No-frills tech news

Techie Tonic: How Rockefeller Habits can strengthen AI-powered <b>cybersecurity</b>

Cyber leaders should focus on indicators that directly reflect resilience, risk reduction Artificial intelligence is transforming cybersecurity by enhancing both defense capabilities and cybercriminal tactics. AI enables attackers to identify vulnerabilities, automate sophisticated attacks, and operate at unprecedented speed, leaving organizations with less time to detect and respond. As threats become more complex, traditional reactive security approaches are no longer enough. To stay ahead, organizations need a disciplined operating model that aligns strategy with execution, supported by clear priorities, accountability, measurable outcomes, and continuous improvement. These principles align closely with the Rockefeller Habits framework, providing a practical foundation for building resilient, agile, and high-performing cybersecurity operations in an increasingly AI-driven threat landscape. Get updated faster and for FREE: Download the Gulf News app now - simply click here. A core Rockefeller principle is maintaining a clear priority. Rather than attempting to secure every system simultaneously, organizations should begin with their most critical business assets, like the applications, systems, and data that would have the greatest impact if compromised. Concentrating AI-enabled security capabilities on these “crown jewels” enables organizations to create immediate value while reducing risk. This focused approach prevents large-scale transformation efforts from becoming overly complex and ensures resources are directed toward the areas that matter most. Execution improves when progress is measurable. Instead of relying on activity-based metrics, Cyber leaders should focus on indicators that directly reflect resilience and risk reduction. Like all our MANY CXO Community experts indicated, two foundational metrics provide a baseline: Blast Radius: the potential business impact if a critical system is breached. Defender Lag: the time required to detect and contain an attack compared with the attacker’s speed. These metrics create a shared understanding of security performance and help leadership teams make informed decisions based on measurable risk. Rockefeller Habits emphasize consistency and accountability.

Ferrari <b>Cybersecurity</b> Head on Defending Formula 1's Most Iconic Team

Ferrari is the most successful Formula 1 team of all time, with over 1100 race entries, 250 Grand Prix wins, 16 Constructor's Championships and 15 Driver’s Championships. The prancing horse has been a fixture in Formula 1 since the first Grand Prix at Silverstone in 1950. Over 75 years on, the team continues to find success, as drivers Lewis Hamilton and Charles Leclerc have both reached the top step of the podium in iconic Ferrari red in the 2026 season. A lot has changed in the decades since that 1950 inaugural Grand Prix and motorsport is no longer just about the drivers and the machinery around them. In the modern age, technology, data and analytics are core aspects of Formula 1 and it’s vital that information is protected from cyber threats. The responsibility for ensuring Italy’s flagship Formula 1 team is prepared to defend against evolving cyber-attacks is Luca Pierro, Head of Enterprise Cybersecurity at Ferrari. In this conversation, which took place at Ferrari’s Maranello headquarters, Pierro detailed to Infosecurity how the team implements a cybersecurity strategy that ensures staff are protected from cyber threats while also operating at speed. Pierro also shared how Ferrari reacts to evolving cyber threats and what the biggest issues he’s thinking about right now are. Infosecurity Magazine: You have a responsibility for managing cybersecurity across Ferrari. How do you go about meeting that challenge? Luca Pierro: Myself and my team are working to protect our brand and identity. It is the biggest challenge we face every day. We have different domains and different areas of expertise, every area of expertise has a different process. This is the real challenge because we act as one company, and we need to protect and cover all these domains while also working 24/7 to protect what we do

#ai | The <b>Cyber Security</b> Hub™

5 Cybersecurity experts highlight the most pressing threats, and how we should respond: Kemba W., President of the Paladin Global Institute and Former US Acting National Cyber Director; Amy Hogan-Burney, Deputy CISO, Governance and Risk at Microsoft; Hayley Davidson van Loon, CEO of Crime Stoppers International; Marc van Zadelhoff, CEO of Mimecast; and Kat Duffy, Senior Fellow for Digital and CyberspacePolicy at the Council on Foreign Relations. Cybercriminals are using #AI to develop more sophisticated cyberattacks. The World Economic Forum’s Global Cybersecurity Outlook 2026 explores how accelerating AI adoption, geopolitical fragmentation and widening cyber inequity are reshaping the global risk landscape. Read more here >> https://lnkd.in/e8STf9x7 I think people have to worry about apathy. The biggest risk to cybersecurity is that no one cares about cybersecurity. It's about making sure that we're able to access banking, access clean water, access reliable energy sources, that we make our community stronger. One misconception I'd love to see an end to is the idea that you can invest in this once or think about it once and be done. There's no way to be able to do that. Whether it's personally or for business professionals or governments around the world, you need to constantly be thinking about the innovation that is coming your way. The biggest cyber security risk to our community is AI powered impersonation at scale, which is eroding trust in our communities. As AI powered impersonation techniques improve everyday people are unsure if who they're speaking to. They're also have a fear of every time that they make public statements themselves, especially Sea Suite or or public persons that can then be used by these cyber criminals to create even more legitimate appearing videos and impersonations by voice and all sorts of things. With AI that what you're seeing is

Türk Telekom Signs Strategic <b>Cybersecurity</b> Partnership with CYBER ME Technology

Türk Telekom Signs Strategic Cybersecurity Partnership with CYBER ME Technology The collaboration is aimed at delivering greater value to customers while enhancing Türkiye's domestic technology ecosystem. Türk Telekom has entered into a strategic partnership with CYBER ME Technology , a company specializing in defence industry solutions, cybersecurity and Internet of Things (IoT) technologies, as the telecommunications operator seeks to strengthen its technology ecosystem and expand its enterprise digital capabilities. The collaboration is aimed at delivering greater value to customers while enhancing Türkiye’s domestic technology ecosystem. Through the partnership, the two companies plan to develop solutions that address the growing cybersecurity and digital transformation needs of public and private sector institutions. Türk Telekom said the agreement is expected to provide high value-added services by combining the operator’s digital infrastructure with CYBER ME Technology’s expertise in cybersecurity, defence technologies and IoT. The partnership also aligns with the company’s broader strategy of supporting national technology development and fostering locally developed digital solutions. Commenting on the agreement, Türk Telekom CEO and Vice Chairman Ebubekir Şahin expressed confidence that the collaboration would strengthen the country’s technology ecosystem and contribute to institutions’ cybersecurity and digital transformation efforts. He also acknowledged the contributions of CYBER ME Technology Founder and Chairwoman Mehtap Özdoğan, as well as Türk Telekom’s corporate sales teams and employees involved in establishing the partnership. The agreement reflects the increasing focus among telecommunications operators on expanding strategic collaborations to deliver secure digital services and support national digital transformation ambitions.

Entry-Level Cyber Jobs Demanding Mid-Level Skills | Dice.com Career Advice

The entry-level cybersecurity job isn’t disappearing. It’s becoming something very different. As generative AI (GenAI) takes over more of the repetitive work that once served as a proving ground for junior analysts, employers are increasingly raising expectations for candidates entering the field. Rather than spending their first year triaging alerts or reviewing logs, new hires are now expected to understand cloud environments, evaluate AI-generated outputs, write code and contribute to security operations almost immediately. The result is a growing disconnect between what employers expect and how cybersecurity talent has traditionally been developed. “We’re seeing a clear move toward more senior hiring in cybersecurity,” says Diana Kelley, chief information security officer at Noma Security. “AI is accelerating the shift. However, it’s not the only driver.” She explains that budget pressure and a growing expectation that candidates arrive job-ready are pushing employers to hire fewer, more experienced practitioners. AI Changing Entry Points For years, entry-level cybersecurity roles gave new practitioners an opportunity to learn through repetition. Analysts reviewed security alerts, investigated suspicious activity, and gradually developed the judgment needed for more complex work — those tasks are increasingly being automated. “AI is raising the floor for what entry-level cybersecurity means,” Kelley says. “Repetitive work that once helped people break in, like basic alert triage, log review, and first-pass analysis, is increasingly being automated or absorbed into platforms.” That means junior candidates need to show more hands-on capability earlier: cloud and identity basics, AI fluency, strong judgment and the ability to validate automated outputs instead of simply trusting them. Dave Gerry, chief executive officer at Bugcrowd, says he sees the same trend on the offensive security side. “AI is squeezing the lower end of the skills curve,” he says. “A lot of the work that used to be a natural entry point for

Kenya restores president's website after <b>cybersecurity</b> breach

Zdravo, Victoria from Techpoint here, Here’s what I’ve got for you today: - Kenya restores president’s website after hack - How fertility struggles led to a health startup - Tinubu signs virtual assets executive order Kenya restores president’s website after hack Just hours after hackers took over Kenya President William Ruto’s official website with a Bitcoin ransom demand and anti-government messages, the government says it has regained control of the platform. On Saturday, July 18, 2026, Kenya’s ICT Ministry confirmed that the website had suffered a cybersecurity incident but insisted there was no evidence that sensitive government data had been stolen. Authorities temporarily restricted access to the site while forensic investigations got underway, and by the end of the day, the website had been restored. Still, restoring the website doesn’t end the story. Even if the attackers only managed to deface the homepage, the breach is a reminder that no government is immune to cyberattacks. The hackers replaced official content with messages insulting President Ruto, displayed a Bitcoin wallet, and demanded 5 BTC (about KSh41 million) before threatening to leak unspecified information. Whether or not they actually accessed sensitive systems remains unclear, but targeting the president’s official website sends a symbolic message and raises fresh questions about the security of Kenya’s digital infrastructure. This also isn’t Kenya’s first run-in with hackers. In July 2023, the country’s eCitizen platform, used for dozens of public services, was disrupted by a cyberattack that affected agencies, including the National Transport and Safety Authority and Kenya Power. Then, on November 17, 2025, hackers launched a coordinated attack on several government websites, including the presidency’s portal, temporarily knocking them offline and replacing some pages with extremist messages. The government later blamed a group calling itself PCP@Kenya, restored the affected platforms, and promised stronger cyber defences. Those

3 <b>Cybersecurity</b> Stocks Facing Rising Demand As Supply Chain Attacks Increase

- United States - / - Software - / - NYSE:DT 3 Cybersecurity Stocks Facing Rising Demand As Supply Chain Attacks Increase Supply chain cyber attacks are rising fast, with third party breaches up 60% year on year and high profile incidents like SolarWinds putting operational resilience in the spotlight. At the same time, new rules such as the UK cyber resilience pledge are set to lift compliance expectations and costs for many listed companies. For investors, that mix of higher risk and tighter regulation can reshape where capital feels comfortable. This article looks at 3 stocks from a cybersecurity screener that appear exposed to these trends, helping you decide whether they could fit, or not fit, into your current approach. A10 Networks (ATEN) Overview: A10 Networks provides security and application delivery products that help organisations keep their digital infrastructure available and protected against threats like DDoS attacks and web application exploits across on premises, cloud, and hybrid environments. Its platforms are used by telecom operators, financial institutions, public sector bodies, and large enterprises that need reliable, high performance traffic management and security. Operations: A10 Networks generates about US$299.4 million in revenue from computer services, with roughly US$177.2 million from the United States and the rest spread across EMEA, Asia Pacific and Japan, and other Americas markets. Market Cap: US$2.6b For investors watching the surge in supply chain cyber attacks, A10 Networks sits at an intersection of security, AI infrastructure, and core networking. The company is focusing on higher margin, security led products, recurring revenue and AI driven offerings. At the same time, the stock trades on a rich P/E and insiders have been selling, while growth depends heavily on large customers and timely adoption of newer AI and cloud security products. How those strengths and pressures interact as regulations

Cisco in talks to buy Israeli cyber startup Zafran at steep discount | Ctech

Cisco in talks to buy Israeli cyber startup Zafran at steep discount Exclusive: A deal valued at $150 million-$200 million would fall well below the company's last fundraising valuation despite backing from Sequoia, Menlo Ventures and Cyberstarts. What is happening at Zafran Security, one of Israel's most closely watched cybersecurity startups? Just four years after its founding, and following a series of high-profile funding rounds, the company is facing growing questions. One of its three founders has left, and according to multiple senior cybersecurity industry sources, Zafran has spent the past several months exploring a sale. Sources told Calcalist that the company is currently in advanced talks with Cisco, which is willing to pay between $150 million and $200 million. If completed, the deal would represent a disappointing outcome for a startup that has raised more than $130 million and was valued at well above $200 million in its most recent funding round in December 2025. Zafran denies that it is negotiating a sale. The company says Cisco is making a strategic investment and that it plans to raise another large funding round. The company's position has nevertheless raised eyebrows, particularly following the departure of co-founder and CPO Snir Havdala. Over the weekend, Havdala announced on LinkedIn that he had joined Nvidia as Director of Engineering, where he will lead the development of AI agents for Nvidia's infrastructure. While the role is a senior one at one of the world's most valuable technology companies, the departure of a founder shortly after a major fundraising round inevitably raises questions about the company's trajectory. Zafran, which frequently publicizes company milestones, did not announce Havdala's departure. In his LinkedIn post, Havdala wrote: "I’ve always been drawn to the hardest technical challenges - and today, I’m incredibly excited to begin a new chapter. I’m

StrongKeep brings enterprise-grade <b>cybersecurity</b> within reach of small businesses

StrongKeep brings enterprise-grade cybersecurity within reach of small businesses As a Singapore-based cybersecurity startup, StrongKeep is focused on helping SMBs protect themselves and meet compliance requirements, without the cost or complexity of enterprise tools. While large enterprises continue to invest in newer and more comprehensive cybersecurity platforms, SMBs struggle to keep the pace not only because they lack the budget, but also the talent needed to manage their cybersecurity. Many SMBs continue to rely on basic cybersecurity protection that often is not sufficient enough to deal with today’s sophisticated cyber threats. In Southeast Asia, SMBs continue to be heavily targeted by criminals, with many struggling to recover from cyberattacks and experiencing heavy losses to the business. Statistics from cybersecurity vendors show SMBs remain one of most exploited businesses in the region when it comes to ransomware, with many also ending up paying the ransom because they don’t have sufficient backup or recovery capabilities. This has led to an increased demand for managed security services providers (MSSPs) in the region, with more cybersecurity vendors also customizing their solutions to support this increased demand. MSSPs are also reevaluating their offerings to make their services more affordable for SMBs, without having to compromise solutions. However, there is still a segment in SMBs that remain vulnerable because they can't even afford some of the MSSP offerings. These include micro SMBs (MSMBs) or even businesses with headcounts that are less than 50 employees, like a law firm for example. These companies have valuable information and if compromised, could end up with huge problems. This is where Gaurav Keerthi, CEO and Founder of StrongKeep is hoping to make a difference. A Singapore-based cybersecurity startup, StrongKeep is focused on helping SMBs protect themselves and meet compliance requirements, without the cost or complexity of enterprise tools. Unlike a

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last week. "We identified unauthorized access to a limited set of internal datasets and to several credentials used by our services," the company said in a statement. While an investigation into the intrusion remains ongoing, Hugging Face said it has found no evidence that the AI agent tampered with public, user-facing models, datasets, or Spaces, and its own software supply chain. The starting point of the attack was the data processing pipeline itself, with a malicious dataset abusing two code execution paths, viz., in its remote code dataset loader and a template injection in a dataset configuration, to run code on a processing worker. With that access, the threat actor is said to have escalated to node-level access, collected cloud and cluster credentials, and moved laterally into several internal clusters over a weekend. The exact large language model (LLM) used to pull off the attack is unclear, but the campaign was executed by an autonomous agent framework performing "many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services." Hugging Face said it has since addressed the root cause of the issue, precisely the code execution pathways used for initial access. It also carried out the following remediation steps - - Removed the attacker's foothold across the affected clusters and rebuilt the compromised nodes - Revoked and rotated the affected credentials and tokens, and a broader rotation of secrets was undertaken as a precautionary measure. - Deployed additional guardrails and stricter admission controls on its clusters - Improved detection and alerting

Future of Pentagon <b>Cybersecurity</b> Program Thrown into Question

CYBERSECURITY Future of Pentagon Cybersecurity Program Thrown into Question By Josh Luckenbaugh and Stew Magnuson iStock illustration The Defense Department July 13 announced it was suspending the Phase 2 requirements for its Cybersecurity Maturity Model Certification program and would be conducting a comprehensive 60-day review of the effort. The program — known as CMMC — has been in the works for seven years and is meant to serve as the department’s mechanism for verifying defense contractors are compliant with its cybersecurity requirements. While the initiative is designed to enhance cybersecurity, “instead it has created prohibitive compliance costs and bureaucratic burdens,” according to a Pentagon release. Small Business Administration data shows that the program is “forcing innovative companies out of the defense industrial base, which will delay the delivery of critical capabilities to the warfighters,” it said. The ongoing pause and review of CMMC puts the fate of the program — and the assessment organizations planning to certify contractors’ cybersecurity posture — into doubt. This is not the first time CMMC has faced headwinds since it was announced by the first Trump administration in 2019. The initial version of the program was met with so much blowback that then-Deputy Secretary of Defense Kathleen Hicks initiated her own review of the program shortly after the Biden administration took office in 2021. The Pentagon unveiled “CMMC 2.0” — the iteration of the program as it exists today — in November 2021, consisting of three compliance levels instead of the original version’s five. It took four more years of rulemaking and industry feedback for the first phase of implementation to begin in November 2025, which introduced in applicable Pentagon solicitations requirements for CMMC Level 1 and Level 2 self-assessments. Phase 2, which was scheduled to begin Nov. 10, would have seen the introduction in

Fairlife pauses US production after cyberattack breached milk brand's systems

Fairlife pauses US production after cyberattack breached milk brand's systems Fairlife is pausing its U.S. production after a ransomware attack breached some of the milk brand's systems NEW YORK -- Milk brand Fairlife is pausing its production in the U.S. after a ransomware cyberattack breached the company's systems. Coca-Cola, which owns Fairlife, announced Thursday that its dairy company had identified “unauthorized access by a third party” to a portion of its systems, including those related to production. The company disclosed that this was in connection to a ransomware event — and in response, it took some operations offline. “Product quality and safety have not been impacted," Atlanta-based Coca-Cola said in a statement. “However, as a result of the incident, production operations at fairlife in the United States are temporarily suspended.” Fairlife’s Canadian operations were not affected. The full scope and impacts of the attack are otherwise still unknown, Coca-Cola added — but the beverage giant said it had informed law enforcement, and is also working with cybersecurity experts as it continues its investigation and recovery to restore operations. A company spokesperson said there were no further updates to share as of Friday morning. Cyberattacks are on the rise across sectors. Beyond dairy goods, other breaches have recently resulted in anything from core education services getting knocked offline to empty shelves at popular clothing or grocery stores. Ransomware attacks — in which hackers demand a hefty payment to restore hacked systems — also account for a growing share of cyber crimes. And experts note that attackers know there’s a particular impact when going after well-known brands and products that shoppers buy or need every day. Fairlife, based in Chicago, touts over $3 billion in annual retail sales today. The company produces a range of lactose-free products — which beyond milk, includes

WARNING: Claude For Chrome Flaw Allows Malicious Extensions To Abuse AI Privileges

WARNING: Claude For Chrome Flaw Allows Malicious Extensions To Abuse AI Privileges A security weakness in Anthropic’s Claude for Chrome extension could allow another malicious browser extension to activate predefined AI workflows without a genuine user click, potentially exposing information held in Gmail, Google Docs and Google Calendar or initiating actions in services such as Salesforce. The issue was discovered by Manifold Security researcher Ax Sharma, who found that Claude for Chrome did not adequately distinguish between a genuine user interaction and a synthetic click generated through JavaScript. The attack does not allow an ordinary malicious website to take control of Claude, nor does it give an attacker the ability to submit arbitrary prompts. Instead, the attacker would first have to persuade the victim to install a separate browser extension with permission to run code on the claude.ai domain. Once installed, that extension could manipulate the page’s Document Object Model (DOM), insert an element containing one of Claude’s recognised workflow identifiers and programmatically generate a click. According to Manifold, Claude would then process the event as though the user had selected the workflow themselves. The potential consequences depend heavily on the user’s Claude configuration, the connected services available to the extension and whether sensitive operations require confirmation. The risk is greater when Claude’s optional “Act without asking” mode is enabled because supported operations may proceed without an additional approval step. Manifold said the issue remained reproducible in Claude for Chrome version 1.0.80, released on July 7, despite being reported to Anthropic in May. The researchers assigned the issue a CVSS score of 7.7 under the default approval configuration and 9.6 when automatic action is enabled. Those scores are Manifold’s assessment and do not appear to have been issued by Anthropic. Missing check allows synthetic clicks The weakness centres on the

Why a <b>cybersecurity</b> strategy needs more than just tools

Why a cybersecurity strategy needs more than just tools Threat Detection IF your cybersecurity strategy is built around buying Managed Detection and Response (MDR), deploying an Endpoint Detection and Response (EDR) agent, and calling it “done”, then someone has sold you a story, not a strategy. Image: IOL / Ron AI IF your cybersecurity strategy is built around buying Managed Detection and Response (MDR), deploying an Endpoint Detection and Response (EDR) agent, and calling it “done”, then someone has sold you a story, not a strategy. There is a growing trend in the industry that is becoming difficult to ignore: organisations believe that once the tools are in place, the job is complete. Buy MDR, deploy EDR, tick the cybersecurity box, and move on. Job done. Except it isn’t. The uncomfortable truth is that cyber criminals are not measuring your security posture by the number of tools you’ve purchased. They are measuring how easily they can move through your business once they get in. And that movement rarely starts where most organisations are looking. MDR is not the problem; it’s a valuable capability and, when implemented properly, it improves visibility and response. We recommend it, but it is not a cybersecurity strategy. It is one layer in a much larger attack surface that many organisations still do not fully grasp. Attackers do not care whether you have an MDR platform watching your endpoints. They care about finding the weakest entry point into your environment. That could be a compromised Microsoft 365 account, a reused password from a breach years ago, a phishing email that looks convincing enough to trust, or a misconfigured cloud application. It could also be a privileged account that was never reviewed or a supplier connection that has been quietly forgotten. None of these are endpoint problems,

Cyber Digital Services, Defence and Security Asia 2026

Cyber Digital Services, Defence and Security Asia 2026 Cyber Digital Services, Defence and Security Asia 2026 (CyberDSA) Kuala Lumpur, Malaysia October 5-7, 2026 CyberDSA aspires to be the leading regional content-driven event serving the cyber defence and security industry. It aims to connect cyber security professionals and executives in the government and private sectors, driven to accelerate the cyber defence and security agenda. This event shall bring the latest technologies, knowledge and insights on cyber intelligence shared by regulators, policy makers, military personnel, CISO’s, Government officials, practitioners and researchers from all over the world. A regional exhibition and conference connecting cybersecurity, data protection, cloud infrastructure, AI solutions and digital transformation for enterprises, government and critical industries. In today’s rapidly evolving digital landscape, artificial intelligence and data have become the new foundations of global power, economic competitiveness, and national security. As societies become more connected and systems increasingly autonomous, the need to secure digital ecosystems has never been more urgent. Cyber threats are growing in scale and sophistication, while data—now a strategic national asset—flows across borders at unprecedented speed. Against this backdrop, CyberDSA 2026, under the theme “Advancing Secure AI, Strengthening Digital Trust, and Safeguarding Data Sovereignty”, emerges as a critical platform for shaping the future of secure and trusted digital transformation. Advancing secure AI is at the heart of this journey. Artificial intelligence is transforming defence, governance, industry, and everyday life, but its promise must be matched with robust security. Secure AI ensures that systems are resilient against adversarial threats, protected from manipulation, and developed within frameworks that uphold accountability, safety, and ethical integrity. It is about ensuring that intelligence systems remain trustworthy from design to deployment. Strengthening digital trust is the cornerstone of a resilient digital economy and society. Trust determines how confidently governments operate, how industries innovate, and

Scattered Spider hackers sentenced, hardware wallet attacks, and other <b>cybersecurity</b> developments

Scattered Spider hackers sentenced, hardware wallet attacks, and other cybersecurity developments Weekly recap of major cybersecurity developments. We compiled the week’s most important cybersecurity news. - macOS malware stole Telegram sessions and replaced wallet apps. - Scattered Spider hackers were sentenced for hacking London’s transport system. - About 300 fake GitHub repositories distributed an infostealer. - The U.S. charged operators of Russian bulletproof hosting providers Media Land and ML.Cloud. macOS malware stole Telegram sessions and replaced crypto wallets Researchers at SlowMist detailed a macOS infostealer’s multi-pronged approach to stealing cryptocurrency. According to them, the malware hijacks authenticated messenger sessions and targets both software and hardware wallets. Once on a device, the malware collected sensitive data: passwords from the macOS Keychain, Safari cookies, hidden entries in Apple Notes, and databases from more than a dozen crypto wallets and browser extensions. How the malware works: - account takeover bypassing 2FA. The malware copies Telegram Desktop’s local session files. These let attackers log in to the victim’s account on another Mac without a phone number, SMS code, or two-factor authentication password, as the system treats the connection as a continuation of an already authorized session; - phishing. The software replaces legitimate hardware wallet apps (Ledger Live and Trezor Suite) with exact copies whose sole purpose is to trick the user into entering the seed phrase. The attackers decrypt stolen databases offline using passwords extracted from the compromised Mac, the researchers said. Targets included Exodus, Atomic, Electrum, Wasabi, Monero wallets, as well as full node clients (Bitcoin Core, Litecoin Core, Dash Core and Dogecoin Core). SlowMist urged users who suspect their Mac is compromised to immediately force-terminate all active sessions in Telegram settings, reauthenticate, and change passwords. To protect crypto assets, the firm advised generating a new seed phrase on a clean device and

Why a <b>cybersecurity</b> strategy needs more than just tools

IF your cybersecurity strategy is built around buying Managed Detection and Response (MDR), deploying an Endpoint Detection and Response (EDR) agent, and calling it “done”, then someone has sold you a story, not a strategy. Image: IOL / Ron AI IF your cybersecurity strategy is built around buying Managed Detection and Response (MDR), deploying an Endpoint Detection and Response (EDR) agent, and calling it “done”, then someone has sold you a story, not a strategy. There is a growing trend in the industry that is becoming difficult to ignore: organisations believe that once the tools are in place, the job is complete. Buy MDR, deploy EDR, tick the cybersecurity box, and move on. Job done. Except it isn’t. The uncomfortable truth is that cyber criminals are not measuring your security posture by the number of tools you’ve purchased. They are measuring how easily they can move through your business once they get in. And that movement rarely starts where most organisations are looking. MDR is not the problem; it’s a valuable capability and, when implemented properly, it improves visibility and response. We recommend it, but it is not a cybersecurity strategy. It is one layer in a much larger attack surface that many organisations still do not fully grasp. Attackers do not care whether you have an MDR platform watching your endpoints. They care about finding the weakest entry point into your environment. That could be a compromised Microsoft 365 account, a reused password from a breach years ago, a phishing email that looks convincing enough to trust, or a misconfigured cloud application. It could also be a privileged account that was never reviewed or a supplier connection that has been quietly forgotten. None of these are endpoint problems, which means none of them are solved by endpoint monitoring alone.

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system. wp2shell is two bugs, not one, and both now carry CVE IDs. CVE-2026-63030 is the REST API batch-route confusion; CVE-2026-60137 is a SQL injection in WordPress core. Chained, they take an anonymous request all the way to code execution. Since Friday, the full mechanism has been published, and a working proof-of-concept has gone up on GitHub. Adam Kues at Assetnote, Searchlight Cyber's attack surface management arm, found the batch-route bug and reported it through WordPress's HackerOne program. The writeup, published under the name wp2shell, says the attack has "no preconditions and can be exploited by an anonymous user." The SQL injection was reported separately by TF1T, dtro, and haongo. Searchlight is still holding its own technical write-up and pointed owners to a checker at wp2shell.com. The reticence is beside the point now: the patch is public, and other researchers read it. The two bugs do not reach the same versions, and that is the key to who is exposed to what. The injection goes back to 6.8. The batch-route confusion, the half that turns a bounded injection into unauthenticated RCE, only exists from 6.9 on. So the ranges split: - 6.8.0 through 6.8.5: SQL injection only, fixed in 6.8.6 - 6.9.0 through 6.9.4: full RCE chain, fixed in 6.9.5 - 7.0.0 through 7.0.1: