The Latest

We may earn a commission from links on this page.

No one dishes out shocking twists and emotionally powerful moments like Harlan Coben, and his partnership with Netflix just keeps delivering stories you can’t help but devour in one sitting. I Will Find You, starring Sam Worthington and Britt Lower, is no exception: The story of a father risking everything to prove he didn’t commit an unspeakable crime while searching for the son he thought lost forever is the sort of show you hop online immediately after the credits roll to see what people are saying. If you’ve already watched the series that give the same vibe and want more innocent people trying to get their lives back, unpredictable plot swerves, and emotionally charged stories of hard-won justice, look no further than 1993’s The Fugitive.

Why you should watch "The Fugitive" after "I Will Find You"

The Fugitive was a massive hit in 1993. Based on a 1960s television series (also called The Fugitive) that was itself a national phenomenon, it’s the story of Dr. Richard Kimble (Harrison Ford), who is convicted of the brutal murder of his wife, Helen (Sela Ward), despite his claims of witnessing a one-armed man committing the crime. When the bus transporting him to prison crashes, Kimble escapes and launches a desperate campaign to prove his innocence, identify the murderer, and evade the dogged pursuit of U.S. Marshal Samuel Gerard (Tommy Lee Jones) and his team.

The Fugitive scratches the precise innocent-man-on-the-run itch as I Will Find You, following Kimble as he uses his medical training and survival instincts to avoid capture while taking enormous risks. He poses as a janitor at a local hospital in order to conduct research on men with prosthetic arms and is almost caught several times by the smart and experienced Gerard (who famously tells Kimble that he doesn’t care when Kimble protests his innocence).

While the film doesn’t have the bonkers twists that Harlan Coben came up with for I Will Find You, there are plenty of unpredictable plot swerves as Kimble unravels a conspiracy that hits closer to home than he expects. Just like the Netflix series, the villain has violently self-serving motives, and the true story of what happened is a surprising reveal. And if your favorite part of I Will Find You was the interaction between father-daughter FBI agents Max Williams (Chi McBride) and Sarah Greer (Logan Browning) as they pursue David, you’ll absolutely love Sam Gerard and his team as they bicker, joke, and follow the trail with absolute dedication to their jobs.

Bottom line: The Fugitive is a big-budget, slightly less shocking Harrison Ford blockbuster that every fan of I Will Find You will love. You can rent The Fugitive on Prime Video.

More movies

Still craving twisty thrillers about innocent folks searching desperately for the truth? Here are a few more brilliant movies to check out.

Primal Fear (1996)

You want more absolutely mind-blowing twists? Primal Fear has one of the most brilliant swerves in film history. Edward Norton’s film debut sees him playing Aaron Luke Stampler, a stuttering, shy altar boy accused of viciously murdering the beloved Archbishop Rushman. Vain, publicity-seeking attorney Martin Vail (Richard Gere) takes Aaron’s case, believing the weak, forgetful Stampler incapable of such atrocities—but the twisty story builds to one of the all-time great reveals, a scene that made Norton a star overnight. Stream Primal Fear on Fubo or Kanopy, or rent it on Prime Video.

Gone Girl (2014)

Was it the complexity of the setup that hooked you in I Will Find You? Gone Girl takes that to the next level. Based on Gillian Flynn’s smash novel, the story begins when Nick Dunne (Ben Affleck) comes home to find his wife, Amy (Rosamund Pike), is missing. The clues at the scene don’t look great for Nick, and as the sordid truth of his marriage emerges, things look worse—but nothing is exactly what it seems in this taut, clever mystery. If you were fascinated by the effort put into painting David as a heartless killer, you should know that Gone Girl takes that to the next level. Rent Gone Girl on Prime Video.

The Next Three Days (2010)

There’s something absolutely gripping about a story focused on an innocent person’s life ruined by a false accusation. The Next Three Days is a tense thrill ride based on that premise: John and Lara Brennan (Russel Crowe and Elizabeth Banks) are happily married with a young son. When Lara’s boss is murdered after Lara had an ugly, public confrontation with him, she’s convicted of his murder. As time passes and John can see her giving up all hope, he launches a desperate plot to break her out of prison and reclaim their lives. If you rooted for David to prove his innocence, you’ll root for John and Lara in the same way. Rent The Next Three Days on Prime Video.

Double Jeopardy (1999)

Part of the thrill of I Will Find You is the slow, twisty route to justice—to finding the truth and punishing the truly guilty. That’s where Double Jeopardy lives. Ashley Judd stars as Elizabeth Parsons, who is convicted of murdering her husband, Nick (Bruce Greenwood), after she’s found with a bloody knife on their boat, his body presumably swept into the ocean. She loses custody of their son and despairs—but she eventually discovers that Nick faked his death and framed her for the murder. Her life becomes consumed with the need to reclaim her son and—when she realizes she cannot be charged with the same murder twice—to get a measure of revenge. Stream Double Jeopardy on Kanopy or rent it on Prime Video.

The Shawshank Redemption (1994)

One of the all-time classics in the “wronged person serving time” genre, The Shawshank Redemption is simultaneously an inspiring story of friendship, a stirring tale of surviving in the face of horrific loss and injustice, and one of the greatest twisty stories of all time. Its steady pacing and careful characterization let you really get to know the wrongly convicted man at its core, and the ending lets you appreciate how resolute and determined he was while experiencing the worst horrors a human can imagine. Rent The Shawshank Redemption on Prime Video.


from Lifehacker https://ift.tt/uX8CRfw

NVIDIA and a group of tech companies have formed an alliance to promote the use of open AI models in cybersecurity, days after OpenAI disclosed that one of its own AI models breached Hugging Face’s systems during an internal security evaluation.

The new group, called the Open Secure AI Alliance, builds on work already underway at the Linux Foundation’s Akrites initiative and the Open Source Security Foundation (OpenSSF).

“Open models, like any powerful technology, can be misused — including through attempts to weaken safeguards or repurpose capabilities for cyber attacks — but those risks are not unique to open systems, and they must be managed wherever advanced AI is deployed,” Nvidia said in a statement.

Among the 27 founding members are Microsoft, Dell Technologies, the Linux Foundation, and NVIDIA itself, alongside companies including Cisco, CrowdStrike, IBM, Palo Alto Networks, Red Hat, and Hugging Face.

OPIS

(Source: NVIDIA)

The Hugging Face incident

“The recent Hugging Face security incident delivered a clear reminder: cyber defenders need open, frontier agentic systems for self-defense,” Nvidia wrote.

“When closed AI tools — unable to distinguish attackers from defenders — blocked essential forensic analysis, Hugging Face ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the intrusion,” the company added.

Hugging Face disclosed the incident on July 16, noting it had identified unauthorized access to internal datasets and service credentials earlier that same week.

The company traced the entry point to a malicious dataset that abused two code-execution paths in its data processing pipeline. That allowed an intruder to execute code on a processing worker, escalate privileges, and move into several internal clusters. At the time, Hugging Face attributed the campaign to an autonomous agent framework of unknown origin.

Last week, OpenAI confirmed the incident was caused by its own AI models during an internal evaluation of their exploitation capabilities.

“That incident showed a practical truth: when defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most,” Nvidia noted.

A message to regulators

The alliance argues that AI security should not depend on a handful of closed systems. Instead, it wants defenders, including companies and governments protecting their own infrastructure, to have access to open models, agent frameworks, and tools they can inspect, modify, and run on their own infrastructure.

“The age of AI agents can be one of resilience and shared security. With the right choices, open secure AI systems can give defenders the tools they need, strengthen competition, extend technological leadership and ensure that the safety and security of this extraordinary technology are built in the open for everyone,” Nvidia concluded.


from Help Net Security https://ift.tt/mo7Lh12

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of publication.

If you've been patiently waiting for the right moment to pull the trigger on the best Nintendo Switch 2 bundle deal like I have, this is the part where your patience gets rewarded. Woot is selling a refurbished Nintendo Switch 2 Mario Kart World Bundle for $419. That's $80 less than the retail price for a new bundle and arguably better than the deal they had in June, as long as you don't mind a refurbished unit.

This bundle deal is a great opportunity when you consider the console by itself (without the bundle) will increase to $499.99 come Sept. 1. Since we're about a month away from that date, this could very well be the last great opportunity to buy the console for its lowest price.

The new console is an upgrade in every way, as you can read in our full review of the Nintendo Switch 2. The ergonomics and design have improved, making it much better to hold and look at. The battery life has also improved, now with about 180 minutes of handheld playtime before the juice runs out.

A big plus is that the Switch 2 is backwards-compatible: You can play your old Switch games on it. Some Switch games have the ability to upgrade to the Switch 2 Edition by buying that game's upgrade pack. This is especially worth it for games like The Legend of Zelda: Tears of the Kingdom, which will look better on the Switch 2.

There aren't many Switch 2 games out at the moment, but there are some classic Nintendo games to keep you busy until the library expands, like Donkey Kong Bananza, Kirby Air Riders, and Hyrule Warriors: Age of Imprisonment. If you already own a Switch 2, check out our Top 10 Hacks to get the most out of your device.


from Lifehacker https://ift.tt/50VIAgX

In this Help Net Security video, Joel Moses, VP, Strategic Engineering at F5, explains how attackers use identity instead of breaking through it. He walks through MFA fatigue, session token theft, and consent given to malicious applications, using the 2022 Uber breach as an example. He also covers how cloud and on-premises trust relationships give attackers a path between environments. Moses suggests number matching, FIDO2 keys, periodic reviews of third party application access, and watching … More

The post What the identity attack surface looks like when trust becomes the target appeared first on Help Net Security.


from Help Net Security https://ift.tt/3CPjkZE

An automated update tool watches a package registry, catches a new release the moment it publishes, and opens a pull request for your team. That is the job it was built to do. In September 2025, that speed cut the wrong way. An attacker phished one npm maintainer’s credentials and shipped poisoned versions of chalk, debug, and about a dozen other packages. Together those packages are downloaded more than 2 billion times a week, and the injected code rewrote cryptocurrency wallet addresses inside any browser app that loaded it.

dependabot cooldown

The bad versions were live for about two hours before the community caught them and npm pulled them. Two hours is a fast cleanup. It is also enough time for an update tool to see the release, file a pull request, and set the malicious code in front of your reviewers.

GitHub’s Dependabot now waits. For non-security version bumps, it holds off at least three days after a release publishes before opening a pull request. The cooldown option in dependabot.yml controls the window, so a project can dial it up or down.

Two kinds of updates, one delay

Dependabot does two separate jobs. Security updates answer a known vulnerability: an advisory lands for a package you use, and Dependabot opens a pull request to move you onto the patched version. Version updates keep your dependencies current as new releases ship.

The three-day delay touches version updates alone. Security updates still open the moment an advisory drops, since holding one back would sit on a fix for a flaw the public already knows about.

Malware that lives for hours

A poisoned build of a popular package tends to have a short life. It publishes, spreads to whatever installs it, and gets caught, usually inside a few hours. Compromised versions of Solana web3.js, Axios, and ua-parser-js each followed that arc.

GitHub’s Advisory Database logged more than 6,500 npm malware advisories in the year ending May 2026.

That works out to about 18 freshly cataloged malicious npm packages a day. A cooldown keeps you out of that opening window and lets a release collect some scrutiny before it reaches you.

Why three days

A review of 21 widely reported supply chain incidents over the past several years found the same rhythm every time. The malicious version publishes, and within hours someone catches it and it comes down. A short waiting period would have filtered most of those publishes before anyone installed them.

Three days pushes you past the window where most of these attacks live. It also avoids holding your dependencies back longer than the job needs. Other tools in the community have settled on the same figure, which keeps behavior consistent for developers moving between them.

The attacks a cooldown misses

A cooldown assumes the malware moves fast. Carlin Cherry, a GitHub product manager who works on Dependabot, names the ones it misses: “It does little against attacks that play a longer game, including backdoors planted in releases and left dormant, maintainer sabotage, or a compromised build system.”

So a cooldown earns a place as one layer among several. Pin dependencies with lockfiles. Turn off install scripts in CI where you can. Scope the tokens in your build pipelines, and review updates before they merge.

The delay is on by default, and a project can tune the window or set different delays for trusted internal packages and public registries. It removes one fast, common path onto your machines. The rest of the supply chain still needs watching.


from Help Net Security https://ift.tt/ZQMgRv8

Claude Opus 5 went live on Amazon Bedrock and Claude Platform on AWS. Anthropic says the model improves on Claude Opus 4.8’s cyber capabilities, coding through cybersecurity.

claude opus 5 aws

Anyone with an AWS account in a supported region can call it. On higher-risk requests, Opus 5 hands the job back to Opus 4.8, the older model. The user sees a notice when that happens. API customers can configure the fallback.

The guardrail that catches the riskiest requests ships with a setting the customer controls.

What the model does now

Opus 5 is a step up in coding, able to read a codebase like an experienced engineer and write production-quality code, adjusting its approach as it works. It runs agents that keep going for hours and overnight, routing around obstacles and recovering from errors. The company reports its largest accuracy gains on document-heavy enterprise work.

For agent automation, the model pushes back on flawed instructions and splits big jobs into sub-agents that need less oversight. It runs multi-day projects and produces professional-grade output.

Where the data goes

On Bedrock, Opus 5 runs with zero data retention by default and zero operator access. The same model reaches customers through Claude Platform on AWS, with zero data retention on request, billed and authenticated through AWS.

How engineers reach it

Engineers select Opus 5 in the Bedrock console playground or call it through the Anthropic Messages API and the Converse API. The model supports adding and removing tools mid-conversation through content blocks on system messages, replacing the re-send of the whole tools array.

Where it runs

Opus 5 is available on Bedrock in four regions at launch: US East (N. Virginia), Asia Pacific (Melbourne), Europe (Ireland), and Europe (Stockholm), with more listed in the documentation. On Claude Platform on AWS, it reaches North America, South America, Europe, and Asia Pacific.

Opus 5 lands with better cyber capabilities than Opus 4.8. The control over when it drops back to Opus 4.8 sits with the customer, in the API.


from Help Net Security https://ift.tt/BYWjIc0

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

Week in review

AI agents are still logging in as humans
Most large companies run more than one AI platform at the same time. Developers pull up coding assistants, marketing teams lean on writing tools, and analysts query enterprise search across separate vendors. Single-provider setups keep giving way to mixed stacks as companies keep their options open.

PR3TACK preemptive framework maps threats before attackers use them
Defensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. This cycle leaves a gap between the moment an attacker invents a technique and the moment defenders learn to catch it. PR3TACK, the Preemptive Tactics and Countermeasures Knowledgebase, aims to close that gap.

The air gap is a myth and other OT security truths
Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth.

Cisco’s open-weight Antares models make vulnerability localization cheaper
A security analyst opens an unfamiliar repository, reviews a vulnerability advisory, and begins searching for the source file where the flaw resides. The naming conventions are unfamiliar, and clues are scattered across thousands of files. That initial triage can consume hours of expert effort. Cisco aims to shorten that process with Antares, a family of small language models designed to identify the source files most likely to contain a known vulnerability.

Snowpick: Open-source ServiceNow exposure scanner
An employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and get records back. Bishop Fox ran that test across 166 ServiceNow instances during authorized penetration tests. The firm published the results along with the Go tool it used, Snowpick.

The AI code vulnerabilities that grow with your app
Theori built 28 apps with AI coding agents and scanned each one through its pentesting platform. Five models did the building, split between Anthropic and OpenAI, across apps written from a spec, thrown together from a casual prompt, and rewritten from an aging PHP codebase.

Multi-patch vulnerability fixes can leave open source exposed
Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two or more commits where the first one leaves the flaw in place. Researchers at the University of Texas at Dallas went through 1,646 open source CVEs that carry more than one patch in the National Vulnerability Database, drawn from records filed between 1999 and 2025.

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process
Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim machine and controls it through Chrome DevTools Protocol, a debugging interface built into both browsers. The browser then carries the command-and-control traffic over a WebRTC channel.

The best-funded companies open the most phishing attachments
An employee gets an email dressed as a password reset. She clicks the link, types her credentials into a page built to copy her company’s login screen, and moves on with her morning. She tells no one. That silence is the exposure. Across 13.9 million simulated phishing messages, one in ten recipients flagged the attempt to their security team. The rest let it through, and a live attacker needs only one of them.

Hugging Face breached by autonomous AI agent
Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous AI agent system. In a blog post published Thursday (July 16), the company said that earlier that week, it identified unauthorized access to some internal datasets and to several credentials used by its services.

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. CVE-2026-6875 is a code injection vulnerability that lets unauthenticated attackers escape ServiceNow’s script sandbox and execute code remotely on a targeted instance.

SonicWall SMA zero-days were exploited weeks before disclosure
Two recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed.

JadePuffer returns with ransomware built to target AI models and infrastructure
JadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now attempting to leverage ENCFORGE, novel ransomware created to target AI and machine learning (ML) infrastructure. The extortion contact embedded in the ransomware is the same one Sysdig researchers found when analyzing that prior campaign.

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. WatchTowr’s global honeypot network registered successful exploitation attempts on July 20, mere hours after the release of the proof-of-concept exploit and less than a week after Microsoft confirmed that CVE-2026-56164 (an privilege elevation flaw) and CVE-2026-58644 (a RCE vulnerability) are being actively exploited by attackers.

OpenAI: Our models breached Hugging Face during a cyber capability test
The recent Hugging Face breach was the work of several OpenAI models, the AI research company claimed in a blog post. Late last week, the company behind Hugging Face, a platform that enables users to share machine learning models and datasets, said some of its internal datasets had been accessed without authorization.

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls).

How attackers hosted a fake Claude download page on the claude.ai domain
A threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app and clicking a sponsored Bing ad.

Shadow AI is becoming enterprise security’s biggest blind spot
Artificial intelligence has moved from experimentation to everyday business operations with remarkable speed. Employees are using it to summarize documents, draft communications, analyze spreadsheets, write code, build automations, and create AI-powered workflows across nearly every business function. As AI is integrated into team members’ daily jobs, businesses are struggling to keep pace with governance, management practices, and organizational readiness.

More alerts are making your team slower, and an outcome-based SOC fixes that
In this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like PowerShell instead of custom malware. He shares a case where attackers called a help desk, reset a privileged cloud account, and exposed thousands of passwords in three minutes.

Building a defense in depth strategy for sensitive data
In this Help Net Security video, Venkata Pavan Kumar Gummadi, Professional Software Engineer at Broadridge, explains how to build a defense in depth strategy for protecting sensitive data.

Governing Al agents at scale: Lessons from the leaders who’ve done it
Enterprise AI leaders from ZoomInfo, Docusign and AppViewX share what it took to build AI Centers of Excellence and govern agent identities inside two companies operating at scale.

A forensic tool for backdoored code completions in AI assistants
Developers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick glance. Those tools learn from large collections of code, and some of that code can be tampered with before training starts. A poisoned example teaches a model to write insecure code when it sees a certain cue, and the flaw sits quietly until the right prompt sets it off.

Italy fines WINDTRE €1.7 million over security flaws behind two data breaches
Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE €1.7 million over “serious data security shortcomings” that let hackers breach its systems twice and exfiltrate personal data belonging to more than 365,000 customers.

Paidwork breach exposes sensitive data of 23 million users
Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets itself as a way to earn money through simple tasks like watching ads, testing apps, and completing surveys, with most jobs paying only a few cents at a time.

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel
Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from Group-IB discovered.

The Odyssey piracy scams surface hours after its theatrical debut
Christopher Nolan’s The Odyssey had barely reached theaters before scammers began targeting people searching for pirated copies, according to Malwarebytes. Within hours of the film’s release, researchers found two separate scams running on cloned piracy sites: fake browser warnings and Windows executables disguised as movie downloads.

Estée Lauder discloses data breach tied to Oracle EBS vulnerability
Cosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. The data taken varied from person to person. According to the notification, it included names, postal and email addresses, dates of birth, Social Security numbers, passport numbers, bank account numbers, health information, and employment records such as performance evaluations and payroll history.

Fake FBI agents target people who already got scammed
Scammers are impersonating FBI personnel who supposedly handle Internet Crime Complaint Center (IC3) complaints, using that disguise to deceive and revictimize people who already lost money once.

AI agents tricked into recommending malicious GitHub repositories
Roughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, according to Island.

Small teams are the heaviest users of AI coding agents
The pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On GitHub that somebody is usually one developer sitting alone with the diff, and the rest of the project never sees the code. Maliha Noushin Raida and Daqing Hou at Rochester Institute of Technology sorted 25,264 agentic pull requests by who reviewed them and who committed to them.

Police dismantle Kratos phishing platform behind 15,000 monthly campaigns
German and US law enforcement have dismantled the infrastructure behind Kratos, a notorious phishing-as-a-service (PhaaS) platform. Its alleged developer and administrator was arrested in Indonesia by local police.

AI models cheat on cybersecurity evaluations, then fail to admit it
Frontier AI models will take just about any route to finish a task, cheating included, according to new cybersecurity evaluations from the UK government’s AI Security Institute (AISI). AISI defines cheating as a model doing something outside the bounds of what a task allows, or breaking a stated rule outright, in order to reach the goal through a shortcut the task wasn’t designed to permit.

US seizes over 1,000 domains used for illegal World Cup 2026 streams
The US Department of Justice has seized more than 1,000 internet domains that streamed FIFA World Cup 2026 matches without a license. The seizures came in three waves over the course of the tournament. The first two rounds took down nearly 400 domains by the end of June, and two later rounds pushed the total past 1,000.

OpenAI Presence connects AI agents to enterprise data with built-in guardrails
OpenAI has introduced Presence, a product designed to help companies deploy AI agents that handle customer support and internal service requests across voice and chat. The company describes Presence as a deployment platform rather than a standalone model.

Swiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattack
Cybercriminal group Everest is demanding 10 million Swiss francs ($12.3 million) from Swiss rail vehicle manufacturer Stadler after breaching a data exchange platform shared with one of its suppliers through compromised credentials.

Months-long breach exposes South Korean diplomats’ personal data
South Korea’s Foreign Ministry has disclosed that attackers breached the Korea National Diplomatic Academy’s online education system, compromising personal data belonging to current and former ministry staff and diplomats stationed abroad.

Ransomware gangs go after EMEA healthcare’s supply chain
A ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage that can be just as bad. Flare researcher Assaf Morag analyzed ransomware leak-site activity tied to healthcare organizations in the EMEA region between 2024 and 2026, and found that ransomware groups are going after the entire healthcare supply chain.

Google gives developers an AI bug hunter that also writes patches
Google has launched a preview of CodeMender, an AI agent built to scan code for security flaws, confirm they are exploitable, and generate fixes for developers to review. The company describes it as a response to attackers who are already using AI to speed up their work, arguing that defenders need automation that moves at the same speed.

Russian hackers exploit unpatched Zimbra servers to steal emails
Russian state-backed hacker group Laundry Bear has been breaking into government and commercial networks for at least a year by exploiting a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform.

Meta takes on AI-generated accounts with free Facebook verification badge
Meta has introduced Facebook Verified, a free badge meant to show that a person behind a profile has completed identity verification through a selfie check. The company says the goal is to give users a signal that they are dealing with a person, not a bot or an AI-generated account, when browsing Marketplace listings, dating profiles, or Group conversations.

Nearly half of open-source AI projects never reach production
Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles as model capability improves.

Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security
ZoneAlarm Mobile Security is a security app from Check Point designed to protect mobile devices against phishing, malicious websites, unsafe networks, and fraudulent links. It is available for iPhone, iPad, Android, and can run on Apple silicon Macs through the App Store.

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform
Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project from Microsoft supplies that infrastructure in a package meant to run inside a private environment.

The Windows 10 hangover is becoming a security problem
Windows 11 now runs on 78.8% of Windows devices after Microsoft ended support for Windows 10 on 14 October 2025, according to Lansweeper. Windows 10 still accounts for 16.9% of devices and no longer receives security updates, leaving newly discovered vulnerabilities unpatched.

AI-generated reports push GNOME to shorten its disclosure window
Volunteer maintainers of open source projects now receive a steady flow of security vulnerability reports produced with AI tools. Many arrive with no mention that a language model helped write them. The volume has grown enough that GNOME is revising the rules it uses to track and disclose vulnerabilities across its projects.

Nobody was checking the drives that encrypt your laptop
A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG Opal2 standard. Milan Brož and three colleagues bought 38 of those drives and ran them through a test bench.

Open-source maintainers still work underfunded as sponsorship crosses $100 million
A maintainer patches a library late at night that ships inside thousands of products, without receiving payment. Sebastián Ramírez (tiangolo) builds tools that many Python projects depend on, while Caleb Porzio created Livewire and Alpine.js, widely used by web developers. That gap comes at a cost. Critical projects lose maintainers to salaried jobs, security fixes slow, and software supply chains become more fragile.

AWS wants GuardDuty to automate the first steps of threat investigations
Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time.

Cloud operations become the next big role for agentic AI
Companies are using agentic AI to manage growing application environments, automate routine tasks, and support decisions. Business and IT leaders increasingly see the technology as part of cloud application management, according to Unisys’ AI & Cloud Insights Report.

AI can’t fix cybersecurity’s hiring problem
Organizations are redefining cybersecurity roles through workforce frameworks and placing greater emphasis on verified skills as AI and new regulatory requirements change hiring. The SANS 2026 Cybersecurity Workforce Survey found demand for specialists in new roles more than doubled over the past year, alongside increased hiring for existing cybersecurity skills.

Security teams keep finding critical flaws after scheduled testing ends
Enterprise environments change between scheduled security assessments, leaving organizations with periods where new vulnerabilities can go undetected. Synack’s State of Continuous Security Validation report found that 95% of surveyed organizations identified high- or critical-severity vulnerabilities outside planned testing windows during the past year, with 42% encountering them at least once a month.

Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter
Google’s Gemini 3.5 Flash Cyber model finds, validates, and patches vulnerabilities before they can be exploited while helping mitigate broader misuse. It is part of a limited-access pilot program that will soon be available to governments and trusted partners through CodeMender, Google DeepMind’s AI coding agent, with broader access planned over time.

GitHub revamps bug bounty program with new VIP tier, payout changes
GitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. The changes will take effect on July 27, 2026. Reports submitted before that date will be honored under the previous bounty structure.

PyPI hardens package security with new upload restrictions
The Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s publishing tokens or release workflows are compromised.

Ransomware in 2026: More groups, more victims, no slowdown
Ransomware activity followed a recognizable pattern during the previous four years. Each year was defined by a dominant actor, its collapse, or a major supply chain incident. Black Kite’s 2026 Ransomware Report documents a more fragmented market, with multiple ransomware playbooks scaling at the same time.

The automotive software vulnerabilities hiding in your dashboard
Pop the hood on a new car and you won’t find much you can fix with a wrench. What you’ll find is software, and a lot of it. The screen in the dash probably runs Android or a flavor of Linux. The system watching the road for you might run QNX or VxWorks, the same kind of code that flies aircraft and runs factory floors.

Google’s newest sign-in method asks you to look at the camera
Google’s selfie video sign-in option verifies that an account owner is a real person and that the account wasn’t created or used by computer programs or bots for the purpose of abuse, such as spamming. It is not available for all regions, accounts, or devices.

Microsoft tightens Windows enterprise activation security
Microsoft is making Trusted Platform Module (TPM)-backed attestation a requirement for Windows Key Management Service (KMS), the on-premises service used for Windows volume activation, replacing the software-only trust model with hardware-backed verification to strengthen enterprise activation security.

Product Showcase: AppViewX Agent Identity Security
Agent Identity Security is a product within the AppViewX platform that enables zero-trust for AI agents by continuously discovering, monitoring, governing, and securing identities across their lifecycle.

Cybersecurity jobs available right now: July 21, 2026
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.

New infosec products of the week: July 24, 2026
Here’s a look at the most interesting products from the past week, featuring releases from Astelia, Druva, Swimlane, and ThreatDown.


from Help Net Security https://ift.tt/pMjGI3c