The Latest

We may earn a commission from links on this page.

Google’s “Health Guardian” feature set is rolling out to Pixel Watches 3, 4, and 5 this week, and to Fitbit Air users “later this year.” Google says the new features will include reports on your blood pressure trends and on insulin resistance, which is a big claim for a wearable. Here’s what we know about Health Guardian, including how to set it up and what to expect. 

Can you really measure insulin resistance with a wearable? 

Insulin resistance is associated with type 2 diabetes, and can be an early sign that you are heading toward pre-diabetes or diabetes. When your body’s insulin receptors stop responding as strongly to insulin, you’re more likely to have higher blood glucose. 

Insulin resistance is normally measured with bloodwork. For example, your fasting glucose levels and fasting insulin are combined into a score called HOMA-IR. If you’re concerned about insulin resistance or pre-diabetes, it’s best to talk to an actual healthcare professional to find out what tests they recommend, and what to do with the results. 

The insulin resistance feature coming to Google Health is, Google notes, “not intended for medical purposes” and “not a pre-screener for diabetes.” 

Google published a paper describing some of the testing that went into developing its insulin resistance algorithm. In the study, the researchers had people use their own Fitbits or Pixel Watches to record a variety of metrics, including heart rate, HRV, and activity. It’s not clear from this paper exactly how the algorithm works or whether it’s likely to be useful in a general population, but apparently Google is betting on it being an interesting factor to track in your Google Health app.

Is Health Guardian free? 

Google said in a press release that Health Guardian is available for free for people who use a Pixel Watch 3, 4, or 5. Fitbit Air users will get blood pressure and insulin resistance trends “with a Google Health Premium subscription later this year.” So it’s free if you have a Pixel Watch, but not if you only have the Fitbit Air. Google Health Premium is $9.99/month. 

It’s unclear what happens if you own both devices; presumably having a Pixel Watch will get you free access. In any case, other devices, including older Fitbits, do not seem to be included. 

How to get Health Guardian’s blood pressure trends and insulin resistance estimates

The new features are built into the 5.09 release of the Google Health app for Android, which is rolling out this week. (It seems iOS will be getting the features later. This makes sense, since iOS users wouldn’t have a Pixel Watch paired, anyway.) 

According to Google, you can “set up” your blood pressure and insulin resistance tracking as soon as you get the new version of the Google Health app. A Reddit user who has gotten the update says that you can set up these features by going to the Health tab and then tapping Metabolic to set up insulin resistance tracking, Heart to set up blood pressure tracking, and Respiratory to set up sleep breathing quality. 

Google says that you’ll receive your first monthly reports for these metrics on Oct. 1, and that afterwards you’ll be able to view this data in the Health tab. 

To get the blood pressure report on Oct. 1, Google says you’ll need to wear the watch for five consecutive days in September. For insulin resistance, you’ll need to wear the watch for seven or more “days and nights” in September. I notice that doesn’t say consecutive days. 

I haven’t gotten the new version of the app yet myself, and nobody has gotten their monthly report yet, so I’m looking forward to it as much as you are. I’ll update when I’ve had a chance to try out the new features. 


from Lifehacker https://ift.tt/dQ95hgv

We may earn a commission from links on this page.

I'm sticking to my marathon training schedule, nor'easter be damned. Normally, that means I'd come home with soaked shoes, prop them in front of a fan, and hope they dry out overnight. And normally, that means I head out with still-damp shoes the next day. Not only is this uncomfortable, but it makes my home smell like a locker room.

This weekend I had two training runs back to back in the rain, which meant my shoes had to be ready to go again almost immediately. This week's upgrade is the gadget that made it work: this Hedgehog Hanger.

The Hedgehog Hanger is my upgrade of the week

The Hedgehog Hanger is a hanging shoe and glove dryer. You can easily hang it in a closet or wardrobe (there's a stainless steel hook), plug it in, and slide your shoes onto its arms. Instead of just warming the air, it pushes airflow through the shoes. The brand says the patented turbine technology moves humidity out of the fabric, and that a pair of shoes or gloves dries in about 15 to 30 minutes.

I really like the control it gives you. The heat is adjustable, from room temperature up through a few warm settings, including lower ones meant for leather and more sensitive materials. That matters if you don't want to blast a nice pair of shoes at full heat. There are five speed settings, and it goes up to a "tornado" mode for the fastest drying when you're in a hurry.

The controls on the Hedgehog Dryer.
The controls on the Hedgehog Dryer. Credit: Meredith Dietz

After my first run in the rain this weekend, I hung my wet shoes on the Hedgehog and let it do its thing. By the time I was ready for the next session, they were dry, fresh, and ready to wear. I didn't have to rotate to a backup pair—or lace up soggy shoes and hope for the best.

If you're a runner, hiker, or anyone who trains through bad weather, that turnaround time is the real selling point. Consistency is so much easier when wet gear isn't a reason to skip a session. That said, I do wish it were a little more affordable: If you only deal with wet shoes a few times a year, $199 is a bit steep.

Still, if you train in all weather, live somewhere rainy or snowy, or have kids constantly tracking in soaked shoes and gloves, you'll get a lot of use out of this gadget. Hey, even when it's not plugged in, I'm grateful for the extra storage by my shoe rack.


from Lifehacker https://ift.tt/WtOEAzG

We may earn a commission from links on this page.

American Horror Story is kind of an institution, at this point. Seasons may vary in impact and the precise tone of the horror may fluctuate, but we’ve come to count on its gonzo sensibility and commitment to the bit. With its anthology approach and rotating troupe of semi-permanent actors (including Jessica Lange and Sarah Paulson), AHS has delivered plenty of twisted stories to keep you up at night. If you’ve watched them all (and the streamalike shows that offer similar chills), it’s time to dive into long-form horror on the same wavelength—starting with what might be the first (and still one of the best) horror anthologies ever made: Dead of Night.

The best movie to watch if you're a fan of American Horror Story

Without Dead of Night, released in 1945, there might not be an American Horror Story. Hugely influential, the movie is regarded as one of (if not the) first horror anthology films widely released, and more than 80 years later it’s still considered one of the best. Watching it is an exercise in noting everything that the horror anthologies that followed—including AHS—have freely borrowed from it. If you love the anthology aspect of AHS, the way each season (or half-season) is a self-contained story with its own tone, visuals, and style of horror, this is the movie you should watch.

The frame story involves architect Walter Craig (Mervyn Johns), who travels to a remote cottage for a potential renovation project. When he arrives, he finds himself one of several guests—all of whom have appeared in dreams experienced by their host, Elliot Foley (Roland Culver). Craig experiences what seem like psychic visions, which prompts the guests to tell tales of supernatural experiences they’ve had, all of which are presented as apparently standalone episodes. The most famous of these is the story of a ventriloquist whose dummy, Hugo, seems to have a will of its own, but all the stories are well-made and effectively scary.

What really sets Dead of Night apart—and makes it perfect for AHS fans—is the way the guests’ tales and the frame story merge into a truly unsettling whole. The film conveys both a sense of dream logic and visceral fright that’s surprisingly powerful and modern for a film of its vintage, and AHS fans will see the clear line of inspiration that starts here and ends with Jessica Lange leading an insane asylum in “The Name Game” (among many, many other insane moments from the show). If you’re looking for a feature film that will slot into the same pleasure centers in your brain as American Horror Story, this is the one to start with. Stream Dead of Night on Kanopy, Plex, or Fawesome, or rent it on Prime Video.

More movies for fans of American Horror Story

Horror is addictive, and the only cure for the end of a horror movie is ... more horror movies. Here are a few more that any fan of AHS will love.

The Shining (1980)

One of the more obvious points of inspiration (especially for Season Five, “Hotel”), The Shining is one of the greatest modern horror films. The combination of Stanley Kubrick’s cold perfection, Jack Nicholson’s volatility (and Shelley Duvall’s criminally underrated desperation), and Stephen King’s wild imagination (despite his reservations about Kubrick’s interpretation) results in a slow burn of insanity as an unstable alcoholic (Nicholson’s Jack Torrance) unravels while working as a winter caretaker in an enormous, haunted mountain hotel. Every scene in this film ramps up the sense of unease and terror, leading to one of the most famous final shots in film history. Rent The Shining on Prime Video.

Rosemary’s Baby (1968)

Season 12 of American Horror Story, “Delicate,” riffs enthusiastically off of Rosemary’s Baby, and the 1968 film could be an entire season of the show itself. The tone, visuals, and story are a perfect match—you can easily imagine most of the usual actors from the AHS troupe showing up as the creepy, devil-worshipping neighbors who manipulate a young woman (Mia Farrow) into conceiving a child under what could be called ominous circumstances. Aside from being an ideal companion film to the series, it’s also a classic that every horror fan should watch (despite some serious implications around marital sexual assault and director Roman Polansky’s gross legacy). Stream Rosemary’s Baby on Kanopy or rent it on Prime Video.

Twisted Nerve (1968)

If you recall the weird whistling theme song associated with serial killer Tate Langdon in Season One, “Murder House,” you’ve already heard the theme song to this movie (you also heard it in Kill Bill: Volume 1). While not overtly gory, Twisted Nerve is a great example of simmering tension as a disturbed man with a split personality, Martin (Hywel Bennett), stalks and ingratiates himself with a young woman named Susan (Haley Mills). The film is dated in many ways (especially its enraging attitude toward Down syndrome), but as a thriller it still works gangbusters. Stream Twisted Nerve on Plex.

The Texas Chainsaw Massacre (1974)

The moment Bloody Face shows up in the second season of American Horror Story, the connection to Tobe Hooper’s 1974 film is pretty clear—but The Texas Chainsaw Massacre reverberates throughout American Horror Story (as it does through most of the horror movies that followed it). Ostensibly based on the true crimes of Ed Gein, it follows five teenagers on a road trip as they stumble into the house where a man wearing a skin mask—the legendary Leatherface—proceeds to savagely murder most of them using a hammer and, of course, a chainsaw. The film’s sweaty, gritty style is a long way from Ryan Murphy’s slicker and more composed approach, but it’s a visceral kick of pure horror fans of the show will love (if they don’t already). Stream The Texas Chainsaw Massacre on Pluto or Tubi, or rent it on Prime Video.

The Craft (1996)

If “Coven” was your favorite season of American Horror Story, this is the film for you. Four outcast teen girls—played by Robin Tunney, Fairuza Balk, Neve Campbell, and Rachel True—discover that they can access supernatural forces, and seek to use this power to punish their enemies and improve their lives. Their spells have unintended consequences, however, and Balk’s character quickly goes power-mad as the girls turn on each other. It’s dark, but anyone who attended high school will 100% understand why things go pear-shaped so fast—and fans of AHS will find a lot to love in this story of teenage angst, rebellion, and occult horrors. Stream The Craft on Plex or rent it on Prime Video.


from Lifehacker https://ift.tt/aRADmC0

AI agents are forcing enterprises to rethink security governance, human accountability and oversight as deployments scale.

AI agent security governance

AWS’s Reimagine 2026 argues that organizations need to build governance into their systems and keep humans accountable for outcomes. The findings come from confidential interviews of 45 to 60 minutes with 154 executives at 128 organizations in 23 industries, conducted over nine months.

A number of the organizations interviewed still apply review processes designed for six-month IT programs to work that takes days. If a two-week experiment waits a month for approval, some teams stop asking for permission. Policy in that situation is “pushing it underground,” the authors write.

One interviewed leader said that CIOs who spent years managing shadow IT are dealing with shadow AI at ten times the scale.

Security, privacy and data leakage are among the technical risks the authors identify. Organizations fear that proprietary data, customer personal information or confidential business intelligence will escape through AI systems, sometimes invisibly and often through third-party tools employees use without oversight.

A Strand Partners survey of European businesses, commissioned by AWS and cited in the document, found that more than half of SMEs and large enterprises use AI. Only 24% have a documented approach to responsible AI use, and 10% have a data governance strategy.

Chris Sedore, VP of Information Services and Technology and CIO at Boston University, estimates that 40 to 50 percent of people at the university use AI at least weekly. “Some of it in models and systems we provide, some of it going rogue,” he said.

When AI reads employee emails

Emails, chats and meeting notes make up what Reimagine 2026 calls the “human layer” of data, and the authors see value in mining it with AI. They note that accessing it raises privacy concerns.

At Houston Methodist Main Campus, a doctor challenged CEO and Chief Innovation Officer Roberta Schwartz, assuming an AI project meant leadership was reading his messages. That wasn’t the case. “I can barely get through my day with my own emails,” Schwartz said, recalling the exchange.

Staff needed a year of experience with the system before they trusted that it surfaced organizational patterns and left personal content alone. The principle that emerged from the interviews is that AI looks at group-level patterns and leaves individuals out.

Where salary data, HR decisions or personal communications were involved, organizations redacted them before processing so that “AI receives the signal without the identity.” Being open with employees about how their data was used was key to building trust.

Writing the rules into the system

Some organizations sort AI projects by risk before they start. Rafael Cavalcanti, Chief Data Officer and Director of Data and AI at Bradesco, built a classification tree that asks whether a use case involves personal data, whether it runs live or in batches, and whether a human must stay in the loop. Each combination of answers maps to a risk level and a set of controls.

For AI agents, the authors advise starting with human approval and expanding autonomy only after the agent shows it is reliable, while keeping the option to narrow it again. “Treat it like probation for a new hire,” they write. Security limits should be set outside the agent, since agents “can misinterpret or work around embedded rules.”

Regulatory differences between jurisdictions complicate things further. “When you’re in 22 countries, you don’t want a paradigm where 20 of the countries are impacted because two of the countries don’t allow certain things,” noted Duncan Macdonald, CTO of Cloud Enablement at Standard Bank.

Wide use, thin results

Usage figures say little about results. One organization observed early in its AI journey appeared 88 percent “adopted,” but produced better work in fewer than one in 5,000 sessions.

Saved time also needs a plan. “If I’m able to do four hours of work in one hour, if there is no structure for how the three hours that have been saved will be used, then there’s no benefit to the company,” stated Dr. Rashed Iqbal, CTO at RAK IDO.

The junior talent gap remains open. AI removes the repetitive work that used to build judgment in junior employees, and while organizations are experimenting with fixes, none of those interviewed claimed an answer.


from Help Net Security https://ift.tt/qgzcFoI

Verdict is an AI image and video detector designed for iPhone. It works offline and requires no account. Choose a photo or video, run a scan, and the app returns a 0–100 score with a verdict and supporting evidence. It requires iOS 16 or later.

Verdict

How it works

For photos, Verdict examines signals from an AI-detection model, camera metadata, and sensor noise. It shows a compression check in the breakdown, but that check does not affect the score.

For a video, it analyzes 15 sampled frames and uses the median result. The breakdown lets users see where the checks agree or disagree.

The analysis takes place on the iPhone. Photos and videos are not uploaded, and scan history remains on the device. The app uses Apple’s photo picker, so selecting a file does not give the app access to the entire library. An optional feedback form sends the message and basic device details if the user chooses to submit it.

Testing Verdict

I tried Verdict with several photos and a video. One garden image received a 51% real result, close to an even split. A different image was labeled 72% AI-generated, while a photograph of a house was marked 100% real. The results screen shows how the individual checks contributed, including cases where they disagree.

Verdict

The video test exposed a more serious error. I scanned footage I had recorded at a concert, and the app labeled it 100% AI-generated. Its frame analysis classified all 15 sampled frames as AI, although the same results screen identified the file as camera-captured video.

Verdict

That result shows why a confident score should still be questioned. I cannot determine whether concert lighting, movement, video processing, or another factor caused the mistake.

Conclusion

Verdict’s offline analysis and evidence breakdown make it useful for an initial check, especially with private media. My concert video shows why it is still important to consider the source and context before accepting an automated verdict.


from Help Net Security https://ift.tt/8eaWmq4

The European Telecommunications Standards Institute’s (ETSI) technical report, ETSI TR 104 171, offers guidance on building and evaluating quantum random number generators (QRNGs). It focuses on weaknesses in the devices and their supporting systems that could make the numbers they produce less secure.

Quantum Random Number Generator guidance

Components of a QRNG (Source: ETSI)

A QRNG measures a quantum process and turns the raw results into usable random numbers. Cryptographic systems rely on unpredictable numbers to generate keys and perform other security functions. If an attacker can predict those numbers, the protection those systems provide may be weakened.

“While quantum physics is adept at providing genuine unpredictability, secure randomness rests on the integrity of the entire implementation,” said Mark Pecen, Chair of ETSI TC Quantum. “These guidelines arrive at a critical moment as organizations need to understand how to validate the quantum source and ensure that entropy is properly extracted, monitored, protected and securely delivered to the applications that depend on it.”

The report follows the numbers from their source to the application that uses them. It explains how manufacturers can verify the source, process its raw output, and check for faults while a device runs. It also addresses physical tampering, information leaks, and the connections that carry the numbers to other systems.

One concern is that numbers can appear random in statistical tests while still giving an attacker clues about future output. Evaluating a QRNG therefore involves understanding how the device works, including the components surrounding its quantum source and the conditions under which it operates.

AI could expose weaknesses in QRNGs

AI could help an attacker spot patterns caused by a QRNG’s sensors, power supplies, or signal processors. These components can add noise to the output, and some of that noise may be predictable. An attacker could analyze a large amount of data, looking for patterns that offer clues about the numbers the device produces. The report says finding and exploiting those clues could take considerable time and effort.

A device may also reveal clues through changes in power use or electromagnetic signals. AI could help an attacker connect those signals to the numbers produced. The concern extends to other types of random number generators that use similar components.

The guidance recommends shielding sensitive hardware, using reliable methods to process raw output, and checking for unexpected patterns during operation. Monitoring can help operators detect a fault or possible interference before they continue using affected output.

Checks at every stage

For QRNGs used in regulated or high-security settings, the report recommends an approach called entropy zero trust. It calls for verifying the quantum source and monitoring the device throughout its operation. Hardware and software protections help guard against tampering, while secure connections protect the output on its way to an application.

The approach also covers systems shared by multiple users. Separate safeguards can help prevent a problem affecting one user’s output from spreading to another.

Devices should record when numbers were generated, which software was running, and information that traces the output to its source. Those records can help organizations investigate faults and show how a device was operating when it produced numbers used by a security system.

ETSI also calls for more consistent ways to compare QRNGs, including their security features, speed, power use, size, and ease of integration.


from Help Net Security https://ift.tt/lG2RcgX

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

Week in review

Know what was tested before your SAP ECC migration goes live
In this Help Net Security interview, Guilherme Joventino, COO of MIGNOW, explains why some large companies plan to stay on ECC past the 2027 deadline and pay SAP for extended support until 2030. The interview covers what that choice may cost, why fear of disruption stalls projects more often than budget, and what the first ninety days of a phased migration involve.

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files
Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put to grab each new or edited document. The same malware steals saved Wi-Fi passwords and clipboard text, takes screenshots, and runs whatever command its operators send.

European AI spending is on track to reach nearly $470 billion by 2030
European organizations will spend nearly $470 billion on AI in 2030, IDC forecasts, with spending growing at a compound annual rate of 35% from 2025. At that rate, the market more than quadruples in five years. Generative AI will account for 55.4% of the total by 2030.

Somewhere in your traffic logs, a bot is doing more than looking
Akamai has watched verified AI crawlers, ChatGPT among them, move from reading web pages to sending high-frequency POST requests. In a 30-day analysis of its global customers, ecommerce accounted for 44.8% of those AI bot POST transactions, and travel climbed to 30% in a single month.

What to do first when you get 90 days to secure AI agent data
In this interview with Help Net Security, Kelly Herrell, CEO at Nol8, explains where AI agents create exposure inside organizations. The first thing to examine is the data path: what an agent can reach, what enters its context, and where results go.

Stop watching what AI agents say and start watching what they do
In this interview with Help Net Security, Ariel Assaraf, CEO of Coralogix, explains why a system prompt can describe a boundary for an AI agent but cannot enforce one. Assaraf covers how his team builds AI agent guardrails at the execution layer, limits context without expanding authority, and tunes controls by risk so agents stay useful during incidents.

North Korea’s job interview scam runs both ways
Attackers are targeting members of the Rust Project and maintainers of widely used crates (Rust code libraries), dangling attractive opportunities to compromise their devices and accounts and, ultimately, publish malware.

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated sensitive data from 996 devices across 48 countries, GreyNoise reported on Monday. The affected switches are predominantly located in Italy, the US, Taiwan, South Korea, and a number of EU countries.

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page
Three domains / web portals belonging to Dutch academic publishing company Elsevier have been redirecting users to a page branded “LAPSUS$ GROUP, Chapter II,” carrying a signed statement that taunted the FBI and counted down to a future victim. According to Cloudskope researchers, the redirect ran for at least 78 minutes, from roughly 7:49pm CT until it was cleared before 10:09pm CT on September 21, 2026.

Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
Check Point Software has released emergency fixes for a critical Check Point Management Server vulnerability (CVE-2026-93616) that has been exploited as far back as July 23, 2026. The company also confirmed that a pre-authentication remote code execution (RCE) vulnerability (CVE-2026-85102) in Check Point (Quantum) Security Gateway for which it released patches on September 9, 2026, started getting probed a few days after.

DarkMe RAT trades zero-days for plain phishing emails
DarkMe, a remote access trojan and info-stealer that has previously been associated with a threat group that targeted financial market traders and cryptocurrency users, has been spotted again. This time around, its distribution has been simplified: instead of leveraging zero-day exploits, attackers are betting on a simple email to convince targets to run it on their machine.

OpenAI agent hacking spree widens to Australia, targeting government website
Before the Hugging Face and RubyGems hacks, autonomous OpenAI agents attempted to hack into three other websites, including an Australian government public health website, independent research lab Transluce revealed on Wednesday. Insight into the agents’ actions was gleaned from reports of tens of thousands of queries apparently made by the agents through urlquery.net, a free URL scanning service, so they could avoid access restrictions.

Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit
EU authorities are reviewing NIS2 compliance, increasing accountability for senior management while cybersecurity teams face skills shortages. This guide explains how Passwork supports NIS2 Article 21 requirements, reduces operational workload, and simplifies audit evidence collection.

Intent injection attacks are a new worry for AI-native 6G networks
Intent-based networking (IBN) lets operators state the outcome they want and leaves its translation into network policy to software, an approach AI-native 6G designs have moved to the forefront. Researchers at the University of Ottawa and Nokia Bell Labs argue that this abstraction gives attackers new openings, and it tests two machine-learning detectors against one of them.

Hackers exploit Gyazo server flaw to steal 23.6 million user records
Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in its image upload server, stealing approximately 23.62 million user records and metadata tied to hundreds of millions of images.

Scammers impersonate cops, use arrest threats to extort victims
Scammers are posing as police officers and federal agents, threatening arrest unless victims pay up, the FBI warns. The FBI’s Internet Crime Complaint Center (IC3) updated an alert it first issued in 2022, citing “losses totaling more than $1.6 billion” between January 2025 and July 2026.

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions
Scammers are using a $249 website toolkit to sell unverified AI subscriptions worth up to $2,000 a year, and a genuine Google sign-in screen is what makes the sites convincing. Malwarebytes found more than 100 websites built this way, all tied to the same toolkit and closely related developer details.

The latest deepfake numbers give CISOs plenty to worry about
AI is letting cybercriminals reach deeper into organizations than a phishing email ever could. 41% of CISOs reported at least one social engineering incident involving a deepfake during an employee audio call in the past 12 months, according to Gartner. 36% reported the same for a video call.

Researchers uncover malware that uses AI to choose its next move
To help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze the threat. The tool, called CAIRN, works entirely from metadata pulled off files. No downloading the malware, no running it.

Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes
The EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcement and private-sector partners led by Microsoft.

WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)
WordPress released version 7.1.2 to fix a critical flaw that lets an unauthenticated attacker make the software load a PHP file of the attacker’s choosing from outside the site’s active theme folders. On sites where the server and the active theme meet certain conditions, the attacker can go on to run code on the server.

Fake Claude Max giveaway tricks users into handing over their Google account credentials
A fake Claude Max giveaway uses a spoofed Google sign-in window to steal users’ login credentials, Malwarebytes researchers have found. “Browser-in-the-browser” is not a new technique. Researchers have documented it since 2022, and in June Palo Alto Networks’ Unit 42 reported a campaign that used draggable fake browser windows to target Microsoft 365 users.

80,000 relay servers help users in China slip past U.S. AI region bans
More than 80,000 relay servers are helping users in China bypass geographic restrictions on leading U.S. AI models, according to Team Cymru. Earlier this month, CISA, the NSA and the FBI warned in a joint advisory that China-based AI firms are running large-scale knowledge distillation campaigns to pull capabilities out of leading U.S. models.

GNOME 50.5 security fixes patch a gvfs CVE and Epiphany code injection
GNOME 50.5, which the GNOME Release Team shipped on September 24, patches a CVE in the gvfs file system layer, a JavaScript injection flaw in the Epiphany web browser and a use-after-free bug in the librsvg image library.

New Android malware RemControl steals banking PINs and blocks removal attempts
A new Android banking trojan called RemControl tricks victims into installing a fake TV app, then takes control of their phones to steal banking PINs, Group-IB has found. Researchers confirmed that the malware targets customers of more than 30 banks in Italy, France, Spain, Poland, Portugal, Canada and some Gulf states.

UK gears up for fight against Russia’s disinformation machine
The UK government will create a new body to track and disrupt disinformation campaigns run by hostile states, Prime Minister Andy Burnham announced at the United Nations General Assembly in New York. In his first address to the Assembly on 22 September, Burnham told world leaders he was tasking UK security chiefs to begin work on the National Centre for Information Defence, which will operate “to detect, attribute and disrupt these kinds of hostile state information attacks.”

Fake payroll desktop apps hand attackers a route to company paychecks
An attacker has been offering “desktop apps” for three large US payroll and HR platforms that have never released one, Allure Security have found. Anyone who runs the installer gets a copy of ScreenConnect, a legitimate remote access tool, configured to let the attacker control the computer without the user knowing.

MacSync info-stealing malware hides malicious commands in an iCloud calendar
A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files, according to Kaspersky. Researchers found the malware spreading through a crypto wallet app called Toria, which had its own website and was promoted on X and Telegram.

Threat detection dashboards are masking security coverage gaps
A detection rule can show up as deployed on a coverage dashboard and still never fire when an attacker uses the technique it was built to catch. Conifers assessed 14,652 detections in its customer base, including rules written by customers and detections managed by vendors in SIEM, endpoint, cloud, identity, email and network tools. The research found that 47% of detections in the average organization need attention.

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor
Forty percent of large companies had an AI-related compliance or governance issue in the past 12 months, according to 1,000 senior IT, operations, and transformation leaders surveyed by Sapio Research. Those leaders said process-related problems contributed to 84 percent of the incidents.

Gopass: Open-source command-line password manager for teams
Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement for pass, the standard Unix password manager.

Product showcase: Helmit alerts parents when online conversations show signs of trouble
Helmit is a parental control app that combines AI-powered social media monitoring with screen time management, web filtering, location tracking, and safety alerts. It identifies potentially concerning interactions and surface the messages associated with an alert.

Google hit with €403 million GDPR fine over location tracking
Ireland’s Data Protection Commission (DPC) has fined Google €403 million (about $463 million) over its processing of users’ location data and ordered the company to bring that processing into compliance within six months.

DavMail 7.0.0 puts most of its work into Microsoft Graph
Anyone who wants to leave Outlook but still has a mailbox on Exchange needs a translator. DavMail is one: a Java gateway that converts the open protocols most mail, calendar and contact apps speak (IMAP, SMTP, CalDAV, CardDAV and LDAP) into requests Exchange and Office 365 accept. “Ever wanted to get rid of Outlook?” the project page asks.

A cheap fake base station can still track 5G subscribers
Researchers from the i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe built a low-cost tool called 5G-Shark that lures a target phone onto a fake base station and questions it, then used it to audit commercial 5G networks.

The next intellectual property thief may sound like your CEO
Impersonation, phishing and domain-name abuse are the most concerning types of online intellectual property infringement, according to CSC’s The State of Online IP Risk 2026 report. Internet and branded content, online marketplaces and paid search were the channels most frequently targeted.

NetBSD 10.2 security fixes close a remote kernel bug in ipfilter
A NetBSD box at the edge of a network, filtering traffic with ipfilter, has been carrying a kernel flaw that someone outside the machine can set off. The bug is a remotely triggerable null pointer dereference in ipfilter, meaning the kernel tries to read memory through a pointer that leads nowhere. In kernel code, that usually ends with the whole system going down.

Nearly two-thirds of tested websites fail every bot test
Malicious bot activity increased 124% between July 2025 and June 2026, compared with 13.2% growth in human traffic. Traffic from AI agents and large language model crawlers rose 82.3% during the same period, according to DataDome’s State of Bot & Agent Security Report 2026.

Product showcase: Scamwise checks the red flags before you take the bait
Scamwise is a free scam-checking service from Savi that examines suspicious messages, emails, websites, phone numbers, images, and real-world situations for signs of fraud. The service works in any web browser on desktop, mobile, or tablet, with no account required.

Prismor: Open-source runtime control plane for AI agents
Prismor is a free, open-source security layer for AI coding agents. It sits between an agent such as Claude Code, Codex, or Cursor and the actions that agent wants to take, and it checks each tool call against a policy before the call runs. Every call gets one of three verdicts: allow, warn, or block.

Claude Opus 5.5 cuts costs and adds safeguards for autonomous AI
Claude Opus 5.5 is available across Anthropic’s platforms, Amazon Web Services, Google Cloud and Microsoft Azure. Developers can access it through the Claude Platform using the model name claude-opus-5-5. It includes watermarking measures designed to comply with the EU AI Act.

GPT-6 Sol and Luna arrive with 50% lower API prices
OpenAI has expanded GPT-6 with the GPT-6 Sol and GPT-6 Luna models. Both are available in ChatGPT Work and Codex for Plus, Pro, Business, Enterprise, and Edu users. Free and Go users can access GPT-6 Luna in the desktop app. The models are not yet available in Chat. OpenAI API users can access them as gpt-6-sol and gpt-6-luna.

Americans’ views on data centers have turned more negative
American attitudes toward data centers have turned noticeably more negative over the course of 2026, according to a new Pew Research Center survey. 54% of U.S. adults now say data centers are mostly bad for the environment, up from 39% in January.

Europe’s technology backbone is becoming a cyber target
Disruptive attacks on public-facing services, financially motivated cybercrime and compromises of shared technology providers are increasing cybersecurity risks across Europe. ENISA’s Threat Landscape 2026 identifies cybercrime, state-linked activity, foreign information manipulation and interference, hacktivism and vulnerability exploitation as key threats.

Ubuntu kernel CVE fixes are moving to a weekly release schedule
Ubuntu kernels will ship every week under a new release schedule from Canonical, which is merging its four-week cycle for regular Stable Release Updates (SRUs) and its two-week cycle for security fixes into a single two-week cycle. The cycles overlap, each starting a week after the one before, which is what produces a weekly release.

Your security program knows about the firewall, but does it know about the elevator?
By early August, attackers had hit water systems in at least seven U.S. states. The FBI and EPA said the intruders remotely accessed internet-facing programmable logic controllers, the small industrial computers that run pumps and valves. Operators lost monitoring or control, and in some cases water operations degraded. Federal investigators are examining possible links to Iran-backed hackers.

Claude.ai is about 3x faster after 3,000+ changes
Anthropic engineers made claude.ai and the Claude desktop app roughly three times faster during a two-week sprint in August, with Claude finding the bottlenecks and writing the fixes. The team merged more than 3,000 changes and says none of them caused a customer-facing incident or rollback.

Apple’s new iOS 27 feature looks for signs you’re being scammed
Apple introduced a scam-prevention feature called Impersonation Risk Detection with iOS 27 and iPadOS 27. The feature allows supported apps to request a risk assessment when a user takes an action that could be connected to an active social engineering scam.

Google plans to give Private AI Compute a memory that follows users across devices
Google plans to add private, server-side memory to Private AI Compute, enabling AI assistants to maintain continuity across devices while providing privacy protections normally associated with on-device processing.

Meta locks itself out of user data on its AI glasses
Meta is expanding Private Processing to its AI glasses, extending their security protections into cloud data centers. The system runs AI models inside confidential virtual machines (CVMs) designed to prevent Meta from accessing users’ data. Private Processing combines protected hardware, encryption and software verification to secure data during cloud processing and storage.

Your incident count is missing a few incidents
If you run security for a brand with hundreds or thousands of locations, the tools you’ve bought may have little to do with whether an attack stays at one store. A new VikingCloud survey asked 200 security and IT leaders at U.S. and European chains about the past year. None of the 13 security technologies it measured was tied to less spread between sites, and neither was real-time visibility. One policy decision was.

Half of threat hunters say bad data is their biggest problem
Half of security professionals name data quality or quantity as their biggest barrier to effective threat hunting, according to the SANS 2026 Threat Hunting Survey. Teams with working playbooks describe the logs as their ceiling, and gaps in cloud logging and identity telemetry come up most often.

Cybersecurity jobs available right now: September 22, 2026
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.

New infosec products of the month: September 2026
Here’s a look at the most interesting products from the past week, featuring releases from Akeyless, Akuity, Bitsight, BugBase, Cloud Range, Cohesity, Dataminr, Gurucul, Nozomi Networks, Orchid Security, Ping Identity, Scytale, Securin, Superna, and Tuskira.


from Help Net Security https://ift.tt/ZL7raOm