The Latest

Bitsight access to a broad risk dataset, combining threat intelligence and continuous exposure monitoring to help teams mitigate risk across the supply chain.

“The surge in third-party-originating cybersecurity breaches demands a fundamental shift in how cybersecurity leaders and their teams manage third-party cybersecurity risks,” said Gartner. “Cybersecurity leaders must shift from a prevention-only mindset to one that prioritizes quick detection, minimizes the impact of incidents, and thoughtfully leverages AI to improve processes.”

Yet most organizations remain too separated in structure, workflow, and data to make this shift. Security operations teams have visibility into exposure and threats facing their own enterprise but lack the same visibility and reach across the extended supply chain. Third-party risk teams can coordinate with at-risk vendors but frequently lack the threat intelligence to proactively engage. As a result, third-parties account for almost half of enterprise breaches, up over 60% from last year.

Bitsight is bridging this divide by enabling security and risk teams with the ability to operate from a single intelligence platform to identify exposure across the supply chain, add real-time context to active threats, and prioritize remediation workflows and activities.

The new capabilities that connect teams and bring trusted cyber risk intelligence directly into AI workflows include:

  • Bitsight Beacon (now generally available) addresses one of the hardest challenges facing security leaders, organizations usually have limited and delayed visibility into exposure across their supply chain, making it an impossible attack surface to secure. Bitsight Beacon continuously monitors critical vendors for exposure and vulnerabilities, malicious activity, intrusion, stolen credentials, and compromise—giving security teams what they need to investigate and risk teams what they need to drive vendor action.
  • Bitsight Model Context Protocol (MCP) and agentic capabilities help customers manage growing alert volumes without adding more manual analysis. MCP and agents bring Bitsight’s continuously updated intelligence directly into AI-enabled workflows, grounding analysis and decisions in trusted cyber-risk context. In just one month, more than 400 customers signed up for early access, underscoring the need for trusted intelligence in AI-enabled workflows.

“AI is upending the threat landscape,” said John Clancy, CEO of Bitsight. “As models advance, every connection across the supply chain becomes a potential path for business disruption. Bitsight is uniquely positioned to help risk and security leaders meet this moment, opening access to over a decade of contextualized, prioritized, supply chain intelligence to mitigate risk.”

Helping customers manage risk

By connecting exposure with active threat intelligence and business context, the platform is helping customers solve three of their greatest challenges.

  • Too many signals, less certainty about what matters. Bitsight continuously maps assets, technologies, vulnerabilities, vendors and dependencies to show where exposures exist and what they affect.
  • Threats moving faster than teams can respond. Bitsight connects exposure with active threat intelligence and business context to identify what requires immediate action.
  • Disconnected processes slowing action. Bitsight gives security teams the technical evidence to investigate and risk teams the context to drive remediation—all from the same intelligence.

“Discovering and validating areas of concentrated risk across a large digital footprint can be challenging,” said Jason Adams, Director of cybersecurity at Cornerstone Building Brands. “Bitsight makes it easy by automatically digesting thousands of risk vectors into an at-a-glance view so we can quickly pinpoint risks by severity, prioritize remediation efforts and drive continuous improvement.”


from Help Net Security https://ift.tt/vYqFuSn

The EU Agency for Cybersecurity switched on the Cyber Resilience Act‘s Single Reporting Platform on 11 September 2026, the same day the law’s reporting obligations started binding manufacturers. ENISA built the tool and runs its day-to-day operations, a job Article 16(1) of the CRA hands to the agency.

CRA Single Reporting Platform

Anyone placing a product with digital elements on the EU market now reports actively exploited vulnerabilities and severe incidents through that one portal. The clock starts when the manufacturer becomes aware of the event. An early warning is due within 24 hours, a fuller notification with an initial assessment within 72 hours, and a final report within 14 days of a corrective or mitigating measure becoming available. For a severe incident, the final report is due one month after the 72-hour notification.

One submission, then the CSIRTs pass it along

A manufacturer files electronically and picks a CSIRT designated as coordinator, the national incident response team that takes first receipt. That team forwards the notification to CSIRTs in other Member States where the product is available. ENISA gets a copy at the same moment, unless the manufacturer marks one of the exceptional circumstances in Article 16(2), in which case ENISA sees partial information until the receiving CSIRT makes the rest available.

Picking the coordinator is the manufacturer’s job. In general it is the Member State of your main establishment in the EU, where decisions about your products’ cybersecurity are predominantly taken. Choose the wrong one and the notification may be invalidated and has to be resubmitted to the correct coordinator.

Registration runs on an EU Login account with multi-factor authentication. Each manufacturer gets one Primary Assigned Representative and up to 20 Secondary ARs, and the designated CSIRT validates the association. An AR whose association is still pending may file up to 20 notifications before verification becomes mandatory.

“The streamlined reporting and sharing of information on actively exploited vulnerabilities and severe incidents helps to build a more resilient Digital Single Market,” said ENISA Executive Director Juhan Lepassaar.

What the first release leaves out

No API ships with this version, so notifications go through the web interface. ENISA says organizations can automate their internal workflows and may get API functionality in a future phase. A vendor with several affected product lines still types one notification per event into a form, and coordinates across its branches and subsidiaries so that exactly one goes in.

The platform is in English at launch, with translations of the supporting material to follow. Voluntary reports of vulnerabilities, cyber threats, incidents and near misses under Article 15 are planned for a later phase. Open-source software stewards come under the same obligation on 11 December 2027.


from Help Net Security https://ift.tt/iPFHjI6

Cybersecurity attention often rises after an incident, then recedes as organizations return to their existing priorities and practices, according to a new ManageEngine survey of 700 IT and cybersecurity leaders in the US and Canada.

cybersecurity breach confidence

(Source: ManageEngine)

All of them had already been through a breach or incident. Still, 91% said they trust their organization’s current cybersecurity posture. Only 8% said cybersecurity becomes a permanent priority once the incident is behind them.

“The belief that breaches are inevitable has lowered the bar for security,” said Dr. Erik Huffman, a cyberpsychology researcher who commented on the findings. “We’ve said ‘it’s not a matter of if, but when’ for far too long. But we still have control over the security processes that directly influence the outcome.”

Confidence that outpaces prevention

A third of respondents believe a major incident is inevitable regardless of their defenses, and a similar share accept the risks they consider manageable. Known gaps often stay open until an audit or an actual incident forces the issue. Only a minority said security gets consistent attention throughout the year, outside the aftermath of an incident.

“It is unfortunate that we have accepted the idea that bad things will happen no matter what we do,” he said. “Many organizations buy security tools in pursuit of the outcome of being ‘secure.’ But security cannot simply be bought or sold. It is an ever-evolving process and should be treated as such.”

The urgency fades fast

Right after a breach, organizations do react. Process discussions ramp up, urgency spreads through the team, and technical fixes go in, such as patching, access reviews, and backup improvements. That attention rarely lasts. Eighty percent of respondents said increased focus on cybersecurity holds for only one to six months before it fades.

Close to half of organizations kept their existing structures and strategy in place after the incident, making no wider change at all. A smaller share made targeted fixes aimed at the specific gap that caused the incident, and fewer still made broader, long-term changes to governance, training, or escalation.

Business priorities are often the reason why. A majority of respondents said competing demands regularly cause security initiatives to be postponed or downgraded, and one in five named exactly that as the leading factor behind their most recent incident.

Fear shapes what gets said after the fact

Most employees, according to respondents, report a mistake immediately when it happens. 83% admitted that fear of consequences influences how the incident is handled once it’s reported, and a notable share described their organization’s response as blame-focused.

“Cybersecurity has had a fear-based culture for a long time, and it has created an environment many people want to avoid,” Huffman added. “Incident response should not be about who did what. The focus should be on what happened, why it happened, and who it impacts.”

Part of the problem, according to the survey, is that ownership itself is unclear. Close to one in five respondents said they weren’t sure whether security, IT, or business teams should be responsible for a given failure. That uncertainty carries a cost, including delayed remediation, business disruption, and a higher risk that data ends up exposed before anyone closes the gap.

AI recommendations often go unchecked

AI use is widespread among these organizations, running incident response automation, threat intelligence, penetration testing, and vulnerability scanning. A large majority said it has made decisions easier to reach, and more than half credit it with greater efficiencies or stronger security capabilities. AI has also made a majority of respondents more willing to accept cyber risk.

Among organizations using AI in cybersecurity, about two in three said they often or always act on its recommendations without additional verification.

“AI undoubtedly introduces new risks for organizations,” Huffman noted. “LLMs are frequent targets for attackers because of the level of trust people place in the information they receive from AI systems. We need to move from ‘trust but verify’ to ‘verify, then trust.'”

“Organizations that genuinely learn from incidents aren’t just the ones that respond quickly. They’re the ones that preserve visibility after the crisis, make risk decisions explicit, and turn temporary urgency into lasting discipline,” researchers concluded.


from Help Net Security https://ift.tt/9rMPpRs

AWS’ Deception Benchmark measures how well AI models distinguish genuine security vulnerabilities from code that looks risky but is safe. AWS is making it publicly available so researchers can use the dataset and evaluation process without repeating the cost of generating and refining the samples.

Security teams use AI for vulnerability triage, penetration testing, threat modeling, incident response, and code review. High false-positive rates can create more work, increase alert fatigue, and reduce confidence in legitimate findings.

The benchmark contains 14,822 samples across 16 programming languages and more than 70 Common Weakness Enumeration (CWE) categories. AWS evaluated 12 models from five providers.

Why another security benchmark?

Existing benchmarks test AI on a range of cybersecurity tasks. CyberGym includes more than 1,500 realistic tasks, Meta’s CyberSecEval covers capabilities such as exploit generation, and CYBENCH focuses on capture-the-flag challenges. ExploitGym tests whether models can go from finding a vulnerability to producing a working exploit.

AWS’ benchmark focuses on a different problem: When a model says code is vulnerable, can it tell a real vulnerability from a false positive?

That can be difficult because code may contain a dangerous pattern while another control prevents it from being exploited. The model has to understand both the code and the protections around it.

How the benchmark works

AWS calls it the Deception Benchmark because its safe samples are designed to mislead models. They contain real vulnerability patterns alongside protections that prevent exploitation. Models must decide whether each sample is vulnerable or safe without being given hints.

“Production tools rely on multi-step loops and agentic workflows to compensate, but that scaffolding masks whether the model itself understands the code. This benchmark strips the scaffolding away and asks the model to make the call in a single pass, so what it measures is understanding, not how many tries a harness takes to get there,” Anshumali Shrivastava, Amazon Scholar, and Neha Rungta, Applied Science Director at AWS Identity, explained.

AWS generated examples, tested them against frontier models, and made them harder when models classified them correctly. Samples that models could easily classify were excluded. According to AWS, generating and refining the samples consumed tens of billions of tokens.

Of the 14,822 samples, 9,695 are scored. These include 6,988 code-level and 2,707 environment-gated challenges.

Code-level challenges have vulnerable and safe versions separated by a small change. Both may look unsafe, but only one can be exploited.

Environment-gated challenges test the same kind of code under different deployment conditions. For example, a Kubernetes Network Policy may block an SSRF attack that appears possible from the code alone. The model must take those protections into account.

AWS publicly releases the samples but withholds their labels. The dataset also includes 5,127 unscored samples mixed with the scored ones. Users submit their predictions to AWS for verified scoring. This setup is intended to make it harder to optimize specifically for the benchmark.

Checking the labels

Multiple independent reviewers check each label without seeing other reviewers’ decisions or the reasoning behind the original label. Disagreements receive further review, and unresolved cases go to human reviewers.

AWS repeats this process until fewer than 3% of scored samples remain contested by independent reviewers, with a target of fewer than 1% surviving human review. Samples that remain disputed are moved to the unscored set instead of being relabeled.

The company also reports that a human review of 100 randomly selected scored samples found no labeling errors.

Models struggle with false positives

The benchmark is roughly balanced between vulnerable and safe samples, so random guessing would score about 50%. AWS considers false-positive and false-negative rates below 10% a minimum bar for production use. None of the tested configurations met both thresholds.

AWS Deception Benchmark

FPR compared to FNR for 12 models across two prompting strategies. No model reaches the generous bar. (Source: AWS)

With direct prompting, models generally found nearly all real vulnerabilities, but incorrectly flagged 41% to 99% of safe code. Precision ranged from 52% to 71%. Asking models to prove that a vulnerability could actually be exploited reduced false positives by 17 to 74 percentage points. The downside was more missed vulnerabilities, with false-negative rates ranging from 7% to 44%. Models had the most difficulty when external security controls made suspicious-looking code impossible to exploit.

AWS tested general-purpose models with single-turn prompts, not purpose-built security systems that use tools and multiple validation steps. The results therefore should not be treated as a direct measure of how complete security products perform.


from Help Net Security https://ift.tt/o4FwXxN

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

Week in review

Zero trust AI agents demand a different kind of security
In this interview, Chris Webber, VP, Product Marketing at Teleport, explains why zero trust principles need to change for AI agents. He covers how agents act fast, unpredictably, and continuously, and why old ideas like least privilege and point-in-time verification fall short.

AI-Infra-Guard: Open-source security scanner for AI systems
Tencent’s Zhuque Lab built AI-Infra-Guard, an open-source security scanner for AI systems. It fingerprints running services such as Ollama, vLLM and ComfyUI and checks them against more than 1,600 known CVEs, inspects MCP servers and agent skills across 14 categories of risk, and runs jailbreak evaluations against a target model.

Kevin Mandia joins the Amazon board with 30-plus years in cybersecurity
Amazon elected Kevin Mandia to its Board of Directors on September 8. Mandia founded Mandiant and served as its CEO before Google acquired the firm in September 2022, and he has worked against cyber threats in the public and private sectors for more than 30 years.

Getting a stranger’s phone kicked off the cellular network costs a few dollars
Researchers at Michigan State University and three partner schools bought a Samsung Galaxy Z Fold 7, copied the identification number printed on the sealed box, and reported the phone to its carrier as lost. Then they opened the box and set the phone up the way a launch-day buyer would. It would not connect. The phone was new, unopened, and sitting on a lab bench the entire time. The team found six weaknesses in the system carriers use to shut off lost and stolen phones, spanning the devices themselves, the carrier systems that take the reports, and the machinery carriers use to share block lists.

Trezor customers hit with phishing calls and letters after shipping-partner breach
Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone numbers, and shipping addresses were exposed.

“Zero-click” WeChat worm could hijack accounts and spread via a single call
Researchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create “WeWorm”, a worm that spreads via WeChat calls without any user interaction.

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor
September 2026 Patch Tuesday is here, with Microsoft delivering another record-breaking number of patches, including those for two vulnerabilities that have been exploited as zero-days.

Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a network.

What breach and attack simulation needs to become in the AI era
Breach and attack simulation (BAS) has always had a supply chain. Somebody has to read the threat report, pull out the techniques, and turn them into something that will actually run against your controls. That somebody has always been a human red team. Up until a few months ago, turning a major new threat into working simulation content within 24 hours counted as very fast.

Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results
Gartner predicts that by 2028, 70% of large SOCs will pilot AI agents, but only 15% will see measurable gains without structured evaluation. The technology has already moved from Gartner’s Innovation Trigger to the Peak of Inflated Expectations. Prophet Security reports that 40% of security teams use AI daily, 56% are evaluating or piloting it, and just 4% have no plans to adopt.

Ransomware negotiation tactics have turned into a business process
In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware negotiations.

Building a ransomware decision tree before the call comes in
In this Help Net Security video, Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walks through the ransomware decision tree in this video. She covers four areas where decisions need settling in advance, starting with containment.

18 ways to check whether data can be trusted for AI
ETSI has published TR 104 180, a technical report that defines 18 metrics for measuring data quality, giving companies a way to check whether their data is good enough for AI before they use it. The report defines each metric and includes the formulas needed to calculate it.

Attackers use rogue ScreenConnect clients to spread malware
A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed. Until a fix is available, ConnectWise recommends that partners disable file transfers for technicians.

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)
N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular with managed service providers (MSPs). In its release notes, N-able described CVE-2026-86218 as a “critical-CVSS-rated vulnerability that could allow for pre-authenticated remote code execution on the N-central server.”

Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication
Attackers are exploiting a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH open to the internet, CERT Polska found. They have discovered six vulnerabilities in RouterOS and coordinated their disclosure with MikroTik. Among the six, two combined let an attacker take full control of a device without authentication, provided the device has SSH accessible from the internet. They named this exploit chain MikroTrick.

Mathspace breach exposes data on over a million students and parents
Mathspace has confirmed that attackers broke into its internal reporting system through an unpatched Metabase vulnerability and stole data belonging to more than a million students, parents, and school staff. The Sydney-based maths education company wrote in a blog post that the vulnerability, in its self-hosted installation of Metabase, allowed attackers to obtain administrator access to the system without a legitimate login.

IT help-desk vishing tricks executives into handing over Microsoft 365 access
IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and other SaaS accounts, according to Arctic Wolf.

Threat actors are giving AI agents a bigger role in cyberattacks
AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker.

Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)
Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. The fix has been shipped in Chrome 153.0.8010.36 and .37 for Windows and macOS and Chrome 153.0.8010.36 for Linux.

Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory
A rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos. F5 BIG-IP APM provides access policy enforcement to secure access to apps, APIs, and data. It’s primarily used by enterprises, financial institutions, government agencies, and public sector organizations.

$245 million in stolen crypto funded racketeering crew’s lavish lifestyle
A 22-year-old man built his fortune by breaking into strangers’ digital wallets, then spent it on nightclub tabs, private jets, and a fleet of cars worth millions. Malone Lam, a Singapore citizen, pleaded guilty this week in a Washington D.C. federal court to running a racketeering conspiracy that stole and laundered more than $245 million in cryptocurrency.

OpenSSL’s new alpha build speeds up post-quantum crypto
The OpenSSL project released the first alpha of OpenSSL 4.1.0, giving developers an early look at a version built for encrypted communication over unreliable connections and faster post-quantum cryptography. This marks the opening test build for a version still months from general availability.

Cybercriminals are building phishing pages that exist only inside victims’ browsers
A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, according to researchers at Barracuda.

Fake GTA 6 download delivers malware-packed bundle to impatient gamers
Grand Theft Auto VI (GTA 6) is still three months from release, but cybercriminals are not waiting for the launch date. Security firm Huntress found malware disguised as a leaked copy of the game, aimed at fans hoping to get their hands on it early.

Attackers call employees’ personal phones to break into Microsoft 365 accounts
Attackers are calling or texting employees on their personal phones, posing as internal IT staff, in a social engineering campaign that tricks them into handing over access to corporate cloud accounts. Once inside, they pull files and email from Microsoft 365 apps, SharePoint, OneDrive, and inboxes, for weeks at a time, according to Microsoft Security Research.

IDScan confirms breach after 153 million driver’s licenses leak on dark web
Days after reports linked IDScan to a dark web database holding more than 153 million driver’s license scans, the identity verification company has confirmed hackers accessed customer data stored on its cloud platform.

AI agents exploited PaperCut flaws to breach 395 organizations
A threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the work on their own, according to GreyNoise.

ToolHive: The open-source way to run any MCP server securely
ToolHive is an open-source platform that runs Model Context Protocol servers inside containers. An MCP server is the connector that lets an AI client like Cursor or Claude Code reach an outside tool, and Stacklok ships ToolHive under Apache 2.0, so the runtime, the Kubernetes operator, and the registry cost nothing to self-host.

OpenAI just hit a milestone on the road to self-improving AI
OpenAI has announced that it has reached a goal set last fall of having an automated research intern by September 2026. The milestone means a system can carry out well-defined research tasks under human direction, including work that would take a skilled researcher several days. The company is also working toward creating an automated AI researcher by March 2028.

Microsoft’s Project Zenith puts large AI models directly on developer PCs
Microsoft’s Project Zenith is a ready-to-code Windows 11 experience for developer-class PCs capable of running AI models with more than 30 billion parameters locally without relying on metered cloud tokens. Designed for systems with at least 64 GB of unified memory and 250 GB/s or more of memory bandwidth, it pairs powerful hardware with a preconfigured software environment for coding, testing, and experimentation.

Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins
Jellyfin shipped version 12.0 of its media server. Several of the security fixes in it block requests built to reach files outside the folders the server is supposed to hand out. The rest of the security work touches first-run setup, plugin installs, parental controls, and the web interface.

BleachBit 6.0.4 fixes secure wiping that skipped clusters on Windows
The open source cleaner BleachBit reached version 6.0.4 this week, erasing caches, browser traces, and files on Windows, Linux, and now macOS. If you shredded a sensitive file on Windows with an earlier build, parts of it may still sit on the disk where the wipe missed. Fragmentation is the ordinary case, since Windows scatters a file across noncontiguous clusters whenever it cannot find one open run large enough to hold it.

AWS spent years rebuilding its routing control plane without taking the network down
Every AWS API call, CloudFront video stream, and Route 53 lookup crosses the same infrastructure, which AWS calls its border network. It now runs on a routing system rebuilt from scratch over several years.

Chinese AI firms are siphoning capabilities from American models, CISA warns
China-based AI companies are using large-scale knowledge distillation campaigns to copy capabilities from leading U.S. AI models, according to a joint cybersecurity advisory from the CISA, NSA, and FBI.

A new open standard locks AI weights to approved hardware
OPAQUE, a confidential computing company that runs AI workloads inside hardware-isolated environments so operators cannot inspect them, released an open standard that lets AI model builders decide when and where their weights can be decrypted once those weights leave the builder’s own servers. The standard, called Weight Custody Manifest, ships as a developer-preview specification, a Python SDK, and a public test suite covering 91 cases.

AI adoption brings new security headaches for already stretched CISOs
CISOs are taking on AI governance without a matching increase in resources or expertise, adding to an already broad remit spanning data protection, identity, resilience and compliance, according to Proofpoint’s 2026 Voice of the CISO report.

Apple is building photo verification for the people who need it most
Apple has introduced Apple Reference Image, an opt-in feature designed to verify the authenticity of photos taken with iPhone 18 Pro models. The company will also add support for the SynthID standard in a software update later this year, helping identify images generated or edited using AI.

WordPress adds automated security checks to block risky plugin releases
WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential security risk will be blocked automatically.

Your passkeys can now move between password managers on Android
Google turned on a transfer feature in Android that moves passwords and passkeys straight from one password manager to another, with no file to download along the way. You start it from inside the app you are switching to, and Google says the data moves between the apps in a few seconds.

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors
Canonical shipped Ubuntu 24.04.5 LTS, bundling security updates and fixes for high-severity bugs into new installation media for the “Noble Numbat” release. Anyone installing fresh now gets those corrections baked in from the start, cutting the batch of updates that would normally follow setup.

AI is changing what Salesforce security needs to govern
Existing security and governance practices have largely focused on identities, permissions, access, configurations and controls. WithSecure’s Navigating Trust in the Modern Salesforce Ecosystem paper says Salesforce environments also require organizations to understand what information they rely on, how trust extends across connected systems, what actions are performed and what outcomes those actions produce.

Companies may be measuring phishing resilience the wrong way
Companies that judge phishing simulation programs by how often employees click simulated attack emails may be overlooking more important indicators of cyber resilience, according to Pistachio’s Phishing Behaviour Report 2026.

Product showcase: Doppler secures secrets for humans, pipelines, and AI agents
AI agents have expanded the secrets management challenge. Coding agents, automated workflows, and MCP servers create more identities that need credentials, and more places those credentials can leak. Doppler centralizes credentials for engineers, pipelines, and AI agents in one easy-to-use control plane. It gives security teams a critical secrets management tool developers use, available in the cloud or on-prem.

Product showcase: GitGuardian Honeytoken catches credential theft as it happens
GitGuardian turns credential harvesting into an immediate, high-confidence detection signal. It deploys honeytokens across developer fleets so that when an infostealer scans a machine and validates a decoy, defenders know within seconds.

Cybersecurity jobs available right now: September 8, 2026
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.

New infosec products of the week: September 11, 2026
Here’s a look at the most interesting products from the past week, featuring releases from Akeyless, Orchid Security, Scytale, and Securin.


from Help Net Security https://ift.tt/CT3gqIJ

We may earn a commission from links on this page.

We expect fitness wearables to count our steps—an idea that Fitbit borrowed from pedometers forever ago. In recent years even Oura and Whoop have added step tracking. But the Apple Watch has never made it easy to see your step count, even though it’s been keeping track in the background all along. Apple is finally changing that. 

On the product pages for the Series 12 and the Apple Watch Ultra, Apple boasts that the new watches give you a more accurate step count—interesting, because step count hasn’t been a selling point in the past. And then comes the big news: “And now you can more easily check your step count, right from your watch face.” 

So far, it has been frustratingly difficult to get a step count on your watch. You would think you could easily add that number to a watch complication (a complication being a mini data field for the watch face), but nope—if you want a little counter of your steps on the watch face, you have to install a third-party app to provide that. 

I kind of understand why: Apple wanted to set itself apart from the Fitbits of the world. You’re supposed to close your rings, and rings are based on movement, exercise, and stand hours. I can imagine somebody at Apple saying “no, step counting is dumb” and they were arguably right. But the idea has stuck in the public consciousness; we now expect step counts, and Apple is finally going to deliver. 

How to get step count on your Apple Watch

First of all, the Apple Watch already counts your steps. You can see your step count by going to the Health app on your phone and searching for Steps. Scroll to the bottom of the Steps screen and tap Add to Pinned. Now it will be the first thing you see when you open the Health app. (Surprised the Health app can do this? You have no idea of the hidden gems in that thing.) 

To get a step count on your Apple Watch right now, without upgrading anything, you’ll need to install a step counter app. Duffy is a popular (free) one; there are plenty of others out there, so choose one you like. These apps typically provide a complication, so you can add your step count to your favorite watch face. 

But what about taking advantage of Apple’s new embrace of the step count? Apple says the feature will be available on the Series 12 and Ultra 4 watches. That said, this seems like a very simple software change, so I’d bet money that step count will become available in WatchOS 27, which is due out any day now, and which will run on Series 9 and newer, Ultra 2 and newer, and the SE 3. I’m currently using the WatchOS 27 public beta, and there’s no step count feature yet, but I’m watching for it.  

I also spied step counts in Apple’s screenshots of its upcoming redesign of the Health app. This is an app that lives on your phone, and in the screenshot there was a little tile with your Apple Watch rings, and underneath the rings, the step count. Apple says the Health app redesign will be available on devices that support Apple Intelligence, which means the iPhone 15 Pro and newer.

Once you have the feature on your watch, it looks like step counts will be available on the cards you see when you swipe up from the main watch face. Currently you can pin a card there with your step distance for the day (I’ve covered 0.65 miles between waking up and making my way to my home office) but steps aren’t available there yet. 


from Lifehacker https://ift.tt/kwDUlGP

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of publication.

Many portable projectors still need separate speakers or extra cables, but the ION Portable HD Outdoor Projector bundles a 720p projector with built-in speakers, Bluetooth, and even a microphone for karaoke, so you can set it up with minimal planning. It's meant for quick setups, like putting on a movie in your living room or taking it out to a terrace, and it's on sale for just $64.99 on StackSocial right now. You can stretch the image up to 150 inches, but the 1280 x 720 resolution and 100 ANSI lumens mean it looks best in a dim room or after sunset. Daytime viewing or bright spaces will wash out the picture.

Most small projectors struggle with sound, but this one puts real focus on audio. The built-in 70W stereo system gets surprisingly loud, with dual drivers and tweeters that can fill a medium room or a small outdoor gathering. You can also use it as a Bluetooth speaker, with Bluetooth 5.3 support and a range of about 100 feet. That makes it useful even when you are not projecting anything. The karaoke feature might not be for everyone, but it's easy to imagine it becoming the main attraction at a house party. You get two mic inputs, echo effects, and one wired microphone in the box. For video, it keeps things simple. Plug in a laptop, streaming stick, or console through HDMI, or use a USB drive for local files—there is no built-in smart platform here.

Battery life is where you need to be realistic. You get around two hours of video playback, which is just enough for a movie, or up to 100 hours if you are only using it as a speaker. All things considered, this ION Portable HD Outdoor Projector is a great deal.

Our Best Editor-Vetted Tech Deals Right Now
Sony WH-1000XM5 $298.00 (List Price $399.99)
Apple Watch Series 12 GPS 42mm Smartwatch (List Price Pre-Order at $399)
Deals are selected by our commerce team

from Lifehacker https://ift.tt/tO1yPlz