The Latest

We may earn a commission from links on this page.

After wearing smart rings for over five years, I’ve become convinced that I deserve one minor luxury whenever I’m traveling with one: a charging case. Even when I’m at home, a charging case is more convenient than a post-style charger. Just before a recent vacation, I got myself a $30 charging case that I like even better than the one Oura sells for $99.

Why charging cases matter for smart rings

Charging cases are handy for a few reasons. Chief among them is that it feels precarious to have your expensive ring on a little stand, attached to a long USB cable. I’m pretty much guaranteed to snag that cable at some point, potentially knocking the ring onto the floor. 

But with a charging case, you not only have the ring in a more secure position, you can also do away with the cable. (The charging case has its own battery, which needs to be charged with a cable, but only once a month or so). I also love that I can put the ring in its charging case, and slip the case into my pocket. When the ring is charged, it’s already with me—no going home to go get it from my desk or nightstand. 

Several smart ring makers include a charging case, or have one available as an extra purchase. That’s a big plus to me when I’m evaluating what you get for your money. RingConn gen 2 and 3 come with cases that have a generous battery; the Ultrahuman Ring Pro has a nice big case as well. The Samsung Galaxy Ring has a clear little case, and so does the Luna ring. Oura rings don’t come standard with a case, but the 4 and 5 generations have a charging case available as an extra purchase. 

Oura sent me a charging case when it was a new product, but it only fit the Oura Ring 4 and not the 5 I’m currently wearing. I tend to do short trips without a charger (since the ring’s battery lasts about a week) and bring the dock on longer ones. But as I was organizing my supplies for a recent vacation, I decided I was going to solve this problem once and for all—I was going to try one of the third-party chargers I keep seeing online, the ones that can fit any charging dock. I bought this Tensea charging case.

How I used the Tensea case on a recent trip

I picked this particular charging case for a few reasons. First, it can fit a variety of Oura docks, and would probably also be able to fit other brands. As a bonus, it has a numerical display to tell you exactly how charged the case is, and a clear lid so you can tell at a glance whether the ring is inside and whether the dock is showing its own charging light. 

Charging case from top
Credit: Beth Skwarecki

These are features that I wish Oura’s own charging case had. Instead, it’s got one LED that changes color to indicate charge level, but sometimes it’s telling you about the ring and sometimes about the case itself. The Tensea case also has a substantially bigger battery than Oura’s. At 7.4 watt-hours, it’s about three times the size of Oura’s 2.5-Wh case. Oura says its case can charge the ring five times, so the Tensea should be able to do around 15 charges. I’ve used it once and the battery level is only down to 96%. I’ll be able to use this for a while. 

Now, this type of case is not a complete replacement—it requires you to add your regular charging dock. The one I bought is made for Oura rings, and it’s sized so that you can pop in the charging dock that came with your Oura Ring 3, 4, or 5. Flip up the case’s hinged USB-C connector, plug in the dock, then hinge the dock down into the case. 

Ultrahuman charging dock doesn't quite fit
The Ultrahuman Air's dock is a bit thicker, so the case won't close—but it does charge like this! Credit: Beth Skwarecki

This design should be able to work with any charging dock that has a USB-C connector and fits in the case, so I tried it with the Ultrahuman Ring Air. I would charitably say that it works with the Ultrahuman, it just doesn’t fit. The ring charged but I couldn’t close the case to slip it in my pocket. If I’m just leaving it on a hotel nightstand, though, it would get the job done without needing a cable. (That’s how I tell myself that this is a versatile item that I can use with many different rings—we will see whether it works with any others I end up testing.) 

In any case, the Tensea did its job, sitting in my backpack waiting to be used. I didn't need it until the day I returned home, but then I was able to quickly find it in my bag and start charging my ring without having to rummage for a cable or find something to plug it into. I'll definitely be using this case for future travel, and I like it as a cable-free nightstand charger at home, too.


from Lifehacker https://ift.tt/VAHd0Ox

In a new ClickFix attack iteration, hackers are pushing an infostealing malware to macOS users that is capable of hijacking your sessions in Google Chrome, Microsoft Edge, and a number of other Chromium-based browsers. AmnesiaStealer grants remote control of your browser and access to plenty of personal data, so you should know how to spot the campaign and protect your device from compromise.

AmnesiaStealer hijacks your web browser on macOS

As BleepingComputer reports, AmnesiaStealer can copy a victim's Chromium profile, which allows it to collect data across 16 Chromium-based web browsers, access authenticated sessions, and control them remotely. This means threat actors can navigate across websites, export or import cookies, and access online portals as well as grab saved logins, history, bookmarks, extensions, and cryptocurrency wallet data. AmnesiaStealer can also capture your macOS password and gain access to keychain data, Apple Notes, Telegram sessions, documents, and system information.

Researchers at security company Jamf found that hackers are distributing the malware via a password-protected ZIP archive on a fake GitHub page and are gaining this level of access when users run a Terminal command that downloads and installs the payload. The campaign mirrors previously identified Atomic and MacSync infostealers.

How to avoid browser takeover attempts

The best way to protect yourself from AmnesiaStealer is to be vigilant against ClickFix attacks, which use social engineering tactics to deliver malware to your device. Common tricks include fake error messages, CAPTCHA forms, and, as in this case, command prompts that install malicious payloads that can then spy on your activity, steal your data, and take over your machine.

Threat actors count on you believing that these commands do something innocuous (like download legitimate software) or not understanding what you're executing on your device. That's why you should be highly skeptical of any prompts you find online and never execute commands in Terminal from non-official sources. Note that the fake GitHub page being used to distribute AmnesiaStealer has a "Verified Publisher" tag to gain user trust. Fraudsters will also try to impersonate legitimate companies—tech support scams are one example—so you should never copy and paste commands in your system dialogue even if you believe you're interacting with a trusted business or service.


from Lifehacker https://ift.tt/8Bhj2ID

Fortinet has acquired Virtue AI, strengthening its broader Security for AI strategy and its vision for securing the agentic enterprise. The acquisition builds on Fortinet’s existing AI security portfolio, which includes the FortiGate Hyperscale Firewall.

As organizations deploy AI applications and autonomous agents, their attack surface expands beyond networks, users, endpoints, applications, and cloud workloads. It now includes prompts, models, agents, Model Context Protocol (MCP) tools, application programming interface (API) calls, and AI infrastructure. Organizations need to adopt AI with confidence, keep it secure in production, and trust it behaves as intended.

Fortinet met that need earlier this year with FortiAIGate, which safeguards large language models (LLMs from prompt injections, data leakage, model poisoning, excessive resource consumption, and other emerging AI-specific risks. Virtue AI extends that security to AI models, applications, and agentic systems from development through runtime, leveraging Virtue AI’s Guardian Agent abilities and key product capabilities, including:

  • Agentic system red-teaming: Tests autonomous agents for exploitable weaknesses across more than 50 sandboxed environments and 14 high-stakes domains, including simulated prompt-injection and MCP-based attacks against leading agent frameworks.
  • Agent protection, governance, and visibility: Provides full visibility into agents and AI tools running in their environment, discovers unsanctioned AI applications and agents, scans MCP tools and source code for hidden risks, monitors agent behavior, and blocks malicious tool calls before they act.
  • Continuous AI validation: Identifies new risks across every model update and fine-tune of policies, while generating audit-ready evidence to support security and compliance reviews. The automated red-teaming runs across hundreds of attack vectors and more than 1,000 risk categories, with multimodal testing and on-demand reporting for security, risk, and compliance teams.
  • Real-time guardrails: Enforces customizable policies across text, images, video, audio, and AI-generated code to keep harmful content, sensitive data, jailbreaks, and vulnerable code from reaching users or downstream systems.

“AI is fundamentally changing enterprise computing, and security must evolve just as quickly,” said Ken Xie, Founder, Chairman of the Board, and Chief Executive Officer at Fortinet. “Virtue AI’s technology will advance our vision for continuous AI assurance, helping customers govern and protect AI systems throughout their lifecycle and operate them confidently at enterprise scale.”

According to Gartner, “the market for securing AI ecosystems and AI agents is rapidly expanding, products and tools is expected to expand from $2.8 billion in 2026 to $16.4 billion by 2030.” Fortinet believes that anticipated market expansion is indicative of the evolving industry demand to secure the AI era.

Customers already rely on the Fortinet AI-native Security Fabric for integrated protection across networks, endpoints, clouds, applications, and AI deployments. This acquisition complements FortiAIGate and further strengthens Fortinet’s AI runtime security capabilities with Virtue AI’s automated validation and real-time protection. Combined with coordinated enforcement and FortiGuard Labs threat intelligence, it will give organizations the confidence to secure AI systems throughout their lifecycle.

Financial terms of the transaction are not disclosed, and the amount paid by Fortinet as consideration is immaterial to Fortinet’s business.


from Help Net Security https://ift.tt/ci45t3n

Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself.

AI coding agent containment

An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configuration in your home directory that has accumulated over years. Hazmat gives the agent a home of its own and shares only the project directory you point it at. Your keys and credential folders sit outside what the session can reach.

Read the terms before the agent starts

Before anything launches, one command shows you the terms of the session. It lists the directory the agent can write to, the paths it only gets to read, whether it can reach the network or any services, and whether a backup runs first. Take the ten seconds and read it. That printout is the last moment you get a look at what the agent can touch, and everything after it happens while you are not watching.

On macOS the launch does four things in order: back up the project, build a sandbox policy for that one session, switch to the agent account, then start the harness. A firewall rule is already in force by then. Linux runs natively, and a backend using Apple’s container tooling sits behind an experimental flag.

A demo you can run yourself

You can test the boundary in about a minute. A demo script creates a throwaway project, switches networking off, and runs a single contained command that writes a file into that project and reaches for a private key in your real home directory. The write lands. The key comes back unreadable, and the comparison afterward lists one new file in the project and nothing else touched.

About 5.5 percent of the code is a formal specification written in TLA+, a language for describing how a system should behave so the description can be checked by machine. The project calls its design verified on that basis. What got checked is the containment model on paper, and the Go binary you install is a separate piece of work with its own bugs.

Hazmat is available for free on GitHub.

Must read:

Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!


from Help Net Security https://ift.tt/Lj56ZKC

Companies that provide specific evidence of how they use AI tend to record stronger revenue growth. Researchers at Carnegie Mellon University and Larridin examined a study universe of 564 companies across 12 industry sectors. Individual analyses used smaller samples depending on data availability.

AI adoption revenue growth

The data included 478 corporate 10-K filings, more than 30,000 classified job postings, financial information, market data, and the AI Transformation Tracker built by Larridin.

The tracker assigns companies scores from 1 to 5 across three areas: AI adoption, workforce proficiency and realized impact. It also provides an overall maturity index. The January 2026 Tracker score vintage contained scores for 562 companies, corresponding to 538 after the researchers’ deduplication process.

“Generalized AI investment alone tells us little about a company’s ability to create value,” said Ameya Kanitkar, CTO of Larridin. “What matters is identifying where AI is being deployed, measuring adoption and workforce proficiency, understanding how customers and employees are benefiting, and connecting those efforts to quantifiable business results.”

Detailed AI disclosures linked to revenue growth

One of the most distinct indicators was what the researchers call “narrative concreteness.” The measure looks at how specifically a business describes its AI deployments and results in regulatory filings.

Companies that named AI systems, explained how they were being used and provided measurable outcomes tended to perform better on revenue growth. In the researchers’ adjusted model, companies at the top of the narrative-concreteness distribution were associated with 8.0 percentage points higher year-over-year revenue growth than companies at the bottom.

The researchers evaluated adoption, employee proficiency, realized impact, overall AI maturity, investment intensity, AI-focused hiring and the level of detail in corporate disclosures. Six score- and filing-based measures were significantly associated with revenue growth in unadjusted analyses. The hiring measure was not.

Several of the broader adoption and composite measures weakened once differences in industry, company size and previous growth were taken into account. Detailed descriptions of AI deployments continued to carry information about revenue growth after those adjustments.

Job postings offered another way to examine adoption. A total of 30,861 postings across 536 companies were classified to determine the share of hiring aimed at roles focused on building or operating AI and machine learning systems. The researchers caution that the job-posting data were collected after the revenue period being studied, so the hiring measure should be treated as descriptive evidence rather than a prospective predictor of revenue growth.

AI adoption shows little connection to margins

Greater signs of AI adoption were not associated with improved operating margins. No significant margin effects were found among the public signals examined.

The results provide little evidence of broad operating-margin improvements associated with the AI signals examined. The study did not directly measure individual cost categories or workforce reductions.

Stock market performance followed a similar pattern. None of the public AI signals predicted risk-adjusted stock returns over the following four months after controls and adjustments for multiple testing were applied.

AI infrastructure providers outperform

Companies supplying infrastructure for the AI market produced a different result. AI infrastructure suppliers outperformed sector- and size-matched peers by about 32 percentage points over four months.

Five large semiconductor companies, Nvidia, Broadcom, AMD, Micron and Intel, were excluded from the main analysis to prevent their performance during the AI investment boom from having an outsized effect on the results. Running the calculations with those companies included did not change the main conclusions.

The relationship between detailed AI disclosures and revenue was particularly useful in asset-heavy industries, where implementation may require changes to physical infrastructure, operations and established processes. Specific descriptions can help distinguish companies that have put AI into use from those still discussing plans or early experiments.

The results show association, not causation

The results do not establish that AI caused stronger revenue growth.

Companies that are already performing well may have more resources to deploy AI, measure its impact and provide detailed information about those deployments. Existing growth trends could also influence subsequent results, although prior revenue growth was among the factors included in the main statistical controls.

The work instead identifies a statistical relationship between observable evidence of AI use and revenue growth. The strongest result centers on concrete disclosures rather than broad claims of AI adoption, suggesting that specific information about deployed systems and measurable outcomes may provide a useful signal of how far implementation has progressed.

“The study suggests companies are using AI primarily to expand capabilities, improve customer experiences, and create new growth opportunities,” said Shixiang (Woody) Zhu, Assistant Professor at Carnegie Mellon University’s Heinz College of Information Systems and Public Policy.

“At this stage, AI’s measurable impact is appearing more clearly in revenue growth than in operating margins or stock performance, indicating that its value goes beyond cost reduction.”


from Help Net Security https://ift.tt/q7SNj1b

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

Week in review

GitHub Dependabot malware alerts now cover eight ecosystems
GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. Dependabot malware alerts, which had run on npm data alone, now draw on all eight ecosystems the moment a user turns malware alerts on. Dependabot itself already runs across more than 30 million repositories and 34-plus package ecosystems overall, which gives a sense of the scale the malware pipeline now has to operate at.

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix
Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws nobody had reported before. Developers have confirmed 83 of them, and 81 now carry CVE numbers.

Post-quantum migration gets harder when every user holds a key
In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees.

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months
Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now resolving to a generic rented server from a German hosting provider. From that server, someone has been pulling records out of Salesforce and ServiceNow portals around the world.

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577
To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs).

Metabase zero-day exploited to access Framework customer data
Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framework customers, the attackers accessed names, email addresses, phone numbers, physical addresses, and login IP addresses, but not payment information or records related to orders.

Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)
Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the patches.

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)
A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog and needs to be remediated by US civilian federal agencies by August 14, 2026.

Who will be the Stanislav Petrov in your organization?
Recent reports of “rogue AI” systems hacking companies reminded Brian Honan, CEO, BH Consulting, of Stanislav Petrov. In 1983, Soviet computers falsely detected a US nuclear missile launch. Instead of trusting the system, Petrov applied human judgement and correctly identified it as a false alarm, potentially preventing nuclear war. That is why the recent incidents involving OpenAI and Hugging Face, Anthropic, Meta, and the UK’s AI Security Institute deserve the attention of CISOs and boards.

338 million attack simulations reveal the state of enterprise defense
First, a bit of good news: Enterprise defenses are recovering. However, it’s a narrow recovery, with a twist. Today, organizations are better at stopping loud attacks but have barely moved the needle at all against the quiet ones. This data, and a lot more, comes straight from the newly published Blue Report 2026, the fourth annual comprehensive study from Picus Labs.

Four corporate investigation mistakes organizations make under pressure
In this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Access gets granted, conversations start, and decisions get made that later affect chain of custody, privilege, and how regulators judge the process.

How to report an AI Act violation in the EU
The EU’s fight to regulate AI models entered a new chapter on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. It creates a common set of rules for AI systems used or sold in the EU, with the goal of encouraging innovation while protecting people’s safety and fundamental rights.

Chainloop: Open-source evidence store and policy engine for the software supply chain
Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable storage, and references each one in a signed in-toto attestation. in-toto is a specification for recording who ran which step of a build, so the record can be checked afterward.

Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users
Microsoft is changing how Entra ID handles MFA for people who sign in with Windows Hello for Business (WHfB) or macOS Platform Single Sign-On (PSSO). The rollout reaches worldwide and GCC tenants starting early October 2026, with completion expected by late November.

Cyberattack on Steam hardware shipper leaks names, addresses, and order data
Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began surfacing on social media earlier today, after Valve started sending out data breach notification emails.

Previously unseen entry vector used to breach Polish energy plant
The December 29 cyberattack on a Polish combined heat and power (CHP) plant was the first observed case of attackers gaining access to an OT network through a private APN, according to CERT Polska. The private APN is a dedicated mobile network that a Distribution System Operator (DSO), the company running the local electricity grid, sets up with a mobile carrier.

GPT-5.6-Cyber refuses security researchers’ requests far less often
GPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. Model is available only through Daybreak Red, the higher tier of OpenAI’s vetted access program for cybersecurity professionals.

Ransomware gangs don’t need control system access to disrupt industrial production
Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial control systems (ICS), according to Dragos. The company identified 1,140 ransomware incidents involving industrial organizations in the second quarter of 2026, up 12% from 1,020 in Q1.

Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G
Researchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, disrupt communications, downgrade connections to 2G, and in some cases execute code.

Ready-made $500 kit puts a crypto scam within anyone’s reach
A seller on a cybercrime forum is offering a ready-made scam kit for $500, complete with an admin panel that tracks victims, checks their crypto wallets for value, and inflates fake balances to squeeze out more money, Malwarebytes found.

Split-second deepfake glitch blows digital certificate fraudster’s cover
Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obtain digital signatures he could use for financial fraud.

Lazarus hackers pair fake job offers with Windows zero-day exploit
The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point researchers have found.

Signal’s new security feature checks if your encrypted chats were tampered with
Signal has introduced a feature called automatic key verification, giving users a new way to confirm that nobody has secretly interfered with their encrypted chats.

153GB of stolen credentials surface after LiteLLM supply chain attack
A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtained and analyzed the archive, which contains 433,909 files, and attributed 118,829 CI runner dumps to 2,488 corporate domains.

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)
Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. Tracked as CVE-2026-55040, the vulnerability was patched by Microsoft as part of its July 2026 Patch Tuesday updates.

White House authorizes private US companies to hack foreign criminal networks
President Trump signed a National Security Presidential Memorandum on August 12 allowing vetted private companies to run offensive cyber operations against foreign threat actors, under the control and oversight of the US government.

Ukrainian police raid 94 fraudulent call centers, seize $2 million
Ukrainian police have disrupted 94 fraudulent call centers during a nationwide operation that involved more than 400 searches and the seizure of thousands of computers, phones, and SIM cards.

New Android malware relays bank cards to fraudsters while victims still hold them
Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real time. WindRelay is paired with the SpyNote remote access trojan, which gives attackers remote access to a victim’s device.

71% of CISOs spend 10+ hours on board reports
Boards want evidence that security controls and architecture reduce business risk, expressed in terms of resilience, consequence, and decision relevance. Translating technical findings into business language remains a major time burden for CISOs, who are calling for simpler data delivery, better frameworks, and better context. Pulse Security AI’s The CISO-Board Communication Gap report found that board members bring external information into discussions while many organizations still lack a formally defined cyber risk appetite.

Product showcase: Enpass Password Manager breaks away from the proprietary cloud model
Enpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information in encrypted vaults. Vaults remain on the device or in a cloud storage service selected by the user.

OpenAI locks down Astra over potential critical cyber capabilities
OpenAI’s internal evaluation of its upcoming model, Astra, found significant advances in agentic coding and cybersecurity, leading the company to conclude that it cannot rule out the model reaching the critical capability level for cybersecurity under its Preparedness Framework.

Anthropic to put AI in charge of reviewing Claude Code actions by default
Anthropic will make auto mode in Claude Code the default for new sessions on Pro, Max, and Team plans starting August 14. Users who previously selected a different default may receive a one-time prompt asking whether they want to switch to auto mode.

Your security vendor gets the frontier cyber model, you get the findings
Selected red team specialists can now use OpenAI’s cyber models to find and exploit weaknesses in client applications and infrastructure. Those clients never get the models themselves. That split is the design of the Daybreak Cyber Partner Program, which OpenAI expanded on August 10: access to the underlying models stays with the approved partner and is not transferred directly to the customer.

Locking your ssh-agent exposed local-only keys until OpenSSH 10.5
Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether a request came from your own machine or arrived down a forwarded connection from a remote server. The fix shipped today in OpenSSH 10.5.

AI deployments are stretching enterprise security to its limits
CISOs and CTOs expect AI deployments to increase their organizations’ attack surface by an average of 14% over the next year. Nearly all lack visibility into AI deployments, and 90% are concerned about employees using unapproved AI tools outside formal oversight, according to NetFoundry’s 2026 State of Secure AI Access survey.

PentestGPT: Open-source automated penetration testing agentic framework
PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then walkthrough, each stage feeding the next. Switch it to pentest mode and the stages become asset discovery, vulnerability identification, report. No human sits in the loop.

Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily
Google Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping reduce scams, phishing attempts, and other deceptive content.

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers
Wireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that reads a capture off disk before any dissection begins: pcapng, Endace ERF, Tektronix K12xx, BUSMASTER, Catapult DCT2000, Gammu DCT3, 3gpp phone logs, TTX Logger, and, on Windows only, Ixia IxVeriWave and Vector Informatik BLF. An attacker never has to touch your network for these. They only have to get you the file.

Product showcase: Is this image real? Slop or Not investigates
Slop or Not is an AI text and image detector for iPhone and Mac that runs entirely offline, with no account required. It uses on-device AI models powered by the Apple Neural Engine to detect AI-generated content.

DDoS attacks hit record scale as 1 Tbps+ campaigns become more common
DDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Cloudflare’s H1 2026 DDoS Threat Report shows threat actors relying on multi-vector techniques and large-scale network-layer attacks to disrupt online services across multiple industries.

17 draft Cyber Resilience Act standards are open for comment
A company selling a connected toy in Europe must show by the end of 2027 that the product meets the Cyber Resilience Act. The law states what manufacturers have to achieve and stops there, which leaves the toymaker to work out the technical detail alone. Seventeen draft standards, now open for comment, supply that detail.

Weak IAM affects up to 98% of cloud environments
Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now mandates baseline cloud configuration practices for US federal agencies.

The hardest part of agentic AI may be rebuilding the business
Organizations expect AI agents to change how work gets done, driving productivity and growth while allowing employees to focus on higher-value tasks. Few, however, have the processes and workflows needed to realize those benefits, according to Deloitte’s latest research.

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals
AWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027, ahead of the Certification Authority/Browser (CA/B) Forum’s March 15, 2028 deadline for ending email-based domain validation.

OpenAI’s GPT-5.6 Sol runs up to 14× faster with Ultrafast mode
OpenAI’s GPT-5.6 Sol on Ultrafast mode is available in limited preview to a select group of customers, launching first through the OpenAI API. The company says the service runs up to 14 times faster than Standard processing and generates up to 750 output tokens per second. Ultrafast is powered by Cerebras as part of the companies’ partnership on ultra-low-latency inference.

Cybersecurity jobs available right now: August 11, 2026
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.

New infosec products of the week: August 14, 2026
Here’s a look at the most interesting products from the past week, featuring releases from A10 Networks, ScienceLogic, Searchlight Cyber, and SelectHub.


from Help Net Security https://ift.tt/acREltg

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of publication.

The era of the boombox as we knew it in the 90s might be over, but if you still want an audio powerhouse that’ll give you better sound than your average portable speaker, there are several options that fit the bill, along with modern features like the ability to float in water and lighting effects. The popular Anker Soundcore Boom 2 Plus Bluetooth speaker is one of them—and right now, it’s 32% off ($169.98, originally $249.99).

This speaker gets seriously loud thanks to two 50W woofers and two 20W tweeters, delivering up to 140W. This is enough to create immersive sound during a backyard or pool party, camping trips, and beach get-togethers. PCMag, which gives it an Editors’ Choice Award, says it has a “powerful low-frequency response” and gives “serious thump” with plenty of bass. When BassUp 2.0 mode is activated (it’s on by default), the sound gets even bassier. Battery life lasts up to 20 hours with BassUp off and volume at 50%. 

The Soundcore Boom 2 Plus has an IPX7 rating that lets the speaker be submerged up to a meter for 30 minutes, and it even floats. Despite being mostly plastic, the speaker still has a rugged build. While it clocks in at 8.4 pounds, a removable, adjustable strap and built-in handle make it easy to carry around. The standout feature that sets it apart from similar speakers in its class is the bright, customizable LED lights that pulse with the beat of the music. The app controls both the sound and the lights, allowing you to further customize colors. 

If you’re craving robust audio that can hold its own outdoors, a rugged build, and fun lighting effects to set the vibe, the Anker Soundcore Boom 2 Plus has the right combination of features, making it a go-to for indoor and outdoor use. At its lowest price yet, this portable party starter should be on your radar.

Our Best Editor-Vetted Tech Deals Right Now
Deals are selected by our commerce team

from Lifehacker https://ift.tt/6B12kRx