are made with a tactical eye rather than a broader strategic view.      </p><p>Part of the problem is that most organizations have never precisely defined the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> outcome they are trying to achieve. Without a shared, specific language for the problem, every new purchase becomes additive, because there is nothing solid to measure it against.      </p><p>Take <a href="https://www.techradar.com/best/best-asset-management-software">asset</a> labelling, which is a core capability most organizations know they need, so they invest in a tool, populate a configuration management database (CMDB), and assign criticality scores. Job done, right? But labelling an asset only answers the question of what it is, and says nothing about how that asset connects to everything around it, or what happens when a policy needs to be enforced against it.      </p><p>Labelling, visibility and enforcement are three distinct jobs, not one. Solve the first and the second and third remain wide open, so another tool gets bought to cover visibility, then another for enforcement. Each purchase solves its own narrow question perfectly well.       </p><p>However, none of them were ever asked to work as a single, continuous capability, because nobody defined that as the actual requirement in the first place.       </p><p>What if <a href="https://www.techradar.com/best/best-software-asset-management-tools">asset management</a> labels fed into visibility views and the same reflected how policy is drafted and then enforced? Now you have a strategic problem solved with interoperable capabilities. </p><h2 id="how-much-of-your-stack-is-really-putting-in-the-work">How much of your stack is really putting in the work? </h2><p>Gartner’s most recent Leadership Perspective Survey saw CISOs noting this as a common issue, with just 20-30% of tool capability actually being used in some cases. The instinctive response to this is to cut the stack down, however, that instinct solves the wrong problem.      </p><p>A good exercise for working out the value of the stack is to evaluate every tool, new or already deployed, against three plain questions.  </p><p>Does it offer continuous validation against a given threat - and what, specifically, does it validate?  Is it still operationally relevant? And is it effective, right now, in the environment you have today? A tool can pass one or two of these and still be failing you.      </p><p>Virtual Local Area Networks (VLANs) are a good example of this. Twenty or thirty years ago, when networks were typically static and everything likely sat inside a single data center, VLAN-based segmentation was genuinely effective. It matched the environment it was built for.       </p><p>That environment has since changed almost beyond recognition. Workloads move between on-premises systems, <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a> and containers, and nothing stays fixed for long. VLANs are still deployed across many stacks today, still technically doing the segmentation job they were built for. Yet their effectiveness has dropped sharply because they offer none of the continuous validation a hybrid, constantly shifting estate actually requires.      </p><p>Effectiveness has an expiry date that has nothing to do with whether the tool still runs. Success should be measured by whether the system as a whole still holds up, not by how many tools remain switched on. </p><h2 id="consolidated-security-not-consolidated-tooling">Consolidated security, not consolidated tooling </h2><p>Gartner identified that most organizations are pursuing a vendor consolidation strategy. While this approach certainly reduces unnecessary spending and keeps budgets under control, it’s not necessarily solving the biggest problem.  </p><p>Consolidated tooling and consolidated security are not the same thing, and it’s an assumption that leads to disappointment. Reducing the number of tools alone achieves little if the underlying processes remain fragmented or teams continue to operate against different objectives. </p><p>No data center I have walked through was built entirely by one manufacturer. Racks, switches, storage and cabling come from a dozen suppliers, yet they operate as one coherent system because they were designed to fit together. Security should work the same way. </p><p>The goal is not necessarily fewer vendors, but every control, whoever built it, feeding into the same continuous picture of identification, visibility and enforcement. </p><h2 id="what-to-ask-instead">What to ask instead </h2><p>Before completing the next security purchase, consider how well a new tool fits into the stack you already have, not just what it claims to do on its own.       </p><p>A tool that deploys cleanly, validates continuously rather than only at go-live, and feeds its findings back into the tools already in place is doing real work. One that arrives as a fresh, isolated source of alerts is just adding to the noise, however good its individual detection rate looks in a demo. That means comparing what the tool was bought to solve against what it is actually delivering today, checking it against newer capabilities, and being willing to redeploy or renegotiate rather than automatically renew or even retire.      </p><p>Ultimately, the strongest security programs are not defined by the number of tools they deploy, nor by the number they eliminate. They're defined by how effectively every control works together when it matters most.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've rounded up the best endpoint protection software suites</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware hackers dump 1.4 million stolen records from German government ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Rhysida ransomware group breached Berlin’s state government, stealing 1.44 million files weighing in at around 5.8TB</strong></li><li><strong>Attackers demanded 30 BTC (~$2.3M); Berlin refused, leading to full leak online</strong></li><li><strong>Leaked data reportedly includes water supply info, staff records, and emergency plans</strong></li></ul><p>A cybercriminal group known as Rhysida allegedly broke into the network of Berlin's state government and exfiltrated 1.44 million files. They then tried to extort the government entity for money and when that failed, they leaked it all into the dark web.</p><p>According to multiple sources, the group first claimed responsibility for the attack on an underground forum, where it shared a small sample of the stolen files and demanded Berlin pay 30 bitcoin (around $2.3 million) in exchange for deleting the files.</p><p>Berlin recognized the attack in a press release, and said it would not be negotiating with the attackers, and instead launched a full-scale investigation into the incident, which it described as an “extremely serious crime and an attack on the state of Berlin.”</p><h2 id="evaluating-the-leaked-files-2">Evaluating the leaked files</h2><p>A few days later, <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">Rhysida</a> decided to leak it all online - and Berlin is now reviewing the leaked files and is assessing the damage:</p><p>“After the publication of the stolen data from the Berlin administration, these files are being evaluated at full speed,” a press release, published on the Berlin.de website (machine-translated), reads. </p><p>“An additional steering unit has been set up in the Senate Chancellery under the leadership of the Chief Digital Officer (CDO), Florian Hauer, which coordinates the review, examination and evaluation of the leaked data and supports the two Senate administrations concerned in informing and advising the affected citizens and companies.”</p><p>According to German public broadcaster Tagesschau, the archive counts 1.44 million files and totals 5.8 terabytes. At the same time, the Chaos Computer Club (Germany's largest and best-known hacker organization) claims the archive contains sensitive data on the city’s water supply, personal data of admin staff, various employment references, and emergency plans. </p><p><em>Via </em><a href="https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/" target="_blank"><em>Reuters</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/ransomware-hackers-dump-1-4-million-stolen-records-from-german-government</link>
                                                                            <description>
                            <![CDATA[ This is an "extremely serious crime" and an attack on Berlin, the government says. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sTAtVCtttosNejBRf3aDA4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3HY9z6jmzyHFPZFAtvox2a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 13:35:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3HY9z6jmzyHFPZFAtvox2a-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3HY9z6jmzyHFPZFAtvox2a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Rhysida ransomware group breached Berlin’s state government, stealing 1.44 million files weighing in at around 5.8TB</strong></li><li><strong>Attackers demanded 30 BTC (~$2.3M); Berlin refused, leading to full leak online</strong></li><li><strong>Leaked data reportedly includes water supply info, staff records, and emergency plans</strong></li></ul><p>A cybercriminal group known as Rhysida allegedly broke into the network of Berlin's state government and exfiltrated 1.44 million files. They then tried to extort the government entity for money and when that failed, they leaked it all into the dark web.</p><p>According to multiple sources, the group first claimed responsibility for the attack on an underground forum, where it shared a small sample of the stolen files and demanded Berlin pay 30 bitcoin (around $2.3 million) in exchange for deleting the files.</p><p>Berlin recognized the attack in a press release, and said it would not be negotiating with the attackers, and instead launched a full-scale investigation into the incident, which it described as an “extremely serious crime and an attack on the state of Berlin.”</p><h2 id="evaluating-the-leaked-files-2">Evaluating the leaked files</h2><p>A few days later, <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">Rhysida</a> decided to leak it all online - and Berlin is now reviewing the leaked files and is assessing the damage:</p><p>“After the publication of the stolen data from the Berlin administration, these files are being evaluated at full speed,” a press release, published on the Berlin.de website (machine-translated), reads. </p><p>“An additional steering unit has been set up in the Senate Chancellery under the leadership of the Chief Digital Officer (CDO), Florian Hauer, which coordinates the review, examination and evaluation of the leaked data and supports the two Senate administrations concerned in informing and advising the affected citizens and companies.”</p><p>According to German public broadcaster Tagesschau, the archive counts 1.44 million files and totals 5.8 terabytes. At the same time, the Chaos Computer Club (Germany's largest and best-known hacker organization) claims the archive contains sensitive data on the city’s water supply, personal data of admin staff, various employment references, and emergency plans. </p><p><em>Via </em><a href="https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05/" target="_blank"><em>Reuters</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using 'invisible' Unicode characters to sneak phishing lures into emails ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft reports phishing campaign using ASCII smuggling to bypass spam filters</strong></li><li><strong>Attackers insert invisible characters into keywords, tricking filters and AI agents</strong></li><li><strong>Defenders should normalize Unicode tags and flag unexpected invisible code points as suspicious</strong></li></ul><p>Cybercriminals are using the “ASCII smuggling” technique to make sure phishing emails pass security filters and land in people’s inboxes, experts have warned.</p><p>ASCII is a character encoding standard that turns characters and words humans can read into numeric values that computers can understand. It can also be used to create characters that aren’t even displayed on the screen (essentially “invisible” ones) but can still be read by the machine.</p><p>In a new <a href="https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/" target="_blank" rel="nofollow">report</a>, security researchers from Microsoft found crooks are abusing this fact to distribute phishing emails. Most email providers offer solutions that filter out spam emails. These filters look for certain keywords and phrases, such as “funding”, “credit”, “loan”, and similar, and automatically send such emails to the spam folder. </p><h2 id="ongoing-campaign">Ongoing campaign</h2><p>By adding a set of invisible characters in the middle of these keywords, the attackers can break them apart and thus “confuse” the filters. </p><p>While the human sees the word “funding” in their email, the security solution is seeing something like “fun[a long string of characters]ding”. This technique has been adopted from prompt injection attacks, where crooks would use ASCII smuggling to deliver malicious and invisible prompts in the emails. </p><p>Therefore, when a victim asks their AI agent to summarize the email, it ends up working on a prompt that could be anything from extracting sensitive data, to deploying <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. </p><p>Microsoft is saying the campaign has been ongoing for months, and while it peaked in February 2026 with more than 2.3 million emails every day, and has been in decline ever since, it remains active to this day. In early February, Microsoft observed a cluster of almost 150 sender domains, all themed around finance. These domains accounted for almost all (96%) of all the spam emails Defender for Office 365 flagged under ASCII smuggling.</p><p>Defending sounds relatively simple, though. IT teams should normalize Unicode tag characters and other invisible code points before applying any keyword detection. They should also consider all unexpected tag-block characters as suspicious.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/hackers-are-using-invisible-unicode-characters-to-sneak-phishing-lures-into-emails</link>
                                                                            <description>
                            <![CDATA[ A technique used in prompt injection attacks has made it into phishing, Microsoft has warned. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kpbZtKyjta2kiuQw3KPbBZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 13:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing]]></media:description>                                                            <media:text><![CDATA[Phishing]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft reports phishing campaign using ASCII smuggling to bypass spam filters</strong></li><li><strong>Attackers insert invisible characters into keywords, tricking filters and AI agents</strong></li><li><strong>Defenders should normalize Unicode tags and flag unexpected invisible code points as suspicious</strong></li></ul><p>Cybercriminals are using the “ASCII smuggling” technique to make sure phishing emails pass security filters and land in people’s inboxes, experts have warned.</p><p>ASCII is a character encoding standard that turns characters and words humans can read into numeric values that computers can understand. It can also be used to create characters that aren’t even displayed on the screen (essentially “invisible” ones) but can still be read by the machine.</p><p>In a new <a href="https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/" target="_blank" rel="nofollow">report</a>, security researchers from Microsoft found crooks are abusing this fact to distribute phishing emails. Most email providers offer solutions that filter out spam emails. These filters look for certain keywords and phrases, such as “funding”, “credit”, “loan”, and similar, and automatically send such emails to the spam folder. </p><h2 id="ongoing-campaign">Ongoing campaign</h2><p>By adding a set of invisible characters in the middle of these keywords, the attackers can break them apart and thus “confuse” the filters. </p><p>While the human sees the word “funding” in their email, the security solution is seeing something like “fun[a long string of characters]ding”. This technique has been adopted from prompt injection attacks, where crooks would use ASCII smuggling to deliver malicious and invisible prompts in the emails. </p><p>Therefore, when a victim asks their AI agent to summarize the email, it ends up working on a prompt that could be anything from extracting sensitive data, to deploying <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. </p><p>Microsoft is saying the campaign has been ongoing for months, and while it peaked in February 2026 with more than 2.3 million emails every day, and has been in decline ever since, it remains active to this day. In early February, Microsoft observed a cluster of almost 150 sender domains, all themed around finance. These domains accounted for almost all (96%) of all the spam emails Defender for Office 365 flagged under ASCII smuggling.</p><p>Defending sounds relatively simple, though. IT teams should normalize Unicode tag characters and other invisible code points before applying any keyword detection. They should also consider all unexpected tag-block characters as suspicious.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Save up to 50% off Keeper plans this September — protect your passwords with half price Personal plans, and a third-off Business plans ]]></title>
                                                                                                <dc:content><![CDATA[ <p>You probably have tens, if not hundreds of passwords floating around across all the online accounts you use every week. In fact, the average person has over 150 passwords. It's not easy to remember them all, making it more attractive to keep them simple and similar - but that can lead to a serious chain of account theft.</p><p>That's why password managers like Keeper exist. They generate strong passwords and store them passwords in a secured vault to keep them safe from hackers and prying eyes. They even autofill your credentials to make logging in to your account faster and easier.</p><p><a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper has cut prices on its personal, family, and business starter plans by up to 50%</a>. Keeper regularly scores highly in our reviews, and includes great features across Personal, Family, and Business plans.</p><div class="product"><a data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:131px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="TbfSUDRsU8NdGFXVDRFiSW" name="keeper!.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TbfSUDRsU8NdGFXVDRFiSW-1920-80.jpg" mos="" align="middle" fullscreen="" width="131" height="131" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25=""><strong>Get up to 50% off Keeper plans</strong></a></p><p>Keeper is offering 50% off its Personal and Family plans, making it even more affordable to secure both personal and household accounts. The Family plan covers multiple users with five secured vaults, making it perfect for shared accounts without the hassle of mixing browsers and reusing passwords.</p><p>Keeper Business Starter is discounted by 30%, and is an excellent choice for small teams looking for a credentials control platform without the complexity and hassle of enduring an enterprise rollout. It includes centralized management, secure password sharing, and role-based access, cleanly organizing your passwords without unnecessary complications.</p><p>The full terms and pricing are available on the <a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper site</a>.<a class="view-deal button" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25="">View Deal</a></p></div><h2 id="why-we-recommend-keeper">Why we recommend Keeper</h2><p>Our <a href="https://www.techradar.com/reviews/keeper-password-manager" target="_blank">Keeper review</a> highlights the platform's zero knowledge architecture and device level encryption that helps keep your password vault secured against unwanted intrusions.</p><p>Where Keeper really shone was in our usability and convenience testing. We loved how Keeper uses biometric security to access your vault, rather than requiring a master password with each log in. By using a facial scan or fingerprint to verify that its actually you accessing your vault, it adds a fast but secure method of verification to ensure its you, and not a nefarious actor.</p><p>For households, the Family Plan includes five private vaults, allowing you to quickly share Wi-Fi or streaming passwords using Keeper's shared vaults.</p><p>The Business Starter plan covers 5 users, covering an unlimited devices, shared team folders, user activity reporting for IT admins, and a free Family Plan for every team member.</p><p>These discounts apply to the first year only, so the value is highest for new customers or anyone switching from a monthly plan. After that, pricing goes back to standard rates.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/save-up-to-50-percent-off-keeper-plans-this-september-protect-your-passwords-with-half-price-personal-plans-and-a-third-off-business-plans</link>
                                                                            <description>
                            <![CDATA[ Keeper is one of the best solutions to password storage and security, with up to 50% off across Personal, Family, and Business plans ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">A3tb9XngX6pNeDLcj6Au2h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 13:17:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:description>                                                            <media:text><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:text>
                                <media:title type="plain"><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>You probably have tens, if not hundreds of passwords floating around across all the online accounts you use every week. In fact, the average person has over 150 passwords. It's not easy to remember them all, making it more attractive to keep them simple and similar - but that can lead to a serious chain of account theft.</p><p>That's why password managers like Keeper exist. They generate strong passwords and store them passwords in a secured vault to keep them safe from hackers and prying eyes. They even autofill your credentials to make logging in to your account faster and easier.</p><p><a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper has cut prices on its personal, family, and business starter plans by up to 50%</a>. Keeper regularly scores highly in our reviews, and includes great features across Personal, Family, and Business plans.</p><div class="product"><a data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:131px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="TbfSUDRsU8NdGFXVDRFiSW" name="keeper!.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TbfSUDRsU8NdGFXVDRFiSW-1920-80.jpg" mos="" align="middle" fullscreen="" width="131" height="131" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25=""><strong>Get up to 50% off Keeper plans</strong></a></p><p>Keeper is offering 50% off its Personal and Family plans, making it even more affordable to secure both personal and household accounts. The Family plan covers multiple users with five secured vaults, making it perfect for shared accounts without the hassle of mixing browsers and reusing passwords.</p><p>Keeper Business Starter is discounted by 30%, and is an excellent choice for small teams looking for a credentials control platform without the complexity and hassle of enduring an enterprise rollout. It includes centralized management, secure password sharing, and role-based access, cleanly organizing your passwords without unnecessary complications.</p><p>The full terms and pricing are available on the <a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper site</a>.<a class="view-deal button" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="db47be5e-aabd-11f1-934c-7dc2c46ec87a" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25="">View Deal</a></p></div><h2 id="why-we-recommend-keeper">Why we recommend Keeper</h2><p>Our <a href="https://www.techradar.com/reviews/keeper-password-manager" target="_blank">Keeper review</a> highlights the platform's zero knowledge architecture and device level encryption that helps keep your password vault secured against unwanted intrusions.</p><p>Where Keeper really shone was in our usability and convenience testing. We loved how Keeper uses biometric security to access your vault, rather than requiring a master password with each log in. By using a facial scan or fingerprint to verify that its actually you accessing your vault, it adds a fast but secure method of verification to ensure its you, and not a nefarious actor.</p><p>For households, the Family Plan includes five private vaults, allowing you to quickly share Wi-Fi or streaming passwords using Keeper's shared vaults.</p><p>The Business Starter plan covers 5 users, covering an unlimited devices, shared team folders, user activity reporting for IT admins, and a free Family Plan for every team member.</p><p>These discounts apply to the first year only, so the value is highest for new customers or anyone switching from a monthly plan. After that, pricing goes back to standard rates.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why is there so much worry about OpenAI Astra, and what issues could ‘recurrent depth’ reasoning cause? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>OpenAI has unveiled a much anticipated AI model which the firm has dubbed ‘GPT-6 Astra’. While the model has improved significantly across benchmark testing and <a href="https://www.techradar.com/pro/gpt-6-astra-lays-the-foundations-for-a-new-way-of-reasoning-a-great-tool-for-businesses-but-experts-have-their-concerns">brings a host of new business features</a>, there is still a dark cloud looming over the new model.</p><p>Off the back of <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in">OpenAI’s accidental hack of Hugging Face</a> and the company’s subsequent efforts to improve how AI agents behave and interact, numerous cybersecurity experts have raised concerns about the model’s new ‘recurrent depth’ reasoning capabilities.</p><p>This new reasoning architecture allows the model to consider a problem multiple times before taking an action, compared to the standard chain-of-thought reasoning used in previous models.</p><h2 id="why-the-concern-about-recurrent-depth-reasoning">Why the concern about recurrent depth reasoning?</h2><p>This new level of reasoning apparently offers improved performance. OpenAI also says it has fixed its models' abilities to circumvent boundaries when performing tests by monitoring the models reasoning and ensuring the model stays aligned within the scope of its task.</p><p>During Astra’s launch event, OpenAI chief scientist Jakub Pachocki said: “We will not accept degradation in our ability to monitor model alignment beyond a certain level. We will withhold scaling until we can regain enough confidence.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9-1920-80.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>But numerous experts believe that the lessons of the Hugging Face incident have not yet been learned, and the model has been released without adequate testing on Astra’s reasoning and monitoring. </p><p>After all, no one thought one of <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal">OpenAI’s models could set up a hidden internet-connected messaging board</a> that allowed AI agents to influence each other's behavior.</p><p>But with Astra being released into the real world, the lessons may have to be learned on the fly.</p><h3 class="article-body__section" id="section-expert-perspectives-on-openai-astra-release"><span>Expert perspectives on OpenAI Astra release</span></h3><ul><li><strong>James Blake, VP of Global Cyber Resiliency Strategy at Cohesity:</strong></li></ul><p><em>The launch of Astra is raising questions again around the safety of Frontier AI. Instead of simply asking whether a model is "safe", organisations now need to ask whether it remains safe across millions of different situations, prompts and interactions. Cyber resilience has traditionally assumed that systems and threat actors behave deterministically. AI systems don’t.</em></p><div><blockquote><p>Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible?</p></blockquote></div><p><em>Advanced models can and will continue to exhibit behaviours that emerge from their optimisation process rather than from explicit programming. We have to move beyond thinking about AI as just another software tool and find ways to ensure these systems remain observable, auditable and governable throughout their lifecycle. </em></p><p><em>The most important question we’ll need to answer in future is one of liability. Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible? The developer that trained the model? The cloud provider operating the infrastructure? Currently the answer is surprisingly unclear. It’s not just about what AI can do: it’s about who is accountable when it does something nobody expected.</em></p><ul><li><strong>Oleksandr Yaremchuk, Co-Founder & CTO at Manifold Security:</strong></li></ul><p><em>OpenAI is calling Astra its most aligned model yet, even as its chief scientist admits monitorability is getting harder as models get more capable. Evidently, Astra hides its reasoning in the majority of tested cases, and some successful attacks left no reasoning trace at all. That's the tool many organisations still use, including the labs themselves, for auditing what an agent is doing, and it's getting less reliable with every release.</em></p><div><blockquote><p>A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</p></blockquote></div><p><em>That matters because Astra isn't staying inside OpenAI's test environment. It's going to run as an agent on employee laptops and in the browser, holding real credentials, inside companies that have no way to watch what it does once it's there. A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</em></p><p><em>Labs can keep debating what these models say or refuse to say. Security teams need to stop relying on that and start monitoring what agents actually do at runtime, with the ability to shut one down mid-action. That's the only oversight left that still works once the reasoning goes quiet.</em></p><ul><li><strong>Kristin Lowery, Field CISO at Optiv:</strong></li></ul><p><em>For boards and executive leaders, the emergence of OpenAI’s Astra model highlights a broader reality: AI is no longer just a productivity issue; it is a risk management issue. </em></p><div><blockquote><p>The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace</p></blockquote></div><p><em>Just as organizations established governance for cloud adoption and digital transformation, they now need clear policies, strong oversight, and accountability for AI use.</em></p><p><em>The question is not whether AI will become more capable — it will. The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace.</em></p><ul><li><strong>Patricia Titus, Field CISO at Abnormal AI:</strong></li></ul><p><em>OpenAI crossing this threshold deserves attention. Credit where it's due, they're handling it responsibly by restricting Astra's advanced cyber capability to a small coalition rather than releasing it broadly.But this isn't one company's problem to contain.</em></p><p><em>Once a model can find and exploit unknown flaws without a human in the loop, that capability doesn't stay exclusive for long. Open-weight and modified models typically trail the frontier by only months, and that's the reality defenders have to plan around now.</em></p><div><blockquote><p>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time.</p></blockquote></div><p><em>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time. Defenders need the same shift, systems that learn what normal looks like for every identity, human, machine, or AI agent, and flag and contain the moment something deviates, at machine speed.</em></p><p><em>The window to build that is open now. It won't stay that way once this capability is common instead of rare.</em></p><ul><li><strong>Raghu Nandakumara, VP of Industry Strategy at Illumio:</strong></li></ul><p><em>With the Astra announcement, OpenAI is doubling down on monitoring the model's own behaviour – a response to the model "breakouts" seen over the past few months.</em></p><div><blockquote><p>The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</p></blockquote></div><p><em>When Anthropic announced Claude Mythos Preview, the core concern was the model falling into the wrong hands. OpenAI's answer goes further adding guardrails around the model's own reasoning and actions, regardless of the user's intent. The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</em></p><p><em>The rest of this announcement can be summarised as ‘we have a new frontier model, and it’s more capable than the last one’.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-is-there-so-much-worry-about-openai-astra-and-what-issues-could-recurrent-depth-reasoning-cause-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ As OpenAI unveils GPT-6 Astra, cybersecurity experts question whether the model's 'recurrent depth' reasoning was properly tested. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C8dxY7YkHdtYyEPzyEiovn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 05 Sep 2026 13:30:00 +0000</pubDate>                                                                                                                                <updated>Mon, 07 Sep 2026 09:36:03 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[ChatGPT]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg">
                                                            <media:credit><![CDATA[OpenAI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI GPT-6 Astra]]></media:description>                                                            <media:text><![CDATA[OpenAI GPT-6 Astra]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI GPT-6 Astra]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI has unveiled a much anticipated AI model which the firm has dubbed ‘GPT-6 Astra’. While the model has improved significantly across benchmark testing and <a href="https://www.techradar.com/pro/gpt-6-astra-lays-the-foundations-for-a-new-way-of-reasoning-a-great-tool-for-businesses-but-experts-have-their-concerns">brings a host of new business features</a>, there is still a dark cloud looming over the new model.</p><p>Off the back of <a href="https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in">OpenAI’s accidental hack of Hugging Face</a> and the company’s subsequent efforts to improve how AI agents behave and interact, numerous cybersecurity experts have raised concerns about the model’s new ‘recurrent depth’ reasoning capabilities.</p><p>This new reasoning architecture allows the model to consider a problem multiple times before taking an action, compared to the standard chain-of-thought reasoning used in previous models.</p><h2 id="why-the-concern-about-recurrent-depth-reasoning">Why the concern about recurrent depth reasoning?</h2><p>This new level of reasoning apparently offers improved performance. OpenAI also says it has fixed its models' abilities to circumvent boundaries when performing tests by monitoring the models reasoning and ensuring the model stays aligned within the scope of its task.</p><p>During Astra’s launch event, OpenAI chief scientist Jakub Pachocki said: “We will not accept degradation in our ability to monitor model alignment beyond a certain level. We will withhold scaling until we can regain enough confidence.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9-1920-80.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>But numerous experts believe that the lessons of the Hugging Face incident have not yet been learned, and the model has been released without adequate testing on Astra’s reasoning and monitoring. </p><p>After all, no one thought one of <a href="https://www.techradar.com/pro/security/openai-reveals-more-on-hugging-face-ai-hack-incident-and-its-pretty-disturbing-stuff-ai-agents-organized-into-a-swarm-considered-the-risks-of-attack-and-did-whatever-it-took-to-achieve-its-goal">OpenAI’s models could set up a hidden internet-connected messaging board</a> that allowed AI agents to influence each other's behavior.</p><p>But with Astra being released into the real world, the lessons may have to be learned on the fly.</p><h3 class="article-body__section" id="section-expert-perspectives-on-openai-astra-release"><span>Expert perspectives on OpenAI Astra release</span></h3><ul><li><strong>James Blake, VP of Global Cyber Resiliency Strategy at Cohesity:</strong></li></ul><p><em>The launch of Astra is raising questions again around the safety of Frontier AI. Instead of simply asking whether a model is "safe", organisations now need to ask whether it remains safe across millions of different situations, prompts and interactions. Cyber resilience has traditionally assumed that systems and threat actors behave deterministically. AI systems don’t.</em></p><div><blockquote><p>Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible?</p></blockquote></div><p><em>Advanced models can and will continue to exhibit behaviours that emerge from their optimisation process rather than from explicit programming. We have to move beyond thinking about AI as just another software tool and find ways to ensure these systems remain observable, auditable and governable throughout their lifecycle. </em></p><p><em>The most important question we’ll need to answer in future is one of liability. Suppose an AI system autonomously develops a strategy that causes financial loss, leaks confidential information or violates regulation. Who is responsible? The developer that trained the model? The cloud provider operating the infrastructure? Currently the answer is surprisingly unclear. It’s not just about what AI can do: it’s about who is accountable when it does something nobody expected.</em></p><ul><li><strong>Oleksandr Yaremchuk, Co-Founder & CTO at Manifold Security:</strong></li></ul><p><em>OpenAI is calling Astra its most aligned model yet, even as its chief scientist admits monitorability is getting harder as models get more capable. Evidently, Astra hides its reasoning in the majority of tested cases, and some successful attacks left no reasoning trace at all. That's the tool many organisations still use, including the labs themselves, for auditing what an agent is doing, and it's getting less reliable with every release.</em></p><div><blockquote><p>A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</p></blockquote></div><p><em>That matters because Astra isn't staying inside OpenAI's test environment. It's going to run as an agent on employee laptops and in the browser, holding real credentials, inside companies that have no way to watch what it does once it's there. A model that explains itself less isn't more aligned, it's just harder to catch when it goes wrong.</em></p><p><em>Labs can keep debating what these models say or refuse to say. Security teams need to stop relying on that and start monitoring what agents actually do at runtime, with the ability to shut one down mid-action. That's the only oversight left that still works once the reasoning goes quiet.</em></p><ul><li><strong>Kristin Lowery, Field CISO at Optiv:</strong></li></ul><p><em>For boards and executive leaders, the emergence of OpenAI’s Astra model highlights a broader reality: AI is no longer just a productivity issue; it is a risk management issue. </em></p><div><blockquote><p>The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace</p></blockquote></div><p><em>Just as organizations established governance for cloud adoption and digital transformation, they now need clear policies, strong oversight, and accountability for AI use.</em></p><p><em>The question is not whether AI will become more capable — it will. The real challenge is whether organizations can strengthen their governance, security controls, and workforce readiness quickly enough to keep pace.</em></p><ul><li><strong>Patricia Titus, Field CISO at Abnormal AI:</strong></li></ul><p><em>OpenAI crossing this threshold deserves attention. Credit where it's due, they're handling it responsibly by restricting Astra's advanced cyber capability to a small coalition rather than releasing it broadly.But this isn't one company's problem to contain.</em></p><p><em>Once a model can find and exploit unknown flaws without a human in the loop, that capability doesn't stay exclusive for long. Open-weight and modified models typically trail the frontier by only months, and that's the reality defenders have to plan around now.</em></p><div><blockquote><p>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time.</p></blockquote></div><p><em>Static, signature-based defences were built for attacks that repeat. They weren't built for an adversary that generates a new one every time. Defenders need the same shift, systems that learn what normal looks like for every identity, human, machine, or AI agent, and flag and contain the moment something deviates, at machine speed.</em></p><p><em>The window to build that is open now. It won't stay that way once this capability is common instead of rare.</em></p><ul><li><strong>Raghu Nandakumara, VP of Industry Strategy at Illumio:</strong></li></ul><p><em>With the Astra announcement, OpenAI is doubling down on monitoring the model's own behaviour – a response to the model "breakouts" seen over the past few months.</em></p><div><blockquote><p>The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</p></blockquote></div><p><em>When Anthropic announced Claude Mythos Preview, the core concern was the model falling into the wrong hands. OpenAI's answer goes further adding guardrails around the model's own reasoning and actions, regardless of the user's intent. The goal is to catch a model going rogue mid-task, not just stop it being misused at the outset.</em></p><p><em>The rest of this announcement can be summarised as ‘we have a new frontier model, and it’s more capable than the last one’.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google patches multiple browser bugs including one that was under active exploitation — so update now ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Google released Chrome 152.0.7977.82/.83 for Windows, Mac, and Linux</strong></li><li><strong>Patch fixes 12 flaws, including zero‑day CVE‑2026‑85046 (type confusion in V8)</strong></li><li><strong>Sixth Chrome zero‑day this year; Chromium browsers also affected, update urged immediately</strong></li></ul><p>Google has released a new version of its Chrome <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> for Windows, Mac, and Linux, fixing a dozen of vulnerabilities. Among them is a high-severity flaw that is being actively exploited in the wild.</p><p>In a security advisory published on the Google blog on September 3, the search engine company said Chrome’s newest version is now 152.0.7977.82/.83 for Windows and Mac, and 152.0.7977.82 for Linux.</p><p>Rollout is expected to be gradual, so make sure to check if you already received it. Most of the time the update is automatic and instant and if you’re not certain, tap the three vertical dots in the top-right corner of the browser and choose Help. Navigate to About Google Chrome and there you will find the version number. </p><h2 id="running-malicious-code-remotely">Running malicious code remotely</h2><p>This patch fixes a total of 12 vulnerabilities, most of which are graded as high severity. Among them is a “type confusion in V8” bug, discovered by security researcher Salvatore Gulizia.</p><p>For his effort, Gulizia was awarded $1,000. Apparently, this bug is being actively leveraged in real-life attacks, although Google (as usual) decided not to share the juicy details until the majority of browsers are protected.</p><p>The vulnerability is tracked as CVE-2026-85046. On the National Vulnerability Database (NVD), it is described as a “type confusion in V8 in Google Chrome [that allows] a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.”</p><p>V8 is Chrome’s JavaScript engine which allows web apps and interactive websites to run in the browser. Those interested in the technical breakdown of the vulnerability can find it on <a href="https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/" target="_blank" rel="nofollow">Guzlia’s blog</a>.</p><p>You can find the full list of fixed vulnerabilities on <a href="https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html" target="_blank" rel="nofollow">this link</a>. </p><p>This is the sixth zero-day Google fixed in Chrome since the start of the year. It also affects other browsers built on Chromium, so if you’re running Edge, Brave, Opera, or Vivaldi, make sure to update to the latest version as soon as possible. </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/google-patches-multiple-browser-bugs-including-one-that-was-under-active-exploitation-so-update-now</link>
                                                                            <description>
                            <![CDATA[ Google did not share the details about the bug being actively used. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PWhL6n866rriJHC4C6KTWa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 19:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg">
                                                            <media:credit><![CDATA[Tada Images / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:description>                                                            <media:text><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:text>
                                <media:title type="plain"><![CDATA[Google Chrome app is seen on an iPhone next to Edge and other web browser apps. Microsoft is using new prompts in Edge to try and stop users from downloading Chrome.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tSejjmrgK46MgdhWqD5miC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Google released Chrome 152.0.7977.82/.83 for Windows, Mac, and Linux</strong></li><li><strong>Patch fixes 12 flaws, including zero‑day CVE‑2026‑85046 (type confusion in V8)</strong></li><li><strong>Sixth Chrome zero‑day this year; Chromium browsers also affected, update urged immediately</strong></li></ul><p>Google has released a new version of its Chrome <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> for Windows, Mac, and Linux, fixing a dozen of vulnerabilities. Among them is a high-severity flaw that is being actively exploited in the wild.</p><p>In a security advisory published on the Google blog on September 3, the search engine company said Chrome’s newest version is now 152.0.7977.82/.83 for Windows and Mac, and 152.0.7977.82 for Linux.</p><p>Rollout is expected to be gradual, so make sure to check if you already received it. Most of the time the update is automatic and instant and if you’re not certain, tap the three vertical dots in the top-right corner of the browser and choose Help. Navigate to About Google Chrome and there you will find the version number. </p><h2 id="running-malicious-code-remotely">Running malicious code remotely</h2><p>This patch fixes a total of 12 vulnerabilities, most of which are graded as high severity. Among them is a “type confusion in V8” bug, discovered by security researcher Salvatore Gulizia.</p><p>For his effort, Gulizia was awarded $1,000. Apparently, this bug is being actively leveraged in real-life attacks, although Google (as usual) decided not to share the juicy details until the majority of browsers are protected.</p><p>The vulnerability is tracked as CVE-2026-85046. On the National Vulnerability Database (NVD), it is described as a “type confusion in V8 in Google Chrome [that allows] a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.”</p><p>V8 is Chrome’s JavaScript engine which allows web apps and interactive websites to run in the browser. Those interested in the technical breakdown of the vulnerability can find it on <a href="https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/" target="_blank" rel="nofollow">Guzlia’s blog</a>.</p><p>You can find the full list of fixed vulnerabilities on <a href="https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html" target="_blank" rel="nofollow">this link</a>. </p><p>This is the sixth zero-day Google fixed in Chrome since the start of the year. It also affects other browsers built on Chromium, so if you’re running Edge, Brave, Opera, or Vivaldi, make sure to update to the latest version as soon as possible. </p><p><em>Via </em><a href="https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html" target="_blank" rel="nofollow"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI warns about how good Astra model is at cracking cybersecurity, releases it anyway because it took 'years of research and big bets' ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI rolled out GPT‑6 Astra, its most advanced AI, with “critical” cyber capabilities</strong></li><li><strong>Astra can autonomously find and exploit unknown flaws; release limited to vetted Daybreak participants</strong></li><li><strong>Staggered rollout sparked user frustration; Altman apologized, promising broader access soon</strong></li></ul><p>OpenAI has begun rolling out <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">GPT-6 Astra</a>, its latest and most capable artificial intelligence model. </p><p>In an announcement published on its website, OpenAI said Astra represents a “significant step up in cyber capabilities”, meeting the company’s “Critical” threshold.</p><p>This threshold, the company explained, means that under the right circumstances, the tool can find “previously unknown security flaws and develop new ways to exploit them across many well-protected systems without a person guiding each step.”</p><h2 id="apologies-for-a-messy-rollout">Apologies for a messy rollout</h2><p>OpenAI also said Astra improves on functions such as computer use, software engineering, and science, and that it should be better at staying oriented, compared to previous versions.</p><p>Just like many of the previous models, Astra’s release has been marred with controversy. Roughly a month ago, OpenAI said the model’s “critical” cybersecurity capabilities prompted it to <a href="https://www.channelnewsasia.com/business/openai-flags-possible-critical-cybersecurity-risk-in-upcoming-model-tightens-controls-6306796" target="_blank" rel="nofollow">pause some internal development</a> and trigger safety protocols.</p><p>In response to early findings, the company scaled up certain security controls and even paused activities that do not meet its newly established security requirements. </p><p>It now decided it was time to release the model, but still not to the general public. Instead, it opted for a staggered release, giving it first to a limited group of companies participating in the Daybreak program, a cybersecurity initiative that gives vetted organizations (cybersecurity and otherwise) specialized AI tools for vulnerability research and threat detection. </p><p>This did not sit well with many ChatGPT users, especially those paying a monthly subscription. As <a href="https://www.theverge.com/ai-artificial-intelligence/990060/altman-apologizes-messy-astra-rollout" target="_blank" rel="nofollow"><em>The Verge</em></a> reported, CEO Sam Altman was apologizing, mere hours after launch, for the “messy rollout” of Astra.</p><p>Initially, all Plus, Pro, Business, and Enterprise users were supposed to gain access to Astra, as well as those accessing through OpenAI API, Microsoft Azure, and AWS Bedrock. </p><p>“We are working towards getting Astra in everyone’s hands as quickly as we can,” Altman said on X. “I know it is frustrating and I appreciate the patience. It should be quick.”</p><p><em>Via </em><a href="https://www.cnbc.com/2026/09/03/open-ai-astra-gpt-6-cyber.html" target="_blank" rel="nofollow"><em>CNBC</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-warns-about-how-good-astra-model-is-at-cracking-cybersecurity-releases-it-anyway-because-it-took-years-of-research-and-big-bets</link>
                                                                            <description>
                            <![CDATA[ GPT-6 Astra was paused a month ago for triggering safety protocols and now it's being slowly rolled out. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JV7weBTmHEVs8GrqeHEVAE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 18:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[ChatGPT]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg">
                                                            <media:credit><![CDATA[OpenAI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI GPT-6 Astra]]></media:description>                                                            <media:text><![CDATA[OpenAI GPT-6 Astra]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI GPT-6 Astra]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/S8KxZGx6n8eh2LiPG7yz36-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI rolled out GPT‑6 Astra, its most advanced AI, with “critical” cyber capabilities</strong></li><li><strong>Astra can autonomously find and exploit unknown flaws; release limited to vetted Daybreak participants</strong></li><li><strong>Staggered rollout sparked user frustration; Altman apologized, promising broader access soon</strong></li></ul><p>OpenAI has begun rolling out <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">GPT-6 Astra</a>, its latest and most capable artificial intelligence model. </p><p>In an announcement published on its website, OpenAI said Astra represents a “significant step up in cyber capabilities”, meeting the company’s “Critical” threshold.</p><p>This threshold, the company explained, means that under the right circumstances, the tool can find “previously unknown security flaws and develop new ways to exploit them across many well-protected systems without a person guiding each step.”</p><h2 id="apologies-for-a-messy-rollout">Apologies for a messy rollout</h2><p>OpenAI also said Astra improves on functions such as computer use, software engineering, and science, and that it should be better at staying oriented, compared to previous versions.</p><p>Just like many of the previous models, Astra’s release has been marred with controversy. Roughly a month ago, OpenAI said the model’s “critical” cybersecurity capabilities prompted it to <a href="https://www.channelnewsasia.com/business/openai-flags-possible-critical-cybersecurity-risk-in-upcoming-model-tightens-controls-6306796" target="_blank" rel="nofollow">pause some internal development</a> and trigger safety protocols.</p><p>In response to early findings, the company scaled up certain security controls and even paused activities that do not meet its newly established security requirements. </p><p>It now decided it was time to release the model, but still not to the general public. Instead, it opted for a staggered release, giving it first to a limited group of companies participating in the Daybreak program, a cybersecurity initiative that gives vetted organizations (cybersecurity and otherwise) specialized AI tools for vulnerability research and threat detection. </p><p>This did not sit well with many ChatGPT users, especially those paying a monthly subscription. As <a href="https://www.theverge.com/ai-artificial-intelligence/990060/altman-apologizes-messy-astra-rollout" target="_blank" rel="nofollow"><em>The Verge</em></a> reported, CEO Sam Altman was apologizing, mere hours after launch, for the “messy rollout” of Astra.</p><p>Initially, all Plus, Pro, Business, and Enterprise users were supposed to gain access to Astra, as well as those accessing through OpenAI API, Microsoft Azure, and AWS Bedrock. </p><p>“We are working towards getting Astra in everyone’s hands as quickly as we can,” Altman said on X. “I know it is frustrating and I appreciate the patience. It should be quick.”</p><p><em>Via </em><a href="https://www.cnbc.com/2026/09/03/open-ai-astra-gpt-6-cyber.html" target="_blank" rel="nofollow"><em>CNBC</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why did FulcrumSec hackers try to extort Manchester Airports Group, and what happens now the data is leaked? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Following the aftermath of the Manchester Airports Group cyberattack - <a href="https://www.techradar.com/pro/security/manchester-airports-hackers-just-posted-the-data-of-8-7-million-people-online-failed-extortion-attempt-triggers-data-dump-sale">where hackers made off with the data of 8.7 million people</a> - the hackers have now posted the entire database for sale on the dark web.</p><p>The group behind the attack, FulcrumSec, attempted to get Manchester Airports Group (MAG) to pay for the security of the database, promising that it wouldn’t be released if the company paid a settlement. But as all companies should do when faced with extortion, MAG didn’t play ball.</p><p>Now FulcrumSec wants to try and maximise the damage of the cyberattack, and has listed the database containing email addresses, phone numbers, vehicle registrations and postcodes online in the hopes a fellow hacking group will find value in the data.</p><h2 id="what-happens-when-extortion-fails-and-why-didn-t-mag-pay">What happens when extortion fails, and why didn’t MAG pay?</h2><p>In the past, when companies faced ransomware attacks or data breaches, they would sometimes quietly pay the hackers for their silence. </p><p>Companies feared serious reputational harm and loss of business would cost more in the long run than the perpetrators were asking for. But this created an incentive for hackers to carry out more attacks.</p><p>After all, if companies aren’t kicking up a fuss about being hacked or reporting the attack to the authorities, hacking groups can launch more attacks on other companies that are completely unaware of their tactics.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9-1920-80.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>In order to counter this, authorities and cyber experts from around the world issued guidance that under no circumstances should companies pay for the safe return of their data. By removing the incentive from ransomware attacks and data breaches, the hope is that hackers will get bored or not see enough ROI, and therefore stop.</p><p>But the 500GB database of data on over 8.7 million people is ripe pickings for other cybercriminals looking to launch highly specific phishing attacks or scam campaigns. While FulcrumSec may not make any money from the attack, they can seriously enhance the damage of the attack by offering the data for free for others to use.</p><p>A successful scam or phishing attack can steal banking and financial details, allowing other groups to steal even more money off the back of the attack.</p><h3 class="article-body__section" id="section-expert-perspectives-on-mag-extortion-and-customer-data"><span>Expert perspectives on MAG extortion and customer data</span></h3><ul><li><strong>Dray Agha, senior manager of security operations at Huntress:</strong></li></ul><p><em>While Manchester Airports Group followed official guidance by refusing to pay the ransom, the release of 8.7 million records creates an immediate risk for passengers.</em></p><div><blockquote><p>The release of 8.7 million records creates an immediate risk for passengers</p></blockquote></div><p><em>We expect other criminals to use this freely available database of vehicle registrations, postcodes and contact details to craft highly convincing phishing attacks.</em></p><p><em>Anyone who has used parking, lounges or Wi-Fi at these airports must treat unexpected messages about their travel with extreme caution.</em></p><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress</strong></li></ul><p><em>The "free release" model is deliberately designed to maximise harm and reputational damage as a warning to the next target. </em></p><div><blockquote><p>It's a marketing campaign aimed at every other organisation watching</p></blockquote></div><p><em>Publishing almost nine million records for free isn't just punishment for MAG it's a marketing campaign aimed at every other organisation watching.</em></p><p><em>Pay up, or your customers' data gets handed to every fraudster and scammer on the internet at no cost. Refusing to pay a ransom is the right call. But nearly nine million people are now paying a different price for a decision that was never theirs to make.</em></p><ul><li><strong>Danny Jenkins, Co Founder & CEO at ThreatLocker</strong></li></ul><p><em>Unfortunately, once data is made public, it can’t be hidden again. The most important thing consumers can do is focus on basic cyber hygiene. Use a unique password for every website, learn how to identify phishing scams, and monitor your credit report.</em></p><div><blockquote><p>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</p></blockquote></div><p><em>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</em></p><p><em>When in doubt, look up the phone number for the alleged sender yourself, rather than using a number provided in the email, and call to confirm whether the communication is genuine.</em></p><ul><li><strong>Brian Higgins, security specialist at Comparitech:</strong></li></ul><p><em>Whilst the airports breached in this attack don't appear to have had any financial data compromised the risk to affected or associated customers is very real. With so much other information freely available in the wild it is vital that airport users stay highly vigilant for some time to come.</em></p><div><blockquote><p>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends.</p></blockquote></div><p><em>Any and all unsolicited contact; whether online, by telephone or even home visit approaches, should be viewed as suspicious. Never engage until you've taken time to check credentials/veracity etc.</em></p><p><em>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends. Look for ways to increase digital and physical security like two factor authentication on Apps and devices or Smart Home tech. </em></p><p><em>When this breach was first reported by the Manchester Evening News the comments were quite telling. Affected parties were quick to identify potential vulnerabilities over and above the breach of financial and banking details. </em></p><p><em>Home addresses, vehicle registrations and time spent away from home all add up to some excellent opportunities for criminal exploitation, not to mention the usual follow-up phishing campaigns common in this type of incident.</em></p><p><em>As AI makes data aggregation swift and easy consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways. It’s no longer enough for data owning organisations to advise post-attack vigilance and turn to their backups.</em></p><p><em>Victim communities rightly expect better protected networks and systems over and above established norms. As the marketplace grows less fearful and more angry when breaches are made public we may see more emphasis on cyber crime prevention which can only be a good thing.</em></p><ul><li><strong>Denis Calderone, CTO at Suzu Labs:</strong></li></ul><p><em>The 8.7 million number is attention-grabbing, but it deserves some context. MAG has confirmed that the vast majority of those records are email addresses collected through airport WiFi sign-ups. </em></p><p><em>A much smaller subset includes phone numbers, vehicle registrations, and postcodes from customers who actually completed parking or lounge bookings.</em></p><div><blockquote><p>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first.</p></blockquote></div><p><em>No payment data, no passwords, no passport information. So despite this affecting airports, which is obviously a sensitive subject, the actual data sensitivity for most affected individuals is relatively low.</em></p><p><em>What's more interesting to us from a technical standpoint is the attack path. MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That's a pivot upstream into a data provider, not downstream into operational systems.</em></p><p><em>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.</em></p><p><em>The UK's Civil Aviation Authority has a Cyber Assessment Framework for Aviation, developed with the NCSC, that mandates strict separation between IT systems and operational technology.</em></p><p><em>We don't know whether MAG was formally operating under that framework at the time of this incident, but I would be very interested to find out. Because the segmentation appears to have held here. Flight operations, baggage handling, terminal systems, etc., all were unaffected. </em></p><p><em>The lateral movement went upstream toward a data provider, not downstream toward the systems that keep planes in the air.</em></p><ul><li><strong>Seemant Sehgal, CEO and Founder at BreachLock:</strong></li></ul><p><em>This data was initially collected because passengers needed a login, and somewhere along the way, the sensitivity of what was accumulating in that database stopped getting the same scrutiny as the network itself.</em></p><div><blockquote><p>Whoever held it for ransom understood its value better than the organization storing it did</p></blockquote></div><p><em>Vehicle registration details, postcodes, and contact information across three major airports are a profiling dataset, and whoever held it for ransom understood its value better than the organization storing it did.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-did-fulcrumsec-hackers-try-to-extort-manchester-airports-group-and-what-happens-now-the-data-is-leaked-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ After hackers failed to extort Manchester Airports Group and posted the data of nearly 9 million people online, we asked the experts what's really going on. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fRCxPaa9De9wPUPVGxjDbh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 14:57:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Airport]]></media:description>                                                            <media:text><![CDATA[Airport]]></media:text>
                                <media:title type="plain"><![CDATA[Airport]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RYNpvpkwHbue2Dnhv3oLpL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Following the aftermath of the Manchester Airports Group cyberattack - <a href="https://www.techradar.com/pro/security/manchester-airports-hackers-just-posted-the-data-of-8-7-million-people-online-failed-extortion-attempt-triggers-data-dump-sale">where hackers made off with the data of 8.7 million people</a> - the hackers have now posted the entire database for sale on the dark web.</p><p>The group behind the attack, FulcrumSec, attempted to get Manchester Airports Group (MAG) to pay for the security of the database, promising that it wouldn’t be released if the company paid a settlement. But as all companies should do when faced with extortion, MAG didn’t play ball.</p><p>Now FulcrumSec wants to try and maximise the damage of the cyberattack, and has listed the database containing email addresses, phone numbers, vehicle registrations and postcodes online in the hopes a fellow hacking group will find value in the data.</p><h2 id="what-happens-when-extortion-fails-and-why-didn-t-mag-pay">What happens when extortion fails, and why didn’t MAG pay?</h2><p>In the past, when companies faced ransomware attacks or data breaches, they would sometimes quietly pay the hackers for their silence. </p><p>Companies feared serious reputational harm and loss of business would cost more in the long run than the perpetrators were asking for. But this created an incentive for hackers to carry out more attacks.</p><p>After all, if companies aren’t kicking up a fuss about being hacked or reporting the attack to the authorities, hacking groups can launch more attacks on other companies that are completely unaware of their tactics.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iGCEJhusMZf623FQovppd9" name="TR.0093_perspectives assets_logo" caption="" alt="TechRadar Pro Perspectives logo in purple" src="https://cdn.mos.cms.futurecdn.net/iGCEJhusMZf623FQovppd9-1920-80.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p class="fancy-box__body-text">Got an opinion for us? <a data-analytics-id="inline-link" href="https://www.techradar.com/pro/perspectives-how-to-submit" target="_blank">Here’s how you can submit your perspective</a></p></div></div><p>In order to counter this, authorities and cyber experts from around the world issued guidance that under no circumstances should companies pay for the safe return of their data. By removing the incentive from ransomware attacks and data breaches, the hope is that hackers will get bored or not see enough ROI, and therefore stop.</p><p>But the 500GB database of data on over 8.7 million people is ripe pickings for other cybercriminals looking to launch highly specific phishing attacks or scam campaigns. While FulcrumSec may not make any money from the attack, they can seriously enhance the damage of the attack by offering the data for free for others to use.</p><p>A successful scam or phishing attack can steal banking and financial details, allowing other groups to steal even more money off the back of the attack.</p><h3 class="article-body__section" id="section-expert-perspectives-on-mag-extortion-and-customer-data"><span>Expert perspectives on MAG extortion and customer data</span></h3><ul><li><strong>Dray Agha, senior manager of security operations at Huntress:</strong></li></ul><p><em>While Manchester Airports Group followed official guidance by refusing to pay the ransom, the release of 8.7 million records creates an immediate risk for passengers.</em></p><div><blockquote><p>The release of 8.7 million records creates an immediate risk for passengers</p></blockquote></div><p><em>We expect other criminals to use this freely available database of vehicle registrations, postcodes and contact details to craft highly convincing phishing attacks.</em></p><p><em>Anyone who has used parking, lounges or Wi-Fi at these airports must treat unexpected messages about their travel with extreme caution.</em></p><ul><li><strong>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress</strong></li></ul><p><em>The "free release" model is deliberately designed to maximise harm and reputational damage as a warning to the next target. </em></p><div><blockquote><p>It's a marketing campaign aimed at every other organisation watching</p></blockquote></div><p><em>Publishing almost nine million records for free isn't just punishment for MAG it's a marketing campaign aimed at every other organisation watching.</em></p><p><em>Pay up, or your customers' data gets handed to every fraudster and scammer on the internet at no cost. Refusing to pay a ransom is the right call. But nearly nine million people are now paying a different price for a decision that was never theirs to make.</em></p><ul><li><strong>Danny Jenkins, Co Founder & CEO at ThreatLocker</strong></li></ul><p><em>Unfortunately, once data is made public, it can’t be hidden again. The most important thing consumers can do is focus on basic cyber hygiene. Use a unique password for every website, learn how to identify phishing scams, and monitor your credit report.</em></p><div><blockquote><p>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</p></blockquote></div><p><em>Be highly suspicious of emails that create a sense of urgency, offer something that seems too good to be true, or ask you to reset your password.</em></p><p><em>When in doubt, look up the phone number for the alleged sender yourself, rather than using a number provided in the email, and call to confirm whether the communication is genuine.</em></p><ul><li><strong>Brian Higgins, security specialist at Comparitech:</strong></li></ul><p><em>Whilst the airports breached in this attack don't appear to have had any financial data compromised the risk to affected or associated customers is very real. With so much other information freely available in the wild it is vital that airport users stay highly vigilant for some time to come.</em></p><div><blockquote><p>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends.</p></blockquote></div><p><em>Any and all unsolicited contact; whether online, by telephone or even home visit approaches, should be viewed as suspicious. Never engage until you've taken time to check credentials/veracity etc.</em></p><p><em>Research advice from trusted sources like the NCA or Information Commissioner and share it with your family and friends. Look for ways to increase digital and physical security like two factor authentication on Apps and devices or Smart Home tech. </em></p><p><em>When this breach was first reported by the Manchester Evening News the comments were quite telling. Affected parties were quick to identify potential vulnerabilities over and above the breach of financial and banking details. </em></p><p><em>Home addresses, vehicle registrations and time spent away from home all add up to some excellent opportunities for criminal exploitation, not to mention the usual follow-up phishing campaigns common in this type of incident.</em></p><p><em>As AI makes data aggregation swift and easy consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways. It’s no longer enough for data owning organisations to advise post-attack vigilance and turn to their backups.</em></p><p><em>Victim communities rightly expect better protected networks and systems over and above established norms. As the marketplace grows less fearful and more angry when breaches are made public we may see more emphasis on cyber crime prevention which can only be a good thing.</em></p><ul><li><strong>Denis Calderone, CTO at Suzu Labs:</strong></li></ul><p><em>The 8.7 million number is attention-grabbing, but it deserves some context. MAG has confirmed that the vast majority of those records are email addresses collected through airport WiFi sign-ups. </em></p><p><em>A much smaller subset includes phone numbers, vehicle registrations, and postcodes from customers who actually completed parking or lounge bookings.</em></p><div><blockquote><p>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first.</p></blockquote></div><p><em>No payment data, no passwords, no passport information. So despite this affecting airports, which is obviously a sensitive subject, the actual data sensitivity for most affected individuals is relatively low.</em></p><p><em>What's more interesting to us from a technical standpoint is the attack path. MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That's a pivot upstream into a data provider, not downstream into operational systems.</em></p><p><em>What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG's network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.</em></p><p><em>The UK's Civil Aviation Authority has a Cyber Assessment Framework for Aviation, developed with the NCSC, that mandates strict separation between IT systems and operational technology.</em></p><p><em>We don't know whether MAG was formally operating under that framework at the time of this incident, but I would be very interested to find out. Because the segmentation appears to have held here. Flight operations, baggage handling, terminal systems, etc., all were unaffected. </em></p><p><em>The lateral movement went upstream toward a data provider, not downstream toward the systems that keep planes in the air.</em></p><ul><li><strong>Seemant Sehgal, CEO and Founder at BreachLock:</strong></li></ul><p><em>This data was initially collected because passengers needed a login, and somewhere along the way, the sensitivity of what was accumulating in that database stopped getting the same scrutiny as the network itself.</em></p><div><blockquote><p>Whoever held it for ransom understood its value better than the organization storing it did</p></blockquote></div><p><em>Vehicle registration details, postcodes, and contact information across three major airports are a profiling dataset, and whoever held it for ransom understood its value better than the organization storing it did.</em></p><section class="article__schema-question"><h3>How do I submit my own perspective on emerging news?</h3><article class="article__schema-answer"><p>If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: benedict.collins@futurenet.com</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco patches three critical vulnerabilities as part of 'comprehensive internal security review' ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Cisco patched eight IOS XR flaws, including three critical (CVE‑2026‑20274, CVE‑2026‑20279, CVE‑2026‑20212)</strong></li><li><strong>Vulnerabilities allow unauthenticated exploitation, improper access control, and crafted input execution</strong></li><li><strong>No abuse reported; patches urged, with iACL workarounds for Nexus 9000 devices using Silicon One ASIC</strong></li></ul><p>Cisco patched eight vulnerabilities affecting its IOS XR operating system, including three critical-severity ones. It urged its customers to apply the patches as soon as possible, even though it stressed that there is no evidence any of these were abused in the wild.</p><p>The company detailed its findings in two advisories published on the same day - September 2.</p><p>In the first one, it disclosed seven vulnerabilities, including two critical-severity ones: CVE-2026-20274 and CVE-2026-20279. Both carry a severity rating of 9.8/10 (critical). The former is an improper control of a resource during its lifetime flaw - a network-based, low complexity, vulnerability that requires no authentication or user interaction to be exploited. The latter is described as an improper access control vulnerability that can lead to the same consequences.</p><h2 id="fixes-and-mitigations">Fixes and mitigations</h2><p>These flaws, along with five others, affect all releases of Cisco IOS XR Software, including Cisco IOS XR7 (LNT) Software, regardless of device configuration, the company explained. There are no available workarounds, and installing the provided patch is the only way to mitigate the risk.</p><p>The third flaw, disclosed in a separate advisory, is tracked as CVE-2026-20212. Successfully exploiting this one allows attackers to connect to an affected device and send crafted input that could be executed as code, without root privileges. “The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload,” Cisco explained. </p><p>This bug affects <a href="https://www.techradar.com/best/best-network-switches" target="_blank">Cisco Nexus 9000 Series Switches</a> if they include a Silicon One ASIC, the company stressed. A possible workaround is to use infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. There is also the option of iACLs only being used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release/5294410" target="_blank" rel="nofollow"><em>The Register</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/cisco-patches-three-critical-vulnerabilities-as-part-of-comprehensive-internal-security-review</link>
                                                                            <description>
                            <![CDATA[ A total of eight flaws were fixed, none of which were exploited in the wild. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NwtFJ9WsAyxAmKVur5Dra9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4vPx4qpVwRADJoMvv3gttX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 13:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4vPx4qpVwRADJoMvv3gttX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Valriya Zankovych]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cisco]]></media:description>                                                            <media:text><![CDATA[Cisco]]></media:text>
                                <media:title type="plain"><![CDATA[Cisco]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4vPx4qpVwRADJoMvv3gttX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Cisco patched eight IOS XR flaws, including three critical (CVE‑2026‑20274, CVE‑2026‑20279, CVE‑2026‑20212)</strong></li><li><strong>Vulnerabilities allow unauthenticated exploitation, improper access control, and crafted input execution</strong></li><li><strong>No abuse reported; patches urged, with iACL workarounds for Nexus 9000 devices using Silicon One ASIC</strong></li></ul><p>Cisco patched eight vulnerabilities affecting its IOS XR operating system, including three critical-severity ones. It urged its customers to apply the patches as soon as possible, even though it stressed that there is no evidence any of these were abused in the wild.</p><p>The company detailed its findings in two advisories published on the same day - September 2.</p><p>In the first one, it disclosed seven vulnerabilities, including two critical-severity ones: CVE-2026-20274 and CVE-2026-20279. Both carry a severity rating of 9.8/10 (critical). The former is an improper control of a resource during its lifetime flaw - a network-based, low complexity, vulnerability that requires no authentication or user interaction to be exploited. The latter is described as an improper access control vulnerability that can lead to the same consequences.</p><h2 id="fixes-and-mitigations">Fixes and mitigations</h2><p>These flaws, along with five others, affect all releases of Cisco IOS XR Software, including Cisco IOS XR7 (LNT) Software, regardless of device configuration, the company explained. There are no available workarounds, and installing the provided patch is the only way to mitigate the risk.</p><p>The third flaw, disclosed in a separate advisory, is tracked as CVE-2026-20212. Successfully exploiting this one allows attackers to connect to an affected device and send crafted input that could be executed as code, without root privileges. “The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload,” Cisco explained. </p><p>This bug affects <a href="https://www.techradar.com/best/best-network-switches" target="_blank">Cisco Nexus 9000 Series Switches</a> if they include a Silicon One ASIC, the company stressed. A possible workaround is to use infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. There is also the option of iACLs only being used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release/5294410" target="_blank" rel="nofollow"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI puts its money where its mouth is, offers $1 billion in AI credits to cyber defenders ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI launched </strong><em><strong>Daybreak for Frontline Defenders</strong></em><strong>, offering $1B in credits for resource‑constrained security orgs</strong></li><li><strong>Priority goes to essential services, governments, banks, nonprofits, and open‑source maintainers</strong></li><li><strong>Initiative includes training, partnerships, and a water‑sector pilot with MS‑ISCA for local defenders</strong></li></ul><p>OpenAI is offering a billion dollars in credits to security organizations who want to use its Daybreak initiative but cannot afford it.</p><p>Daybreak is a cybersecurity program that provides vetted defenders with specialized <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI tools</a> and models. It was introduced in May this year, and later expanded into two tiers - Blue, and Red. Blue is the entry-level tier, providing a general-purpose model with custom-tailored safeguards. Red, on the other hand, offers a more purpose-trained cybersecurity model and almost no safeguards.</p><p>According to OpenAI, “thousands of defenders across 2,000 approved organizations and workspaces” already use Daybreak, including cybersecurity companies, defense organizations, and law enforcement agencies.</p><h2 id="who-gets-priority">Who gets priority?</h2><p>But these models cost money, and to make sure more businesses can access them, OpenAI announced, “Daybreak for Frontline Defenders”, a project where defenders can apply and receive credits for AI tokens. Even though the company announced it as a global initiative, it seems that US businesses will be the first to take advantage of it:</p><p>“OpenAI is committing $1 billion in subsidized Daybreak access to help resource-constrained cyber defenders, starting with the United States, put frontier AI to work, targeting it to be consumed over the next six months,” the company said in an announcement blog.</p><p>Businesses operating essential services such as water and wastewater systems, and electric grid operators, will get priority, OpenAI said. Then come state and local governments, community and regional banks, nonprofits, open-source maintainers, and then “other organizations with limited security resources.”</p><p>The subsidy is not just about using the models, though. OpenAI also said it will be increasing hands-on support for frontline defenders, training, and new partnerships. </p><p>On top of all that, OpenAI also announced a public sector, water-focused pilot with the Multi-State Information Sharing and Analysis Center (MS-ISCA) to train and support local, tribal, and territorial defenders.</p><p>“The pilot will pair Daybreak access with guided training and hands-on assistance for an initial group of public sector and water system defenders, helping them validate and prioritize findings, coordinate remediation, and develop a repeatable approach that can be expanded over time,” the announcement concluded.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-puts-its-money-where-its-mouth-is-offers-usd1-billion-in-ai-credits-to-cyber-defenders</link>
                                                                            <description>
                            <![CDATA[ Want to use Daybreak but cannot afford it? You can now apply for a subsidy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">t2rShP2332cHQ4q6yU7QA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6whQhAYA48xb8xVGQ3HNyX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 12:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms & Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6whQhAYA48xb8xVGQ3HNyX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/SPOA Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ChatGPT logo on a smartphone.]]></media:description>                                                            <media:text><![CDATA[ChatGPT logo on a smartphone.]]></media:text>
                                <media:title type="plain"><![CDATA[ChatGPT logo on a smartphone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6whQhAYA48xb8xVGQ3HNyX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI launched </strong><em><strong>Daybreak for Frontline Defenders</strong></em><strong>, offering $1B in credits for resource‑constrained security orgs</strong></li><li><strong>Priority goes to essential services, governments, banks, nonprofits, and open‑source maintainers</strong></li><li><strong>Initiative includes training, partnerships, and a water‑sector pilot with MS‑ISCA for local defenders</strong></li></ul><p>OpenAI is offering a billion dollars in credits to security organizations who want to use its Daybreak initiative but cannot afford it.</p><p>Daybreak is a cybersecurity program that provides vetted defenders with specialized <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI tools</a> and models. It was introduced in May this year, and later expanded into two tiers - Blue, and Red. Blue is the entry-level tier, providing a general-purpose model with custom-tailored safeguards. Red, on the other hand, offers a more purpose-trained cybersecurity model and almost no safeguards.</p><p>According to OpenAI, “thousands of defenders across 2,000 approved organizations and workspaces” already use Daybreak, including cybersecurity companies, defense organizations, and law enforcement agencies.</p><h2 id="who-gets-priority">Who gets priority?</h2><p>But these models cost money, and to make sure more businesses can access them, OpenAI announced, “Daybreak for Frontline Defenders”, a project where defenders can apply and receive credits for AI tokens. Even though the company announced it as a global initiative, it seems that US businesses will be the first to take advantage of it:</p><p>“OpenAI is committing $1 billion in subsidized Daybreak access to help resource-constrained cyber defenders, starting with the United States, put frontier AI to work, targeting it to be consumed over the next six months,” the company said in an announcement blog.</p><p>Businesses operating essential services such as water and wastewater systems, and electric grid operators, will get priority, OpenAI said. Then come state and local governments, community and regional banks, nonprofits, open-source maintainers, and then “other organizations with limited security resources.”</p><p>The subsidy is not just about using the models, though. OpenAI also said it will be increasing hands-on support for frontline defenders, training, and new partnerships. </p><p>On top of all that, OpenAI also announced a public sector, water-focused pilot with the Multi-State Information Sharing and Analysis Center (MS-ISCA) to train and support local, tribal, and territorial defenders.</p><p>“The pilot will pair Daybreak access with guided training and hands-on assistance for an initial group of public sector and water system defenders, helping them validate and prioritize findings, coordinate remediation, and develop a repeatable approach that can be expanded over time,” the announcement concluded.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IT helpdesk impersonation hits Microsoft Teams once again, with the hackers hiding their activity within legitimate tools ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft warns of Teams‑based campaign where attackers impersonate IT staff</strong></li><li><strong>Victims tricked into granting remote access, leading to malware, lateral movement, and ransomware</strong></li><li><strong>Defenses: verify support contacts, train staff, harden Teams, and use Defender Safe Links/ZAP</strong></li></ul><p>Microsoft is warning about an ongoing hacking campaign that starts with a Teams message and ends with a ransomware infection and data theft.</p><p>In a new in-depth report published on the Microsoft blog, it was said that unnamed threat actors were reaching out to their targets at various enterprises via a <a href="https://www.techradar.com/best/best-online-collaboration-tools" target="_blank">Teams chat</a>, while impersonating IT staff.</p><p>They were coercing their victims into granting remote access via screen sharing or <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote monitoring and management tools</a> and once received, used their access to install malware loaders and various other implants.</p><h2 id="how-to-defend-against-teams-borne-phishing">How to defend against Teams-borne phishing</h2><p>The malware was just the first stage of the attack. Subsequent stages include host reconnaissance, security-product and virtualization discovery, and “periodic desktop screen capture”. In other words - mapping out the landscape and conducting espionage.</p><p>The crooks would then enumerate domain accounts, servers, and users, through native tools and Active Directory Service Interfaces (ADSI) queries and begin moving laterally.</p><p>The final step includes identifying and extracting valuable data, followed by a ransomware infection.</p><p>Microsoft does not name the perpetrators, and mostly refers to them as “threat actors”. It makes sense, since the “fake IT support via Teams” technique is being used by multiple groups at this moment. Russia’s Cozy Bear, FIN7, and Storm-1811 are probably the most obvious examples.</p><p>The world’s biggest extortionists - ShinyHunters - are also known to use Teams to trick victims into granting access, but this group rarely deploys an encryptor and instead just focuses on data exfiltration.</p><p>Whoever the attackers are, and whoever they’re after, one thing is for certain - the risk in the enterprise environment has never been greater. </p><p>That is why Microsoft advises reinforcing user education by establishing internal helpdesk authentication phrases, and by training employees to recognize external-tenant indicators.</p><p>The company also urges enterprises to verify unsolicited support contact, and to harden Microsoft Teams and email against social engineering. “Use Microsoft Defender for Office 365 with Safe Links and Zero-hour auto purge (ZAP) so malicious messages and URLs are neutralized at time of click and removed after delivery,” Microsoft urges.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/it-helpdesk-impersonation-hits-microsoft-teams-once-again-with-the-hackers-hiding-their-activity-within-legitimate-tools</link>
                                                                            <description>
                            <![CDATA[ Microsoft is warning about an ongoing scam campaign starting in Teams. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QAnBBRikxHpmReRRcBoNhU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D4YBMfcEsNT7BhaNJJgm2A-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 16:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/D4YBMfcEsNT7BhaNJJgm2A-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pexels]]></media:description>                                                            <media:text><![CDATA[Collaboration in an office.]]></media:text>
                                <media:title type="plain"><![CDATA[Collaboration in an office.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D4YBMfcEsNT7BhaNJJgm2A-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft warns of Teams‑based campaign where attackers impersonate IT staff</strong></li><li><strong>Victims tricked into granting remote access, leading to malware, lateral movement, and ransomware</strong></li><li><strong>Defenses: verify support contacts, train staff, harden Teams, and use Defender Safe Links/ZAP</strong></li></ul><p>Microsoft is warning about an ongoing hacking campaign that starts with a Teams message and ends with a ransomware infection and data theft.</p><p>In a new in-depth report published on the Microsoft blog, it was said that unnamed threat actors were reaching out to their targets at various enterprises via a <a href="https://www.techradar.com/best/best-online-collaboration-tools" target="_blank">Teams chat</a>, while impersonating IT staff.</p><p>They were coercing their victims into granting remote access via screen sharing or <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote monitoring and management tools</a> and once received, used their access to install malware loaders and various other implants.</p><h2 id="how-to-defend-against-teams-borne-phishing">How to defend against Teams-borne phishing</h2><p>The malware was just the first stage of the attack. Subsequent stages include host reconnaissance, security-product and virtualization discovery, and “periodic desktop screen capture”. In other words - mapping out the landscape and conducting espionage.</p><p>The crooks would then enumerate domain accounts, servers, and users, through native tools and Active Directory Service Interfaces (ADSI) queries and begin moving laterally.</p><p>The final step includes identifying and extracting valuable data, followed by a ransomware infection.</p><p>Microsoft does not name the perpetrators, and mostly refers to them as “threat actors”. It makes sense, since the “fake IT support via Teams” technique is being used by multiple groups at this moment. Russia’s Cozy Bear, FIN7, and Storm-1811 are probably the most obvious examples.</p><p>The world’s biggest extortionists - ShinyHunters - are also known to use Teams to trick victims into granting access, but this group rarely deploys an encryptor and instead just focuses on data exfiltration.</p><p>Whoever the attackers are, and whoever they’re after, one thing is for certain - the risk in the enterprise environment has never been greater. </p><p>That is why Microsoft advises reinforcing user education by establishing internal helpdesk authentication phrases, and by training employees to recognize external-tenant indicators.</p><p>The company also urges enterprises to verify unsolicited support contact, and to harden Microsoft Teams and email against social engineering. “Use Microsoft Defender for Office 365 with Safe Links and Zero-hour auto purge (ZAP) so malicious messages and URLs are neutralized at time of click and removed after delivery,” Microsoft urges.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Clicking 'Allow' on a Google and Microsoft permission screens could give hackers access to your entire account, FBI warns ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>FBI warns of rising </strong><em><strong>OAuth consent phishing</strong></em><strong> attacks exploiting legitimate app permissions</strong></li><li><strong>Victims tricked into granting malicious apps access, enabling email reading and sending</strong></li><li><strong>Password changes don’t help; users must revoke tokens in app security settings</strong></li></ul><p>Hackers found a way to access your data, read your messages, and even send emails to your contacts, without ever needing your password or other login credentials. All they need from you is a single click on a completely legitimate, well-known platform.</p><p>The technique is called “OAuth consent phishing”. It’s been around for more than a year and it’s gotten popular to a point where even the FBI is taking note. Earlier this week, the law enforcement agency issued a new public service announcement, via its Internet Crime Complaint Center (IC3), warning Americans about the threat.</p><p>OAuth (Open Authorization) is an internet standard that allows users to give apps access to their account on another service, without giving the app their <a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> for that service. For example, when users install a new app, they have the “Continue with Google” option. When they click it, they are asked if they allow the app to access their email. If they approve, Google gives that app a special access token, which allows the app to access the user’s Google account without ever seeing the password.</p><h2 id="pulling-off-an-oauth-attack">Pulling off an OAuth attack</h2><p>So, to pull off an OAuth attack, the threat actor must first trick Google (or Microsoft, or any other company providing the service) and get their (malicious) app registered on the platform. Then they would reach out to their target via instant messaging, while impersonating government officials, media, and other publicly known personalities, and sharing a link to what appears to be a document.</p><p>The link redirects the victim to a legitimate service (for example, Google), where they are asked to grant permissions to the malicious app. If they approve, the attackers gain access to their email accounts with which they can do almost anything.</p><p>To make matters worse, simply changing the password does not fix the issue. The only way to eliminate the threat is to revoke the access token that was given, which can be done in the application security settings.</p><p>The FBI did not say who the threat actors were or who they were targeting, other than they were “prominent victims”. Their family members were being targeted, as well.</p><p><em>Via </em><a href="https://cybernews.com/news/oauth-consent-phishing-fbi-warning-account-takeover/" target="_blank"><em>The Record</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/clicking-allow-on-a-google-and-microsoft-permission-screens-could-give-hackers-access-to-your-entire-account-fbi-warns</link>
                                                                            <description>
                            <![CDATA[ OAuth consent phishing is a thing and the FBI is worried. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pWbGg4PydfXBEVQetdDJBV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 14:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay/Tumisu]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing]]></media:description>                                                            <media:text><![CDATA[Phishing]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>FBI warns of rising </strong><em><strong>OAuth consent phishing</strong></em><strong> attacks exploiting legitimate app permissions</strong></li><li><strong>Victims tricked into granting malicious apps access, enabling email reading and sending</strong></li><li><strong>Password changes don’t help; users must revoke tokens in app security settings</strong></li></ul><p>Hackers found a way to access your data, read your messages, and even send emails to your contacts, without ever needing your password or other login credentials. All they need from you is a single click on a completely legitimate, well-known platform.</p><p>The technique is called “OAuth consent phishing”. It’s been around for more than a year and it’s gotten popular to a point where even the FBI is taking note. Earlier this week, the law enforcement agency issued a new public service announcement, via its Internet Crime Complaint Center (IC3), warning Americans about the threat.</p><p>OAuth (Open Authorization) is an internet standard that allows users to give apps access to their account on another service, without giving the app their <a href="https://www.techradar.com/best/password-manager" target="_blank">password</a> for that service. For example, when users install a new app, they have the “Continue with Google” option. When they click it, they are asked if they allow the app to access their email. If they approve, Google gives that app a special access token, which allows the app to access the user’s Google account without ever seeing the password.</p><h2 id="pulling-off-an-oauth-attack">Pulling off an OAuth attack</h2><p>So, to pull off an OAuth attack, the threat actor must first trick Google (or Microsoft, or any other company providing the service) and get their (malicious) app registered on the platform. Then they would reach out to their target via instant messaging, while impersonating government officials, media, and other publicly known personalities, and sharing a link to what appears to be a document.</p><p>The link redirects the victim to a legitimate service (for example, Google), where they are asked to grant permissions to the malicious app. If they approve, the attackers gain access to their email accounts with which they can do almost anything.</p><p>To make matters worse, simply changing the password does not fix the issue. The only way to eliminate the threat is to revoke the access token that was given, which can be done in the application security settings.</p><p>The FBI did not say who the threat actors were or who they were targeting, other than they were “prominent victims”. Their family members were being targeted, as well.</p><p><em>Via </em><a href="https://cybernews.com/news/oauth-consent-phishing-fbi-warning-account-takeover/" target="_blank"><em>The Record</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thomson Reuters hit by cyberattack that saw court documents across 11 states accessed by a hacker ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Thomson Reuters confirmed March 2026 breach of its C‑Track court management system</strong></li><li><strong>Incident affected courts in 11 US states, Ontario, and the US Virgin Islands</strong></li><li><strong>No operational disruption; scope of exposed records still under investigation, no misuse reported yet</strong></li></ul><p>Thomson Reuters, the IT company behind the Reuters news agency, suffered a cyberattack a few months ago, exposing certain court documents to the attackers. In a brief announcement published earlier this week, it seems Thomson Reuters only noticed the intrusion now, months after it was already over.</p><p>Here is what happened: Thomson Reuters operates a court case-management system called C-Track. It is a tool used by different courts to manage things like cases, filings, hearings, and schedules. It is used by courts in several US states, the US Virgin Islands, as well as Ontario, Canada.</p><p>On June 30, 2026, Thomson Reuters detected unauthorized activity in one of its cloud environments, prompting an investigation which later determined that an unauthorized threat actor broke in and obtained some C-Track files. This happened in March 2026. </p><h2 id="investigation-underway">Investigation underway</h2><p>So far, the incident is confirmed to have taken place across 11 US states (Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming), the U.S. Virgin Islands, and Ontario, Canada, exposing court records and personal information. Ontario's three Chief Justices confirmed it, as well, saying Thomson Reuters notified Ontario's Ministry of the Attorney General on July 23.</p><p>A more detailed investigation is currently underway, and all relevant authorities have been notified, it was said. At press time, Thomson Reuters did not yet determine exactly what information was accessed, or how many people were affected. The good news, however, is that there is currently no evidence of identity theft resulting from the incident, and there is no indication that systems handling court-related financial transactions were affected. </p><p>C-Track itself remains operational, as well. No threat actors have yet claimed responsibility for the attack or threatened to leak the files to the dark web.</p><p>"There has been no operational disruption to C-Track as a result of this incident," a Thomson Reuters spokesperson said. "Our products and services remain fully operational and are safe ​to continue to use. Independent ​cybersecurity experts assisted in ⁠the investigation and validated the remediation measures implemented."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/thomson-reuters-hit-by-cyberattack-that-saw-court-documents-across-11-states-accessed-by-a-hacker</link>
                                                                            <description>
                            <![CDATA[ A threat actor accessed C-Track files, compromised a cloud environment, and accessed court records across 11 states. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m8aiHByXqAA9YTCGGbFHxY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 14:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Thomson Reuters confirmed March 2026 breach of its C‑Track court management system</strong></li><li><strong>Incident affected courts in 11 US states, Ontario, and the US Virgin Islands</strong></li><li><strong>No operational disruption; scope of exposed records still under investigation, no misuse reported yet</strong></li></ul><p>Thomson Reuters, the IT company behind the Reuters news agency, suffered a cyberattack a few months ago, exposing certain court documents to the attackers. In a brief announcement published earlier this week, it seems Thomson Reuters only noticed the intrusion now, months after it was already over.</p><p>Here is what happened: Thomson Reuters operates a court case-management system called C-Track. It is a tool used by different courts to manage things like cases, filings, hearings, and schedules. It is used by courts in several US states, the US Virgin Islands, as well as Ontario, Canada.</p><p>On June 30, 2026, Thomson Reuters detected unauthorized activity in one of its cloud environments, prompting an investigation which later determined that an unauthorized threat actor broke in and obtained some C-Track files. This happened in March 2026. </p><h2 id="investigation-underway">Investigation underway</h2><p>So far, the incident is confirmed to have taken place across 11 US states (Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming), the U.S. Virgin Islands, and Ontario, Canada, exposing court records and personal information. Ontario's three Chief Justices confirmed it, as well, saying Thomson Reuters notified Ontario's Ministry of the Attorney General on July 23.</p><p>A more detailed investigation is currently underway, and all relevant authorities have been notified, it was said. At press time, Thomson Reuters did not yet determine exactly what information was accessed, or how many people were affected. The good news, however, is that there is currently no evidence of identity theft resulting from the incident, and there is no indication that systems handling court-related financial transactions were affected. </p><p>C-Track itself remains operational, as well. No threat actors have yet claimed responsibility for the attack or threatened to leak the files to the dark web.</p><p>"There has been no operational disruption to C-Track as a result of this incident," a Thomson Reuters spokesperson said. "Our products and services remain fully operational and are safe ​to continue to use. Independent ​cybersecurity experts assisted in ⁠the investigation and validated the remediation measures implemented."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>