The Latest

Deepfakes have made one of our oldest assumptions unreliable: that you can trust a familiar face or voice. While the industry focuses mainly on building “in-line detection tools” that try to spot the fake, BlackCloak, the leader in Digital Executive Protection (DEP), built Impersonation Protection to focus on validating the authenticity of communications.

BlackCloak deepfake protection

Circle of trust functionality is the most significant expansion of that capability to date — giving executives and high-profile individuals a new way to confirm the authenticity of communications from their trusted contacts.

Research commissioned by BlackCloak from the Ponemon Institute found that 42% of respondents say their executives and board members have already been targeted at least once by a fake image or video, and 59% say deepfake attacks are very or highly difficult to detect. Generative AI has lowered the technical barrier for attackers, and traditional in-line detection cannot cover every channel an executive actually uses such as personal phones, FaceTime, the WhatsApp thread, the family group text chat. Attackers know this, and they aim for the personal lives of these executives on the channels corporate controls cannot reach.

Industry analysts are raising similar concerns around disinformation security.

According to a Gartner Report, “Examples of disinformation attacks include targeting employees with social engineering using deepfakes or propagating malicious narratives online via fake websites, deepfaked media and impersonated social media profiles to phish customers or manipulate financials. Evidence shows the urgency: 36% of respondents to a 2025 Gartner survey said their organization had experienced social engineering with a deepfake in a video call with an employee. Without clear ownership and cross-functional effort, fragmented responses will leave organizations vulnerable to industrial attacks targeting reputation and episodic attacks targeting individuals.”

Gartner defines episodic attacks as “individual attacks at a moment in time, often with a narrow goal — for example, to trick an employee into transferring funds or specifically harm the reputation of an executive.” We think this is precisely the category BlackCloak’s Impersonation Protection is built to address: the single, high-stakes moment when an executive, an assistant, or a family member must decide whether the person on the other end is real.

“You can’t spot every fake, but you can confirm the authenticity of communications with your trusted circle,” said Dr. Chris Pierson, Founder and CEO of BlackCloak. “Believing under some false pretense that cybercriminals will only target “official corporate” modes of communication as opposed to just picking up the phone and calling or texting is the root cause for incorrect assumptions and control ineffectiveness. We are not in the detection arms race. Detection asks whether the content is fake. Impersonation Protection with the expanded feature, circle of trust, answers the question that actually matters: is the person communicating with me now really that member of my circle who is already trusted and on the BlackCloak platform? By anchoring trust to the person, on a channel the attacker doesn’t control, we neutralize impersonation, deepfake, and social engineering attacks at the moment of decision.”

How impersonation protection works

Already protecting BlackCloak members today, Impersonation Protection enables members to authenticate phone calls, video meetings, emails, WhatsApp and Slack messages, texts, and other communications in real time. BlackCloak moves the security control out of the potentially compromised channel, and puts the focus on the basis of trust between the two parties. It starts with a simple question – who really sent me this message? From that starting point, Impersonation Protection provides users with a secure way to ensure that the message originated from a trusted source.

The expanded capability, introduced with circle of trust as part of Impersonation Protection, extends this functionality beyond BlackCloak’s membership. Members can now invite the people they trust most: family members, wealth advisors, lawyers, executive assistants, caregivers, and household staff, into their own circle of trust. Invited contacts download a free version of the BlackCloak app, register their device, and can then both send and receive authentication requests with the member.

“An executive’s trust network doesn’t stop at the corporate directory, and neither do the attackers,” said Matt Covington, SVP of Product at BlackCloak. “The assistant approving a wire, the advisor moving funds, the caregiver picking up a child, these are the relationships threat actors exploit. This enhancement brings every one of them inside the same authenticated perimeter.”

Capabilities of Impersonation Protection with circle of trust

  • Anchored to the person and their device, not the message. The trusted contact responds to an authentication request at the moment of decision, on a channel the attacker doesn’t control.
  • Built on the basis of trust. Confirmation happens separately from the potentially compromised communication channel.
  • Privacy-first validation. Biometric checks can use the device’s built-in authentication features; BlackCloak never collects or stores biometric data.
  • A record on both sides. Confirmations are preserved for both parties, creating an audit trail of authenticated communications.

Availability

Impersonation Protection is available now as an add-on to the BlackCloak platform. The circle of trust enhancement will be included as part of Impersonation Protection and generally available to members in early fall. Both will be demonstrated live at Black Hat USA 2026, August 5–6 at Mandalay Bay, Booth #5926. Go here to request a meeting.


from Help Net Security https://ift.tt/twdhAEv

We may earn a commission from links on this page.

A wildly toxic eight-year relationship doesn't sound like much fun—but better a fictional couple than me. The juicy, addictive Tell Me Lies (streaming on Hulu and Disney+) ended this year after three seasons, finally revealing the full story that unfolded behind the wedding that kicked off the very first episode. If you're seeking more salacious drama, here are 10 other shows that dig into similarly, uhm, complicated, messy relationships.

You (2018 – 2025)

You want a toxic relationship? How about a string of them involving a hot serial killer? Penn Badgley plays Joe Goldberg, who, in the first season, develops an extreme romantic obsession with Elizabeth Lail's struggling MFA student Guinevere Beck. He'll do whatever it takes to clear a path to lasting love—like, literally anything. The show concluded after five seasons of toxic, obsessive relationships that were just about as addictive for audiences as they were for Joe. Stream You on Netflix.


Big Little Lies (2017 – )

These rich ladies are going through it, and just because they've got beautiful homes and nice clothes doesn't mean they're not getting the full treatment. As the series opens, five women (played by Nicole Kidman, Reese Witherspoon, Shailene Woodley, Laura Dern, and Zoë Kravitz) become involved in a murder investigation connected to a school fundraiser that threatens to bring all of their private dirt out into the open—and there are secrets aplenty to uncover. Toxic relationships come into the light, and others become toxic under pressure. In their social strata, any threat to the status quo can lead to big drama. Stream Big Little Lies on HBO Max.


Normal People (2020)

Less overtly toxic than Tell Me Lies, this is nonetheless a show about a thoroughly complicated relationship over time, and no less compelling. This one comes from Sally Rooney's smart, bestselling novel about the steamy coming-of-age romance between Marianne (Daisy Edgar-Jones) and Connell (Paul Mescal), characters and actors with impressive chemistry. She's rich but lonely; he's popular but the son of a housekeeper. As time goes on and their roles start to shift, life and love only grow more complicated. The plot isn't groundbreaking, but its uncommon intelligence and a frankness about sex and sexual violence set it apart. Stream Normal People on Hulu.


Bad Sisters (2022 – 2024)

A pitch-perfect (and pitch-dark) comedy, the Irish import Bad Sisters picked up several well-deserved Emmy nominations in its first year. Writer and co-creator Sharon Horgan leads the cast as Eva Garvey, oldest of five sisters, including Grace (Anne-Marie Duff), who's married to John Paul, an abusive and isolating husband. When the dude winds up dead under rather suspicious circumstances, down-on-his-luck insurance investigator Tom (Brian Gleeson) starts poking his nose into things. We know the sisters definitely wanted John Paul dead, but did they actually do the deed? Tom's family business will go under if he has to pay out on the life insurance policy, so he's motivated to pin the (potential) crime on at least one of the women. This isn't so much about a toxic romance as it is about toxic...well, everything. Stream Bad Sisters on Apple TV.


The Affair (2014 – 2019)

The title's affair impressively spins out over the course of five seasons via a clever, Rashōmon-like structure that has us constantly questioning our perspective as viewers. Starring Dominic West, Ruth Wilson, Maura Tierney, and Joshua Jackson, the show explores the extramarital relationship between West's Noah Solloway and Wilson's Alison Bailey, rotating between the points-of-view of the four leads to constantly put new light on events, while also suggesting that memories are ever-shifting and often self-aggrandizing. Stream The Affair on Paramount+ and Prime Video.


Nevertheless (2021)

A messy relationship sits at the center of this addictive, if also slightly messy, South Korean miniseries. Art student Na-bi (Han So-hee) is coming off a borderline abusive relationship and no longer believes in love, which is not to say that she's entirely lost interest in sex. Convenient, then, that she meets flirty fellow student Jae-eon (Song Kang), similarly disinterested in anything long-term—at least initially. With impressive chemistry between the leads and a strong supporting cast of characters with their own issues, the show solidly depicts a modern situationship that slowly turns romantic despite its leads' best intentions. Stream Nevertheless on Netflix.


Sex/Life (2021 – 2023)

Sarah Shahi is Billie Connelly, a married mother of two in a quiet, wealthy suburb—and a woman with a rather wild past she's keen to reexamine. She starts daydreaming about her hot and horny relationship with an ex-boyfriend, Brad, writing down the sexy details, which her husband soon finds. And then it turns out that her bestie is sleeping with Brad, which puts her back in touch with the object of her fantasies. It's a show that asks: Do you stick with your safe, happy family or opt for the very extra good sex? Stream Sex/Life on Netflix.


Behind Her Eyes (2021)

Good luck finding a twisty relationship drama that goes harder than Behind Her Eyes, a show that builds to a climax so cuckoo bananas that you'll either applaud its audacity or cackle at its outrageousness. Louise (Simona Brown) is a single mother who starts an affair with her boss—and his wife—and then gets involved with his former mistress in the wake of a mysterious death. And then it gets really wild. Stream Behind Her Eyes on Netflix.


Forever (2025 – )

Based on your affection for Tell Me Lies, I'm guessing you're here for the drama—the truly fucked up relationships best enjoyed from the comfort of your living room (hey, no judgements!). In case you're looking for something a little less twisty and a little more sincere (and just as addictive), you might turn to Judy Blume. This adaptation of her widely banned 1975 novel updates the setting to current-ish day Los Angeles, and expands its exploration of the complexities of teen love and sex to include the challenges of being young, exceptional, and Black in 2020s America. Keisha Clark (Lovie Simone) attends a predominantly Black private school and is working toward a track scholarship at Howard, while Justin Edwards (Michael Cooper Jr.) goes to school with white kids and is on his parents' track to go to Northeastern, ideally on a basketball scholarship. Forever follows their budding romance in a way that feels real and compelling—it's one of the best young relationship dramas streaming. Stream Forever on Netflix.


You're the Worst (2014 – 2019)

A rom-com so dark and messy that it very nearly misses the cut-off for the genre, functioning simultaneously as a satire and a very believable relationship drama. Jimmy Shive-Overly (Chris Greer) is an entirely self-absorbed writer; Gretchen Cutler (Aya Cash) is a publicist/cynical chaos goblin. They have what feels like a one-night stand after a wedding, but find themselves drawn to each other, in large part because they're similarly self-sabotaging. Rather than a long will-they/won't-they build up, the two immediately dive into a wildly dysfunctional relationship; the question isn't "will they get together?" so much as "how can they possibly make this work?" Stream You're the Worst on Hulu.


from Lifehacker https://ift.tt/8Q73LRw

We may earn a commission from links on this page.

No one dishes out shocking twists and emotionally powerful moments like Harlan Coben, and his partnership with Netflix just keeps delivering stories you can’t help but devour in one sitting. I Will Find You, starring Sam Worthington and Britt Lower, is no exception: The story of a father risking everything to prove he didn’t commit an unspeakable crime while searching for the son he thought lost forever is the sort of show you hop online immediately after the credits roll to see what people are saying. If you’ve already watched the series that give the same vibe and want more innocent people trying to get their lives back, unpredictable plot swerves, and emotionally charged stories of hard-won justice, look no further than 1993’s The Fugitive.

Why you should watch "The Fugitive" after "I Will Find You"

The Fugitive was a massive hit in 1993. Based on a 1960s television series (also called The Fugitive) that was itself a national phenomenon, it’s the story of Dr. Richard Kimble (Harrison Ford), who is convicted of the brutal murder of his wife, Helen (Sela Ward), despite his claims of witnessing a one-armed man committing the crime. When the bus transporting him to prison crashes, Kimble escapes and launches a desperate campaign to prove his innocence, identify the murderer, and evade the dogged pursuit of U.S. Marshal Samuel Gerard (Tommy Lee Jones) and his team.

The Fugitive scratches the precise innocent-man-on-the-run itch as I Will Find You, following Kimble as he uses his medical training and survival instincts to avoid capture while taking enormous risks. He poses as a janitor at a local hospital in order to conduct research on men with prosthetic arms and is almost caught several times by the smart and experienced Gerard (who famously tells Kimble that he doesn’t care when Kimble protests his innocence).

While the film doesn’t have the bonkers twists that Harlan Coben came up with for I Will Find You, there are plenty of unpredictable plot swerves as Kimble unravels a conspiracy that hits closer to home than he expects. Just like the Netflix series, the villain has violently self-serving motives, and the true story of what happened is a surprising reveal. And if your favorite part of I Will Find You was the interaction between father-daughter FBI agents Max Williams (Chi McBride) and Sarah Greer (Logan Browning) as they pursue David, you’ll absolutely love Sam Gerard and his team as they bicker, joke, and follow the trail with absolute dedication to their jobs.

Bottom line: The Fugitive is a big-budget, slightly less shocking Harrison Ford blockbuster that every fan of I Will Find You will love. You can rent The Fugitive on Prime Video.

More movies

Still craving twisty thrillers about innocent folks searching desperately for the truth? Here are a few more brilliant movies to check out.

Primal Fear (1996)

You want more absolutely mind-blowing twists? Primal Fear has one of the most brilliant swerves in film history. Edward Norton’s film debut sees him playing Aaron Luke Stampler, a stuttering, shy altar boy accused of viciously murdering the beloved Archbishop Rushman. Vain, publicity-seeking attorney Martin Vail (Richard Gere) takes Aaron’s case, believing the weak, forgetful Stampler incapable of such atrocities—but the twisty story builds to one of the all-time great reveals, a scene that made Norton a star overnight. Stream Primal Fear on Fubo or Kanopy, or rent it on Prime Video.

Gone Girl (2014)

Was it the complexity of the setup that hooked you in I Will Find You? Gone Girl takes that to the next level. Based on Gillian Flynn’s smash novel, the story begins when Nick Dunne (Ben Affleck) comes home to find his wife, Amy (Rosamund Pike), is missing. The clues at the scene don’t look great for Nick, and as the sordid truth of his marriage emerges, things look worse—but nothing is exactly what it seems in this taut, clever mystery. If you were fascinated by the effort put into painting David as a heartless killer, you should know that Gone Girl takes that to the next level. Rent Gone Girl on Prime Video.

The Next Three Days (2010)

There’s something absolutely gripping about a story focused on an innocent person’s life ruined by a false accusation. The Next Three Days is a tense thrill ride based on that premise: John and Lara Brennan (Russel Crowe and Elizabeth Banks) are happily married with a young son. When Lara’s boss is murdered after Lara had an ugly, public confrontation with him, she’s convicted of his murder. As time passes and John can see her giving up all hope, he launches a desperate plot to break her out of prison and reclaim their lives. If you rooted for David to prove his innocence, you’ll root for John and Lara in the same way. Rent The Next Three Days on Prime Video.

Double Jeopardy (1999)

Part of the thrill of I Will Find You is the slow, twisty route to justice—to finding the truth and punishing the truly guilty. That’s where Double Jeopardy lives. Ashley Judd stars as Elizabeth Parsons, who is convicted of murdering her husband, Nick (Bruce Greenwood), after she’s found with a bloody knife on their boat, his body presumably swept into the ocean. She loses custody of their son and despairs—but she eventually discovers that Nick faked his death and framed her for the murder. Her life becomes consumed with the need to reclaim her son and—when she realizes she cannot be charged with the same murder twice—to get a measure of revenge. Stream Double Jeopardy on Kanopy or rent it on Prime Video.

The Shawshank Redemption (1994)

One of the all-time classics in the “wronged person serving time” genre, The Shawshank Redemption is simultaneously an inspiring story of friendship, a stirring tale of surviving in the face of horrific loss and injustice, and one of the greatest twisty stories of all time. Its steady pacing and careful characterization let you really get to know the wrongly convicted man at its core, and the ending lets you appreciate how resolute and determined he was while experiencing the worst horrors a human can imagine. Rent The Shawshank Redemption on Prime Video.


from Lifehacker https://ift.tt/uX8CRfw

NVIDIA and a group of tech companies have formed an alliance to promote the use of open AI models in cybersecurity, days after OpenAI disclosed that one of its own AI models breached Hugging Face’s systems during an internal security evaluation.

The new group, called the Open Secure AI Alliance, builds on work already underway at the Linux Foundation’s Akrites initiative and the Open Source Security Foundation (OpenSSF).

“Open models, like any powerful technology, can be misused — including through attempts to weaken safeguards or repurpose capabilities for cyber attacks — but those risks are not unique to open systems, and they must be managed wherever advanced AI is deployed,” Nvidia said in a statement.

Among the 27 founding members are Microsoft, Dell Technologies, the Linux Foundation, and NVIDIA itself, alongside companies including Cisco, CrowdStrike, IBM, Palo Alto Networks, Red Hat, and Hugging Face.

OPIS

(Source: NVIDIA)

The Hugging Face incident

“The recent Hugging Face security incident delivered a clear reminder: cyber defenders need open, frontier agentic systems for self-defense,” Nvidia wrote.

“When closed AI tools — unable to distinguish attackers from defenders — blocked essential forensic analysis, Hugging Face ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the intrusion,” the company added.

Hugging Face disclosed the incident on July 16, noting it had identified unauthorized access to internal datasets and service credentials earlier that same week.

The company traced the entry point to a malicious dataset that abused two code-execution paths in its data processing pipeline. That allowed an intruder to execute code on a processing worker, escalate privileges, and move into several internal clusters. At the time, Hugging Face attributed the campaign to an autonomous agent framework of unknown origin.

Last week, OpenAI confirmed the incident was caused by its own AI models during an internal evaluation of their exploitation capabilities.

“That incident showed a practical truth: when defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most,” Nvidia noted.

A message to regulators

The alliance argues that AI security should not depend on a handful of closed systems. Instead, it wants defenders, including companies and governments protecting their own infrastructure, to have access to open models, agent frameworks, and tools they can inspect, modify, and run on their own infrastructure.

“The age of AI agents can be one of resilience and shared security. With the right choices, open secure AI systems can give defenders the tools they need, strengthen competition, extend technological leadership and ensure that the safety and security of this extraordinary technology are built in the open for everyone,” Nvidia concluded.


from Help Net Security https://ift.tt/mo7Lh12

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of publication.

If you've been patiently waiting for the right moment to pull the trigger on the best Nintendo Switch 2 bundle deal like I have, this is the part where your patience gets rewarded. Woot is selling a refurbished Nintendo Switch 2 Mario Kart World Bundle for $419. That's $80 less than the retail price for a new bundle and arguably better than the deal they had in June, as long as you don't mind a refurbished unit.

This bundle deal is a great opportunity when you consider the console by itself (without the bundle) will increase to $499.99 come Sept. 1. Since we're about a month away from that date, this could very well be the last great opportunity to buy the console for its lowest price.

The new console is an upgrade in every way, as you can read in our full review of the Nintendo Switch 2. The ergonomics and design have improved, making it much better to hold and look at. The battery life has also improved, now with about 180 minutes of handheld playtime before the juice runs out.

A big plus is that the Switch 2 is backwards-compatible: You can play your old Switch games on it. Some Switch games have the ability to upgrade to the Switch 2 Edition by buying that game's upgrade pack. This is especially worth it for games like The Legend of Zelda: Tears of the Kingdom, which will look better on the Switch 2.

There aren't many Switch 2 games out at the moment, but there are some classic Nintendo games to keep you busy until the library expands, like Donkey Kong Bananza, Kirby Air Riders, and Hyrule Warriors: Age of Imprisonment. If you already own a Switch 2, check out our Top 10 Hacks to get the most out of your device.


from Lifehacker https://ift.tt/50VIAgX

In this Help Net Security video, Joel Moses, VP, Strategic Engineering at F5, explains how attackers use identity instead of breaking through it. He walks through MFA fatigue, session token theft, and consent given to malicious applications, using the 2022 Uber breach as an example. He also covers how cloud and on-premises trust relationships give attackers a path between environments. Moses suggests number matching, FIDO2 keys, periodic reviews of third party application access, and watching … More

The post What the identity attack surface looks like when trust becomes the target appeared first on Help Net Security.


from Help Net Security https://ift.tt/3CPjkZE

An automated update tool watches a package registry, catches a new release the moment it publishes, and opens a pull request for your team. That is the job it was built to do. In September 2025, that speed cut the wrong way. An attacker phished one npm maintainer’s credentials and shipped poisoned versions of chalk, debug, and about a dozen other packages. Together those packages are downloaded more than 2 billion times a week, and the injected code rewrote cryptocurrency wallet addresses inside any browser app that loaded it.

dependabot cooldown

The bad versions were live for about two hours before the community caught them and npm pulled them. Two hours is a fast cleanup. It is also enough time for an update tool to see the release, file a pull request, and set the malicious code in front of your reviewers.

GitHub’s Dependabot now waits. For non-security version bumps, it holds off at least three days after a release publishes before opening a pull request. The cooldown option in dependabot.yml controls the window, so a project can dial it up or down.

Two kinds of updates, one delay

Dependabot does two separate jobs. Security updates answer a known vulnerability: an advisory lands for a package you use, and Dependabot opens a pull request to move you onto the patched version. Version updates keep your dependencies current as new releases ship.

The three-day delay touches version updates alone. Security updates still open the moment an advisory drops, since holding one back would sit on a fix for a flaw the public already knows about.

Malware that lives for hours

A poisoned build of a popular package tends to have a short life. It publishes, spreads to whatever installs it, and gets caught, usually inside a few hours. Compromised versions of Solana web3.js, Axios, and ua-parser-js each followed that arc.

GitHub’s Advisory Database logged more than 6,500 npm malware advisories in the year ending May 2026.

That works out to about 18 freshly cataloged malicious npm packages a day. A cooldown keeps you out of that opening window and lets a release collect some scrutiny before it reaches you.

Why three days

A review of 21 widely reported supply chain incidents over the past several years found the same rhythm every time. The malicious version publishes, and within hours someone catches it and it comes down. A short waiting period would have filtered most of those publishes before anyone installed them.

Three days pushes you past the window where most of these attacks live. It also avoids holding your dependencies back longer than the job needs. Other tools in the community have settled on the same figure, which keeps behavior consistent for developers moving between them.

The attacks a cooldown misses

A cooldown assumes the malware moves fast. Carlin Cherry, a GitHub product manager who works on Dependabot, names the ones it misses: “It does little against attacks that play a longer game, including backdoors planted in releases and left dormant, maintainer sabotage, or a compromised build system.”

So a cooldown earns a place as one layer among several. Pin dependencies with lockfiles. Turn off install scripts in CI where you can. Scope the tokens in your build pipelines, and review updates before they merge.

The delay is on by default, and a project can tune the window or set different delays for trusted internal packages and public registries. It removes one fast, common path onto your machines. The rest of the supply chain still needs watching.


from Help Net Security https://ift.tt/ZQMgRv8