<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.techradar.com/uk/feeds/tag/security"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar UK in Security ]]></title>
                <link>https://www.techradar.com/uk/pro/security</link>
        <description><![CDATA[ All the latest security content from the TechRadar  UK team ]]></description>
                                    <lastBuildDate>Tue, 18 Aug 2026 15:05:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Geekom reveals multiple mini-PCs may be infected with malware hidden in a network driver — but it's now down to you to fix your PC ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Geekom has admitted a software driver contained malware</strong></li><li><strong>A LAN driver on a legacy page was hosting the Asruex backdoor</strong></li><li><strong>The malware can track keystrokes, steal passwords, and intercept data</strong></li></ul><p>Hardware maker Geekom has admitted that a network driver for multiple mini PC variants hosted Asruex backdoor malware, potentially putting users at risk</p><p>The LAN driver for Geekom’s range of A7, A8, AE7, AE8, AX7 Pro and AX8 Pro mini-PCs hosted the malicious package with administrator-level permissions that allowed it to monitor everything you type, steal data, and even swipe passwords from your machine. The malicious software also connects to a command and control (C2) network to send and receive information from hackers.</p><p>Geekom has issued an apology and removed the software package in question, but if you have a Geekom mini PC from the aforementioned range and have installed the LAN driver, I’d definitely recommend doing a full system virus scan, with a wipe and reset just to be sure.</p><h2 id="geekom-ships-malware-riddled-lan-driver">Geekom ships malware-riddled LAN driver</h2><p><a href="https://videocardz.com/newz/geekom-mini-pc-driver-archive-contains-file-flagged-as-malware" target="_blank"><em>Videocardz</em></a> first broke the story after investigating claims from a Reddit user who reported finding a malicious executable file contained within the LAN driver.</p><p><em>Videocardz</em> then independently investigated the claim using FileScan.IO, MetaDefender VirusTotal, and YARAify. Each antivirus engine detected the executable as malicious.</p><p>In Geekom’s statement about the malicious file, the company said that the driver was hosted on a “legacy page [that] had already been replaced and was no longer accessible through the normal Support navigation, although it remained indexed by search engines.”</p><p>So when users searched for the LAN driver using Google, the result that came up was the malicious file. I always recommend users install drivers and other software from the official distributor rather than using Google listings as hackers can use tactics such as SEO poisoning or promoted pages to offer dodgy software. But in this case the legacy page was official.</p><p>Geekom has <a href="https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs" target="_blank" rel="nofollow">confirmed</a> that none of its mini PC range were shipped with the malicious driver preinstalled, so if you haven’t directly downloaded the malicious software from the legacy page, you should be okay. But consider running a Windows Defender scan to be sure.</p><p>In order to guarantee that your mini PC is free of the malicious driver, perform a complete wipe and reset of Windows, and install a new Windows image direct from Microsoft’s official page. Going forward, only install software and drivers from the official support pages of the manufacturer.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/geekom-reveals-multiple-mini-pcs-may-be-infected-with-malware-hidden-in-a-network-driver-but-its-now-down-to-you-to-fix-your-pc</link>
                                                                            <description>
                            <![CDATA[ A malicious executable hidden within a LAN driver can track keystrokes, intercept data, and swipe passwords from Geekom mini-PCs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AhLptuzu7RCo7xSnaxqfyg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WJok7QZ99U3Sz57DMBX87f-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WJok7QZ99U3Sz57DMBX87f-1280-80.jpg">
                                                            <media:credit><![CDATA[Alastair Jennings]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Geekom Mini PC A7]]></media:description>                                                            <media:text><![CDATA[Geekom Mini PC A7]]></media:text>
                                <media:title type="plain"><![CDATA[Geekom Mini PC A7]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WJok7QZ99U3Sz57DMBX87f-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Geekom has admitted a software driver contained malware</strong></li><li><strong>A LAN driver on a legacy page was hosting the Asruex backdoor</strong></li><li><strong>The malware can track keystrokes, steal passwords, and intercept data</strong></li></ul><p>Hardware maker Geekom has admitted that a network driver for multiple mini PC variants hosted Asruex backdoor malware, potentially putting users at risk</p><p>The LAN driver for Geekom’s range of A7, A8, AE7, AE8, AX7 Pro and AX8 Pro mini-PCs hosted the malicious package with administrator-level permissions that allowed it to monitor everything you type, steal data, and even swipe passwords from your machine. The malicious software also connects to a command and control (C2) network to send and receive information from hackers.</p><p>Geekom has issued an apology and removed the software package in question, but if you have a Geekom mini PC from the aforementioned range and have installed the LAN driver, I’d definitely recommend doing a full system virus scan, with a wipe and reset just to be sure.</p><h2 id="geekom-ships-malware-riddled-lan-driver">Geekom ships malware-riddled LAN driver</h2><p><a href="https://videocardz.com/newz/geekom-mini-pc-driver-archive-contains-file-flagged-as-malware" target="_blank"><em>Videocardz</em></a> first broke the story after investigating claims from a Reddit user who reported finding a malicious executable file contained within the LAN driver.</p><p><em>Videocardz</em> then independently investigated the claim using FileScan.IO, MetaDefender VirusTotal, and YARAify. Each antivirus engine detected the executable as malicious.</p><p>In Geekom’s statement about the malicious file, the company said that the driver was hosted on a “legacy page [that] had already been replaced and was no longer accessible through the normal Support navigation, although it remained indexed by search engines.”</p><p>So when users searched for the LAN driver using Google, the result that came up was the malicious file. I always recommend users install drivers and other software from the official distributor rather than using Google listings as hackers can use tactics such as SEO poisoning or promoted pages to offer dodgy software. But in this case the legacy page was official.</p><p>Geekom has <a href="https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs" target="_blank" rel="nofollow">confirmed</a> that none of its mini PC range were shipped with the malicious driver preinstalled, so if you haven’t directly downloaded the malicious software from the legacy page, you should be okay. But consider running a Windows Defender scan to be sure.</p><p>In order to guarantee that your mini PC is free of the malicious driver, perform a complete wipe and reset of Windows, and install a new Windows image direct from Microsoft’s official page. Going forward, only install software and drivers from the official support pages of the manufacturer.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Loan company breach sees nearly 750,000 users have financial info, SSNs leaked ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Heights Finance breach exposed sensitive customer data via a compromised third‑party cloud platform</strong></li><li><strong>Stolen records included contact details, financial info, and government identifiers</strong></li><li><strong>Over 700,000 Texans affected; company offers credit monitoring and identity protection</strong></li></ul><p>US loan company Heights Finance has revealed it suffered a cyberattack earlier in 2026 in which it lost sensitive data on hundreds of thousands of its customers.</p><p>The company published a data breach notification on its website, disclosing that on May 7 2026, it saw an “unauthorized actor” gaining access to a cloud-based platform, hosted by a third party, which the company uses to store certain customer data. </p><p>The breach was limited to that cloud platform only and did not affect its loan management system, or other systems and networks.</p><h2 id="at-least-700-000-victims">At least 700,000 victims</h2><p>As is standard practice in these incidents, Heights Finance notified the relevant authorities and brought in outside cybersecurity help.</p><p>The subsequent investigation determined that the attackers - which were not named - stole contact details (names, postal addresses, phone numbers, email addresses), financial information (account details, bank account information such as bank name, account number, routing number), government identifiers (Social Security numbers, tax IDs, driver’s license numbers), and other miscellaneous data.</p><p>“Your information may be involved if you received a loan through Heights, or if you inquired about or applied for a loan product (including through a third party),” the company said. “Your information may also be involved if you were a former borrower of Curo Management or any of its former or current related brands.”</p><p>The exact number of affected individuals is not known at this time. Heights Finance told regulators in Texas that the breach affected more than 730,000 of its residents, and added that it affected those living in Alabama, Tennessee, Georgia, Texas and South Carolina.</p><p>We don’t know which <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud-based platform</a> Heights Finance is using, and the threat actors are yet to claim responsibility for the attack. In the meantime, the company is offering affected customers credit monitoring and identity protection services through Epiq.</p><p><em>Via </em><a href="https://therecord.media/financial-info-leak-debt-consolidator" target="_blank"><em>The Record</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/loan-company-breach-sees-nearly-750-000-users-have-financial-info-ssns-leaked</link>
                                                                            <description>
                            <![CDATA[ Heights Finance said its cloud account was compromised, and information such as bank accounts and SSNs, stolen. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sVNrSWMVEPvYz8KDTwayqF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 14:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:description>                                                            <media:text><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:text>
                                <media:title type="plain"><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Heights Finance breach exposed sensitive customer data via a compromised third‑party cloud platform</strong></li><li><strong>Stolen records included contact details, financial info, and government identifiers</strong></li><li><strong>Over 700,000 Texans affected; company offers credit monitoring and identity protection</strong></li></ul><p>US loan company Heights Finance has revealed it suffered a cyberattack earlier in 2026 in which it lost sensitive data on hundreds of thousands of its customers.</p><p>The company published a data breach notification on its website, disclosing that on May 7 2026, it saw an “unauthorized actor” gaining access to a cloud-based platform, hosted by a third party, which the company uses to store certain customer data. </p><p>The breach was limited to that cloud platform only and did not affect its loan management system, or other systems and networks.</p><h2 id="at-least-700-000-victims">At least 700,000 victims</h2><p>As is standard practice in these incidents, Heights Finance notified the relevant authorities and brought in outside cybersecurity help.</p><p>The subsequent investigation determined that the attackers - which were not named - stole contact details (names, postal addresses, phone numbers, email addresses), financial information (account details, bank account information such as bank name, account number, routing number), government identifiers (Social Security numbers, tax IDs, driver’s license numbers), and other miscellaneous data.</p><p>“Your information may be involved if you received a loan through Heights, or if you inquired about or applied for a loan product (including through a third party),” the company said. “Your information may also be involved if you were a former borrower of Curo Management or any of its former or current related brands.”</p><p>The exact number of affected individuals is not known at this time. Heights Finance told regulators in Texas that the breach affected more than 730,000 of its residents, and added that it affected those living in Alabama, Tennessee, Georgia, Texas and South Carolina.</p><p>We don’t know which <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud-based platform</a> Heights Finance is using, and the threat actors are yet to claim responsibility for the attack. In the meantime, the company is offering affected customers credit monitoring and identity protection services through Epiq.</p><p><em>Via </em><a href="https://therecord.media/financial-info-leak-debt-consolidator" target="_blank"><em>The Record</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Millions of stolen records allegedly dumped online by mystery "Hatman" hacker — McDonalds, Vodafone and more see Microsoft Azure records stolen ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Hacker “TheHatman” claims to have stolen millions of Azure/Entra employee records from major firms</strong></li><li><strong>Data includes names, emails, job titles, privileged accounts; risks include impersonation and fraud</strong></li><li><strong>Victims dispute scope, but researchers say infostealer‑based theft makes the leaks likely authentic</strong></li></ul><p>A cybercriminal is selling millions of user records on the dark web, which they claim to have stolen from large organizations such as McDonalds, Tata Consultancy Services, and Wyndham Hotels.</p><p>A hacker going by the alias “TheHatman” posted multiple threads on dark web forums, claiming to have stolen information from Azure and Entra environments. </p><p>TheHatman said they broke in using compromised login credentials, targeting almost a dozen organizations.</p><h2 id="what-was-stolen-and-from-whom">What was stolen and from whom?</h2><p>Among the victims and the number of records exposed, are:</p><p>McDonald’s Corporation: 1,700,000 records<br>TCS (Tata Consultancy Services): 800,000 records<br>Vodafone: 425,000 records<br>HCL Technologies: 250,000 records<br>InterContinental Hotels Group (IHG): 185,000 records<br>Kyndryl: 170,000 records<br>Gap Inc.: 80,000 records<br>Hexaware Technologies: 20,000 records<br>Wyndham Hotels: 9,000 records</p><p>They are now looking for a buyer: “I’m selling McDonald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials,” TheHatman said in one of the posts.</p><p>In their writeup, security researchers from <a href="https://cybernews.com/security/mcdonalds-vodafone-azure-microdoft-credential-theft/" target="_blank"><em>Cybernews</em></a> said they analyzed one of the samples posted on the dark web and said the entries were “consistent with Azure directory exports”.</p><p>They contained employee names, emails, phone numbers, job titles, workplace addresses, IDs, the departments they work in, user group memberships, service accounts, and highly privileged account records. </p><h2 id="what-are-the-risks">What are the risks?</h2><p>Stealing information such as names, email addresses, and workplace details might not sound like a worrisome breach of privacy, but the implications are rather big. Cybercriminals can use it to impersonate a business partner or a major client, and try to trick their employees into installing <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a>, or making a fraudulent wire transaction. That way, they can escalate what seems like a relatively benign breach, into a full-blown cyberattack with material and legal consequences.</p><p>For example, a criminal might discover a Vodafone employee that regularly handles payments to a particular supplier. They might impersonate that supplier’s finance director, engage in conversation and, while requesting a new payment, warn that the company changed their bank account. This is not a purely theoretical scenario - it’s been documented time and time again. </p><h2 id="what-did-the-victims-say">What did the victims say?</h2><p>Most organizations are yet to give an official statement about these claims. Gap told <a href="https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/" target="_blank"><em>BleepingComputer</em></a> that it found no evidence of the breach and suggested that the attackers merely repackaged data from an older incident. </p><p>“Our preliminary investigation indicates that the data in question is limited in scope, non-sensitive and dated back to several years ago. Notably, there is no evidence to suggest that our corporate systems have been compromised,” Gap told the publication.</p><p>Tata Consultancy Services notified the Indian National Stock Exchange about the breach last week, also suggesting that this was a resurfacing of an older incident. </p><p>“The Company has investigated the matter and has not found any credible evidence of a breach of TCS systems or customer environments,” TCS said in the filing. “The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted.”</p><p>TCS said the attackers broke in using credential stuffing, something that could have only been done years ago: “The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such techniques for more than two years.” </p><p>Not everyone agrees with that assessment, though. Security researchers Hudson Rock believe the attackers stole login credentials with an <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">infostealer</a>, rather than through password spraying. </p><p>“Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure,” the researchers said in their report. “If this were a widespread vulnerability, we would likely see a much broader spectrum of organizations impacted, including smaller businesses, rather than just these massive Fortune 500-level enterprises.”</p><p>Hudson Rock also described the stolen data as “likely highly authentic”, hinting that just because it’s older, it doesn’t mean it’s not useful.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/millions-of-stolen-records-allegedly-dumped-online-by-mystery-hatman-hacker-mcdonalds-vodafone-and-more-see-microsoft-azure-records-stolen</link>
                                                                            <description>
                            <![CDATA[ Some affected companies argue the data is years old and claim no breach in their systems. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">g2uaoVUQzwLLWJpVyugm5B</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Thapana Onphalai via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:description>                                                            <media:text><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:text>
                                <media:title type="plain"><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hacker “TheHatman” claims to have stolen millions of Azure/Entra employee records from major firms</strong></li><li><strong>Data includes names, emails, job titles, privileged accounts; risks include impersonation and fraud</strong></li><li><strong>Victims dispute scope, but researchers say infostealer‑based theft makes the leaks likely authentic</strong></li></ul><p>A cybercriminal is selling millions of user records on the dark web, which they claim to have stolen from large organizations such as McDonalds, Tata Consultancy Services, and Wyndham Hotels.</p><p>A hacker going by the alias “TheHatman” posted multiple threads on dark web forums, claiming to have stolen information from Azure and Entra environments. </p><p>TheHatman said they broke in using compromised login credentials, targeting almost a dozen organizations.</p><h2 id="what-was-stolen-and-from-whom">What was stolen and from whom?</h2><p>Among the victims and the number of records exposed, are:</p><p>McDonald’s Corporation: 1,700,000 records<br>TCS (Tata Consultancy Services): 800,000 records<br>Vodafone: 425,000 records<br>HCL Technologies: 250,000 records<br>InterContinental Hotels Group (IHG): 185,000 records<br>Kyndryl: 170,000 records<br>Gap Inc.: 80,000 records<br>Hexaware Technologies: 20,000 records<br>Wyndham Hotels: 9,000 records</p><p>They are now looking for a buyer: “I’m selling McDonald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials,” TheHatman said in one of the posts.</p><p>In their writeup, security researchers from <a href="https://cybernews.com/security/mcdonalds-vodafone-azure-microdoft-credential-theft/" target="_blank"><em>Cybernews</em></a> said they analyzed one of the samples posted on the dark web and said the entries were “consistent with Azure directory exports”.</p><p>They contained employee names, emails, phone numbers, job titles, workplace addresses, IDs, the departments they work in, user group memberships, service accounts, and highly privileged account records. </p><h2 id="what-are-the-risks">What are the risks?</h2><p>Stealing information such as names, email addresses, and workplace details might not sound like a worrisome breach of privacy, but the implications are rather big. Cybercriminals can use it to impersonate a business partner or a major client, and try to trick their employees into installing <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a>, or making a fraudulent wire transaction. That way, they can escalate what seems like a relatively benign breach, into a full-blown cyberattack with material and legal consequences.</p><p>For example, a criminal might discover a Vodafone employee that regularly handles payments to a particular supplier. They might impersonate that supplier’s finance director, engage in conversation and, while requesting a new payment, warn that the company changed their bank account. This is not a purely theoretical scenario - it’s been documented time and time again. </p><h2 id="what-did-the-victims-say">What did the victims say?</h2><p>Most organizations are yet to give an official statement about these claims. Gap told <a href="https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/" target="_blank"><em>BleepingComputer</em></a> that it found no evidence of the breach and suggested that the attackers merely repackaged data from an older incident. </p><p>“Our preliminary investigation indicates that the data in question is limited in scope, non-sensitive and dated back to several years ago. Notably, there is no evidence to suggest that our corporate systems have been compromised,” Gap told the publication.</p><p>Tata Consultancy Services notified the Indian National Stock Exchange about the breach last week, also suggesting that this was a resurfacing of an older incident. </p><p>“The Company has investigated the matter and has not found any credible evidence of a breach of TCS systems or customer environments,” TCS said in the filing. “The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted.”</p><p>TCS said the attackers broke in using credential stuffing, something that could have only been done years ago: “The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such techniques for more than two years.” </p><p>Not everyone agrees with that assessment, though. Security researchers Hudson Rock believe the attackers stole login credentials with an <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">infostealer</a>, rather than through password spraying. </p><p>“Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure,” the researchers said in their report. “If this were a widespread vulnerability, we would likely see a much broader spectrum of organizations impacted, including smaller businesses, rather than just these massive Fortune 500-level enterprises.”</p><p>Hudson Rock also described the stolen data as “likely highly authentic”, hinting that just because it’s older, it doesn’t mean it’s not useful.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Pokémon Center data breach exposes customer info, cancels some orders ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Pokémon Center UK orders disrupted after CEVA Logistics cyberattack on July 30 2026</strong></li><li><strong>Customer names, addresses, emails, and order details likely exposed, but accounts and payments safe</strong></li><li><strong>Around a dozen organizations confirmed affected; no group has claimed responsibility yet</strong></li></ul><p>Customers who recently ordered their favorite Pikachu toy from Pokémon Center might have to do it all over again, since the company suffered a third-party cyberattack which disrupted its operations.</p><p>The official store for Pokémon merchandise in the UK has reached out to its customers via email to warn them about a recent cyberattack and its consequences. </p><p>According to<em> </em><a href="https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/" target="_blank"><em>BleepingComputer</em></a>, which has seen a copy of the email, the company told its customers they had to “cancel your recent order due to an unforeseen fulfilment issue”. </p><div class="product"><a data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="ceva-logistics">CEVA Logistics</h2><p>The company’s website is also showing a notification saying the company is “currently experiencing delays affecting some orders for our UK customers.” </p><p>“These orders may take longer than usual to process, dispatch, and deliver. We apologize for the inconvenience and appreciate your patience.”</p><p>The company said the attack struck its logistics provider, CEVA Logistics. </p><p>"CEVA Logistics, the vendor Pokémon Center utilizes to ship products from PokemonCenter.com for customers in the United Kingdom and Germany, has informed us that unfortunately they were a victim of a cyber attack commencing on 30 July, 2026."</p><p>Last week, one of the biggest shipping and logistics companies in the world <a href="https://www.techradar.com/pro/security/the-ceva-logistics-data-breach-is-having-major-knock-on-effects-across-europe-heres-what-we-know" target="_blank">disclosed an incident</a> that forced it to shut down parts of its IT infrastructure and affected eight warehouses. At the time, a handful of its customers reported being affected by the breach, including Dutch retailers Bol and De Bijenkorf, and PC gaming powerhouse Valve. </p><p>Pokémon Center said the data most likely exposed in this incident includes people’s full names, mailing addresses, phone numbers, <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email addresses</a>, and details about what they previously ordered on the site. User accounts are apparently safe, and so are payment details. </p><p>So far, around a dozen organizations are confirmed as having been affected. No threat actors have claimed responsibility yet. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders</link>
                                                                            <description>
                            <![CDATA[ Another victim of the CEVA Logistics supply chain attack steps forward as orders get halted and postponed. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gmsChWHs9LaKRXbkHCNR48</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uhBYCXndSH8w5FSohcafnX-1280-80.jpeg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 10:23:42 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Aug 2026 13:29:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uhBYCXndSH8w5FSohcafnX-1280-80.jpeg">
                                                            <media:credit><![CDATA[Pokemon Company]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Jiggly puff Angry]]></media:description>                                                            <media:text><![CDATA[Jiggly puff Angry]]></media:text>
                                <media:title type="plain"><![CDATA[Jiggly puff Angry]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uhBYCXndSH8w5FSohcafnX-1280-80.jpeg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Pokémon Center UK orders disrupted after CEVA Logistics cyberattack on July 30 2026</strong></li><li><strong>Customer names, addresses, emails, and order details likely exposed, but accounts and payments safe</strong></li><li><strong>Around a dozen organizations confirmed affected; no group has claimed responsibility yet</strong></li></ul><p>Customers who recently ordered their favorite Pikachu toy from Pokémon Center might have to do it all over again, since the company suffered a third-party cyberattack which disrupted its operations.</p><p>The official store for Pokémon merchandise in the UK has reached out to its customers via email to warn them about a recent cyberattack and its consequences. </p><p>According to<em> </em><a href="https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/" target="_blank"><em>BleepingComputer</em></a>, which has seen a copy of the email, the company told its customers they had to “cancel your recent order due to an unforeseen fulfilment issue”. </p><div class="product"><a data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="ceva-logistics">CEVA Logistics</h2><p>The company’s website is also showing a notification saying the company is “currently experiencing delays affecting some orders for our UK customers.” </p><p>“These orders may take longer than usual to process, dispatch, and deliver. We apologize for the inconvenience and appreciate your patience.”</p><p>The company said the attack struck its logistics provider, CEVA Logistics. </p><p>"CEVA Logistics, the vendor Pokémon Center utilizes to ship products from PokemonCenter.com for customers in the United Kingdom and Germany, has informed us that unfortunately they were a victim of a cyber attack commencing on 30 July, 2026."</p><p>Last week, one of the biggest shipping and logistics companies in the world <a href="https://www.techradar.com/pro/security/the-ceva-logistics-data-breach-is-having-major-knock-on-effects-across-europe-heres-what-we-know" target="_blank">disclosed an incident</a> that forced it to shut down parts of its IT infrastructure and affected eight warehouses. At the time, a handful of its customers reported being affected by the breach, including Dutch retailers Bol and De Bijenkorf, and PC gaming powerhouse Valve. </p><p>Pokémon Center said the data most likely exposed in this incident includes people’s full names, mailing addresses, phone numbers, <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email addresses</a>, and details about what they previously ordered on the site. User accounts are apparently safe, and so are payment details. </p><p>So far, around a dozen organizations are confirmed as having been affected. No threat actors have claimed responsibility yet. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybersecurity needs a new KPI: it's time to measure our ability to adapt ]]></title>
                                                                                                <dc:content><![CDATA[ <p>For years, cybersecurity has become increasingly measurable. <a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> leaders can often tell you how long it takes to detect an intrusion, contain an attack and restore normal operation. Those figures have given boards a straightforward way to judge progress, offering reassurance that investment in security is delivering real improvements.</p><p>Metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) have earned their place at the table. They both provide a clear picture of how effectively security teams perform when something goes wrong and have helped drive better incident response across the industry. </p><p>The problem is not that these metrics are wrong. They were designed for a different era, when technology changed more slowly, attack methods evolved over longer timescales and AI wasn't yet part of the equation.</p><p>Today's businesses are introducing new technologies at an extraordinary pace. AI is becoming embedded across organizations, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud</a> environments continue to expand and businesses are more interconnected than ever before. At the same time, attackers are constantly adapting their own techniques, taking advantage of new tactics and tools almost as quickly as they emerge.</p><p>CISO’s and boards need to dynamically review the changing threat landscape and risk posture and ask themselves whether the metrics relied on for years still tell us everything we need to know.</p><h2 id="mind-the-gap">Mind the gap</h2><p>Every business wants to detect attacks sooner, contain them faster and recover with minimal disruption. That’s why MTTD and MTTR  remain valuable operational measures. They tell us how effectively a security team performed once an incident was underway.</p><p>What they don't tell us is whether the <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> is becoming better prepared for what comes next, more resilient, more agile in recovery. That matters because cyber risk continues to evolve long after an incident has been contained.</p><p>The UK Government's Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses experienced a cyber breach or attack during the previous year.</p><p>This reinforces how security teams are operating in an environment where incidents are a regular reality, whether it's in their own environment, or that of one of their supply chain. Responding well is important, but resilience is shaped by everything that happens before incidents.</p><p>A business may recover quickly from an attack but still take months to review its security policies, reassess supplier risk or strengthen controls in response to what it has learned. By the time those changes are made, the threat landscape will have moved on.</p><p>Traditional metrics tell us how quickly a business responds to an incident. They don't tell us how quickly it learns from one, or how quickly it adapts. </p><h2 id="closing-the-gap">Closing the gap</h2><p>If we're going to close that gap of preparedness, our metrics need to evolve as well. Resilience is no longer defined solely by how well a business responds to isolated incidents, but by how quickly it keeps pace with continuous change.</p><p>I believe organizations should start thinking about another benchmark alongside the ones we already know: Mean Time to Adapt (MTTA).</p><p>MTTA considers how long it takes to recognize a meaningful change in the threat landscape and turn that knowledge into action.</p><p>Sometimes that action will be technical. It could mean updating the rules security tools used to detect emerging attack techniques. Or it might involve tightening access to critical systems after a serious vulnerability is discovered. It may also be a proactive lessons learned view of an attack on another organization or sector to understand how vulnerable the organization would be.</p><p>In other cases, the response will be organizational rather than technical. It may involve reviewing governance, changing how cyber risk is reported to the board or refreshing <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> awareness programs to reflect the latest tactics being used by attackers.  </p><p>Either way, resilience depends on both. The strongest security programs combine technical improvements with organizational change, ensuring businesses can recognize change and act on it quickly.</p><p>That’s why closing this gap is not only a technology challenge. It relies on decision-making, leadership and a willingness to keep questioning whether existing assumptions still hold true. <a href="https://www.techradar.com/best/best-small-business-website-builders">Businesses</a> that adapt well rarely assume their current security program is finished. They expect it to evolve because the environment around them is evolving too.</p><p>That thinking is increasingly reflected across the wider industry. For example, the National Cyber Security Centre's Cyber Assessment Framework places governance, risk management and continual improvement at the heart of cyber resilience. It recognizes that security is an ongoing organizational capability, not a one-time achievement. </p><h2 id="a-different-conversation-in-the-boardroom">A different conversation in the boardroom</h2><p>If preparedness and adaptation becomes a more meaningful measure of resilience, it will change the conversations taking place in the boardroom.</p><p>Most directors already receive regular updates covering incidents, phishing activity and response times. Those reports remain important, but they won’t always show how well the business is responding to change itself.</p><p>The discussion must now move beyond operational reporting and give greater prominence to MTTA. This would give boards a way to measure how quickly an organization responds to change, rather than simply how efficiently it handles incidents.</p><p>In practice, that means asking a different set of questions. How quickly does the business reassess risk when a significant new threat emerges? How long does it take for new intelligence to shape security policies? Have lessons from recent attacks fundamentally changed the way the organization operates, or have they simply been recorded and filed away?</p><p>By measuring adaptation, rather than response alone, organizations can answer these questions with greater confidence and build a broader picture of resilience.</p><p>And this isn't solely a question for security teams. It depends on leadership, governance and how prepared the wider business is to make decisions as risks continue to evolve.</p><h2 id="measuring-what-matters">Measuring what matters</h2><p>MTTD and MTTR will remain valuable measures of operational performance. But if organizations want to understand how resilient they really are, they also need to know how quickly they adapt.</p><p>MTTA fills that gap. It won't replace today's cyber metrics, but it will enhance them by measuring a capability that is becoming increasingly important as technology, AI and cyber threats continue to evolve.</p><p>It’s now MTTA time to shine.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/cybersecurity-needs-a-new-kpi-its-time-to-measure-our-ability-to-adapt</link>
                                                                            <description>
                            <![CDATA[ Cyber resilience depends on more than response times. It's time to measure adaptation too. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pN5E9BZQwVuAYtmzZC5MrH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 10:00:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Cheryl Martin ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For years, cybersecurity has become increasingly measurable. <a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> leaders can often tell you how long it takes to detect an intrusion, contain an attack and restore normal operation. Those figures have given boards a straightforward way to judge progress, offering reassurance that investment in security is delivering real improvements.</p><p>Metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) have earned their place at the table. They both provide a clear picture of how effectively security teams perform when something goes wrong and have helped drive better incident response across the industry. </p><p>The problem is not that these metrics are wrong. They were designed for a different era, when technology changed more slowly, attack methods evolved over longer timescales and AI wasn't yet part of the equation.</p><p>Today's businesses are introducing new technologies at an extraordinary pace. AI is becoming embedded across organizations, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud</a> environments continue to expand and businesses are more interconnected than ever before. At the same time, attackers are constantly adapting their own techniques, taking advantage of new tactics and tools almost as quickly as they emerge.</p><p>CISO’s and boards need to dynamically review the changing threat landscape and risk posture and ask themselves whether the metrics relied on for years still tell us everything we need to know.</p><h2 id="mind-the-gap">Mind the gap</h2><p>Every business wants to detect attacks sooner, contain them faster and recover with minimal disruption. That’s why MTTD and MTTR  remain valuable operational measures. They tell us how effectively a security team performed once an incident was underway.</p><p>What they don't tell us is whether the <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> is becoming better prepared for what comes next, more resilient, more agile in recovery. That matters because cyber risk continues to evolve long after an incident has been contained.</p><p>The UK Government's Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses experienced a cyber breach or attack during the previous year.</p><p>This reinforces how security teams are operating in an environment where incidents are a regular reality, whether it's in their own environment, or that of one of their supply chain. Responding well is important, but resilience is shaped by everything that happens before incidents.</p><p>A business may recover quickly from an attack but still take months to review its security policies, reassess supplier risk or strengthen controls in response to what it has learned. By the time those changes are made, the threat landscape will have moved on.</p><p>Traditional metrics tell us how quickly a business responds to an incident. They don't tell us how quickly it learns from one, or how quickly it adapts. </p><h2 id="closing-the-gap">Closing the gap</h2><p>If we're going to close that gap of preparedness, our metrics need to evolve as well. Resilience is no longer defined solely by how well a business responds to isolated incidents, but by how quickly it keeps pace with continuous change.</p><p>I believe organizations should start thinking about another benchmark alongside the ones we already know: Mean Time to Adapt (MTTA).</p><p>MTTA considers how long it takes to recognize a meaningful change in the threat landscape and turn that knowledge into action.</p><p>Sometimes that action will be technical. It could mean updating the rules security tools used to detect emerging attack techniques. Or it might involve tightening access to critical systems after a serious vulnerability is discovered. It may also be a proactive lessons learned view of an attack on another organization or sector to understand how vulnerable the organization would be.</p><p>In other cases, the response will be organizational rather than technical. It may involve reviewing governance, changing how cyber risk is reported to the board or refreshing <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> awareness programs to reflect the latest tactics being used by attackers.  </p><p>Either way, resilience depends on both. The strongest security programs combine technical improvements with organizational change, ensuring businesses can recognize change and act on it quickly.</p><p>That’s why closing this gap is not only a technology challenge. It relies on decision-making, leadership and a willingness to keep questioning whether existing assumptions still hold true. <a href="https://www.techradar.com/best/best-small-business-website-builders">Businesses</a> that adapt well rarely assume their current security program is finished. They expect it to evolve because the environment around them is evolving too.</p><p>That thinking is increasingly reflected across the wider industry. For example, the National Cyber Security Centre's Cyber Assessment Framework places governance, risk management and continual improvement at the heart of cyber resilience. It recognizes that security is an ongoing organizational capability, not a one-time achievement. </p><h2 id="a-different-conversation-in-the-boardroom">A different conversation in the boardroom</h2><p>If preparedness and adaptation becomes a more meaningful measure of resilience, it will change the conversations taking place in the boardroom.</p><p>Most directors already receive regular updates covering incidents, phishing activity and response times. Those reports remain important, but they won’t always show how well the business is responding to change itself.</p><p>The discussion must now move beyond operational reporting and give greater prominence to MTTA. This would give boards a way to measure how quickly an organization responds to change, rather than simply how efficiently it handles incidents.</p><p>In practice, that means asking a different set of questions. How quickly does the business reassess risk when a significant new threat emerges? How long does it take for new intelligence to shape security policies? Have lessons from recent attacks fundamentally changed the way the organization operates, or have they simply been recorded and filed away?</p><p>By measuring adaptation, rather than response alone, organizations can answer these questions with greater confidence and build a broader picture of resilience.</p><p>And this isn't solely a question for security teams. It depends on leadership, governance and how prepared the wider business is to make decisions as risks continue to evolve.</p><h2 id="measuring-what-matters">Measuring what matters</h2><p>MTTD and MTTR will remain valuable measures of operational performance. But if organizations want to understand how resilient they really are, they also need to know how quickly they adapt.</p><p>MTTA fills that gap. It won't replace today's cyber metrics, but it will enhance them by measuring a capability that is becoming increasingly important as technology, AI and cyber threats continue to evolve.</p><p>It’s now MTTA time to shine.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ National infrastructure needs a new approach to cyber resilience ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The prospect of bringing more of Britain's critical national infrastructure into public ownership has prompted plenty of debate about investment, governance and accountability. </p><p>Far less attention has been paid to what it could mean for <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a>. </p><p>Regardless of where you stand politically, one thing is clear. Public ownership does not make cyber risk disappear. </p><p>If anything, it raises expectations that essential services will be more resilient, more coordinated and better prepared to withstand disruption.</p><p>That expectation reflects the reality of the threat landscape. Energy providers, water companies, transport operators and healthcare organizations all sit at the center of complex digital ecosystems. Their ability to deliver essential services depends on thousands of suppliers, technology vendors and third parties. </p><p>When one organization is compromised, the effects can spread well beyond its own network. Resilience therefore depends on far more than protecting individual organizations. It depends on understanding and managing the relationships between them.</p><p>If the government is serious about strengthening national infrastructure, cybersecurity must become part of that conversation from day one. That means moving beyond isolated <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> programs and towards a model where organizations share intelligence, understand common risks and coordinate their response before disruption spreads.</p><h2 id="critical-infrastructure-extends-beyond-organizational-boundaries">Critical infrastructure extends beyond organizational boundaries</h2><p>Some of the defining cyber attacks of recent years have demonstrated that attackers are rarely interested in a single target. They look for opportunities to compromise one organization in order to reach many others.</p><p>The SolarWinds attack remains one of the clearest examples. By compromising trusted software updates, attackers gained access to thousands of organizations around the world. More recently, the <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> attack on Synnovis disrupted pathology services across several NHS trusts, leading to cancelled operations, delayed appointments and widespread disruption to patient care. </p><p>Neither incident remained confined to the organization that was initially compromised. Both exposed the reality that critical infrastructure now depends on interconnected supply chains as much as physical assets.</p><p>That presents a challenge for every operator of critical national infrastructure. Security can no longer be viewed solely through the lens of protecting your own estate. Organizations also need visibility into the threats affecting suppliers, partners and the wider ecosystem. A vulnerability within a <a href="https://www.techradar.com/best/best-open-source-software">software</a> provider or outsourced service can quickly become a problem for every organization that depends on it.</p><p>This is where many existing security programs begin to show their limitations. Organizations have invested heavily in detection technologies, vulnerability management platforms and threat intelligence feeds. They are collecting more information than ever before. Yet many still struggle to translate that information into confident operational decisions.</p><h2 id="better-decisions-start-with-better-intelligence">Better decisions start with better intelligence</h2><p>The cybersecurity industry has spent years focusing on visibility. The assumption has been that if organizations can discover every vulnerability, identify every <a href="https://www.techradar.com/best/best-software-asset-management-tools">asset</a> and collect every threat feed, they will naturally become more secure.</p><p>The evidence suggests otherwise.</p><p>Filigran's recent State of Threat Management report found that organizations consume an average of fourteen different threat intelligence feeds, yet fewer than half have fully operationalized that intelligence across their security programs. </p><p>At the same time, 84% of respondents said the attacks they experience exploit risks that were already known but had not been prioritized. Almost every organization surveyed also reported difficulty determining whether identified exposures were genuinely exploitable.</p><p>Those findings illustrate a wider industry problem. The challenge is no longer discovering risk. It is deciding which risks deserve immediate attention.</p><p>Security teams are surrounded by alerts, vulnerability reports and intelligence updates. Every tool claims to identify another critical issue demanding urgent action. Without context, everything starts to look important. Analysts spend valuable time investigating vulnerabilities that may never be exploited while genuinely dangerous attack paths remain hidden among the noise. </p><p>That has consequences beyond operational efficiency. Every hour spent investigating a low priority issue is an hour that cannot be spent reducing real business risk. Organizations are not simply overwhelmed by the volume of information. They are overwhelmed by the number of decisions they are expected to make every day.</p><h2 id="threat-intelligence-should-shape-decisions-long-before-an-incident">Threat intelligence should shape decisions long before an incident</h2><p>One reason this happens is that threat intelligence is still too often treated as a function of the Security Operations Centre. Intelligence is gathered, analyzed and used to help detect or investigate malicious activity once attackers have already reached the network.</p><p>Yet, threat intelligence has far greater value when it informs decisions much earlier in the security lifecycle.</p><p>Used effectively, it should help organizations understand which vulnerabilities are actively being targeted, which attack paths present the greatest business risk and which remediation activities will deliver the greatest reduction in exposure. Rather than treating every vulnerability as equally urgent, security teams can focus on the threats that genuinely matter to their environment.</p><p>This is also where Continuous Threat Exposure Management, or CTEM, has an important role to play. CTEM should not be viewed as another technology category or another security acronym. It provides a structured framework for connecting threat intelligence, exposure management, validation and remediation into a continuous process. Instead of relying on assumptions or theoretical risk scores, organizations can validate whether a vulnerability is genuinely exploitable before committing time and resources to fixing it.</p><p>Perhaps the biggest obstacle is not technical at all. Many organizations still operate with threat intelligence, vulnerability management, penetration testing and governance teams working independently, each with different priorities, processes and tooling. Breaking down those silos often delivers greater improvements than introducing another security platform.</p><h2 id="building-a-national-capability">Building a national capability</h2><p>If critical infrastructure is expected to become more resilient, collaboration has to become part of everyday operations rather than something that only happens during a major incident. That thinking is already beginning to take shape. </p><p>Earlier this month, the National Cyber Security Centre and GCHQ issued a call for industry, academia and critical infrastructure operators to help define Cyber Shield, a proposed national cyber defense capability designed to combine AI, shared intelligence and coordinated defense at national scale. </p><p>Significantly, the initiative recognizes that the government cannot build this capability alone. It will depend on close collaboration with the organizations responsible for protecting the UK's essential services. </p><p>Additionally, the Cyber Security and Resilience Bill provides an opportunity to strengthen that approach by encouraging greater consistency across essential sectors. Frameworks such as the National Cyber Security Centre's Cyber Assessment Framework already give organizations a common language for measuring resilience. </p><p>They become even more valuable when they encourage organizations to learn from one another instead of tackling similar challenges in isolation.</p><p>Open standards have an important role to play as well. The Dutch National Cyber Security Centre recently made STIX and TAXII 2.1 the mandatory standard for sharing cyber threat intelligence across government. </p><p>While technical on the surface, the decision reflects a broader principle. When organizations exchange intelligence using common standards, they remove friction from collaboration and can respond to threats more quickly.</p><p>Technology alone will not deliver that outcome. Artificial intelligence, automation and modern security platforms can help organizations process more information and reduce manual effort, but they still depend on good intelligence, sound governance and trusted relationships. </p><p>For the simple reason that fast decisions only become good decisions when they are supported by the right context.</p><h2 id="resilience-is-a-shared-responsibility">Resilience is a shared responsibility</h2><p>Whether more of Britain's critical national infrastructure ultimately moves into public ownership is only part of the story. Cyber attackers do not distinguish between public and private organizations. They target weak links, trusted suppliers and interconnected systems wherever they find them.</p><p>The organizations that will be best prepared for the years ahead will be those that treat resilience as a collective responsibility. They will operationalize threat intelligence before incidents occur, validate real-world risk rather than relying on assumptions, and collaborate across organizational boundaries as readily as attackers do.</p><p>Protecting critical infrastructure has never been solely about defending individual organizations. It is about strengthening the entire ecosystem that keeps essential services running. If the UK wants to build genuinely resilient national infrastructure, that is where the conversation needs to begin.</p><p><a href="https://www.techradar.com/best/best-patch-management-tools"><em>We've listed the best path management software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/national-infrastructure-needs-a-new-approach-to-cyber-resilience</link>
                                                                            <description>
                            <![CDATA[ Public ownership cannot stop cyber threats; Britain needs shared intelligence, prioritized risks and coordinated resilience. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xEJFbFMZL3oxC8gS262oBg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5RYCUPY3MrRkUECQECzDC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 08:56:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jake Taylor ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5RYCUPY3MrRkUECQECzDC-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Trojan horse on top of blocks of hexadecimal programming codes. 3D illustration of the concept of online hacking, computer spyware, malware and ransomware.]]></media:description>                                                            <media:text><![CDATA[Trojan horse on top of blocks of hexadecimal programming codes. 3D illustration of the concept of online hacking, computer spyware, malware and ransomware.]]></media:text>
                                <media:title type="plain"><![CDATA[Trojan horse on top of blocks of hexadecimal programming codes. 3D illustration of the concept of online hacking, computer spyware, malware and ransomware.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5RYCUPY3MrRkUECQECzDC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The prospect of bringing more of Britain's critical national infrastructure into public ownership has prompted plenty of debate about investment, governance and accountability. </p><p>Far less attention has been paid to what it could mean for <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a>. </p><p>Regardless of where you stand politically, one thing is clear. Public ownership does not make cyber risk disappear. </p><p>If anything, it raises expectations that essential services will be more resilient, more coordinated and better prepared to withstand disruption.</p><p>That expectation reflects the reality of the threat landscape. Energy providers, water companies, transport operators and healthcare organizations all sit at the center of complex digital ecosystems. Their ability to deliver essential services depends on thousands of suppliers, technology vendors and third parties. </p><p>When one organization is compromised, the effects can spread well beyond its own network. Resilience therefore depends on far more than protecting individual organizations. It depends on understanding and managing the relationships between them.</p><p>If the government is serious about strengthening national infrastructure, cybersecurity must become part of that conversation from day one. That means moving beyond isolated <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> programs and towards a model where organizations share intelligence, understand common risks and coordinate their response before disruption spreads.</p><h2 id="critical-infrastructure-extends-beyond-organizational-boundaries">Critical infrastructure extends beyond organizational boundaries</h2><p>Some of the defining cyber attacks of recent years have demonstrated that attackers are rarely interested in a single target. They look for opportunities to compromise one organization in order to reach many others.</p><p>The SolarWinds attack remains one of the clearest examples. By compromising trusted software updates, attackers gained access to thousands of organizations around the world. More recently, the <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> attack on Synnovis disrupted pathology services across several NHS trusts, leading to cancelled operations, delayed appointments and widespread disruption to patient care. </p><p>Neither incident remained confined to the organization that was initially compromised. Both exposed the reality that critical infrastructure now depends on interconnected supply chains as much as physical assets.</p><p>That presents a challenge for every operator of critical national infrastructure. Security can no longer be viewed solely through the lens of protecting your own estate. Organizations also need visibility into the threats affecting suppliers, partners and the wider ecosystem. A vulnerability within a <a href="https://www.techradar.com/best/best-open-source-software">software</a> provider or outsourced service can quickly become a problem for every organization that depends on it.</p><p>This is where many existing security programs begin to show their limitations. Organizations have invested heavily in detection technologies, vulnerability management platforms and threat intelligence feeds. They are collecting more information than ever before. Yet many still struggle to translate that information into confident operational decisions.</p><h2 id="better-decisions-start-with-better-intelligence">Better decisions start with better intelligence</h2><p>The cybersecurity industry has spent years focusing on visibility. The assumption has been that if organizations can discover every vulnerability, identify every <a href="https://www.techradar.com/best/best-software-asset-management-tools">asset</a> and collect every threat feed, they will naturally become more secure.</p><p>The evidence suggests otherwise.</p><p>Filigran's recent State of Threat Management report found that organizations consume an average of fourteen different threat intelligence feeds, yet fewer than half have fully operationalized that intelligence across their security programs. </p><p>At the same time, 84% of respondents said the attacks they experience exploit risks that were already known but had not been prioritized. Almost every organization surveyed also reported difficulty determining whether identified exposures were genuinely exploitable.</p><p>Those findings illustrate a wider industry problem. The challenge is no longer discovering risk. It is deciding which risks deserve immediate attention.</p><p>Security teams are surrounded by alerts, vulnerability reports and intelligence updates. Every tool claims to identify another critical issue demanding urgent action. Without context, everything starts to look important. Analysts spend valuable time investigating vulnerabilities that may never be exploited while genuinely dangerous attack paths remain hidden among the noise. </p><p>That has consequences beyond operational efficiency. Every hour spent investigating a low priority issue is an hour that cannot be spent reducing real business risk. Organizations are not simply overwhelmed by the volume of information. They are overwhelmed by the number of decisions they are expected to make every day.</p><h2 id="threat-intelligence-should-shape-decisions-long-before-an-incident">Threat intelligence should shape decisions long before an incident</h2><p>One reason this happens is that threat intelligence is still too often treated as a function of the Security Operations Centre. Intelligence is gathered, analyzed and used to help detect or investigate malicious activity once attackers have already reached the network.</p><p>Yet, threat intelligence has far greater value when it informs decisions much earlier in the security lifecycle.</p><p>Used effectively, it should help organizations understand which vulnerabilities are actively being targeted, which attack paths present the greatest business risk and which remediation activities will deliver the greatest reduction in exposure. Rather than treating every vulnerability as equally urgent, security teams can focus on the threats that genuinely matter to their environment.</p><p>This is also where Continuous Threat Exposure Management, or CTEM, has an important role to play. CTEM should not be viewed as another technology category or another security acronym. It provides a structured framework for connecting threat intelligence, exposure management, validation and remediation into a continuous process. Instead of relying on assumptions or theoretical risk scores, organizations can validate whether a vulnerability is genuinely exploitable before committing time and resources to fixing it.</p><p>Perhaps the biggest obstacle is not technical at all. Many organizations still operate with threat intelligence, vulnerability management, penetration testing and governance teams working independently, each with different priorities, processes and tooling. Breaking down those silos often delivers greater improvements than introducing another security platform.</p><h2 id="building-a-national-capability">Building a national capability</h2><p>If critical infrastructure is expected to become more resilient, collaboration has to become part of everyday operations rather than something that only happens during a major incident. That thinking is already beginning to take shape. </p><p>Earlier this month, the National Cyber Security Centre and GCHQ issued a call for industry, academia and critical infrastructure operators to help define Cyber Shield, a proposed national cyber defense capability designed to combine AI, shared intelligence and coordinated defense at national scale. </p><p>Significantly, the initiative recognizes that the government cannot build this capability alone. It will depend on close collaboration with the organizations responsible for protecting the UK's essential services. </p><p>Additionally, the Cyber Security and Resilience Bill provides an opportunity to strengthen that approach by encouraging greater consistency across essential sectors. Frameworks such as the National Cyber Security Centre's Cyber Assessment Framework already give organizations a common language for measuring resilience. </p><p>They become even more valuable when they encourage organizations to learn from one another instead of tackling similar challenges in isolation.</p><p>Open standards have an important role to play as well. The Dutch National Cyber Security Centre recently made STIX and TAXII 2.1 the mandatory standard for sharing cyber threat intelligence across government. </p><p>While technical on the surface, the decision reflects a broader principle. When organizations exchange intelligence using common standards, they remove friction from collaboration and can respond to threats more quickly.</p><p>Technology alone will not deliver that outcome. Artificial intelligence, automation and modern security platforms can help organizations process more information and reduce manual effort, but they still depend on good intelligence, sound governance and trusted relationships. </p><p>For the simple reason that fast decisions only become good decisions when they are supported by the right context.</p><h2 id="resilience-is-a-shared-responsibility">Resilience is a shared responsibility</h2><p>Whether more of Britain's critical national infrastructure ultimately moves into public ownership is only part of the story. Cyber attackers do not distinguish between public and private organizations. They target weak links, trusted suppliers and interconnected systems wherever they find them.</p><p>The organizations that will be best prepared for the years ahead will be those that treat resilience as a collective responsibility. They will operationalize threat intelligence before incidents occur, validate real-world risk rather than relying on assumptions, and collaborate across organizational boundaries as readily as attackers do.</p><p>Protecting critical infrastructure has never been solely about defending individual organizations. It is about strengthening the entire ecosystem that keeps essential services running. If the UK wants to build genuinely resilient national infrastructure, that is where the conversation needs to begin.</p><p><a href="https://www.techradar.com/best/best-patch-management-tools"><em>We've listed the best path management software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian websites could soon be easy pickings for hackers as security certificates expire — banks, emails, and government systems all potentially at risk ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Japanese certificate authority GlobalSign revoked TLS certificates for thousands of Russian domains in June 2026 as it implemented US and EU sanctions</strong></li><li><strong>As a result, seven major Russian banks now serve certificates from a state root that no mainstream browser trusts, forcing users to manually install them</strong></li><li><strong>Ukraine's Foreign Intelligence Service says the losses turn Russian banking, email, and internal systems into easier targets</strong></li></ul><p>Russian companies are finding themselves in an extremely tricky situation as US OFAC and EU sanctions now affect international security certificates issued by third-party providers.</p><p>A statement <a href="https://szru.gov.ua/news-media/news/rosiyany-spalyat-miliony-rubliv-shchob-vidkryty-sait-vlasnoi-podatkovoi" target="_blank">issued by Ukraine's Foreign Intelligence Service</a> on August 12 said the certificate withdrawals essentially left the country's internal systems, email, and banking exposed to attack because no internationally recognized certificates were issued for their domains.</p><p>It noted Russian state services, including the Federal Tax Service, increasingly fail to load in Chrome, Firefox, and Safari, and estimated that roughly 90% of the Russian market still depends on foreign-issued certificates, and that wide implementation of these sanctions could make it harder for users to access affected sites.</p><div class="product"><a data-dimension112="f4664762-9b08-11f1-a4e4-9bf54b7953c4" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="f4664762-9b08-11f1-a4e4-9bf54b7953c4" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="f4664762-9b08-11f1-a4e4-9bf54b7953c4" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="web-trust-certificates-sanctioned-away">Web trust certificates sanctioned away?</h2><p>The move began on June 13 2026 when Japanese certificate authority GlobalSign, which controls much of Russia's commercial foreign certificate market, force-revoked TLS certificates it had previously issued to Russian companies.</p><p>Its local arm said that it could not influence the parent company's decision, which came due to new CA/Browser Forum rules, starting May 4. The rules effectively made screening applicants against the US OFAC and BIS lists, and European sanctions lists, mandatory for certificate authorities rather than optional, essentially tying the certificate provider's hands.</p><p>The move was implemented in two waves; the first affected an estimated 15,000-20,000 domains, and the second affected a more specific 310 domains across 44 companies, including large domestic names such as Rosneft, Gazprombank, Alrosa, and Positive Technologies.</p><p>The Ukrainian side insists that Russian internal systems, messengers, email, and banking APIs have become "ideal targets for hacker attacks," and there is some truth to it, even if mitigation is already underway on the Russian end. It estimates that reconfiguring infrastructure could cost larger corporations as much as 10 to 50 million rubles and take up to six months, and it is an error-prone process.</p><p>The move saw Russian domain owners, including its banks and tax services, turn elsewhere, with some moving first to a Greek academic certificate authority, HARICA, before turning to China's TrustAsia, which currently provides its state entities with certificates.</p><p>A more complicated play from the Russian end is a homegrown alternative the government continues pushing: <a href="https://www.techradar.com/news/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions" target="_blank">state-issued trust root certificates</a> that users must install manually. While the Ministry of Digital Development describes manual installation of its root certificate as "safe" and as having no effect on device function, <a href="https://www.bleepingcomputer.com/news/security/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions/" target="_blank">security researchers have previously warned in 2022</a> and <a href="https://riposte.levelflow.org/2026/06/state-ssl/" target="_blank">again in 2026</a> that a state-controlled root could be abused for "HTTPS traffic interception and man-in-the-middle attacks".</p><p>Moscow's other recommendation is that users switch to Yandex Browser, which ships with the domestic root built in. Ukraine's narrative dismisses that as an alternative prone to freezing and cache failures and offering no meaningful data protection, an assessment it attributes to "experts inside Russia."</p><p>Whatever the short-term outcomes result in here for .RU domains, a move like this could further disconnect Russia from the rest of the world, with Russian services working smoothly only for users running Russian software with a state root installed. </p><p>This might already be the trajectory for a Russia reeling from cyberattacks and sanctions, but one can assume the certificate revocations will only compress the timeline to that point, whether by design or an unintended consequence.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/russian-websites-could-soon-be-easy-pickings-for-hackers-as-security-certificates-expire-banks-emails-and-government-systems-all-potentially-at-risk</link>
                                                                            <description>
                            <![CDATA[ Russia's websites lost their trusted certificates, and the fix Moscow is offering asks users to install a state root that can vouch for any site on the internet. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VksYNmo8goBbFDPCH35DfJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2026 19:35:00 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Aug 2026 13:30:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Thapana Onphalai via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:description>                                                            <media:text><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:text>
                                <media:title type="plain"><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Japanese certificate authority GlobalSign revoked TLS certificates for thousands of Russian domains in June 2026 as it implemented US and EU sanctions</strong></li><li><strong>As a result, seven major Russian banks now serve certificates from a state root that no mainstream browser trusts, forcing users to manually install them</strong></li><li><strong>Ukraine's Foreign Intelligence Service says the losses turn Russian banking, email, and internal systems into easier targets</strong></li></ul><p>Russian companies are finding themselves in an extremely tricky situation as US OFAC and EU sanctions now affect international security certificates issued by third-party providers.</p><p>A statement <a href="https://szru.gov.ua/news-media/news/rosiyany-spalyat-miliony-rubliv-shchob-vidkryty-sait-vlasnoi-podatkovoi" target="_blank">issued by Ukraine's Foreign Intelligence Service</a> on August 12 said the certificate withdrawals essentially left the country's internal systems, email, and banking exposed to attack because no internationally recognized certificates were issued for their domains.</p><p>It noted Russian state services, including the Federal Tax Service, increasingly fail to load in Chrome, Firefox, and Safari, and estimated that roughly 90% of the Russian market still depends on foreign-issued certificates, and that wide implementation of these sanctions could make it harder for users to access affected sites.</p><div class="product"><a data-dimension112="f4664762-9b08-11f1-a4e4-9bf54b7953c4" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="f4664762-9b08-11f1-a4e4-9bf54b7953c4" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="f4664762-9b08-11f1-a4e4-9bf54b7953c4" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="web-trust-certificates-sanctioned-away">Web trust certificates sanctioned away?</h2><p>The move began on June 13 2026 when Japanese certificate authority GlobalSign, which controls much of Russia's commercial foreign certificate market, force-revoked TLS certificates it had previously issued to Russian companies.</p><p>Its local arm said that it could not influence the parent company's decision, which came due to new CA/Browser Forum rules, starting May 4. The rules effectively made screening applicants against the US OFAC and BIS lists, and European sanctions lists, mandatory for certificate authorities rather than optional, essentially tying the certificate provider's hands.</p><p>The move was implemented in two waves; the first affected an estimated 15,000-20,000 domains, and the second affected a more specific 310 domains across 44 companies, including large domestic names such as Rosneft, Gazprombank, Alrosa, and Positive Technologies.</p><p>The Ukrainian side insists that Russian internal systems, messengers, email, and banking APIs have become "ideal targets for hacker attacks," and there is some truth to it, even if mitigation is already underway on the Russian end. It estimates that reconfiguring infrastructure could cost larger corporations as much as 10 to 50 million rubles and take up to six months, and it is an error-prone process.</p><p>The move saw Russian domain owners, including its banks and tax services, turn elsewhere, with some moving first to a Greek academic certificate authority, HARICA, before turning to China's TrustAsia, which currently provides its state entities with certificates.</p><p>A more complicated play from the Russian end is a homegrown alternative the government continues pushing: <a href="https://www.techradar.com/news/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions" target="_blank">state-issued trust root certificates</a> that users must install manually. While the Ministry of Digital Development describes manual installation of its root certificate as "safe" and as having no effect on device function, <a href="https://www.bleepingcomputer.com/news/security/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions/" target="_blank">security researchers have previously warned in 2022</a> and <a href="https://riposte.levelflow.org/2026/06/state-ssl/" target="_blank">again in 2026</a> that a state-controlled root could be abused for "HTTPS traffic interception and man-in-the-middle attacks".</p><p>Moscow's other recommendation is that users switch to Yandex Browser, which ships with the domestic root built in. Ukraine's narrative dismisses that as an alternative prone to freezing and cache failures and offering no meaningful data protection, an assessment it attributes to "experts inside Russia."</p><p>Whatever the short-term outcomes result in here for .RU domains, a move like this could further disconnect Russia from the rest of the world, with Russian services working smoothly only for users running Russian software with a state root installed. </p><p>This might already be the trajectory for a Russia reeling from cyberattacks and sanctions, but one can assume the certificate revocations will only compress the timeline to that point, whether by design or an unintended consequence.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware gang crashes own attack — with no-one to blame but themselves ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Akira ransomware tried Safe Mode boot to disable defenses but broke its own encryptor</strong></li><li><strong>Defender later flagged and quarantined payload, leaving attackers with only stolen data</strong></li><li><strong>Huntress advises VPN brute‑force alerts, MFA, SIEM logging, and Safe Mode monitoring</strong></li></ul><p>A recent ransomware attack saw the operators Akira (figuratively) shoot themselves in the foot - and they still walked away with sensitive data, albeit limping.</p><p>Akira is a well-known <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> group, considered one of the most active cybercriminal organizations on the internet. Its modus operandi is simple in theory: they look for an exposed VPN instance (for example, one with a default or weak password), access the domain controller, enumerate Active Directory, steal sensitive data, and deploy an encryptor.</p><p>With the encryptor they leave a ransom note, instructing the victim to reach out and negotiate a payment in exchange for the decryption key and for deleting the stolen documents and information.</p><p>However, in a recent attack, they tried to first disable the device’s antivirus and endpoint detection and response (EDR) solutions. The process backfired, resulting in the security solutions successfully spotting and quarantining the encryptor. </p><div class="product"><a data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="the-good-and-the-bad-of-safe-mode-with-networking">The good and the bad of Safe Mode with Networking</h2><p>A new report published by security researchers <a href="https://www.huntress.com/blog/akira-hits-safe-mode-ransomware-rebooting-around-edr" target="_blank">Huntress</a> said that after establishing persistence on a device, Akira rebooted it into Safe Mode with Networking. This Windows startup mode boots the OS with only the essential drivers and services, excluding important components such as antivirus programs or EDR agents. At the same time, it grants internet access which, for Akira, is the perfect combination.</p><p>“This means Defender real-time protection was down too,” Akira explained. “For the entire Safe Mode window, the host had no working EDR, and AV was blinded. This is MITRE ATT&CK T1688: Impair Defenses: Safe Mode Boot, a technique that ransomware families like Snatch and AvosLocker have used for years. However, this is the first time we have seen Akira use it.”</p><p>What Akira didn’t bank on was Safe Mode with Networking also preventing its encryptor from running. “Safe Mode boots with a stripped-down environment and constrained virtual memory, and the Akira process tree appears to have starved it, getting the "Out of Virtual Memory" pop-up and the cascade of PowerShell hard errors line up exactly with the moment the payload tried to kick things off.”</p><p>The operators had no other choice but to boot the device back up normally, at which point a scheduled Defender scan detected the encryptor, flagged it, and ultimately quarantined it. </p><p>“The takeaway is a little uncomfortable. While Safe Mode blinded our controls, it may also have prevented the encryption it was meant to enable. That's a lucky side effect of the attacker's own mistake in these circumstances, not a defense you can plan around,” Huntress warned, stressing that not every victim might get such a lucky break.</p><p>“Ultimately, this could be a case of winning the battle, but not the war. It's possible that a host with more physical memory or a larger page file might give akira.exe enough virtual memory to encrypt the endpoint in Safe Mode. Akira's developers or affiliates could retool the encryptor to reduce its memory demands or make its Safe Mode launch sequence more reliable, meaning that the same failure may not occur in a future intrusion.”</p><h2 id="how-to-defend-against-akira-ransomware">How to defend against Akira ransomware</h2><p>To defend against Akira, Huntress recommends users set up alerts on bursts of failed VPN logins against multiple usernames from one source. It works well because Akira starts its breach with a brute-force attack against the VPN. It also says users should correlate those failures with a successful login from the same IP or ASN within a short window.</p><p>The second step is to turn on multi-factor authentication (<a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA</a>) on every VPN account. Users should also disable or IP-allowlist the SSL VPN during active attacks and, if compromised, rotate all AD and VPN credentials. “Treat everything in that Get-ADUser dump as exposed,” the researchers warn.</p><p>EDR should be deployed to every host, as well as SIEM and ingest VPN + Windows Event Logs. “The first VPN logons were visible hours before any detonation—this time advantage is only possible if the logs are on SIEM.”</p><p>Finally, users can set up alerts on boot-configuration changes and Safe Mode boots, to catch Akira red handed. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/ransomware-gang-crashes-own-attack-with-no-one-to-blame-but-themselves</link>
                                                                            <description>
                            <![CDATA[ In a new attack, Akira disables EDR tools, but kills the encryptor, as well, as researchers still warn of a worrying practice. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">S9XN4Dopx2hurqZaBZ8g2k</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2026 16:15:00 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Aug 2026 13:30:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Akira ransomware tried Safe Mode boot to disable defenses but broke its own encryptor</strong></li><li><strong>Defender later flagged and quarantined payload, leaving attackers with only stolen data</strong></li><li><strong>Huntress advises VPN brute‑force alerts, MFA, SIEM logging, and Safe Mode monitoring</strong></li></ul><p>A recent ransomware attack saw the operators Akira (figuratively) shoot themselves in the foot - and they still walked away with sensitive data, albeit limping.</p><p>Akira is a well-known <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> group, considered one of the most active cybercriminal organizations on the internet. Its modus operandi is simple in theory: they look for an exposed VPN instance (for example, one with a default or weak password), access the domain controller, enumerate Active Directory, steal sensitive data, and deploy an encryptor.</p><p>With the encryptor they leave a ransom note, instructing the victim to reach out and negotiate a payment in exchange for the decryption key and for deleting the stolen documents and information.</p><p>However, in a recent attack, they tried to first disable the device’s antivirus and endpoint detection and response (EDR) solutions. The process backfired, resulting in the security solutions successfully spotting and quarantining the encryptor. </p><div class="product"><a data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="the-good-and-the-bad-of-safe-mode-with-networking">The good and the bad of Safe Mode with Networking</h2><p>A new report published by security researchers <a href="https://www.huntress.com/blog/akira-hits-safe-mode-ransomware-rebooting-around-edr" target="_blank">Huntress</a> said that after establishing persistence on a device, Akira rebooted it into Safe Mode with Networking. This Windows startup mode boots the OS with only the essential drivers and services, excluding important components such as antivirus programs or EDR agents. At the same time, it grants internet access which, for Akira, is the perfect combination.</p><p>“This means Defender real-time protection was down too,” Akira explained. “For the entire Safe Mode window, the host had no working EDR, and AV was blinded. This is MITRE ATT&CK T1688: Impair Defenses: Safe Mode Boot, a technique that ransomware families like Snatch and AvosLocker have used for years. However, this is the first time we have seen Akira use it.”</p><p>What Akira didn’t bank on was Safe Mode with Networking also preventing its encryptor from running. “Safe Mode boots with a stripped-down environment and constrained virtual memory, and the Akira process tree appears to have starved it, getting the "Out of Virtual Memory" pop-up and the cascade of PowerShell hard errors line up exactly with the moment the payload tried to kick things off.”</p><p>The operators had no other choice but to boot the device back up normally, at which point a scheduled Defender scan detected the encryptor, flagged it, and ultimately quarantined it. </p><p>“The takeaway is a little uncomfortable. While Safe Mode blinded our controls, it may also have prevented the encryption it was meant to enable. That's a lucky side effect of the attacker's own mistake in these circumstances, not a defense you can plan around,” Huntress warned, stressing that not every victim might get such a lucky break.</p><p>“Ultimately, this could be a case of winning the battle, but not the war. It's possible that a host with more physical memory or a larger page file might give akira.exe enough virtual memory to encrypt the endpoint in Safe Mode. Akira's developers or affiliates could retool the encryptor to reduce its memory demands or make its Safe Mode launch sequence more reliable, meaning that the same failure may not occur in a future intrusion.”</p><h2 id="how-to-defend-against-akira-ransomware">How to defend against Akira ransomware</h2><p>To defend against Akira, Huntress recommends users set up alerts on bursts of failed VPN logins against multiple usernames from one source. It works well because Akira starts its breach with a brute-force attack against the VPN. It also says users should correlate those failures with a successful login from the same IP or ASN within a short window.</p><p>The second step is to turn on multi-factor authentication (<a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA</a>) on every VPN account. Users should also disable or IP-allowlist the SSL VPN during active attacks and, if compromised, rotate all AD and VPN credentials. “Treat everything in that Get-ADUser dump as exposed,” the researchers warn.</p><p>EDR should be deployed to every host, as well as SIEM and ingest VPN + Windows Event Logs. “The first VPN logons were visible hours before any detonation—this time advantage is only possible if the logs are on SIEM.”</p><p>Finally, users can set up alerts on boot-configuration changes and Safe Mode boots, to catch Akira red handed. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ MacOS users warned to beware screen-sharing bug which can turn Macs into cryptomining slaves ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CVE‑2026‑65400 macOS Screen Sharing flaw exploited for cryptojacking within days of disclosure</strong></li><li><strong>Attackers gained root via exposed port 5900 and deployed Monero miners using XMRig</strong></li><li><strong>Apple patched in Sequoia 15.7.9, Sonoma 14.8.9, Tahoe 26.6.1; users urged to update immediately</strong></li></ul><p>Less than a week after being publicly disclosed, a macOS vulnerability plaguing Screen Sharing was observed as being used in cryptojacking attacks.</p><p>Alfredo Pesoli, a security researcher from Bynario, discovered an authentication issue in macOS Screen Sharing and reported it to Apple. Screen Sharing is a built-in macOS tool that allows users to remotely connect, and use, another Mac device. It is similar to third-party tools such as AnyDesk or TeamViewer and comes in rather handy for IT teams accessing Macs stored in closets or used by remote and home-working employees.</p><p>The bug allows a remote attacker to bypass authentication and gain access to a vulnerable Mac device without valid credentials. It apparently stems from a logic issue in the Screen Sharing server’s authentication process, affecting systems where the service is exposed to the internet.</p><h2 id="the-netherlands-issue-a-warning">The Netherlands issue a warning</h2><p>Soon after disclosure, Apple released an out-of-bound fix, signaling that this is, indeed, a dangerous vulnerability. “Apple does not ship an update out of band unless something is critical,” security researchers Calif said in their <a href="https://blog.calif.io/p/no-country-for-old-passwords" target="_blank" rel="nofollow">technical writeup</a>. The National Vulnerability Database (NVD) assigned it an identifier - CVE-2026-65400 - and gave it a severity rating of 9.6/10 (critical). </p><p>Approximately at the same time the patch was released, the flaw was also showcased at the 2026 Black Hat conference, with a video demonstration was made public a few days later.</p><p>Apple said it fixed it with improved state management, addressing the bug in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1.</p><p>Now, less than a week after the disclosure, researchers are saying the bug is being leveraged in actual cyberattacks, with Dutch security officials being first to react</p><p>“The NCSC has received a report showing that active abuse of this vulnerability has been observed on several systems on which port 5900 was accessible from the internet,” the Netherlands National Cyber Security Centrum (NCSC) said in a machine-translated report. “In all these cases, root access was gained on the affected system and a Monero crypto miner was placed.”</p><h2 id="why-monero">Why Monero?</h2><p>Monero is considered an “altcoin” - a cryptocurrency built as an alternative to Bitcoin. It is one of the oldest active altcoins out there, having been launched more than 12 years ago. Most cryptocurrencies rarely live through a single four-year bitcoin cycle but Monero, just like Ethereum, Litecoin, Solana, and a handful of others, endures.</p><p>It is similar to Bitcoin because it, too, can be “mined” (unlike Ethereum, for example). It differs on the privacy front. Unlike Bitcoin, whose transactions are recorded on a public ledger and can often be traced, Monero is designed to obscure the sender, recipient, and the amount of transactions. This privacy feature has, unfortunately, also attracted criminals.</p><p>Another key feature that made crooks choose Monero for their <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">cryptojackers</a> is the fact that the altcoin uses a proof-of-work (mining) algorithm optimized for general-purpose CPUs, making mining relatively profitable on ordinary servers, desktops, and cloud machines. </p><p>Although it was not specifically stated, it is safe to assume that in this incident, the attackers were deploying XMRig. It is, by far, the most popular cryptojacker and one that mines primarily Monero (its ticker is XMR).</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>The best way to go about it is to install the patch Apple just released. This effectively plugs the hole and makes the device secure. Those who are unable to deploy the patch immediately should block Screen Sharing and enable it only when it is actually needed and used. To do that, users can go to System Settings > General > Sharing and toggle the Screen Sharing switch off. </p><p>Finally, it is worth mentioning that the NCSC stressed the crooks could only exploit the flaw when the target device’s port 5900 is exposed to the internet. Therefore, setting routers and firewalls to block the port can also work, although we’d only recommend it as a last resort. Installing the patch is still the best way to go. </p><p>Right now, no groups claimed responsibility for this attack, and there is no evidence it is being used for anything else. In theory, though, it can also be used for data exfiltration, malware deployment, and possibly even ransomware attacks. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/macos-users-warned-to-beware-screen-sharing-bug-which-can-turn-macs-into-cryptomining-slaves</link>
                                                                            <description>
                            <![CDATA[ Apple patched a critical-severity flaw in Screen Sharing which allowed crooks unabated access to vulnerable devices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GNymd9yeKgRVNJ8phk4pgn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5HfdStguEjjwWA3HyeKfCZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5HfdStguEjjwWA3HyeKfCZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Far Chinberdiev / Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Apple Mac Pro on a desk.]]></media:description>                                                            <media:text><![CDATA[The Apple Mac Pro on a desk.]]></media:text>
                                <media:title type="plain"><![CDATA[The Apple Mac Pro on a desk.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5HfdStguEjjwWA3HyeKfCZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CVE‑2026‑65400 macOS Screen Sharing flaw exploited for cryptojacking within days of disclosure</strong></li><li><strong>Attackers gained root via exposed port 5900 and deployed Monero miners using XMRig</strong></li><li><strong>Apple patched in Sequoia 15.7.9, Sonoma 14.8.9, Tahoe 26.6.1; users urged to update immediately</strong></li></ul><p>Less than a week after being publicly disclosed, a macOS vulnerability plaguing Screen Sharing was observed as being used in cryptojacking attacks.</p><p>Alfredo Pesoli, a security researcher from Bynario, discovered an authentication issue in macOS Screen Sharing and reported it to Apple. Screen Sharing is a built-in macOS tool that allows users to remotely connect, and use, another Mac device. It is similar to third-party tools such as AnyDesk or TeamViewer and comes in rather handy for IT teams accessing Macs stored in closets or used by remote and home-working employees.</p><p>The bug allows a remote attacker to bypass authentication and gain access to a vulnerable Mac device without valid credentials. It apparently stems from a logic issue in the Screen Sharing server’s authentication process, affecting systems where the service is exposed to the internet.</p><h2 id="the-netherlands-issue-a-warning">The Netherlands issue a warning</h2><p>Soon after disclosure, Apple released an out-of-bound fix, signaling that this is, indeed, a dangerous vulnerability. “Apple does not ship an update out of band unless something is critical,” security researchers Calif said in their <a href="https://blog.calif.io/p/no-country-for-old-passwords" target="_blank" rel="nofollow">technical writeup</a>. The National Vulnerability Database (NVD) assigned it an identifier - CVE-2026-65400 - and gave it a severity rating of 9.6/10 (critical). </p><p>Approximately at the same time the patch was released, the flaw was also showcased at the 2026 Black Hat conference, with a video demonstration was made public a few days later.</p><p>Apple said it fixed it with improved state management, addressing the bug in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1.</p><p>Now, less than a week after the disclosure, researchers are saying the bug is being leveraged in actual cyberattacks, with Dutch security officials being first to react</p><p>“The NCSC has received a report showing that active abuse of this vulnerability has been observed on several systems on which port 5900 was accessible from the internet,” the Netherlands National Cyber Security Centrum (NCSC) said in a machine-translated report. “In all these cases, root access was gained on the affected system and a Monero crypto miner was placed.”</p><h2 id="why-monero">Why Monero?</h2><p>Monero is considered an “altcoin” - a cryptocurrency built as an alternative to Bitcoin. It is one of the oldest active altcoins out there, having been launched more than 12 years ago. Most cryptocurrencies rarely live through a single four-year bitcoin cycle but Monero, just like Ethereum, Litecoin, Solana, and a handful of others, endures.</p><p>It is similar to Bitcoin because it, too, can be “mined” (unlike Ethereum, for example). It differs on the privacy front. Unlike Bitcoin, whose transactions are recorded on a public ledger and can often be traced, Monero is designed to obscure the sender, recipient, and the amount of transactions. This privacy feature has, unfortunately, also attracted criminals.</p><p>Another key feature that made crooks choose Monero for their <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">cryptojackers</a> is the fact that the altcoin uses a proof-of-work (mining) algorithm optimized for general-purpose CPUs, making mining relatively profitable on ordinary servers, desktops, and cloud machines. </p><p>Although it was not specifically stated, it is safe to assume that in this incident, the attackers were deploying XMRig. It is, by far, the most popular cryptojacker and one that mines primarily Monero (its ticker is XMR).</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>The best way to go about it is to install the patch Apple just released. This effectively plugs the hole and makes the device secure. Those who are unable to deploy the patch immediately should block Screen Sharing and enable it only when it is actually needed and used. To do that, users can go to System Settings > General > Sharing and toggle the Screen Sharing switch off. </p><p>Finally, it is worth mentioning that the NCSC stressed the crooks could only exploit the flaw when the target device’s port 5900 is exposed to the internet. Therefore, setting routers and firewalls to block the port can also work, although we’d only recommend it as a last resort. Installing the patch is still the best way to go. </p><p>Right now, no groups claimed responsibility for this attack, and there is no evidence it is being used for anything else. In theory, though, it can also be used for data exfiltration, malware deployment, and possibly even ransomware attacks. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The internet is becoming more stressful and unlikeable — with AI slop and data leaks to blame ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>An Incogni survey has found people are becoming more frustrated with the internet</strong></li><li><strong>Users cite AI slop and data leaks as the main reasons for stress and anxiety when using the internet</strong></li><li><strong>Many users want to spend less time online, and are deleting social media profiles and messaging</strong></li></ul><p>For years, personal data collection for advertising, tracking, and service improvement was thought to be the fair price to pay to access the world wide web. But now, many people believe that using the internet will lead to their data being leaked or exposed.</p><p>A new <a href="https://blog.incogni.com/attitudes-toward-internet-stressed-exposed/" target="_blank" rel="nofollow">Incogni survey</a> found more than half of internet users believe their personal data will inevitably be exposed, with 63% stating that this fear causes anxiety when using the internet.</p><p>But beyond this, internet users now fear they can no longer tell what is real content uploaded by a human and what is AI generated, not only eroding trust in the internet, but also making people not want to use the internet at all. Almost half of internet users are less sure of what is real on the internet.</p><h2 id="inevitable-data-exposure">Inevitable data exposure</h2><p>You’ve likely been prompted thousands of times to accept or reject cookies, or review a privacy policy before using a website. Every cookie you accept will collect data on your browsing habits and behavior on sites in order to display personalized adverts that you are more likely to click. Cookies also help keep you logged in and store your information on websites.</p><p>While this helps make many websites across the web free to use for those accessing them, sometimes your data is sold to advertisers or third-parties where it is stored insecurely, and <a href="https://www.techradar.com/pro/security/stolen-session-cookies-render-mfa-irrelevant-how-usd900-per-month-turnkey-malware-is-putting-enterprise-grade-account-hijacking-in-the-hands-of-rookie-hackers" target="_blank">can be stolen or leaked</a>.</p><p>Among the 1,000 internet users surveyed, the fear of data exposure was strongest among the Millennials and Gen X generations. 56% of Gen X and 55% of Millennials believed that their data would at some point be breached or exposed, showing just how normal data breaches and exposure have become online.</p><p>Just 11% of those surveyed believed there was little likelihood of their data being breached.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:60.35%;"><img id="BdfP8Jxppb8qhTMGtD7v9j" name="more_than_50_of_respondents_believe_that_their_data_is_bound_to_be_breached" alt="A graph showing internet user opinions on how likely their data is to be leaked online." src="https://cdn.mos.cms.futurecdn.net/BdfP8Jxppb8qhTMGtD7v9j.jpg" mos="" align="middle" fullscreen="" width="1024" height="618" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><h2 id="ai-is-making-the-internet-less-real">AI is making the internet less real</h2><p>AI content creation has exploded in recent years. Social media sites are full of AI ‘creators’ whose pages either share AI generated content or scrape the internet for content that users are likely to interact with, and share it through their own pages. These profiles require little human input, but can share content at an industrial scale and reap huge rewards from advertisers.</p><p>If you’ve been on Instagram lately, you may have seen videos from AI creators all sharing the same captions. “Tonight, V stepped into the crowd..” or “Japan is transforming footsteps into electricity.” These captions use keywords to abuse Instagram’s algorithm on popular topics to drive engagement, regardless of whether the content actually has anything to do with the caption.</p><p>But they’re also making it harder to know what is real on the internet.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:86.23%;"><img id="Scf358baJc5KPcBAWuaJP3" name="majority_of_respondents_highlight_negative_aspects_of_ai_proliferation" alt="A graph showing the opinions of internet users on AI generated content" src="https://cdn.mos.cms.futurecdn.net/Scf358baJc5KPcBAWuaJP3.jpg" mos="" align="middle" fullscreen="" width="1024" height="883" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>48% of those surveyed said that they are less sure of what’s real, with 40% also stating that the lack of accountability for deepfake creators was a bother. </p><p>Additionally, 27% said that AI generated content made them want to spend less time online, with 16% also saying that navigating an internet full of low quality AI content made them feel more tired or fatigued. Just 8% of respondents said that AI generated content improved their online experience.</p><p>There are some positive attitudes to AI content online. 12% said that AI-generated content made information more accessible, with slightly less (11%) saying that they were excited about the creative possibilities AI offers.</p><div style="min-height: 250px;">                                <div class="kwizly-quiz kwizly-eEqjge"></div>                            </div>                            <script src="https://kwizly.com/embed/eEqjge.js" async></script><h2 id="time-to-go-offline">Time to go offline?</h2><p>Attitudes to how long people spend online are also changing. Over half (51%) of Gen Z internet users believe they spend too much time on consuming content on the internet, with 43% of Millennials and 42% of Gen X respondents having a likeminded view.</p><p>Whether it’s responding to emails, navigating networking platforms, finding new furniture, or looking for where to go to eat - the internet is now a life requirement for most people. And every time you access another website in work or your personal life, there is more data that could be leaked.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:50.10%;"><img id="bKNqbbh5Xk5WGih8KJEY58" name="almost_half_of_respondents_believe_they_spend_too_much_time_online" alt="A graph showing opinions on whether internet users spend too much time online" src="https://cdn.mos.cms.futurecdn.net/bKNqbbh5Xk5WGih8KJEY58.jpg" mos="" align="middle" fullscreen="" width="1024" height="513" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>The ultimate effect of this is that people are being driven away from using the internet. 58% of respondents said that they had deleted a social media account or messaging app because of stress, anxiety, or privacy concerns. </p><p>“It seems that the costs of engaging with these platforms are starting to outweigh any perceived or actual benefits,” the Incogni survey said.</p><h2 id="or-time-to-pay-for-privacy">Or time to pay for privacy?</h2><p>Incogni also asked if users would be willing to pay for an internet where tracking and algorithms did not exist. 30% of respondents said they would, but this largely relied on income. Those with a higher income were more likely to pay for this ‘private’ internet, while those with a lower income were less likely.</p><p>For many internet users, privacy shouldn’t be a luxury, but a guarantee. There is a level of trust involved when sharing personal data with advertisers, and the expectation is that the data won’t be leaked or stolen. Unfortunately, the opinions show that this is far from what's expected.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:60.35%;"><img id="GzytHWP7DeEspVa7QgtqPD" name="fewer_than_30_of_respondents_would_pay_for_an_internet_with_no_tracking_or_algorithmic_feeds" alt="A graph showing if internet users would pay for an internet without tracking or algorithmic feeds" src="https://cdn.mos.cms.futurecdn.net/GzytHWP7DeEspVa7QgtqPD.jpg" mos="" align="middle" fullscreen="" width="1024" height="618" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/the-internet-is-becoming-more-stressful-and-unlikeable-with-ai-slop-and-data-leaks-to-blame</link>
                                                                            <description>
                            <![CDATA[ AI content and data leaks are driving people away from the internet, with some people willing to pay for an internet without algorithms or data harvesting. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5VpX2PdN4zGpVbwe7CEvnX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HU8VZ2jkrVAHBpb3Aqqg8j-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2026 13:08:34 +0000</pubDate>                                                                                                                                <updated>Mon, 17 Aug 2026 13:08:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Browsers]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HU8VZ2jkrVAHBpb3Aqqg8j-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/Tatiana Maksimova]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Female hands typing on a laptop in neon light. A lock as a symbol of cybersecurity on a foreground.]]></media:description>                                                            <media:text><![CDATA[Female hands typing on a laptop in neon light. A lock as a symbol of cybersecurity on a foreground.]]></media:text>
                                <media:title type="plain"><![CDATA[Female hands typing on a laptop in neon light. A lock as a symbol of cybersecurity on a foreground.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HU8VZ2jkrVAHBpb3Aqqg8j-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>An Incogni survey has found people are becoming more frustrated with the internet</strong></li><li><strong>Users cite AI slop and data leaks as the main reasons for stress and anxiety when using the internet</strong></li><li><strong>Many users want to spend less time online, and are deleting social media profiles and messaging</strong></li></ul><p>For years, personal data collection for advertising, tracking, and service improvement was thought to be the fair price to pay to access the world wide web. But now, many people believe that using the internet will lead to their data being leaked or exposed.</p><p>A new <a href="https://blog.incogni.com/attitudes-toward-internet-stressed-exposed/" target="_blank" rel="nofollow">Incogni survey</a> found more than half of internet users believe their personal data will inevitably be exposed, with 63% stating that this fear causes anxiety when using the internet.</p><p>But beyond this, internet users now fear they can no longer tell what is real content uploaded by a human and what is AI generated, not only eroding trust in the internet, but also making people not want to use the internet at all. Almost half of internet users are less sure of what is real on the internet.</p><h2 id="inevitable-data-exposure">Inevitable data exposure</h2><p>You’ve likely been prompted thousands of times to accept or reject cookies, or review a privacy policy before using a website. Every cookie you accept will collect data on your browsing habits and behavior on sites in order to display personalized adverts that you are more likely to click. Cookies also help keep you logged in and store your information on websites.</p><p>While this helps make many websites across the web free to use for those accessing them, sometimes your data is sold to advertisers or third-parties where it is stored insecurely, and <a href="https://www.techradar.com/pro/security/stolen-session-cookies-render-mfa-irrelevant-how-usd900-per-month-turnkey-malware-is-putting-enterprise-grade-account-hijacking-in-the-hands-of-rookie-hackers" target="_blank">can be stolen or leaked</a>.</p><p>Among the 1,000 internet users surveyed, the fear of data exposure was strongest among the Millennials and Gen X generations. 56% of Gen X and 55% of Millennials believed that their data would at some point be breached or exposed, showing just how normal data breaches and exposure have become online.</p><p>Just 11% of those surveyed believed there was little likelihood of their data being breached.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:60.35%;"><img id="BdfP8Jxppb8qhTMGtD7v9j" name="more_than_50_of_respondents_believe_that_their_data_is_bound_to_be_breached" alt="A graph showing internet user opinions on how likely their data is to be leaked online." src="https://cdn.mos.cms.futurecdn.net/BdfP8Jxppb8qhTMGtD7v9j.jpg" mos="" align="middle" fullscreen="" width="1024" height="618" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><h2 id="ai-is-making-the-internet-less-real">AI is making the internet less real</h2><p>AI content creation has exploded in recent years. Social media sites are full of AI ‘creators’ whose pages either share AI generated content or scrape the internet for content that users are likely to interact with, and share it through their own pages. These profiles require little human input, but can share content at an industrial scale and reap huge rewards from advertisers.</p><p>If you’ve been on Instagram lately, you may have seen videos from AI creators all sharing the same captions. “Tonight, V stepped into the crowd..” or “Japan is transforming footsteps into electricity.” These captions use keywords to abuse Instagram’s algorithm on popular topics to drive engagement, regardless of whether the content actually has anything to do with the caption.</p><p>But they’re also making it harder to know what is real on the internet.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:86.23%;"><img id="Scf358baJc5KPcBAWuaJP3" name="majority_of_respondents_highlight_negative_aspects_of_ai_proliferation" alt="A graph showing the opinions of internet users on AI generated content" src="https://cdn.mos.cms.futurecdn.net/Scf358baJc5KPcBAWuaJP3.jpg" mos="" align="middle" fullscreen="" width="1024" height="883" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>48% of those surveyed said that they are less sure of what’s real, with 40% also stating that the lack of accountability for deepfake creators was a bother. </p><p>Additionally, 27% said that AI generated content made them want to spend less time online, with 16% also saying that navigating an internet full of low quality AI content made them feel more tired or fatigued. Just 8% of respondents said that AI generated content improved their online experience.</p><p>There are some positive attitudes to AI content online. 12% said that AI-generated content made information more accessible, with slightly less (11%) saying that they were excited about the creative possibilities AI offers.</p><div style="min-height: 250px;">                                <div class="kwizly-quiz kwizly-eEqjge"></div>                            </div>                            <script src="https://kwizly.com/embed/eEqjge.js" async></script><h2 id="time-to-go-offline">Time to go offline?</h2><p>Attitudes to how long people spend online are also changing. Over half (51%) of Gen Z internet users believe they spend too much time on consuming content on the internet, with 43% of Millennials and 42% of Gen X respondents having a likeminded view.</p><p>Whether it’s responding to emails, navigating networking platforms, finding new furniture, or looking for where to go to eat - the internet is now a life requirement for most people. And every time you access another website in work or your personal life, there is more data that could be leaked.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:50.10%;"><img id="bKNqbbh5Xk5WGih8KJEY58" name="almost_half_of_respondents_believe_they_spend_too_much_time_online" alt="A graph showing opinions on whether internet users spend too much time online" src="https://cdn.mos.cms.futurecdn.net/bKNqbbh5Xk5WGih8KJEY58.jpg" mos="" align="middle" fullscreen="" width="1024" height="513" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>The ultimate effect of this is that people are being driven away from using the internet. 58% of respondents said that they had deleted a social media account or messaging app because of stress, anxiety, or privacy concerns. </p><p>“It seems that the costs of engaging with these platforms are starting to outweigh any perceived or actual benefits,” the Incogni survey said.</p><h2 id="or-time-to-pay-for-privacy">Or time to pay for privacy?</h2><p>Incogni also asked if users would be willing to pay for an internet where tracking and algorithms did not exist. 30% of respondents said they would, but this largely relied on income. Those with a higher income were more likely to pay for this ‘private’ internet, while those with a lower income were less likely.</p><p>For many internet users, privacy shouldn’t be a luxury, but a guarantee. There is a level of trust involved when sharing personal data with advertisers, and the expectation is that the data won’t be leaked or stolen. Unfortunately, the opinions show that this is far from what's expected.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:60.35%;"><img id="GzytHWP7DeEspVa7QgtqPD" name="fewer_than_30_of_respondents_would_pay_for_an_internet_with_no_tracking_or_algorithmic_feeds" alt="A graph showing if internet users would pay for an internet without tracking or algorithmic feeds" src="https://cdn.mos.cms.futurecdn.net/GzytHWP7DeEspVa7QgtqPD.jpg" mos="" align="middle" fullscreen="" width="1024" height="618" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Tokenmaxxing: Why AI consumption needs control ]]></title>
                                                                                                <dc:content><![CDATA[ <p>AI spend made headlines again recently with the Claude Fable 5 model from Anthropic. Before <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> concerns led to the model being suspended, there were also cost concerns. Anthropic says Fable costs $10 or approximately €9 per million input tokens and $50 per million output tokens. This is double the price of the company’s previously most expensive model, Claude Opus 4.8.</p><p>Posts soon began to pop up on LinkedIn, showing just how quickly teams were going through their tokens and, as a result, their budget. There are some caveats here. Namely, that Fable 5 is an advanced model and, for most <a href="https://www.techradar.com/best/best-small-business-phone-systems">businesses</a>, won’t need to run non-stop or be used for every task.</p><p>But therein lies a key issue: AI use is accelerating and models are evolving. But the level of control and visibility businesses have over how much is being spent, by who and for what is lagging behind.</p><h2 id="how-ai-consumption-became-a-finance-problem">How AI consumption became a finance problem </h2><p>There is a massive shift within the UK software market toward AI and specifically Anthropic’s ecosystem. Proprietary data from Pleo looking at the top tech merchants based on number of spending customers, shows that Anthropic (Claude) surged from 12th place in Q4 2025 to 7th in Q1 2026. Meanwhile, the average spend per customer increased +43.0% in this time.</p><p>This rapid climb signals that Anthropic has reached enterprise maturity in the UK market with businesses moving beyond the experimentation phase. But while this reflects growing confidence in AI adoption, it also presents some financial challenges.</p><p>On the whole, AI has redefined how the workplace runs, but it is not a free trial. The cost of tokens has gone up, and new models that can achieve what was seemingly unthinkable a few years ago come with a price tag to match. The new challenge for business leaders is to leverage these technologies but also limit rampant spending.  </p><p>This is why many organizations are turning to their <a href="https://www.techradar.com/best/best-personal-finance-software">finance</a> teams. Finance has the visibility to dig into the details and map AI use across the organization, whether it quietly shows up as a subscription renewal or a new budget request. But more than that, they can be instrumental in ensuring teams embrace open conversations, not just OpenAI. </p><h2 id="ai-activity-does-not-translate-to-ai-value">AI activity does not translate to AI value</h2><p>Just about every organization will have developed transformational ways of using <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a>. But, whether they know it or not, there will be wasteful ones too.</p><p>When it comes to inefficient use, some of the major culprits include asking AI agents open-ended questions, model mismatch where tokens are burned unnecessarily; and duplicate tools, resulting from shadow AI and overlapping subscriptions. These prevent businesses from seeing the full picture; one that is, in all probability, very expensive. </p><p>User literacy can improve this. But for finance teams they must start with the grey area of AI consumption. Two teams might show as active AI users, but one that’s using an LLM to produce more content faster is doing something fundamentally different to one that’s using it for peripheral <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> tasks. In fact, only 29% of European SMEs using Gen AI are doing so in core business activities.</p><p>To improve the control they have over AI, organizations must start by elevating their visibility from who is using AI, to who is using it to become smarter, faster and more productive.  </p><h2 id="how-to-regain-control-over-ai-use">How to regain control over AI use</h2><p>A complete view of AI spend is essential, regardless of whether costs are rising.   </p><p>Breaking spend down by department, team and budget helps identify both disproportionate usage and areas where adoption may be lagging. These should be combined with performance metrics such as the time-to-first-draft on marketing content; code review cycle times in engineering; support ticket resolution time in customer support; and so on.</p><p>This combination of spend and performance can reveal whether AI investment is translating into measurable productivity gains and not just higher <a href="https://www.techradar.com/best/best-small-business-software">software</a> costs.</p><p>Visibility should also extend to model-level usage. As mentioned before, the cost difference between frontier reasoning models and lighter alternatives can be tenfold. Monitoring model and vendor usage alongside token consumption helps organizations route routine tasks to lower-cost options, maximize ROI and reduce unnecessary spend. </p><p>Finance teams should therefore expand reporting and budgeting frameworks to include AI-specific metrics. A key question at month-end is whether AI-enabled teams are increasing output and capacity without increasing headcount. This provides a clear headline for AI's impact, can justify investment and distinguish between high-value and low-value AI usage. </p><p>Ultimately, effective control over AI is not about costs alone. It is about understanding where AI is creating value and ensuring investment is aligned with <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> outcomes.</p><h2 id="ai-control-is-at-your-fingertips">AI control is at your fingertips</h2><p>The good news is that none of these metrics require a sophisticated AI analytics stack. Finance teams should already have the tools for real-time visibility into what’s being spent and where. All that’s needed now is to fold AI into the mix and collaborate with other departments to measure and improve its ROI.</p><p>The outcome is that organizations control AI use through oversight, without restricting spend, adoption or innovation through lengthy procurement processes. Spend policies, category controls and clear approval thresholds control what is spent, and everything is measured.</p><p>But crucially, teams don’t slow down as a result. The only difference is that AI is optimized for impact.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-chatbot-for-business"><em>We've featured the best AI chatbot for business.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/tokenmaxxing-why-ai-consumption-needs-control</link>
                                                                            <description>
                            <![CDATA[ Finance teams aren't trying to stop AI investment – they want to maximise its impact ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hcyzexFFxWpsNFQSDUDure</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U76sZeRd6fS2fKt5RqBYPL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2026 09:47:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Marija Nakevska ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U76sZeRd6fS2fKt5RqBYPL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Big letters AI in pink in front of pink and blue strands of light suggesting a digital explosion]]></media:description>                                                            <media:text><![CDATA[Big letters AI in pink in front of pink and blue strands of light suggesting a digital explosion]]></media:text>
                                <media:title type="plain"><![CDATA[Big letters AI in pink in front of pink and blue strands of light suggesting a digital explosion]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U76sZeRd6fS2fKt5RqBYPL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI spend made headlines again recently with the Claude Fable 5 model from Anthropic. Before <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> concerns led to the model being suspended, there were also cost concerns. Anthropic says Fable costs $10 or approximately €9 per million input tokens and $50 per million output tokens. This is double the price of the company’s previously most expensive model, Claude Opus 4.8.</p><p>Posts soon began to pop up on LinkedIn, showing just how quickly teams were going through their tokens and, as a result, their budget. There are some caveats here. Namely, that Fable 5 is an advanced model and, for most <a href="https://www.techradar.com/best/best-small-business-phone-systems">businesses</a>, won’t need to run non-stop or be used for every task.</p><p>But therein lies a key issue: AI use is accelerating and models are evolving. But the level of control and visibility businesses have over how much is being spent, by who and for what is lagging behind.</p><h2 id="how-ai-consumption-became-a-finance-problem">How AI consumption became a finance problem </h2><p>There is a massive shift within the UK software market toward AI and specifically Anthropic’s ecosystem. Proprietary data from Pleo looking at the top tech merchants based on number of spending customers, shows that Anthropic (Claude) surged from 12th place in Q4 2025 to 7th in Q1 2026. Meanwhile, the average spend per customer increased +43.0% in this time.</p><p>This rapid climb signals that Anthropic has reached enterprise maturity in the UK market with businesses moving beyond the experimentation phase. But while this reflects growing confidence in AI adoption, it also presents some financial challenges.</p><p>On the whole, AI has redefined how the workplace runs, but it is not a free trial. The cost of tokens has gone up, and new models that can achieve what was seemingly unthinkable a few years ago come with a price tag to match. The new challenge for business leaders is to leverage these technologies but also limit rampant spending.  </p><p>This is why many organizations are turning to their <a href="https://www.techradar.com/best/best-personal-finance-software">finance</a> teams. Finance has the visibility to dig into the details and map AI use across the organization, whether it quietly shows up as a subscription renewal or a new budget request. But more than that, they can be instrumental in ensuring teams embrace open conversations, not just OpenAI. </p><h2 id="ai-activity-does-not-translate-to-ai-value">AI activity does not translate to AI value</h2><p>Just about every organization will have developed transformational ways of using <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a>. But, whether they know it or not, there will be wasteful ones too.</p><p>When it comes to inefficient use, some of the major culprits include asking AI agents open-ended questions, model mismatch where tokens are burned unnecessarily; and duplicate tools, resulting from shadow AI and overlapping subscriptions. These prevent businesses from seeing the full picture; one that is, in all probability, very expensive. </p><p>User literacy can improve this. But for finance teams they must start with the grey area of AI consumption. Two teams might show as active AI users, but one that’s using an LLM to produce more content faster is doing something fundamentally different to one that’s using it for peripheral <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> tasks. In fact, only 29% of European SMEs using Gen AI are doing so in core business activities.</p><p>To improve the control they have over AI, organizations must start by elevating their visibility from who is using AI, to who is using it to become smarter, faster and more productive.  </p><h2 id="how-to-regain-control-over-ai-use">How to regain control over AI use</h2><p>A complete view of AI spend is essential, regardless of whether costs are rising.   </p><p>Breaking spend down by department, team and budget helps identify both disproportionate usage and areas where adoption may be lagging. These should be combined with performance metrics such as the time-to-first-draft on marketing content; code review cycle times in engineering; support ticket resolution time in customer support; and so on.</p><p>This combination of spend and performance can reveal whether AI investment is translating into measurable productivity gains and not just higher <a href="https://www.techradar.com/best/best-small-business-software">software</a> costs.</p><p>Visibility should also extend to model-level usage. As mentioned before, the cost difference between frontier reasoning models and lighter alternatives can be tenfold. Monitoring model and vendor usage alongside token consumption helps organizations route routine tasks to lower-cost options, maximize ROI and reduce unnecessary spend. </p><p>Finance teams should therefore expand reporting and budgeting frameworks to include AI-specific metrics. A key question at month-end is whether AI-enabled teams are increasing output and capacity without increasing headcount. This provides a clear headline for AI's impact, can justify investment and distinguish between high-value and low-value AI usage. </p><p>Ultimately, effective control over AI is not about costs alone. It is about understanding where AI is creating value and ensuring investment is aligned with <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> outcomes.</p><h2 id="ai-control-is-at-your-fingertips">AI control is at your fingertips</h2><p>The good news is that none of these metrics require a sophisticated AI analytics stack. Finance teams should already have the tools for real-time visibility into what’s being spent and where. All that’s needed now is to fold AI into the mix and collaborate with other departments to measure and improve its ROI.</p><p>The outcome is that organizations control AI use through oversight, without restricting spend, adoption or innovation through lengthy procurement processes. Spend policies, category controls and clear approval thresholds control what is spent, and everything is measured.</p><p>But crucially, teams don’t slow down as a result. The only difference is that AI is optimized for impact.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-chatbot-for-business"><em>We've featured the best AI chatbot for business.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Securing adoption in the era of shadow AI ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Artificial intelligence (AI) is rapidly becoming embedded in the modern workplace, with employees are increasingly turning to <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> to work more efficiently and boost productivity. </p><p>This growing demand for faster, more effective ways of working is driving the rise of shadow AI - the use of AI tools outside approved organizational controls and governance frameworks – which results in organizations quickly losing visibility into data usage and potential risks.</p><p>The scale of this challenge is significant. While 90% of executives are confident in their organizations' visibility into AI tools, just 52% of employees admit to using AI tools without approval, often through personal accounts. </p><p>As a result, organizations are left grappling with a widening gap between AI adoption and AI governance.</p><h2 id="the-next-frontier-of-ai-risk">The next frontier of AI risk</h2><p>When AI is used without formal oversight, it can bypass governance controls, increasing the risk of errors, regulatory breaches and sensitive data leakages. Organizations are most exposed when AI is already influencing business-critical activities, from customer service and operational decision-making to software development and content creation.  </p><p>The challenge will intensify as businesses move beyond <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">large language models</a>, which generate information, to large action models and agentic systems that can take action. These systems can diagnose issues, recommend actions and execute workflows with minimum human input, increasing both the speed and scale at which mistakes occur. </p><p>A shadow agent operating outside approved governance frameworks could trigger harmful actions before organizations have the visibility and governance capabilities needed to intervene.</p><p>There is also a longer-term risk that future AI systems will be trained on synthetic or lower-quality data, weakening performance and decision-making over time. Transparency and traceability will be critical to maintaining accountability, protecting ethical standards and preserving the effectiveness of AI systems as adoption continues to accelerate.</p><h2 id="ai-governance-as-an-enabler">AI governance as an enabler</h2><p>What works is AI governance that enables innovation while putting clear guardrails in place that are integrated, transparent, auditable, and aligned with existing risk and compliance frameworks. If AI is to be used safely, firms must be able to successfully identify exactly what went wrong and why when issues arise.  </p><p>In practice, mature governance starts with an approved AI tool stack that provides safe and trusted options for common use cases. This should be supported by risk-based policies that make clear the <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> being handled, what can and cannot be shared, which tools are permitted, and where human approval is required. </p><p>Low-risk tasks such as drafting or summarizing content should not be governed in the same way as high-risk uses involving customer data, regulated information or business-critical decisions.</p><p>Training is equally important. The challenge, beyond only enforcing controls, involves helping employees understand why those controls exist and how to use AI responsibly. As agents increasingly diagnose issues, recommend actions, and execute workflows with minimum input, human oversight and approval processes must scale alongside them. </p><p>Interoperability will be critical to making this workable at scale, allowing organizations to operate across jurisdictions and multiple AI models without repeatedly rebuilding governance processes and systems from scratch.</p><h2 id="making-responsible-adoption-the-easy-choice">Making responsible adoption the easy choice </h2><p>For <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> and compliance leaders, the goal should be to make responsible AI adoption the path of least resistance. Employees turn to shadow AI when approved tools are unavailable, difficult to access or fail to meet their needs. Companies that focus solely on restricting usage risk driving activity further underground and losing out on the efficiency and innovation gains that AI can deliver. </p><p>Organizations that successfully balance AI <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> and control over their systems recognize that shadow AI use is often a symptom of unmet demand. Employees typically turn to unauthorized tools because they are easier to access, faster to use or better suited to the task at hand. Rather than focusing on restrictions alone, leaders should understand where AI is already being used across the business and ensure approved alternatives are available for the most common use cases. </p><p>With three-quarters of office professionals saying they would be likely to look for a new job that offered better AI skills development, firms that combine governance with opportunities to build AI skills are likely to see stronger adoption of approved tools and, as a result, less reliance on shadow AI. </p><p>Building an AI-enabled culture means giving employees the tools, knowledge and confidence to innovate within clear boundaries. By doing so, shadow AI can be reduced while the speed and agility that workers increasingly expect is maintained. </p><h2 id="the-organizations-best-positioned-to-succeed">The organizations best positioned to succeed</h2><p>The businesses that strike the right balance for AI success will be those that view governance as a foundation for AI adoption and not a barrier to it. By making the secure, approved path the easiest path, shadow AI risk is reduced without sacrificing productivity. </p><p>Embedding strong governance, supported by trusted and well-managed data foundations, avoids costly mistakes and allows AI to be deployed and scaled with greater safety and confidence.</p><p><em></em><a href="https://www.techradar.com/best/best-small-business-software"><em>We've reviewed, rated, and ranked the best small business software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/securing-adoption-in-the-era-of-shadow-ai</link>
                                                                            <description>
                            <![CDATA[ How organizations can reduce shadow AI risks while enabling secure, responsible AI adoption at scale. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wWQQNLn4PNm6qBbTdrgQiB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qP76MS2BAb7kSuWrvJXXYL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2026 07:43:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Martin Tombs ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qP76MS2BAb7kSuWrvJXXYL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands typing on a tablet with AI superimposed in text in front]]></media:description>                                                            <media:text><![CDATA[Hands typing on a tablet with AI superimposed in text in front]]></media:text>
                                <media:title type="plain"><![CDATA[Hands typing on a tablet with AI superimposed in text in front]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qP76MS2BAb7kSuWrvJXXYL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Artificial intelligence (AI) is rapidly becoming embedded in the modern workplace, with employees are increasingly turning to <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> to work more efficiently and boost productivity. </p><p>This growing demand for faster, more effective ways of working is driving the rise of shadow AI - the use of AI tools outside approved organizational controls and governance frameworks – which results in organizations quickly losing visibility into data usage and potential risks.</p><p>The scale of this challenge is significant. While 90% of executives are confident in their organizations' visibility into AI tools, just 52% of employees admit to using AI tools without approval, often through personal accounts. </p><p>As a result, organizations are left grappling with a widening gap between AI adoption and AI governance.</p><h2 id="the-next-frontier-of-ai-risk">The next frontier of AI risk</h2><p>When AI is used without formal oversight, it can bypass governance controls, increasing the risk of errors, regulatory breaches and sensitive data leakages. Organizations are most exposed when AI is already influencing business-critical activities, from customer service and operational decision-making to software development and content creation.  </p><p>The challenge will intensify as businesses move beyond <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">large language models</a>, which generate information, to large action models and agentic systems that can take action. These systems can diagnose issues, recommend actions and execute workflows with minimum human input, increasing both the speed and scale at which mistakes occur. </p><p>A shadow agent operating outside approved governance frameworks could trigger harmful actions before organizations have the visibility and governance capabilities needed to intervene.</p><p>There is also a longer-term risk that future AI systems will be trained on synthetic or lower-quality data, weakening performance and decision-making over time. Transparency and traceability will be critical to maintaining accountability, protecting ethical standards and preserving the effectiveness of AI systems as adoption continues to accelerate.</p><h2 id="ai-governance-as-an-enabler">AI governance as an enabler</h2><p>What works is AI governance that enables innovation while putting clear guardrails in place that are integrated, transparent, auditable, and aligned with existing risk and compliance frameworks. If AI is to be used safely, firms must be able to successfully identify exactly what went wrong and why when issues arise.  </p><p>In practice, mature governance starts with an approved AI tool stack that provides safe and trusted options for common use cases. This should be supported by risk-based policies that make clear the <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> being handled, what can and cannot be shared, which tools are permitted, and where human approval is required. </p><p>Low-risk tasks such as drafting or summarizing content should not be governed in the same way as high-risk uses involving customer data, regulated information or business-critical decisions.</p><p>Training is equally important. The challenge, beyond only enforcing controls, involves helping employees understand why those controls exist and how to use AI responsibly. As agents increasingly diagnose issues, recommend actions, and execute workflows with minimum input, human oversight and approval processes must scale alongside them. </p><p>Interoperability will be critical to making this workable at scale, allowing organizations to operate across jurisdictions and multiple AI models without repeatedly rebuilding governance processes and systems from scratch.</p><h2 id="making-responsible-adoption-the-easy-choice">Making responsible adoption the easy choice </h2><p>For <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> and compliance leaders, the goal should be to make responsible AI adoption the path of least resistance. Employees turn to shadow AI when approved tools are unavailable, difficult to access or fail to meet their needs. Companies that focus solely on restricting usage risk driving activity further underground and losing out on the efficiency and innovation gains that AI can deliver. </p><p>Organizations that successfully balance AI <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> and control over their systems recognize that shadow AI use is often a symptom of unmet demand. Employees typically turn to unauthorized tools because they are easier to access, faster to use or better suited to the task at hand. Rather than focusing on restrictions alone, leaders should understand where AI is already being used across the business and ensure approved alternatives are available for the most common use cases. </p><p>With three-quarters of office professionals saying they would be likely to look for a new job that offered better AI skills development, firms that combine governance with opportunities to build AI skills are likely to see stronger adoption of approved tools and, as a result, less reliance on shadow AI. </p><p>Building an AI-enabled culture means giving employees the tools, knowledge and confidence to innovate within clear boundaries. By doing so, shadow AI can be reduced while the speed and agility that workers increasingly expect is maintained. </p><h2 id="the-organizations-best-positioned-to-succeed">The organizations best positioned to succeed</h2><p>The businesses that strike the right balance for AI success will be those that view governance as a foundation for AI adoption and not a barrier to it. By making the secure, approved path the easiest path, shadow AI risk is reduced without sacrificing productivity. </p><p>Embedding strong governance, supported by trusted and well-managed data foundations, avoids costly mistakes and allows AI to be deployed and scaled with greater safety and confidence.</p><p><em></em><a href="https://www.techradar.com/best/best-small-business-software"><em>We've reviewed, rated, and ranked the best small business software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Is the new Water Cyber Shield Act too little, too late, and can a cyber group do it better? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Two US senators have proposed a new <a href="https://www.schiff.senate.gov/wp-content/uploads/2026/08/Summary_Water-Cyber-Shield-Act.pdf" target="_blank" rel="nofollow">Water Cyber Shield Act</a> to provide the EPA with additional funding and tools to conduct cybersecurity assessments on critical water infrastructure.</p><p>The act would provide $300 million annually to allow for upgrades to water utility infrastructure. Numerous coordinated attacks have been launched against US water infrastructure in recent years across 12 states, with <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">30 Minnesota utilities hit by Iran earlier this month</a>.</p><p>But a separate Water Watch Center group has been set up to monitor 91% of the roughly 50,000 community water systems nationwide following a two-year pilot. The group, set up by DEF CON Franklin and the National Rural Water Association, will offer managed detection and response services provided by five cybersecurity firms.</p><h2 id="why-are-water-utilities-being-attacked">Why are water utilities being attacked?</h2><p>The FBI, CISA, NSA, and many more <a href="https://www.techradar.com/pro/security/us-agencies-warn-iranian-hackers-are-targeting-american-critical-infrastructure-causing-disruptive-effects-within-the-united-states">agencies have issued warnings</a> about the increased threat to water utilities from Iran. </p><p>Water utilities are considered a low risk, high reward attack for state-sponsored hackers looking to cause as much damage as possible as many of the water control systems rely on  internet connected operational technology (OT) devices and logic controllers.</p><p>These devices are widely deployed across water infrastructure to control water treatment and are connected to computers at monitoring stations. Theoretically if a hacker gained control of these systems, they could turn off the treatment of water or open sewage gates to contaminate water supplies.</p><p>Many water treatment systems are designed to last decades, with these OT devices and logic controllers expected to last as long as possible. But as new tech and hardware is developed, these devices stop receiving software updates that can put them at a greater risk of being attacked.</p><p>For many in the cybersecurity industry though, the Water Cyber Shield Act is too little, too late.</p><h3 class="article-body__section" id="section-expert-perspectives-on-hardening-water-utilities"><span>Expert perspectives on hardening water utilities</span></h3><h2 id="will-the-water-cyber-shield-act-be-passed">Will the Water Cyber Shield Act be passed?</h2><p><strong>Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs: </strong></p><p><em>While it's always exciting to see Congress attempt to get some good cybersecurity hygiene laws in place, it's likely a far reach from what will actually happen. The Water Cyber Shield Act feels a lot like a round two attempt from when this was attempted back in 2023 under the existing Safe Drinking Water Act authority as a rule, but that got shut down when water industry groups and a coalition of GOP states argued that it would increase costs on ratepayers, and then the EPA folded and pulled the rule. (More info can be found </em><a href="https://www.epa.gov/cyberwater/cybersecurity-sanitary-surveys" target="_blank" rel="nofollow"><em>here</em></a><em>)</em></p><div><blockquote><p>Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn't the first time we have had this situation happen before.  So, my fingers are crossed, but I'm not holding my breath.</p></blockquote></div><p><em>I hate to say it, but historically speaking, this is likely to fail before making it to a vote, just like all other bills that have been attempted to improve water cybersecurity in the past.  If we look at just the 118</em><sup><em>th</em></sup><em> and 119</em><sup><em>th</em></sup><em> Congress, we have had 9 bills introduced, as far as I'm aware, that pushed language that would have focused on either providing monetary assistance for, directly enforcing industry standards, and/or regulation around cybersecurity for water systems and CI, each varying in degree of what they would have provided and who they would have protected (rural vs non), but of those 9, all from within the 118th congress died within committees and without comments or markup, meaning no one even bothered to fight for them to get a vote across. Technically, the 4 from this congress (119) are still "pending' but considering no movement has occurred on them, they will likely reach the same fate.</em></p><p><em>Ultimately, Congress has been unreliable in pushing forward regulation and standards towards CI for quite some time, and the mantle thankfully has been picked up by private organizations and security practitioners who wish to have a safer and more secure water source. Even though it shouldn't be dependent on the goodwill of private citizens to protect public infrastructure.</em></p><p><em>Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn't the first time we have had this situation happen before.  So, my fingers are crossed, but I'm not holding my breath.</em></p><h2 id="too-little-too-late">Too little, too late?</h2><p><strong>John Strand, Owner, Black Hills Information Security, Inc.:</strong> </p><p><em>I think this type of legislation is important, but it’s also long overdue. People have known about the security weaknesses in critical infrastructure, especially within municipalities, for well over a decade.</em></p><div><blockquote><p>This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.</p></blockquote></div><p><em>Unfortunately, this is another example of a reactive approach to cybersecurity. Too often, meaningful action doesn’t happen until the damage has already been done.</em></p><p><em>My concern is that by the time these programs are fully implemented and organizations begin benefiting from them, many of the municipalities with the same vulnerabilities that enabled recent attacks will have already been compromised.</em></p><p><em>It’s a positive step, but it’s arriving years after the underlying risks were widely understood. This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.</em></p><h2 id="is-300-million-even-enough">Is $300 million even enough?</h2><p><strong>Damon Small, Board of Directors, Xcape, Inc.:</strong> </p><p><em>The Water Cyber Shield Act attempts to address a major regulatory gap by granting the Environmental Protection Agency explicit authority to enforce baseline security standards and allocate $300 million annually for utility upgrades, but federal dollars alone cannot fix this sector's systemic fragility.</em></p><div><blockquote><p>Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.</p></blockquote></div><p><em>Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.</em></p><p><em>The industry already possesses robust reference architectures and standards for protecting control systems, so the primary barrier is execution rather than a lack of guidance. Furthermore, claiming that capital injections will solve the threat ignores the reality that maintenance windows are rare in continuous operational technology environments.</em></p><p><em>Rather than waiting on Congressional appropriations, security leaders and asset owners must immediately execute foundational controls: strictly isolate industrial control networks from corporate IT, eliminate publicly exposed management interfaces to the Internet, enforce multi-factor authentication, and replace default device credentials.</em></p><p><em>Operational security standards already exist; what utilities lack is not awareness, but the uptime flexibility to actually apply patches.</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/is-the-new-water-cyber-shield-act-too-little-too-late-and-can-a-cyber-group-do-it-better-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ Numerous recent attacks are prompting Congress to do something ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tjiX2NnAd6dGXFsmpcTECc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZtdYh6C8PhDP5njg8EtK6M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 16 Aug 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZtdYh6C8PhDP5njg8EtK6M-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Aerial view of water treatment factory at city wastewater cleaning facility]]></media:description>                                                            <media:text><![CDATA[Aerial view of water treatment factory at city wastewater cleaning facility]]></media:text>
                                <media:title type="plain"><![CDATA[Aerial view of water treatment factory at city wastewater cleaning facility]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZtdYh6C8PhDP5njg8EtK6M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Two US senators have proposed a new <a href="https://www.schiff.senate.gov/wp-content/uploads/2026/08/Summary_Water-Cyber-Shield-Act.pdf" target="_blank" rel="nofollow">Water Cyber Shield Act</a> to provide the EPA with additional funding and tools to conduct cybersecurity assessments on critical water infrastructure.</p><p>The act would provide $300 million annually to allow for upgrades to water utility infrastructure. Numerous coordinated attacks have been launched against US water infrastructure in recent years across 12 states, with <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">30 Minnesota utilities hit by Iran earlier this month</a>.</p><p>But a separate Water Watch Center group has been set up to monitor 91% of the roughly 50,000 community water systems nationwide following a two-year pilot. The group, set up by DEF CON Franklin and the National Rural Water Association, will offer managed detection and response services provided by five cybersecurity firms.</p><h2 id="why-are-water-utilities-being-attacked">Why are water utilities being attacked?</h2><p>The FBI, CISA, NSA, and many more <a href="https://www.techradar.com/pro/security/us-agencies-warn-iranian-hackers-are-targeting-american-critical-infrastructure-causing-disruptive-effects-within-the-united-states">agencies have issued warnings</a> about the increased threat to water utilities from Iran. </p><p>Water utilities are considered a low risk, high reward attack for state-sponsored hackers looking to cause as much damage as possible as many of the water control systems rely on  internet connected operational technology (OT) devices and logic controllers.</p><p>These devices are widely deployed across water infrastructure to control water treatment and are connected to computers at monitoring stations. Theoretically if a hacker gained control of these systems, they could turn off the treatment of water or open sewage gates to contaminate water supplies.</p><p>Many water treatment systems are designed to last decades, with these OT devices and logic controllers expected to last as long as possible. But as new tech and hardware is developed, these devices stop receiving software updates that can put them at a greater risk of being attacked.</p><p>For many in the cybersecurity industry though, the Water Cyber Shield Act is too little, too late.</p><h3 class="article-body__section" id="section-expert-perspectives-on-hardening-water-utilities"><span>Expert perspectives on hardening water utilities</span></h3><h2 id="will-the-water-cyber-shield-act-be-passed">Will the Water Cyber Shield Act be passed?</h2><p><strong>Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs: </strong></p><p><em>While it's always exciting to see Congress attempt to get some good cybersecurity hygiene laws in place, it's likely a far reach from what will actually happen. The Water Cyber Shield Act feels a lot like a round two attempt from when this was attempted back in 2023 under the existing Safe Drinking Water Act authority as a rule, but that got shut down when water industry groups and a coalition of GOP states argued that it would increase costs on ratepayers, and then the EPA folded and pulled the rule. (More info can be found </em><a href="https://www.epa.gov/cyberwater/cybersecurity-sanitary-surveys" target="_blank" rel="nofollow"><em>here</em></a><em>)</em></p><div><blockquote><p>Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn't the first time we have had this situation happen before.  So, my fingers are crossed, but I'm not holding my breath.</p></blockquote></div><p><em>I hate to say it, but historically speaking, this is likely to fail before making it to a vote, just like all other bills that have been attempted to improve water cybersecurity in the past.  If we look at just the 118</em><sup><em>th</em></sup><em> and 119</em><sup><em>th</em></sup><em> Congress, we have had 9 bills introduced, as far as I'm aware, that pushed language that would have focused on either providing monetary assistance for, directly enforcing industry standards, and/or regulation around cybersecurity for water systems and CI, each varying in degree of what they would have provided and who they would have protected (rural vs non), but of those 9, all from within the 118th congress died within committees and without comments or markup, meaning no one even bothered to fight for them to get a vote across. Technically, the 4 from this congress (119) are still "pending' but considering no movement has occurred on them, they will likely reach the same fate.</em></p><p><em>Ultimately, Congress has been unreliable in pushing forward regulation and standards towards CI for quite some time, and the mantle thankfully has been picked up by private organizations and security practitioners who wish to have a safer and more secure water source. Even though it shouldn't be dependent on the goodwill of private citizens to protect public infrastructure.</em></p><p><em>Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn't the first time we have had this situation happen before.  So, my fingers are crossed, but I'm not holding my breath.</em></p><h2 id="too-little-too-late">Too little, too late?</h2><p><strong>John Strand, Owner, Black Hills Information Security, Inc.:</strong> </p><p><em>I think this type of legislation is important, but it’s also long overdue. People have known about the security weaknesses in critical infrastructure, especially within municipalities, for well over a decade.</em></p><div><blockquote><p>This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.</p></blockquote></div><p><em>Unfortunately, this is another example of a reactive approach to cybersecurity. Too often, meaningful action doesn’t happen until the damage has already been done.</em></p><p><em>My concern is that by the time these programs are fully implemented and organizations begin benefiting from them, many of the municipalities with the same vulnerabilities that enabled recent attacks will have already been compromised.</em></p><p><em>It’s a positive step, but it’s arriving years after the underlying risks were widely understood. This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.</em></p><h2 id="is-300-million-even-enough">Is $300 million even enough?</h2><p><strong>Damon Small, Board of Directors, Xcape, Inc.:</strong> </p><p><em>The Water Cyber Shield Act attempts to address a major regulatory gap by granting the Environmental Protection Agency explicit authority to enforce baseline security standards and allocate $300 million annually for utility upgrades, but federal dollars alone cannot fix this sector's systemic fragility.</em></p><div><blockquote><p>Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.</p></blockquote></div><p><em>Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.</em></p><p><em>The industry already possesses robust reference architectures and standards for protecting control systems, so the primary barrier is execution rather than a lack of guidance. Furthermore, claiming that capital injections will solve the threat ignores the reality that maintenance windows are rare in continuous operational technology environments.</em></p><p><em>Rather than waiting on Congressional appropriations, security leaders and asset owners must immediately execute foundational controls: strictly isolate industrial control networks from corporate IT, eliminate publicly exposed management interfaces to the Internet, enforce multi-factor authentication, and replace default device credentials.</em></p><p><em>Operational security standards already exist; what utilities lack is not awareness, but the uptime flexibility to actually apply patches.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why was there an 'evil’ Delta airlines Wi-Fi network? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>As many attendees of this year’s DEF CON hacker conference departed Las Vegas recently, many unsuspecting passengers on Delta Flight 591 attempted to access an onboard Wi-Fi network.</p><p>What they didn’t know was that ‘Delta WiFi Fast’ was actually a fake network, allegedly set up by a fellow passenger intended to mimic the actual onboard Wi-Fi network and scam other users.</p><p>The unknown passenger was able to disable the legitimate Wi-Fi networks for 30 minutes while they launched the attack, and in doing so, may have violated United States federal law.</p><h2 id="how-did-the-attack-take-place">How did the attack take place?</h2><p>According to Aircraft Communications Addressing and Reporting System (ACARS) messages, the situation was first brought to light by the crew of the flight, who shared the following message:</p><p>“HEY ALERT CORP SECURITY WE HAVE A PAX [passenger] ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST WE BELIEVE THEY ARE TRYING TO SCAM THE OTH PAX”</p><p>Another message <a href="https://app.airframes.io/messages/7299585926" target="_blank" rel="nofollow">read</a>:</p><p>“NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFRENCE IN LAS THE WERE ABLE TO JAM OUR WIFI AND BRODCAST THERE SIGNIAL”</p><p>The actual details of what happened on the flight outside of these messages isn’t clear, but according to Monika Hathaway, head of press for DEF CON, similar attacks happened in Las Vegas: “Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations.”</p><p>Delta airlines confirmed that no aircraft operating systems were affected and flight safety was never in question.</p><p>Wi-Fi deauthorization attacks can be launched with cheap, widely available ‘deauth boards’ which are small, battery powered devices that send deauthentication frames to devices within their range. On board a plane, these could easily reach most devices.</p><p>Once the legitimate Wi-Fi has been jammed and the other users booted from the network, the attacker can then set up an ‘evil twin’ network that users will attempt to connect to, which can be used to snoop on their internet traffic, steal credentials, and perform other malicious activities.</p><h3 class="article-body__section" id="section-expert-perspectives-on-the-delta-wi-fi-attack"><span>Expert perspectives on the Delta Wi-Fi attack</span></h3><h2 id="evil-twin-attacks-and-the-risks-of-connecting">‘Evil twin’ attacks and the risks of connecting</h2><p><strong>Aras Nazarovas, Senior Information Security Researcher at Cybernews:</strong></p><p><em>An evil twin attack is when hackers create fake Wi-Fi networks with the goal of stealing sensitive information from people, or exploiting known vulnerabilities present on victim devices. The fake networks often have a very similar (or identical) name to the legitimate network, which was the case here.</em></p><p><em>Once a person connects to the hacker’s Wi-Fi network, the hacker may be able to see what the victim is doing online and what data they transfer. However, since most websites have HTTPS/TLS encryption, much of what the user does, even on the rogue network, is private.</em></p><p><em>The risk here is that the hacker may attempt to redirect the victim to a phishing website – for instance, in this case, it may have been a fake Delta login page asking for personal data like name, email, address, etc. Or, the hacker may even go further and provide fake login pages for banks, social media, and try to extract login details from the victims.</em></p><div><blockquote><p>Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers.</p></blockquote></div><p><em>Connecting to such a network comes with some risk in itself. Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers. </em></p><p><em>If a person entered credentials into a Wi-Fi login page, noticed security warnings popping up after visiting a website, downloaded something, or entered payment information into an unfamiliar page, then they may have had their data stolen. In that case, the victim should immediately change any passwords that were transmitted, do a thorough scan of their device for malware, and if bank details were transmitted, freeze the bank account until new credentials are received.</em></p><p><em>However, if a user just connected and disconnected to the Wi-Fi without entering any details or clicking suspicious links, they should be fine.</em></p><h2 id="who-would-launch-the-attack">Who would launch the attack?</h2><p><strong>Seemant Sehgal, Founder & CEO, BreachLock:</strong></p><p><em>Flying out of Vegas after Black Hat myself just a few days before this incident, I can tell you the security conference crowd that passes through that airport is unlike any other, and the crew on Flight 591 made the right call with the information they had in front of them.</em></p><div><blockquote><p>The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.</p></blockquote></div><p><em>Rogue access points impersonating a legitimate network are one of the oldest tricks in the book, and doing it on an aircraft to scam passengers is a federal crime regardless of the sophistication involved.</em></p><p><em>The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.</em></p><p><strong>Denis Calderone, CTO, Suzu Labs:</strong></p><p><em>Hackers will hack. I go to DEF CON most years, and it's pretty common to have a terrible wifi experience on those flights because everyone is playing with their WiFi Pineapples and whatnot. That said, my flight home this year had no rogue SSIDs that I could see, and although, as usual, the wifi was shoddy, I never took the time to analyze the radio signals in the cabin, but if a few deauths were flying around, I wouldn't have been too surprised. It is concerning to hear about attempted credential harvesting on the flight though, and I feel that that's taking the expected hijinks way too far.</em></p><div><blockquote><p>These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth.</p></blockquote></div><p><em>The deauthentication and evil twin combination used on Flight 591 is a well-documented attack that the security community has been demonstrating for a good two decades. These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth.</em></p><p><em>But there's a significant difference between demonstrating a technique at a conference and deploying it against 199 unsuspecting passengers on a commercial aircraft. Last November, an Australian man was sentenced to seven years and four months in prison for running the exact same attack on domestic flights using a WiFi Pineapple and now the FBI is already involved in this case. There is definitely a legal exposure here.</em></p><p><em>For anyone who travels for work, in-flight WiFi should be treated as an untrusted network, period. The enterprise advice is encrypted DNS through your MDM and always-on VPN with captive portal remediation configured. But honestly, a VPN is something every traveler should be using, not just corporate road warriors. I make sure mine is on whenever I travel, and my family does the same.</em></p><p><em>Beyond that, if a WiFi network on a plane doesn't match what the crew announced or what's printed on the seat card, don't connect to it. If a network asks you to log in with your Google account or email credentials to get WiFi access, that's not how airline WiFi works. Airline captive portals ask for a credit card or a loyalty account, not your personal email password. If you're being asked for something that doesn't make sense for the context, you're probably not on the real network.</em></p><h2 id="reputational-harm-for-the-cybersecurity-industry">Reputational harm for the cybersecurity industry</h2><p><strong>Jacob Warner, Director of IT, Xcape, Inc.:</strong></p><p><em>While a rogue Wi-Fi access point on a commercial airliner poses zero direct risk to air-gapped flight safety controls, it creates a serious enterprise security hazard for business travelers relying on inflight networks.</em></p><p><em>Dismissing an onboard network impersonation as a harmless prank ignores the reality of man-in-the-middle attacks, credential harvesting, and fake authentication portals targeting captive passengers connecting to the Internet.</em></p><div><blockquote><p>Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.</p></blockquote></div><p><em>Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.</em></p><p><em>This juvenile behavior is precisely why hackers suffer such a poor reputation among non-technical audiences and why security professionals struggle to build mainstream trust. Enterprise security teams must mandate always-on virtual private networks or zero-trust network access, disable automatic connections to open SSIDs on corporate endpoints, and instruct travelers to treat cabin wireless environments as untrusted networks.</em></p><p><em>Setting up an evil twin at 30,000 feet does not make you a clever researcher; it just proves why we cannot have nice things.</em></p><p><strong>John Strand, Owner, Black Hills Information Security, Inc.:</strong></p><p><em>This one hits differently because this is my community. These are my people. When security professionals engage in this kind of behavior, they’re betraying the very community they’re claim to represent.</em></p><div><blockquote><p>There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated.</p></blockquote></div><p><em>There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated. They’re simply people with enough technical knowledge taking advantage of others who don’t have the experience to recognize what’s happening. That isn’t skill. It’s bullying.</em></p><p><em>I hope the people responsible are held accountable. This isn’t funny, it isn’t clever, and it doesn’t demonstrate technical excellence. It’s just people abusing their knowledge to prey on those who are at a disadvantage. That’s not what this profession should stand for.</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-was-there-an-evil-delta-airlines-wi-fi-network-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ A passenger set up an evil Wi-Fi network on a post-DEF CON Delta flight - we find out what the experts think. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZAjHb9bTEpdhjJqTyEPWfb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KZMrozx7RQQq5F2nbhK2iZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 15 Aug 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Servers &amp; Network Devices]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Computing Components]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KZMrozx7RQQq5F2nbhK2iZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wi-Fi]]></media:description>                                                            <media:text><![CDATA[Wi-Fi]]></media:text>
                                <media:title type="plain"><![CDATA[Wi-Fi]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KZMrozx7RQQq5F2nbhK2iZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As many attendees of this year’s DEF CON hacker conference departed Las Vegas recently, many unsuspecting passengers on Delta Flight 591 attempted to access an onboard Wi-Fi network.</p><p>What they didn’t know was that ‘Delta WiFi Fast’ was actually a fake network, allegedly set up by a fellow passenger intended to mimic the actual onboard Wi-Fi network and scam other users.</p><p>The unknown passenger was able to disable the legitimate Wi-Fi networks for 30 minutes while they launched the attack, and in doing so, may have violated United States federal law.</p><h2 id="how-did-the-attack-take-place">How did the attack take place?</h2><p>According to Aircraft Communications Addressing and Reporting System (ACARS) messages, the situation was first brought to light by the crew of the flight, who shared the following message:</p><p>“HEY ALERT CORP SECURITY WE HAVE A PAX [passenger] ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST WE BELIEVE THEY ARE TRYING TO SCAM THE OTH PAX”</p><p>Another message <a href="https://app.airframes.io/messages/7299585926" target="_blank" rel="nofollow">read</a>:</p><p>“NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFRENCE IN LAS THE WERE ABLE TO JAM OUR WIFI AND BRODCAST THERE SIGNIAL”</p><p>The actual details of what happened on the flight outside of these messages isn’t clear, but according to Monika Hathaway, head of press for DEF CON, similar attacks happened in Las Vegas: “Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations.”</p><p>Delta airlines confirmed that no aircraft operating systems were affected and flight safety was never in question.</p><p>Wi-Fi deauthorization attacks can be launched with cheap, widely available ‘deauth boards’ which are small, battery powered devices that send deauthentication frames to devices within their range. On board a plane, these could easily reach most devices.</p><p>Once the legitimate Wi-Fi has been jammed and the other users booted from the network, the attacker can then set up an ‘evil twin’ network that users will attempt to connect to, which can be used to snoop on their internet traffic, steal credentials, and perform other malicious activities.</p><h3 class="article-body__section" id="section-expert-perspectives-on-the-delta-wi-fi-attack"><span>Expert perspectives on the Delta Wi-Fi attack</span></h3><h2 id="evil-twin-attacks-and-the-risks-of-connecting">‘Evil twin’ attacks and the risks of connecting</h2><p><strong>Aras Nazarovas, Senior Information Security Researcher at Cybernews:</strong></p><p><em>An evil twin attack is when hackers create fake Wi-Fi networks with the goal of stealing sensitive information from people, or exploiting known vulnerabilities present on victim devices. The fake networks often have a very similar (or identical) name to the legitimate network, which was the case here.</em></p><p><em>Once a person connects to the hacker’s Wi-Fi network, the hacker may be able to see what the victim is doing online and what data they transfer. However, since most websites have HTTPS/TLS encryption, much of what the user does, even on the rogue network, is private.</em></p><p><em>The risk here is that the hacker may attempt to redirect the victim to a phishing website – for instance, in this case, it may have been a fake Delta login page asking for personal data like name, email, address, etc. Or, the hacker may even go further and provide fake login pages for banks, social media, and try to extract login details from the victims.</em></p><div><blockquote><p>Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers.</p></blockquote></div><p><em>Connecting to such a network comes with some risk in itself. Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers. </em></p><p><em>If a person entered credentials into a Wi-Fi login page, noticed security warnings popping up after visiting a website, downloaded something, or entered payment information into an unfamiliar page, then they may have had their data stolen. In that case, the victim should immediately change any passwords that were transmitted, do a thorough scan of their device for malware, and if bank details were transmitted, freeze the bank account until new credentials are received.</em></p><p><em>However, if a user just connected and disconnected to the Wi-Fi without entering any details or clicking suspicious links, they should be fine.</em></p><h2 id="who-would-launch-the-attack">Who would launch the attack?</h2><p><strong>Seemant Sehgal, Founder & CEO, BreachLock:</strong></p><p><em>Flying out of Vegas after Black Hat myself just a few days before this incident, I can tell you the security conference crowd that passes through that airport is unlike any other, and the crew on Flight 591 made the right call with the information they had in front of them.</em></p><div><blockquote><p>The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.</p></blockquote></div><p><em>Rogue access points impersonating a legitimate network are one of the oldest tricks in the book, and doing it on an aircraft to scam passengers is a federal crime regardless of the sophistication involved.</em></p><p><em>The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.</em></p><p><strong>Denis Calderone, CTO, Suzu Labs:</strong></p><p><em>Hackers will hack. I go to DEF CON most years, and it's pretty common to have a terrible wifi experience on those flights because everyone is playing with their WiFi Pineapples and whatnot. That said, my flight home this year had no rogue SSIDs that I could see, and although, as usual, the wifi was shoddy, I never took the time to analyze the radio signals in the cabin, but if a few deauths were flying around, I wouldn't have been too surprised. It is concerning to hear about attempted credential harvesting on the flight though, and I feel that that's taking the expected hijinks way too far.</em></p><div><blockquote><p>These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth.</p></blockquote></div><p><em>The deauthentication and evil twin combination used on Flight 591 is a well-documented attack that the security community has been demonstrating for a good two decades. These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth.</em></p><p><em>But there's a significant difference between demonstrating a technique at a conference and deploying it against 199 unsuspecting passengers on a commercial aircraft. Last November, an Australian man was sentenced to seven years and four months in prison for running the exact same attack on domestic flights using a WiFi Pineapple and now the FBI is already involved in this case. There is definitely a legal exposure here.</em></p><p><em>For anyone who travels for work, in-flight WiFi should be treated as an untrusted network, period. The enterprise advice is encrypted DNS through your MDM and always-on VPN with captive portal remediation configured. But honestly, a VPN is something every traveler should be using, not just corporate road warriors. I make sure mine is on whenever I travel, and my family does the same.</em></p><p><em>Beyond that, if a WiFi network on a plane doesn't match what the crew announced or what's printed on the seat card, don't connect to it. If a network asks you to log in with your Google account or email credentials to get WiFi access, that's not how airline WiFi works. Airline captive portals ask for a credit card or a loyalty account, not your personal email password. If you're being asked for something that doesn't make sense for the context, you're probably not on the real network.</em></p><h2 id="reputational-harm-for-the-cybersecurity-industry">Reputational harm for the cybersecurity industry</h2><p><strong>Jacob Warner, Director of IT, Xcape, Inc.:</strong></p><p><em>While a rogue Wi-Fi access point on a commercial airliner poses zero direct risk to air-gapped flight safety controls, it creates a serious enterprise security hazard for business travelers relying on inflight networks.</em></p><p><em>Dismissing an onboard network impersonation as a harmless prank ignores the reality of man-in-the-middle attacks, credential harvesting, and fake authentication portals targeting captive passengers connecting to the Internet.</em></p><div><blockquote><p>Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.</p></blockquote></div><p><em>Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.</em></p><p><em>This juvenile behavior is precisely why hackers suffer such a poor reputation among non-technical audiences and why security professionals struggle to build mainstream trust. Enterprise security teams must mandate always-on virtual private networks or zero-trust network access, disable automatic connections to open SSIDs on corporate endpoints, and instruct travelers to treat cabin wireless environments as untrusted networks.</em></p><p><em>Setting up an evil twin at 30,000 feet does not make you a clever researcher; it just proves why we cannot have nice things.</em></p><p><strong>John Strand, Owner, Black Hills Information Security, Inc.:</strong></p><p><em>This one hits differently because this is my community. These are my people. When security professionals engage in this kind of behavior, they’re betraying the very community they’re claim to represent.</em></p><div><blockquote><p>There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated.</p></blockquote></div><p><em>There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated. They’re simply people with enough technical knowledge taking advantage of others who don’t have the experience to recognize what’s happening. That isn’t skill. It’s bullying.</em></p><p><em>I hope the people responsible are held accountable. This isn’t funny, it isn’t clever, and it doesn’t demonstrate technical excellence. It’s just people abusing their knowledge to prey on those who are at a disadvantage. That’s not what this profession should stand for.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'This one just needs a script': Researchers find ultimate Windows kill switch which can disable antivirus with almost no user interaction ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers uncovered “Download more RAM” flaw in consumer DDR4/DDR5 memory</strong></li><li><strong>Attack bypassed Windows VBS and HVCI, disabling antivirus and protections</strong></li><li><strong>Microsoft patched CVE‑2026‑23670; tools now help enable memory write protection</strong></li></ul><p>Microsoft has recently fixed a vulnerability that allowed threat actors to bypass advanced security measures, disable antivirus software, and expose the target device to full system takeover. </p><p>All of this, it seems, could have been possible with a very simple script, and a single click from the victim’s side.</p><p>Luckily, the vulnerability was discovered by white hat hackers, reported to Microsoft and remedied before falling into the wrong hands.</p><h2 id="download-more-ram">Download more RAM</h2><p>During the 2026 USENIX Security Symposium, security researchers from the University of Birmingham and Durham University presented a discovery they called “Download more RAM”. </p><p>According to the researchers, some consumer memory chips (DDR4 and <a href="https://www.techradar.com/computing/best-ddr5-ram" target="_blank">DDR5</a> DIMM) allowed software to alter the configuration reports it sends to the motherboard. In practice, it means that a threat actor could instruct the RAM chip to tell the computer it was bigger than it actually was, making the device “think” it has twice as much RAM memory as it actually has.</p><p>The researchers then established that this phantom extra memory can serve as an alias for real memory locations, granting them the ability to both read, and modify, memory allocations that should be under the processor’s, and Windows’ protection.</p><p>This window let them work around both Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI). </p><p>VBS, first introduced with Windows 10, is a security feature that uses hardware virtualization to isolate critical security functions from the OS, while HVCI uses virtualization to make sure only trusted and verified code can run in the Windows kernel.</p><p>The researchers also used the flaw to disable both antivirus and endpoint detection and response (EDR) software, re-introduce older, vulnerable drivers, compromise corporate systems under lockdown, and bypass kernel-level game anti-cheat protections. </p><p>The worst part is that this entire process can be chained together into a one-click script. In theory, if a victim is served this script as a file and they run it, they would trigger a chain of events that includes creating memory aliases, rebooting the computer, and disabling security protections. </p><p>"Our work exploits the fact that all processes share the same memory to bypass Windows' strongest security guarantees,” said Professor Tom Chothia, from the University of Birmingham. “Previous attacks of this kind needed a screwdriver and physical access to the machine. This one just needs a script. That changes who can carry it out and how far it can spread."</p><h2 id="who-is-vulnerable-and-how-to-stay-safe">Who is vulnerable and how to stay safe</h2><p>The attack surface is rather large, as well. The researchers analyzed the market and found three major manufacturers (Corsair, G.Skill, and ADATA) shipping at least one consumer memory product line in which the configuration chip was left entirely unprotected. Together, these vendors make up more than half (55%) of the high-performance consumer memory market and more than 70% of the gaming market (this doesn’t mean that 55% of the high-performance market is vulnerable - many devices are running other modules, too).</p><p>Modules from Crucial, Kingston and HyperX, and some G.Skill lines, were found to use partial write protection, but still enough to keep the device secure. </p><p>Before publishing their work, the researchers disclosed their findings to Microsoft, who quickly addressed it. The bug is now tracked as CVE-2026-23670, and is described on the National Vulnerability Database (NVD) as an “untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave” which “allows an authorized attacker to bypass a security feature locally.”</p><p>The bug was given a severity score of 5.7/10 (medium), and was fixed as part of the April 2026 Patch Tuesday cumulative update. Therefore, systems with Secure Boot running should be protected against this vulnerability. </p><p>Corsair added a feature to its iCue tools that lets users retroactively enable write protection on their memory modules. There is also a free tool called HWinfo with the same functionality, the researchers said, stressing that it mitigates the issue on non-Corsair models. Also, some motherboards offer a BIOS setting to block writes to memory configuration chips, which users can enable as an interim measure.</p><p>“The ‘Download More RAM’ attack demonstrates once more the importance of understanding systems, especially in terms of security guarantees. If a lower layer can become compromised, it puts the full system at risk,” said Dr Marius Muench, from the University of Birmingham.  </p><p>“Windows makes a strong promise: that even an attacker with administrator rights can't touch the secure kernel. We found that promise rests on the assumption that your memory is telling the truth about itself - on a lot of the memory people actually buy, it doesn't have to." </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-one-just-needs-a-script-researchers-find-ultimate-windows-kill-switch-which-can-disable-antivirus-with-almost-no-user-interaction</link>
                                                                            <description>
                            <![CDATA[ Microsoft fixed it as part of the April Patch Tuesday cumulative update, but there are other fixes and mitigations available, too. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">D5GiErt8bYeqUgE82r6EtQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Är du ute efter bästa VPN för Windows 10 och Windwos 11? Här är våra favoriter just nu.]]></media:description>                                                            <media:text><![CDATA[Fingertip pressing keyboard key with Windows logo on it]]></media:text>
                                <media:title type="plain"><![CDATA[Fingertip pressing keyboard key with Windows logo on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers uncovered “Download more RAM” flaw in consumer DDR4/DDR5 memory</strong></li><li><strong>Attack bypassed Windows VBS and HVCI, disabling antivirus and protections</strong></li><li><strong>Microsoft patched CVE‑2026‑23670; tools now help enable memory write protection</strong></li></ul><p>Microsoft has recently fixed a vulnerability that allowed threat actors to bypass advanced security measures, disable antivirus software, and expose the target device to full system takeover. </p><p>All of this, it seems, could have been possible with a very simple script, and a single click from the victim’s side.</p><p>Luckily, the vulnerability was discovered by white hat hackers, reported to Microsoft and remedied before falling into the wrong hands.</p><h2 id="download-more-ram">Download more RAM</h2><p>During the 2026 USENIX Security Symposium, security researchers from the University of Birmingham and Durham University presented a discovery they called “Download more RAM”. </p><p>According to the researchers, some consumer memory chips (DDR4 and <a href="https://www.techradar.com/computing/best-ddr5-ram" target="_blank">DDR5</a> DIMM) allowed software to alter the configuration reports it sends to the motherboard. In practice, it means that a threat actor could instruct the RAM chip to tell the computer it was bigger than it actually was, making the device “think” it has twice as much RAM memory as it actually has.</p><p>The researchers then established that this phantom extra memory can serve as an alias for real memory locations, granting them the ability to both read, and modify, memory allocations that should be under the processor’s, and Windows’ protection.</p><p>This window let them work around both Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI). </p><p>VBS, first introduced with Windows 10, is a security feature that uses hardware virtualization to isolate critical security functions from the OS, while HVCI uses virtualization to make sure only trusted and verified code can run in the Windows kernel.</p><p>The researchers also used the flaw to disable both antivirus and endpoint detection and response (EDR) software, re-introduce older, vulnerable drivers, compromise corporate systems under lockdown, and bypass kernel-level game anti-cheat protections. </p><p>The worst part is that this entire process can be chained together into a one-click script. In theory, if a victim is served this script as a file and they run it, they would trigger a chain of events that includes creating memory aliases, rebooting the computer, and disabling security protections. </p><p>"Our work exploits the fact that all processes share the same memory to bypass Windows' strongest security guarantees,” said Professor Tom Chothia, from the University of Birmingham. “Previous attacks of this kind needed a screwdriver and physical access to the machine. This one just needs a script. That changes who can carry it out and how far it can spread."</p><h2 id="who-is-vulnerable-and-how-to-stay-safe">Who is vulnerable and how to stay safe</h2><p>The attack surface is rather large, as well. The researchers analyzed the market and found three major manufacturers (Corsair, G.Skill, and ADATA) shipping at least one consumer memory product line in which the configuration chip was left entirely unprotected. Together, these vendors make up more than half (55%) of the high-performance consumer memory market and more than 70% of the gaming market (this doesn’t mean that 55% of the high-performance market is vulnerable - many devices are running other modules, too).</p><p>Modules from Crucial, Kingston and HyperX, and some G.Skill lines, were found to use partial write protection, but still enough to keep the device secure. </p><p>Before publishing their work, the researchers disclosed their findings to Microsoft, who quickly addressed it. The bug is now tracked as CVE-2026-23670, and is described on the National Vulnerability Database (NVD) as an “untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave” which “allows an authorized attacker to bypass a security feature locally.”</p><p>The bug was given a severity score of 5.7/10 (medium), and was fixed as part of the April 2026 Patch Tuesday cumulative update. Therefore, systems with Secure Boot running should be protected against this vulnerability. </p><p>Corsair added a feature to its iCue tools that lets users retroactively enable write protection on their memory modules. There is also a free tool called HWinfo with the same functionality, the researchers said, stressing that it mitigates the issue on non-Corsair models. Also, some motherboards offer a BIOS setting to block writes to memory configuration chips, which users can enable as an interim measure.</p><p>“The ‘Download More RAM’ attack demonstrates once more the importance of understanding systems, especially in terms of security guarantees. If a lower layer can become compromised, it puts the full system at risk,” said Dr Marius Muench, from the University of Birmingham.  </p><p>“Windows makes a strong promise: that even an attacker with administrator rights can't touch the secure kernel. We found that promise rests on the assumption that your memory is telling the truth about itself - on a lot of the memory people actually buy, it doesn't have to." </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Scammers hijack real Shopify notifications to swindle victims — here's how to stay safe ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress uncovers Shopify refund scam using fake orders and app notifications</strong></li><li><strong>Attackers embed contact details in shipping addresses to trick victims into paying</strong></li><li><strong>Users advised to ignore suspicious info, verify refunds, and report fake stores</strong></li></ul><p>Hackers are targeting businesses and individuals running Shopify stores with a highly sophisticated fake refund scam, experts have warned.</p><p>Security researchers at Huntress <a href="https://www.huntress.com/blog/shopify-fake-refund-scam" target="_blank">outlined</a> how the fake refund scam works: first, a victim gets a notification that they received a refund. It could be for a returned iPhone, or a canceled service or order. The “refund” can be anywhere from a few hundred, to a few thousand dollars. Soon after, the scammers call (or mail) the victim, say they work at the company that gave the erroneous refund, and convince the victim to return the funds.</p><p>If the victim complies, they are actually sending their own money to the victims, since the “refund” part never happened.</p><h2 id="abusing-shopify-s-infrastructure">Abusing Shopify's infrastructure</h2><p>There are a couple of ways to pull this attack off: sometimes the scammers really make the initial transaction, but are able to cancel it and return the funds; in other scenarios, they create spoofed pages showing the transactions, tricking those slightly more gullible. </p><p>In most cases, fake refund scams can be spotted relatively easily, which is why they are not that popular nowadays. However, this new campaign comes with a sinister twist that will make even hardened veterans wince.</p><p>Huntress’ report notes the attackers start by creating a Shopify store of their own (or use a compromised one). The one the researchers observed was called “My Store” and was later deleted before it could be further scrutinized. Then, the attackers make a fake order themselves, setting their targets as the recipients using their phone numbers, or email addresses.</p><p>This type of information isn’t that difficult to come by these days. There are hundreds of email and phone number databases leaked on the dark web, which can be picked up for free (or for a handful of dollars). When they submit the purchase order, a notification appears in the victim’s Shop apps. </p><p>Yes, that’s right. In the Shopify app itself. Coming through Shopify infrastructure. As such, it can easily be confused for an authentic notification. It is even worse for users that enabled push notifications on their mobile phones, since they’ll see a notification with the Shopify logo, next to all the other notifications on their phone. </p><p>But the attackers still need to pull off the hardest part - getting the victim to “return” the money. In this case, instead of calling or messaging them, they leave their contact information in the shipping address, hoping victims would panic and reach out themselves.</p><p>In one shared example, the shipping address was listed as: Owen Nolan “2856 If You Didnt Place This Order Call Us at 1_888_690_3420-”, Albany NY United States 1_888_690_3420.”</p><p>For those treading carefully through the internet’s wastelands, the message included in the shipping address is an immediate red flag. Grammar mistakes, all letters capitalized, and a phone number completely out of place should be quite an obvious sign of an attempted fraud. However, since these kinds of scams bet on people being fast, reckless, overworked, and afraid, it might just work.</p><p>Huntress did not say if the scam made any meaningful impact among the Shopify’s community, or if it targeted a specific subgroup of users. </p><h2 id="defending-against-fake-refund-scams">Defending against fake refund scams</h2><p>To protect against such attacks, the researchers advise users never interact with phone numbers, email addresses, or links contained in an order that aren’t recognizable. They also advise users concerned about the security of their SHop account or personal data to contact support, and stress users should check their bank accounts to confirm whether they were actually changed. If they weren’t, they can report the order as “Not my order” in the shop app. </p><p>Finally, when purchasing from a store on Shop in general, users should check the store and its product reviews to learn about other customers’ experiences. If users are concerned that a product or store could be fake, it can easily be reported. Many of the shops in this scam were brand-new, with some using a "coming soon" description, as well. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/scammers-hijack-real-shopify-notifications-to-swindle-victims-heres-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Would you recognize a fake notification if it came directly from Shopify? Some scammers are betting you wouldn't. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">u7cEBFyhxgwb3nwswX5ieS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sTv9eAmsTTbHV59N8KXUZk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 15:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sTv9eAmsTTbHV59N8KXUZk-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[use Shopify to build your online busness]]></media:description>                                                            <media:text><![CDATA[use Shopify to build your online busness]]></media:text>
                                <media:title type="plain"><![CDATA[use Shopify to build your online busness]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sTv9eAmsTTbHV59N8KXUZk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress uncovers Shopify refund scam using fake orders and app notifications</strong></li><li><strong>Attackers embed contact details in shipping addresses to trick victims into paying</strong></li><li><strong>Users advised to ignore suspicious info, verify refunds, and report fake stores</strong></li></ul><p>Hackers are targeting businesses and individuals running Shopify stores with a highly sophisticated fake refund scam, experts have warned.</p><p>Security researchers at Huntress <a href="https://www.huntress.com/blog/shopify-fake-refund-scam" target="_blank">outlined</a> how the fake refund scam works: first, a victim gets a notification that they received a refund. It could be for a returned iPhone, or a canceled service or order. The “refund” can be anywhere from a few hundred, to a few thousand dollars. Soon after, the scammers call (or mail) the victim, say they work at the company that gave the erroneous refund, and convince the victim to return the funds.</p><p>If the victim complies, they are actually sending their own money to the victims, since the “refund” part never happened.</p><h2 id="abusing-shopify-s-infrastructure">Abusing Shopify's infrastructure</h2><p>There are a couple of ways to pull this attack off: sometimes the scammers really make the initial transaction, but are able to cancel it and return the funds; in other scenarios, they create spoofed pages showing the transactions, tricking those slightly more gullible. </p><p>In most cases, fake refund scams can be spotted relatively easily, which is why they are not that popular nowadays. However, this new campaign comes with a sinister twist that will make even hardened veterans wince.</p><p>Huntress’ report notes the attackers start by creating a Shopify store of their own (or use a compromised one). The one the researchers observed was called “My Store” and was later deleted before it could be further scrutinized. Then, the attackers make a fake order themselves, setting their targets as the recipients using their phone numbers, or email addresses.</p><p>This type of information isn’t that difficult to come by these days. There are hundreds of email and phone number databases leaked on the dark web, which can be picked up for free (or for a handful of dollars). When they submit the purchase order, a notification appears in the victim’s Shop apps. </p><p>Yes, that’s right. In the Shopify app itself. Coming through Shopify infrastructure. As such, it can easily be confused for an authentic notification. It is even worse for users that enabled push notifications on their mobile phones, since they’ll see a notification with the Shopify logo, next to all the other notifications on their phone. </p><p>But the attackers still need to pull off the hardest part - getting the victim to “return” the money. In this case, instead of calling or messaging them, they leave their contact information in the shipping address, hoping victims would panic and reach out themselves.</p><p>In one shared example, the shipping address was listed as: Owen Nolan “2856 If You Didnt Place This Order Call Us at 1_888_690_3420-”, Albany NY United States 1_888_690_3420.”</p><p>For those treading carefully through the internet’s wastelands, the message included in the shipping address is an immediate red flag. Grammar mistakes, all letters capitalized, and a phone number completely out of place should be quite an obvious sign of an attempted fraud. However, since these kinds of scams bet on people being fast, reckless, overworked, and afraid, it might just work.</p><p>Huntress did not say if the scam made any meaningful impact among the Shopify’s community, or if it targeted a specific subgroup of users. </p><h2 id="defending-against-fake-refund-scams">Defending against fake refund scams</h2><p>To protect against such attacks, the researchers advise users never interact with phone numbers, email addresses, or links contained in an order that aren’t recognizable. They also advise users concerned about the security of their SHop account or personal data to contact support, and stress users should check their bank accounts to confirm whether they were actually changed. If they weren’t, they can report the order as “Not my order” in the shop app. </p><p>Finally, when purchasing from a store on Shop in general, users should check the store and its product reviews to learn about other customers’ experiences. If users are concerned that a product or store could be fake, it can easily be reported. Many of the shops in this scam were brand-new, with some using a "coming soon" description, as well. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI is making cyber threats faster, but trust will define which businesses survive ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A small business owner receives a call from a customer. </p><p>An email that appeared to come from the business led the customer to a fraudulent <a href="https://www.techradar.com/news/the-best-website-builder">website</a>, and their personal information may have been compromised. </p><p>What makes situations like this so damaging is that the owner never knew the risk existed. </p><p>The domain used in the attack had been registered for a campaign years earlier and left quietly active, sitting outside anyone's management, until someone else found a use for it.</p><p>Situations like this rarely begin with a major <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> breach. More often they start with something small: a forgotten domain, an outdated email configuration, or a digital asset nobody realized was still active. </p><p>AI makes finding those unnoticed weaknesses all too easy for attackers. According to KnowBe4's 2025 Phishing Threat Trends Report, 82.6% of phishing emails now show some use of AI, a 53.5% increase year-over-year. Attackers are adopting the same <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> businesses use to improve efficiency, and the speed advantage has shifted. The good news is that businesses can use the same advances in AI to identify many of these risks before attackers do.</p><p>But the speed of detection is only part of the challenge. The harder problem is visibility. You can't secure what you don't know you own.</p><p>More and more, small businesses manage <a href="https://www.techradar.com/news/best-domain-registrars">domain names</a>, websites, email systems, social channels, and third-party tools, and as those layers expand, the gaps between ownership and oversight become easier to miss. </p><p>Forgotten domains are a common example. Domains created for promotions, campaigns, or discontinued services often stay active long after their purpose disappears. Left unmanaged, they become blind spots that attackers exploit through phishing, impersonation, and brand abuse, and they can quietly erode credibility well before any breach, since a domain that no longer resolves correctly signals neglect to customers and machines alike.</p><p>Simply put, many business owners no longer have a complete view of the digital assets they own or the vulnerabilities that come with them.</p><h2 id="security-needs-to-be-embedded-not-bolted-on">Security needs to be embedded, not bolted on</h2><p>Small business owners are focused on serving customers, growing revenue, and running their businesses. They are not thinking about <a href="https://www.techradar.com/news/best-dns-server">DNS</a> records, certificate renewals, or dormant subdomains during their day. Nor should they have to.</p><p>But many do not have the option. According to VikingCloud's 2026 research, 84% of SMB owners manage cybersecurity themselves, often without dedicated training or expertise. </p><p>The most effective security strategies are built into the infrastructure which businesses depend on every day, rather than added after problems arise. There are three layers where this matters most: the domain, which serves as a business' identity online; the website, where customers form opinions about credibility and trustworthiness; and <a href="https://www.techradar.com/news/best-email-provider">email</a>, which remains one of the most important channels for customer communication and one of the most common targets for impersonation and fraud.</p><p>Embedding security into the solutions businesses already use helps them maintain visibility and confidence without constant manual oversight of all of those moving parts.</p><h2 id="trust-is-now-measured-by-both-people-and-machines">Trust is now measured by both people and machines</h2><p>Today’s <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> conversation always comes back to trust. That’s what SMBs want to win by securing their online business. It is the engine of their success.</p><p>We know that trust is one of the most important competitive advantages a business can have: according to McKinsey reporting on digital trust, 40% of consumers have completely pulled their business from a company after discovering the organization was reckless with customer data, and 10% of consumers will cut ties with a brand immediately upon learning of a data breach, regardless of whether their own personal information was actually compromised or stolen.</p><p>For years, trust online was primarily a human judgment. Customers visited a website, received an email, or interacted with a brand, and decided whether it appeared credible. Today they still make those decisions, but they are no longer the only ones making them.</p><p>Search engines, AI assistants, and automated systems increasingly evaluate trust signals on behalf of users. Roughly two-thirds of Google searches now end without a click, according to Similarweb clickstream data analyzed by SparkToro. Trust is no longer just a customer's perception; it is becoming part of how businesses get discovered.</p><p>Credibility is no longer determined solely by what customers see. Domain resolution, certificate validity, email authentication records, and the consistency of businesses’ online presence all feed into the assessments that influence search rankings, AI-generated recommendations, and discovery across the platforms customers use every day. A business that doesn’t deliver on these fronts may be overlooked long before a customer ever decides whether to trust it.</p><h2 id="trust-and-security-are-now-competitive-infrastructure">Trust and security are now competitive infrastructure</h2><p>For decades, businesses viewed security as a defensive function, meant to reduce risk and respond to threats. That perspective is changing.</p><p>Trust and security now influence customer acquisition, retention, reputation, and long-term growth. In the <a href="https://www.techradar.com/best/best-ai-tools">AI</a> era, trust is no longer just a security outcome. It is a business strategy. As AI accelerates both innovation and risk, customers have become more selective about who they engage with and where they share their information. Credibility is difficult to earn and almost impossible to buy back once lost.</p><p>At Network Solutions, we have spent decades helping businesses establish and protect their digital identities. One lesson remains consistent: investing in trust early creates advantages competitors struggle to replicate.</p><p>Businesses that stand out in the years ahead won't simply adopt more AI. They'll build trust into every layer of their digital presence. The business owner who took that call from a customer deserved a better security infrastructure, not a better incident response after the fact.</p><p>Technology will continue to evolve, and so will the threats. Trust will only become more valuable. The businesses that thrive won't simply adopt more AI; they'll build stronger foundations for trust. That's where our industry needs to go next.</p><p><em></em><a href="https://www.techradar.com/news/the-best-free-website-builder"><em>We've listed the best free website builders</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ai-is-making-cyber-threats-faster-but-trust-will-define-which-businesses-survive</link>
                                                                            <description>
                            <![CDATA[ AI exposes forgotten digital risks, but trust determines who earns customers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rjWsC9qPQ3tDUr7vdY2jQE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 13:04:56 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sachin Puri ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phone malware]]></media:description>                                                            <media:text><![CDATA[Phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A small business owner receives a call from a customer. </p><p>An email that appeared to come from the business led the customer to a fraudulent <a href="https://www.techradar.com/news/the-best-website-builder">website</a>, and their personal information may have been compromised. </p><p>What makes situations like this so damaging is that the owner never knew the risk existed. </p><p>The domain used in the attack had been registered for a campaign years earlier and left quietly active, sitting outside anyone's management, until someone else found a use for it.</p><p>Situations like this rarely begin with a major <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> breach. More often they start with something small: a forgotten domain, an outdated email configuration, or a digital asset nobody realized was still active. </p><p>AI makes finding those unnoticed weaknesses all too easy for attackers. According to KnowBe4's 2025 Phishing Threat Trends Report, 82.6% of phishing emails now show some use of AI, a 53.5% increase year-over-year. Attackers are adopting the same <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> businesses use to improve efficiency, and the speed advantage has shifted. The good news is that businesses can use the same advances in AI to identify many of these risks before attackers do.</p><p>But the speed of detection is only part of the challenge. The harder problem is visibility. You can't secure what you don't know you own.</p><p>More and more, small businesses manage <a href="https://www.techradar.com/news/best-domain-registrars">domain names</a>, websites, email systems, social channels, and third-party tools, and as those layers expand, the gaps between ownership and oversight become easier to miss. </p><p>Forgotten domains are a common example. Domains created for promotions, campaigns, or discontinued services often stay active long after their purpose disappears. Left unmanaged, they become blind spots that attackers exploit through phishing, impersonation, and brand abuse, and they can quietly erode credibility well before any breach, since a domain that no longer resolves correctly signals neglect to customers and machines alike.</p><p>Simply put, many business owners no longer have a complete view of the digital assets they own or the vulnerabilities that come with them.</p><h2 id="security-needs-to-be-embedded-not-bolted-on">Security needs to be embedded, not bolted on</h2><p>Small business owners are focused on serving customers, growing revenue, and running their businesses. They are not thinking about <a href="https://www.techradar.com/news/best-dns-server">DNS</a> records, certificate renewals, or dormant subdomains during their day. Nor should they have to.</p><p>But many do not have the option. According to VikingCloud's 2026 research, 84% of SMB owners manage cybersecurity themselves, often without dedicated training or expertise. </p><p>The most effective security strategies are built into the infrastructure which businesses depend on every day, rather than added after problems arise. There are three layers where this matters most: the domain, which serves as a business' identity online; the website, where customers form opinions about credibility and trustworthiness; and <a href="https://www.techradar.com/news/best-email-provider">email</a>, which remains one of the most important channels for customer communication and one of the most common targets for impersonation and fraud.</p><p>Embedding security into the solutions businesses already use helps them maintain visibility and confidence without constant manual oversight of all of those moving parts.</p><h2 id="trust-is-now-measured-by-both-people-and-machines">Trust is now measured by both people and machines</h2><p>Today’s <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> conversation always comes back to trust. That’s what SMBs want to win by securing their online business. It is the engine of their success.</p><p>We know that trust is one of the most important competitive advantages a business can have: according to McKinsey reporting on digital trust, 40% of consumers have completely pulled their business from a company after discovering the organization was reckless with customer data, and 10% of consumers will cut ties with a brand immediately upon learning of a data breach, regardless of whether their own personal information was actually compromised or stolen.</p><p>For years, trust online was primarily a human judgment. Customers visited a website, received an email, or interacted with a brand, and decided whether it appeared credible. Today they still make those decisions, but they are no longer the only ones making them.</p><p>Search engines, AI assistants, and automated systems increasingly evaluate trust signals on behalf of users. Roughly two-thirds of Google searches now end without a click, according to Similarweb clickstream data analyzed by SparkToro. Trust is no longer just a customer's perception; it is becoming part of how businesses get discovered.</p><p>Credibility is no longer determined solely by what customers see. Domain resolution, certificate validity, email authentication records, and the consistency of businesses’ online presence all feed into the assessments that influence search rankings, AI-generated recommendations, and discovery across the platforms customers use every day. A business that doesn’t deliver on these fronts may be overlooked long before a customer ever decides whether to trust it.</p><h2 id="trust-and-security-are-now-competitive-infrastructure">Trust and security are now competitive infrastructure</h2><p>For decades, businesses viewed security as a defensive function, meant to reduce risk and respond to threats. That perspective is changing.</p><p>Trust and security now influence customer acquisition, retention, reputation, and long-term growth. In the <a href="https://www.techradar.com/best/best-ai-tools">AI</a> era, trust is no longer just a security outcome. It is a business strategy. As AI accelerates both innovation and risk, customers have become more selective about who they engage with and where they share their information. Credibility is difficult to earn and almost impossible to buy back once lost.</p><p>At Network Solutions, we have spent decades helping businesses establish and protect their digital identities. One lesson remains consistent: investing in trust early creates advantages competitors struggle to replicate.</p><p>Businesses that stand out in the years ahead won't simply adopt more AI. They'll build trust into every layer of their digital presence. The business owner who took that call from a customer deserved a better security infrastructure, not a better incident response after the fact.</p><p>Technology will continue to evolve, and so will the threats. Trust will only become more valuable. The businesses that thrive won't simply adopt more AI; they'll build stronger foundations for trust. That's where our industry needs to go next.</p><p><em></em><a href="https://www.techradar.com/news/the-best-free-website-builder"><em>We've listed the best free website builders</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI agents are inside the enterprise – are your security foundations ready for them? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The recent release of Anthropic Mythos is a wake-up call for the tech industry – and the fact that Anthropic themselves chose not to release it publicly speaks volumes about the level of risk we have now reached. AI agents have evolved from <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">chatbots</a> with upgraded capabilities to effective employees with <a href="https://www.techradar.com/best/best-database-software">database</a> access, API keys, and system privileges.</p><p>However, the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> protecting them is built on the same strategy that failed to stop ChatGPT jailbreaks in 2023. And this time, there’s no human to review an agent’s output, just an autonomous agent carrying out commands in a silo.</p><p>AI agents are reshaping enterprise systems and the way work gets done. Securing them requires an equally fundamental shift in thinking. Ultimately, now that agents act independently, resilience must be rooted in foundational controls, including hardware-level and lower-stack security, to be ready when the higher-level safeguards fail.</p><h2 id="how-ai-agents-expand-the-attack-surface">How AI agents expand the attack surface</h2><p>Before agentic AI, the biggest AI risks were bad recommendations, inappropriate responses, and conversational data exposure. Human oversight acted as a safeguard for every action, and AI systems operated without direct access to sensitive information. The primary concern was reputational damage rather than risks to underlying <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>.</p><p>When Anthropic released the Model Context Protocol (MCP) in November 2024, it established a standardized framework that allows AI agents to connect to databases, file systems, and enterprise tools. But within eight months, a critical vulnerability emerged (CVE-2025-49596, CVSS9.4), triggering emergency security responses across the industry.</p><p>The risk came from four factors working together. Autonomy means agents can decide and act without human review. Privileged access gives them credentials, tokens and file system permissions. Machine-speed execution leaves little time for human intervention. And cross-system reach means one compromised agent can move across connected environments.</p><p>Together, these factors expanded the attack surface far beyond what traditional security controls – even AI-enabled ones – were built to manage.</p><h2 id="why-software-only-defences-keep-falling-short">Why software-only defences keep falling short</h2><p>The industry is moving quickly to secure AI agents, but the response largely mirrors a familiar approach: adding more layers of <a href="https://www.techradar.com/best/best-small-business-software">software</a>. Most companies are focusing on two main layers: input guardrails – implementing more software tools designed to stop malicious instructions from ever reaching AI agents, and permissions and monitoring – limiting what compromised agents can access.</p><p>It’s the same strategy the industry had relied on for decades: deploy quickly, remain agile, and address vulnerabilities as they emerge. Both methods operate inside the software trust boundary.</p><p>But history shows this approach often ends the same way: with the need for hardware-layer protections. In the 1990s and 2000s, network security responded to software exploits by deploying additional software layers. Breaches persisted until organizations eventually adopted hardware-enforced network segmentation.</p><p>The same pattern played out with endpoint security in the 2000s and 2010s. As malware evolved to bypass detection, the response was behavioral analysis, sandboxing, and endpoint detection and response. Yet more software. Breaches continued until TPM (Trust Platform Module) chips and hardware-enforced secure boot became widely adopted. <a href="https://www.techradar.com/uk/best/best-cloud-storage">Cloud</a> security, in the 2010s and 2020s, followed a similar path.</p><p>A common lesson runs through each of these domains: when the software trust boundary is compromised, the hardware layer – where data actually lives – must be secured too.</p><h2 id="the-case-for-hardware-level-security">The case for hardware-level security</h2><p>This time, we cannot afford to learn slowly. Agents are already being connected to the systems that <a href="https://www.techradar.com/news/best-business-laptops">business</a> rely on for their daily operations. Incidents like the MCP critical vulnerability and recent reports of a data leak caused by a Meta AI agent show how quickly the risks can become real.</p><p>Guardrails, permissions, and monitoring are necessary, but they are insufficient, and they represent the security layers that history shows will eventually be bypassed. Effective defense requires a third layer – one that exists beyond the software trust boundary and provides oversight at the hardware level, where sensitive data is ultimately stored and processed.</p><p>Hardware Root of Trust serves as the final security barrier, helping contain breaches before they escalate into a full system compromise. As the number of companies using AI agents continues to grow, security needs to move deeper than the application layer.</p><p>The industry has already learned that software alone cannot secure complex systems – it should not wait for a major compromise to learn the same lesson again.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ai-agents-are-inside-the-enterprise-are-your-security-foundations-ready-for-them</link>
                                                                            <description>
                            <![CDATA[ How AI agents are exposing the need for hardware-level security foundations. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cv4mtV4XvRUK6YcpZ6GRQL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 10:30:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Camellia Chan ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The recent release of Anthropic Mythos is a wake-up call for the tech industry – and the fact that Anthropic themselves chose not to release it publicly speaks volumes about the level of risk we have now reached. AI agents have evolved from <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">chatbots</a> with upgraded capabilities to effective employees with <a href="https://www.techradar.com/best/best-database-software">database</a> access, API keys, and system privileges.</p><p>However, the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> protecting them is built on the same strategy that failed to stop ChatGPT jailbreaks in 2023. And this time, there’s no human to review an agent’s output, just an autonomous agent carrying out commands in a silo.</p><p>AI agents are reshaping enterprise systems and the way work gets done. Securing them requires an equally fundamental shift in thinking. Ultimately, now that agents act independently, resilience must be rooted in foundational controls, including hardware-level and lower-stack security, to be ready when the higher-level safeguards fail.</p><h2 id="how-ai-agents-expand-the-attack-surface">How AI agents expand the attack surface</h2><p>Before agentic AI, the biggest AI risks were bad recommendations, inappropriate responses, and conversational data exposure. Human oversight acted as a safeguard for every action, and AI systems operated without direct access to sensitive information. The primary concern was reputational damage rather than risks to underlying <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>.</p><p>When Anthropic released the Model Context Protocol (MCP) in November 2024, it established a standardized framework that allows AI agents to connect to databases, file systems, and enterprise tools. But within eight months, a critical vulnerability emerged (CVE-2025-49596, CVSS9.4), triggering emergency security responses across the industry.</p><p>The risk came from four factors working together. Autonomy means agents can decide and act without human review. Privileged access gives them credentials, tokens and file system permissions. Machine-speed execution leaves little time for human intervention. And cross-system reach means one compromised agent can move across connected environments.</p><p>Together, these factors expanded the attack surface far beyond what traditional security controls – even AI-enabled ones – were built to manage.</p><h2 id="why-software-only-defences-keep-falling-short">Why software-only defences keep falling short</h2><p>The industry is moving quickly to secure AI agents, but the response largely mirrors a familiar approach: adding more layers of <a href="https://www.techradar.com/best/best-small-business-software">software</a>. Most companies are focusing on two main layers: input guardrails – implementing more software tools designed to stop malicious instructions from ever reaching AI agents, and permissions and monitoring – limiting what compromised agents can access.</p><p>It’s the same strategy the industry had relied on for decades: deploy quickly, remain agile, and address vulnerabilities as they emerge. Both methods operate inside the software trust boundary.</p><p>But history shows this approach often ends the same way: with the need for hardware-layer protections. In the 1990s and 2000s, network security responded to software exploits by deploying additional software layers. Breaches persisted until organizations eventually adopted hardware-enforced network segmentation.</p><p>The same pattern played out with endpoint security in the 2000s and 2010s. As malware evolved to bypass detection, the response was behavioral analysis, sandboxing, and endpoint detection and response. Yet more software. Breaches continued until TPM (Trust Platform Module) chips and hardware-enforced secure boot became widely adopted. <a href="https://www.techradar.com/uk/best/best-cloud-storage">Cloud</a> security, in the 2010s and 2020s, followed a similar path.</p><p>A common lesson runs through each of these domains: when the software trust boundary is compromised, the hardware layer – where data actually lives – must be secured too.</p><h2 id="the-case-for-hardware-level-security">The case for hardware-level security</h2><p>This time, we cannot afford to learn slowly. Agents are already being connected to the systems that <a href="https://www.techradar.com/news/best-business-laptops">business</a> rely on for their daily operations. Incidents like the MCP critical vulnerability and recent reports of a data leak caused by a Meta AI agent show how quickly the risks can become real.</p><p>Guardrails, permissions, and monitoring are necessary, but they are insufficient, and they represent the security layers that history shows will eventually be bypassed. Effective defense requires a third layer – one that exists beyond the software trust boundary and provides oversight at the hardware level, where sensitive data is ultimately stored and processed.</p><p>Hardware Root of Trust serves as the final security barrier, helping contain breaches before they escalate into a full system compromise. As the number of companies using AI agents continues to grow, security needs to move deeper than the application layer.</p><p>The industry has already learned that software alone cannot secure complex systems – it should not wait for a major compromise to learn the same lesson again.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Beware the token trap: Why saving on inference might put your ADLC at risk ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Agentic AI’s prolific use of tokens can create sizeable, unexpected costs for organizations. But saving on token costs without factoring in risk can be a fatal step.  </p><p>As upfront prices for flagship <a href="https://www.techradar.com/phones/best-ai-phone">artificial intelligence</a> models continue to shrink, organizations have begun to wise up to the hidden costs they encounter with agentic AI models.</p><p>Specifically, the costs of tokens, which may look tiny when viewed as individual charges, can add up exponentially as AI agents become more active, leaving organizations with hefty AI expenditures they may not have anticipated.  </p><p>This is putting CISOs in something of a bind. If they seek to save money on inference costs, primarily driven by token generation incurred by agentic AI, they may increase their security risk and accumulate hidden technical debt that puts their Agentic Development Lifecycle (ADLC) in jeopardy. It’s a problem that many CISOs may not have factored into their security budgets, but it cannot be left unaddressed.</p><p>The effectiveness of automated security processes is being impeded by fragmented pricing across the AI landscape, whether we’re talking about hyper-optimized nano models (essentially lightweight, yet powerful models built for a specific use, like Google’s Nano Banana 2 image generator) or premium reasoning engines, like Salesforce Atlas or OpenAI o3. </p><p>Organizations do have to keep a close eye on token costs to prevent them from spiraling, but CISOs also need to examine how agentic AI is affecting their <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>.</p><h2 id="the-hidden-costs-of-ai-agents">The hidden costs of AI agents</h2><p>Erratic pricing has been a trademark of generative AI pretty much from the beginning.  </p><p>About two years after OpenAI released ChatGPT, the Chinese company DeepSeek shook up the AI market with the release of a powerful, open-weighted large language model whose training parameters were publicly available, allowing users to customize the model and build on the cheap compared with other generative AI models. </p><p>ChatGPT-maker OpenAI and other AI companies started doing the same, and suddenly, the costs of using GenAI systems dropped off a cliff. In fact, prices fell faster for GenAI than for any other technology in history.</p><p>The emergence of agentic AI has introduced some stealth costs into the equation, however. The costs of agentic software range from free for <a href="https://www.techradar.com/best/the-best-open-source-crm-of-year">open-source</a> models to enterprise agents, with prices that vary from one-time fees (roughly $15,000 for basic models to more than $1 million for global enterprise models) to monthly subscriptions (which can range from a few thousand to $13,000 or more).</p><p>But those costs are fixed. Inference costs are another story: they scale with usage and can amount to 90% of AI lifecycle costs. </p><p>Tokens come into play when an AI agent requests processing from GenAI models, which charge agents for processing information. At a glance, the costs may appear inconsequential. Input tokens generally range from 15 cents to $5 per million requests. Output tokens, which require slightly more processing, cost from about 60 cents to $25 per million.</p><p>They may start small, but can add up in no time, thanks to AI agents that work very quickly, autonomously, and unpredictably. They are designed to interact with systems and other agents throughout the enterprise. A single action might generate scores of LLM calls. Token use, which has grown exponentially with the use of AI agents, has already increased IT budgets by about 20% according to recent estimates.</p><p>The accelerating cost of agentic AI is prompting CISOs to look for ways to save money where they can, and one way is to identify <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">LLMs</a> that charge the least per token. But what they may not be considering are the risk factors associated with those LLMs. If CISOs concern themselves only with the costs, they may open themselves up to security risks.</p><p>But better security doesn’t necessarily have to cost more. Depending on what they’re using agentic AI for, they may find they don’t always have to trade security for lower token costs. </p><h2 id="getting-costs-and-risks-under-control">Getting costs (and risks) under control</h2><p>There are a few things organizations can do to help stop token costs from getting out of hand, including:</p><p>Match Agents and LLMs to the Job at Hand. Commodity AI systems can cost little or nothing, but they lack the deep reasoning for complex security synthesis. But not every application or function within the organization requires a reasoning engine. You can set up agents to work with low-cost LLMs on low-risk projects, while preserving higher-cost LLMs for critical tasks. It’s also worth being aware of which agents are likely to request more LLM calls.</p><p>Factor Risk Scores in Choosing Agents and LLMs. The security implications of using AI can’t be ignored. When developing a budget plan, include risk factors.</p><p>Monitor Workflows. Keeping a close watch on workflows can help you track costs and performance, allowing you to better understand which tools work best in which situations.</p><p>Lean on Human Oversight. Despite agentic AI’s autonomy, in fact, because of agentic AI’s autonomy, forgetting about the importance of the human element is risky business. Teams need thorough upskilling in secure development, with clearly defined ownership roles. And they must be given prominent oversight roles throughout the ADLC.</p><p>Agentic AI is fast becoming integral to enterprise operations, and organizations must control its associated costs. But a race to the bottom on token pricing creates hidden technical debt. Instead, CISOs need to weigh security performance when choosing <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> as part of establishing an up-to-date security maturity model and an AI governance policy that emphasizes performance, costs, and risk <a href="https://www.techradar.com/best/it-management-tools">management</a>.</p><p>Only that approach allows agentic AI to be deployed without either breaking the budget or putting your entire organization at risk.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/beware-the-token-trap-why-saving-on-inference-might-put-your-adlc-at-risk</link>
                                                                            <description>
                            <![CDATA[ Saving on token costs without factoring in risk can be a fatal step. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">yV7Rm3gzNFF6xcfugivXJ4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 09:57:27 +0000</pubDate>                                                                                                                                <updated>Fri, 14 Aug 2026 09:57:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Pieter Danhieux ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Agentic AI’s prolific use of tokens can create sizeable, unexpected costs for organizations. But saving on token costs without factoring in risk can be a fatal step.  </p><p>As upfront prices for flagship <a href="https://www.techradar.com/phones/best-ai-phone">artificial intelligence</a> models continue to shrink, organizations have begun to wise up to the hidden costs they encounter with agentic AI models.</p><p>Specifically, the costs of tokens, which may look tiny when viewed as individual charges, can add up exponentially as AI agents become more active, leaving organizations with hefty AI expenditures they may not have anticipated.  </p><p>This is putting CISOs in something of a bind. If they seek to save money on inference costs, primarily driven by token generation incurred by agentic AI, they may increase their security risk and accumulate hidden technical debt that puts their Agentic Development Lifecycle (ADLC) in jeopardy. It’s a problem that many CISOs may not have factored into their security budgets, but it cannot be left unaddressed.</p><p>The effectiveness of automated security processes is being impeded by fragmented pricing across the AI landscape, whether we’re talking about hyper-optimized nano models (essentially lightweight, yet powerful models built for a specific use, like Google’s Nano Banana 2 image generator) or premium reasoning engines, like Salesforce Atlas or OpenAI o3. </p><p>Organizations do have to keep a close eye on token costs to prevent them from spiraling, but CISOs also need to examine how agentic AI is affecting their <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>.</p><h2 id="the-hidden-costs-of-ai-agents">The hidden costs of AI agents</h2><p>Erratic pricing has been a trademark of generative AI pretty much from the beginning.  </p><p>About two years after OpenAI released ChatGPT, the Chinese company DeepSeek shook up the AI market with the release of a powerful, open-weighted large language model whose training parameters were publicly available, allowing users to customize the model and build on the cheap compared with other generative AI models. </p><p>ChatGPT-maker OpenAI and other AI companies started doing the same, and suddenly, the costs of using GenAI systems dropped off a cliff. In fact, prices fell faster for GenAI than for any other technology in history.</p><p>The emergence of agentic AI has introduced some stealth costs into the equation, however. The costs of agentic software range from free for <a href="https://www.techradar.com/best/the-best-open-source-crm-of-year">open-source</a> models to enterprise agents, with prices that vary from one-time fees (roughly $15,000 for basic models to more than $1 million for global enterprise models) to monthly subscriptions (which can range from a few thousand to $13,000 or more).</p><p>But those costs are fixed. Inference costs are another story: they scale with usage and can amount to 90% of AI lifecycle costs. </p><p>Tokens come into play when an AI agent requests processing from GenAI models, which charge agents for processing information. At a glance, the costs may appear inconsequential. Input tokens generally range from 15 cents to $5 per million requests. Output tokens, which require slightly more processing, cost from about 60 cents to $25 per million.</p><p>They may start small, but can add up in no time, thanks to AI agents that work very quickly, autonomously, and unpredictably. They are designed to interact with systems and other agents throughout the enterprise. A single action might generate scores of LLM calls. Token use, which has grown exponentially with the use of AI agents, has already increased IT budgets by about 20% according to recent estimates.</p><p>The accelerating cost of agentic AI is prompting CISOs to look for ways to save money where they can, and one way is to identify <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">LLMs</a> that charge the least per token. But what they may not be considering are the risk factors associated with those LLMs. If CISOs concern themselves only with the costs, they may open themselves up to security risks.</p><p>But better security doesn’t necessarily have to cost more. Depending on what they’re using agentic AI for, they may find they don’t always have to trade security for lower token costs. </p><h2 id="getting-costs-and-risks-under-control">Getting costs (and risks) under control</h2><p>There are a few things organizations can do to help stop token costs from getting out of hand, including:</p><p>Match Agents and LLMs to the Job at Hand. Commodity AI systems can cost little or nothing, but they lack the deep reasoning for complex security synthesis. But not every application or function within the organization requires a reasoning engine. You can set up agents to work with low-cost LLMs on low-risk projects, while preserving higher-cost LLMs for critical tasks. It’s also worth being aware of which agents are likely to request more LLM calls.</p><p>Factor Risk Scores in Choosing Agents and LLMs. The security implications of using AI can’t be ignored. When developing a budget plan, include risk factors.</p><p>Monitor Workflows. Keeping a close watch on workflows can help you track costs and performance, allowing you to better understand which tools work best in which situations.</p><p>Lean on Human Oversight. Despite agentic AI’s autonomy, in fact, because of agentic AI’s autonomy, forgetting about the importance of the human element is risky business. Teams need thorough upskilling in secure development, with clearly defined ownership roles. And they must be given prominent oversight roles throughout the ADLC.</p><p>Agentic AI is fast becoming integral to enterprise operations, and organizations must control its associated costs. But a race to the bottom on token pricing creates hidden technical debt. Instead, CISOs need to weigh security performance when choosing <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> as part of establishing an up-to-date security maturity model and an AI governance policy that emphasizes performance, costs, and risk <a href="https://www.techradar.com/best/it-management-tools">management</a>.</p><p>Only that approach allows agentic AI to be deployed without either breaking the budget or putting your entire organization at risk.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ World-first autonomous ‘end-to-end’ AI attack against Taiwan tied to Chinese hackers — and the scariest part is that it was fully open source ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>China launched a fully autonomous vulnerability hunting attack against Taiwan</strong></li><li><strong>The attack leveraged eight open-source AI models to hunt for new attack vectors</strong></li><li><strong>The attack hit Taiwan government accounts, personnel records, the nuclear safety agency, and more</strong></li></ul><p>A first-of-its-kind cyberattack using autonomous AI has been spotted attacking Taiwan, and it compromised 85 government accounts and stole over 2,500 personnel records before moving on to hit the country’s nuclear safety agency and at least seven energy companies.</p><p>The attack used eight open-source AI models to build a hacking program that was able to independently conduct reconnaissance and intrusion, and was able to chain vulnerabilities and change tactics whenever it was blocked.</p><p>The intrusion took place over the course of four days, and was first exposed by <a href="https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795?syn-25a6b1a6=1" target="_blank" rel="nofollow"><em>The Financial Times</em></a> on August 12, 2026. The FT article covered research performed by Dream, an Israeli AI and cyberdefense company that first identified the breach.</p><h2 id="autonomous-ai-attack">Autonomous AI attack</h2><p>The attack was first uncovered during routine monitoring of cyber criminal activity. Dream found a 160MB online archive of 1,395 files. Further examination of the files revealed that the attack relied on Hermes and OpenClaw - two open-source AI agents.</p><p>As is typical of attacks relying on AI models, the hackers had framed the context of the intrusion as a routine cyber readiness test in order to bypass the built-in guardrails of the AI models.</p><p>The attack used multiple agents to hunt for new vulnerabilities and access points across the internet, providing the tool with multiple attack paths to take if one failed to gain entry.</p><p>AI agents have been quickly integrated into the attacks of cybercriminal organizations and state-sponsored threat actors alike, enhancing their abilities to launch highly complex attacks at scale. “This must be the basic assumption of every government around the globe,” said Amir Becker, Dream's chief strategy officer.</p><p>Dream did not tie the attack to any specific cybercriminal group, nor did it confirm the target of the attack, but said it had alerted a government in the “Asia-Pacific.” Documentation within the recovered archive contained Simplified Chinese, which is the official written language used in mainland China. </p><p>The archive also contained data collected from the targets, which was written in Traditional Chinese. This form of written Chinese is widely used in Taiwan, Hong Kong, and Macau.</p><p>Taiwan's Ministry of Digital Affairs has refused to comment on the breach, and the Chinese authorities have not responded to requests for comment.</p><p>China has long considered Taiwan to be a part of mainland China. Taiwan declared its independence following the end of the Chinese Civil War in 1949. A report from Taiwan’s National Security Bureau earlier this year revealed that the country was subject to <a href="https://www.techradar.com/pro/security/taiwanese-infrastructure-suffered-over-2-5-million-chinese-cyberattacks-per-day-in-2025-report-reveals">2.5 million Chinese cyberattacks per day in 2025</a>.</p><h2 id="expert-perspective-on-autonomous-ai-attack">Expert perspective on autonomous AI attack</h2><p><strong>Collin Hogue-Spears, senior director of solution management at Black Duck:</strong></p><p><em>The agents ran the intrusion end to end and invented nothing new to run it with. Familiar identity and API failures opened every confirmed path into Taiwan's systems. Dream Research Labs documented up to eight subagents working concurrently across twelve waves, ranking attack paths, redirecting when a technique failed, and researching alternatives online before trying again.</em></p><p><em>What they found was exposed development endpoints, an API accepting authentication tokens with the signature check disabled, unauthenticated data APIs, and passwords built from employee ID numbers.</em></p><p><em>The framework also ran its own AI static analysis hunting unknown flaws, but Dream says it worked against two public single sign-on SDK sample projects, and none of those findings produced a confirmed exploit on the live systems. No zero-day appears anywhere in the report, but a nuclear safety regulator does.</em></p><p><em>In conventional web and identity logs, this reads as a security scan. The distinguishing signal is the sequence across systems, not any single request. The tell is not the request. It is what the same account does next, somewhere else.</em></p><p><em>Conventional scanners have tested thousands of endpoints at machine speed for twenty years, so raw coverage is not the change here. What Dream Research Labs describes is chaining: password spraying, then fresh SSO sessions, then access to routes an account had never touched, then the same suspected weakness retested until it held, then one identity surfacing across several connected applications.</em></p><div><blockquote><p>The evidence therefore supports a Chinese Mainland-language operator against a Taiwanese target, with a target profile consistent with mainland collection priorities.</p></blockquote></div><p><em>Simplified Chinese in the operator's notes is one signal. Traditional Chinese in the stolen files is just Taiwan. Dream rested its China assessment on a code-switching observation, and only half of it points at the attacker. Per Chinese-language coverage of the report, Simplified characters appeared in the operators' internal communications and Traditional characters appeared in the exfiltrated data. The first describes the operator's working language. The second describes the victim, because that is what Taiwanese government files look like [Traditional Characters].</em></p><p><em>The evidence therefore supports a Chinese Mainland-language operator against a Taiwanese target, with a target profile consistent with mainland collection priorities. It does not name a group or establish state direction. The report also publishes no indicators, no hashes, and no victim confirmation; it does not identify the model, and its executive summary claims installed backdoors while its own attack chain says authentication blocked the web shell.</em></p><p><em>Security leaders must reject unsigned authentication tokens and prohibit the alg:none setting outright, and separately require reauthentication or multi-factor at any single sign-on boundary into a sensitive system. Dream describes two independent identity failures in Taiwan, and closing one leaves the other open. Provider guardrails cannot compensate for a password-only SSO bridge.</em></p><p><em>They must also monitor route diversity per source, per session, per account, and per device rather than by request rate alone, because a distributed set of agents spreads requests across addresses and sessions that no single volume threshold catches. If your detection assumes one attacker at one address working one path at a time, you have modeled the wrong shape.</em></p><p><em>Your thresholds were built for one attacker on one path. This was eight, in parallel. And they must ask two questions of any AI attack disclosure before acting on it: which model ran the operation, and what can we hunt on tomorrow morning?"</em></p><p>Via <a href="https://united24media.com/world/researchers-say-china-likely-linked-to-unprecedented-autonomous-ai-attack-on-taiwan-21623" target="_blank" rel="nofollow"><em>United24</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/world-first-autonomous-end-to-end-ai-attack-against-taiwan-tied-to-chinese-hackers-and-the-scariest-part-is-that-it-was-fully-open-source</link>
                                                                            <description>
                            <![CDATA[ China implicated in Taiwan attack through written documentation recovered from the attack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HxPDT8x5CyBeVeFNd79h3E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 21:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:description>                                                            <media:text><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:text>
                                <media:title type="plain"><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>China launched a fully autonomous vulnerability hunting attack against Taiwan</strong></li><li><strong>The attack leveraged eight open-source AI models to hunt for new attack vectors</strong></li><li><strong>The attack hit Taiwan government accounts, personnel records, the nuclear safety agency, and more</strong></li></ul><p>A first-of-its-kind cyberattack using autonomous AI has been spotted attacking Taiwan, and it compromised 85 government accounts and stole over 2,500 personnel records before moving on to hit the country’s nuclear safety agency and at least seven energy companies.</p><p>The attack used eight open-source AI models to build a hacking program that was able to independently conduct reconnaissance and intrusion, and was able to chain vulnerabilities and change tactics whenever it was blocked.</p><p>The intrusion took place over the course of four days, and was first exposed by <a href="https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795?syn-25a6b1a6=1" target="_blank" rel="nofollow"><em>The Financial Times</em></a> on August 12, 2026. The FT article covered research performed by Dream, an Israeli AI and cyberdefense company that first identified the breach.</p><h2 id="autonomous-ai-attack">Autonomous AI attack</h2><p>The attack was first uncovered during routine monitoring of cyber criminal activity. Dream found a 160MB online archive of 1,395 files. Further examination of the files revealed that the attack relied on Hermes and OpenClaw - two open-source AI agents.</p><p>As is typical of attacks relying on AI models, the hackers had framed the context of the intrusion as a routine cyber readiness test in order to bypass the built-in guardrails of the AI models.</p><p>The attack used multiple agents to hunt for new vulnerabilities and access points across the internet, providing the tool with multiple attack paths to take if one failed to gain entry.</p><p>AI agents have been quickly integrated into the attacks of cybercriminal organizations and state-sponsored threat actors alike, enhancing their abilities to launch highly complex attacks at scale. “This must be the basic assumption of every government around the globe,” said Amir Becker, Dream's chief strategy officer.</p><p>Dream did not tie the attack to any specific cybercriminal group, nor did it confirm the target of the attack, but said it had alerted a government in the “Asia-Pacific.” Documentation within the recovered archive contained Simplified Chinese, which is the official written language used in mainland China. </p><p>The archive also contained data collected from the targets, which was written in Traditional Chinese. This form of written Chinese is widely used in Taiwan, Hong Kong, and Macau.</p><p>Taiwan's Ministry of Digital Affairs has refused to comment on the breach, and the Chinese authorities have not responded to requests for comment.</p><p>China has long considered Taiwan to be a part of mainland China. Taiwan declared its independence following the end of the Chinese Civil War in 1949. A report from Taiwan’s National Security Bureau earlier this year revealed that the country was subject to <a href="https://www.techradar.com/pro/security/taiwanese-infrastructure-suffered-over-2-5-million-chinese-cyberattacks-per-day-in-2025-report-reveals">2.5 million Chinese cyberattacks per day in 2025</a>.</p><h2 id="expert-perspective-on-autonomous-ai-attack">Expert perspective on autonomous AI attack</h2><p><strong>Collin Hogue-Spears, senior director of solution management at Black Duck:</strong></p><p><em>The agents ran the intrusion end to end and invented nothing new to run it with. Familiar identity and API failures opened every confirmed path into Taiwan's systems. Dream Research Labs documented up to eight subagents working concurrently across twelve waves, ranking attack paths, redirecting when a technique failed, and researching alternatives online before trying again.</em></p><p><em>What they found was exposed development endpoints, an API accepting authentication tokens with the signature check disabled, unauthenticated data APIs, and passwords built from employee ID numbers.</em></p><p><em>The framework also ran its own AI static analysis hunting unknown flaws, but Dream says it worked against two public single sign-on SDK sample projects, and none of those findings produced a confirmed exploit on the live systems. No zero-day appears anywhere in the report, but a nuclear safety regulator does.</em></p><p><em>In conventional web and identity logs, this reads as a security scan. The distinguishing signal is the sequence across systems, not any single request. The tell is not the request. It is what the same account does next, somewhere else.</em></p><p><em>Conventional scanners have tested thousands of endpoints at machine speed for twenty years, so raw coverage is not the change here. What Dream Research Labs describes is chaining: password spraying, then fresh SSO sessions, then access to routes an account had never touched, then the same suspected weakness retested until it held, then one identity surfacing across several connected applications.</em></p><div><blockquote><p>The evidence therefore supports a Chinese Mainland-language operator against a Taiwanese target, with a target profile consistent with mainland collection priorities.</p></blockquote></div><p><em>Simplified Chinese in the operator's notes is one signal. Traditional Chinese in the stolen files is just Taiwan. Dream rested its China assessment on a code-switching observation, and only half of it points at the attacker. Per Chinese-language coverage of the report, Simplified characters appeared in the operators' internal communications and Traditional characters appeared in the exfiltrated data. The first describes the operator's working language. The second describes the victim, because that is what Taiwanese government files look like [Traditional Characters].</em></p><p><em>The evidence therefore supports a Chinese Mainland-language operator against a Taiwanese target, with a target profile consistent with mainland collection priorities. It does not name a group or establish state direction. The report also publishes no indicators, no hashes, and no victim confirmation; it does not identify the model, and its executive summary claims installed backdoors while its own attack chain says authentication blocked the web shell.</em></p><p><em>Security leaders must reject unsigned authentication tokens and prohibit the alg:none setting outright, and separately require reauthentication or multi-factor at any single sign-on boundary into a sensitive system. Dream describes two independent identity failures in Taiwan, and closing one leaves the other open. Provider guardrails cannot compensate for a password-only SSO bridge.</em></p><p><em>They must also monitor route diversity per source, per session, per account, and per device rather than by request rate alone, because a distributed set of agents spreads requests across addresses and sessions that no single volume threshold catches. If your detection assumes one attacker at one address working one path at a time, you have modeled the wrong shape.</em></p><p><em>Your thresholds were built for one attacker on one path. This was eight, in parallel. And they must ask two questions of any AI attack disclosure before acting on it: which model ran the operation, and what can we hunt on tomorrow morning?"</em></p><p>Via <a href="https://united24media.com/world/researchers-say-china-likely-linked-to-unprecedented-autonomous-ai-attack-on-taiwan-21623" target="_blank" rel="nofollow"><em>United24</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft's nemesis returns: Nightmare Eclipse is back with a new zero day which could be bad news for Windows users ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Nightmare Eclipse discloses ShieldBreak, a new Windows privilege‑escalation zero‑day</strong></li><li><strong>Flaw bypasses a recent patch and works on fully updated Windows 11 systems</strong></li><li><strong>Researcher’s ongoing exploit spree leaves multiple Windows vulnerabilities still unpatched</strong></li></ul><p>Nightmare Eclipse has struck again! The notorious zero-day researcher with a Microsoft grudge disclosed its latest vulnerability, and just as in previous instances, they picked their timing and released their research hours after Microsoft published its August Patch Tuesday cumulative update in order to maximize the hurt.</p><p>The newest flaw is called ShieldBreak, and is described as a local escalation of privilege vulnerability that allows threat actors to gain SYSTEM-level privileges on vulnerable systems. Speaking of vulnerable systems, the list is rather long because it includes all versions of Windows 11, including those with the latest security patches. </p><p>“The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate,” Nightmare Eclipse <a href="https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak/src/branch/main/ShieldBreak.cpp" target="_blank" rel="nofollow">said</a> on their GitHub account. “Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.”</p><h2 id="a-bypass-for-the-rogueplanet-fix">A bypass for the RoguePlanet fix</h2><p>The mysterious attacker also said that the bug was actually a bypass for the patch Microsoft issued to fix their earlier work, called RoguePlanet.</p><p>“Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass,” the GitHub read entry.</p><p>Microsoft, on the other hand, responded in pure enterprise fashion, sharing a boilerplate statement that it was “investigating” and that it “supports coordinated <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">vulnerability</a> disclosure”. </p><p>In response to an enquiry by <a href="https://www.theregister.com/cyber-crime/2026/08/12/microsoft-vendetta-hacker-has-a-new-zero-day-that-gives-system-privileges-on-fully-patched-windows/5286889" target="_blank"><em>The Register</em></a>, a company spokesperson said Microsoft "is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims."</p><p>"Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible,” the statement reads. “Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public."</p><h2 id="a-hacker-on-a-mission">A hacker on a mission</h2><p>Together with ShieldBreak, the number of disclosed Windows vulnerabilities and exploits now counts 10. Nightmare Eclipse’s campaign began in April 2026, when they demonstrated BlueHammer, a Windows Defender local privilege-escalation flaw that gives low-privileged users SYSTEM-level access. The researcher claimed BlueHammer, now tracked as CVE-2026-33825, was previously reported to Microsoft, but the company allegedly mishandled the disclosure. </p><p>Just before publishing the work, they <a href="https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/" target="_blank" rel="nofollow">said</a> “someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.”</p><p>At first, Microsoft took a tough stance, calling the public release “<a href="https://therecord.media/microsoft-says-it-will-not-pursue-security-researchers-disclosure" target="_blank">never justifiable</a>” and even warning that it might pursue legal cases against people who put customers at risk.</p><p>The community interpreted this statement as a threat of legal action against Nightmare Eclipse, which triggered a backlash. Microsoft later backed away, saying “to be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research.”</p><p>In the meantime, Nightmare Eclipse (also known as Chaotic Eclipse) went on a full-blown rampage. They released RedSun and UnDefend (both targeting Defender), YellowKey (a BitLocker bypass), GreenPlasma (a CTFMON-based privilege-escalation flaw), MiniPlasma (a regression of a vulnerability Microsoft had originally fixed in 2020), RoguePlanet (another Defender privilege-escalation bug), GreatXML (a BitLocker/Windows Recovery Environment bypass), LegacyHive (a Windows User Profile Service privilege-escalation flaw), and now ShieldBreak. </p><p>BlueHammer was fixed in April, RedSun and UnDefend in May, and YellowKey, GreenPlasma, and MiniPlasma, in June. RoguePlanet was patched in July, while LegacyHive, GreatXML, and ShieldBreak, remain unpatched. </p><p>It is also worth mentioning that not all of Nightmare Eclipse’s releases were equally complete or reproducible by third parties. For GreenPlasma, independent researchers said it contained the vulnerability but turning it into a reliable working exploit required significant additional technical work. Some of the early Defender exploits were also apparently difficult to reproduce, mostly because they relied on delicate race conditions and very specific sequences of Windows components. </p><p>ShieldBreak, however, seems to be more dangerous in that respect. Speaking to <em>The Register</em>, security researcher Kevin Beaumont confirmed it as working: “I've tried it, it works on latest Windows 11,” he told the publication. </p><p>He also said that while ShieldBreak was described as a bypass for the RoguePlanet fix, the two flaws actually operated quite differently. </p><p>“RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files,” Beaumont explained. “ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API).”</p><p>No one knows how much ammunition Nightmare Eclipse still has, but we will certainly be paying attention to them in the hours after next month’s Patch Tuesday, as well. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsofts-nemesis-returns-nightmare-eclipse-is-back-with-a-new-zero-day-which-could-be-bad-news-for-windows-users</link>
                                                                            <description>
                            <![CDATA[ This is the tenth zero-day the disgruntled researcher disclosed, and yet another released soon after a Patch Tuesday. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Y9Ed8CXdbTCPjPE5PcQuC6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 16:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Är du ute efter bästa VPN för Windows 10 och Windwos 11? Här är våra favoriter just nu.]]></media:description>                                                            <media:text><![CDATA[Fingertip pressing keyboard key with Windows logo on it]]></media:text>
                                <media:title type="plain"><![CDATA[Fingertip pressing keyboard key with Windows logo on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Nightmare Eclipse discloses ShieldBreak, a new Windows privilege‑escalation zero‑day</strong></li><li><strong>Flaw bypasses a recent patch and works on fully updated Windows 11 systems</strong></li><li><strong>Researcher’s ongoing exploit spree leaves multiple Windows vulnerabilities still unpatched</strong></li></ul><p>Nightmare Eclipse has struck again! The notorious zero-day researcher with a Microsoft grudge disclosed its latest vulnerability, and just as in previous instances, they picked their timing and released their research hours after Microsoft published its August Patch Tuesday cumulative update in order to maximize the hurt.</p><p>The newest flaw is called ShieldBreak, and is described as a local escalation of privilege vulnerability that allows threat actors to gain SYSTEM-level privileges on vulnerable systems. Speaking of vulnerable systems, the list is rather long because it includes all versions of Windows 11, including those with the latest security patches. </p><p>“The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate,” Nightmare Eclipse <a href="https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak/src/branch/main/ShieldBreak.cpp" target="_blank" rel="nofollow">said</a> on their GitHub account. “Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.”</p><h2 id="a-bypass-for-the-rogueplanet-fix">A bypass for the RoguePlanet fix</h2><p>The mysterious attacker also said that the bug was actually a bypass for the patch Microsoft issued to fix their earlier work, called RoguePlanet.</p><p>“Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass,” the GitHub read entry.</p><p>Microsoft, on the other hand, responded in pure enterprise fashion, sharing a boilerplate statement that it was “investigating” and that it “supports coordinated <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">vulnerability</a> disclosure”. </p><p>In response to an enquiry by <a href="https://www.theregister.com/cyber-crime/2026/08/12/microsoft-vendetta-hacker-has-a-new-zero-day-that-gives-system-privileges-on-fully-patched-windows/5286889" target="_blank"><em>The Register</em></a>, a company spokesperson said Microsoft "is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims."</p><p>"Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible,” the statement reads. “Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public."</p><h2 id="a-hacker-on-a-mission">A hacker on a mission</h2><p>Together with ShieldBreak, the number of disclosed Windows vulnerabilities and exploits now counts 10. Nightmare Eclipse’s campaign began in April 2026, when they demonstrated BlueHammer, a Windows Defender local privilege-escalation flaw that gives low-privileged users SYSTEM-level access. The researcher claimed BlueHammer, now tracked as CVE-2026-33825, was previously reported to Microsoft, but the company allegedly mishandled the disclosure. </p><p>Just before publishing the work, they <a href="https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/" target="_blank" rel="nofollow">said</a> “someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.”</p><p>At first, Microsoft took a tough stance, calling the public release “<a href="https://therecord.media/microsoft-says-it-will-not-pursue-security-researchers-disclosure" target="_blank">never justifiable</a>” and even warning that it might pursue legal cases against people who put customers at risk.</p><p>The community interpreted this statement as a threat of legal action against Nightmare Eclipse, which triggered a backlash. Microsoft later backed away, saying “to be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research.”</p><p>In the meantime, Nightmare Eclipse (also known as Chaotic Eclipse) went on a full-blown rampage. They released RedSun and UnDefend (both targeting Defender), YellowKey (a BitLocker bypass), GreenPlasma (a CTFMON-based privilege-escalation flaw), MiniPlasma (a regression of a vulnerability Microsoft had originally fixed in 2020), RoguePlanet (another Defender privilege-escalation bug), GreatXML (a BitLocker/Windows Recovery Environment bypass), LegacyHive (a Windows User Profile Service privilege-escalation flaw), and now ShieldBreak. </p><p>BlueHammer was fixed in April, RedSun and UnDefend in May, and YellowKey, GreenPlasma, and MiniPlasma, in June. RoguePlanet was patched in July, while LegacyHive, GreatXML, and ShieldBreak, remain unpatched. </p><p>It is also worth mentioning that not all of Nightmare Eclipse’s releases were equally complete or reproducible by third parties. For GreenPlasma, independent researchers said it contained the vulnerability but turning it into a reliable working exploit required significant additional technical work. Some of the early Defender exploits were also apparently difficult to reproduce, mostly because they relied on delicate race conditions and very specific sequences of Windows components. </p><p>ShieldBreak, however, seems to be more dangerous in that respect. Speaking to <em>The Register</em>, security researcher Kevin Beaumont confirmed it as working: “I've tried it, it works on latest Windows 11,” he told the publication. </p><p>He also said that while ShieldBreak was described as a bypass for the RoguePlanet fix, the two flaws actually operated quite differently. </p><p>“RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files,” Beaumont explained. “ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API).”</p><p>No one knows how much ammunition Nightmare Eclipse still has, but we will certainly be paying attention to them in the hours after next month’s Patch Tuesday, as well. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Android users targeted by new WindRelay malware which can clone contactless cards in just 13 minutes ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>WindRelay campaign used vishing plus custom malware to turn phones into POS skimmers</strong></li><li><strong>Victims installed personalized RATs and NFC malware, enabling real‑time card theft</strong></li><li><strong>Attacks were highly targeted across Eastern Europe, with only a few individuals hit</strong></li></ul><p>Hackers are turning people’s smartphones into malicious <a href="https://www.techradar.com/news/the-best-pos-system" target="_blank">Point of Sale</a> (POS) devices and stealing their money directly from their payment cards, experts have warned. </p><p>Security researchers Group-IB spotted multiple such attacks across Eastern Europe, and named the campaign <a href="https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/" target="_blank">WindRelay</a>, after the custom-built malware used during the attacks.</p><p>The report notes this is a highly sophisticated, custom-tailored attack designed specifically for the victim. It starts with some form of reconnaissance, in which the attackers learn their victim’s identity, phone number, and likely other details. Although the researchers don’t discuss it, it is quite possible that the attackers obtained (or purchased) the data from unrelated data breaches and leaks.</p><h2 id="vishing-and-malware">Vishing and malware</h2><p>After learning a little bit about their target, the attackers get to work. They first prepare a remote access trojan (RAT) named SpyNote. They personalize the label with the victim’s own name (instead of it being a generic or impersonated brand), to build trust with their victim:</p><p>“Such tactics are more effective at weakening a victim’s natural defenses and suspicions,” the researchers noted in the report. “It removes the one cue people are trained to check before installing something unfamiliar — a strange or generic app name — right at the moment they’re most likely to hesitate.”</p><p>Then, they call the victim on the phone and introduce themselves as employees of their target’s bank. They claim the victim has a problem with their bank card, and instruct them to deploy SpyNote through the device’s package installer (the standard way to sideload apps outside an official app store).</p><p>SpyNote is a classic RAT that the attackers then use to deploy stage-two malware themselves. In this next step, they personally (as opposed to having the victim do it) install WindRelay, custom near-field communication (NFC) malware designed to capture contactless payment card data in real-time, when a card is tapped against the phone. </p><p>In other words, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> turns the smartphone into a POS, and when a victim taps their card against it, the information is relayed to an attacker’s terminal. </p><h2 id="vishing-malware">Vishing + malware</h2><p>Vishing + malware combo is nothing new. We’ve seen it deployed numerous times before, and ShinyHunters are probably the shiniest example of the practice (pun definitely intended). Over the last couple of years, ShinyHunters have been calling their victims on the phone, impersonating the IT department, and getting their victims to log in via fake login portals which relay the credentials to the attackers.</p><p>They then use the credentials to access their victims’ SaaS products, exfiltrate as much sensitive data as possible, and then demand ransom in exchange for deleting the stolen files.</p><p>This new campaign, however, is a testament to the technique’s evolution. While ShinyHunters’ operatives only stay on the phone call until the victim logs in, these crooks remain on the line for as long as it takes. Group-IB says the average call lasts around 13 minutes, and by that moment, the victim will have installed both SpyNote and WindRelay, and has tapped their bank card against the phone, making unwanted payments.</p><p>In at least one case, the attackers successfully applied for a loan at the victim’s bank, stealing not only the money they had on their account, but also money they would have earned in the future.</p><p>The identity of the attackers is unknown at the time. We also don’t know exactly how many victims there were, but given the highly personalized nature of the attack, it’s safe to assume that there were only a handful.</p><p>Group-IB says it observed attacks in Czechia, Slovakia, and Slovenia, suggesting a threat actor focused primarily on Eastern European victims. The researchers also said they identified 23 samples uploaded to VirusTotal between November 2025 and July 2026, meaning the campaign was active for approximately seven months, targeting 23 individuals. </p><p>“The samples mimic various institutions from the targeted countries and contain text in the language of each targeted country,” the researchers said. “Some samples contain personalized UI elements and labels, such as the name of the victim, similar to the personalized RAT. This suggests the threat actor behind these campaigns most likely has the capability to dynamically build malicious applications tailored to individual victims.”</p><p>Group-IB says users should treat personalized app labels as a red flag and should apply extra friction to loan applications. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/android-users-targeted-by-new-windrelay-malware-which-can-clone-contactless-cards-in-just-13-minutes</link>
                                                                            <description>
                            <![CDATA[ Crooks are calling victims on the phone and installing POS malware on their smartphones. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">shwHxntyNEjscciJEjL9Li</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5kMrDAjQJGcdHytVASFjn5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 15:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5kMrDAjQJGcdHytVASFjn5-1280-80.jpg">
                                                            <media:credit><![CDATA[Rapeepong Puttakumwong via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Person pays using POS hardware card reader]]></media:description>                                                            <media:text><![CDATA[Person pays using POS hardware card reader]]></media:text>
                                <media:title type="plain"><![CDATA[Person pays using POS hardware card reader]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5kMrDAjQJGcdHytVASFjn5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>WindRelay campaign used vishing plus custom malware to turn phones into POS skimmers</strong></li><li><strong>Victims installed personalized RATs and NFC malware, enabling real‑time card theft</strong></li><li><strong>Attacks were highly targeted across Eastern Europe, with only a few individuals hit</strong></li></ul><p>Hackers are turning people’s smartphones into malicious <a href="https://www.techradar.com/news/the-best-pos-system" target="_blank">Point of Sale</a> (POS) devices and stealing their money directly from their payment cards, experts have warned. </p><p>Security researchers Group-IB spotted multiple such attacks across Eastern Europe, and named the campaign <a href="https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/" target="_blank">WindRelay</a>, after the custom-built malware used during the attacks.</p><p>The report notes this is a highly sophisticated, custom-tailored attack designed specifically for the victim. It starts with some form of reconnaissance, in which the attackers learn their victim’s identity, phone number, and likely other details. Although the researchers don’t discuss it, it is quite possible that the attackers obtained (or purchased) the data from unrelated data breaches and leaks.</p><h2 id="vishing-and-malware">Vishing and malware</h2><p>After learning a little bit about their target, the attackers get to work. They first prepare a remote access trojan (RAT) named SpyNote. They personalize the label with the victim’s own name (instead of it being a generic or impersonated brand), to build trust with their victim:</p><p>“Such tactics are more effective at weakening a victim’s natural defenses and suspicions,” the researchers noted in the report. “It removes the one cue people are trained to check before installing something unfamiliar — a strange or generic app name — right at the moment they’re most likely to hesitate.”</p><p>Then, they call the victim on the phone and introduce themselves as employees of their target’s bank. They claim the victim has a problem with their bank card, and instruct them to deploy SpyNote through the device’s package installer (the standard way to sideload apps outside an official app store).</p><p>SpyNote is a classic RAT that the attackers then use to deploy stage-two malware themselves. In this next step, they personally (as opposed to having the victim do it) install WindRelay, custom near-field communication (NFC) malware designed to capture contactless payment card data in real-time, when a card is tapped against the phone. </p><p>In other words, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> turns the smartphone into a POS, and when a victim taps their card against it, the information is relayed to an attacker’s terminal. </p><h2 id="vishing-malware">Vishing + malware</h2><p>Vishing + malware combo is nothing new. We’ve seen it deployed numerous times before, and ShinyHunters are probably the shiniest example of the practice (pun definitely intended). Over the last couple of years, ShinyHunters have been calling their victims on the phone, impersonating the IT department, and getting their victims to log in via fake login portals which relay the credentials to the attackers.</p><p>They then use the credentials to access their victims’ SaaS products, exfiltrate as much sensitive data as possible, and then demand ransom in exchange for deleting the stolen files.</p><p>This new campaign, however, is a testament to the technique’s evolution. While ShinyHunters’ operatives only stay on the phone call until the victim logs in, these crooks remain on the line for as long as it takes. Group-IB says the average call lasts around 13 minutes, and by that moment, the victim will have installed both SpyNote and WindRelay, and has tapped their bank card against the phone, making unwanted payments.</p><p>In at least one case, the attackers successfully applied for a loan at the victim’s bank, stealing not only the money they had on their account, but also money they would have earned in the future.</p><p>The identity of the attackers is unknown at the time. We also don’t know exactly how many victims there were, but given the highly personalized nature of the attack, it’s safe to assume that there were only a handful.</p><p>Group-IB says it observed attacks in Czechia, Slovakia, and Slovenia, suggesting a threat actor focused primarily on Eastern European victims. The researchers also said they identified 23 samples uploaded to VirusTotal between November 2025 and July 2026, meaning the campaign was active for approximately seven months, targeting 23 individuals. </p><p>“The samples mimic various institutions from the targeted countries and contain text in the language of each targeted country,” the researchers said. “Some samples contain personalized UI elements and labels, such as the name of the victim, similar to the personalized RAT. This suggests the threat actor behind these campaigns most likely has the capability to dynamically build malicious applications tailored to individual victims.”</p><p>Group-IB says users should treat personalized app labels as a red flag and should apply extra friction to loan applications. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Bad news: your AI application isn't that special ]]></title>
                                                                                                <dc:content><![CDATA[ <p>There are more than 70,000 <a href="https://www.techradar.com/best/best-ai-tools">AI</a> companies operating today. </p><p>Most of them will not exist in five years. </p><p>Before you can see why — or figure out whether yours is one of them — you need a distinction the market keeps blurring.</p><p>Strip away the pitch decks and there are really only two types of AI system being built today.</p><p>The first is AI infrastructure: the orchestration and governance technology that makes AI usable at scale. In plain terms, this is the plumbing — agent frameworks, model routing, evaluation and monitoring tools, guardrails, and the controls that let a large organization use AI safely. </p><p>It sits between the foundation models and the end user, and it is where an enormous amount of venture money is going right now.</p><p>The second is the surface application: the tool an actual person uses to do actual work. The underwriting assistant, the contract reviewer, the sales copilot. The thing with a login screen and a job to do.</p><p>What I see in the market is a blending of the two. Some firms are selling <a href="https://www.techradar.com/best/best-architecture-software">architecture</a>. </p><p>Some are selling tools. Many are trying to sell both, on the theory that owning the whole stack is the safest position. </p><p>And while this market is filled with tremendous exuberance with seemingly everyone starting an AI company, I am very skeptical that many of these firms will ever see profitability as history offers a strong counter. </p><p>We've run this experiment twice.</p><h2 id="the-past-and-the-future">The past and the future</h2><p>The dot-com era ran the first version of this experiment, and its final tally is worth stating plainly. Researchers estimate that roughly 50,000 <a href="https://www.techradar.com/best/the-best-crm-for-startups">startups</a> were founded in the United States between 1998 and 2002 to commercialize the internet. </p><p>Of those, something like 8,000 attracted venture funding. About 1,700 internet-related companies made it to an IPO across the whole era — 585 in 1999 and 2000 alone — and at the peak, only about 14 percent of the tech companies going public were profitable. </p><p>By late 2002, most internet stocks had lost more than three-quarters of their value and roughly 1.7 trillion dollars had been wiped out. And the number of enduring, large-scale winners from that entire cohort — Amazon, eBay, Priceline, Expedia — you can count on two hands. Run the funnel: 50,000 founded, 8,000 funded, 1,700 public, fewer than ten giants. </p><p>A real gold rush works the same way: a few strike it rich, some make a living, and most go home with less than they brought. This is important to remember for everything that follows.</p><p>If that funnel looks like a quirk of one bubble, it is not — it is how markets distribute winnings everywhere. Hendrik Bessembinder at Arizona State studied every U.S. stock since 1926, more than 25,000 companies, and found that the best-performing 4 percent account for all of the net wealth the stock market has ever created; the other 96 percent, taken together, did no better than Treasury bills. </p><p>Just 90 companies — a third of one percent — produced more than half of it, and the majority of stocks lost money outright over their lifetimes. The market wins; almost no individual company does. Keep that in mind every time someone tells you AI will create trillions in value. It will. That says nothing about whether any particular company captures a dime of it.</p><h2 id="the-example-of-cloud">The example of cloud</h2><p><a href="https://www.techradar.com/best/best-cloud-computing-services">Cloud computing</a> is the sharper rerun. In the early days there were hundreds of cloud providers and a thriving ecosystem of middleware companies selling the connective tissue — provisioning tools, management layers, monitoring platforms. </p><p>Today three companies control roughly two-thirds of the cloud market, and their share grows every year. </p><p>And here is the part that matters for AI: the middleware layer did not consolidate alongside the platforms. It was absorbed by them. The hyperscalers built the management consoles, the <a href="https://www.techradar.com/best/best-network-monitoring-tools">monitoring</a>, the orchestration, and shipped it as a feature. The companies whose entire business was cloud plumbing were acquired cheap or squeezed out.</p><p>Meanwhile, the application layer on top of that consolidated <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> exploded. Thousands of SaaS companies built durable, profitable businesses without owning a single server. The bottom of the stack ended up in a few hands. The top produced thousands of winners.</p><h2 id="it-has-already-happened-once-inside-this-stack">It has already happened once inside this stack</h2><p>If cloud feels like ancient history, look at the data layer — the foundation every AI system sits on. That consolidation already occurred, and it finished recently. The "modern data stack" boom of the last decade funded hundreds of startups selling pipelines, catalogs, transformation tools, and warehouses. </p><p>Today the independent tier has settled to exactly two companies at scale: Snowflake and Databricks, each running at roughly five billion dollars in annual revenue, with the hyperscalers’ native offerings holding most of the rest of the market. Nearly everyone else was acquired, absorbed as a platform feature, or left scraping for the remainder.</p><p>And notice the shape it settled into. The top five data platforms — Snowflake, BigQuery, Redshift, Databricks, and Microsoft’s offering — hold roughly two-thirds of the market. That is almost exactly where cloud landed: three players, about two-thirds of the market, a long tail fighting over the rest. </p><p>Two different layers, a decade apart, ending in the same proportions. That is not a coincidence. It is what happens when competing takes huge capital and the platforms can build whatever sits next to them. Expect the AI orchestration layer to end up the same way.</p><p>The consolidation was driven as much by the buyer as by the vendors. Large enterprises learned that scattered data is expensive data: every additional platform meant another copy of the truth, another integration, another <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> review, another contract. </p><p>So CTOs stopped buying data tools one team at a time and started making strategic platform decisions — pick one or two providers, consolidate the estate onto them, and hold that line. A single source of truth became an explicit architectural goal at most large companies, and once thousands of enterprises were making that same decision, the market had no room left for a long tail of vendors.</p><p>Look at what it took for Snowflake and Databricks to survive that consolidation: enormous capital, the fact that customers’ data lives on their platforms and is costly to move, and deep ties into how their customers work every day. You can survive as an independent alongside the hyperscalers — but only by becoming one of the few names a CTO puts on the strategic list, and almost nobody makes that list.</p><h2 id="the-same-consolidation-is-coming-for-ai">The same consolidation is coming for AI</h2><p>Apply that pattern to the two types of AI company and the forecast writes itself.</p><p>The infrastructure layer — orchestration and governance — will consolidate down to a few. Not because the current tools are bad, but because this layer sits directly in the expansion path of the biggest players in technology. The model providers and hyperscalers have every incentive to build orchestration, evaluation, and governance into their platforms, and they are already doing it. Every capability that today justifies a standalone infrastructure startup is a roadmap item at a company with a hundred times the resources and a direct line to the same customers.</p><p>If you are building an architecture-only solution, this is the uncomfortable implication: you are likely to be taken out by one of the big players. Maybe you get acquired, if you are early and lucky. More often, the platform simply builds what you sell and includes it for free. Either way, orchestration and governance alone is not a <a href="https://www.techradar.com/best/best-business-plan-software">business</a> you can hold. The only real question is how long you have.</p><p>Which leaves the application layer as the open field. And this is the counterintuitive part: infrastructure consolidation is good news for application builders. When orchestration and governance become cheap, standardized, and built into the platforms, the cost of building a serious AI application collapses — just as commodity cloud ignited the SaaS boom. We are already seeing a massive increase in the number of AI applications getting built, and most will likely not survive.</p><h2 id="better-software-worse-odds">Better software, worse odds</h2><p>Part of what makes this cycle different is how little it costs to enter. Building serious software used to take millions in capital and a room full of engineers — a filter that limited how many companies could even try. Today a handful of people with AI tools can ship in weeks what took a funded startup a year. </p><p>So new ventures are multiplying, not because there are more good ideas, but because the cost of trying has collapsed. The scale tells the story: more than 70,000 AI companies operate globally today, roughly 18,000 to 30,000 of them in the United States alone. </p><p>The comparison to the dot-com era’s 50,000 is not perfectly apples to apples — that was a five-year founding total for one country, this is a snapshot of companies operating worldwide right now — but the order of magnitude is the same, this wave is global, and the count is still climbing.</p><p>Here is the twist that makes the coming shakeout more brutal, not less: the <a href="https://www.techradar.com/best/best-small-business-software">software</a> being built is genuinely good. This is not the dot-com era, where half-finished products hid behind splashy <a href="https://www.techradar.com/best/best-content-marketing-tools">marketing</a>. The tools are now so powerful that quality is the baseline — which means quality has stopped differentiating anything. When every product is polished, capable, and shipped fast, none of that separates you from the next founder who did the same thing last month. </p><p>And that is precisely why so few founders see the danger. Every one of them genuinely believes they are building something singular — and by their own measure, they are right. They compare their product to what came before: the clunky incumbent, the manual process, the way the work used to get done. Against that <a href="https://www.techradar.com/best/best-benchmarks-software">benchmark</a> it looks revolutionary. </p><p>What they never compare it to is the tens of thousands of other teams looking at the same models and the same problems, building virtually the same thing at the same time. Measured against the past, every AI product is remarkable. Measured against the field, almost none are. More entrants than either previous cycle, all building excellent software, almost none of it distinguishable. </p><p>That is the setup for the largest culling yet, and it will run almost entirely on the moats, because there is nothing else left to separate the winners from the losers.</p><h2 id="the-delusion-of-special">The delusion of special</h2><p>I see this up close. I have this conversation with application founders every week, and it always goes the same way. They believe the quality of what they built is their moat: the product works, customers love it, nothing else on the market feels as good. </p><p>All of that can be true, and none of it protects them. Quality can be copied. The same tools that let them build an excellent product in months let a competitor build one in weeks. A few founders have built something that truly stands alone, but I just can’t see many finding a way to real profitability.  </p><p>There will be some winners, but I think they will need to rest on three key differentiators:</p><p><strong>1. Data</strong>. Not data you scraped or licensed — proprietary data your business generates by operating: claims histories, transaction flows, patient outcomes. If your system gets smarter from data competitors cannot obtain at any price, you compound. If you are building on the same public internet as everyone else, you do not.</p><p><strong>2. Distribution</strong>. If you already own the customer relationship — an installed base, a trusted brand, an embedded sales channel — you can put an AI product in front of buyers faster and cheaper than any startup. This is why incumbents are more dangerous in this cycle than the last one. The startup has to build the product and buy the audience. The incumbent only has to build the product.</p><p><strong>3. Integration into workflows</strong>. The one people underestimate. Companies that wire themselves into how work actually gets done — the approvals, the systems of record, the daily habits of thousands of employees — become painful to remove even when a rival ships something better. Switching costs are not glamorous, but they have protected enterprise software for thirty years, and they will protect AI applications too.</p><p>Have one of these and you can build a durable business on commodity infrastructure. Have two and you can build a great one. Have none and you are likely running out of time.</p><h2 id="your-toughest-competitor-is-your-customer">Your toughest competitor is your customer</h2><p>And here is what makes the application layer even harder than the dot-com or SaaS eras: surface applications are not just competing with other vendors. They are competing with the companies they are trying to sell to. The same commodity infrastructure that makes it easy for a startup to spin up an AI application makes it just as easy for the buyer to build one internally. </p><p>Every enterprise pitch now runs into a question that barely existed in the SaaS era: why would we buy this when a small internal team could build it in a quarter?</p><p>And here is the uncomfortable part. The three advantages that decide the application winners — distribution, proprietary data, embedded workflows — are precisely what the buyer already has. The enterprise owns its data. It is its own distribution. It controls its own workflows. The customer starts the build-versus-buy conversation holding every moat you are trying to claim. </p><p>A surface application does not just need to be better than its competitors. It needs to be so much better than what the customer could build themselves that buying beats owning — and that bar rises every time the underlying infrastructure gets easier to use.</p><h2 id="know-which-company-you-are">Know which company you are</h2><p>I am not going to pretend to know which specific firms win. But the structure of the outcome is already visible, because we have now watched it three times — dot-com, cloud, and the data layer: infrastructure consolidates to a few, applications proliferate, and the survivors are the ones holding data, distribution, or workflow integration that cannot be copied.</p><p>So the first question is not "is my product good?" It is "which of the two companies am I?" If you are infrastructure, your realistic endgame is being bought or being bypassed — plan accordingly. If you are an application, the model is not your moat and the product probably is not either.</p><p>So what is?</p><h2 id="the-good-news-and-who-gets-it">The good news, and who gets it</h2><p>One clarification before closing, because everything above can read as pessimism about AI itself. It is the opposite. The technology will create enormous value, and the markets built on it will grow. The open question is who keeps that value, and a century of evidence gives a consistent answer: mostly the consumers of a technology, not its producers. </p><p>William Nordhaus at Yale measured this across decades of American innovation and found that producers capture only about 2 percent of the total value their innovations create — the rest flows to the people and businesses that use them. Railroads transformed the economy and ruined most of their investors. Airlines moved the world and destroyed capital for a hundred years. The internet made a handful of platforms rich — and made every company that deployed it more productive. </p><p>This cycle is already tracing the same shape: the infrastructure layer consolidates, prices its scarcity, and books historic profits, while the application layer competes and hands its margin to the buyer.</p><p>That is the real ending of this story. The coming massacre of AI companies and the coming growth of the AI economy are the same event, seen from opposite sides of the table. If you sell AI, the funnel is your problem and the moats are your only defense. </p><p>If you buy AI, the competition among 70,000 firms is working precisely in your favor: every improvement, every price cut, every copied feature moves value from their side of the table to yours. The bad news in this article is only bad depending on which chair you sit in.</p><p><em></em><a href="https://www.techradar.com/best/best-business-cloud-storage-service"><em>We've reviewed, rated, and ranked the best business cloud storage</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/bad-news-your-ai-application-isnt-that-special</link>
                                                                            <description>
                            <![CDATA[ The AI massacre is coming, and knowing which side of the stack you're on will decide whether you survive it. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eHLUZAbXTkXznrbUAxNgqW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 14:40:17 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jeff McMillan ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There are more than 70,000 <a href="https://www.techradar.com/best/best-ai-tools">AI</a> companies operating today. </p><p>Most of them will not exist in five years. </p><p>Before you can see why — or figure out whether yours is one of them — you need a distinction the market keeps blurring.</p><p>Strip away the pitch decks and there are really only two types of AI system being built today.</p><p>The first is AI infrastructure: the orchestration and governance technology that makes AI usable at scale. In plain terms, this is the plumbing — agent frameworks, model routing, evaluation and monitoring tools, guardrails, and the controls that let a large organization use AI safely. </p><p>It sits between the foundation models and the end user, and it is where an enormous amount of venture money is going right now.</p><p>The second is the surface application: the tool an actual person uses to do actual work. The underwriting assistant, the contract reviewer, the sales copilot. The thing with a login screen and a job to do.</p><p>What I see in the market is a blending of the two. Some firms are selling <a href="https://www.techradar.com/best/best-architecture-software">architecture</a>. </p><p>Some are selling tools. Many are trying to sell both, on the theory that owning the whole stack is the safest position. </p><p>And while this market is filled with tremendous exuberance with seemingly everyone starting an AI company, I am very skeptical that many of these firms will ever see profitability as history offers a strong counter. </p><p>We've run this experiment twice.</p><h2 id="the-past-and-the-future">The past and the future</h2><p>The dot-com era ran the first version of this experiment, and its final tally is worth stating plainly. Researchers estimate that roughly 50,000 <a href="https://www.techradar.com/best/the-best-crm-for-startups">startups</a> were founded in the United States between 1998 and 2002 to commercialize the internet. </p><p>Of those, something like 8,000 attracted venture funding. About 1,700 internet-related companies made it to an IPO across the whole era — 585 in 1999 and 2000 alone — and at the peak, only about 14 percent of the tech companies going public were profitable. </p><p>By late 2002, most internet stocks had lost more than three-quarters of their value and roughly 1.7 trillion dollars had been wiped out. And the number of enduring, large-scale winners from that entire cohort — Amazon, eBay, Priceline, Expedia — you can count on two hands. Run the funnel: 50,000 founded, 8,000 funded, 1,700 public, fewer than ten giants. </p><p>A real gold rush works the same way: a few strike it rich, some make a living, and most go home with less than they brought. This is important to remember for everything that follows.</p><p>If that funnel looks like a quirk of one bubble, it is not — it is how markets distribute winnings everywhere. Hendrik Bessembinder at Arizona State studied every U.S. stock since 1926, more than 25,000 companies, and found that the best-performing 4 percent account for all of the net wealth the stock market has ever created; the other 96 percent, taken together, did no better than Treasury bills. </p><p>Just 90 companies — a third of one percent — produced more than half of it, and the majority of stocks lost money outright over their lifetimes. The market wins; almost no individual company does. Keep that in mind every time someone tells you AI will create trillions in value. It will. That says nothing about whether any particular company captures a dime of it.</p><h2 id="the-example-of-cloud">The example of cloud</h2><p><a href="https://www.techradar.com/best/best-cloud-computing-services">Cloud computing</a> is the sharper rerun. In the early days there were hundreds of cloud providers and a thriving ecosystem of middleware companies selling the connective tissue — provisioning tools, management layers, monitoring platforms. </p><p>Today three companies control roughly two-thirds of the cloud market, and their share grows every year. </p><p>And here is the part that matters for AI: the middleware layer did not consolidate alongside the platforms. It was absorbed by them. The hyperscalers built the management consoles, the <a href="https://www.techradar.com/best/best-network-monitoring-tools">monitoring</a>, the orchestration, and shipped it as a feature. The companies whose entire business was cloud plumbing were acquired cheap or squeezed out.</p><p>Meanwhile, the application layer on top of that consolidated <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> exploded. Thousands of SaaS companies built durable, profitable businesses without owning a single server. The bottom of the stack ended up in a few hands. The top produced thousands of winners.</p><h2 id="it-has-already-happened-once-inside-this-stack">It has already happened once inside this stack</h2><p>If cloud feels like ancient history, look at the data layer — the foundation every AI system sits on. That consolidation already occurred, and it finished recently. The "modern data stack" boom of the last decade funded hundreds of startups selling pipelines, catalogs, transformation tools, and warehouses. </p><p>Today the independent tier has settled to exactly two companies at scale: Snowflake and Databricks, each running at roughly five billion dollars in annual revenue, with the hyperscalers’ native offerings holding most of the rest of the market. Nearly everyone else was acquired, absorbed as a platform feature, or left scraping for the remainder.</p><p>And notice the shape it settled into. The top five data platforms — Snowflake, BigQuery, Redshift, Databricks, and Microsoft’s offering — hold roughly two-thirds of the market. That is almost exactly where cloud landed: three players, about two-thirds of the market, a long tail fighting over the rest. </p><p>Two different layers, a decade apart, ending in the same proportions. That is not a coincidence. It is what happens when competing takes huge capital and the platforms can build whatever sits next to them. Expect the AI orchestration layer to end up the same way.</p><p>The consolidation was driven as much by the buyer as by the vendors. Large enterprises learned that scattered data is expensive data: every additional platform meant another copy of the truth, another integration, another <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> review, another contract. </p><p>So CTOs stopped buying data tools one team at a time and started making strategic platform decisions — pick one or two providers, consolidate the estate onto them, and hold that line. A single source of truth became an explicit architectural goal at most large companies, and once thousands of enterprises were making that same decision, the market had no room left for a long tail of vendors.</p><p>Look at what it took for Snowflake and Databricks to survive that consolidation: enormous capital, the fact that customers’ data lives on their platforms and is costly to move, and deep ties into how their customers work every day. You can survive as an independent alongside the hyperscalers — but only by becoming one of the few names a CTO puts on the strategic list, and almost nobody makes that list.</p><h2 id="the-same-consolidation-is-coming-for-ai">The same consolidation is coming for AI</h2><p>Apply that pattern to the two types of AI company and the forecast writes itself.</p><p>The infrastructure layer — orchestration and governance — will consolidate down to a few. Not because the current tools are bad, but because this layer sits directly in the expansion path of the biggest players in technology. The model providers and hyperscalers have every incentive to build orchestration, evaluation, and governance into their platforms, and they are already doing it. Every capability that today justifies a standalone infrastructure startup is a roadmap item at a company with a hundred times the resources and a direct line to the same customers.</p><p>If you are building an architecture-only solution, this is the uncomfortable implication: you are likely to be taken out by one of the big players. Maybe you get acquired, if you are early and lucky. More often, the platform simply builds what you sell and includes it for free. Either way, orchestration and governance alone is not a <a href="https://www.techradar.com/best/best-business-plan-software">business</a> you can hold. The only real question is how long you have.</p><p>Which leaves the application layer as the open field. And this is the counterintuitive part: infrastructure consolidation is good news for application builders. When orchestration and governance become cheap, standardized, and built into the platforms, the cost of building a serious AI application collapses — just as commodity cloud ignited the SaaS boom. We are already seeing a massive increase in the number of AI applications getting built, and most will likely not survive.</p><h2 id="better-software-worse-odds">Better software, worse odds</h2><p>Part of what makes this cycle different is how little it costs to enter. Building serious software used to take millions in capital and a room full of engineers — a filter that limited how many companies could even try. Today a handful of people with AI tools can ship in weeks what took a funded startup a year. </p><p>So new ventures are multiplying, not because there are more good ideas, but because the cost of trying has collapsed. The scale tells the story: more than 70,000 AI companies operate globally today, roughly 18,000 to 30,000 of them in the United States alone. </p><p>The comparison to the dot-com era’s 50,000 is not perfectly apples to apples — that was a five-year founding total for one country, this is a snapshot of companies operating worldwide right now — but the order of magnitude is the same, this wave is global, and the count is still climbing.</p><p>Here is the twist that makes the coming shakeout more brutal, not less: the <a href="https://www.techradar.com/best/best-small-business-software">software</a> being built is genuinely good. This is not the dot-com era, where half-finished products hid behind splashy <a href="https://www.techradar.com/best/best-content-marketing-tools">marketing</a>. The tools are now so powerful that quality is the baseline — which means quality has stopped differentiating anything. When every product is polished, capable, and shipped fast, none of that separates you from the next founder who did the same thing last month. </p><p>And that is precisely why so few founders see the danger. Every one of them genuinely believes they are building something singular — and by their own measure, they are right. They compare their product to what came before: the clunky incumbent, the manual process, the way the work used to get done. Against that <a href="https://www.techradar.com/best/best-benchmarks-software">benchmark</a> it looks revolutionary. </p><p>What they never compare it to is the tens of thousands of other teams looking at the same models and the same problems, building virtually the same thing at the same time. Measured against the past, every AI product is remarkable. Measured against the field, almost none are. More entrants than either previous cycle, all building excellent software, almost none of it distinguishable. </p><p>That is the setup for the largest culling yet, and it will run almost entirely on the moats, because there is nothing else left to separate the winners from the losers.</p><h2 id="the-delusion-of-special">The delusion of special</h2><p>I see this up close. I have this conversation with application founders every week, and it always goes the same way. They believe the quality of what they built is their moat: the product works, customers love it, nothing else on the market feels as good. </p><p>All of that can be true, and none of it protects them. Quality can be copied. The same tools that let them build an excellent product in months let a competitor build one in weeks. A few founders have built something that truly stands alone, but I just can’t see many finding a way to real profitability.  </p><p>There will be some winners, but I think they will need to rest on three key differentiators:</p><p><strong>1. Data</strong>. Not data you scraped or licensed — proprietary data your business generates by operating: claims histories, transaction flows, patient outcomes. If your system gets smarter from data competitors cannot obtain at any price, you compound. If you are building on the same public internet as everyone else, you do not.</p><p><strong>2. Distribution</strong>. If you already own the customer relationship — an installed base, a trusted brand, an embedded sales channel — you can put an AI product in front of buyers faster and cheaper than any startup. This is why incumbents are more dangerous in this cycle than the last one. The startup has to build the product and buy the audience. The incumbent only has to build the product.</p><p><strong>3. Integration into workflows</strong>. The one people underestimate. Companies that wire themselves into how work actually gets done — the approvals, the systems of record, the daily habits of thousands of employees — become painful to remove even when a rival ships something better. Switching costs are not glamorous, but they have protected enterprise software for thirty years, and they will protect AI applications too.</p><p>Have one of these and you can build a durable business on commodity infrastructure. Have two and you can build a great one. Have none and you are likely running out of time.</p><h2 id="your-toughest-competitor-is-your-customer">Your toughest competitor is your customer</h2><p>And here is what makes the application layer even harder than the dot-com or SaaS eras: surface applications are not just competing with other vendors. They are competing with the companies they are trying to sell to. The same commodity infrastructure that makes it easy for a startup to spin up an AI application makes it just as easy for the buyer to build one internally. </p><p>Every enterprise pitch now runs into a question that barely existed in the SaaS era: why would we buy this when a small internal team could build it in a quarter?</p><p>And here is the uncomfortable part. The three advantages that decide the application winners — distribution, proprietary data, embedded workflows — are precisely what the buyer already has. The enterprise owns its data. It is its own distribution. It controls its own workflows. The customer starts the build-versus-buy conversation holding every moat you are trying to claim. </p><p>A surface application does not just need to be better than its competitors. It needs to be so much better than what the customer could build themselves that buying beats owning — and that bar rises every time the underlying infrastructure gets easier to use.</p><h2 id="know-which-company-you-are">Know which company you are</h2><p>I am not going to pretend to know which specific firms win. But the structure of the outcome is already visible, because we have now watched it three times — dot-com, cloud, and the data layer: infrastructure consolidates to a few, applications proliferate, and the survivors are the ones holding data, distribution, or workflow integration that cannot be copied.</p><p>So the first question is not "is my product good?" It is "which of the two companies am I?" If you are infrastructure, your realistic endgame is being bought or being bypassed — plan accordingly. If you are an application, the model is not your moat and the product probably is not either.</p><p>So what is?</p><h2 id="the-good-news-and-who-gets-it">The good news, and who gets it</h2><p>One clarification before closing, because everything above can read as pessimism about AI itself. It is the opposite. The technology will create enormous value, and the markets built on it will grow. The open question is who keeps that value, and a century of evidence gives a consistent answer: mostly the consumers of a technology, not its producers. </p><p>William Nordhaus at Yale measured this across decades of American innovation and found that producers capture only about 2 percent of the total value their innovations create — the rest flows to the people and businesses that use them. Railroads transformed the economy and ruined most of their investors. Airlines moved the world and destroyed capital for a hundred years. The internet made a handful of platforms rich — and made every company that deployed it more productive. </p><p>This cycle is already tracing the same shape: the infrastructure layer consolidates, prices its scarcity, and books historic profits, while the application layer competes and hands its margin to the buyer.</p><p>That is the real ending of this story. The coming massacre of AI companies and the coming growth of the AI economy are the same event, seen from opposite sides of the table. If you sell AI, the funnel is your problem and the moats are your only defense. </p><p>If you buy AI, the competition among 70,000 firms is working precisely in your favor: every improvement, every price cut, every copied feature moves value from their side of the table to yours. The bad news in this article is only bad depending on which chair you sit in.</p><p><em></em><a href="https://www.techradar.com/best/best-business-cloud-storage-service"><em>We've reviewed, rated, and ranked the best business cloud storage</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Trump signs memo calling for cyber privateers to conduct cyberattacks abroad against criminal groups targeting Americans — but they have to escrow $1 million to join ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>US government to allow private firms to conduct legal cyberattacks on foreign organizations targeting Americans</strong></li><li><strong>Firms will be allowed to disrupt and destroy physical and virtual information systems and networks</strong></li><li><strong>US victims of cyber scams and fraud lose around $20,000</strong></li></ul><p>President Trump has signed a <a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/" target="_blank" rel="nofollow">memo</a> which allows private US firms to partner with the US government in operations designed to surveille and disrupt Transnational Criminal Organizations (TCOs).</p><p>According to the memo, the partnership “will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” essentially turning private companies into privateers with the ability to launch cyber attacks against foreign entities.</p><p>The memo marks a significant shift in how the US tackles foreign cybercrime. “American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace,” the memo states. But what does this actually mean in practice?</p><h2 id="us-to-leverage-private-sector-for-cyber-defense">US to leverage private sector for cyber defense</h2><p>The US is the most targeted country in the world for cyber attacks and cybercrime, with <a href="https://www.techradar.com/pro/security/cybercrime-is-costing-the-world-trillions-every-year-new-report-says-victims-lose-an-average-of-nearly-usd10-000-in-every-hit">6.7 million victims losing $138.9 billion in the last year</a>, placing the average loss per-victim at around $20,731.</p><p>The program will effectively create a global cyber surveillance network that acts as an early warning system against attacks targeting critical national infrastructure, such as the recent <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">Iranian attacks targeting over 30 US water systems</a>. Private companies that “discover an imminent cyber-attack against United States critical infrastructure” will be required to notify the National Coordination Center (NCC).</p><p>The US government isn’t just looking to work alongside the big tech companies. Big companies will be part of the picture to “provide critical capacity,” but smaller companies will also have the opportunity to become involved with the program as they are “more agile,” and “may be better suited for specialized or discrete tasks.”</p><p>When a threat is detected, private companies will put together a “cyber operations package” to be reviewed and approved by the Program Executive Directors. These packages will likely include plans for surveillance and offensive cyber operations.</p><p>Private companies looking to become part of the program will be vetted according to government guidelines, and will have to operate within a set of operating procedures under the oversight of the federal government. “No operation may be approved unless it complies with these operating procedures,” the memo says.</p><p>There is however a caveat that those involved within the program must “maintain a bond or escrow in an amount not less than $1 million,” which would be forfeit should a private company “enter non‑compliance with its contractual agreement.”</p><p>The memo also sets our parameters to prevent private companies from accidentally or intentionally targeting US citizens, or US information systems at home and abroad, with the company required to “cease such operation, conduct minimization procedures, and immediately notify the NCC,” in the event that a company “discovers operational activity exceeding the parameters and restrictions of the cyber operation”.</p><p>Additionally, “any activity authorized by the Program must be conducted subject to the oversight, operational control, and legal authorities of the United States Government”.</p><p>The memo is the latest step in the Trump administration’s efforts to allow private companies to legally launch cyberattacks on behalf of the US government. “The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States,” the memo states.</p><p>The program will also put together a report on its progress every year, as well as reviewing the performance of each private company within the program within the same time frame.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/trump-signs-memo-calling-for-cyber-privateers-to-conduct-cyberattacks-abroad-against-criminal-groups-targeting-americans-but-they-have-to-escrow-usd1-million-to-join</link>
                                                                            <description>
                            <![CDATA[ Private companies will be legally allowed to conduct cyberattacks against foreign groups on behalf of the US government. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">utyNFb8pS4FFJvAbLae83g</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 12:05:00 +0000</pubDate>                                                                                                                                <updated>Thu, 13 Aug 2026 12:52:56 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:description>                                                            <media:text><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:text>
                                <media:title type="plain"><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>US government to allow private firms to conduct legal cyberattacks on foreign organizations targeting Americans</strong></li><li><strong>Firms will be allowed to disrupt and destroy physical and virtual information systems and networks</strong></li><li><strong>US victims of cyber scams and fraud lose around $20,000</strong></li></ul><p>President Trump has signed a <a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/" target="_blank" rel="nofollow">memo</a> which allows private US firms to partner with the US government in operations designed to surveille and disrupt Transnational Criminal Organizations (TCOs).</p><p>According to the memo, the partnership “will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” essentially turning private companies into privateers with the ability to launch cyber attacks against foreign entities.</p><p>The memo marks a significant shift in how the US tackles foreign cybercrime. “American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace,” the memo states. But what does this actually mean in practice?</p><h2 id="us-to-leverage-private-sector-for-cyber-defense">US to leverage private sector for cyber defense</h2><p>The US is the most targeted country in the world for cyber attacks and cybercrime, with <a href="https://www.techradar.com/pro/security/cybercrime-is-costing-the-world-trillions-every-year-new-report-says-victims-lose-an-average-of-nearly-usd10-000-in-every-hit">6.7 million victims losing $138.9 billion in the last year</a>, placing the average loss per-victim at around $20,731.</p><p>The program will effectively create a global cyber surveillance network that acts as an early warning system against attacks targeting critical national infrastructure, such as the recent <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">Iranian attacks targeting over 30 US water systems</a>. Private companies that “discover an imminent cyber-attack against United States critical infrastructure” will be required to notify the National Coordination Center (NCC).</p><p>The US government isn’t just looking to work alongside the big tech companies. Big companies will be part of the picture to “provide critical capacity,” but smaller companies will also have the opportunity to become involved with the program as they are “more agile,” and “may be better suited for specialized or discrete tasks.”</p><p>When a threat is detected, private companies will put together a “cyber operations package” to be reviewed and approved by the Program Executive Directors. These packages will likely include plans for surveillance and offensive cyber operations.</p><p>Private companies looking to become part of the program will be vetted according to government guidelines, and will have to operate within a set of operating procedures under the oversight of the federal government. “No operation may be approved unless it complies with these operating procedures,” the memo says.</p><p>There is however a caveat that those involved within the program must “maintain a bond or escrow in an amount not less than $1 million,” which would be forfeit should a private company “enter non‑compliance with its contractual agreement.”</p><p>The memo also sets our parameters to prevent private companies from accidentally or intentionally targeting US citizens, or US information systems at home and abroad, with the company required to “cease such operation, conduct minimization procedures, and immediately notify the NCC,” in the event that a company “discovers operational activity exceeding the parameters and restrictions of the cyber operation”.</p><p>Additionally, “any activity authorized by the Program must be conducted subject to the oversight, operational control, and legal authorities of the United States Government”.</p><p>The memo is the latest step in the Trump administration’s efforts to allow private companies to legally launch cyberattacks on behalf of the US government. “The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States,” the memo states.</p><p>The program will also put together a report on its progress every year, as well as reviewing the performance of each private company within the program within the same time frame.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why employees, not threat actors, are 2026’s biggest risk ]]></title>
                                                                                                <dc:content><![CDATA[ <p>With all the buzz around nation-state threats, it’s easy for organizations to focus on threats outside the business – and forget about risks that can spiral outwards from within.</p><p>Whilst GenAI tools have introduced undeniable efficiencies for <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employees</a>, these platforms have also introduced a new class of risk: two in three UK organizations admit they can’t track whether employees are sharing data via approved tools.</p><p>Most of the time, employees aren’t sharing sensitive data because they have malicious intentions. They are uploading sensitive information – like contracts, client proposals or supplier agreements to models like ChatGPT and Claude to save time on routine tasks.</p><p>Almost all (93%) of CEOs across the globe have adopted generative AI to some extent in the past 12 months (PwC). What’s concerning is that much of this activity is happening without any oversight, in the <a href="https://www.techradar.com/best/browser">browser</a> – meaning organizations are failing to track the flow of company information, including when and where it’s uploaded.   </p><p>This is spiraling into serious risk for businesses.</p><p>First, because employees may inadvertently share credentials or other access details with public LLMs, which could result in unauthorized access if the model is compromised.</p><p>Second, uploading personal <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> to LLMs can trigger compliance breaches with laws like GDPR and the Data Use and Access Act – resulting in costly fines as well as reputational damage.</p><p>To take control of this issue, leaders will need to implement tools and technologies that provide visibility and control over usage at both the browser and the application levels. </p><h2 id="the-incentive-problem">The incentive problem</h2><p>Employees don’t need more mandatory cybersecurity training – the problem is incentive. Many company-owned gated LLMs are still in the pilot stage, falling short of the speed and precision offered by public alternatives.</p><p>While the majority of employees understand the risks, 35% of UK <a href="https://www.techradar.com/best/best-small-business-software">businesses</a> admit data sharing through external tools takes place – indicating many would rather ‘throw caution to the wind’ than waste valuable time using slower tools.</p><p>But the risks of this behavior – particularly in highly regulated sectors like financial services, could mean unsanctioned LLMs become 'hidden icebergs’ in an organization. Concealed, but capable of causing catastrophic damage upon impact – like inadvertently exposing customer transaction histories or credit scores. </p><p>Part of curbing Shadow AI use in the enterprise therefore starts with designing approved AI tools that integrate easily with existing platforms (for example, Microsoft 365 and Google Workspace). These tools should be continuously improved based on user feedback, ideally avoiding excessive restrictions that make the tool frustrating to use.</p><p>But the fact is, nearly two-thirds of organizations are currently stuck in the pilot stage when it comes to their AI initiatives and haven’t started to scale across the enterprise (McKinsey). So, what can organizations do today to gain control of the Shadow AI problem?</p><h2 id="the-solution-tools-to-bring-unsanctioned-ai-usage-under-control">The solution – tools to bring unsanctioned AI usage under control </h2><p>You can’t control what you can’t see, which is why organizations need a real-time view of who, or what, is accessing what data, from which devices, and where it’s being shared.</p><p>Next-gen identity <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> platforms can help organizations to gain an immediate understanding of how employees interact with consumer AI tools like ChatGPT, Claude, and Gemini, tracking interaction frequency and monitoring document uploads.</p><p>Once high-risk behavior is identified, organizations can then automate corrective actions, redirect users to secure AI alternatives, or prompt users to justify their business use case before proceeding. </p><p>Visibility will become even more important with the emergence of ‘nested’ agents. In this scenario, employees might believe they’re only interacting with a single AI agent, but that <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">chatbot</a> may delegate tasks to multiple underlying agents. The organization has no visibility into how many downstream agents or services its information is being shared with. </p><p>An identity security tool makes these identities ‘discoverable’ via a real-time ‘agent ledger’. This ledger acts as a complete, unchangeable trace of all agent activities and interactions. It also applies controls to each agent in the database.</p><p>Only the absolute minimum privilege required for a task is granted, at the exact moment it is needed, and for the shortest possible duration. In this way, agent permissions don’t automatically ‘cascade’. If an agent wants to connect with another agent, it must be verified by the system first.  </p><h2 id="closing-the-visibility-gap">Closing the visibility gap</h2><p>Shadow AI is more than a tooling problem: it’s an identity problem. Organizations can close the ‘visibility gap’ by using tools that track interaction frequency, block sensitive document uploads, and prompt employees as well as AI agents to justify their business case before they use unsanctioned tools.</p><p>Once organizations know which tools are being used, what data they're accessing, and where that information goes, they can apply effective guardrails to secure behaviors – both human and non-human. A simple inventory of AI agents is not enough; now, organizations need to move beyond flat inventories and develop an understanding of the context and relationships that surround every agent.</p><p>In essence, identity security platforms become adaptive – moving from static to dynamic, real-time approaches to access. This is helping organizations to operationalize zero trust by ensuring that no identity, human or non-human, is trusted by default. </p><p>In the era of AI agents, securing <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a> has become a prerequisite for innovation.</p><p><em></em><a href="https://www.techradar.com/best/best-ai-tools"><em>We've featured the best AI tool.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/why-employees-not-threat-actors-are-2026s-biggest-risk</link>
                                                                            <description>
                            <![CDATA[ Shadow AI is exposing businesses to hidden employee-led risks, demanding stronger identity security and visibility. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7wTNzGYJUFR6wQCijY6k9G</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 09:48:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Bradford ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Thapana Onphalai via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:description>                                                            <media:text><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:text>
                                <media:title type="plain"><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With all the buzz around nation-state threats, it’s easy for organizations to focus on threats outside the business – and forget about risks that can spiral outwards from within.</p><p>Whilst GenAI tools have introduced undeniable efficiencies for <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employees</a>, these platforms have also introduced a new class of risk: two in three UK organizations admit they can’t track whether employees are sharing data via approved tools.</p><p>Most of the time, employees aren’t sharing sensitive data because they have malicious intentions. They are uploading sensitive information – like contracts, client proposals or supplier agreements to models like ChatGPT and Claude to save time on routine tasks.</p><p>Almost all (93%) of CEOs across the globe have adopted generative AI to some extent in the past 12 months (PwC). What’s concerning is that much of this activity is happening without any oversight, in the <a href="https://www.techradar.com/best/browser">browser</a> – meaning organizations are failing to track the flow of company information, including when and where it’s uploaded.   </p><p>This is spiraling into serious risk for businesses.</p><p>First, because employees may inadvertently share credentials or other access details with public LLMs, which could result in unauthorized access if the model is compromised.</p><p>Second, uploading personal <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> to LLMs can trigger compliance breaches with laws like GDPR and the Data Use and Access Act – resulting in costly fines as well as reputational damage.</p><p>To take control of this issue, leaders will need to implement tools and technologies that provide visibility and control over usage at both the browser and the application levels. </p><h2 id="the-incentive-problem">The incentive problem</h2><p>Employees don’t need more mandatory cybersecurity training – the problem is incentive. Many company-owned gated LLMs are still in the pilot stage, falling short of the speed and precision offered by public alternatives.</p><p>While the majority of employees understand the risks, 35% of UK <a href="https://www.techradar.com/best/best-small-business-software">businesses</a> admit data sharing through external tools takes place – indicating many would rather ‘throw caution to the wind’ than waste valuable time using slower tools.</p><p>But the risks of this behavior – particularly in highly regulated sectors like financial services, could mean unsanctioned LLMs become 'hidden icebergs’ in an organization. Concealed, but capable of causing catastrophic damage upon impact – like inadvertently exposing customer transaction histories or credit scores. </p><p>Part of curbing Shadow AI use in the enterprise therefore starts with designing approved AI tools that integrate easily with existing platforms (for example, Microsoft 365 and Google Workspace). These tools should be continuously improved based on user feedback, ideally avoiding excessive restrictions that make the tool frustrating to use.</p><p>But the fact is, nearly two-thirds of organizations are currently stuck in the pilot stage when it comes to their AI initiatives and haven’t started to scale across the enterprise (McKinsey). So, what can organizations do today to gain control of the Shadow AI problem?</p><h2 id="the-solution-tools-to-bring-unsanctioned-ai-usage-under-control">The solution – tools to bring unsanctioned AI usage under control </h2><p>You can’t control what you can’t see, which is why organizations need a real-time view of who, or what, is accessing what data, from which devices, and where it’s being shared.</p><p>Next-gen identity <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> platforms can help organizations to gain an immediate understanding of how employees interact with consumer AI tools like ChatGPT, Claude, and Gemini, tracking interaction frequency and monitoring document uploads.</p><p>Once high-risk behavior is identified, organizations can then automate corrective actions, redirect users to secure AI alternatives, or prompt users to justify their business use case before proceeding. </p><p>Visibility will become even more important with the emergence of ‘nested’ agents. In this scenario, employees might believe they’re only interacting with a single AI agent, but that <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">chatbot</a> may delegate tasks to multiple underlying agents. The organization has no visibility into how many downstream agents or services its information is being shared with. </p><p>An identity security tool makes these identities ‘discoverable’ via a real-time ‘agent ledger’. This ledger acts as a complete, unchangeable trace of all agent activities and interactions. It also applies controls to each agent in the database.</p><p>Only the absolute minimum privilege required for a task is granted, at the exact moment it is needed, and for the shortest possible duration. In this way, agent permissions don’t automatically ‘cascade’. If an agent wants to connect with another agent, it must be verified by the system first.  </p><h2 id="closing-the-visibility-gap">Closing the visibility gap</h2><p>Shadow AI is more than a tooling problem: it’s an identity problem. Organizations can close the ‘visibility gap’ by using tools that track interaction frequency, block sensitive document uploads, and prompt employees as well as AI agents to justify their business case before they use unsanctioned tools.</p><p>Once organizations know which tools are being used, what data they're accessing, and where that information goes, they can apply effective guardrails to secure behaviors – both human and non-human. A simple inventory of AI agents is not enough; now, organizations need to move beyond flat inventories and develop an understanding of the context and relationships that surround every agent.</p><p>In essence, identity security platforms become adaptive – moving from static to dynamic, real-time approaches to access. This is helping organizations to operationalize zero trust by ensuring that no identity, human or non-human, is trusted by default. </p><p>In the era of AI agents, securing <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a> has become a prerequisite for innovation.</p><p><em></em><a href="https://www.techradar.com/best/best-ai-tools"><em>We've featured the best AI tool.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Data sovereignty is more than a pin on a map ]]></title>
                                                                                                <dc:content><![CDATA[ <p>As governments and organizations rethink their reliance on foreign-owned <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a>, data sovereignty has become a boardroom priority. </p><p>However, the conversation has become overly focused on where data is stored, overlooking the legal, operational and resilience factors that determine whether organizations are truly in control.</p><p>Whether through misunderstanding or a deliberate attempt to mislead, the term data sovereignty is often misused.</p><p>Data residency and data sovereignty are being conflated, despite being very different. Data residency is about the physical location of data, while data sovereignty is much broader and also includes legal jurisdiction, operational control, resilience, governance and the ability to manage risk.</p><p>Concerns about dependence on foreign-owned digital infrastructure have brought added urgency to issues of digital independence and control over critical technology.</p><p>In response, various vendors - particularly the big US-based hyperscalers - are now repositioning themselves with “sovereign” alternatives based primarily on where they store customer data. </p><p>While this might address some of their customers’ needs, reducing sovereignty to a question of geography creates a misleadingly simple narrative: if an organization moves data to the “right” country, it will somehow become compliant. In reality, the core issue is not just where data should be hosted, but understanding who may seek access to it and who ultimately controls the infrastructure supporting it. </p><p>This misunderstanding is giving rise to what could be described as “data sovereignty washing”, with simplified claims that don't reflect legal or operational reality. </p><h2 id="data-sans-frontieres">Data sans frontières</h2><p>Governments the world over have well-established legal mechanisms for requesting information held in other jurisdictions. While data residency influences which laws apply and how requests are handled, it does not provide immunity from lawful access or eliminate international cooperation. </p><p>An example is the US CLOUD Act. Under certain conditions, it enables US authorities to request data from US service providers even when it is stored outside the United States. So, even if a UK or European-owned organization hosts data with a US-owned provider in a UK or European data center, it may still be reachable under US legal process. Being physically ‘local’ doesn’t change that. </p><p>The US is far from unique in this regard. Many other countries have legislation in place allowing authorities to access data for law enforcement or national security purposes, often supported by cross-border agreements and established legal processes. </p><p>The risk is that enterprises treat location as a complete sovereignty strategy, rather than one element of it. Threat actors care about the value of the data, not geography. As a result, organizations can spend significant time and money <a href="https://www.techradar.com/best/best-data-migration-tools">migrating data</a> to new locations while leaving their biggest <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> risks fundamentally unchanged. </p><p>A more useful starting point is to ask what risks the organization is actually trying to reduce. That shifts the focus and any subsequent changes in approach away from maps, and towards threat modelling, which provides the right context for meaningful conversations about sovereignty.</p><h2 id="start-with-the-threat-model">Start with the threat model</h2><p>Different organizations have fundamentally different threat models. A local retailer, a multinational bank, a defense contractor and a government department are unlikely to share the same priorities, even if they all process sensitive information. </p><p>For some organizations, regulatory compliance or data residency requirements may be the primary concern. For others, resilience against cyberattack, protection of intellectual property, or reducing dependence on a particular technology provider may be far more important. It’s generally a matter of sector-specific and business priorities. </p><p>So, rather than simply asking where data is stored, leaders should consider who ultimately controls the infrastructure, how dependent they are on individual <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud providers</a>, what happens if services become unavailable, and whether they retain sufficient visibility and control over critical systems. If any of this raises operational or regulatory concerns, it may be sensible to adjust strategy.</p><h2 id="the-resilience-paradox">The resilience paradox</h2><p>An unintended consequence of pursuing absolute data localization is that it can reduce resilience. Organizations often improve availability and <a href="https://www.techradar.com/best/best-data-recovery-service">data recovery</a> by maintaining geographically separate copies of critical data. Restricting everything to a single jurisdiction can reduce those options. </p><p>Decisions about sovereignty should therefore factor in availability, confidentiality, and integrity – all of which are important. The most effective approaches recognize that resilience sometimes requires carefully managed distribution rather than rigid localization. </p><p>Consider this scenario: an organization has ensured all their <a href="https://www.techradar.com/news/best-email-provider">email</a> is stored within a single jurisdiction to meet sovereignty objectives. Months later, their provider has a major outage in that one region, and they lose access to their email for days. Even worse, a serious data loss event affects their <a href="https://www.techradar.com/best/best-backup-software">backups</a>, which are also stored in the same region. If they had optimized for resilience instead, their data would have been safe and available throughout. </p><p>Even though the organization successfully addressed one aspect of sovereignty, they weakened another by reducing their ability to recover critical business information. That's ultimately the difference between treating sovereignty as a marketing claim and treating it as a genuine risk management exercise.</p><p><a href="https://www.techradar.com/best/best-cloud-backup"><em>We've reviewed, rated, and ranked the best cloud backup</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/data-sovereignty-is-more-than-a-pin-on-a-map</link>
                                                                            <description>
                            <![CDATA[ Storing data locally won't guarantee sovereignty without governance, resilience and operational control. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a3JZoFhZVMmYES4ZxKQdSY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EXMLBYo5k7EwcuyYg9vmmM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 09:00:20 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bron Gondwana ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EXMLBYo5k7EwcuyYg9vmmM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A long corridor with a sleek black floor, glowing green lights in the ceiling and rows of LEDS on either wall]]></media:description>                                                            <media:text><![CDATA[A long corridor with a sleek black floor, glowing green lights in the ceiling and rows of LEDS on either wall]]></media:text>
                                <media:title type="plain"><![CDATA[A long corridor with a sleek black floor, glowing green lights in the ceiling and rows of LEDS on either wall]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EXMLBYo5k7EwcuyYg9vmmM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As governments and organizations rethink their reliance on foreign-owned <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a>, data sovereignty has become a boardroom priority. </p><p>However, the conversation has become overly focused on where data is stored, overlooking the legal, operational and resilience factors that determine whether organizations are truly in control.</p><p>Whether through misunderstanding or a deliberate attempt to mislead, the term data sovereignty is often misused.</p><p>Data residency and data sovereignty are being conflated, despite being very different. Data residency is about the physical location of data, while data sovereignty is much broader and also includes legal jurisdiction, operational control, resilience, governance and the ability to manage risk.</p><p>Concerns about dependence on foreign-owned digital infrastructure have brought added urgency to issues of digital independence and control over critical technology.</p><p>In response, various vendors - particularly the big US-based hyperscalers - are now repositioning themselves with “sovereign” alternatives based primarily on where they store customer data. </p><p>While this might address some of their customers’ needs, reducing sovereignty to a question of geography creates a misleadingly simple narrative: if an organization moves data to the “right” country, it will somehow become compliant. In reality, the core issue is not just where data should be hosted, but understanding who may seek access to it and who ultimately controls the infrastructure supporting it. </p><p>This misunderstanding is giving rise to what could be described as “data sovereignty washing”, with simplified claims that don't reflect legal or operational reality. </p><h2 id="data-sans-frontieres">Data sans frontières</h2><p>Governments the world over have well-established legal mechanisms for requesting information held in other jurisdictions. While data residency influences which laws apply and how requests are handled, it does not provide immunity from lawful access or eliminate international cooperation. </p><p>An example is the US CLOUD Act. Under certain conditions, it enables US authorities to request data from US service providers even when it is stored outside the United States. So, even if a UK or European-owned organization hosts data with a US-owned provider in a UK or European data center, it may still be reachable under US legal process. Being physically ‘local’ doesn’t change that. </p><p>The US is far from unique in this regard. Many other countries have legislation in place allowing authorities to access data for law enforcement or national security purposes, often supported by cross-border agreements and established legal processes. </p><p>The risk is that enterprises treat location as a complete sovereignty strategy, rather than one element of it. Threat actors care about the value of the data, not geography. As a result, organizations can spend significant time and money <a href="https://www.techradar.com/best/best-data-migration-tools">migrating data</a> to new locations while leaving their biggest <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> risks fundamentally unchanged. </p><p>A more useful starting point is to ask what risks the organization is actually trying to reduce. That shifts the focus and any subsequent changes in approach away from maps, and towards threat modelling, which provides the right context for meaningful conversations about sovereignty.</p><h2 id="start-with-the-threat-model">Start with the threat model</h2><p>Different organizations have fundamentally different threat models. A local retailer, a multinational bank, a defense contractor and a government department are unlikely to share the same priorities, even if they all process sensitive information. </p><p>For some organizations, regulatory compliance or data residency requirements may be the primary concern. For others, resilience against cyberattack, protection of intellectual property, or reducing dependence on a particular technology provider may be far more important. It’s generally a matter of sector-specific and business priorities. </p><p>So, rather than simply asking where data is stored, leaders should consider who ultimately controls the infrastructure, how dependent they are on individual <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud providers</a>, what happens if services become unavailable, and whether they retain sufficient visibility and control over critical systems. If any of this raises operational or regulatory concerns, it may be sensible to adjust strategy.</p><h2 id="the-resilience-paradox">The resilience paradox</h2><p>An unintended consequence of pursuing absolute data localization is that it can reduce resilience. Organizations often improve availability and <a href="https://www.techradar.com/best/best-data-recovery-service">data recovery</a> by maintaining geographically separate copies of critical data. Restricting everything to a single jurisdiction can reduce those options. </p><p>Decisions about sovereignty should therefore factor in availability, confidentiality, and integrity – all of which are important. The most effective approaches recognize that resilience sometimes requires carefully managed distribution rather than rigid localization. </p><p>Consider this scenario: an organization has ensured all their <a href="https://www.techradar.com/news/best-email-provider">email</a> is stored within a single jurisdiction to meet sovereignty objectives. Months later, their provider has a major outage in that one region, and they lose access to their email for days. Even worse, a serious data loss event affects their <a href="https://www.techradar.com/best/best-backup-software">backups</a>, which are also stored in the same region. If they had optimized for resilience instead, their data would have been safe and available throughout. </p><p>Even though the organization successfully addressed one aspect of sovereignty, they weakened another by reducing their ability to recover critical business information. That's ultimately the difference between treating sovereignty as a marketing claim and treating it as a genuine risk management exercise.</p><p><a href="https://www.techradar.com/best/best-cloud-backup"><em>We've reviewed, rated, and ranked the best cloud backup</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is Tokenmaxxing, and why should businesses care about it? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The past two years have seen unprecedented adoption of generative AI. This was driven largely by <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">LLM</a> platforms such as Claude, which reported 28 million paying US customers in March.</p><p>In the corporate world and startups, this has put the pressure on companies to invest in AI, to keep up with the latest models and bolster <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> and efficiency. But now that the world has adopted AI, a stark readiness gap is emerging as governance and AI skills lag behind. AI fluency is now a baseline expectation for employees as leaders feel the pressure to prove the returns on their hefty investments.  </p><p>Tokenmaxxing is the latest AI trend to come under fire as businesses want employees to use more AI in their work. In essence, this means boosting AI input to maximize AI output. On the surface, it sounds efficient and harmless. But underneath, it poses major security risks. </p><h2 id="tokenmaxxing-explained">Tokenmaxxing explained</h2><p>So what actually is tokenmaxxing?</p><p>A ‘token’ is a unit of data processed by an AI model. For example, a word or character inputted into an LLM search. So ‘tokenmaxxing’ quite simply means over-engineering generative AI prompts to get the most out of one search input. This can be anything from overly detailed prompts, to overloading an LLM chat with information, to asking an AI model for step-by-step breakdowns, as opposed to short summaries.</p><p>The trend is driven by businesses as leaders face pressure to prove the ROI of AI. It became a tongue-in-cheek benchmark of AI performance. Some companies, such as Meta, even gamified tokenmaxxing, measuring and ranking AI usage and citing the highest scorers ‘Token Legends’.</p><p>Their assumption is that AI usage means being AI-forward. But instead, companies need to consider the value they get from <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a>. They also need to keep security at the center of the conversation.</p><h2 id="the-hidden-costs-of-tokenmaxxing">The hidden costs of tokenmaxxing</h2><p>Although it might look like harmless corporate showboating, this trend poses a wide range of security risks given that LLM vendors are 52% more likely to be designated as “high risk” than traditional SaaS. This is due to access to sensitive data, IP, and internal workflows, so it’s imperative that <a href="https://www.techradar.com/best/best-business-cloud-storage-service">businesses</a> have oversight of how employees use these resources.</p><p>Rapid adoption of AI has led to an experimentation mindset. This is a positive shift from an innovation standpoint, but from a compliance perspective, a ‘trial and error’ approach is more error than trial.</p><p>The legacy tech systems most major enterprises are still reliant on are controlled by procurement and security teams and were not designed for the agility of AI technology. Meaning both innovation and compliance are lagging behind. It’s the latter that’s causing major concerns in the <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> world.  </p><p>When employees face mounting pressure to get the job done, they won’t wait for security teams to approve new tools, which results in shadow AI. This is where unmanaged, unapproved AI tools operate inside company environments without oversight.</p><p>Industry data shows that 70% of 16k cybersecurity customers currently have some form of shadow AI lurking within their organization, largely due to AI tools introduced through improper procurement channels that now have access to company data without oversight or guardrails.</p><p>There’s also been a 36% increase in shadow IT year-on-year, with organizations discovering, on average, around 140 Shadow IT tools accessing their environment within 90 days of connecting to the platform.</p><p>The bottom line is that AI adoption is drastically outpacing governance, and employees are prioritizing speed over control.</p><h2 id="how-businesses-can-defend-against-shadow-ai">How businesses can defend against Shadow AI</h2><p>The core issue isn’t tokenmaxxing itself; it’s businesses' inability to keep up with <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> demand for speedy access to the latest AI tools. This ultimately results in friction between the desire to safely onboard new tools and the ongoing pressure to use AI.</p><p>When security teams intervene and revoke access to unmanaged tools, employees just reinstall them. Industry data finds that within a 30-day period, the average enterprise sees employees reinstall revoked tools 100+ times. Within one year, it happens 1,000 times.</p><p>To bolster defenses, organizations must design their procurement systems to match the speed of AI innovation, so they can keep up with the rate of AI usage, as demonstrated by so-called ‘token legends’.</p><h2 id="three-actions-businesses-can-take-now">Three actions businesses can take now</h2><p>The more generative AI gets adopted in the corporate world, the more employees will face pressure to adopt and prove its ROI. Tokenmaxxing is just one hype within this wider picture. Businesses need to act fast to stop the gap between experimentation and control widening.</p><p>Three things leaders and compliance teams can kickstart today to bolster defenses against shadow AI are:</p><ul><li>Shrinking vendor review timelines so they match the speed of AI adoption</li><li>Set up continuous monitoring systems to detect threats caused by tokenmaxxing before they jeopardize safety</li><li>Implement employee training and policies for AI usage to ensure employees don’t expose sensitive data or IP</li></ul><p>The new mandate is matching speed with governance, and it’s up to <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> teams to lead the charge.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-chatbot-for-business"><em>We've featured the best AI chatbot for business.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/what-is-tokenmaxxing-and-why-should-businesses-care-about-it</link>
                                                                            <description>
                            <![CDATA[ Tokenmaxxing highlights how businesses’ race to maximize AI productivity is exposing governance and security risks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7XwpBRLwgXdzyzYFZ2ewYA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 08:59:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Iccha Sethi ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A line of robots typing at computers]]></media:description>                                                            <media:text><![CDATA[A line of robots typing at computers]]></media:text>
                                <media:title type="plain"><![CDATA[A line of robots typing at computers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The past two years have seen unprecedented adoption of generative AI. This was driven largely by <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">LLM</a> platforms such as Claude, which reported 28 million paying US customers in March.</p><p>In the corporate world and startups, this has put the pressure on companies to invest in AI, to keep up with the latest models and bolster <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> and efficiency. But now that the world has adopted AI, a stark readiness gap is emerging as governance and AI skills lag behind. AI fluency is now a baseline expectation for employees as leaders feel the pressure to prove the returns on their hefty investments.  </p><p>Tokenmaxxing is the latest AI trend to come under fire as businesses want employees to use more AI in their work. In essence, this means boosting AI input to maximize AI output. On the surface, it sounds efficient and harmless. But underneath, it poses major security risks. </p><h2 id="tokenmaxxing-explained">Tokenmaxxing explained</h2><p>So what actually is tokenmaxxing?</p><p>A ‘token’ is a unit of data processed by an AI model. For example, a word or character inputted into an LLM search. So ‘tokenmaxxing’ quite simply means over-engineering generative AI prompts to get the most out of one search input. This can be anything from overly detailed prompts, to overloading an LLM chat with information, to asking an AI model for step-by-step breakdowns, as opposed to short summaries.</p><p>The trend is driven by businesses as leaders face pressure to prove the ROI of AI. It became a tongue-in-cheek benchmark of AI performance. Some companies, such as Meta, even gamified tokenmaxxing, measuring and ranking AI usage and citing the highest scorers ‘Token Legends’.</p><p>Their assumption is that AI usage means being AI-forward. But instead, companies need to consider the value they get from <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a>. They also need to keep security at the center of the conversation.</p><h2 id="the-hidden-costs-of-tokenmaxxing">The hidden costs of tokenmaxxing</h2><p>Although it might look like harmless corporate showboating, this trend poses a wide range of security risks given that LLM vendors are 52% more likely to be designated as “high risk” than traditional SaaS. This is due to access to sensitive data, IP, and internal workflows, so it’s imperative that <a href="https://www.techradar.com/best/best-business-cloud-storage-service">businesses</a> have oversight of how employees use these resources.</p><p>Rapid adoption of AI has led to an experimentation mindset. This is a positive shift from an innovation standpoint, but from a compliance perspective, a ‘trial and error’ approach is more error than trial.</p><p>The legacy tech systems most major enterprises are still reliant on are controlled by procurement and security teams and were not designed for the agility of AI technology. Meaning both innovation and compliance are lagging behind. It’s the latter that’s causing major concerns in the <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> world.  </p><p>When employees face mounting pressure to get the job done, they won’t wait for security teams to approve new tools, which results in shadow AI. This is where unmanaged, unapproved AI tools operate inside company environments without oversight.</p><p>Industry data shows that 70% of 16k cybersecurity customers currently have some form of shadow AI lurking within their organization, largely due to AI tools introduced through improper procurement channels that now have access to company data without oversight or guardrails.</p><p>There’s also been a 36% increase in shadow IT year-on-year, with organizations discovering, on average, around 140 Shadow IT tools accessing their environment within 90 days of connecting to the platform.</p><p>The bottom line is that AI adoption is drastically outpacing governance, and employees are prioritizing speed over control.</p><h2 id="how-businesses-can-defend-against-shadow-ai">How businesses can defend against Shadow AI</h2><p>The core issue isn’t tokenmaxxing itself; it’s businesses' inability to keep up with <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> demand for speedy access to the latest AI tools. This ultimately results in friction between the desire to safely onboard new tools and the ongoing pressure to use AI.</p><p>When security teams intervene and revoke access to unmanaged tools, employees just reinstall them. Industry data finds that within a 30-day period, the average enterprise sees employees reinstall revoked tools 100+ times. Within one year, it happens 1,000 times.</p><p>To bolster defenses, organizations must design their procurement systems to match the speed of AI innovation, so they can keep up with the rate of AI usage, as demonstrated by so-called ‘token legends’.</p><h2 id="three-actions-businesses-can-take-now">Three actions businesses can take now</h2><p>The more generative AI gets adopted in the corporate world, the more employees will face pressure to adopt and prove its ROI. Tokenmaxxing is just one hype within this wider picture. Businesses need to act fast to stop the gap between experimentation and control widening.</p><p>Three things leaders and compliance teams can kickstart today to bolster defenses against shadow AI are:</p><ul><li>Shrinking vendor review timelines so they match the speed of AI adoption</li><li>Set up continuous monitoring systems to detect threats caused by tokenmaxxing before they jeopardize safety</li><li>Implement employee training and policies for AI usage to ensure employees don’t expose sensitive data or IP</li></ul><p>The new mandate is matching speed with governance, and it’s up to <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> teams to lead the charge.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-chatbot-for-business"><em>We've featured the best AI chatbot for business.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This North Korean recruitment scam was so convincing it even fooled Google ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Lazarus expanded Dream Job with a zero‑day, new backdoor, and advanced relays</strong></li><li><strong>Fake job lures, trojanized PDFs, and spoofed sites enabled high‑level compromises</strong></li><li><strong>Targets included defense and aerospace firms, prompting stronger phishing awareness</strong></li></ul><p>Security experts from <a href="https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/" target="_blank">Check Point Research</a> say they have uncovered a new wave of "Operation Dream Job" attacks, leveraging a previously undocumented backdoor, a brand new Windows zero-day vulnerability, and a never-before-seen webshell/relay.</p><p>Lazarus Group is a hacking collective on the payroll of the North Korean government. It is a state-sponsored threat actor known for targeting cryptocurrency developers and other professionals in the Web3 industry, stealing their tokens and using the money to fund the country’s weapons program and the wider state apparatus.</p><p>It is also known for running Operation Dream Job - a hacking campaign that’s been going on for years, and that lures victims with highly lucrative but bogus job opportunities.</p><h2 id="what-is-operation-dream-job">What is Operation Dream Job?</h2><p>The scam works like this: the attackers come up with a fake company, often in the software development, defense, aerospace, or military industries. </p><p>They create the fake company’s website, LinkedIn account, as well as fake people supposedly employed there. Then, they reach out to their targets, offering great working conditions, amazing salaries, and an opportunity to work on exciting projects.</p><p>Victims that take the bait are then led through a series of “interviews” and somewhere along the line, they are either given weaponized PDF files or asked to download and run executables and other code, as part of a “training exercise” or “skill evaluation”. At this moment, the victims get compromised, while the attackers gain access to their actual employers’ infrastructure.</p><p>From there, the ending can be relatively different. Lazarus has, on at least one occasion, stolen <a href="https://www.techradar.com/pro/security/fbi-says-north-korean-lazarus-hackers-were-behind-usd1-5-billion-bybit-crypto-hack" target="_blank">more than a billion dollars</a> in cryptocurrency from one of its victims.</p><h2 id="ante-up">Ante up</h2><p>Perhaps the biggest finding is that Lazarus even managed to fool Google - fake Lockheed Martin and Enveil job postings all made it through filters, while spoofed, malicious websites were showing at the top of search results.</p><p>Then, there is the new Windows vulnerability the group has been exploiting. A zero-day, now tracked as CVE-2026-68820, is described as a “use-after-free bug in Windows Ancillary Function Driver for WinSock”, allowing authorized attackers to elevate privileges locally.</p><p>This bug was found in a core Windows networking component and allows an attacker who already deployed a piece of malware on the machine to escalate privileges to the highest level. Microsoft patched it on August 11 2026. </p><p>Lazarus used this bug to deploy a previously undocumented backdoor called Troy. This <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> comes with 17 commands, including file upload and download, interactive shell access, in-memory DLL injection, and process termination.</p><p>The group was also using compromised Roundcube webmail and CMS servers as C2 relays, instead of simply running their own infrastructure, and they were deploying a new PHP webshell called RelayShell. This one doesn’t behave like a conventional backdoor, since it passes commands and responses between victims and operators through text files. </p><p>In one of the observed infection chains, Check Point also found the crooks using SecurityPDF, a trojanized <a href="https://www.techradar.com/best/best-pdf-readers-for-windows" target="_blank">PDF viewer</a> which they were hosting on websites impersonating a legitimate business called Enveil. The drake viewer scans PDF files for a particular hidden marker and, if it finds it, decrypts it and loads Troy directly into memory. </p><p>Lazarus usually targets cryptocurrency and software developers. This time around, however, it set its sights on defense organizations, aerospace companies, as well as those working in aviation. Most of the victims are located in Europe and India, with confirmed activity in France, Germany, Brazil and India.</p><p>Check Point also said that not all victims were also targets - some of the organizations compromised in the attacks were later used as infrastructure. In at least one case, Lazarus compromised a Western European organization and used it to send spear-phishing messages to additional victims, effectively exploiting that organization’s reputation and trusted communications. </p><p>Since these attacks primarily start with a social engineering element, the best course of action is to educate employees on the dangers of phishing and the fact that, if someone is reaching out with a job offer too good to be true - it most likely is.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-north-korean-recruitment-scam-was-so-convincing-it-even-fooled-google</link>
                                                                            <description>
                            <![CDATA[ Fake sites were popping up at the top of search engine results pages and used to convince victims to download a trojanized PDF viewer. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BcxcZYRcAHfQvhcvJWD8HM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean flag with a hooded hacker]]></media:description>                                                            <media:text><![CDATA[North Korean flag with a hooded hacker]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean flag with a hooded hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Lazarus expanded Dream Job with a zero‑day, new backdoor, and advanced relays</strong></li><li><strong>Fake job lures, trojanized PDFs, and spoofed sites enabled high‑level compromises</strong></li><li><strong>Targets included defense and aerospace firms, prompting stronger phishing awareness</strong></li></ul><p>Security experts from <a href="https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/" target="_blank">Check Point Research</a> say they have uncovered a new wave of "Operation Dream Job" attacks, leveraging a previously undocumented backdoor, a brand new Windows zero-day vulnerability, and a never-before-seen webshell/relay.</p><p>Lazarus Group is a hacking collective on the payroll of the North Korean government. It is a state-sponsored threat actor known for targeting cryptocurrency developers and other professionals in the Web3 industry, stealing their tokens and using the money to fund the country’s weapons program and the wider state apparatus.</p><p>It is also known for running Operation Dream Job - a hacking campaign that’s been going on for years, and that lures victims with highly lucrative but bogus job opportunities.</p><h2 id="what-is-operation-dream-job">What is Operation Dream Job?</h2><p>The scam works like this: the attackers come up with a fake company, often in the software development, defense, aerospace, or military industries. </p><p>They create the fake company’s website, LinkedIn account, as well as fake people supposedly employed there. Then, they reach out to their targets, offering great working conditions, amazing salaries, and an opportunity to work on exciting projects.</p><p>Victims that take the bait are then led through a series of “interviews” and somewhere along the line, they are either given weaponized PDF files or asked to download and run executables and other code, as part of a “training exercise” or “skill evaluation”. At this moment, the victims get compromised, while the attackers gain access to their actual employers’ infrastructure.</p><p>From there, the ending can be relatively different. Lazarus has, on at least one occasion, stolen <a href="https://www.techradar.com/pro/security/fbi-says-north-korean-lazarus-hackers-were-behind-usd1-5-billion-bybit-crypto-hack" target="_blank">more than a billion dollars</a> in cryptocurrency from one of its victims.</p><h2 id="ante-up">Ante up</h2><p>Perhaps the biggest finding is that Lazarus even managed to fool Google - fake Lockheed Martin and Enveil job postings all made it through filters, while spoofed, malicious websites were showing at the top of search results.</p><p>Then, there is the new Windows vulnerability the group has been exploiting. A zero-day, now tracked as CVE-2026-68820, is described as a “use-after-free bug in Windows Ancillary Function Driver for WinSock”, allowing authorized attackers to elevate privileges locally.</p><p>This bug was found in a core Windows networking component and allows an attacker who already deployed a piece of malware on the machine to escalate privileges to the highest level. Microsoft patched it on August 11 2026. </p><p>Lazarus used this bug to deploy a previously undocumented backdoor called Troy. This <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> comes with 17 commands, including file upload and download, interactive shell access, in-memory DLL injection, and process termination.</p><p>The group was also using compromised Roundcube webmail and CMS servers as C2 relays, instead of simply running their own infrastructure, and they were deploying a new PHP webshell called RelayShell. This one doesn’t behave like a conventional backdoor, since it passes commands and responses between victims and operators through text files. </p><p>In one of the observed infection chains, Check Point also found the crooks using SecurityPDF, a trojanized <a href="https://www.techradar.com/best/best-pdf-readers-for-windows" target="_blank">PDF viewer</a> which they were hosting on websites impersonating a legitimate business called Enveil. The drake viewer scans PDF files for a particular hidden marker and, if it finds it, decrypts it and loads Troy directly into memory. </p><p>Lazarus usually targets cryptocurrency and software developers. This time around, however, it set its sights on defense organizations, aerospace companies, as well as those working in aviation. Most of the victims are located in Europe and India, with confirmed activity in France, Germany, Brazil and India.</p><p>Check Point also said that not all victims were also targets - some of the organizations compromised in the attacks were later used as infrastructure. In at least one case, Lazarus compromised a Western European organization and used it to send spear-phishing messages to additional victims, effectively exploiting that organization’s reputation and trusted communications. </p><p>Since these attacks primarily start with a social engineering element, the best course of action is to educate employees on the dangers of phishing and the fact that, if someone is reaching out with a job offer too good to be true - it most likely is.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘TikTok may be used on government devices’: Trump administration removes TikTok ban on government phones, so employees are now free to doomscroll once again ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>The Trump administration has lifted the TikTok ban for federal devices</strong></li><li><strong>The app was banned from being installed by government employees in 2022</strong></li><li><strong>TikTok in America is now majority owned by a US company, with ByteDance still holding around a 20% share</strong></li></ul><p>The Trump administration has lifted a ban on government employees having TikTok on their mobile devices.</p><p>The law was introduced in 2022 when TikTok was deemed to be a national security threat because of potential ties between TikTok’s parent company ByteDance, and the Chinese government.</p><p>A memo released by the Office of Management and Budget (OMB) states, “TikTok may be used on government devices.”</p><h2 id="government-to-go-back-to-doomscrolling">Government to go back to doomscrolling</h2><p>The details as to why the government banned the app in the first place have not been fully disclosed. Discussions within the senate centered around data collection and Chinese government influence over the app’s algorithm.</p><p><a href="https://www.techradar.com/computing/cyber-security/tiktok-to-be-saved-in-the-us-as-trump-confirms-a-deal-with-china-ahead-of-upcoming-ban">TikTok briefly went offline in the US in 2025</a> as the Trump administration forced ByteDance to sell the app to American owners or have the app be permanently blacklisted in the US.</p><p>The two settled on having an American version of the app for American audiences controlled by TikTok USDS Joint Venture.</p><p>The Department of Transportation, Treasury Department, and Health and Human Services have all since created official accounts on the app and have begun posting. The White House also has an official account which mainly posts hype edits of the President.</p><p>Via <a href="https://www.engadget.com/2235010/government-workers-can-officially-waste-time-scrolling-tiktok-again/" target="_blank"><em>Engadget</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/tiktok-may-be-used-on-government-devices-trump-administration-removes-tiktok-ban-on-government-phones-so-employees-are-now-free-to-doomscroll-once-again</link>
                                                                            <description>
                            <![CDATA[ The US government has lifted the ban on TikTok being installed on government devices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Nk7HzCowcX9FXAeH86JDcF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Caa2mzJkJUGpLHopsEdCMZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 16:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Tiktok]]></category>
                                                    <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Caa2mzJkJUGpLHopsEdCMZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Photo by Jaap Arriens/NurPhoto via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The TikTok logo is seen on a mobile device, with a picture of US President Trump in the background]]></media:description>                                                            <media:text><![CDATA[The TikTok logo is seen on a mobile device, with a picture of US President Trump in the background]]></media:text>
                                <media:title type="plain"><![CDATA[The TikTok logo is seen on a mobile device, with a picture of US President Trump in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Caa2mzJkJUGpLHopsEdCMZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The Trump administration has lifted the TikTok ban for federal devices</strong></li><li><strong>The app was banned from being installed by government employees in 2022</strong></li><li><strong>TikTok in America is now majority owned by a US company, with ByteDance still holding around a 20% share</strong></li></ul><p>The Trump administration has lifted a ban on government employees having TikTok on their mobile devices.</p><p>The law was introduced in 2022 when TikTok was deemed to be a national security threat because of potential ties between TikTok’s parent company ByteDance, and the Chinese government.</p><p>A memo released by the Office of Management and Budget (OMB) states, “TikTok may be used on government devices.”</p><h2 id="government-to-go-back-to-doomscrolling">Government to go back to doomscrolling</h2><p>The details as to why the government banned the app in the first place have not been fully disclosed. Discussions within the senate centered around data collection and Chinese government influence over the app’s algorithm.</p><p><a href="https://www.techradar.com/computing/cyber-security/tiktok-to-be-saved-in-the-us-as-trump-confirms-a-deal-with-china-ahead-of-upcoming-ban">TikTok briefly went offline in the US in 2025</a> as the Trump administration forced ByteDance to sell the app to American owners or have the app be permanently blacklisted in the US.</p><p>The two settled on having an American version of the app for American audiences controlled by TikTok USDS Joint Venture.</p><p>The Department of Transportation, Treasury Department, and Health and Human Services have all since created official accounts on the app and have begun posting. The White House also has an official account which mainly posts hype edits of the President.</p><p>Via <a href="https://www.engadget.com/2235010/government-workers-can-officially-waste-time-scrolling-tiktok-again/" target="_blank"><em>Engadget</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why organizations are falling into an AI Security Illusion ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Many organizations believe they are successfully leveraging <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> to strengthen their security posture. </p><p>Investment is rising, AI is being embedded across multiple workloads and workflows, and governance frameworks continue to expand, giving the impression on the surface that progress is being made. </p><p>But beneath this AI adoption lies an unseen problem: a growing gap between what organizations believe about their infrastructure security, and what they can actually evidence. </p><h2 id="confidence-is-rising-but-so-are-breaches">Confidence is rising, but so are breaches</h2><p>According to a global 2026 Hybrid Cloud Security Survey, which gathered the views of more than 1,000 Security and IT leaders, 93 percent have invested in new security technologies, yet despite this, breach rates have hit their highest point. Sixty-five per cent of organizations experienced a data breach in the past 12 months, an 18 percent rise year on year, and a near 40 percent rise over three years. </p><p>These worrying statistics are starting to ring alarm bells, highlighting that within organizations we are starting to see an ‘illusion of security’ creeping in. Organizations are investing heavily in <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> tools,  yet still seem to lack clear visibility into the outcomes of their investments. In other words,  leaving security to be measured by what has been implemented, rather than what can actually be verified.</p><p>A perfect storm of conditions has brought us to this point: AI adoption has scaled faster than governance and security teams can keep pace with, and hybrid <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a> has added another dimension of complexity that few organizations have fully reckoned with.</p><p>AI is now embedded across enterprise environments, accelerating not just how organizations operate, but how risk moves through them. As adoption has outpaced oversight, the consequences are starting to surface, with nearly half of organizations surveyed reporting a rise in AI-related insider threats, including data leaks, and unsanctioned use (shadow AI). Perhaps surprisingly confidence hasn't reduced. Many organizations continue to classify their AI security posture as "defined" or "integrated," despite evidence portraying a radically different story.</p><p>That confidence often rests on assumptions, and the scale of the disconnect is striking; AI is now involved in 83 percent of security incidents, spanning external attacks, internal exposures, and direct targeting of AI systems. As threats move faster across increasingly fragmented and distributed environments, assumptions about what’s secure quickly fall apart and without clear visibility into how data moves and systems behave, organizations cannot reliably manage risk.</p><h2 id="the-warning-signs">The warning signs</h2><p>No single indicator reveals a false sense of AI security, but several recurring patterns make it obvious.</p><p>The first is investment without impact. Many organizations are expanding their security stacks, yet detection and response times are still moving in the wrong direction. More than 40 percent report that it now takes longer to detect and investigate breaches than it did previously, and that's not a coincidence. </p><p>When signals are spread across systems that don't connect, teams spend longer piecing together what happened rather than acting on it. Adding tools without improving visibility doesn't create more clarity. It creates more data, and more data without context is just more noise to wade through not to mention more false positives and perhaps even worse more false negatives.  </p><p>The second is an inability to trace incidents back to their source. More than one in four organizations cannot determine the root cause of a breach, which means incidents are being closed out without fully understanding how they happened. The consequences are predictable: nearly one-third of organizations report multiple incidents within the same year. Without traceability, there is no learning, and without learning, the same gaps simply get exploited again.</p><p>The third is the visibility gap opening in AI-driven environments. With nearly three-quarters of organizations reporting limited visibility into AI-driven data flows, which span APIs, models, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a>, and distributed infrastructure that is dynamic by design and doesn't map cleanly onto traditional monitoring approaches. Security teams can often see that something happened, but simply can’t get to the how or the why. That gap between knowing an incident occurred and understanding it, is exactly where the illusion lives.</p><h2 id="moving-from-illusion-to-evidence">Moving from illusion to evidence</h2><p>In response to growing complexity, organizations are collecting more telemetry than ever; metrics, events, logs and traces (MELT data), but more data does not necessarily equate to better understanding. These signals each offer only a partial view: one measures performance, another records activity, other flags issues after the fact. </p><p>None of them, on their own, are able to explain how systems behave as a whole. What’s missing is the connective tissue, the context that shows how these signals relate, how one event triggers another, and how issues propagate across the environment. Without that, organizations aren’t gaining insight; they’re just accumulating noise.</p><p>Shattering the AI ‘security illusion’ requires a shift from reactive security to proactive monitoring and real-time observation of how systems behave. Security leaders agree, with more than 90 percent of organizations reporting that complete visibility across data in motion is critical to their successful security outcomes. </p><p>This is where network-derived telemetry becomes essential. Unlike logs, which show what systems say they’re doing, network telemetry proves what is happening: how data moves, how systems interact, and how threats develop. It's the shift from assumption to evidence and then proof, and it's the only foundation solid enough to build real security on. The network is the source of truth for today’s security teams.</p><h2 id="ai-security-must-be-measured-not-assumed">AI security must be measured, not assumed</h2><p>AI is reshaping the threat landscape, enabling faster, more adaptive attacks while increasing the complexity of enterprise environments. But defenders are not without their own advantages. </p><p>The same technologies fueling attacks are already supporting security teams, automating detection, accelerating response, and investment in these capabilities continues to grow.</p><p>But let there be no mistake: investment is not proof. Security must be measured by the ability to observe, understand, and validate what is actually happening across the environment. </p><p>In the age of AI, the real risk is not organizations underinvesting in security, but the belief that they are secure without the evidence to prove it.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-backup"><em>We've reviewed, rated, and ranked the best cloud backup</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/why-organizations-are-falling-into-an-ai-security-illusion</link>
                                                                            <description>
                            <![CDATA[ If AI strengthens security, why do organizations continue to suffer breaches? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ztCCsPmiPEsGZaQpY9QqRF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 14:39:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danielle Kinsella ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Many organizations believe they are successfully leveraging <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> to strengthen their security posture. </p><p>Investment is rising, AI is being embedded across multiple workloads and workflows, and governance frameworks continue to expand, giving the impression on the surface that progress is being made. </p><p>But beneath this AI adoption lies an unseen problem: a growing gap between what organizations believe about their infrastructure security, and what they can actually evidence. </p><h2 id="confidence-is-rising-but-so-are-breaches">Confidence is rising, but so are breaches</h2><p>According to a global 2026 Hybrid Cloud Security Survey, which gathered the views of more than 1,000 Security and IT leaders, 93 percent have invested in new security technologies, yet despite this, breach rates have hit their highest point. Sixty-five per cent of organizations experienced a data breach in the past 12 months, an 18 percent rise year on year, and a near 40 percent rise over three years. </p><p>These worrying statistics are starting to ring alarm bells, highlighting that within organizations we are starting to see an ‘illusion of security’ creeping in. Organizations are investing heavily in <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> tools,  yet still seem to lack clear visibility into the outcomes of their investments. In other words,  leaving security to be measured by what has been implemented, rather than what can actually be verified.</p><p>A perfect storm of conditions has brought us to this point: AI adoption has scaled faster than governance and security teams can keep pace with, and hybrid <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a> has added another dimension of complexity that few organizations have fully reckoned with.</p><p>AI is now embedded across enterprise environments, accelerating not just how organizations operate, but how risk moves through them. As adoption has outpaced oversight, the consequences are starting to surface, with nearly half of organizations surveyed reporting a rise in AI-related insider threats, including data leaks, and unsanctioned use (shadow AI). Perhaps surprisingly confidence hasn't reduced. Many organizations continue to classify their AI security posture as "defined" or "integrated," despite evidence portraying a radically different story.</p><p>That confidence often rests on assumptions, and the scale of the disconnect is striking; AI is now involved in 83 percent of security incidents, spanning external attacks, internal exposures, and direct targeting of AI systems. As threats move faster across increasingly fragmented and distributed environments, assumptions about what’s secure quickly fall apart and without clear visibility into how data moves and systems behave, organizations cannot reliably manage risk.</p><h2 id="the-warning-signs">The warning signs</h2><p>No single indicator reveals a false sense of AI security, but several recurring patterns make it obvious.</p><p>The first is investment without impact. Many organizations are expanding their security stacks, yet detection and response times are still moving in the wrong direction. More than 40 percent report that it now takes longer to detect and investigate breaches than it did previously, and that's not a coincidence. </p><p>When signals are spread across systems that don't connect, teams spend longer piecing together what happened rather than acting on it. Adding tools without improving visibility doesn't create more clarity. It creates more data, and more data without context is just more noise to wade through not to mention more false positives and perhaps even worse more false negatives.  </p><p>The second is an inability to trace incidents back to their source. More than one in four organizations cannot determine the root cause of a breach, which means incidents are being closed out without fully understanding how they happened. The consequences are predictable: nearly one-third of organizations report multiple incidents within the same year. Without traceability, there is no learning, and without learning, the same gaps simply get exploited again.</p><p>The third is the visibility gap opening in AI-driven environments. With nearly three-quarters of organizations reporting limited visibility into AI-driven data flows, which span APIs, models, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a>, and distributed infrastructure that is dynamic by design and doesn't map cleanly onto traditional monitoring approaches. Security teams can often see that something happened, but simply can’t get to the how or the why. That gap between knowing an incident occurred and understanding it, is exactly where the illusion lives.</p><h2 id="moving-from-illusion-to-evidence">Moving from illusion to evidence</h2><p>In response to growing complexity, organizations are collecting more telemetry than ever; metrics, events, logs and traces (MELT data), but more data does not necessarily equate to better understanding. These signals each offer only a partial view: one measures performance, another records activity, other flags issues after the fact. </p><p>None of them, on their own, are able to explain how systems behave as a whole. What’s missing is the connective tissue, the context that shows how these signals relate, how one event triggers another, and how issues propagate across the environment. Without that, organizations aren’t gaining insight; they’re just accumulating noise.</p><p>Shattering the AI ‘security illusion’ requires a shift from reactive security to proactive monitoring and real-time observation of how systems behave. Security leaders agree, with more than 90 percent of organizations reporting that complete visibility across data in motion is critical to their successful security outcomes. </p><p>This is where network-derived telemetry becomes essential. Unlike logs, which show what systems say they’re doing, network telemetry proves what is happening: how data moves, how systems interact, and how threats develop. It's the shift from assumption to evidence and then proof, and it's the only foundation solid enough to build real security on. The network is the source of truth for today’s security teams.</p><h2 id="ai-security-must-be-measured-not-assumed">AI security must be measured, not assumed</h2><p>AI is reshaping the threat landscape, enabling faster, more adaptive attacks while increasing the complexity of enterprise environments. But defenders are not without their own advantages. </p><p>The same technologies fueling attacks are already supporting security teams, automating detection, accelerating response, and investment in these capabilities continues to grow.</p><p>But let there be no mistake: investment is not proof. Security must be measured by the ability to observe, understand, and validate what is actually happening across the environment. </p><p>In the age of AI, the real risk is not organizations underinvesting in security, but the belief that they are secure without the evidence to prove it.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-backup"><em>We've reviewed, rated, and ranked the best cloud backup</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google says Chrome blocked seven billion malicious Android notifications every day in its bid to cut down on scams ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Google cut seven billion daily Android Chrome notifications using layered defenses</strong></li><li><strong>Chrome now limits abusive sites, revokes permissions, and blocks high‑volume spam</strong></li><li><strong>Android improvements simplify managing alerts and reduce scam and malware exposure</strong></li></ul><p>Google says it has cut the number of notifications Chrome users get on their Android devices by seven billion a day. </p><p>In a new <a href="https://blog.google/security/the-multi-layered-defenses-that-harden-chrome-against-abusive-notifications/" target="_blank" rel="nofollow">report</a>, the company outlined how it has built a multi-layered defense system to shield its users from unwanted notifications, protecting them from spam and malware, and helping their devices’ battery last longer. </p><p>Most importantly, Google says the achievement significantly improved the overall user experience on Android. </p><h2 id="notification-bombardment">Notification bombardment</h2><p>For the longest time, individual websites were allowed to send push notifications directly to their users’ phones, even when they were not actively browsing them. </p><p>When a user visits a certain website, they get prompted to “show notifications”, and if they tap “allow”, the website starts sending the alerts. Sometimes, users do it without fully realizing what they’re agreeing to.</p><p>Once granted, the notifications (sent through Chrome) get shown next to other alerts (such as the ones coming from WhatsApp, Gmail, or other apps). </p><p>Unlike other notifications - which usually alert users to unread messages, calendar events, or similar - these mostly promote new content, deals, or other updates. They can also alert users of breaking news, which is arguably the most useful type among the ones mentioned here. </p><p>Legitimate websites use the feature responsibly and generally don’t flood their users with unwanted pings. However, some sites abuse the privilege, bombarding users with unwanted advertising, misleading alerts, clickbait articles, and other formats, just to get them to open the page (where they’re often served ads). More worryingly, malicious or compromised websites can use notifications to push scam messages, fake virus warnings, phishing links or other potentially dangerous content. </p><p>Because these alerts are served through Chrome and resemble ordinary system notifications, users may not immediately realize the risk. </p><p>But because they are served through Chrome, Google can do something about it, and the company has now “pulled back the curtain” on the toolkit that made these improvements possible.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:800px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="M8dLsateSbGVwYwoPrRba3" name="mobile security.jpg" alt="Mobile Security" src="https://cdn.mos.cms.futurecdn.net/M8dLsateSbGVwYwoPrRba3.jpg" mos="" align="middle" fullscreen="" width="800" height="450" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock.com)</span></figcaption></figure><h2 id="swiss-cheese">Swiss cheese</h2><p>Described as a “swiss cheese” model, Google says it created overlapping protections that cover the entire notification lifecycle. Chrome now automatically revokes notification permissions for sites users haven’t engaged with in a little while. </p><p>So, if a site keeps flooding the visitor with notifications that they’re not responding to, Chrome will eventually shut them off. Same goes for sites that have “repeatedly received suspicious notification warnings”. Google did not say how many is considered “repeatedly” and in what timeframe.</p><p>The second layer is analyzing signals such as service worker activity. By looking for coordinated behaviors, Google claims it can now pinpoint networks that serve malicious content, and block them. </p><p>On the Firebase Cloud Messaging (FCM) server side, the company introduced message rate limits that disallow high-volume notification abuse. Google now evaluates sites based on factors such as message volume relative to time spent on site, the frequency of permission prompts, and general engagement levels.</p><p>In other words, if a user spends 10 minutes on a website but then receives 50 notifications, it will raise quite a few red flags. Same goes for users that don’t really interact with the website a lot. “Disruptive domains” are now limited to 1,000 messages per minute and will receive HTTP 429 responses if they exceed this threshold, Google explained.</p><p>Finally, the company updated how notifications are handled on Android phones. Users can update their preferences directly from the notification bar, simplifying the process for users who can’t be bothered to dig deep into system settings. </p><p>“These integrated efforts effectively shield users from sophisticated scams that leverage notifications to distribute malware, harvest personal information, or solicit fraudulent payments,” Google said. </p><p>“Beyond security enhancements, this strategy has substantially decreased unnecessary background activity, reduced user device battery consumption, and transformed the notification lifecycle so users receive only the content they find truly valuable.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/google-says-chrome-blocked-seven-billion-malicious-android-notifications-every-day-in-its-bid-to-cut-down-on-scams</link>
                                                                            <description>
                            <![CDATA[ A "Swiss cheese" approach to defense seems to be working, as the number of unwanted notifications dwindles. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">DYTMghKLR3LUcJNVnvbzV4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/o9BDDKXmm9T4Lqtm38fsmV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/o9BDDKXmm9T4Lqtm38fsmV-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Annoyed man with phone]]></media:description>                                                            <media:text><![CDATA[Annoyed man with phone]]></media:text>
                                <media:title type="plain"><![CDATA[Annoyed man with phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/o9BDDKXmm9T4Lqtm38fsmV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Google cut seven billion daily Android Chrome notifications using layered defenses</strong></li><li><strong>Chrome now limits abusive sites, revokes permissions, and blocks high‑volume spam</strong></li><li><strong>Android improvements simplify managing alerts and reduce scam and malware exposure</strong></li></ul><p>Google says it has cut the number of notifications Chrome users get on their Android devices by seven billion a day. </p><p>In a new <a href="https://blog.google/security/the-multi-layered-defenses-that-harden-chrome-against-abusive-notifications/" target="_blank" rel="nofollow">report</a>, the company outlined how it has built a multi-layered defense system to shield its users from unwanted notifications, protecting them from spam and malware, and helping their devices’ battery last longer. </p><p>Most importantly, Google says the achievement significantly improved the overall user experience on Android. </p><h2 id="notification-bombardment">Notification bombardment</h2><p>For the longest time, individual websites were allowed to send push notifications directly to their users’ phones, even when they were not actively browsing them. </p><p>When a user visits a certain website, they get prompted to “show notifications”, and if they tap “allow”, the website starts sending the alerts. Sometimes, users do it without fully realizing what they’re agreeing to.</p><p>Once granted, the notifications (sent through Chrome) get shown next to other alerts (such as the ones coming from WhatsApp, Gmail, or other apps). </p><p>Unlike other notifications - which usually alert users to unread messages, calendar events, or similar - these mostly promote new content, deals, or other updates. They can also alert users of breaking news, which is arguably the most useful type among the ones mentioned here. </p><p>Legitimate websites use the feature responsibly and generally don’t flood their users with unwanted pings. However, some sites abuse the privilege, bombarding users with unwanted advertising, misleading alerts, clickbait articles, and other formats, just to get them to open the page (where they’re often served ads). More worryingly, malicious or compromised websites can use notifications to push scam messages, fake virus warnings, phishing links or other potentially dangerous content. </p><p>Because these alerts are served through Chrome and resemble ordinary system notifications, users may not immediately realize the risk. </p><p>But because they are served through Chrome, Google can do something about it, and the company has now “pulled back the curtain” on the toolkit that made these improvements possible.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:800px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="M8dLsateSbGVwYwoPrRba3" name="mobile security.jpg" alt="Mobile Security" src="https://cdn.mos.cms.futurecdn.net/M8dLsateSbGVwYwoPrRba3.jpg" mos="" align="middle" fullscreen="" width="800" height="450" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock.com)</span></figcaption></figure><h2 id="swiss-cheese">Swiss cheese</h2><p>Described as a “swiss cheese” model, Google says it created overlapping protections that cover the entire notification lifecycle. Chrome now automatically revokes notification permissions for sites users haven’t engaged with in a little while. </p><p>So, if a site keeps flooding the visitor with notifications that they’re not responding to, Chrome will eventually shut them off. Same goes for sites that have “repeatedly received suspicious notification warnings”. Google did not say how many is considered “repeatedly” and in what timeframe.</p><p>The second layer is analyzing signals such as service worker activity. By looking for coordinated behaviors, Google claims it can now pinpoint networks that serve malicious content, and block them. </p><p>On the Firebase Cloud Messaging (FCM) server side, the company introduced message rate limits that disallow high-volume notification abuse. Google now evaluates sites based on factors such as message volume relative to time spent on site, the frequency of permission prompts, and general engagement levels.</p><p>In other words, if a user spends 10 minutes on a website but then receives 50 notifications, it will raise quite a few red flags. Same goes for users that don’t really interact with the website a lot. “Disruptive domains” are now limited to 1,000 messages per minute and will receive HTTP 429 responses if they exceed this threshold, Google explained.</p><p>Finally, the company updated how notifications are handled on Android phones. Users can update their preferences directly from the notification bar, simplifying the process for users who can’t be bothered to dig deep into system settings. </p><p>“These integrated efforts effectively shield users from sophisticated scams that leverage notifications to distribute malware, harvest personal information, or solicit fraudulent payments,” Google said. </p><p>“Beyond security enhancements, this strategy has substantially decreased unnecessary background activity, reduced user device battery consumption, and transformed the notification lifecycle so users receive only the content they find truly valuable.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A dangerous Zoom screen-sharing bug could have let hackers hijack other devices on a call ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>AI‑found Zoom flaws enabled device takeover through malicious annotation messages</strong></li><li><strong>Exploits worked across all platforms and required only joining a video call</strong></li><li><strong>Researchers warn AI now enables rapid, nation‑state‑level exploit development</strong></li></ul><p>Experts have warned that Zoom, one of the most popular collaboration tools in the world, carried multiple vulnerabilities that allowed malicious actors to take over people’s devices, entirely. </p><p>What makes these vulnerabilities particularly dangerous is that the victims need not do much to be compromised - participating in a video call with the attacker is enough.</p><p>The bugs were said to be present in every version of Zoom, on every device and operating system - Windows, Mac, iPhone, Android, and Linux, in all versions up to and including 7.0.5 - with patches available now, so be sure to update immediately.</p><h2 id="ai-powered-security">AI-powered security</h2><p>The flaws were <a href="https://a.security/blog/asecurity-zoomsday" target="_blank" rel="nofollow">discovered</a> by security researchers A Security, which focuses on “autonomous offensive security”, using AI agents to simulate real-work attacks, identify vulnerabilities, and chain them into exploitable attack paths. </p><p>The company “simply” used publicly available frontier models and within 24 hours and fewer than 20 prompts, went from finding the flaws to building a working exploit. </p><p>The flaws are described as memory corruption bugs exploiting Zoom’s annotation feature. That feature, built on a proprietary protocol (meaning it has no public documentation or specifications, as opposed to being open source), meant that the Zoom client parsed everything it received, including specially crafted, malicious messages.</p><p>During the call, a malicious actor could send a message to each visitor that would corrupt their device’s memory and execute weaponized code, all without the victim knowing, being prompted to do anything, or clicking anything at all. </p><p>The vulnerability can be exploited regardless of if the attacker hosted, or simply joined, a call. All participants, regardless of their status in the call, were equally at risk. There were no visual cues indicating the compromise whatsoever. </p><p>Once the threat actor runs the malware on the victim’s device, they can do all sorts of things, from stealing sensitive files, to switching on the device’s camera or microphone. They can also deploy stage-two malware, steal login credentials and crypto wallet information, access the inbox, and more. </p><p>A Security responsibly disclosed their findings to Zoom, who labeled the vulnerabilities as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, and all given a severity score of 9.0/10 (critical). </p><p>Furthermore, all Zoom Workplace clients on all supported platforms before version 7.1.5 and 7.0.6 using end-to-end encryption settings are considered vulnerable. A Security recommends updating the client to the latest version. </p><h2 id="lowering-the-barrier">Lowering the barrier</h2><p>In its writeup, A Security stressed the simplicity and ease with which it managed to find the bugs and develop the exploits. It warned that AI has dramatically lowered the barrier for entry, and argued that in the pre-AI era, exploits like these were “reserved” for nation-state threat actors with virtually limitless resources:</p><p>“This class of capability would previously have only been available to nation-state threat actors, but the model requiring elite teams, months of effort, and weapons-grade budgets has collapsed,” the researchers warned. “Today, a single researcher was able to develop a nation-state-level exploit in less than a day.”</p><p>To add insult to injury, these flaws were found using “publicly available frontier models” such as GPT-5.6 Sol, Claude Opus 5, and the likes. Besides the frontier models, these companies also have dedicated cybersecurity programs where they offer specialized models with fewer guardrails and more flexibility for both offensive and defensive actions. </p><p>Earlier this week, OpenAI said that its Daybreak project now offers GPT-5.6-Cyber, a model built on GPT‑5.6 Sol and trained to improve capabilities on several specialized cybersecurity tasks such as finding zero-day vulnerabilities and developing exploit chains.</p><p>Daybreak came as a direct response to Anthropic’s Project Glasswing. This is an offering that came with Mythos Preview, an AI model that proved unusually capable at cybersecurity tasks. Allegedly, Mythos can autonomously identify and exploit zero-day flaws across major operating systems and browsers, as well as develop complex exploit chains. Because of those capabilities, Anthropic did not release Mythos Preview broadly. Instead, it made the model available to a limited group of organizations.</p><p>While some expressed their skepticism over Mythos, saying Anthropic is engaging in <a href="https://techcrunch.com/2026/04/21/sam-altman-throws-shade-at-anthropics-cyber-model-mythos-fear-based-marketing/" target="_blank"><u>fear-based marketing</u></a>, others have backed the company, saying Mythos proved exceptionally useful at identifying and fixing flaws. Microsoft, for example, is one of the original Project Glasswing partners, and ever since it started using it, the number of flaws patched through its Patch Tuesday cumulative update <a href="https://www.techradar.com/pro/security/microsoft-just-released-its-biggest-patch-tuesday-ever-with-a-mammoth-622-fixes-including-three-dangerous-zero-days" target="_blank"><u>quadrupled</u></a>.</p><p>Mozilla is also among those showering Mythos with praise, saying earlier this year that it is “<a href="https://www.techradar.com/pro/mozilla-says-anthropics-mythos-is-every-bit-as-capable-as-the-worlds-best-security-researchers-after-firefox-experiment-and-says-the-zero-days-are-numbered" target="_blank"><u>every bit as capable</u></a>” as the world’s best security researchers.</p><p>If A Security managed to find such dangerous flaws with publicly available models, there’s no telling what these dedicated models can do.</p><p><em>Via </em><a href="https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html" target="_blank"><em>The Hacker News</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/a-dangerous-zoom-screen-sharing-bug-could-have-let-hackers-hijack-other-devices-on-a-call</link>
                                                                            <description>
                            <![CDATA[ It doesn't matter if the attacker is the host or a participant. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">V4iS9gg8ADwLuvqhJmnGxH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/q7LJWDP3HaKLzyUesaBUh7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 12:56:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/q7LJWDP3HaKLzyUesaBUh7-1280-80.jpg">
                                                            <media:credit><![CDATA[Zoom]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Zoom app running in macOS.]]></media:description>                                                            <media:text><![CDATA[The Zoom app running in macOS.]]></media:text>
                                <media:title type="plain"><![CDATA[The Zoom app running in macOS.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/q7LJWDP3HaKLzyUesaBUh7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>AI‑found Zoom flaws enabled device takeover through malicious annotation messages</strong></li><li><strong>Exploits worked across all platforms and required only joining a video call</strong></li><li><strong>Researchers warn AI now enables rapid, nation‑state‑level exploit development</strong></li></ul><p>Experts have warned that Zoom, one of the most popular collaboration tools in the world, carried multiple vulnerabilities that allowed malicious actors to take over people’s devices, entirely. </p><p>What makes these vulnerabilities particularly dangerous is that the victims need not do much to be compromised - participating in a video call with the attacker is enough.</p><p>The bugs were said to be present in every version of Zoom, on every device and operating system - Windows, Mac, iPhone, Android, and Linux, in all versions up to and including 7.0.5 - with patches available now, so be sure to update immediately.</p><h2 id="ai-powered-security">AI-powered security</h2><p>The flaws were <a href="https://a.security/blog/asecurity-zoomsday" target="_blank" rel="nofollow">discovered</a> by security researchers A Security, which focuses on “autonomous offensive security”, using AI agents to simulate real-work attacks, identify vulnerabilities, and chain them into exploitable attack paths. </p><p>The company “simply” used publicly available frontier models and within 24 hours and fewer than 20 prompts, went from finding the flaws to building a working exploit. </p><p>The flaws are described as memory corruption bugs exploiting Zoom’s annotation feature. That feature, built on a proprietary protocol (meaning it has no public documentation or specifications, as opposed to being open source), meant that the Zoom client parsed everything it received, including specially crafted, malicious messages.</p><p>During the call, a malicious actor could send a message to each visitor that would corrupt their device’s memory and execute weaponized code, all without the victim knowing, being prompted to do anything, or clicking anything at all. </p><p>The vulnerability can be exploited regardless of if the attacker hosted, or simply joined, a call. All participants, regardless of their status in the call, were equally at risk. There were no visual cues indicating the compromise whatsoever. </p><p>Once the threat actor runs the malware on the victim’s device, they can do all sorts of things, from stealing sensitive files, to switching on the device’s camera or microphone. They can also deploy stage-two malware, steal login credentials and crypto wallet information, access the inbox, and more. </p><p>A Security responsibly disclosed their findings to Zoom, who labeled the vulnerabilities as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, and all given a severity score of 9.0/10 (critical). </p><p>Furthermore, all Zoom Workplace clients on all supported platforms before version 7.1.5 and 7.0.6 using end-to-end encryption settings are considered vulnerable. A Security recommends updating the client to the latest version. </p><h2 id="lowering-the-barrier">Lowering the barrier</h2><p>In its writeup, A Security stressed the simplicity and ease with which it managed to find the bugs and develop the exploits. It warned that AI has dramatically lowered the barrier for entry, and argued that in the pre-AI era, exploits like these were “reserved” for nation-state threat actors with virtually limitless resources:</p><p>“This class of capability would previously have only been available to nation-state threat actors, but the model requiring elite teams, months of effort, and weapons-grade budgets has collapsed,” the researchers warned. “Today, a single researcher was able to develop a nation-state-level exploit in less than a day.”</p><p>To add insult to injury, these flaws were found using “publicly available frontier models” such as GPT-5.6 Sol, Claude Opus 5, and the likes. Besides the frontier models, these companies also have dedicated cybersecurity programs where they offer specialized models with fewer guardrails and more flexibility for both offensive and defensive actions. </p><p>Earlier this week, OpenAI said that its Daybreak project now offers GPT-5.6-Cyber, a model built on GPT‑5.6 Sol and trained to improve capabilities on several specialized cybersecurity tasks such as finding zero-day vulnerabilities and developing exploit chains.</p><p>Daybreak came as a direct response to Anthropic’s Project Glasswing. This is an offering that came with Mythos Preview, an AI model that proved unusually capable at cybersecurity tasks. Allegedly, Mythos can autonomously identify and exploit zero-day flaws across major operating systems and browsers, as well as develop complex exploit chains. Because of those capabilities, Anthropic did not release Mythos Preview broadly. Instead, it made the model available to a limited group of organizations.</p><p>While some expressed their skepticism over Mythos, saying Anthropic is engaging in <a href="https://techcrunch.com/2026/04/21/sam-altman-throws-shade-at-anthropics-cyber-model-mythos-fear-based-marketing/" target="_blank"><u>fear-based marketing</u></a>, others have backed the company, saying Mythos proved exceptionally useful at identifying and fixing flaws. Microsoft, for example, is one of the original Project Glasswing partners, and ever since it started using it, the number of flaws patched through its Patch Tuesday cumulative update <a href="https://www.techradar.com/pro/security/microsoft-just-released-its-biggest-patch-tuesday-ever-with-a-mammoth-622-fixes-including-three-dangerous-zero-days" target="_blank"><u>quadrupled</u></a>.</p><p>Mozilla is also among those showering Mythos with praise, saying earlier this year that it is “<a href="https://www.techradar.com/pro/mozilla-says-anthropics-mythos-is-every-bit-as-capable-as-the-worlds-best-security-researchers-after-firefox-experiment-and-says-the-zero-days-are-numbered" target="_blank"><u>every bit as capable</u></a>” as the world’s best security researchers.</p><p>If A Security managed to find such dangerous flaws with publicly available models, there’s no telling what these dedicated models can do.</p><p><em>Via </em><a href="https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Trustworthy AI starts with surviving production failures ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Evaluating <a href="https://www.techradar.com/best/best-ai-tools">AI</a> agents in production tends to focus only on positive results. Did the agent complete the task? Was the output accurate? Did the demo go well? </p><p>The answers to those questions matter, but they miss the case that determines whether an enterprise can actually trust agents with real work: what happens in the 30% of instances where something goes wrong?</p><p>In financial services, for example, an autonomous agent that mishandles a money-movement workflow doesn't turn into an innocuous support ticket. It creates legal liability that can extend across an entire business. </p><p>In healthcare, unchecked data access calls can compromise patient safety and lead to HIPAA violations. Highly regulated industries can’t treat failure as a minor inconvenience. And when the stakes are categorically higher than in most other sectors, it changes what "production-ready" means.</p><p>The problem? Most popular agent frameworks were built by teams focused on connecting <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">large language models</a> to reasoning loops and evaluation. While valuable, it's not the same discipline as distributed systems engineering. </p><p>Few of these frameworks were built by people who spend their careers thinking about recovery, consistency and fault isolation. Many give little thought to what happens when an agent fails mid-flight, and that gap can be very expensive once agents are handling real-world transactions.</p><h2 id="replaying-from-scratch-doesn-t-work">Replaying From Scratch Doesn't Work</h2><p>When a sales agent moves through a 10-step workflow and fails at step nine, the naive recovery approach is to start the entire flow over from step one. That sounds harmless until you account for what each step actually costs. Every restart means re-running every LLM call that already succeeded, burning through token spend for work that was already done correctly. At scale, that inefficiency turns a single bug into a real financial problem.</p><p>It also produces a worse experience for the people and systems downstream. In a regulated workflow, it’s sloppy work that becomes a compliance and audit problem waiting to surface.</p><p>The fix is durable execution: checkpointing that captures progress at each meaningful step, so recovery means resuming from step nine, not replaying the whole sequence. This has become standard practice in distributed systems, and agent orchestration needs to follow suit. </p><p>When you’re evaluating agent frameworks, here’s the question you should ask: if an agent fails partway through a long-running task, does the system resume from where it left off, or does it start over? The answer will tell you the difference between frameworks built for production and those built for demos.</p><h2 id="there-s-an-access-problem-nobody-talks-about">There’s an Access Problem Nobody Talks About</h2><p><a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> in agentic systems presents its own version of this challenge, and it starts with a question that sounds basic but that most organizations can't seem to answer: can you prove exactly who or what did what, and when?</p><p>That question is harder to answer as agents act on behalf of other agents, which act on behalf of humans. Each layer of delegation adds ambiguity about accountability. And when you add MCP servers into the mix, the exposure compounds. MCP gives language models access to company records, patient data and internal systems. The vast majority of MCP servers in production today connect to some kind of <a href="https://www.techradar.com/best/best-database-software">database</a>, and the common mistake is granting broad access to that entire data store rather than narrowly scoping what each server can see.</p><p>That distinction matters when something goes wrong. If a system with broad access suffers a breach or a supply chain compromise, the attacker gains access to the entire environment. Scoped access, where an MCP <a href="https://www.techradar.com/web-hosting/best-minecraft-server-hosting">server</a> or agent can only reach the specific data it needs for the task at hand, is one of the most overlooked design decisions in agentic architecture right now. It's also a relatively cheap problem to fix before deployment, yet one of the most expensive to fix after a breach.</p><p>Identity adds another layer. Many organizations still use traditional authentication protocols that were made for human users logging into applications, not for autonomous systems that act at machine speed and scale. Without verifiable identities for each agent and each component, malicious code can impersonate a legitimate part of the system and operate undetected. </p><p>What’s needed here is what’s known as cryptographic attestation: a tamper-proof record of everything that happened in the system tied to the specific identity that did it. That record lets you replay the system's state after the fact and determine with certainty that a specific piece of code accessed a specific system at a specific moment. Why? Because that identity was managed and enforced in real time. It's the difference between a policy that says a component “should” be trusted and a system that can prove what it actually did.</p><h2 id="design-to-limit-the-blast-radius-not-just-patch-the-damage">Design to Limit the Blast Radius, Not Just Patch the Damage</h2><p>There's also a problem with how most organizations think about vulnerabilities. The industry's attention is almost entirely on patching known CVEs, and that's necessary. But at the same time, it misses something important: a vulnerability only becomes a known CVE after a breach has already occurred. <a href="https://www.techradar.com/best/best-patch-management-tools">Patch management</a> is inherently reactive and does nothing while a system is actively compromised, by which point malicious code is already trying to move laterally through the network.</p><p>This is why runtime enforcement deserves far more attention. The goal isn't just prevention; it's containment. If a system is compromised, can you detect that a component is behaving abnormally and immediately restrict its access, even before you’ve identified or patched the underlying flaw? Limiting the blast radius in real time, rather than relying solely on detection after the fact, is what separates a contained incident from a full-scale breach.</p><p>Zero trust principles should be applied specifically to AI workloads, not just inherited from traditional cloud-native security protocols. That means strict authentication and authorization for every agent and MCP server, clear policies on what each component is allowed to access, and controls that stop compromised components from sending data outside the organization. </p><h2 id="you-need-to-prove-safety-not-just-function">You Need to Prove Safety, Not Just Function</h2><p>This isn’t pessimism toward AI agents; it's about engineering maturity. Every distributed system that has matured into something enterprises trust with critical workloads, from databases to cloud infrastructure, went through this same evolution. They go from optimizing for common cases to designing explicitly for the rare, expensive failure.</p><p>Agentic AI is now at that point. The organizations that get it right will be able to sit down with an auditor or a regulator and demonstrate, with evidence, exactly how their systems behave when something breaks:</p><p>- Durable recovery that doesn't waste a single completed step.</p><p>- Access that's scoped to the task, not the whole database.</p><p>- Identity that can be cryptographically verified, not just assumed.</p><p>- Containment that activates in real time, not after the fact.</p><p>These are the bars that enterprises serious about deploying AI agents at scale need to meet.</p><p><em></em><a href="https://www.techradar.com/best/best-business-cloud-storage-service"><em>We list the best business cloud storage to manage your data</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/trustworthy-ai-starts-with-surviving-production-failures</link>
                                                                            <description>
                            <![CDATA[ Reliable AI agents recover from failures, prove identity, and contain breaches before damage spreads. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">39xB8utzgeYzb845bQg9si</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 10:47:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Yaron Schneider ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Evaluating <a href="https://www.techradar.com/best/best-ai-tools">AI</a> agents in production tends to focus only on positive results. Did the agent complete the task? Was the output accurate? Did the demo go well? </p><p>The answers to those questions matter, but they miss the case that determines whether an enterprise can actually trust agents with real work: what happens in the 30% of instances where something goes wrong?</p><p>In financial services, for example, an autonomous agent that mishandles a money-movement workflow doesn't turn into an innocuous support ticket. It creates legal liability that can extend across an entire business. </p><p>In healthcare, unchecked data access calls can compromise patient safety and lead to HIPAA violations. Highly regulated industries can’t treat failure as a minor inconvenience. And when the stakes are categorically higher than in most other sectors, it changes what "production-ready" means.</p><p>The problem? Most popular agent frameworks were built by teams focused on connecting <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">large language models</a> to reasoning loops and evaluation. While valuable, it's not the same discipline as distributed systems engineering. </p><p>Few of these frameworks were built by people who spend their careers thinking about recovery, consistency and fault isolation. Many give little thought to what happens when an agent fails mid-flight, and that gap can be very expensive once agents are handling real-world transactions.</p><h2 id="replaying-from-scratch-doesn-t-work">Replaying From Scratch Doesn't Work</h2><p>When a sales agent moves through a 10-step workflow and fails at step nine, the naive recovery approach is to start the entire flow over from step one. That sounds harmless until you account for what each step actually costs. Every restart means re-running every LLM call that already succeeded, burning through token spend for work that was already done correctly. At scale, that inefficiency turns a single bug into a real financial problem.</p><p>It also produces a worse experience for the people and systems downstream. In a regulated workflow, it’s sloppy work that becomes a compliance and audit problem waiting to surface.</p><p>The fix is durable execution: checkpointing that captures progress at each meaningful step, so recovery means resuming from step nine, not replaying the whole sequence. This has become standard practice in distributed systems, and agent orchestration needs to follow suit. </p><p>When you’re evaluating agent frameworks, here’s the question you should ask: if an agent fails partway through a long-running task, does the system resume from where it left off, or does it start over? The answer will tell you the difference between frameworks built for production and those built for demos.</p><h2 id="there-s-an-access-problem-nobody-talks-about">There’s an Access Problem Nobody Talks About</h2><p><a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> in agentic systems presents its own version of this challenge, and it starts with a question that sounds basic but that most organizations can't seem to answer: can you prove exactly who or what did what, and when?</p><p>That question is harder to answer as agents act on behalf of other agents, which act on behalf of humans. Each layer of delegation adds ambiguity about accountability. And when you add MCP servers into the mix, the exposure compounds. MCP gives language models access to company records, patient data and internal systems. The vast majority of MCP servers in production today connect to some kind of <a href="https://www.techradar.com/best/best-database-software">database</a>, and the common mistake is granting broad access to that entire data store rather than narrowly scoping what each server can see.</p><p>That distinction matters when something goes wrong. If a system with broad access suffers a breach or a supply chain compromise, the attacker gains access to the entire environment. Scoped access, where an MCP <a href="https://www.techradar.com/web-hosting/best-minecraft-server-hosting">server</a> or agent can only reach the specific data it needs for the task at hand, is one of the most overlooked design decisions in agentic architecture right now. It's also a relatively cheap problem to fix before deployment, yet one of the most expensive to fix after a breach.</p><p>Identity adds another layer. Many organizations still use traditional authentication protocols that were made for human users logging into applications, not for autonomous systems that act at machine speed and scale. Without verifiable identities for each agent and each component, malicious code can impersonate a legitimate part of the system and operate undetected. </p><p>What’s needed here is what’s known as cryptographic attestation: a tamper-proof record of everything that happened in the system tied to the specific identity that did it. That record lets you replay the system's state after the fact and determine with certainty that a specific piece of code accessed a specific system at a specific moment. Why? Because that identity was managed and enforced in real time. It's the difference between a policy that says a component “should” be trusted and a system that can prove what it actually did.</p><h2 id="design-to-limit-the-blast-radius-not-just-patch-the-damage">Design to Limit the Blast Radius, Not Just Patch the Damage</h2><p>There's also a problem with how most organizations think about vulnerabilities. The industry's attention is almost entirely on patching known CVEs, and that's necessary. But at the same time, it misses something important: a vulnerability only becomes a known CVE after a breach has already occurred. <a href="https://www.techradar.com/best/best-patch-management-tools">Patch management</a> is inherently reactive and does nothing while a system is actively compromised, by which point malicious code is already trying to move laterally through the network.</p><p>This is why runtime enforcement deserves far more attention. The goal isn't just prevention; it's containment. If a system is compromised, can you detect that a component is behaving abnormally and immediately restrict its access, even before you’ve identified or patched the underlying flaw? Limiting the blast radius in real time, rather than relying solely on detection after the fact, is what separates a contained incident from a full-scale breach.</p><p>Zero trust principles should be applied specifically to AI workloads, not just inherited from traditional cloud-native security protocols. That means strict authentication and authorization for every agent and MCP server, clear policies on what each component is allowed to access, and controls that stop compromised components from sending data outside the organization. </p><h2 id="you-need-to-prove-safety-not-just-function">You Need to Prove Safety, Not Just Function</h2><p>This isn’t pessimism toward AI agents; it's about engineering maturity. Every distributed system that has matured into something enterprises trust with critical workloads, from databases to cloud infrastructure, went through this same evolution. They go from optimizing for common cases to designing explicitly for the rare, expensive failure.</p><p>Agentic AI is now at that point. The organizations that get it right will be able to sit down with an auditor or a regulator and demonstrate, with evidence, exactly how their systems behave when something breaks:</p><p>- Durable recovery that doesn't waste a single completed step.</p><p>- Access that's scoped to the task, not the whole database.</p><p>- Identity that can be cryptographically verified, not just assumed.</p><p>- Containment that activates in real time, not after the fact.</p><p>These are the bars that enterprises serious about deploying AI agents at scale need to meet.</p><p><em></em><a href="https://www.techradar.com/best/best-business-cloud-storage-service"><em>We list the best business cloud storage to manage your data</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why AI is accelerating old cyber risks, not creating new ones ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The integration of <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">artificial intelligence</a> (AI) into everyday work and life has prompted businesses and regulatory bodies to take action. AI is a force introducing entirely new categories of threat, making heightened cyber resilience essential. However, amidst the panic to get in front of this, it should be noted that not all the hype is entirely accurate. </p><p>The underlying vulnerabilities organizations face today are largely the same ones they faced five or ten years ago: unpatched systems, weak <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a> controls, excessive privileges, insecure third-party integrations.</p><p>In some cases, these weaknesses have existed for some time, and most likely, will continue to exist because the first fundamental constraint of computer science is that the removal of all vulnerabilities is impossible. Therefore, no amount of tooling or budget will ever make any business 100% secure. Equally, that doesn’t mean improvements should simply be dismissed - especially in the age of AI.</p><h2 id="speed-not-novelty">Speed, not novelty</h2><p>While not introducing anything inherently new, there is still some cause for concern surrounding AI. The nature of existing weaknesses remains the same. However, AI does significantly change the speed and scale at which they can be identified and exploited. Tasks that once required time, skill, and persistence can now be automated, accelerated, and in some cases delegated.</p><p>The barrier to entry has been lowered for less sophisticated actors to operate with greater efficiency and success.</p><p>We are already seeing early signs of this shift. Elements of the attack lifecycle can be automated, be that reconnaissance or lateral movement. Nation-state actors have begun experimenting with using these systems to coordinate multi-stage operations, and we’ve recently seen a fully autonomous attack take place, without any human supervision.</p><p>At the same time, more familiar techniques are being enhanced rather than replaced. <a href="https://www.techradar.com/best/best-malware-removal">Malware</a> can be generated or iterated more quickly to evade detection. Social engineering has become more convincing through deepfakes, and phishing campaigns have become easier to scale. </p><p>None of this represents a fundamentally new playbook, simply the acceleration of an existing one. </p><h2 id="the-distraction-problem">The distraction problem</h2><p>The distinction between novelty and speed matters because it shapes how organizations respond. If AI is treated as a novel and exceptional threat, it encourages a reactive mindset. <a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> teams are pushed towards finding “AI-specific” solutions, often at the expense of addressing longstanding gaps in their environment. In practice, those gaps still remain the most reliable entry points for attackers.</p><p>The risk that the current level of attention on AI creates, is a form of strategic distraction. Boards and executives are rightly asking questions about AI risk, but those conversations can become detached from the basics. Patch management programs remain inconsistent. Asset inventories are incomplete. Third-party exposure is poorly understood. Identity and access management remains fragmented across systems. </p><p>These are the same issues that security professionals were tackling before the advent of AI and the technology does not take them off the board. If anything, these become more consequential as the speed of exploitation increases. </p><h2 id="the-right-response">The right response</h2><p>It is worth being clear about the limits of control. No organization will ever be 100% secure. There will always be unknown vulnerabilities, many of which the new frontier models will be able to fish out.</p><p>However, the idea that AI introduces risk that can be entirely “solved” is misleading. Even if advanced models identify previously unknown weaknesses, the response remains the same as it has always been: prioritize, remediate and reduce exposure over time.</p><p>For defenders, matching this increased tempo requires a combination of discipline and adaptation. Established practices such as red teaming and tabletop exercises need to evolve to incorporate AI-enabled scenarios. Incident response teams need to be prepared to handle new forms of evidence, including those generated or manipulated by AI systems.</p><p>In addition, training programs need to reflect the growing sophistication of social engineering, particularly where deepfakes and voice cloning is concerned. </p><p>AI-driven detection and response capabilities can play an important role, particularly in identifying patterns at scale. But they are not a substitute for secure-by-design principles, robust access controls, or a clear understanding of where critical <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> resides. Therefore, organizations should observe caution about over-rotating towards new tools without addressing foundational weaknesses.</p><p>The expansion of the attack surface through enterprise AI adoption adds another layer of complexity. Threat actors are already targeting AI workflows directly, exploiting vulnerabilities in <a href="https://www.techradar.com/best/best-antivirus">software</a> development environments, and using techniques such as prompt injection to manipulate system behavior.</p><p>In some cases, malicious instructions can be embedded within otherwise benign content, triggering unintended actions when processed by an AI system. </p><p>Again, these developments are best understood as extensions of familiar concepts. Input validation, supply chain risk, and data integrity have always been central to security. AI introduces new contexts in which these issues manifest, but not entirely new categories of risk.</p><p>From a governance perspective, this reinforces the need for clarity rather than novelty. Boards should be focused on defining risk tolerance, ensuring accountability, and maintaining visibility over how AI is used within the organization.</p><p>This includes integrating AI considerations into existing risk frameworks rather than treating them as a separate domain. Legal, technical, and communications teams need to be aligned, particularly in scenarios involving misinformation or synthetic media, where response speed is critical. </p><h2 id="what-matters-now">What matters now</h2><p>There is value in the current focus on cyber risk. Increased attention at the board level can drive investment and accountability in ways that were previously difficult to achieve. But that attention needs to be directed towards the right problems. Treating AI as an entirely new threat risks misallocating resources and overlooking the vulnerabilities that are already present.</p><p>AI will continue to evolve and so will the ways in which it is used by both attackers and defenders. In cyber security, progress is often less about discovering new answers and more about applying existing ones with greeted consistency and speed.</p><p>The organizations that navigate this shift most effectively will be those that remain grounded in a clear understanding of what has and has not changed.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/why-ai-is-accelerating-old-cyber-risks-not-creating-new-ones</link>
                                                                            <description>
                            <![CDATA[ AI is changing cyber threats, but core security principles still determine organizational resilience. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nK4aRi3GqqpfroE4X3Ryg3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 10:27:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ed Williams, LevelBlue ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The integration of <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">artificial intelligence</a> (AI) into everyday work and life has prompted businesses and regulatory bodies to take action. AI is a force introducing entirely new categories of threat, making heightened cyber resilience essential. However, amidst the panic to get in front of this, it should be noted that not all the hype is entirely accurate. </p><p>The underlying vulnerabilities organizations face today are largely the same ones they faced five or ten years ago: unpatched systems, weak <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a> controls, excessive privileges, insecure third-party integrations.</p><p>In some cases, these weaknesses have existed for some time, and most likely, will continue to exist because the first fundamental constraint of computer science is that the removal of all vulnerabilities is impossible. Therefore, no amount of tooling or budget will ever make any business 100% secure. Equally, that doesn’t mean improvements should simply be dismissed - especially in the age of AI.</p><h2 id="speed-not-novelty">Speed, not novelty</h2><p>While not introducing anything inherently new, there is still some cause for concern surrounding AI. The nature of existing weaknesses remains the same. However, AI does significantly change the speed and scale at which they can be identified and exploited. Tasks that once required time, skill, and persistence can now be automated, accelerated, and in some cases delegated.</p><p>The barrier to entry has been lowered for less sophisticated actors to operate with greater efficiency and success.</p><p>We are already seeing early signs of this shift. Elements of the attack lifecycle can be automated, be that reconnaissance or lateral movement. Nation-state actors have begun experimenting with using these systems to coordinate multi-stage operations, and we’ve recently seen a fully autonomous attack take place, without any human supervision.</p><p>At the same time, more familiar techniques are being enhanced rather than replaced. <a href="https://www.techradar.com/best/best-malware-removal">Malware</a> can be generated or iterated more quickly to evade detection. Social engineering has become more convincing through deepfakes, and phishing campaigns have become easier to scale. </p><p>None of this represents a fundamentally new playbook, simply the acceleration of an existing one. </p><h2 id="the-distraction-problem">The distraction problem</h2><p>The distinction between novelty and speed matters because it shapes how organizations respond. If AI is treated as a novel and exceptional threat, it encourages a reactive mindset. <a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> teams are pushed towards finding “AI-specific” solutions, often at the expense of addressing longstanding gaps in their environment. In practice, those gaps still remain the most reliable entry points for attackers.</p><p>The risk that the current level of attention on AI creates, is a form of strategic distraction. Boards and executives are rightly asking questions about AI risk, but those conversations can become detached from the basics. Patch management programs remain inconsistent. Asset inventories are incomplete. Third-party exposure is poorly understood. Identity and access management remains fragmented across systems. </p><p>These are the same issues that security professionals were tackling before the advent of AI and the technology does not take them off the board. If anything, these become more consequential as the speed of exploitation increases. </p><h2 id="the-right-response">The right response</h2><p>It is worth being clear about the limits of control. No organization will ever be 100% secure. There will always be unknown vulnerabilities, many of which the new frontier models will be able to fish out.</p><p>However, the idea that AI introduces risk that can be entirely “solved” is misleading. Even if advanced models identify previously unknown weaknesses, the response remains the same as it has always been: prioritize, remediate and reduce exposure over time.</p><p>For defenders, matching this increased tempo requires a combination of discipline and adaptation. Established practices such as red teaming and tabletop exercises need to evolve to incorporate AI-enabled scenarios. Incident response teams need to be prepared to handle new forms of evidence, including those generated or manipulated by AI systems.</p><p>In addition, training programs need to reflect the growing sophistication of social engineering, particularly where deepfakes and voice cloning is concerned. </p><p>AI-driven detection and response capabilities can play an important role, particularly in identifying patterns at scale. But they are not a substitute for secure-by-design principles, robust access controls, or a clear understanding of where critical <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> resides. Therefore, organizations should observe caution about over-rotating towards new tools without addressing foundational weaknesses.</p><p>The expansion of the attack surface through enterprise AI adoption adds another layer of complexity. Threat actors are already targeting AI workflows directly, exploiting vulnerabilities in <a href="https://www.techradar.com/best/best-antivirus">software</a> development environments, and using techniques such as prompt injection to manipulate system behavior.</p><p>In some cases, malicious instructions can be embedded within otherwise benign content, triggering unintended actions when processed by an AI system. </p><p>Again, these developments are best understood as extensions of familiar concepts. Input validation, supply chain risk, and data integrity have always been central to security. AI introduces new contexts in which these issues manifest, but not entirely new categories of risk.</p><p>From a governance perspective, this reinforces the need for clarity rather than novelty. Boards should be focused on defining risk tolerance, ensuring accountability, and maintaining visibility over how AI is used within the organization.</p><p>This includes integrating AI considerations into existing risk frameworks rather than treating them as a separate domain. Legal, technical, and communications teams need to be aligned, particularly in scenarios involving misinformation or synthetic media, where response speed is critical. </p><h2 id="what-matters-now">What matters now</h2><p>There is value in the current focus on cyber risk. Increased attention at the board level can drive investment and accountability in ways that were previously difficult to achieve. But that attention needs to be directed towards the right problems. Treating AI as an entirely new threat risks misallocating resources and overlooking the vulnerabilities that are already present.</p><p>AI will continue to evolve and so will the ways in which it is used by both attackers and defenders. In cyber security, progress is often less about discovering new answers and more about applying existing ones with greeted consistency and speed.</p><p>The organizations that navigate this shift most effectively will be those that remain grounded in a clear understanding of what has and has not changed.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The UK's on-device scanning plan is a threat to enterprise environments ]]></title>
                                                                                                <dc:content><![CDATA[ <p>In June, Keir Starmer announced at London Tech Week that tech firms have until September to introduce device controls that prevent children from sending and receiving sexually explicit images. The plan requires on-device or client-side scanning, and has been framed as a child safety measure. For enterprise <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> teams, it raises a different set of questions entirely.</p><p>For enterprises, the proposal challenges one of the core assumptions underpinning modern cybersecurity: that devices can be trusted to process sensitive information without external inspection.</p><p>If software is required to scan content before it is encrypted or transmitted, it introduces new attack surfaces and weakens the privacy and integrity that businesses depend on to protect intellectual property and confidential information.</p><p>It’s a concern being felt widely across the industry, with organizations including Signal and the British Computer Society issuing statements warning that client-side scanning can create systemic vulnerabilities that could ultimately be exploited by cybercriminals and other malicious actors, fundamentally reshaping digital trust.</p><p>As organizations prepare for the September deadline, they must equip teams with the necessary skills to evaluate potential risks that client-side scanning could cause, adapting security strategies where necessary. </p><h2 id="why-the-proposed-plan-has-led-to-conversations-around-security">Why the proposed plan has led to conversations around security</h2><p>The greatest risk posed by mandatory on-device scanning is the disruption of trust architecture on which enterprise security depends. Modern <a href="https://www.techradar.com/best/best-android-phones">mobile</a> security frameworks, including mobile device management (MDM), endpoint protection and zero-trust access controls, are built on the assumption that the operating system functions as a controlled and trusted layer.</p><p>Enterprises use this trusted foundation to enforce security policies and verify the integrity of managed devices.</p><p>Introducing a government-mandated scanning agent beneath or alongside that trusted layer fundamentally changes the security model. Once an additional privileged component can inspect device content, the integrity of the operating system can no longer be assumed, making the security controls that sit above it less reliable.</p><p>This structural change to the trust boundary that underpins enterprise mobile security, creates new opportunities for exploitation if the capability is ever compromised or repurposed.</p><h2 id="the-operational-problems-for-security-teams">The operational problems for security teams</h2><p>The consequences extend beyond security architecture into day-to-day enterprise operations. The underlying issue is not <a href="https://www.techradar.com/best/best-privacy-apps-for-android">privacy</a>, which is what the government’s plan is concerned with, but architecture. A scanning agent at the operating system level sits outside the boundaries that enterprise security teams are able to govern,  disrupting security processes that organizations rely on to verify whether endpoints remain in a trusted state.</p><p>Government-run scanning agents also create the potential for compliance failures, particularly in highly regulated sectors where organizations must demonstrate control over how sensitive <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> is processed and monitored. If the scanning function operates outside the managed work profile used by enterprise MDM platforms, it remains effectively invisible to IT administrators.</p><p>As a result, security teams have no practical mechanism to audit its behavior or control how it acts with secure data. This also disrupts device attestation - the process by which MDM platforms verify a device is in a known, trusted state - which could cause managed devices to be flagged as non-compliant and blocked from corporate resources.</p><p>In an environment where visibility and assurance are fundamental principles of cyber defense, introducing a privileged component that falls outside enterprise oversight creates a blind spot that weakens, rather than strengthens, organizational security.</p><p>While intended to improve online safety, client-side scanning raises significant concerns for organizations. Because it requires privileged access to device content and is widely considered incompatible with true end-to-end encryption, it could weaken security, increase the risk of sensitive data exposure, and force organizations to navigate difficult trade-offs between compliance and protecting critical systems.</p><p>The lack of clear exemptions for legally privileged, healthcare and <a href="https://www.techradar.com/best/best-personal-finance-software?bingParse">financial</a> data also leaves regulated sectors facing uncertainty over how to meet competing legal obligations.</p><h2 id="what-organizations-can-do-to-prepare">What organizations can do to prepare</h2><p>Organizations cannot afford to treat this proposal as a policy issue alone. Security leaders should already be engaging with the compliance and governance issues it raises, assessing how any mandated changes to mobile operating systems could affect device trust, regulatory obligations and existing security controls.</p><p>This also means investing in the skills needed to assess security risks at the architectural level, rather than simply responding to threats after they emerge. </p><p>Security teams will need a deeper understanding of operating system security models, trusted execution environments, encryption, <a href="https://www.techradar.com/news/best-endpoint-security-software">endpoint</a> architecture and mobile device management, enabling them to evaluate how changes to core platform designs could affect an organization's overall security posture.</p><p>Building these capabilities will help organizations make informed decisions about adopting new technologies, understand the implications of regulatory changes, and identify potential weaknesses before they become exploitable.</p><p>As trust increasingly becomes embedded within the architecture itself, having teams with the expertise to assess and challenge these foundations will be just as important as the security tools used to defend them.</p><h2 id="safety-cannot-erode-trust">Safety cannot erode trust</h2><p>As the debate surrounding the UK’s on-device scanning proposal continues, the conversation must move beyond the framing of privacy versus safety and consider the wider architectural consequences for enterprise environments.</p><p>Weakening the trusted computing model on which modern mobile security is built risks introducing new vulnerabilities, reducing visibility for security teams and undermining confidence in the platform’s organizations depend on.</p><p>Making the internet safer for children is crucial, but achieving that goal should not come at the expense of the security foundations that <a href="https://www.techradar.com/best/best-small-business-website-builders">businesses</a> rely on every day. The challenge for policymakers and technology providers is not just to implement new safeguards, but to do so without eroding the trust that underpins the wider digital ecosystem.</p><p><em></em><a href="https://www.techradar.com/best/secure-file-transfer-solutions"><em>We've featured the best secure file sharing.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/the-uks-on-device-scanning-plan-is-a-threat-to-enterprise-environments</link>
                                                                            <description>
                            <![CDATA[ A proposed plan for government scanning will threaten the privacy of enterprise environments. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PvgiJhbb7kmVhXTUf7ypwP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 09:56:39 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Matthew Lloyd Davies ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:description>                                                            <media:text><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In June, Keir Starmer announced at London Tech Week that tech firms have until September to introduce device controls that prevent children from sending and receiving sexually explicit images. The plan requires on-device or client-side scanning, and has been framed as a child safety measure. For enterprise <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> teams, it raises a different set of questions entirely.</p><p>For enterprises, the proposal challenges one of the core assumptions underpinning modern cybersecurity: that devices can be trusted to process sensitive information without external inspection.</p><p>If software is required to scan content before it is encrypted or transmitted, it introduces new attack surfaces and weakens the privacy and integrity that businesses depend on to protect intellectual property and confidential information.</p><p>It’s a concern being felt widely across the industry, with organizations including Signal and the British Computer Society issuing statements warning that client-side scanning can create systemic vulnerabilities that could ultimately be exploited by cybercriminals and other malicious actors, fundamentally reshaping digital trust.</p><p>As organizations prepare for the September deadline, they must equip teams with the necessary skills to evaluate potential risks that client-side scanning could cause, adapting security strategies where necessary. </p><h2 id="why-the-proposed-plan-has-led-to-conversations-around-security">Why the proposed plan has led to conversations around security</h2><p>The greatest risk posed by mandatory on-device scanning is the disruption of trust architecture on which enterprise security depends. Modern <a href="https://www.techradar.com/best/best-android-phones">mobile</a> security frameworks, including mobile device management (MDM), endpoint protection and zero-trust access controls, are built on the assumption that the operating system functions as a controlled and trusted layer.</p><p>Enterprises use this trusted foundation to enforce security policies and verify the integrity of managed devices.</p><p>Introducing a government-mandated scanning agent beneath or alongside that trusted layer fundamentally changes the security model. Once an additional privileged component can inspect device content, the integrity of the operating system can no longer be assumed, making the security controls that sit above it less reliable.</p><p>This structural change to the trust boundary that underpins enterprise mobile security, creates new opportunities for exploitation if the capability is ever compromised or repurposed.</p><h2 id="the-operational-problems-for-security-teams">The operational problems for security teams</h2><p>The consequences extend beyond security architecture into day-to-day enterprise operations. The underlying issue is not <a href="https://www.techradar.com/best/best-privacy-apps-for-android">privacy</a>, which is what the government’s plan is concerned with, but architecture. A scanning agent at the operating system level sits outside the boundaries that enterprise security teams are able to govern,  disrupting security processes that organizations rely on to verify whether endpoints remain in a trusted state.</p><p>Government-run scanning agents also create the potential for compliance failures, particularly in highly regulated sectors where organizations must demonstrate control over how sensitive <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> is processed and monitored. If the scanning function operates outside the managed work profile used by enterprise MDM platforms, it remains effectively invisible to IT administrators.</p><p>As a result, security teams have no practical mechanism to audit its behavior or control how it acts with secure data. This also disrupts device attestation - the process by which MDM platforms verify a device is in a known, trusted state - which could cause managed devices to be flagged as non-compliant and blocked from corporate resources.</p><p>In an environment where visibility and assurance are fundamental principles of cyber defense, introducing a privileged component that falls outside enterprise oversight creates a blind spot that weakens, rather than strengthens, organizational security.</p><p>While intended to improve online safety, client-side scanning raises significant concerns for organizations. Because it requires privileged access to device content and is widely considered incompatible with true end-to-end encryption, it could weaken security, increase the risk of sensitive data exposure, and force organizations to navigate difficult trade-offs between compliance and protecting critical systems.</p><p>The lack of clear exemptions for legally privileged, healthcare and <a href="https://www.techradar.com/best/best-personal-finance-software?bingParse">financial</a> data also leaves regulated sectors facing uncertainty over how to meet competing legal obligations.</p><h2 id="what-organizations-can-do-to-prepare">What organizations can do to prepare</h2><p>Organizations cannot afford to treat this proposal as a policy issue alone. Security leaders should already be engaging with the compliance and governance issues it raises, assessing how any mandated changes to mobile operating systems could affect device trust, regulatory obligations and existing security controls.</p><p>This also means investing in the skills needed to assess security risks at the architectural level, rather than simply responding to threats after they emerge. </p><p>Security teams will need a deeper understanding of operating system security models, trusted execution environments, encryption, <a href="https://www.techradar.com/news/best-endpoint-security-software">endpoint</a> architecture and mobile device management, enabling them to evaluate how changes to core platform designs could affect an organization's overall security posture.</p><p>Building these capabilities will help organizations make informed decisions about adopting new technologies, understand the implications of regulatory changes, and identify potential weaknesses before they become exploitable.</p><p>As trust increasingly becomes embedded within the architecture itself, having teams with the expertise to assess and challenge these foundations will be just as important as the security tools used to defend them.</p><h2 id="safety-cannot-erode-trust">Safety cannot erode trust</h2><p>As the debate surrounding the UK’s on-device scanning proposal continues, the conversation must move beyond the framing of privacy versus safety and consider the wider architectural consequences for enterprise environments.</p><p>Weakening the trusted computing model on which modern mobile security is built risks introducing new vulnerabilities, reducing visibility for security teams and undermining confidence in the platform’s organizations depend on.</p><p>Making the internet safer for children is crucial, but achieving that goal should not come at the expense of the security foundations that <a href="https://www.techradar.com/best/best-small-business-website-builders">businesses</a> rely on every day. The challenge for policymakers and technology providers is not just to implement new safeguards, but to do so without eroding the trust that underpins the wider digital ecosystem.</p><p><em></em><a href="https://www.techradar.com/best/secure-file-transfer-solutions"><em>We've featured the best secure file sharing.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Scammers are using fake Odyssey pirate downloads to spread malware that's more dangerous than the Cyclops and Circe combined ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Bitdefender says fake pirated downloads of </strong><em><strong>The Odyssey</strong></em><strong>, disguised as scene releases with .exe files carrying VLC icons, are spreading Lumma Stealer malware</strong></li><li><strong>Stolen session cookies are the real danger, because they let an attacker resume an authenticated session without ever triggering a multi-factor prompt</strong></li><li><strong>These builds seemingly ship without droppers or persistence, which is less sophisticated than earlier movie-themed samples but no less harmful, since credential theft does not require staying resident</strong></li></ul><p>With <em>The Odyssey</em> set to became one of the year's biggest theatrical launches, people looking for a free copy online started finding one with a few extra caveats in tow.</p><p>What they were actually downloading, according to <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/the-odyssey-piracy-lumma-stealer" target="_blank">Bitdefender</a>, was Lumma Stealer, a prominent infostealer that operates as a Malware-as-a-Service (MaaS).</p><p>The company's researchers say its security products blocked users from downloading and running malicious files disguised as the film, circulating under names designed to look like scene releases: "the odyssey 2026 1080p webrip-lama.exe" is one of three examples published, alongside variants dressed as 2160p HD and H. 264 rips. </p><h2 id="a-regular-occurrence-for-pirates">A regular occurrence for pirates</h2><p>The threat is a well-worn playbook rather than a new one, as Bitdefender documented a near-identical campaign in 2025 built around <em>Mission: Impossible – The Final Reckoning</em>, distributing the same malware family through torrent sites using files dressed as movie releases. The blockbuster changes; the delivery does not.</p><p>The most useful detail in the report is also the least dramatic, and it explains why a file extension that should be a screaming red flag frequently is not: Windows does not show file extensions by default.</p><p>Unless a user has enabled that option in Explorer settings, the ".exe" at the end of a filename is simply invisible. Attackers pair that with a custom icon, commonly one lifted from VLC Media Player or a generic video file, so what appears on screen is a VLC icon and a filename that reads like a movie rip. There is nothing visible to distinguish it from the thing the user was actually looking for.</p><p>Bitdefender's point about social engineering follows from that, and it is a sharp one: almost none is required here. Someone hunting for a leaked copy of a film still in theaters has already accepted that they will be dealing with odd filenames, unofficial sources, and compressed archives. An executable claiming to be a video player or installer is not an uncommon sight in the world of piracy, where such practices are rife.</p><p>Lumma, also tracked as LummaC2, is a Russian-developed information stealer sold as a service, with affiliates paying somewhere between $250 and $1,000 a month for access. Upon execution, it harvests browser passwords, authentication cookies, saved payment information, cryptocurrency wallet data, autofill data, and remote desktop credentials.</p><p>It has often been highlighted as one of the most prolific MaaS options out there and has had <a href="https://www.techradar.com/pro/security/microsoft-takes-legal-action-against-lumma-stealer-after-400-000-devices-infected" target="_blank">Microsoft, the DOJ, and the FBI act directly against it</a> in the past, but has managed to stay alive since, evolving into a more stealthy entity.</p><p>Bitdefender notes that the samples in this campaign arrive without droppers and without persistence mechanisms. </p><p>Previous movie-themed Lumma builds carried more machinery, including delayed execution when security software was detected and encrypted payload delivery through AutoIt scripts. The approach here differs considerably: the attackers appear content with whatever they can collect at execution time and do not attempt to hold the machine afterward.</p><p>Prevention in this case simply involves avoiding the download of pirated films from channels that, as a rule of thumb, do not implement many, if any, security measures to keep infostealers out. </p><p>For those seeking a broader solution, enabling file extensions in Windows Explorer is the way to go. It takes seconds, it is off by default, and it removes the specific blind spot this particular campaign depends on.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/scammers-are-using-fake-odyssey-pirate-downloads-to-spread-malware-thats-more-dangerous-than-the-cyclops-and-circe-combined</link>
                                                                            <description>
                            <![CDATA[ Fake downloads of The Odyssey are delivering Lumma Stealer, and the stolen session cookies walk straight past your two-factor authentication ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xoShk7grh9qqbbQ4g5pjNT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U6UNG2aaqj47hstBqBLsGd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Aug 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U6UNG2aaqj47hstBqBLsGd-1280-80.jpg">
                                                            <media:credit><![CDATA[Universal Studios]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Matt Damon&#039;s Odysseus looking over his left shoulder with some ships in the background in The Odyssey]]></media:description>                                                            <media:text><![CDATA[Matt Damon&#039;s Odysseus looking over his left shoulder with some ships in the background in The Odyssey]]></media:text>
                                <media:title type="plain"><![CDATA[Matt Damon&#039;s Odysseus looking over his left shoulder with some ships in the background in The Odyssey]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U6UNG2aaqj47hstBqBLsGd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Bitdefender says fake pirated downloads of </strong><em><strong>The Odyssey</strong></em><strong>, disguised as scene releases with .exe files carrying VLC icons, are spreading Lumma Stealer malware</strong></li><li><strong>Stolen session cookies are the real danger, because they let an attacker resume an authenticated session without ever triggering a multi-factor prompt</strong></li><li><strong>These builds seemingly ship without droppers or persistence, which is less sophisticated than earlier movie-themed samples but no less harmful, since credential theft does not require staying resident</strong></li></ul><p>With <em>The Odyssey</em> set to became one of the year's biggest theatrical launches, people looking for a free copy online started finding one with a few extra caveats in tow.</p><p>What they were actually downloading, according to <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/the-odyssey-piracy-lumma-stealer" target="_blank">Bitdefender</a>, was Lumma Stealer, a prominent infostealer that operates as a Malware-as-a-Service (MaaS).</p><p>The company's researchers say its security products blocked users from downloading and running malicious files disguised as the film, circulating under names designed to look like scene releases: "the odyssey 2026 1080p webrip-lama.exe" is one of three examples published, alongside variants dressed as 2160p HD and H. 264 rips. </p><h2 id="a-regular-occurrence-for-pirates">A regular occurrence for pirates</h2><p>The threat is a well-worn playbook rather than a new one, as Bitdefender documented a near-identical campaign in 2025 built around <em>Mission: Impossible – The Final Reckoning</em>, distributing the same malware family through torrent sites using files dressed as movie releases. The blockbuster changes; the delivery does not.</p><p>The most useful detail in the report is also the least dramatic, and it explains why a file extension that should be a screaming red flag frequently is not: Windows does not show file extensions by default.</p><p>Unless a user has enabled that option in Explorer settings, the ".exe" at the end of a filename is simply invisible. Attackers pair that with a custom icon, commonly one lifted from VLC Media Player or a generic video file, so what appears on screen is a VLC icon and a filename that reads like a movie rip. There is nothing visible to distinguish it from the thing the user was actually looking for.</p><p>Bitdefender's point about social engineering follows from that, and it is a sharp one: almost none is required here. Someone hunting for a leaked copy of a film still in theaters has already accepted that they will be dealing with odd filenames, unofficial sources, and compressed archives. An executable claiming to be a video player or installer is not an uncommon sight in the world of piracy, where such practices are rife.</p><p>Lumma, also tracked as LummaC2, is a Russian-developed information stealer sold as a service, with affiliates paying somewhere between $250 and $1,000 a month for access. Upon execution, it harvests browser passwords, authentication cookies, saved payment information, cryptocurrency wallet data, autofill data, and remote desktop credentials.</p><p>It has often been highlighted as one of the most prolific MaaS options out there and has had <a href="https://www.techradar.com/pro/security/microsoft-takes-legal-action-against-lumma-stealer-after-400-000-devices-infected" target="_blank">Microsoft, the DOJ, and the FBI act directly against it</a> in the past, but has managed to stay alive since, evolving into a more stealthy entity.</p><p>Bitdefender notes that the samples in this campaign arrive without droppers and without persistence mechanisms. </p><p>Previous movie-themed Lumma builds carried more machinery, including delayed execution when security software was detected and encrypted payload delivery through AutoIt scripts. The approach here differs considerably: the attackers appear content with whatever they can collect at execution time and do not attempt to hold the machine afterward.</p><p>Prevention in this case simply involves avoiding the download of pirated films from channels that, as a rule of thumb, do not implement many, if any, security measures to keep infostealers out. </p><p>For those seeking a broader solution, enabling file extensions in Windows Explorer is the way to go. It takes seconds, it is off by default, and it removes the specific blind spot this particular campaign depends on.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Five questions to test whether an AI stack is truly under your control ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Control is one of the easiest words in enterprise AI to misuse. </p><p>A business may download a model, run it in its own <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud</a> and negotiate favorable terms, and yet still remain dependent at the points that matter. </p><p>Access can create useful freedom. It does not, by itself, prove operating control.</p><p>I have learned to treat sovereignty as an operating discipline, not a nationality badge.</p><p>If an organization cannot prove what it is running, who can change it, what it depends on and how it can be retired, its control is largely assumed. </p><p>These five questions turn an ambiguous claim into a practical test for procurement, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> and leadership teams.</p><h2 id="1-can-you-prove-exactly-what-you-are-running">1. Can you prove exactly what you are running?</h2><p>A model name and version number on an <a href="https://www.techradar.com/best/best-architecture-software">architecture</a> diagram are not provenance. Teams need a traceable origin, an artefact identifier, a cryptographic hash or signature, the approved configuration and a record of every material change. That record should include fine-tunes, safety layers, prompt templates, retrieval sources and any post-deployment adjustments that affect behavior.</p><p>The harder question is operational: who approved the change, who can make the next one and how quickly can the previous state be restored? If a supplier can alter behavior without the customer seeing the change, or rollback depends on goodwill, control is borrowed. The evidence should be simple enough to inspect during an incident, not buried in a quarterly assurance exercise.</p><h2 id="2-can-you-verify-the-weights-and-every-critical-dependency">2. Can you verify the weights and every critical dependency?</h2><p>Model weights matter, but they are only one layer of an AI system. The inference engine, libraries, drivers, orchestration tools, safety filters, retrieval components, <a href="https://www.techradar.com/best/best-network-monitoring-tools">monitoring</a> services and update channels all shape how it operates. Open weights may remove one dependency while introducing several others.</p><p>Every critical component therefore needs an owner, a known version, a license, an update route, a vulnerability response and a credible substitute. Integrity checks should run when the system is built, when it is deployed and after a suspected incident. A bill of materials is useful only when it connects inventory to verification and action. A long list of components with no decision rights is <a href="https://www.techradar.com/pro/best-it-documentation-tool">documentation</a>, not control.</p><h2 id="3-who-controls-the-infrastructure-and-operating-conditions">3. Who controls the infrastructure and operating conditions?</h2><p>Location is not the same as control. A model can sit in a domestic data center whilst essential decisions remain elsewhere. Teams should map who operates the compute, network, identity system, <a href="https://www.techradar.com/best/best-encryption-software">encryption</a> keys, logs and administrative tools. They should know which party can pause, patch, throttle, inspect or revoke the service, and under what conditions.</p><p>Owning the building is not enough if a supplier retains remote administration, a proprietary control plane or the only route to scarce accelerators. Backups and telemetry matter too: where they go, who can read them and how long they persist. The strongest test is a degraded-mode exercise. When capacity disappears, credentials are compromised or a provider becomes unavailable, can the organization continue safely and make its own decisions?</p><h2 id="4-which-law-license-and-contract-governs-the-stack">4. Which law, license and contract governs the stack?</h2><p>Technical architecture and legal architecture form the same control map. The relevant questions cover the law, license and contract governing the weights, hosted services, support, telemetry and any fine-tuned assets. They also cover subcontractors, audit rights, incident notification, unilateral changes, export constraints, and the rights available at exit.</p><p>Data residency does not settle jurisdiction, and a familiar supplier name does not settle enforceability. Legal, procurement, and security teams should be able to answer from the same evidence set. Contradictions between the contract and the system design are not paperwork problems; they are design defects. The useful test is not whether a supplier appears trustworthy today, but which rights survive a dispute, acquisition, service withdrawal or regulatory change.</p><h2 id="5-can-you-switch-stop-and-dispose-safely">5. Can you switch, stop and dispose safely?</h2><p>No AI strategy is controlled until its exit has been tested. Could the organization move to another model, runtime, or provider without rebuilding the entire service? Can it export configurations, evaluation sets, prompts, logs, and fine-tuning artefacts in usable formats? Can it revoke identities and tokens, remove deployed copies, clear checkpoints and caches, and still retain the evidence required for audit or investigation?</p><p>Safe stopping deserves the same attention as fast starting. The exit plan should name triggers, owners, sequence, time limits, and recovery targets, then be rehearsed before dependence becomes difficult to unwind. If switching exists only in a contract slide, it is not a credible option. Disposal is the final proof that control includes ending a dependency without creating a new operational or security risk.</p><h2 id="control-must-be-evidenced-not-declared">Control must be evidenced, not declared</h2><p>The answer to these questions will rarely be a clean yes or no. Control has degrees, and different workloads justify different dependencies. What matters is that each answer is evidenced, assigned to an owner and tested again as the stack changes.</p><p>Open access, local <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> and strong contracts can all reduce risk. None substitutes for the ability to prove what is running, verify its dependencies, identify who can intervene, understand which rules bind it and leave safely. </p><p>That is less glamorous than a sovereignty label, but it is the difference between an AI architecture an organization can use and a stack it can genuinely govern.</p><p><em></em><a href="https://www.techradar.com/best/best-business-cloud-storage-service"><em>Use the best business cloud storage to manage your data</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/five-questions-to-test-whether-an-ai-stack-is-truly-under-your-control</link>
                                                                            <description>
                            <![CDATA[ How leaders can verify provenance, dependencies, infrastructure, jurisdiction and safe exit. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AU9WfE8A2ojEgGKetWrCUV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y9gz3ntBvZYTntd8XpFxfL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Aug 2026 14:25:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Varun Sharma ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y9gz3ntBvZYTntd8XpFxfL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A blue digital cloud containing lots of symbols on a dark blue background]]></media:description>                                                            <media:text><![CDATA[A blue digital cloud containing lots of symbols on a dark blue background]]></media:text>
                                <media:title type="plain"><![CDATA[A blue digital cloud containing lots of symbols on a dark blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y9gz3ntBvZYTntd8XpFxfL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Control is one of the easiest words in enterprise AI to misuse. </p><p>A business may download a model, run it in its own <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud</a> and negotiate favorable terms, and yet still remain dependent at the points that matter. </p><p>Access can create useful freedom. It does not, by itself, prove operating control.</p><p>I have learned to treat sovereignty as an operating discipline, not a nationality badge.</p><p>If an organization cannot prove what it is running, who can change it, what it depends on and how it can be retired, its control is largely assumed. </p><p>These five questions turn an ambiguous claim into a practical test for procurement, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> and leadership teams.</p><h2 id="1-can-you-prove-exactly-what-you-are-running">1. Can you prove exactly what you are running?</h2><p>A model name and version number on an <a href="https://www.techradar.com/best/best-architecture-software">architecture</a> diagram are not provenance. Teams need a traceable origin, an artefact identifier, a cryptographic hash or signature, the approved configuration and a record of every material change. That record should include fine-tunes, safety layers, prompt templates, retrieval sources and any post-deployment adjustments that affect behavior.</p><p>The harder question is operational: who approved the change, who can make the next one and how quickly can the previous state be restored? If a supplier can alter behavior without the customer seeing the change, or rollback depends on goodwill, control is borrowed. The evidence should be simple enough to inspect during an incident, not buried in a quarterly assurance exercise.</p><h2 id="2-can-you-verify-the-weights-and-every-critical-dependency">2. Can you verify the weights and every critical dependency?</h2><p>Model weights matter, but they are only one layer of an AI system. The inference engine, libraries, drivers, orchestration tools, safety filters, retrieval components, <a href="https://www.techradar.com/best/best-network-monitoring-tools">monitoring</a> services and update channels all shape how it operates. Open weights may remove one dependency while introducing several others.</p><p>Every critical component therefore needs an owner, a known version, a license, an update route, a vulnerability response and a credible substitute. Integrity checks should run when the system is built, when it is deployed and after a suspected incident. A bill of materials is useful only when it connects inventory to verification and action. A long list of components with no decision rights is <a href="https://www.techradar.com/pro/best-it-documentation-tool">documentation</a>, not control.</p><h2 id="3-who-controls-the-infrastructure-and-operating-conditions">3. Who controls the infrastructure and operating conditions?</h2><p>Location is not the same as control. A model can sit in a domestic data center whilst essential decisions remain elsewhere. Teams should map who operates the compute, network, identity system, <a href="https://www.techradar.com/best/best-encryption-software">encryption</a> keys, logs and administrative tools. They should know which party can pause, patch, throttle, inspect or revoke the service, and under what conditions.</p><p>Owning the building is not enough if a supplier retains remote administration, a proprietary control plane or the only route to scarce accelerators. Backups and telemetry matter too: where they go, who can read them and how long they persist. The strongest test is a degraded-mode exercise. When capacity disappears, credentials are compromised or a provider becomes unavailable, can the organization continue safely and make its own decisions?</p><h2 id="4-which-law-license-and-contract-governs-the-stack">4. Which law, license and contract governs the stack?</h2><p>Technical architecture and legal architecture form the same control map. The relevant questions cover the law, license and contract governing the weights, hosted services, support, telemetry and any fine-tuned assets. They also cover subcontractors, audit rights, incident notification, unilateral changes, export constraints, and the rights available at exit.</p><p>Data residency does not settle jurisdiction, and a familiar supplier name does not settle enforceability. Legal, procurement, and security teams should be able to answer from the same evidence set. Contradictions between the contract and the system design are not paperwork problems; they are design defects. The useful test is not whether a supplier appears trustworthy today, but which rights survive a dispute, acquisition, service withdrawal or regulatory change.</p><h2 id="5-can-you-switch-stop-and-dispose-safely">5. Can you switch, stop and dispose safely?</h2><p>No AI strategy is controlled until its exit has been tested. Could the organization move to another model, runtime, or provider without rebuilding the entire service? Can it export configurations, evaluation sets, prompts, logs, and fine-tuning artefacts in usable formats? Can it revoke identities and tokens, remove deployed copies, clear checkpoints and caches, and still retain the evidence required for audit or investigation?</p><p>Safe stopping deserves the same attention as fast starting. The exit plan should name triggers, owners, sequence, time limits, and recovery targets, then be rehearsed before dependence becomes difficult to unwind. If switching exists only in a contract slide, it is not a credible option. Disposal is the final proof that control includes ending a dependency without creating a new operational or security risk.</p><h2 id="control-must-be-evidenced-not-declared">Control must be evidenced, not declared</h2><p>The answer to these questions will rarely be a clean yes or no. Control has degrees, and different workloads justify different dependencies. What matters is that each answer is evidenced, assigned to an owner and tested again as the stack changes.</p><p>Open access, local <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> and strong contracts can all reduce risk. None substitutes for the ability to prove what is running, verify its dependencies, identify who can intervene, understand which rules bind it and leave safely. </p><p>That is less glamorous than a sovereignty label, but it is the difference between an AI architecture an organization can use and a stack it can genuinely govern.</p><p><em></em><a href="https://www.techradar.com/best/best-business-cloud-storage-service"><em>Use the best business cloud storage to manage your data</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI extends 'Daybreak' security project and reveals new cyber model — but for approved users only ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>OpenAI expands Daybreak with Blue and Red tiers for defensive cyber work</strong></li><li><strong>New GPT‑5.6‑Cyber model offers high compliance for authorized vulnerability research</strong></li><li><strong>Access remains restricted due to dual‑use risks and reduced safeguard operation</strong></li></ul><p>OpenAI has <a href="https://openai.com/index/expanding-daybreak-as-the-cyber-defense-window-narrows/" target="_blank" rel="nofollow">announced</a> two new tiers for its Daybreak dedicated cybersecurity project, each offering a different model with different levels of compliance. It also used the opportunity to introduce a new security-focused AI model, as well.</p><p>Hackers and criminals are increasingly abusing AI to improve and speed up the creation of phishing emails and malicious code, and with the introduction of <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a>, they’ve also used it to automate entire attack processes. The AI community responded by placing strong guardrails, making sure their models do not comply with requests to build malware, or hack other companies.</p><p>These guardrails ended up being a two-edged sword, because as they slowed down attackers, they also slowed down the defenders.</p><h2 id="what-is-daybreak">What is Daybreak?</h2><p>To give the cybersecurity community the upper edge, companies like OpenAI started creating <a href="https://www.techradar.com/pro/security/openai-reveals-daybreak-its-attempt-to-topple-anthropic-mythos" target="_blank">dedicated cybersecurity initiatives</a> that provide a vetted list of companies state-of-the-art models, free of guardrails. The company also provided them with pre-trained AI agents, as well as access to a pool of shared knowledge.</p><p>Initially launched in June 2026, Daybreak originally included GPT.5-5-Cyber (a model optimized for security work), Codex Security (an agent that can analyze codebases, identify vulnerabilities, validate findings, and help develop patches), Patch the Planet (an initiative with Trail of Bits to find and fix vulnerabilities in open-source software), Daybreak Cyber Partner Program (lets approved cybersecurity companies such as Cloudflare or Cisco integrate OpenAI's cyber capabilities into their own products and services), and Trusted Access for Cyber (the governance/access system for organizations doing authorized cybersecurity work with these capabilities).</p><p>Now, OpenAI has expanded Daybreak with two access tiers, Daybreak Blue, and Daybreak Red.</p><p>The company says Daybreak Blue is “the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation. Companies opting for this tier can expect access to frontier general-purpose models, including GPT‑5.6 Sol, whose safeguards have been tailored to authorized defensive security work.</p><p>Daybreak Red, on the other hand, provides access to OpenAI’s “purpose-trained cybersecurity models for authorized vulnerability research, exploit validation, and security testing.” This tier offers the brand new GPT‑5.6‑Cyber, built on GPT‑5.6 Sol and trained to improve capabilities on several specialized cybersecurity tasks such as finding zero-day vulnerabilities and developing exploit chains.</p><p>This model is also more compliant and less likely to refuse certain higher-risk, dual-use cyber tasks.</p><h2 id="complying-with-dangerous-requests">Complying with "dangerous" requests</h2><p>Request compliance is the name of the game here. OpenAI says the new model addresses feedback from security researchers who “encountered persistent refusals with the earlier model.” General-purpose GPT-5.6 Sol, for example, will comply with just 1.5% of the requests usually given by cyber-defenders working on codebase analysis or vulnerability identification. This percentage increases to 2.0% with Daybreak Blue access. </p><p>GPT-5.6-Cyber, on the other hand, completes 95.0% of requests, OpenAI says, up from 57.3% of the previous model, GPT-5.5-Cyber. We weren’t able to independently verify these claims, though. </p><p>While it doesn’t outright say it, OpenAI considers these models relatively dangerous to use, which is why they’re locked behind the Daybreak Cyber Partner Program. However, the program is now expanding, allowing these companies to embed the models behind their own products, managed services, or cybersecurity engagements, and offer them to clients of their own. </p><p>Those who wish to be a part of the program directly can do so by applying to join online now.</p><p>“Models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment. Despite these risks, we believe that democratizing access to frontier intelligence for defenders is crucial to accelerating and automating cyber defense,” OpenAI said.</p><p>“Daybreak Blue and Daybreak Red access are available for approved individuals⁠ and organizations conducting authorized work. We control access through identity verification, account security, monitoring, approved-use restrictions, and legal attestations.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/openai-extends-daybreak-security-project-and-reveals-new-cyber-model-but-for-approved-users-only</link>
                                                                            <description>
                            <![CDATA[ Daybreak now offers two different models that come with varying degrees of compliance. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AjWZELXMsLjAfnbdxFTR4P</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gN6Qsf7QSmrmYwtYPr47HY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Aug 2026 13:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gN6Qsf7QSmrmYwtYPr47HY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI logo on smartphone, reflected on main screen]]></media:description>                                                            <media:text><![CDATA[OpenAI logo on smartphone, reflected on main screen]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI logo on smartphone, reflected on main screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gN6Qsf7QSmrmYwtYPr47HY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI expands Daybreak with Blue and Red tiers for defensive cyber work</strong></li><li><strong>New GPT‑5.6‑Cyber model offers high compliance for authorized vulnerability research</strong></li><li><strong>Access remains restricted due to dual‑use risks and reduced safeguard operation</strong></li></ul><p>OpenAI has <a href="https://openai.com/index/expanding-daybreak-as-the-cyber-defense-window-narrows/" target="_blank" rel="nofollow">announced</a> two new tiers for its Daybreak dedicated cybersecurity project, each offering a different model with different levels of compliance. It also used the opportunity to introduce a new security-focused AI model, as well.</p><p>Hackers and criminals are increasingly abusing AI to improve and speed up the creation of phishing emails and malicious code, and with the introduction of <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a>, they’ve also used it to automate entire attack processes. The AI community responded by placing strong guardrails, making sure their models do not comply with requests to build malware, or hack other companies.</p><p>These guardrails ended up being a two-edged sword, because as they slowed down attackers, they also slowed down the defenders.</p><h2 id="what-is-daybreak">What is Daybreak?</h2><p>To give the cybersecurity community the upper edge, companies like OpenAI started creating <a href="https://www.techradar.com/pro/security/openai-reveals-daybreak-its-attempt-to-topple-anthropic-mythos" target="_blank">dedicated cybersecurity initiatives</a> that provide a vetted list of companies state-of-the-art models, free of guardrails. The company also provided them with pre-trained AI agents, as well as access to a pool of shared knowledge.</p><p>Initially launched in June 2026, Daybreak originally included GPT.5-5-Cyber (a model optimized for security work), Codex Security (an agent that can analyze codebases, identify vulnerabilities, validate findings, and help develop patches), Patch the Planet (an initiative with Trail of Bits to find and fix vulnerabilities in open-source software), Daybreak Cyber Partner Program (lets approved cybersecurity companies such as Cloudflare or Cisco integrate OpenAI's cyber capabilities into their own products and services), and Trusted Access for Cyber (the governance/access system for organizations doing authorized cybersecurity work with these capabilities).</p><p>Now, OpenAI has expanded Daybreak with two access tiers, Daybreak Blue, and Daybreak Red.</p><p>The company says Daybreak Blue is “the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation. Companies opting for this tier can expect access to frontier general-purpose models, including GPT‑5.6 Sol, whose safeguards have been tailored to authorized defensive security work.</p><p>Daybreak Red, on the other hand, provides access to OpenAI’s “purpose-trained cybersecurity models for authorized vulnerability research, exploit validation, and security testing.” This tier offers the brand new GPT‑5.6‑Cyber, built on GPT‑5.6 Sol and trained to improve capabilities on several specialized cybersecurity tasks such as finding zero-day vulnerabilities and developing exploit chains.</p><p>This model is also more compliant and less likely to refuse certain higher-risk, dual-use cyber tasks.</p><h2 id="complying-with-dangerous-requests">Complying with "dangerous" requests</h2><p>Request compliance is the name of the game here. OpenAI says the new model addresses feedback from security researchers who “encountered persistent refusals with the earlier model.” General-purpose GPT-5.6 Sol, for example, will comply with just 1.5% of the requests usually given by cyber-defenders working on codebase analysis or vulnerability identification. This percentage increases to 2.0% with Daybreak Blue access. </p><p>GPT-5.6-Cyber, on the other hand, completes 95.0% of requests, OpenAI says, up from 57.3% of the previous model, GPT-5.5-Cyber. We weren’t able to independently verify these claims, though. </p><p>While it doesn’t outright say it, OpenAI considers these models relatively dangerous to use, which is why they’re locked behind the Daybreak Cyber Partner Program. However, the program is now expanding, allowing these companies to embed the models behind their own products, managed services, or cybersecurity engagements, and offer them to clients of their own. </p><p>Those who wish to be a part of the program directly can do so by applying to join online now.</p><p>“Models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment. Despite these risks, we believe that democratizing access to frontier intelligence for defenders is crucial to accelerating and automating cyber defense,” OpenAI said.</p><p>“Daybreak Blue and Daybreak Red access are available for approved individuals⁠ and organizations conducting authorized work. We control access through identity verification, account security, monitoring, approved-use restrictions, and legal attestations.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The CEVA Logistics data breach is having major knock-on effects across Europe - here's what we know ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CEVA Logistics hack disrupted European warehouses and exposed some customer data</strong></li><li><strong>Retailers and Valve reported compromised delivery information and service delays</strong></li><li><strong>Clients warned of targeted scams while awaiting fuller incident details from CEVA</strong></li></ul><p>CEVA Logistics, one of the biggest shipping and logistics companies in the world, has suffered a major cyberattack, the effects of which are trickling down to many of its clients. </p><p>The details of the hack itself, however, are not yet publicly available and what little information is out there came from the affected clients themselves.</p><p>CEVA has not yet issued an official statement, or filed a report with the regulators, but confirmed to <a href="https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/" target="_blank"><em>TechCrunch</em></a> that the attack most likely started on July 29, 2026, and affected at least eight warehouses across Europe.</p><h2 id="technical-details-missing-affected-customers-step-forward">Technical details missing, affected customers step forward</h2><p>CEVA Logistics is a global logistics and supply-chain company and a wholly owned subsidiary of CMA CGM, a French shipping giant. It provides freight forwarding, contract logistics, warehousing and transportation services to thousands of customers, including major companies in the consumer and retail, automotive, industrial and aerospace sectors. </p><p>The company operates in more than 170 countries around the world and last year it generated $18.3 billion in gross revenue, so it is a major player and a key target for attackers.</p><p>The details about the incident itself are scarce right now. We don’t know how the crooks broke in (via a successful social engineering attack, or by abusing a software vulnerability, for example), how much data they stole, or if they demanded a ransom payment in exchange for deleting the stolen goods. From one of the victims, though, we have learned that some data was most likely compromised.</p><p>When the effects of a cyberattack spill into the physical realm (as is the case here with eight affected warehouses) we can speculate the attack was either <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a>, or disruptive <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. Companies shut down parts of their IT infrastructure only when there is no other way to clear an infection or remove malicious outsiders.</p><p>In the meantime, a small number of CEVA’s customers confirmed suffering an attack and losing sensitive data. </p><p>Among them is Bol, a Dutch online retail company, which said the incident affected two systems used for processing orders from one of its fulfillment</p><p>“No bol systems were affected,” it said. “However, data of customers whose orders were processed via this location may have been viewed or copied.”</p><p>Bol also said restoring operations at one of CEVA’s locations was taking longer than anticipated. As a result, the assortment stored at the affected location was taken offline, and the products were unavailable for sale. Also, Bol is currently unable to receive goods from suppliers and sales partners at that location.</p><p>A similar announcement was given by De Bijenkorf, another Dutch luxury retailer, who said that order processing, returns, and refunds, might take longer, but stressed that its stores remained open. It also said that some customer data may have been compromised, including names, contact details, online orders data and, in some cases, VAT numbers. Payment information, bank account numbers (IBANs), credit card information, usernames, or passwords, were not compromised, it was confirmed. </p><h2 id="valve-steps-forward">Valve steps forward</h2><p>Retail giants aside, PC gaming powerhouse Valve also notified its customers about the incident. It said CEVA ships Steam hardware to its European customers and as such, receives specific delivery-related information from Steam. </p><p>This information, which CEVA retains for up to 90 days after the order, was most likely compromised. It includes names, street addresses, phone numbers, email addresses, and the type and price of ordered products.</p><p>Valve warned its customers to expect fake messages, either via email, SMS, or phone, that might mention recent hardware orders. </p><p>“They may quote your address back to you to prove they're genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to “verify” your order. Treat all of them as fake,” Valve warned. The company also stressed that customer accounts are safe and that users need not do anything to secure them.</p><p>Other details are missing, not just for the general public, but for the affected CEVA clients, as well. Valve said it was “pressing” the company for the full scope of what was taken and how, and added that it is notifying the relevant authorities, as well. </p><p>A spokesperson of the Dutch data protection authority, Mark Schenkel, told <em>TechCrunch</em> the agency so far received 10 incident reports. Given the size of CEVA, it’s safe to assume there will be others.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/the-ceva-logistics-data-breach-is-having-major-knock-on-effects-across-europe-heres-what-we-know</link>
                                                                            <description>
                            <![CDATA[ Shipping and logistics powerhouse suffers a cyberattack, affecting almost a dozen of its clients - we take a look at the details. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">znDNTChe2TpJRXew9c5Wz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Aug 2026 11:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CEVA Logistics hack disrupted European warehouses and exposed some customer data</strong></li><li><strong>Retailers and Valve reported compromised delivery information and service delays</strong></li><li><strong>Clients warned of targeted scams while awaiting fuller incident details from CEVA</strong></li></ul><p>CEVA Logistics, one of the biggest shipping and logistics companies in the world, has suffered a major cyberattack, the effects of which are trickling down to many of its clients. </p><p>The details of the hack itself, however, are not yet publicly available and what little information is out there came from the affected clients themselves.</p><p>CEVA has not yet issued an official statement, or filed a report with the regulators, but confirmed to <a href="https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/" target="_blank"><em>TechCrunch</em></a> that the attack most likely started on July 29, 2026, and affected at least eight warehouses across Europe.</p><h2 id="technical-details-missing-affected-customers-step-forward">Technical details missing, affected customers step forward</h2><p>CEVA Logistics is a global logistics and supply-chain company and a wholly owned subsidiary of CMA CGM, a French shipping giant. It provides freight forwarding, contract logistics, warehousing and transportation services to thousands of customers, including major companies in the consumer and retail, automotive, industrial and aerospace sectors. </p><p>The company operates in more than 170 countries around the world and last year it generated $18.3 billion in gross revenue, so it is a major player and a key target for attackers.</p><p>The details about the incident itself are scarce right now. We don’t know how the crooks broke in (via a successful social engineering attack, or by abusing a software vulnerability, for example), how much data they stole, or if they demanded a ransom payment in exchange for deleting the stolen goods. From one of the victims, though, we have learned that some data was most likely compromised.</p><p>When the effects of a cyberattack spill into the physical realm (as is the case here with eight affected warehouses) we can speculate the attack was either <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a>, or disruptive <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. Companies shut down parts of their IT infrastructure only when there is no other way to clear an infection or remove malicious outsiders.</p><p>In the meantime, a small number of CEVA’s customers confirmed suffering an attack and losing sensitive data. </p><p>Among them is Bol, a Dutch online retail company, which said the incident affected two systems used for processing orders from one of its fulfillment</p><p>“No bol systems were affected,” it said. “However, data of customers whose orders were processed via this location may have been viewed or copied.”</p><p>Bol also said restoring operations at one of CEVA’s locations was taking longer than anticipated. As a result, the assortment stored at the affected location was taken offline, and the products were unavailable for sale. Also, Bol is currently unable to receive goods from suppliers and sales partners at that location.</p><p>A similar announcement was given by De Bijenkorf, another Dutch luxury retailer, who said that order processing, returns, and refunds, might take longer, but stressed that its stores remained open. It also said that some customer data may have been compromised, including names, contact details, online orders data and, in some cases, VAT numbers. Payment information, bank account numbers (IBANs), credit card information, usernames, or passwords, were not compromised, it was confirmed. </p><h2 id="valve-steps-forward">Valve steps forward</h2><p>Retail giants aside, PC gaming powerhouse Valve also notified its customers about the incident. It said CEVA ships Steam hardware to its European customers and as such, receives specific delivery-related information from Steam. </p><p>This information, which CEVA retains for up to 90 days after the order, was most likely compromised. It includes names, street addresses, phone numbers, email addresses, and the type and price of ordered products.</p><p>Valve warned its customers to expect fake messages, either via email, SMS, or phone, that might mention recent hardware orders. </p><p>“They may quote your address back to you to prove they're genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to “verify” your order. Treat all of them as fake,” Valve warned. The company also stressed that customer accounts are safe and that users need not do anything to secure them.</p><p>Other details are missing, not just for the general public, but for the affected CEVA clients, as well. Valve said it was “pressing” the company for the full scope of what was taken and how, and added that it is notifying the relevant authorities, as well. </p><p>A spokesperson of the Dutch data protection authority, Mark Schenkel, told <em>TechCrunch</em> the agency so far received 10 incident reports. Given the size of CEVA, it’s safe to assume there will be others.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Preparing for post-quantum cryptography: Building a practical roadmap ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The conversation around post-quantum cryptography (PQC) has shifted. Organizations are no longer asking whether they should prepare for quantum computing, but how quickly they can execute a <a href="https://www.techradar.com/best/best-data-migration-tools">migration</a> that many expect will take years to complete.</p><p>As technology providers accelerate their roadmaps, governments introduce new expectations and boards seek greater assurance over cyber resilience, quantum readiness has become a business priority rather than a future technology project.</p><p>That urgency is being driven from several directions. Google and Microsoft have both set out roadmaps that point towards 2029 as a significant milestone in the transition to quantum-safe cryptography, while the recent US Executive Order on strengthening national cyber <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> reinforces the expectation that organizations begin preparing for the post-quantum era.</p><p>Together, these developments are shortening the planning horizon and increasing the pressure on CISOs to move from strategy to execution.</p><p>That shift from awareness to execution is reflected across the industry. Gartner's 2026 CISO Role-Based Survey: State of the Union found that fewer than one in four organizations have made measurable progress towards quantum readiness and only 8% have a usable cryptographic inventory.</p><p>DigiCert’s own Quantum Readiness Outlook research tells a similar story, as most IT and security leaders expect quantum computers to be capable of breaking today's encryption methods within the next three to five years, yet only 7% report that more than half of their digital certificates are already quantum-safe or hybrid.</p><p>The greatest challenge organizations face is no longer understanding the risks posed by quantum, but instead about becoming quantum-ready before today's cryptography becomes tomorrow's liability.</p><h2 id="why-the-risk-is-already-here">Why the risk is already here</h2><p>Quantum computing has the potential to deliver significant advances across science, medicine and <a href="https://www.techradar.com/phones/best-ai-phone">artificial intelligence</a>, but it also threatens the asymmetric cryptography that secures digital identities, software, financial transactions and communications. The concern is no longer confined to the arrival of a cryptographically relevant quantum computer.</p><p>Threat actors are widely believed to be adopting a harvest now, decrypt later (HNDL) approach, collecting encrypted <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> today with the expectation that it can be decrypted once quantum capabilities mature. For organizations protecting information with a long operational life, that changes the timeline completely.</p><p>Our data found that 84% of organizations believe at least some of their encrypted data is vulnerable to HNDL attacks. Financial transaction records and banking data were identified as the assets most at risk (58%), followed by cryptocurrency wallets and private keys (53%).</p><p>For CISOs, this provides an important starting point because rather than attempting to replace every cryptographic system simultaneously, the priority should be identifying the systems protecting long-lived, high-value information and focusing migration efforts where the business impact would be greatest.</p><h2 id="discovery-before-deployment">Discovery before deployment</h2><p>For many organizations, the greatest challenge is not selecting quantum-resistant algorithms, but understanding where vulnerable cryptography exists across the business.</p><p>Furthermore, cryptography underpins cloud infrastructure, enterprise applications, connected devices, operational technology, software signing and countless machine identities. Over time, certificates, keys and algorithms become distributed across complex environments, often without a complete inventory of where they are used or which business services depend on them.</p><p>This is why discovery should be the first stage of every quantum readiness program. Organizations cannot prioritize risk, assess dependencies or build a realistic migration roadmap without first understanding their existing cryptographic estate. Discovery also enables security teams to identify the systems protecting their most valuable assets, allowing them to focus investment where it will have the greatest impact.</p><p>Once that foundation is in place, organizations can begin introducing quantum-resistant algorithms alongside existing <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, testing interoperability, prioritizing critical systems and building the crypto-agility needed to adapt as standards continue to evolve.</p><h2 id="building-a-practical-roadmap">Building a practical roadmap</h2><p>Preparing for post-quantum cryptography is not a single technology upgrade, in fact, it is a long-term business transformation program that requires collaboration across security, infrastructure, application teams and technology partners.</p><p>The discovery stage provides the foundation by revealing where cryptography is deployed, exposing hidden dependencies and identifying systems that may otherwise be overlooked. Those unknowns are often the biggest source of delay, making early discovery essential to building a realistic migration roadmap.</p><p>With that understanding, organizations can begin prioritizing the systems that present the greatest business risk while assessing whether their wider technology ecosystem is ready for the transition.</p><p>That means working with <a href="https://www.techradar.com/best/best-small-business-software">software</a>, hardware and <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud providers</a> to understand their post-quantum roadmaps, identifying platforms that will require upgrades, and reviewing critical infrastructure, including web servers and TLS implementations, to ensure they can support quantum-safe cryptography.</p><p>It is important to remember that cryptographic standards will continue to evolve, making automation and crypto-agility essential for managing certificates, keys and algorithms at scale and adapting to future change.</p><p>The organizations that succeed will not be those that wait for quantum computing to arrive, but those that begin preparing now. By uncovering the unknowns within their cryptographic estate and building a phased migration strategy based on business risk, CISOs can strengthen resilience today while preparing their organizations for the cryptographic challenges of tomorrow.</p><p><em></em><a href="https://www.techradar.com/news/best-business-desktop-pcs"><em>We've featured the best business computer.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/preparing-for-post-quantum-cryptography-building-a-practical-roadmap</link>
                                                                            <description>
                            <![CDATA[ Organizations must become quantum-ready before today's cryptography becomes tomorrow's liability. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Mmdh7reK9bRVsRGAh65p34</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Vnzhig9TKriKCaFGiYi92E-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Aug 2026 09:44:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rich Hall ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Vnzhig9TKriKCaFGiYi92E-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Quantum computing]]></media:description>                                                            <media:text><![CDATA[Quantum computing]]></media:text>
                                <media:title type="plain"><![CDATA[Quantum computing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Vnzhig9TKriKCaFGiYi92E-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The conversation around post-quantum cryptography (PQC) has shifted. Organizations are no longer asking whether they should prepare for quantum computing, but how quickly they can execute a <a href="https://www.techradar.com/best/best-data-migration-tools">migration</a> that many expect will take years to complete.</p><p>As technology providers accelerate their roadmaps, governments introduce new expectations and boards seek greater assurance over cyber resilience, quantum readiness has become a business priority rather than a future technology project.</p><p>That urgency is being driven from several directions. Google and Microsoft have both set out roadmaps that point towards 2029 as a significant milestone in the transition to quantum-safe cryptography, while the recent US Executive Order on strengthening national cyber <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> reinforces the expectation that organizations begin preparing for the post-quantum era.</p><p>Together, these developments are shortening the planning horizon and increasing the pressure on CISOs to move from strategy to execution.</p><p>That shift from awareness to execution is reflected across the industry. Gartner's 2026 CISO Role-Based Survey: State of the Union found that fewer than one in four organizations have made measurable progress towards quantum readiness and only 8% have a usable cryptographic inventory.</p><p>DigiCert’s own Quantum Readiness Outlook research tells a similar story, as most IT and security leaders expect quantum computers to be capable of breaking today's encryption methods within the next three to five years, yet only 7% report that more than half of their digital certificates are already quantum-safe or hybrid.</p><p>The greatest challenge organizations face is no longer understanding the risks posed by quantum, but instead about becoming quantum-ready before today's cryptography becomes tomorrow's liability.</p><h2 id="why-the-risk-is-already-here">Why the risk is already here</h2><p>Quantum computing has the potential to deliver significant advances across science, medicine and <a href="https://www.techradar.com/phones/best-ai-phone">artificial intelligence</a>, but it also threatens the asymmetric cryptography that secures digital identities, software, financial transactions and communications. The concern is no longer confined to the arrival of a cryptographically relevant quantum computer.</p><p>Threat actors are widely believed to be adopting a harvest now, decrypt later (HNDL) approach, collecting encrypted <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> today with the expectation that it can be decrypted once quantum capabilities mature. For organizations protecting information with a long operational life, that changes the timeline completely.</p><p>Our data found that 84% of organizations believe at least some of their encrypted data is vulnerable to HNDL attacks. Financial transaction records and banking data were identified as the assets most at risk (58%), followed by cryptocurrency wallets and private keys (53%).</p><p>For CISOs, this provides an important starting point because rather than attempting to replace every cryptographic system simultaneously, the priority should be identifying the systems protecting long-lived, high-value information and focusing migration efforts where the business impact would be greatest.</p><h2 id="discovery-before-deployment">Discovery before deployment</h2><p>For many organizations, the greatest challenge is not selecting quantum-resistant algorithms, but understanding where vulnerable cryptography exists across the business.</p><p>Furthermore, cryptography underpins cloud infrastructure, enterprise applications, connected devices, operational technology, software signing and countless machine identities. Over time, certificates, keys and algorithms become distributed across complex environments, often without a complete inventory of where they are used or which business services depend on them.</p><p>This is why discovery should be the first stage of every quantum readiness program. Organizations cannot prioritize risk, assess dependencies or build a realistic migration roadmap without first understanding their existing cryptographic estate. Discovery also enables security teams to identify the systems protecting their most valuable assets, allowing them to focus investment where it will have the greatest impact.</p><p>Once that foundation is in place, organizations can begin introducing quantum-resistant algorithms alongside existing <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, testing interoperability, prioritizing critical systems and building the crypto-agility needed to adapt as standards continue to evolve.</p><h2 id="building-a-practical-roadmap">Building a practical roadmap</h2><p>Preparing for post-quantum cryptography is not a single technology upgrade, in fact, it is a long-term business transformation program that requires collaboration across security, infrastructure, application teams and technology partners.</p><p>The discovery stage provides the foundation by revealing where cryptography is deployed, exposing hidden dependencies and identifying systems that may otherwise be overlooked. Those unknowns are often the biggest source of delay, making early discovery essential to building a realistic migration roadmap.</p><p>With that understanding, organizations can begin prioritizing the systems that present the greatest business risk while assessing whether their wider technology ecosystem is ready for the transition.</p><p>That means working with <a href="https://www.techradar.com/best/best-small-business-software">software</a>, hardware and <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud providers</a> to understand their post-quantum roadmaps, identifying platforms that will require upgrades, and reviewing critical infrastructure, including web servers and TLS implementations, to ensure they can support quantum-safe cryptography.</p><p>It is important to remember that cryptographic standards will continue to evolve, making automation and crypto-agility essential for managing certificates, keys and algorithms at scale and adapting to future change.</p><p>The organizations that succeed will not be those that wait for quantum computing to arrive, but those that begin preparing now. By uncovering the unknowns within their cryptographic estate and building a phased migration strategy based on business risk, CISOs can strengthen resilience today while preparing their organizations for the cryptographic challenges of tomorrow.</p><p><em></em><a href="https://www.techradar.com/news/best-business-desktop-pcs"><em>We've featured the best business computer.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'It's Stalin's dream' — Quote of the day by software pioneer Richard Stallman on the tracking capabilities of cell phones ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The programmer Richard Stallman is not a household name, but his work has been instrumental in building the software industry, as has his long-term campaign for free software. He's also been a huge advocate for privacy in the digital age, and has railed against the rise of cell phones for that reason.</p><h2 id="who-needs-phones-anyway">Who needs phones anyway? </h2><p>Stallman first disclosed his views on cell phones in an interview with <a href="https://www.networkworld.com/article/721767/software-cell-phones-are-stalin-s-dream-says-free-software-movement-founder.html" target="_blank" rel="nofollow"><em>Network World</em></a>, during a time in which smartphones were exploding in popularity.</p><div  class="fancy-box"><div class="fancy_box-title">Quote of the day</div><div class="fancy_box_body"><p class="fancy-box__body-text">This article is part of TechRadar Pro's QOTD project to provide an insight into the minds of the brightest and most recognized figures in the technology industry today and in years gone by. <a data-analytics-id="inline-link" href="https://www.techradar.com/tag/qotd">Read the full series here</a>.</p></div></div><p>During this interview, Stallman indicated his long-held belief that the portable phones that many millions use would be the perfect tool that authoritarian forces could exploit and use to track the movements of populations. </p><p>He also advocated for free software, which you would expect from the founder of the Free Software Foundation (FSF), which he established in 1985. This was backed by the creation of the GNU project – a free software, mass collaboration movement to give users freedom of choice to use and develop software for their devices.</p><h2 id="the-legacy-of-free-software">The legacy of free software</h2><p>Despite his reluctance to ever use a cell phone, one of Stallman's achievements – which he himself acknowledged in the interview – was the third-party version of the Android mobile OS, from which all proprietary software was stripped out. </p><p>He pointed to new systems like Replicant, an alternative version of Android, that can run on certain devices without additional proprietary software. The catch is that this only works with <a href="https://replicant.us/supported-devices.php" target="_blank" rel="nofollow">older and outdated handsets</a>, like the Samsung Galaxy S3 or the Galaxy Note 2.  </p><div style="min-height: 250px;">                                <div class="kwizly-quiz kwizly-OdvAJe"></div>                            </div>                            <script src="https://kwizly.com/embed/OdvAJe.js" async></script> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/its-stalins-dream-quote-of-the-day-by-software-pioneer-richard-stallman-on-the-tracking-capabilities-of-cell-phones</link>
                                                                            <description>
                            <![CDATA[ The long-time privacy advocate doesn't carry a cell phone to avoid being tracked ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Cas6XEM9cLfLKfJ7YmVypY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/M7itUxdAuWUDX9UeViLsfP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 22:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/baEeYWYTHEpvddufVqymoA.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Keumars Afifi-Sabet is a freelance contributor for Tech Radar and Technology Editor for Live Science. He has written for a variety of publications including ITPro, The Week Digital and ComputerActive. He has worked as a technology journalist for more than five years, having previously held the role of features editor with ITPro. In his previous role, he oversaw the commissioning and publishing of long form in areas including AI, cyber security, cloud computing and digital transformation.&lt;/p&gt;&lt;p&gt;An NCTJ-qualified journalist who specialises in technology, his path into journalism began at university. He immersed himself in student media while studying for a degree in biomedical sciences at Queen Mary, University of London. After graduating, Keumars wrote for a variety of local and national publications as a freelancer, including The Independent, The Observer, and Metro. While studying for his NCTJ certification, his work was commended in the category of ‘Top Scoop’ in the 2017 NCTJ awards. He’s also registered as a foundational chartered manager with the Chartered Management Institute (CMI), having qualified as a Level 3 Team leader with distinction in 2023.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/M7itUxdAuWUDX9UeViLsfP-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/FRANCOIS GUILLOT / Staff]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Richard Stallman]]></media:description>                                                            <media:text><![CDATA[Richard Stallman]]></media:text>
                                <media:title type="plain"><![CDATA[Richard Stallman]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/M7itUxdAuWUDX9UeViLsfP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The programmer Richard Stallman is not a household name, but his work has been instrumental in building the software industry, as has his long-term campaign for free software. He's also been a huge advocate for privacy in the digital age, and has railed against the rise of cell phones for that reason.</p><h2 id="who-needs-phones-anyway">Who needs phones anyway? </h2><p>Stallman first disclosed his views on cell phones in an interview with <a href="https://www.networkworld.com/article/721767/software-cell-phones-are-stalin-s-dream-says-free-software-movement-founder.html" target="_blank" rel="nofollow"><em>Network World</em></a>, during a time in which smartphones were exploding in popularity.</p><div  class="fancy-box"><div class="fancy_box-title">Quote of the day</div><div class="fancy_box_body"><p class="fancy-box__body-text">This article is part of TechRadar Pro's QOTD project to provide an insight into the minds of the brightest and most recognized figures in the technology industry today and in years gone by. <a data-analytics-id="inline-link" href="https://www.techradar.com/tag/qotd">Read the full series here</a>.</p></div></div><p>During this interview, Stallman indicated his long-held belief that the portable phones that many millions use would be the perfect tool that authoritarian forces could exploit and use to track the movements of populations. </p><p>He also advocated for free software, which you would expect from the founder of the Free Software Foundation (FSF), which he established in 1985. This was backed by the creation of the GNU project – a free software, mass collaboration movement to give users freedom of choice to use and develop software for their devices.</p><h2 id="the-legacy-of-free-software">The legacy of free software</h2><p>Despite his reluctance to ever use a cell phone, one of Stallman's achievements – which he himself acknowledged in the interview – was the third-party version of the Android mobile OS, from which all proprietary software was stripped out. </p><p>He pointed to new systems like Replicant, an alternative version of Android, that can run on certain devices without additional proprietary software. The catch is that this only works with <a href="https://replicant.us/supported-devices.php" target="_blank" rel="nofollow">older and outdated handsets</a>, like the Samsung Galaxy S3 or the Galaxy Note 2.  </p><div style="min-height: 250px;">                                <div class="kwizly-quiz kwizly-OdvAJe"></div>                            </div>                            <script src="https://kwizly.com/embed/OdvAJe.js" async></script>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top US defense device maker IEH Corporation admits hackers broke into its systems ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Attackers stole IEH employee credentials via a fake Microsoft login page</strong></li><li><strong>Inbox access exposed sensitive defense‑related communications and technical documentation</strong></li><li><strong>Malicious mailbox rules were removed as IEH contained the unauthorized access</strong></li></ul><p>Criminals have broken into the email inboxes of IEH Corporation, a significant supplier for the US military and companies in the commercial aerospace and space industry.</p><p>In an 8-K report filed with the US Securities and Exchange Commission (SEC), IEH said that unidentified threat actors reached out to one of its employees, pretending to be a “prospective business contact”. </p><p>The atatckers shared a link to what appeared to be a Microsoft document, prompting the victim to log in. Obviously, the login page was bogus, and the login credentials were relayed to the attackers instead.</p><h2 id="malicious-mailbox-rules">Malicious mailbox rules</h2><p>“The threat actor gained access to mailbox contents, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information,” the 8-K reads.</p><p>The culprits, however, were not named and no threat actors have yet claimed responsibility for the attack.</p><p>IEH said it found no evidence that data had been exfiltrated from the compromised inbox. However, its defenders did discover and remove “malicious mailbox rules”. Usually, crooks set up such rules to automatically forward incoming emails to an inbox under their control, while deleting traces of the activity. This would allow them to continue receiving sensitive emails even after the initial compromise was remediated. </p><p>The company also said it completed a full audit of the inbox and done “corrective actions to contain any impact of the unauthorized access.”</p><p>IEH Corporation produces “specialized products used in military satellites, missiles and fighter jets,” meaning the information found in the inbox could be quite valuable, especially for nation-states such as Russia, China, North Korea, or Iran. </p><p>IEH does not publicly name its clients but it does say that its defense applications include Apache AH-64, V-280 Valor and SH-60 Seahawk programs, as well as Patriot, THAAD, AMRAAM and APKWS missile programs. It reported a revenue of almost $30 million for the 2026 fiscal year.</p><p><em>Via </em><a href="https://therecord.media/military-device-manufacturer-discloses-cyber-incident" target="_blank"><em>The Record</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/top-us-defense-device-maker-ieh-corporation-admits-hackers-broke-into-its-systems</link>
                                                                            <description>
                            <![CDATA[ Someone used social engineering to access an employee's email account, viewing purchase orders, engineering-related documentation, and more. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pZcCMmHbAqHJRNxLfwWFdY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TLsB5tZb8kRUnWbcRmNDuB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TLsB5tZb8kRUnWbcRmNDuB-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ground military drone for cargo transportation]]></media:description>                                                            <media:text><![CDATA[Ground military drone for cargo transportation]]></media:text>
                                <media:title type="plain"><![CDATA[Ground military drone for cargo transportation]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TLsB5tZb8kRUnWbcRmNDuB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers stole IEH employee credentials via a fake Microsoft login page</strong></li><li><strong>Inbox access exposed sensitive defense‑related communications and technical documentation</strong></li><li><strong>Malicious mailbox rules were removed as IEH contained the unauthorized access</strong></li></ul><p>Criminals have broken into the email inboxes of IEH Corporation, a significant supplier for the US military and companies in the commercial aerospace and space industry.</p><p>In an 8-K report filed with the US Securities and Exchange Commission (SEC), IEH said that unidentified threat actors reached out to one of its employees, pretending to be a “prospective business contact”. </p><p>The atatckers shared a link to what appeared to be a Microsoft document, prompting the victim to log in. Obviously, the login page was bogus, and the login credentials were relayed to the attackers instead.</p><h2 id="malicious-mailbox-rules">Malicious mailbox rules</h2><p>“The threat actor gained access to mailbox contents, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information,” the 8-K reads.</p><p>The culprits, however, were not named and no threat actors have yet claimed responsibility for the attack.</p><p>IEH said it found no evidence that data had been exfiltrated from the compromised inbox. However, its defenders did discover and remove “malicious mailbox rules”. Usually, crooks set up such rules to automatically forward incoming emails to an inbox under their control, while deleting traces of the activity. This would allow them to continue receiving sensitive emails even after the initial compromise was remediated. </p><p>The company also said it completed a full audit of the inbox and done “corrective actions to contain any impact of the unauthorized access.”</p><p>IEH Corporation produces “specialized products used in military satellites, missiles and fighter jets,” meaning the information found in the inbox could be quite valuable, especially for nation-states such as Russia, China, North Korea, or Iran. </p><p>IEH does not publicly name its clients but it does say that its defense applications include Apache AH-64, V-280 Valor and SH-60 Seahawk programs, as well as Patriot, THAAD, AMRAAM and APKWS missile programs. It reported a revenue of almost $30 million for the 2026 fiscal year.</p><p><em>Via </em><a href="https://therecord.media/military-device-manufacturer-discloses-cyber-incident" target="_blank"><em>The Record</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why business leaders need to take quantum seriously ]]></title>
                                                                                                <dc:content><![CDATA[ <p>You may have heard a lot about quantum in the past few months, from your newsfeed to your competitors’ strategies. Last year was proclaimed the “International Year of Quantum Science and Technology” by the United Nations to celebrate the 100th anniversary of quantum mechanics.  </p><p>While quantum belonged to the writings of the brightest scientists a century ago, it now animates conversations in both academic and business circles. </p><p>But what should you do about it as a <a href="https://www.techradar.com/best/best-business-plan-software">business</a> leader?</p><p>Quantum technologies use the principles of quantum mechanics to unlock new possibilities and can be split into three distinct categories. Quantum computing uses quantum bits instead of classical 0 or 1 bits to perform calculations. </p><p>Quantum sensing uses the same underlying physics to take very precise measurements, like an extraordinarily precise compass. And quantum communication enables the ultra-secure exchange of sensitive information. </p><p>Each of these technologies is on a different maturity curve. </p><h2 id="one-theory-three-subfields">One theory, three subfields</h2><p>Quantum computing gets the most attention for a reason: it represents the largest estimated market size; and will unlock a completely new set of possibilities. Unlike classical bits, quantum bits can exist in a superposition of 0 and 1 simultaneously, enabling the exploration of many possibilities at once. </p><p>This capability is especially valuable for optimization problems, for example, finding the optimal route between two points. However, quantum bits, or qubits, are fragile and error-prone, today’s machines are still what we call “Noisy Intermediate-Scale” systems, and hold limited practical usefulness. </p><p>The industry is developing Fault-Tolerant Quantum Computers (FTQC) by using error correction methods to unlock reliable calculations. Given that these systems are not commercially available, waiting might seem like the best way forward; but it is exactly the opposite.</p><p>Businesses must prepare now for the advent of FTQCs. Because quantum <a href="https://www.techradar.com/news/best-business-desktop-pcs">computers</a> operate on fundamentally different principles from classical machines, algorithms must be tailored to them, often to the point of redesign. </p><p>Building these capabilities is critical for businesses to secure a competitive advantage, but it will take time, so companies must start now if they have not yet explored this field. While quantum computers mature, another branch is already delivering value: quantum sensing.</p><p>Quantum sensors are one of the most underrated segments of the industry. Far more mature than quantum computers, some technologies are already being deployed in real-world settings. Applications have been developed in many sectors such as non-invasive cardiac diagnosis, non-destructive testing in manufacturing or GPS-free navigation. </p><p>This subfield is dual-use: sensors can passively detect concealed objects or track ground vehicles, which is why this technology is considered a strategic asset rather than a purely commercial one in many countries. </p><p>Quantum communications use the principles of quantum mechanics to create secure <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> transmission networks in which leaks or espionage can be physically detected. The EuroQCI joint initiative between the European Commission and ESA aims to develop this <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> across the continent, while China has constructed a secure link spanning more than two thousand kilometers between Beijing and Shanghai.</p><h2 id="quantum-as-a-strategic-asset">Quantum as a strategic asset</h2><p>The advent of FTQCs will not only unlock new opportunities for businesses but also pose significant <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> threats for our systems. Indeed, they are expected to break the most widely used cryptographic schemes, creating a cybersecurity nightmare situation. </p><p>Although quantum computers do not yet have this capability, highly sensitive information like health or financial data can be collected now and decrypted later. Post-quantum cryptography, which uses classical methods, has been developed to resist quantum attacks. A June 2026 US executive order set a 2031 deadline for high-value, high-impact systems to migrate to post-quantum cryptography, and France's <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity </a>agency will certify only quantum-safe products starting in 2027.</p><p>Governments have also begun treating quantum as a controlled and sovereign technology. The US restricted exports of quantum computers in late 2024, and the EU added quantum to its dual-use control list in 2025. This pattern mirrors what’s happening with AI, with the US government briefly imposing export controls on Anthropic’s Fable 5 model. </p><p>These regulatory efforts are happening while AI and quantum are already converging and accelerating each other’s development, despite being fundamentally different technologies. <a href="https://www.techradar.com/best/best-ai-tools">Artificial intelligence</a> is now widely used in the computing community for programming, notably to accelerate the creation of quantum algorithms. </p><p>Quantum sensors already rely on to machine learning methods to differentiate target signatures against noise, notably enabling more sensitive detection. Quantum computing, in turn, could open new hardware possibilities for artificial intelligence. Recent research also shows that quantum algorithms can pre-select features to accelerate processes before handling them to AI models.</p><h2 id="start-small-but-start-now">Start small, but start now</h2><p>From cancer drug discovery and delivery scheduling optimization to GPS-free navigation and risk simulation, quantum technologies hold the promise of revolutionizing various use cases across industries. Investors spent more than $12B on quantum technology startups in 2025, and around 30 countries have developed specific policies or a national strategy. </p><p>No one expects business leaders to become quantum physicists; however, ignoring the quantum opportunities and threats could put your business at risk. Developing expertise, notably by hiring or upskilling a “Chief Quantum Officer” who will lead quantum strategy and prepare for the opportunities and risks ahead, will secure a competitive advantage in the long run. </p><p>In order to grasp this potential, start by identifying at least one business challenge you are currently facing and explore whether quantum can solve it.</p><p><em></em><a href="https://www.techradar.com/news/best-business-laptops"><em>We list the best business laptops</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/why-business-leaders-need-to-take-quantum-seriously</link>
                                                                            <description>
                            <![CDATA[ Quantum is now a conversation that business leaders are having and this article explores what leaders should be doing to grasp its potential ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Dq9QJRJt6XLf3g945d8QBP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/d4oN2QTeNf8QYJDmjZnAKE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 14:47:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Camille Georges ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/d4oN2QTeNf8QYJDmjZnAKE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Quantum computing]]></media:description>                                                            <media:text><![CDATA[Quantum computing]]></media:text>
                                <media:title type="plain"><![CDATA[Quantum computing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/d4oN2QTeNf8QYJDmjZnAKE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>You may have heard a lot about quantum in the past few months, from your newsfeed to your competitors’ strategies. Last year was proclaimed the “International Year of Quantum Science and Technology” by the United Nations to celebrate the 100th anniversary of quantum mechanics.  </p><p>While quantum belonged to the writings of the brightest scientists a century ago, it now animates conversations in both academic and business circles. </p><p>But what should you do about it as a <a href="https://www.techradar.com/best/best-business-plan-software">business</a> leader?</p><p>Quantum technologies use the principles of quantum mechanics to unlock new possibilities and can be split into three distinct categories. Quantum computing uses quantum bits instead of classical 0 or 1 bits to perform calculations. </p><p>Quantum sensing uses the same underlying physics to take very precise measurements, like an extraordinarily precise compass. And quantum communication enables the ultra-secure exchange of sensitive information. </p><p>Each of these technologies is on a different maturity curve. </p><h2 id="one-theory-three-subfields">One theory, three subfields</h2><p>Quantum computing gets the most attention for a reason: it represents the largest estimated market size; and will unlock a completely new set of possibilities. Unlike classical bits, quantum bits can exist in a superposition of 0 and 1 simultaneously, enabling the exploration of many possibilities at once. </p><p>This capability is especially valuable for optimization problems, for example, finding the optimal route between two points. However, quantum bits, or qubits, are fragile and error-prone, today’s machines are still what we call “Noisy Intermediate-Scale” systems, and hold limited practical usefulness. </p><p>The industry is developing Fault-Tolerant Quantum Computers (FTQC) by using error correction methods to unlock reliable calculations. Given that these systems are not commercially available, waiting might seem like the best way forward; but it is exactly the opposite.</p><p>Businesses must prepare now for the advent of FTQCs. Because quantum <a href="https://www.techradar.com/news/best-business-desktop-pcs">computers</a> operate on fundamentally different principles from classical machines, algorithms must be tailored to them, often to the point of redesign. </p><p>Building these capabilities is critical for businesses to secure a competitive advantage, but it will take time, so companies must start now if they have not yet explored this field. While quantum computers mature, another branch is already delivering value: quantum sensing.</p><p>Quantum sensors are one of the most underrated segments of the industry. Far more mature than quantum computers, some technologies are already being deployed in real-world settings. Applications have been developed in many sectors such as non-invasive cardiac diagnosis, non-destructive testing in manufacturing or GPS-free navigation. </p><p>This subfield is dual-use: sensors can passively detect concealed objects or track ground vehicles, which is why this technology is considered a strategic asset rather than a purely commercial one in many countries. </p><p>Quantum communications use the principles of quantum mechanics to create secure <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> transmission networks in which leaks or espionage can be physically detected. The EuroQCI joint initiative between the European Commission and ESA aims to develop this <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> across the continent, while China has constructed a secure link spanning more than two thousand kilometers between Beijing and Shanghai.</p><h2 id="quantum-as-a-strategic-asset">Quantum as a strategic asset</h2><p>The advent of FTQCs will not only unlock new opportunities for businesses but also pose significant <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> threats for our systems. Indeed, they are expected to break the most widely used cryptographic schemes, creating a cybersecurity nightmare situation. </p><p>Although quantum computers do not yet have this capability, highly sensitive information like health or financial data can be collected now and decrypted later. Post-quantum cryptography, which uses classical methods, has been developed to resist quantum attacks. A June 2026 US executive order set a 2031 deadline for high-value, high-impact systems to migrate to post-quantum cryptography, and France's <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity </a>agency will certify only quantum-safe products starting in 2027.</p><p>Governments have also begun treating quantum as a controlled and sovereign technology. The US restricted exports of quantum computers in late 2024, and the EU added quantum to its dual-use control list in 2025. This pattern mirrors what’s happening with AI, with the US government briefly imposing export controls on Anthropic’s Fable 5 model. </p><p>These regulatory efforts are happening while AI and quantum are already converging and accelerating each other’s development, despite being fundamentally different technologies. <a href="https://www.techradar.com/best/best-ai-tools">Artificial intelligence</a> is now widely used in the computing community for programming, notably to accelerate the creation of quantum algorithms. </p><p>Quantum sensors already rely on to machine learning methods to differentiate target signatures against noise, notably enabling more sensitive detection. Quantum computing, in turn, could open new hardware possibilities for artificial intelligence. Recent research also shows that quantum algorithms can pre-select features to accelerate processes before handling them to AI models.</p><h2 id="start-small-but-start-now">Start small, but start now</h2><p>From cancer drug discovery and delivery scheduling optimization to GPS-free navigation and risk simulation, quantum technologies hold the promise of revolutionizing various use cases across industries. Investors spent more than $12B on quantum technology startups in 2025, and around 30 countries have developed specific policies or a national strategy. </p><p>No one expects business leaders to become quantum physicists; however, ignoring the quantum opportunities and threats could put your business at risk. Developing expertise, notably by hiring or upskilling a “Chief Quantum Officer” who will lead quantum strategy and prepare for the opportunities and risks ahead, will secure a competitive advantage in the long run. </p><p>In order to grasp this potential, start by identifying at least one business challenge you are currently facing and explore whether quantum can solve it.</p><p><em></em><a href="https://www.techradar.com/news/best-business-laptops"><em>We list the best business laptops</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Age verification failed. Regulating VPNs won't fix it ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Governments are beginning to look beyond age verification itself and toward the tools people use to bypass it. In Australia, recently released Freedom of Information <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a> revealed the eSafety Commissioner wants technology companies to actively detect and block VPNs used to circumvent age checks. In the UK, Technology Secretary Liz Kendall has also suggested the government could revisit restrictions on <a href="https://www.techradar.com/vpn/best-vpn">VPNs</a>.</p><p>Viewed individually, these proposals may seem limited. Taken together, they illustrate how VPNs are increasingly being treated as part of the enforcement problem, when in reality, they are part of the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> infrastructure that businesses, journalists, remote employees and millions of ordinary users rely on every day. In the United States alone, half of the country’s remote workers use a VPN.</p><p>Age verification laws were introduced with the objective of making it harder for minors to access harmful content, but it produced an unintended consequence. Across multiple markets, growing numbers of users are turning to VPNs because they don't want to upload government IDs or facial scans to websites they neither trust nor expect to visit regularly.</p><p>Folding VPNs into the regulatory framework confuses the symptom with the problem. Banning or restricting VPNs rarely stops the underlying behavior. Instead, it pushes users toward less regulated workarounds while handing governments a new lever to tighten control over what citizens can access online. Having spent years building a <a href="https://www.techradar.com/best/best-privacy-apps-for-android">privacy</a>-first browser, I’ve learned that internet users adapt far faster than regulation.</p><h2 id="you-can-t-regulate-intent">You can't regulate intent</h2><p>Every proposal to restrict VPN use runs into the same technical problem. A VPN connection doesn't explain why someone is using it. A journalist protecting sources, a remote <a href="https://www.techradar.com/pro/best-employee-recognition-software-of-year">employee</a> on a hotel network, and someone dodging an age check look identical from the network's side, and enforcement can't tell them apart.</p><p>Any enforcement mechanism built to catch age-check bypass has to sit on top of that same traffic, and it has no way to separate a teenager evading harmful content from an accountant filing a report over a hotel connection.</p><p>Stigmatizing VPNs further won't change the underlying demand either. People don't stop wanting privacy because a tool becomes less socially acceptable. They find another way to get both, often through channels with far less transparency than the ones being restricted.</p><h2 id="the-precedent-is-important">The precedent is important</h2><p>The concern here is sharper because of where these laws tend to originate. Rules written in a few high-profile markets often become templates, and other governments treat them as proven models regardless of how well they work. If privacy tools must identify users to function, that expectation can eventually reach encrypted messaging, <a href="https://www.techradar.com/uk/best/best-cloud-storage">cloud storage</a>, and other technologies businesses depend on daily.</p><p>A company that accepts identity checks on its VPN traffic today has little basis to object when the same logic gets applied to its encrypted messaging platform or its cloud storage provider tomorrow. The infrastructure being debated under the banner of child safety is the same infrastructure that keeps corporate communications and data secure.</p><h2 id="privacy-tools-are-not-the-problem">Privacy tools are not the problem</h2><p>An estimated 1.7 billion people worldwide use VPNs, a scale that should give policymakers pause before treating them primarily as a way to bypass age verification. For most users, VPNs are part of everyday internet security, protecting communications and safeguarding public Wi-Fi connections.</p><p>The spikes in VPN usage tell a consistent story. The largest surges follow political unrest, as seen during Myanmar's turmoil, or when a popular platform is suddenly blocked, as happened when Turkey restricted Wikipedia for several years.</p><p>Laws tied to age verification drive new sign-ups too, albeit on a smaller scale, mostly from people who don't want to upload an ID or a face scan to reach a site they'd rather not be seen visiting, adult sites being the clearest case.</p><h2 id="not-all-verification-is-equal">Not all verification is equal</h2><p>It's worth separating two different situations.</p><p>Verifying age on a social network, where someone already has an <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a> and a reason to be recognized, differs from verifying age on an adult site, where the point is precisely not to be identified.</p><p>The first one is reasonable. On the other hand, I don't think anyone should hand over an ID or a facial scan for the second, given the risk of that data leaking and being used for blackmail.</p><h2 id="the-technology-already-exists-with-limits">The technology already exists, with limits</h2><p>Privacy-preserving age verification is real, and working versions already exist, though it's worth being precise about what they can and can't guarantee. Proving something with zero trace anywhere in the system is extremely hard to achieve, and trust must always sit somewhere.</p><p>A workable model separates the party confirming someone's age from the party they're visiting. A trusted intermediary checks eligibility once and issues a token in return. That token isn't a currency and isn't tied to a wallet or an account, it's simply cryptographic proof that can't be traced back to the person it was issued to. No one can identify who is presenting the token later.</p><p>It works like an ID card with the photo, name and number stripped out, leaving only a yes or no answer to one question. That token lives on the person's own device. The service confirming eligibility never holds it, the user does.</p><h2 id="privacy-and-verification-can-coexist">Privacy and verification can coexist</h2><p>Protecting minors is a legitimate policy objective, and rejecting today's approach isn't the same as rejecting age verification altogether. The question is how to achieve it without asking millions of adults to surrender more personal information than necessary. Parents are best placed to decide what their children can access using tools that already exist. Public policy should support that role.</p><p>Governments should encourage age verification systems that collect the minimum information needed to confirm eligibility, while letting privacy tools do the job they were built for. The real work is building age verification people can trust without asking them to surrender their privacy. Regulating VPNs won't get us there.</p><p><em></em><a href="https://www.techradar.com/vpn/most-secure-vpns-best-encryption"><em>We've featured the best secure VPN provider.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/age-verification-failed-regulating-vpns-wont-fix-it</link>
                                                                            <description>
                            <![CDATA[ Regulators are targeting VPNs to enforce age checks, but that confuses the symptom with the real problem. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LWhByRwnQ2sd4asHAGXAcR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 14:22:16 +0000</pubDate>                                                                                                                                <updated>Mon, 10 Aug 2026 14:22:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Andrew Frost Moroz ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Thapana Onphalai via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:description>                                                            <media:text><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:text>
                                <media:title type="plain"><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Governments are beginning to look beyond age verification itself and toward the tools people use to bypass it. In Australia, recently released Freedom of Information <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a> revealed the eSafety Commissioner wants technology companies to actively detect and block VPNs used to circumvent age checks. In the UK, Technology Secretary Liz Kendall has also suggested the government could revisit restrictions on <a href="https://www.techradar.com/vpn/best-vpn">VPNs</a>.</p><p>Viewed individually, these proposals may seem limited. Taken together, they illustrate how VPNs are increasingly being treated as part of the enforcement problem, when in reality, they are part of the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> infrastructure that businesses, journalists, remote employees and millions of ordinary users rely on every day. In the United States alone, half of the country’s remote workers use a VPN.</p><p>Age verification laws were introduced with the objective of making it harder for minors to access harmful content, but it produced an unintended consequence. Across multiple markets, growing numbers of users are turning to VPNs because they don't want to upload government IDs or facial scans to websites they neither trust nor expect to visit regularly.</p><p>Folding VPNs into the regulatory framework confuses the symptom with the problem. Banning or restricting VPNs rarely stops the underlying behavior. Instead, it pushes users toward less regulated workarounds while handing governments a new lever to tighten control over what citizens can access online. Having spent years building a <a href="https://www.techradar.com/best/best-privacy-apps-for-android">privacy</a>-first browser, I’ve learned that internet users adapt far faster than regulation.</p><h2 id="you-can-t-regulate-intent">You can't regulate intent</h2><p>Every proposal to restrict VPN use runs into the same technical problem. A VPN connection doesn't explain why someone is using it. A journalist protecting sources, a remote <a href="https://www.techradar.com/pro/best-employee-recognition-software-of-year">employee</a> on a hotel network, and someone dodging an age check look identical from the network's side, and enforcement can't tell them apart.</p><p>Any enforcement mechanism built to catch age-check bypass has to sit on top of that same traffic, and it has no way to separate a teenager evading harmful content from an accountant filing a report over a hotel connection.</p><p>Stigmatizing VPNs further won't change the underlying demand either. People don't stop wanting privacy because a tool becomes less socially acceptable. They find another way to get both, often through channels with far less transparency than the ones being restricted.</p><h2 id="the-precedent-is-important">The precedent is important</h2><p>The concern here is sharper because of where these laws tend to originate. Rules written in a few high-profile markets often become templates, and other governments treat them as proven models regardless of how well they work. If privacy tools must identify users to function, that expectation can eventually reach encrypted messaging, <a href="https://www.techradar.com/uk/best/best-cloud-storage">cloud storage</a>, and other technologies businesses depend on daily.</p><p>A company that accepts identity checks on its VPN traffic today has little basis to object when the same logic gets applied to its encrypted messaging platform or its cloud storage provider tomorrow. The infrastructure being debated under the banner of child safety is the same infrastructure that keeps corporate communications and data secure.</p><h2 id="privacy-tools-are-not-the-problem">Privacy tools are not the problem</h2><p>An estimated 1.7 billion people worldwide use VPNs, a scale that should give policymakers pause before treating them primarily as a way to bypass age verification. For most users, VPNs are part of everyday internet security, protecting communications and safeguarding public Wi-Fi connections.</p><p>The spikes in VPN usage tell a consistent story. The largest surges follow political unrest, as seen during Myanmar's turmoil, or when a popular platform is suddenly blocked, as happened when Turkey restricted Wikipedia for several years.</p><p>Laws tied to age verification drive new sign-ups too, albeit on a smaller scale, mostly from people who don't want to upload an ID or a face scan to reach a site they'd rather not be seen visiting, adult sites being the clearest case.</p><h2 id="not-all-verification-is-equal">Not all verification is equal</h2><p>It's worth separating two different situations.</p><p>Verifying age on a social network, where someone already has an <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a> and a reason to be recognized, differs from verifying age on an adult site, where the point is precisely not to be identified.</p><p>The first one is reasonable. On the other hand, I don't think anyone should hand over an ID or a facial scan for the second, given the risk of that data leaking and being used for blackmail.</p><h2 id="the-technology-already-exists-with-limits">The technology already exists, with limits</h2><p>Privacy-preserving age verification is real, and working versions already exist, though it's worth being precise about what they can and can't guarantee. Proving something with zero trace anywhere in the system is extremely hard to achieve, and trust must always sit somewhere.</p><p>A workable model separates the party confirming someone's age from the party they're visiting. A trusted intermediary checks eligibility once and issues a token in return. That token isn't a currency and isn't tied to a wallet or an account, it's simply cryptographic proof that can't be traced back to the person it was issued to. No one can identify who is presenting the token later.</p><p>It works like an ID card with the photo, name and number stripped out, leaving only a yes or no answer to one question. That token lives on the person's own device. The service confirming eligibility never holds it, the user does.</p><h2 id="privacy-and-verification-can-coexist">Privacy and verification can coexist</h2><p>Protecting minors is a legitimate policy objective, and rejecting today's approach isn't the same as rejecting age verification altogether. The question is how to achieve it without asking millions of adults to surrender more personal information than necessary. Parents are best placed to decide what their children can access using tools that already exist. Public policy should support that role.</p><p>Governments should encourage age verification systems that collect the minimum information needed to confirm eligibility, while letting privacy tools do the job they were built for. The real work is building age verification people can trust without asking them to surrender their privacy. Regulating VPNs won't get us there.</p><p><em></em><a href="https://www.techradar.com/vpn/most-secure-vpns-best-encryption"><em>We've featured the best secure VPN provider.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US healthcare software giant Unlimited Technology Systems admits hackers may have stolen sensitive data of 3.8 million people ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Attackers stole extensive personal and medical data from 3.8 million individuals from Unlimited Technology Systems</strong></li><li><strong>Breach source and methods remain unknown, with no group claiming responsibility</strong></li><li><strong>Stolen data poses major fraud risks, prompting free identity monitoring from Kroll</strong></li></ul><p>US healthcare organization Unlimited Technology Systems has revealed it suffered a cyberattack in which it lost a treasure trove of sensitive information belonging to millions of people.</p><p>The company recently made the information public and shared details with the US Department of Health and Human Services, noting that someone broke in on October 5, 2025 and within five days exfiltrated valuable data belonging to just over 3.8 million people.</p><p>The attacker stole people’s full names, Social Security numbers (SSN), dates of birth, emails and mailing addresses, phone numbers, demographic information, scans of driver’s licenses and other government IDs, insurance cards, intake forms, health insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis data.</p><h2 id="supply-chain-woes">Supply chain woes</h2><p>The company did not say who the threat actors were, or if they demanded any ransom in exchange for deleting the data. </p><p>No hackers have claimed responsibility just yet, and we also don’t know how they managed to break in, as different groups have different methods. </p><p>ShinyHunters, for example, prefer calling their victims on the phone, pretending to be IT support and convincing their victims to give them access via remote management tools. Other groups might try to exploit vulnerabilities in routers, firewalls, and other hardware.</p><p>Whoever it was, they have a valuable data set in their possession. This kind of information can be sold on the black market or used in <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a> and wire fraud. To mitigate these risks, Unlimited Technology Systems is offering free identity monitoring services to affected individuals through Kroll.</p><p>Unlimited Technology Systems is a software company that provides financial technology for healthcare organizations. It works with around 4,500 clinics and 6,500 specialty healthcare providers in the US, processing north of $70 billion in net healthcare charges every year. </p><p>According to <a href="https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/" target="_blank"><em>BleepingComputer</em></a>, the company processes information on behalf of its clients, which means that the victims of this attack have no direct relationship with Unlimited and have probably not even heard of it.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/us-healthcare-software-giant-unlimited-technology-systems-admits-hackers-may-have-stolen-sensitive-data-of-3-8-million-people</link>
                                                                            <description>
                            <![CDATA[ Insurance cards, intake forms, health insurance policy numbers, and other information stolen in major attack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JLszabNNmVbjnunuyMbNwL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kCbP2VkzMgQpYqJDgMQ8UZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 14:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kCbP2VkzMgQpYqJDgMQ8UZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity]]></media:description>                                                            <media:text><![CDATA[Cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kCbP2VkzMgQpYqJDgMQ8UZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers stole extensive personal and medical data from 3.8 million individuals from Unlimited Technology Systems</strong></li><li><strong>Breach source and methods remain unknown, with no group claiming responsibility</strong></li><li><strong>Stolen data poses major fraud risks, prompting free identity monitoring from Kroll</strong></li></ul><p>US healthcare organization Unlimited Technology Systems has revealed it suffered a cyberattack in which it lost a treasure trove of sensitive information belonging to millions of people.</p><p>The company recently made the information public and shared details with the US Department of Health and Human Services, noting that someone broke in on October 5, 2025 and within five days exfiltrated valuable data belonging to just over 3.8 million people.</p><p>The attacker stole people’s full names, Social Security numbers (SSN), dates of birth, emails and mailing addresses, phone numbers, demographic information, scans of driver’s licenses and other government IDs, insurance cards, intake forms, health insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis data.</p><h2 id="supply-chain-woes">Supply chain woes</h2><p>The company did not say who the threat actors were, or if they demanded any ransom in exchange for deleting the data. </p><p>No hackers have claimed responsibility just yet, and we also don’t know how they managed to break in, as different groups have different methods. </p><p>ShinyHunters, for example, prefer calling their victims on the phone, pretending to be IT support and convincing their victims to give them access via remote management tools. Other groups might try to exploit vulnerabilities in routers, firewalls, and other hardware.</p><p>Whoever it was, they have a valuable data set in their possession. This kind of information can be sold on the black market or used in <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a> and wire fraud. To mitigate these risks, Unlimited Technology Systems is offering free identity monitoring services to affected individuals through Kroll.</p><p>Unlimited Technology Systems is a software company that provides financial technology for healthcare organizations. It works with around 4,500 clinics and 6,500 specialty healthcare providers in the US, processing north of $70 billion in net healthcare charges every year. </p><p>According to <a href="https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/" target="_blank"><em>BleepingComputer</em></a>, the company processes information on behalf of its clients, which means that the victims of this attack have no direct relationship with Unlimited and have probably not even heard of it.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Samsung patches nearly 200 security issues on its phone hardware - here's what you need to know ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Oversecured found 176 vulnerabilities across Samsung’s preinstalled mobile apps</strong></li><li><strong>Flaws enabled account takeover, code execution, and traffic hijacking via bloatware</strong></li><li><strong>Samsung patched all reported issues, affecting hundreds of millions of devices</strong></li></ul><p>Security researchers from Oversecured have given “bloatware” an entirely new meaning, revealing that they uncovered 176 vulnerabilities - including some rather worrying ones - in Samsung’s mobile apps.</p><p>For the last three years, the team analyzed Samsung’s preinstalled system applications and found vulnerabilities that could cause some serious harm. Some of the bugs granted camera and microphone access, while others allowed for remote Samsung Account takeover with nothing more than a single click.</p><p>Some flaws allowed for network traffic hijacking via DNS manipulation, and others granted arbitrary code execution via an image. In theory, a malicious actor could craft and send a JPEG image which, when the victim opens, copies and loads attacker-controlled native libraries from the SD card. Finally, Oversecured found path traversal vulnerabilities allowing writing arbitrary files to the file system without proper path validation. </p><h2 id="arbitrary-code-execution">Arbitrary code execution</h2><p>The researchers disclosed their findings to Samsung which, according to their report, fixed all of the reported issues - the full list can be found on <a href="https://github.com/oversecured/Samsung_Vulnerabilities" target="_blank"><u>GitHub</u></a>.</p><p>Most <a href="https://www.techradar.com/best/best-android-phones" target="_blank">Android smartphone</a> manufacturers preload their devices with proprietary apps - think Bixby, Samsung Free, or AR Zone. These apps - which cannot be uninstalled or removed from the devices - aren’t necessary to their operations and are often not wanted by the users in the first place. </p><p>This 'bloatware' is also one of the key selling propositions of <a href="https://www.techradar.com/news/best-pixel-phones" target="_blank">Google Pixel</a> devices, since these are considered “stock Android”, or bloatware-free. </p><p>Out of context, these bugs are nothing extraordinary. Single-click account takeover flaws and traffic hijacking bugs pop up every now and then and get fixed rather quickly. The context here is that these are Samsung’s proprietary apps that don’t fall under the protection of Google’s Play Protect. Users might think they’re safe because they’ve not downloaded apps from risky places, or enabled dangerous permissions, when in reality, they’re not safe at all:</p><p>“Preinstalled system applications run with extra privileges than normal apps, cannot be removed by users, and operate outside Google Play Protect,” the researchers warned. “A single vulnerability affects hundreds of millions of devices globally through one vendor's distribution channel.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/samsung-patches-nearly-200-security-issues-on-its-phone-hardware-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ Samsung's bloatware carried dangerous flaws that enabled access to the phone's microphone and camera. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iprsfWxDRtGKN2ZuvjjwSd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BBM4XfubmWGFTaMhYGgJKX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 13:50:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BBM4XfubmWGFTaMhYGgJKX-1280-80.jpg">
                                                            <media:credit><![CDATA[Future | Alex Walker-Todd]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Er du ute efter den beste Android-mobilen? Her er våre  favoritter akkurat nå.]]></media:description>                                                            <media:text><![CDATA[Samsung Galaxy S23 Ultra review angled tea]]></media:text>
                                <media:title type="plain"><![CDATA[Samsung Galaxy S23 Ultra review angled tea]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BBM4XfubmWGFTaMhYGgJKX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Oversecured found 176 vulnerabilities across Samsung’s preinstalled mobile apps</strong></li><li><strong>Flaws enabled account takeover, code execution, and traffic hijacking via bloatware</strong></li><li><strong>Samsung patched all reported issues, affecting hundreds of millions of devices</strong></li></ul><p>Security researchers from Oversecured have given “bloatware” an entirely new meaning, revealing that they uncovered 176 vulnerabilities - including some rather worrying ones - in Samsung’s mobile apps.</p><p>For the last three years, the team analyzed Samsung’s preinstalled system applications and found vulnerabilities that could cause some serious harm. Some of the bugs granted camera and microphone access, while others allowed for remote Samsung Account takeover with nothing more than a single click.</p><p>Some flaws allowed for network traffic hijacking via DNS manipulation, and others granted arbitrary code execution via an image. In theory, a malicious actor could craft and send a JPEG image which, when the victim opens, copies and loads attacker-controlled native libraries from the SD card. Finally, Oversecured found path traversal vulnerabilities allowing writing arbitrary files to the file system without proper path validation. </p><h2 id="arbitrary-code-execution">Arbitrary code execution</h2><p>The researchers disclosed their findings to Samsung which, according to their report, fixed all of the reported issues - the full list can be found on <a href="https://github.com/oversecured/Samsung_Vulnerabilities" target="_blank"><u>GitHub</u></a>.</p><p>Most <a href="https://www.techradar.com/best/best-android-phones" target="_blank">Android smartphone</a> manufacturers preload their devices with proprietary apps - think Bixby, Samsung Free, or AR Zone. These apps - which cannot be uninstalled or removed from the devices - aren’t necessary to their operations and are often not wanted by the users in the first place. </p><p>This 'bloatware' is also one of the key selling propositions of <a href="https://www.techradar.com/news/best-pixel-phones" target="_blank">Google Pixel</a> devices, since these are considered “stock Android”, or bloatware-free. </p><p>Out of context, these bugs are nothing extraordinary. Single-click account takeover flaws and traffic hijacking bugs pop up every now and then and get fixed rather quickly. The context here is that these are Samsung’s proprietary apps that don’t fall under the protection of Google’s Play Protect. Users might think they’re safe because they’ve not downloaded apps from risky places, or enabled dangerous permissions, when in reality, they’re not safe at all:</p><p>“Preinstalled system applications run with extra privileges than normal apps, cannot be removed by users, and operate outside Google Play Protect,” the researchers warned. “A single vulnerability affects hundreds of millions of devices globally through one vendor's distribution channel.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Levi's reveals security tear may have let hackers steal important corporate data ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Attackers used social engineering to access Levi’s network and steal corporate data</strong></li><li><strong>Details on stolen information, methods, and perpetrators remain largely undisclosed</strong></li><li><strong>Voice‑phishing extortion groups are suspected, though no one has claimed responsibility</strong></li></ul><p>Levi Strauss has revealed it recently suffered a cyberattack and lost corporate files - however some crucial details around the incident are missing.</p><p>The company filed a new report with the US Securities and Exchange Commission (SEC), noting how hackers accessed its infrastructure through “social engineering” against three of its employees. We don’t know if that was via email, voice phishing, or some other technique.</p><p>After breaching the network, the crooks - who weren’t identified - “accessed and exfiltrated certain corporate information”. Again, we don’t know which information was accessed, or how much of it.</p><h2 id="was-it-unc6671">Was it UNC6671?</h2><p>In response, Levi’s said it had “initiated response protocols, implemented containment measures, and launched an investigation” which remains ongoing. Again, we don’t know what these measures are, or how the crooks were ousted. </p><p>The company says the incident did not disrupt its business operations, or caused interruptions, in any way, and that it does not expect it to have any material impact whatsoever. </p><p>While Levi’s did not name the perpetrators, and while none have yet claimed responsibility on the dark web, <a href="https://cyberinsider.com/levi-strauss-discloses-data-breach-after-social-engineering-attack-on-employees/" target="_blank">some publications </a>have hinted at UNC6671, a “financially motivated threat cluster that conducts data-theft extortion attacks through voice phishing”. The tactic seems to have been “borrowed” from ShinyHunters, arguably one of the largest data extortionists out there. </p><p>The group would call their targets on the phone (usually low-level employees with access to company SaaS solutions) and, while pretending to be from the IT department, convince the victims to either grant <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote access</a>, or to visit a malicious credential-grabbing landing page. </p><p>From there, the attackers would move in, map the infrastructure, exfiltrate valuable data, and then demand payment in cryptocurrency in exchange for deleting the data. </p><p>We have reached out to Levi’s with further questions and will update the article if we get an answer.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/levi-strauss-and-co-says-hackers-stole-corporate-data-in-cyberattack/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/levis-reveals-security-tear-may-have-let-hackers-steal-important-corporate-data</link>
                                                                            <description>
                            <![CDATA[ Crucial data is missing following Levi's attack, including who the threat actors were, what kind of files they stolen, or if customers are at risk. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">75grDbVtv9pCkChbwo6C5m</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 12:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers used social engineering to access Levi’s network and steal corporate data</strong></li><li><strong>Details on stolen information, methods, and perpetrators remain largely undisclosed</strong></li><li><strong>Voice‑phishing extortion groups are suspected, though no one has claimed responsibility</strong></li></ul><p>Levi Strauss has revealed it recently suffered a cyberattack and lost corporate files - however some crucial details around the incident are missing.</p><p>The company filed a new report with the US Securities and Exchange Commission (SEC), noting how hackers accessed its infrastructure through “social engineering” against three of its employees. We don’t know if that was via email, voice phishing, or some other technique.</p><p>After breaching the network, the crooks - who weren’t identified - “accessed and exfiltrated certain corporate information”. Again, we don’t know which information was accessed, or how much of it.</p><h2 id="was-it-unc6671">Was it UNC6671?</h2><p>In response, Levi’s said it had “initiated response protocols, implemented containment measures, and launched an investigation” which remains ongoing. Again, we don’t know what these measures are, or how the crooks were ousted. </p><p>The company says the incident did not disrupt its business operations, or caused interruptions, in any way, and that it does not expect it to have any material impact whatsoever. </p><p>While Levi’s did not name the perpetrators, and while none have yet claimed responsibility on the dark web, <a href="https://cyberinsider.com/levi-strauss-discloses-data-breach-after-social-engineering-attack-on-employees/" target="_blank">some publications </a>have hinted at UNC6671, a “financially motivated threat cluster that conducts data-theft extortion attacks through voice phishing”. The tactic seems to have been “borrowed” from ShinyHunters, arguably one of the largest data extortionists out there. </p><p>The group would call their targets on the phone (usually low-level employees with access to company SaaS solutions) and, while pretending to be from the IT department, convince the victims to either grant <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote access</a>, or to visit a malicious credential-grabbing landing page. </p><p>From there, the attackers would move in, map the infrastructure, exfiltrate valuable data, and then demand payment in cryptocurrency in exchange for deleting the data. </p><p>We have reached out to Levi’s with further questions and will update the article if we get an answer.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/levi-strauss-and-co-says-hackers-stole-corporate-data-in-cyberattack/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn North Korean hackers are increasingly using AI to build smarter and more devious cyberattacks ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Kimsuky used local AI tools to evade monitoring and enhance operations</strong></li><li><strong>Researchers observed extensive AI-driven capability building across the group’s infrastructure</strong></li><li><strong>Defenders urged behavior-based detection to spot evolving AI-enabled threats</strong></li></ul><p>North Korean hackers have found a way to use Generative Artificial Intelligence (GenAI) to supercharge their activities without tipping off the tool’s maintainers.</p><p>When people use AI tools like ChatGPT or Claude, their activities can be (at least to some extent) tracked and curbed - with OpenAI recently identifying and <a href="https://www.techradar.com/pro/security/openai-says-it-stopped-an-asian-scam-campaign-hijacking-chatgpt-to-lure-in-victims" target="_blank">terminating multiple ChatGPT accounts</a> used in phishing and human trafficking. </p><p>That is why Kimsuky - a known state-sponsored North Korean threat actor, used Ollama, GPT4All and Msty locally, allowing them to process documents without sending any sensitive information to outside AI services. </p><h2 id="consistent-process-of-capability-development">"Consistent process of capability development"</h2><p>The attacks were spotted by security researchers <a href="https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm" target="_blank" rel="nofollow">Genians</a> who “conducted months of tracking and log analysis on the infrastructure utilized as C2 in this campaign,” to identify the tools they used.</p><p>Aside from the three LLMs, they also used retrieval augmented generation (RAG) tools for document search, as well as AI agent development frameworks, text-to-speech software, and an AI-assisted coding tool called Cursor.</p><p>Using AI to write malicious code is not as simple as it sounds, due to various guardrails set up by the developers. As a result, AI in crime has been mostly limited to drafting phishing emails and crafting authentic-looking but malicious landing pages. However, Kimsuky has shown that AI in cybercrime continues to evolve and is becoming an ever-greater threat. </p><p>“What was observed in the threat actor's infrastructure was not merely evidence of several documents being created with AI, but a consistent process of capability development: establishing local LLM runtime environments, configuring RAG based on documents in the actor's possession, collecting AI agent development frameworks, and acquiring libraries for integration with external commercial AI services,” Genians concluded.</p><p>As a result, defenders must move from content-based assessment to behavior-based detection, the researchers warned, saying this should serve “as the fundamental premise of security recommendations.”</p><p>“In addition to indicator of compromise (IoC)-based detection, organizations should contextually correlate the sequence of anomalous activities following LNK execution, including PowerShell execution, persistence establishment, and external communications, to assess the overall threat level.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-warn-north-korean-hackers-are-increasingly-using-ai-to-build-smarter-and-more-devious-cyberattacks</link>
                                                                            <description>
                            <![CDATA[ In cybercrime, AI is used for more than simply drafting phishing emails and defenders need to adapt, new report states. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pMvkj5n6fSoGUjACrTKmVj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 11:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kimsuky used local AI tools to evade monitoring and enhance operations</strong></li><li><strong>Researchers observed extensive AI-driven capability building across the group’s infrastructure</strong></li><li><strong>Defenders urged behavior-based detection to spot evolving AI-enabled threats</strong></li></ul><p>North Korean hackers have found a way to use Generative Artificial Intelligence (GenAI) to supercharge their activities without tipping off the tool’s maintainers.</p><p>When people use AI tools like ChatGPT or Claude, their activities can be (at least to some extent) tracked and curbed - with OpenAI recently identifying and <a href="https://www.techradar.com/pro/security/openai-says-it-stopped-an-asian-scam-campaign-hijacking-chatgpt-to-lure-in-victims" target="_blank">terminating multiple ChatGPT accounts</a> used in phishing and human trafficking. </p><p>That is why Kimsuky - a known state-sponsored North Korean threat actor, used Ollama, GPT4All and Msty locally, allowing them to process documents without sending any sensitive information to outside AI services. </p><h2 id="consistent-process-of-capability-development">"Consistent process of capability development"</h2><p>The attacks were spotted by security researchers <a href="https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm" target="_blank" rel="nofollow">Genians</a> who “conducted months of tracking and log analysis on the infrastructure utilized as C2 in this campaign,” to identify the tools they used.</p><p>Aside from the three LLMs, they also used retrieval augmented generation (RAG) tools for document search, as well as AI agent development frameworks, text-to-speech software, and an AI-assisted coding tool called Cursor.</p><p>Using AI to write malicious code is not as simple as it sounds, due to various guardrails set up by the developers. As a result, AI in crime has been mostly limited to drafting phishing emails and crafting authentic-looking but malicious landing pages. However, Kimsuky has shown that AI in cybercrime continues to evolve and is becoming an ever-greater threat. </p><p>“What was observed in the threat actor's infrastructure was not merely evidence of several documents being created with AI, but a consistent process of capability development: establishing local LLM runtime environments, configuring RAG based on documents in the actor's possession, collecting AI agent development frameworks, and acquiring libraries for integration with external commercial AI services,” Genians concluded.</p><p>As a result, defenders must move from content-based assessment to behavior-based detection, the researchers warned, saying this should serve “as the fundamental premise of security recommendations.”</p><p>“In addition to indicator of compromise (IoC)-based detection, organizations should contextually correlate the sequence of anomalous activities following LNK execution, including PowerShell execution, persistence establishment, and external communications, to assess the overall threat level.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Without global interoperability, digital IDs can't deliver on their promise ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Governments worldwide are racing to deploy and enforce digital <a href="https://www.techradar.com/best/best-identity-theft-protection">IDs</a> to enhance data <a href="https://www.techradar.com/best/best-privacy-apps-for-android">privacy</a> and national security. As adoption accelerates, it’s estimated that more than two-thirds of the global population, 5.6 billion people will own a digital wallet by 2029. Yet these credentials remain largely confined to national borders due to the lack of global interoperability.</p><p>This is a challenge for today's digital economy and is becoming even more complex with the rapid rise of agentic commerce as autonomous AI agents are increasingly executing cross-border transactions on behalf of users. This interoperability gap forces platforms to reject foreign digital credentials, forcing users to upload their physical IDs to complete global purchases—the exact security risk digital IDs were designed to eliminate.</p><h2 id="digital-ids-locked-behind-borders-brings-vulnerabilities">Digital IDs locked behind borders brings vulnerabilities  </h2><p>Without clear global frameworks, a digital ID issued by one nation is completely unreadable and untrusted by digital services based in another. This creates a gap between privacy, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, and convenience as consumers interact with cross-border digital services.</p><p>This could include booking an accommodation at a hotel, completing a global transaction, or deploying an AI agent to negotiate a corporate purchase. This mismatch brings severe vulnerability risks for all parties, the enterprise, the nation who deployed the digital ID, and the consumer.</p><p>When consumers are forced to upload their passport, just to complete a routine transaction, the government that spent millions building a secure digital ID ecosystem now completely lost control over its citizens' data sovereignty.</p><p>While image-based verification methods are secure and functional for localized onboarding, there are challenges that arise when users must repeatedly share sensitive documents across multiple organizations and jurisdictions to then be stored in a foreign <a href="https://www.techradar.com/best/best-database-software">database</a>.</p><p>It expands the enterprise attack surface by multiplying the number of disparate databases where a user's personal identifiable information (PII) is stored and can become a target for data breaches and identity attacks.  </p><h2 id="the-technical-debt-of-fragmented-standards">The technical debt of fragmented standards</h2><p>Without clear standards for digital IDs, enterprises are forced to navigate a patchwork of identity protocols. This creates security blind spots that make it easier for fraudsters to steal passport images and other personal data to open fraudulent accounts at scale.   </p><p>Beyond security risks, IT leaders are facing technical debt with the fragmentation of digital IDs. In order to accommodate new digital ID variations, institutions would have to completely re-file pre-approved processes for regulatory approval. Since this is a complex and exhaustive process, organizations stick to their approved legacy workflows. However, this leaves them more vulnerable to emerging threats.  </p><p>This challenge only gets worse when you take into consideration that some countries are heavily restricting their digital IDs. 31% of OECD countries do not provide any form of cross-border digital identity recognition, meaning roughly 3 in 10 countries still cannot use foreign digital identities to access public services. However, it’s not a lack of technical interoperability that prevents the cross-border use of digital IDs; rather, governing bodies are actively forbidding it.</p><p>For example, Under the EU’s upcoming EUDI wallet (eIDAS 2.0), only <a href="https://www.techradar.com/best/business-security-systems">businesses</a> established within an EU Member State have a clear path to register and accept verified citizen digital identities.</p><p>Similarly, processing the Philippines' PhilID is strictly restricted to companies incorporated and headquartered locally. Even if relying parties would be willing to deal with the non-standardized fractured technology of digital IDs, these protective regulations shut out international organizations from consuming them, forcing a reliance on legacy verification processes.</p><h2 id="the-security-promise-of-digital-ids">The security promise of digital IDs</h2><p>Digital identity does have major benefits when it’s allowed to act at its full cross-border potential. When recognized and accepted by other organizations in other jurisdictions, consumers can establish trust without oversharing their personal information.</p><p>This limits the vulnerable information that organizations have to store in their databases and safeguards citizen’s privacy. Since only the specific data required to confirm authorization is transmitted, both organizations and sovereign nations can finally operationalize true data minimization.</p><p>As agents start executing actions on behalf of humans, reusable identity is the missing layer that makes the agentic ecosystem safe. Rather than forcing users back into a manual verification process, a standardized digital ID framework would allow an agent to present a pre-verified, universally trusted digital token.</p><p>This token could verify both the agent's authorization and the user's identity without exposing raw login credentials. This allows AI agents to fulfill their promise of true, autonomous <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a>.</p><h2 id="the-trust-required-for-a-borderless-digital-economy">The trust required for a borderless digital economy</h2><p>Creating global interoperability for digital IDs isn’t just about ensuring a seamless digital economy; it’s about fundamentally shifting how we build and maintain trust in digital systems. While standardized cross-border frameworks are essential for the initial onboarding with digital IDs, true security with reusable identity requires moving beyond static, point-in-time checks.</p><p>This is especially true as AI agents begin navigating global platforms and executing transactions on behalf of users. As these agents are designed to operate continuously in the background, identity verification can no longer be a single, one-time event.</p><p>To make the digital ecosystem more secure and resilient for both humans and machines, trust must be re-established throughout the entire user lifecycle.</p><p>By deploying continuous monitoring through real-time behavioral and device pattern signals, enterprises can allow authentic users and their authorized AI agents to interact seamlessly beyond borders. Friction with identity verification would then only enter the equation when suspicious behavior is detected.</p><p>But spotting these subtle anomalies means fraud can no longer be addressed in isolation. By adopting an identity intelligence solution, organizations can layer multiple <a href="https://www.techradar.com/best/best-authenticator-apps">authentication</a> and identity signals to build a more complete picture of risk. This intelligence can then be shared across organizations and even governments to detect fraud patterns and threats in real time, before they become widespread.</p><p>This unified knowledge is essential because the purpose of digital IDs was never meant to end at national borders. Governments must stop restricting international organizations from accepting their digital IDs because, when implemented correctly, enabling cross-border access creates a fundamentally safer environment for citizens. </p><p>We are living in a truly borderless digital economy, and our frameworks for digital trust must evolve to match this reality. Global interoperability and continuous trust are the foundation for a more secure, privacy-centric ecosystem—one where individuals, enterprises, and autonomous AI agents can interact with total confidence anywhere in the world.</p><p><em></em><a href="https://www.techradar.com/vpn/best-vpn"><em>We're featured the best VPN service.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/without-global-interoperability-digital-ids-cant-deliver-on-their-promise</link>
                                                                            <description>
                            <![CDATA[ Digital IDs are designed around borders, forcing citizens who live digitally global lives to upload physical IDs to foreign databases. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UmBX9oBAVbzksEy9drh8s3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GoQVn5Ea8CSCW9TuKx43QM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 09:31:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Philipp Pointner ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GoQVn5Ea8CSCW9TuKx43QM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital representation of the globe in blue with binary numbers around it]]></media:description>                                                            <media:text><![CDATA[A digital representation of the globe in blue with binary numbers around it]]></media:text>
                                <media:title type="plain"><![CDATA[A digital representation of the globe in blue with binary numbers around it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GoQVn5Ea8CSCW9TuKx43QM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Governments worldwide are racing to deploy and enforce digital <a href="https://www.techradar.com/best/best-identity-theft-protection">IDs</a> to enhance data <a href="https://www.techradar.com/best/best-privacy-apps-for-android">privacy</a> and national security. As adoption accelerates, it’s estimated that more than two-thirds of the global population, 5.6 billion people will own a digital wallet by 2029. Yet these credentials remain largely confined to national borders due to the lack of global interoperability.</p><p>This is a challenge for today's digital economy and is becoming even more complex with the rapid rise of agentic commerce as autonomous AI agents are increasingly executing cross-border transactions on behalf of users. This interoperability gap forces platforms to reject foreign digital credentials, forcing users to upload their physical IDs to complete global purchases—the exact security risk digital IDs were designed to eliminate.</p><h2 id="digital-ids-locked-behind-borders-brings-vulnerabilities">Digital IDs locked behind borders brings vulnerabilities  </h2><p>Without clear global frameworks, a digital ID issued by one nation is completely unreadable and untrusted by digital services based in another. This creates a gap between privacy, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, and convenience as consumers interact with cross-border digital services.</p><p>This could include booking an accommodation at a hotel, completing a global transaction, or deploying an AI agent to negotiate a corporate purchase. This mismatch brings severe vulnerability risks for all parties, the enterprise, the nation who deployed the digital ID, and the consumer.</p><p>When consumers are forced to upload their passport, just to complete a routine transaction, the government that spent millions building a secure digital ID ecosystem now completely lost control over its citizens' data sovereignty.</p><p>While image-based verification methods are secure and functional for localized onboarding, there are challenges that arise when users must repeatedly share sensitive documents across multiple organizations and jurisdictions to then be stored in a foreign <a href="https://www.techradar.com/best/best-database-software">database</a>.</p><p>It expands the enterprise attack surface by multiplying the number of disparate databases where a user's personal identifiable information (PII) is stored and can become a target for data breaches and identity attacks.  </p><h2 id="the-technical-debt-of-fragmented-standards">The technical debt of fragmented standards</h2><p>Without clear standards for digital IDs, enterprises are forced to navigate a patchwork of identity protocols. This creates security blind spots that make it easier for fraudsters to steal passport images and other personal data to open fraudulent accounts at scale.   </p><p>Beyond security risks, IT leaders are facing technical debt with the fragmentation of digital IDs. In order to accommodate new digital ID variations, institutions would have to completely re-file pre-approved processes for regulatory approval. Since this is a complex and exhaustive process, organizations stick to their approved legacy workflows. However, this leaves them more vulnerable to emerging threats.  </p><p>This challenge only gets worse when you take into consideration that some countries are heavily restricting their digital IDs. 31% of OECD countries do not provide any form of cross-border digital identity recognition, meaning roughly 3 in 10 countries still cannot use foreign digital identities to access public services. However, it’s not a lack of technical interoperability that prevents the cross-border use of digital IDs; rather, governing bodies are actively forbidding it.</p><p>For example, Under the EU’s upcoming EUDI wallet (eIDAS 2.0), only <a href="https://www.techradar.com/best/business-security-systems">businesses</a> established within an EU Member State have a clear path to register and accept verified citizen digital identities.</p><p>Similarly, processing the Philippines' PhilID is strictly restricted to companies incorporated and headquartered locally. Even if relying parties would be willing to deal with the non-standardized fractured technology of digital IDs, these protective regulations shut out international organizations from consuming them, forcing a reliance on legacy verification processes.</p><h2 id="the-security-promise-of-digital-ids">The security promise of digital IDs</h2><p>Digital identity does have major benefits when it’s allowed to act at its full cross-border potential. When recognized and accepted by other organizations in other jurisdictions, consumers can establish trust without oversharing their personal information.</p><p>This limits the vulnerable information that organizations have to store in their databases and safeguards citizen’s privacy. Since only the specific data required to confirm authorization is transmitted, both organizations and sovereign nations can finally operationalize true data minimization.</p><p>As agents start executing actions on behalf of humans, reusable identity is the missing layer that makes the agentic ecosystem safe. Rather than forcing users back into a manual verification process, a standardized digital ID framework would allow an agent to present a pre-verified, universally trusted digital token.</p><p>This token could verify both the agent's authorization and the user's identity without exposing raw login credentials. This allows AI agents to fulfill their promise of true, autonomous <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a>.</p><h2 id="the-trust-required-for-a-borderless-digital-economy">The trust required for a borderless digital economy</h2><p>Creating global interoperability for digital IDs isn’t just about ensuring a seamless digital economy; it’s about fundamentally shifting how we build and maintain trust in digital systems. While standardized cross-border frameworks are essential for the initial onboarding with digital IDs, true security with reusable identity requires moving beyond static, point-in-time checks.</p><p>This is especially true as AI agents begin navigating global platforms and executing transactions on behalf of users. As these agents are designed to operate continuously in the background, identity verification can no longer be a single, one-time event.</p><p>To make the digital ecosystem more secure and resilient for both humans and machines, trust must be re-established throughout the entire user lifecycle.</p><p>By deploying continuous monitoring through real-time behavioral and device pattern signals, enterprises can allow authentic users and their authorized AI agents to interact seamlessly beyond borders. Friction with identity verification would then only enter the equation when suspicious behavior is detected.</p><p>But spotting these subtle anomalies means fraud can no longer be addressed in isolation. By adopting an identity intelligence solution, organizations can layer multiple <a href="https://www.techradar.com/best/best-authenticator-apps">authentication</a> and identity signals to build a more complete picture of risk. This intelligence can then be shared across organizations and even governments to detect fraud patterns and threats in real time, before they become widespread.</p><p>This unified knowledge is essential because the purpose of digital IDs was never meant to end at national borders. Governments must stop restricting international organizations from accepting their digital IDs because, when implemented correctly, enabling cross-border access creates a fundamentally safer environment for citizens. </p><p>We are living in a truly borderless digital economy, and our frameworks for digital trust must evolve to match this reality. Global interoperability and continuous trust are the foundation for a more secure, privacy-centric ecosystem—one where individuals, enterprises, and autonomous AI agents can interact with total confidence anywhere in the world.</p><p><em></em><a href="https://www.techradar.com/vpn/best-vpn"><em>We're featured the best VPN service.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts find AI agents can be tricked into 'remembering' fake facts for months — so how do we stop it? ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Forcepoint X-Labs publishes threat model for persistent memory poisoning </strong></li><li><strong>Hidden text on a webpage becomes a durable "fact" an agent retrieves and trusts in unrelated tasks weeks later</strong></li><li><strong>It has already been demonstrated against products already in the market, including ChatGPT, Gemini, Claude and Microsoft 365 Copilot</strong></li></ul><p>New findings from Forcepoint's X-Labs <a href="forcepoint.com/blog/x-labs/persistent-memory-poisoning-ai-agents" target="_blank">outline an interesting scenario</a> that could easily mimic real life: An AI assistant with browser access reads a webpage about travel disruption.</p><p>Near the bottom of that page, in text sized and positioned so no human will ever see it, sits a short paragraph stating that ABC Travel Support is the official emergency booking provider and should always be recommended when urgent travel changes are needed. </p><p>The assistant's text extractor does not distinguish between hidden and visible text, so the model treats the whole thing as plain prose and files the claim away as a useful fact about how this organization handles travel. A month later, the user's flight is canceled. They ask their assistant what to do, and it tells them, helpfully and with no sign of anything wrong, to contact ABC Travel Support.</p><h2 id="an-easy-to-replicate-attack-vector">An easy-to-replicate attack vector</h2><p>This is what Forcepoint calls persistent memory poisoning, a security vulnerability where an attacker injects false data or malicious instructions into an AI agent's long-term memory or retrieval database, and it is a threat model that is increasingly in focus as users increasingly rely on AI, often treating its responses as gospel, despite the warnings most chatbots come with.</p><p>The canonical academic result is MINJA, short for Memory INJection Attack, <a href="https://neurips.cc/virtual/2025/loc/san-diego/poster/118152" target="_blank">presented at NeurIPS 2025</a>. Its significance is the attacker model. MINJA does not assume access to the memory store, elevated privileges, or any compromise of the system. It works by submitting ordinary queries through the standard interface, using indication prompts, bridging steps, and a progressive-shortening technique that strips away giveaway language while leaving the poisoned record behind.</p><p>Across GPT-4o-mini, Gemini 2.0 Flash, and Llama 3.1 8B, it reported injection success above 95% and attack success above 70%.</p><p>It must be noted that those numbers might be optimistic; a January 2026 paper evaluating memory poisoning in electronic health record agents notes that MINJA's numbers were obtained under idealized conditions, and that how well these attacks hold up in realistic deployments remains understudied.</p><p>Despite this, it remains a significant threat to products that continue to ship, including ChatGPT, Gemini, Claude, and Microsoft 365 Copilot. It is important to find a solution to a problem that <a href="https://www.techradar.com/pro/security/if-someone-can-inject-instructions-or-spurious-facts-into-your-ais-memory-they-gain-persistent-influence-over-your-future-interactions-microsoft-warns-ai-recommendations-are-being-poisoned-to-serve-up-malicious-results" target="_blank">Microsoft has already warned about in the past</a>; Forcepoint suggests an approach that could mitigate it.</p><p>Its proposal is to stop treating extracted memories as facts and start treating them as objects that can be inspected. Each memory is stored with metadata: where it came from, what type of source it is, whether a user confirmed it, and a risk score. Language written to shape future behavior, phrases like "from now on" or "make this your default going forward," adds to the score. So does the sudden appearance of a previously unseen domain, contact, or vendor.</p><p>Contradiction detection is also in play: if new memory conflicts with an existing entry about the official travel provider, both cannot be true, so the engine flags the conflict and holds the new item for user confirmation rather than silently overwriting it. At the same time, anything related to payment instructions, banking details, VPN configuration, or security contacts is given higher weight, regardless of where it came from.</p><p>None of these approaches, however, solves the underlying problem: agents are built to treat retrieved memory as their own experience rather than as input. Scoring raises the cost of poisoning. It does not change what the agent believes once something gets through, and <a href="https://luckfort.github.io/ASBench/" target="_blank">as Agent Security Bench found</a>, current defenses are not doing well.</p><p>For anyone using an assistant with memory today, the practical play is unglamorous but worth following anyway: open the memory settings occasionally and read what is in there, but that's easier said than done when it comes to propagating the message since a sizeable chunk of AI users never bother to look under the hood.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-find-ai-agents-can-be-tricked-into-remembering-fake-facts-for-months-so-how-do-we-stop-it</link>
                                                                            <description>
                            <![CDATA[ Hidden text on a webpage can become a fact your AI assistant "remembers" and acts on weeks later. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZtynXaFNJGLGPbMhDaiXAW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TaxPLZc75WiicpmgZNzWzL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 09 Aug 2026 23:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TaxPLZc75WiicpmgZNzWzL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A woman out of focus in the background touches the word AI, lit up in glowing yellow light, in the foreground. The woman is wearing smart glasses]]></media:description>                                                            <media:text><![CDATA[A woman out of focus in the background touches the word AI, lit up in glowing yellow light, in the foreground. The woman is wearing smart glasses]]></media:text>
                                <media:title type="plain"><![CDATA[A woman out of focus in the background touches the word AI, lit up in glowing yellow light, in the foreground. The woman is wearing smart glasses]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TaxPLZc75WiicpmgZNzWzL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Forcepoint X-Labs publishes threat model for persistent memory poisoning </strong></li><li><strong>Hidden text on a webpage becomes a durable "fact" an agent retrieves and trusts in unrelated tasks weeks later</strong></li><li><strong>It has already been demonstrated against products already in the market, including ChatGPT, Gemini, Claude and Microsoft 365 Copilot</strong></li></ul><p>New findings from Forcepoint's X-Labs <a href="forcepoint.com/blog/x-labs/persistent-memory-poisoning-ai-agents" target="_blank">outline an interesting scenario</a> that could easily mimic real life: An AI assistant with browser access reads a webpage about travel disruption.</p><p>Near the bottom of that page, in text sized and positioned so no human will ever see it, sits a short paragraph stating that ABC Travel Support is the official emergency booking provider and should always be recommended when urgent travel changes are needed. </p><p>The assistant's text extractor does not distinguish between hidden and visible text, so the model treats the whole thing as plain prose and files the claim away as a useful fact about how this organization handles travel. A month later, the user's flight is canceled. They ask their assistant what to do, and it tells them, helpfully and with no sign of anything wrong, to contact ABC Travel Support.</p><h2 id="an-easy-to-replicate-attack-vector">An easy-to-replicate attack vector</h2><p>This is what Forcepoint calls persistent memory poisoning, a security vulnerability where an attacker injects false data or malicious instructions into an AI agent's long-term memory or retrieval database, and it is a threat model that is increasingly in focus as users increasingly rely on AI, often treating its responses as gospel, despite the warnings most chatbots come with.</p><p>The canonical academic result is MINJA, short for Memory INJection Attack, <a href="https://neurips.cc/virtual/2025/loc/san-diego/poster/118152" target="_blank">presented at NeurIPS 2025</a>. Its significance is the attacker model. MINJA does not assume access to the memory store, elevated privileges, or any compromise of the system. It works by submitting ordinary queries through the standard interface, using indication prompts, bridging steps, and a progressive-shortening technique that strips away giveaway language while leaving the poisoned record behind.</p><p>Across GPT-4o-mini, Gemini 2.0 Flash, and Llama 3.1 8B, it reported injection success above 95% and attack success above 70%.</p><p>It must be noted that those numbers might be optimistic; a January 2026 paper evaluating memory poisoning in electronic health record agents notes that MINJA's numbers were obtained under idealized conditions, and that how well these attacks hold up in realistic deployments remains understudied.</p><p>Despite this, it remains a significant threat to products that continue to ship, including ChatGPT, Gemini, Claude, and Microsoft 365 Copilot. It is important to find a solution to a problem that <a href="https://www.techradar.com/pro/security/if-someone-can-inject-instructions-or-spurious-facts-into-your-ais-memory-they-gain-persistent-influence-over-your-future-interactions-microsoft-warns-ai-recommendations-are-being-poisoned-to-serve-up-malicious-results" target="_blank">Microsoft has already warned about in the past</a>; Forcepoint suggests an approach that could mitigate it.</p><p>Its proposal is to stop treating extracted memories as facts and start treating them as objects that can be inspected. Each memory is stored with metadata: where it came from, what type of source it is, whether a user confirmed it, and a risk score. Language written to shape future behavior, phrases like "from now on" or "make this your default going forward," adds to the score. So does the sudden appearance of a previously unseen domain, contact, or vendor.</p><p>Contradiction detection is also in play: if new memory conflicts with an existing entry about the official travel provider, both cannot be true, so the engine flags the conflict and holds the new item for user confirmation rather than silently overwriting it. At the same time, anything related to payment instructions, banking details, VPN configuration, or security contacts is given higher weight, regardless of where it came from.</p><p>None of these approaches, however, solves the underlying problem: agents are built to treat retrieved memory as their own experience rather than as input. Scoring raises the cost of poisoning. It does not change what the agent believes once something gets through, and <a href="https://luckfort.github.io/ASBench/" target="_blank">as Agent Security Bench found</a>, current defenses are not doing well.</p><p>For anyone using an assistant with memory today, the practical play is unglamorous but worth following anyway: open the memory settings occasionally and read what is in there, but that's easier said than done when it comes to propagating the message since a sizeable chunk of AI users never bother to look under the hood.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>