News

OpenAI tightens defenses after AI agents breach research environment

OpenAI tightens defenses after AI agents breach research environment 2026-08-18 at 12:41 By Anamarija Pogorelec Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production infrastructure by chaining together multiple weaknesses, OpenAI began strengthening its safety requirements. The weaknesses included previously unknown vulnerabilities and credentials leaked […]

OpenAI tightens defenses after AI agents breach research environment Read More »

France’s tax authority admits hackers made off with data on 678,000 individuals

France’s tax authority admits hackers made off with data on 678,000 individuals 2026-08-17 at 17:20 By Sinisa Markovic France’s tax authority has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems, saying the intrusion exposed data on 678,000 individuals and professionals. The incident came to light after an

France’s tax authority admits hackers made off with data on 678,000 individuals Read More »

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer 2026-08-17 at 15:23 By Sinisa Markovic A recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns. The vulnerability, tracked as CVE-2026-65400, , let

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer Read More »

SafePal breach affects 39,798 customers, data allegedly for sale

SafePal breach affects 39,798 customers, data allegedly for sale 2026-08-17 at 13:29 By Sinisa Markovic Cryptocurrency wallet maker SafePal disclosed a data breach that exposed order information for 39,798 customers, including names, email addresses, shipping addresses, phone numbers and purchase details. The company traced the exposure to an authorization flaw in a plug-in used for

SafePal breach affects 39,798 customers, data allegedly for sale Read More »

Police bust cybercrime ring accused of stealing €30 million in four-day spree

Police bust cybercrime ring accused of stealing €30 million in four-day spree 2026-08-17 at 11:08 By Sinisa Markovic German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. Brazilian police

Police bust cybercrime ring accused of stealing €30 million in four-day spree Read More »

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Windows 11’s strongest security defenses can be bypassed without a screwdriver 2026-08-17 at 08:30 By Sinisa Markovic Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has

Windows 11’s strongest security defenses can be bypassed without a screwdriver Read More »

Hazmat: Open-source containment for AI agents

Hazmat: Open-source containment for AI agents 2026-08-17 at 08:00 By Anamarija Pogorelec Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the

Hazmat: Open-source containment for AI agents Read More »

Product showcase: ScamNet looks for warning signs in suspicious calls and shady links

Product showcase: ScamNet looks for warning signs in suspicious calls and shady links 2026-08-17 at 07:30 By Anamarija Pogorelec ScamNet: Anti-Scam Suite is a consumer security app from Synaptrex Technologies that helps users detect and block scams involving phone calls, text messages, websites, and other suspicious content. The app is available for iPhone, iPad, and

Product showcase: ScamNet looks for warning signs in suspicious calls and shady links Read More »

When companies get specific about AI, revenue growth looks different

When companies get specific about AI, revenue growth looks different 2026-08-17 at 07:00 By Anamarija Pogorelec Companies that provide specific evidence of how they use AI tend to record stronger revenue growth. Researchers at Carnegie Mellon University and Larridin examined a study universe of 564 companies across 12 industry sectors. Individual analyses used smaller samples

When companies get specific about AI, revenue growth looks different Read More »

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day 2026-08-16 at 11:00 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day Read More »

New Android malware relays bank cards to fraudsters while victims still hold them

New Android malware relays bank cards to fraudsters while victims still hold them 2026-08-14 at 14:08 By Sinisa Markovic Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real time. WindRelay is paired with the SpyNote remote access

New Android malware relays bank cards to fraudsters while victims still hold them Read More »

OpenAI’s GPT-5.6 Sol runs up to 14× faster with Ultrafast mode

OpenAI’s GPT-5.6 Sol runs up to 14× faster with Ultrafast mode 2026-08-14 at 13:55 By Anamarija Pogorelec OpenAI’s GPT-5.6 Sol on Ultrafast mode is available in limited preview to a select group of customers, launching first through the OpenAI API. The company says the service runs up to 14 times faster than Standard processing and

OpenAI’s GPT-5.6 Sol runs up to 14× faster with Ultrafast mode Read More »

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals 2026-08-14 at 11:25 By Anamarija Pogorelec AWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027, ahead of the Certification Authority/Browser (CA/B) Forum’s March 15, 2028 deadline for ending email-based domain validation. The CA/B Forum sets standards that browsers and

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals Read More »

Ukrainian police raid 94 fraudulent call centers, seize $2 million

Ukrainian police raid 94 fraudulent call centers, seize $2 million 2026-08-14 at 10:56 By Sinisa Markovic Ukrainian police have disrupted 94 fraudulent call centers during a nationwide operation that involved more than 400 searches and the seizure of thousands of computers, phones, and SIM cards. Ukrainian police raid at a fraudulent call center (Source: Cyberpolice

Ukrainian police raid 94 fraudulent call centers, seize $2 million Read More »

The hardest part of agentic AI may be rebuilding the business

The hardest part of agentic AI may be rebuilding the business 2026-08-14 at 08:30 By Anamarija Pogorelec Organizations expect AI agents to change how work gets done, driving productivity and growth while allowing employees to focus on higher-value tasks. Few, however, have the processes and workflows needed to realize those benefits, according to Deloitte’s latest

The hardest part of agentic AI may be rebuilding the business Read More »

Weak IAM affects up to 98% of cloud environments

Weak IAM affects up to 98% of cloud environments 2026-08-14 at 08:00 By Anamarija Pogorelec Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now mandates baseline cloud configuration practices for US federal

Weak IAM affects up to 98% of cloud environments Read More »

17 draft Cyber Resilience Act standards are open for comment

17 draft Cyber Resilience Act standards are open for comment 2026-08-14 at 07:30 By Anamarija Pogorelec A company selling a connected toy in Europe must show by the end of 2027 that the product meets the Cyber Resilience Act. The law states what manufacturers have to achieve and stops there, which leaves the toymaker to

17 draft Cyber Resilience Act standards are open for comment Read More »

New infosec products of the week: August 14, 2026

New infosec products of the week: August 14, 2026 2026-08-14 at 07:00 By Anamarija Pogorelec Here’s a look at the most interesting products from the past week, featuring releases from A10 Networks, ScienceLogic, Searchlight Cyber, and SelectHub. ScienceLogic delivers secure AI deployment and smarter IT operations with Skylar AI 2.5 ScienceLogic has announced Skylar AI

New infosec products of the week: August 14, 2026 Read More »

White House authorizes private US companies to hack foreign criminal networks

White House authorizes private US companies to hack foreign criminal networks 2026-08-13 at 17:31 By Sinisa Markovic President Trump signed a National Security Presidential Memorandum on August 12 allowing vetted private companies to run offensive cyber operations against foreign threat actors, under the control and oversight of the US government. The post White House authorizes

White House authorizes private US companies to hack foreign criminal networks Read More »

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040) 2026-08-13 at 16:05 By Sinisa Markovic Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About CVE-2026-55040 Tracked as CVE-2026-55040, the vulnerability was patched by Microsoft as part of its July 2026 Patch Tuesday

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040) Read More »

Scroll to Top