The Latest

Tanium has relaunched Tanium Security Operations to address AI-assisted attacks in which adversaries use legitimate administrative tools to blend into normal activity and spread across endpoints. The platform is designed to detect this behavior, support response across affected endpoints and help analysts investigate threats.

With AI, attackers no longer need malware that a scanner can catch. They sign in with stolen credentials and run the same administrative tools IT uses every day. To a security tool hunting for known-bad files, that activity looks like a normal workday. Catching that behavior means knowing what normal looks like on every endpoint and acting on all of them the moment something drifts. Tanium already does that job for IT teams. Tanium Security Operations turns that same foundation on the attacker, working alongside the SIEM and EDR tools teams already own.

“AI has changed who the attacker is and how fast they move. The next breach won’t look like malware. It will look like one of your own administrators,” said Harman Kaur, chief technology officer at Tanium. “We have spent years learning what normal looks like on every endpoint our customers run. Now we use that to catch what doesn’t belong and stop it everywhere at once. That is what security operations has to become in the AI era.”

Detection, response, and hunting as one continuous loop

Tanium Security Operations runs on the same platform and real-time data IT teams already use to manage every endpoint. With the relaunch, detection, response, and hunting are no longer separate steps handed from tool to tool. They run as one continuous loop.

Detection that looks for behavior, not just known-bad files. When attackers use the same tools as IT, a list of bad files will not catch them. New Endpoint Drift learns how each endpoint normally behaves and ranks the machines acting out of character, so hunters start where it matters. New Insights Engine replaces Tanium’s process injection detection with an engine built to catch attackers hiding inside trusted processes.

Response sized to the threat. Detection without action is just an alert queue. When an attack spreads across thousands of endpoints in minutes, one quarantine button is too blunt and too slow. Tanium runs a range of responses directly on the endpoint, from stopping a single process or collecting forensic evidence to isolating a host, on one machine or across the whole fleet at once. A new Federated SOC model lets separate security teams share one platform while each sets its own suppressions and automatic reactions, so one team’s rules never land on another team’s endpoints. People set the guardrails, and every automated action stays inside them.

Hunting for every analyst, not just a few experts. Most teams rarely hunt because it takes deep skill and days of work. Tanium Atlas changes that. An analyst asks a question in plain language, gets an answer from every endpoint in seconds, and acts on it in the same place. Hunt strategies written by Tanium threat hunters guide each step. Tanium Atlas also ranks the alert queue and recommends whether to dismiss, escalate, hunt, or contain each one, and new SecOps dashboards and templates give every team a place to start. With Tanium, hunting becomes a routine, repeatable workflow any analyst can run.

“The AI-fueled threat landscape has changed the dynamics of security operations,” said Dave Gruber, chief analyst at Omdia. “Speed is more important than ever before, as attack execution speeds out pace current security operations mechanisms and processes. Agentic capabilities can speed detection and response, but without access to near real-time telemetry and response, agentic SOC capabilities still lag attacker activities. Tanium’s approach of grounding detection and hunting in real-time endpoint state addresses one of the most persistent gaps in enterprise SOC architectures.”

For organizations that want experts on their side, Tanium HuntIQ pairs Tanium threat hunters with the same platform and AI. HuntIQ hunters work directly in customer environments to find threats, strengthen detections, and support incident response, and can build a hunt before a patch or CVE exists, as they did for the FalconFlank zero-day. What they learn feeds back into the platform, so every hunt that follows starts smarter.


from Help Net Security https://ift.tt/YmRFQxg

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of publication.

People are often unprepared for the amount of work a house requires. It doesn’t matter if it’s a new build or a creaking classic; unless they’ve got the cash to just hire out for every little project, new homeowners are going to need tools. That makes a basic tool set the perfect housewarming gift, and this one from Black+Decker is my go-to when a friend buys their first home. It has everything a DIY newbie needs, and at this price you can buy a couple to have on hand for future gifting needs.

The Black+Decker 20V MAX 68-Piece Kit has everything the new DIYer needs

A basic tool kit like this is a great idea for folks who don’t have a lot of experience doing small repairs and DIY jobs around the house because it has all the basics (including a durable bag to carry it all around in):

  • A basic 12oz hammer

  • An adjustable wrench

  • Needle-nose and slip-joint pliers

  • A ratcheting screwdriver with a full set of bits

  • One Phillips and one flathead screwdriver

  • A utility knife

  • A tape measure

Those are the basic hand tools anyone looking to do small jobs around the house needs. They’re basic, but decent quality, so they’ll last a long time. They can also be upgraded one piece at a time as people gain knowledge and skills.

This kit is special because it includes a power drill

What really sets this kit apart from others is that it’s one of the only decent-quality beginner tool sets that includes a power drill (as well as a battery and charger). Sure, Black+Decker is happy to hook newbies into their battery ecosystem, but a power drill is a game-changer when it comes to DIY stuff around the house. The kit includes all the basic drilling, spade, and hole saw bits you might need for basic work (as well as the screwdriver bits listed above), and includes a magnetic bit holder to prevent bit loss.

If you or your gift recipient develop your DIY skills, you’ll definitely wind up replacing most of this kit with better, more capable tools. But for a complete newcomer who has just completed the stress and complexity of buying their first property, this kit gets them set up to tackle basic maintenance right off the bat—and at 20% off, it's a great value.

Our Best Editor-Vetted Prime Day Deals Right Now
Deals are selected by our commerce team

from Lifehacker https://ift.tt/IuWTbvf

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of publication.

There's a reason the MacBook Pro is so expensive. Apple saves its most premium features for this product line—mini-LED displays, built-in fans, HDMI and SD ports, and, depending on the model, the most powerful chips. None of these comes cheap, and, after recent RAM-related price hikes, the MacBook Pro now starts at a steep $1,999. That's not the case during October Prime Day, however: Right now, you can take a decent chunk off many MacBook Pro models, and even more if you opt for one of Apple's M5 Pro or M5 Pro Max devices.

You can save $160 on the M5 MacBook Pro

Let's start with the standard M5 MacBook Pro. This uses a similar M5 chip to the one found in the MacBook Air, though the Pro does come with 10 GPU cores (that costs extra on the Air). Other than that, these are the same processors, running the same 16GB of RAM—though the M5 MacBook Pro comes with 1TB of storage standard. You also get most of the hardware perks of the other MacBook Pro devices, without venturing into $2,499 and up territory, including three USB-C ports, the HDMI and SD card ports, a 14.2-inch mini-LED display, and a 12MP FaceTime camera. Typically, that'd cost you $1,999. But on Amazon, you can pick this machine up today for $1,869.

Save $155 on the 14-inch M5 Pro MacBook Pro

This is a great price for this MacBook, but it's not the only savings you'll find on MacBook Pros this October Prime Day. If you upgrade to the M5 Pro MacBook Pro, you can save $155 off its retail price, bringing the machine down to $2,345 from $2,499. With this laptop, you get all the perks of the M5 MacBook Pro, but with the M5 Pro chip, which is much more powerful. This chip comes with a 15-core CPU and 16-core GPU, along with 24GB of RAM and a 1TB SSD. It also supports Wi-Fi 7, while the M5 MacBook Pro only supports Wi-Fi 6E.

Amazon also has the M5 Pro MacBook Pro with an 18-core CPU and 20-core GPU $150 off. But the biggest discounts are on Apple's most expensive 14-inch MacBook Pros. If you're in the market for a souped-up M5 Pro model, or one of Apple's M5 Max configurations, Amazon has huge discounts:

Save $150 on the 16-inch M5 Pro MacBook Pro

Similarly, Amazon has big discounts on the 16-inch version of these MacBook Pros. The best option for most people in this category is going to be the base model 16-inch, which comes with the M5 Pro with an 18-core CPU and 20-core GPU, as well as 24GB of RAM and a 1TB SSD.

But as with the 14-inch MacBook Pros, the biggest deals are on the most expensive 16-inch Pros. Here's how much you can save:

October Prime Day FAQ

When is Prime Day in October?

Amazon Prime Day is an annual event held in June or July. Amazon's October Prime Day event, known as Prime Big Deal Days, is a two-day sale that starts Oct. 6 and ends on Oct. 7.

What goes on sale during October Prime Day?

Since Prime Big Deal Days happens in the fall, you're likely to see more deals on gaming and indoor gym equipment. Amazon has already announced some of the 35 categories that will be on sale, including beauty, tech, kitchen, fashion, and home. Some brands Amazon has already mentioned are: Shark, Princess Polly, Soundcore by Anker, UGG, Nest New York, Sony, Tarte, Adidas, and Barefoot Dreams.

Is Prime Day once a year?

Prime Day happens every summer. Prime Big Deal Days (or October Prime Day) happens every October. Amazon's Big Spring Sale happens every spring.

Our Best Editor-Vetted Prime Day Deals Right Now
Deals are selected by our commerce team

from Lifehacker https://ift.tt/c5UMxSi

We may earn a commission from links on this page.

A new Google wearable may be on the way, and leaked pictures suggest it may be a fitness band with a screen, a successor to the Fitbit Charge 6. Android Headlines reports that the new device will be called the Fitbit Edge. 

Earlier this year, Google ran ads on Reddit that seemed to show a new fitness band alongside Pixel watches and phones. In a post titled “Um so what the hell is that??,” redditors debated whether the unfamiliar wearable was an accidental leak of a yet-unreleased device, or just an AI hallucination. After all, if you asked an AI to create a hybrid of a Fitbit and a Pixel Watch, it would look more or less like what was in the picture.

What rumors say about the new "Fitbit Edge"

The leaked photos appearing at Android Headlines look like the device from the ad. It has an oval screen, only about as wide as the wristband and taller than it is wide. The rounded edges and the style of watch band match aesthetically with Pixel Watches, while the overall form factor—a tall screen set into a thin wristband—fits the design of the old Fitbit Charge 6. 

According to spec sheets that were reportedly also included in the leak, the device will have GPS, an altimeter, and a seven-day battery life. That's the same battery life as the Charge 6, which had GPS but no altimeter. The new device is said to work with both iOS and Android, as the Fitbit Air does, rather than being Android-only like the Pixel Watch. The rumors do not include a price, a release date, or a full list of features.

What this means, if true

If it weren’t for the earlier ad—the one that many thought was a hallucination—I probably wouldn’t have expected Google to release a device like this at all. Its last fitness tracker with a screen was the Fitbit Charge 6 in 2023. The Fitbit Air makes sense since smart bands are having a moment, and the Fitbit Air is a really well-executed one. But I wasn’t sure if Google was interested in continuing the Fitbit line beyond that one device. 

It’s a good idea, I think. Small trackers are easy to wear (and forget you’re wearing), but sometimes you just want to be able to see the time on your wrist. If Google is smart, they’ll allow you to swap seamlessly between the new device and the screenless Fitbit Air. (Currently, you can pair one Pixel Watch and one Fitbit to your phone, but you can’t pair two different models of Fitbit.) 

I’m excited to see what Google has in mind for the new device, assuming the rumors are true about its size, shape, and capabilities. I was disappointed by all the things the Charge 6 couldn’t do, and I hope the new Fitbit doesn’t repeat those mistakes. For example, the Charge 6 can control the music that’s playing on your phone, but only if you pay for a YouTube Music subscription. Most fitness watches—including Garmin, Coros, and Suunto watches I’ve tried—will simply give you controls for whatever is playing on your phone, no matter what app it comes from. 

If it’s true that the new device also has its own GPS and altimeter, that’s also exciting—but I’m skeptical that Google will be able to stuff in high-quality versions of those components in the space available. The Charge 6, I found, had trouble getting a good GPS reading and a good heart rate reading at the same time. But the Fitbit Air is surprisingly small and capable for its size, so I’m looking forward to seeing what the new device might be able to do.


from Lifehacker https://ift.tt/Batq7jS

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of publication.

The October Prime Day sale is officially here, and the best deals on headphones, fitness tech, and other essentials from premium brands are popping up all over Amazon. Right now, these Sony LinkBuds Clip Open Earbuds are down to $158 (originally $229.99), an all-time low according to price tracking tools.

One of the top Prime Day earbuds deals for people who dislike conventional in-ear buds, the Sony LinkBuds Clip gets praise in PCMag for crystal-clear audio and long-lasting battery life. With a lightweight clip-on design that sits outside the ear canal and lets you hear background noise like traffic or announcements, they’re a useful essential for errand runs, busy workdays, dog walks, and other settings where you don’t want total noise cancellation. An IPX4 rating can handle sweat and light rain, while multipoint pairing lets you stay connected to devices without constant re-pairing. 

The earbuds last up to 37 hours and offer nine hours of continuous use per charge, far more than the AirPods 4 with ANC, which last five hours with ANC off and four with it on. A three-minute charge provides around an hour of playback. The app makes the sound heavily customizable, and while sound quality is robust and impressive, it’s not quite as bass-forward as in-ear buds.

Though they can’t overcome the limitations most open-ear designs face, the Sony LinkBuds Clip Open Earbuds are a reliable, long-lasting option for settings where you need situational awareness.

October Prime Day FAQs

How does Prime Day work?

Prime Day lets Prime Members shop online for thousands of products with big discounts. It only lasts two days, so make sure you check out everything we know about the sale before it starts.

Is Prime Day only for Prime Members?

Yes, you will need to be a Prime Member to shop the exclusive sales during Amazon's Prime Big Deal Days. Prime membership starts at $14.99 per month.

What goes on sale on Prime Day?

Since Prime Big Deal Days happens in the fall, you're likely to see more deals on gaming and indoor gym equipment. Amazon has already announced some of the 35 categories that will be on sale, including beauty, tech, kitchen, fashion, and home. Some brands Amazon has already mentioned are: Shark, Princess Polly, Soundcore by Anker, UGG, Nest New York, Sony, Tarte, Adidas, and Barefoot Dreams.

Our Best Editor-Vetted Tech Deals Right Now
Deals are selected by our commerce team

from Lifehacker https://ift.tt/eGNknmJ

CISA has added another Citrix NetScaler vulnerability to its Known Exploited Vulnerabilities catalog on Sunday: CVE-2026-88779, a memory overflow bug that may cripple vulnerable NetScaler ADCs and Gateways.

“Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service. If the condition is triggered repeatedly, the service may remain unavailable,” the vendor stated.

“Our analysis indicates that this issue affects service availability, and we have not identified an impact on the integrity of customer data.”

Attacks observed after patching spree

Bishop Fox and watchTowr researchers have been credited with flagging CVE-2026-88779, and the latter have reproduced it, but have yet to share technical details.

Reddit users have been reporting that their organizations’ NetScaler appliances have been hit by crashes and reboots after they’ve upgraded to patch eight vulnerabilities, including two actively exploited zero-days: CVE-2026-88771 and CVE-2026-88772.

Apparently, the attackers are trying to exploit the flaw to download and run a script to install webshells.

Security researcher Kevin Beaumont reported attacks on his honeypots, from multiple IP addresses, and said he found a downloaded malware binary on one of them.

A threat hunter working at insurance company Geico has shared a SIGMA rule for identifying probing/scanning and exploitation attempts, but it’s still unclear if exploitation of this vulnerability can lead to successful remote code execution.

Affected versions and mitigation

The following supported NetScaler versions are affected by CVE-2026-88779:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 before 14.1-73.41
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 before 13.1-64.28
  • Citrix NetScaler ADC FIPS before 14.1-73.41 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP before 13.1-37.282

CVE-2026-88779 can be exploited on vulnerable on-prem NetScaler deployments only if the appliance has been configured to use SAML authentication (either as a service provider or an identity provider) in conjunction with Gateway or AAA functionality.

Citrix advised customers to upgrade to a fixed version and has pushed out signatures, usable via the Global Deny List feature, to reduce exposure while they plan the upgrade. The signatures should block access from known malicious IP addresses.

“Citrix provides an indicator of compromise script through NetScaler Console to check affected appliances for signs of compromise. Citrix notes that the latest script version can report a false positive about suspicious nobody processes even when it finds no compromise, so administrators should review results carefully and preserve evidence before applying the update,” watchTowr advised.

CISA has ordered US federal civilian agencies to address the vulnerability by October 7 and to check for compromise.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!


from Help Net Security https://ift.tt/sPfFaUy

Your iPhone 18 Pro Max can do a lot. It has a variable aperture that lets you control the amount of light that hits the camera sensor; it can charge up to 50% of its battery in 15 minutes (with the right adapter, of course); and it can run all of Apple's latest AI features, thanks to the new A20 processor. But the 18 Pro Max is still, above all, a phone. If it can't connect to the cellular network, you no longer have an iPhone, but a glorified iPod touch.

Unfortunately, that's the situation some iPhone 18 Pro Max users find themselves in. Despite being "the best" iPhone Apple has ever made, Apple confirmed that a "small number" of 18 Pro Max units—specifically on the AT&T carrier network—can no longer connect to cellular service, with the devices only displaying an "SOS" icon at the top of their screens. That's a pretty glaring issue: Without cellular service, you'll need a wifi connection to use any apps or features that require the internet and you'll lose the ability to make calls over cellular entirely. It's so bad that some users may not even be able to call 911.

What if my iPhone 18 Pro Max can connect to cellular service right now?

If your iPhone 18 Pro Max has the ability to connect to cellular service, that doesn't mean you're in the clear. Just because there's nothing wrong with your unit yet, you can still be affected by the glitch, and you'll need to install the latest update, iOS 27.0.1, as well as the latest carrier update from AT&T, to ensure your 18 Pro Max won't be affected by these mysterious cellular issues in the future. That's what Apple told 9to5Mac in the following statement: “We have identified an issue affecting a small number of iPhone 18 Pro Max users on the AT&T network that may cause a device to lose service and be unable to make calls. We released iOS 27.0.1 earlier this week and strongly encourage all iPhone 18 Pro Max users to update now, and are also issuing a carrier settings update today. These updates together are meant to help prevent this issue from occurring.”

While you can always install iOS 27.0.1 from Settings > General> Software Update, Apple says that the carrier update will install on its own at some point over the next 14 days. However, I'd advise manually installing it by heading to Settings > General > About. There won't be any confirmation that the carrier update installs, but rest assured, this process will ensure that it has.

What if my iPhone 18 Pro Max cannot connect to cellular?

Unfortunately, if your iPhone is already experiencing issues connecting to cellular service, there is no fix. The updates above only help with prevention; they cannot patch an iPhone 18 Pro Max that already can't reach the network. Unfortunately, the only solution is to swap out the unit with either Apple or AT&T. The good news is your store will make the trade for you free of charge, as it is a hardware defect covered under warranty.

It's not clear why this issue is only affecting iPhone 18 Pro Maxes and not the standard iPhone 18 Pro, nor is it evident why only AT&T devices appear to be experiencing it. A possible point of failure: The iPhone 18 Pro Max uses a Qualcomm modem, while the iPhone 18 Pro uses Apple's proprietary C2 modem. Perhaps there's some flaw with Qualcomm's hardware specifically on the AT&T network.

That's not to say the launch of the iPhone 18 Pro has been otherwise drama-free—far from it. As it happens, the 18 Pro (along with the 18 Pro Max) has also experienced three other public-facing issues since Apple launched the devices last month. First, there was an issue with phones randomly rebooting following a failed Face ID attempt; next, some users noticed their devices emitting a cracking or popping sound through the speakers. Finally, some units also appear to be losing their exterior color. If you've upgraded, I hope your fancy new iPhone is doing well.


from Lifehacker https://ift.tt/IUjaPNQ