The Latest

We may earn a commission from links on this page.

If someone on your gift list is looking to make their home smarter, the challenge can be daunting. There are a lot of smart products out there, all with varying price points and feature sets. What's more, smart home designs can be as simple or as complex as the user wants them to be: Maybe someone wants to be able to control their lights with the same convenient smart speaker they use to listen to music, while others might want their house running on automations.

If you're here, you likely know your giftee is looking for smart home devices but aren't sure where to start. As such, I've compiled some of the most popular smart categories and highlighted a specific product that is generally best for the majority of users interested in that type of device. (Though, with all technology gifts, my main piece of advice is asking what your recipient wants exactly—that will help eliminate risks of buying something incompatible with their systems, or something that requires a subscription they don't want to pay for.)

Best smart speaker gift: Echo Dot Max

"Smart home" encompasses a myriad of product categories, but for me, the most important is arguably the smart speaker. It's the most universal by far: A smart speaker can act as a smart hub to power the rest of your smart home, or it can be your only smart device. Maybe someone on your list wants to build out their smart home, and this is their first step, or they simply want something that can play music and tell them the weather at the same time.

It's tough to pick a smart speaker to recommend over all others, since this category is particularly platform-dependent. If your giftee is all-in on the Apple ecosystem, the HomePod mini could be the best choice; on the other hand, if they love Google products, the Google Home Speaker could be equally as solid. However, if I have to choose one speaker over all others, I'd have to go with Amazon. It's not that I necessarily think Amazon's product has the best audio quality, but I do think it's the most universal speaker of the bunch. It doesn't matter what platform your recipient depends on; they can connect their Amazon speaker to it and power any number of smart home devices. If they happen to have other Amazon devices, like a Fire TV or Kindle, even better; if not, it won't hurt.

Amazon makes quite a few smart speakers these days, but I'm focused on the best bang for your buck here. For that, the Echo Dot Max might take the cake. It's a bit more powerful than the Echo Dot, with more audio tech (Amazon says it has a tweeter and woofer, compared to the single front-firing speaker of the Dot), plus it's a more recent device (2025 vs. 2022). While you could upgrade to the Echo Studio, which has better audio tech than the Dot Max, the former costs nearly double. The Echo Dot Max seems to be the better overall value—or, you could gift someone two Echo Dot Max for a stereo setup, for the price of one Echo Studio.

Best smart lights gift: WiZ LED Smart Light Bulb

Other than smart speakers, smart lights are probably the first device that comes to mind when I think "smart home." Not only are they easy to set up and use, but they're perhaps the easiest demonstration of how your smart home works: Most people get a kick out of turning lights on and off with voice commands, as well as changing the colors on a whim.

There are a ton of smart lights to choose from on the market, with varying brands, price points, and features to consider. But if you want to get someone started with a set of smart lights, WiZ might have the best value. These smart lights run just over $20 per bulb, but drop in individual price quickly when you buy in multi-packs. A two-pack is $21.99, a three-pack is $24.99, and a four-pack is $37.99. These WiZ bulbs are CNET's pick for best smart lights of 2026, in part because of the affordable price, but also because they don't require a hub, support a wide range of platforms, and come with both color-changing and motion-sensing capabilities.

Best smart cameras gift: Eufy Eufycam C35

If you google "best smart cameras of 2026," you're going to find a host of brands and opinions out there. Ring, Blink, Arlo, Google, and more top all of the best-of lists out there, with features like pan and tilt, 4K video, AI capabilities, cloud video storage, etc. The problem is, many of the best smart camera features require a subscription, which I'm not a huge fan of for gifts. You want someone to be able to use the thing you buy them without also having to worry about a monthly or annual payment. And unless you're willing to keep that subscription going for them, you might want to find an option that works well without one.

That's why I'd lean towards the Eufy EufyCam C35. Eufy's outdoor camera is reasonably priced, especially when it's on sale (currently $54.99). It comes with two-way audio, as well as color night vision, and it supports on-device media storage. CNET recommends adding an SD card or Eufy hub for expanded local storage, and even a solar panel if you want to avoid having to recharge the camera every now and again. The video resolution here isn't as sharp as some other models, capping at 1080p, but that means less video data to worry about. Plus, the whole operation works without a subscription. If you're looking for something with more features, CNET has an excellent list of the best smart cameras of 2026.

Best smart lock gift: Yale Assure Lock 2

If someone in your life is looking for a smart lock, prepare yourself: These things can get a bit pricey. I suppose that's to be expected. If you're going to trust a piece of tech to keep your front door protected, you want it to be good at its job, which means it might tend to cost more than other individual smart home devices.

For the money, one of the best and most feature-rich smart locks you can buy is Yale's Assure Lock 2. It isn't the cheapest smart lock on the market, but it's not the priciest. For that price ($240), you get a versatile smart lock that works with all the major platforms (Alexa, Google, and Apple Home), supports digital passes, key-free unlocking, app control, and comes with a simple keypad for easy unlocking. There's even a version that comes with a fingerprint reader if your giftee is looking for a smart lock with biometrics, but that will up the price a bit more.

Now, other smart locks tend to hover around this price point, if not even higher. But if you're looking for something that isn't quite as expensive without compromising the feature list too much, check out the Ultraloq U-Bolt Pro. CNET highlights this option as a more affordable smart lock (around $110) that has keypad and fingerprint entry, as well as IP65 weather resistance. However, the big trade-off is the lack of Apple support, so if you're all in on Siri, you'll need to look elsewhere.

Best smart doorbell gift: TP-Link Tapo D225

Like smart locks, smart doorbells can get expensive fast. And like smart locks, that's for a good reason. You want your video doorbell to catch everything, whether that's a delivery made while you're away or an intruder looking for ways to break in.

For most people looking for a smart video doorbell, the best choice might just be the TP-Link Tapo D225. It's reasonably priced and comes with 2K video with a wide 180-degree angle, with both wired and wireless installation options. If your giftee doesn't feel like hard-wiring the doorbell to their house, they can get by on eight months of battery life in between charges. It also supports a number of platforms, including Alexa, Google Home, and IFTTT, though unfortunately not Apple Home. They'll also need to provide their own SD card for footage, or pay for cloud storage.

If you need an alternative, Arlo's second-generation video doorbell is also excellent, and is PCMag's pick for best smart doorbell. This option is around the same price, is easy to set up, has excellent video quality with a wide-angle view, and runs on a charge for four months at a time (though you can also hard-wire the doorbell if you wish). Arlo also doesn't support Apple Home, but it does support a wide variety of other platforms, including Alexa, Google Home, IFTTT, and Samsung SmartThings.

The big caveat here is that you will need an Arlo Secure subscription in order to access certain features. That includes motion alerts, notifications, and even recorded video, which can be a bummer if your giftee isn't interested in a subscription. As such, I'd point most toward the TP-Link option.

Best smart outdoor camera gift: TP-Link Tapo C310

Here's what I look for in a smart security camera: high-quality video, night vision support, and smart motion detection, all without requiring a subscription for many (or any) of the features. (Bonus points if there's a built-in spotlight.)

Speaking of TP-Link in the last category, I'd also recommend the company if you're looking for a smart home camera. Specifically, the TP-Link Tapo Wire-Free MagCam. This smart camera supports 2K video, color night vision, both local and cloud-based video recording, with an extended battery life running up to almost a year. Those perks, combined with its reasonable price, make it a great choice for a smart camera gift, and are why PCMag named it the best 2K wireless camera of the year. I particularly like that you don't need a subscription for any of these features, so your recipient can simply set up the camera and get monitoring.

Again, TP-Link doesn't support Apple Home, but it does support Alexa, Google Assistant, and IFTTT. It also doesn't have a mechanical pan and tilt system, so it won't be able to move to capture more of your yard. If your giftee is looking for something that supports this type of security capture, PCMag recommends Arlo Essential Outdoor Pan Tilt. This one's even less expensive than the Tapo C310, and also supports 2K video. That said, it requires payment to access recorded video and receive AI-powered alerts, and you have to use Arlo's cloud-based recording solution, as there is no local recording here. For those reasons, I'd recommend the TP-Link for more users.


from Lifehacker https://ift.tt/78bmEws

We may earn a commission from links on this page.

If you love doing your own home maintenance or tinkering in your garage, having the right tools can make all the difference. If you’re looking for new tools, keeping in mind durability, battery life, and ease of use can help you find something that will work well and save you money down the road on replacing broken tools and worn-out batteries. With so many options, it can be hard to figure out which tools are the best quality, so I put together a list of my favorites to help you choose.

This drill and driver set is my overall favorite cordless tool

The new Makita 18-volt LXT drill and driver combo set is my favorite tool this year because it has better battery life than other drill and driver sets, and the drill in this kit can deliver 70% more torque than its predecessors, allowing you to drill into tougher materials like pressure-treated lumber or plaster more quickly. The impact driver on this set also has a three-speed control switch, allowing you to choose the amount of force you want to use for a given project. This gives you the advantage of more power when you’re trying to undo an old, rusted nut, and less when you’re trying to screw a hanger into a picture frame.

The set comes with an 18-volt hammer drill, an 18-volt impact driver, a 2-amp-hour battery, a 4-amp-hour battery, a charger, and a tool bag.

Makita has been known for making reliable cordless tools since they launched the first battery-operated drill in 1969. The early in-handle batteries were easy on the wrists because they balanced the weight of the drill fairly evenly between the motor and battery pocket. The new drill and driver set has lighter batteries and builds on Makita’s reputation for ergonomic design.

This pocket hole joiner is my favorite DIY woodworking tool

The standout new tool for woodworking is the Kreg Rebel 20-volt pocket hole joiner. This is a completely new power tool that improves on Kreg’s previous jigs for making pocket hole joints by adding an integrated powered drill to the jig, improving precision and making it a simple, single-action tool. It comes with the joint-making tool, a 4-amp-hour battery, a charger, an easy-set drill bit, and dust collection attachments.

I’ve used Kreg jigs for lots of projects, like cabinet joints, shelving, and furniture builds. The added convenience of this tool saves time and allows you to make about twice as many joints in the same amount of time.

This orbital sander is my favorite finishing tool

The 20-volt MAX XR DeWalt 5-inch random orbital sander is my pick for best cordless finishing tool. It has engineering updates that improve counterbalance and reduce vibration, preventing stress on your wrist while you’re using it and reducing the numbness and tingling experienced with many sanders. Its redesigned body is more balanced, especially on narrow surfaces, and it’s easier to grip because of the new shape and battery position. The sander is a tool-only package, so you’ll need a 20-volt DeWalt battery and a charger to use it.

DeWalt makes some of my favorite cordless tools, and they’re known for making high-quality woodworking-focused tools. This tool has the power to sand down rough surfaces more quickly than previous versions of a cordless sander because it can rotate up to 1,200 OPM (oscillations per minute) and has a more powerful motor. This, combined with the decreased tool vibration, makes it my favorite cordless random orbital sander.

This cordless chainsaw is my favorite tool for yard work

My favorite new power tool for yard work by far is the EGO 56-volt 12-inch cordless chainsaw. Chainsaws are just a good time, but this one stands out because it has the equivalent power to a 55cc gas-powered saw—but it’s rechargeable and lighter. The improvements to power and utility make this tool easier to control than previous EGO chainsaws, allowing you to operate it more safely, as well as making cleaner cuts. The set comes with a 56-volt cordless 12-inch chainsaw, a 56-volt, 6-amp-hour battery, and a charger.

EGO makes the most efficient batteries for cordless outdoor power equipment. They have the most powerful, long-lasting batteries, and you can use them to cut hardwood like oak for up to 80 cuts.

This powered ratchet set is my favorite mechanics tool

Cordless powered ratchets are having a moment right now, and DeWalt makes the best one I’ve found. The new 20-volt sealed head DeWalt powered ratchet set stands out because it comes with both a ⅜-inch and a ½-inch interchangeable coupling that allows you to use a much broader range of sockets than other similar tools that constrain you to a ⅜-inch or a ½-inch attachment. It’s made to last because the gear mechanism that drives the socket head is protected from metal dust and debris, keeping it from wearing down as quickly. The set comes with a 20-volt cordless powered ratchet, a 20-volt, 2-amp-hour battery, and a charger.

This cordless ratchet is powerful enough to turn bolts for DIY oil changes, but you can also use it for DIY appliance repair like changing out the drum in your washer.

This cordless tire inflator is my favorite new tool under $100

Ryobi is known as a solid DIY standby because it makes affordable cordless tools that are durable enough for most home shops and DIY projects. Their new 4-volt rechargeable cordless tire inflator has a 150 PSI rating that allows you to top off a car tire in about 90 seconds. This tiny powerhouse is perfect for an emergency car kit because it’s compact and powerful enough to inflate a tire in a pinch. The set comes with a cordless tire inflator, a hose, bicycle and passenger vehicle connectors, a 4-volt battery, and a charging cable.

This update to a previous version of this tool, which was mainly useful for bike tires, allows you to more practically use it for inflating tires on larger vehicles.


from Lifehacker https://ift.tt/MeXUCA1

Bitsight access to a broad risk dataset, combining threat intelligence and continuous exposure monitoring to help teams mitigate risk across the supply chain.

“The surge in third-party-originating cybersecurity breaches demands a fundamental shift in how cybersecurity leaders and their teams manage third-party cybersecurity risks,” said Gartner. “Cybersecurity leaders must shift from a prevention-only mindset to one that prioritizes quick detection, minimizes the impact of incidents, and thoughtfully leverages AI to improve processes.”

Yet most organizations remain too separated in structure, workflow, and data to make this shift. Security operations teams have visibility into exposure and threats facing their own enterprise but lack the same visibility and reach across the extended supply chain. Third-party risk teams can coordinate with at-risk vendors but frequently lack the threat intelligence to proactively engage. As a result, third-parties account for almost half of enterprise breaches, up over 60% from last year.

Bitsight is bridging this divide by enabling security and risk teams with the ability to operate from a single intelligence platform to identify exposure across the supply chain, add real-time context to active threats, and prioritize remediation workflows and activities.

The new capabilities that connect teams and bring trusted cyber risk intelligence directly into AI workflows include:

  • Bitsight Beacon (now generally available) addresses one of the hardest challenges facing security leaders, organizations usually have limited and delayed visibility into exposure across their supply chain, making it an impossible attack surface to secure. Bitsight Beacon continuously monitors critical vendors for exposure and vulnerabilities, malicious activity, intrusion, stolen credentials, and compromise—giving security teams what they need to investigate and risk teams what they need to drive vendor action.
  • Bitsight Model Context Protocol (MCP) and agentic capabilities help customers manage growing alert volumes without adding more manual analysis. MCP and agents bring Bitsight’s continuously updated intelligence directly into AI-enabled workflows, grounding analysis and decisions in trusted cyber-risk context. In just one month, more than 400 customers signed up for early access, underscoring the need for trusted intelligence in AI-enabled workflows.

“AI is upending the threat landscape,” said John Clancy, CEO of Bitsight. “As models advance, every connection across the supply chain becomes a potential path for business disruption. Bitsight is uniquely positioned to help risk and security leaders meet this moment, opening access to over a decade of contextualized, prioritized, supply chain intelligence to mitigate risk.”

Helping customers manage risk

By connecting exposure with active threat intelligence and business context, the platform is helping customers solve three of their greatest challenges.

  • Too many signals, less certainty about what matters. Bitsight continuously maps assets, technologies, vulnerabilities, vendors and dependencies to show where exposures exist and what they affect.
  • Threats moving faster than teams can respond. Bitsight connects exposure with active threat intelligence and business context to identify what requires immediate action.
  • Disconnected processes slowing action. Bitsight gives security teams the technical evidence to investigate and risk teams the context to drive remediation—all from the same intelligence.

“Discovering and validating areas of concentrated risk across a large digital footprint can be challenging,” said Jason Adams, Director of cybersecurity at Cornerstone Building Brands. “Bitsight makes it easy by automatically digesting thousands of risk vectors into an at-a-glance view so we can quickly pinpoint risks by severity, prioritize remediation efforts and drive continuous improvement.”


from Help Net Security https://ift.tt/vYqFuSn

The EU Agency for Cybersecurity switched on the Cyber Resilience Act‘s Single Reporting Platform on 11 September 2026, the same day the law’s reporting obligations started binding manufacturers. ENISA built the tool and runs its day-to-day operations, a job Article 16(1) of the CRA hands to the agency.

CRA Single Reporting Platform

Anyone placing a product with digital elements on the EU market now reports actively exploited vulnerabilities and severe incidents through that one portal. The clock starts when the manufacturer becomes aware of the event. An early warning is due within 24 hours, a fuller notification with an initial assessment within 72 hours, and a final report within 14 days of a corrective or mitigating measure becoming available. For a severe incident, the final report is due one month after the 72-hour notification.

One submission, then the CSIRTs pass it along

A manufacturer files electronically and picks a CSIRT designated as coordinator, the national incident response team that takes first receipt. That team forwards the notification to CSIRTs in other Member States where the product is available. ENISA gets a copy at the same moment, unless the manufacturer marks one of the exceptional circumstances in Article 16(2), in which case ENISA sees partial information until the receiving CSIRT makes the rest available.

Picking the coordinator is the manufacturer’s job. In general it is the Member State of your main establishment in the EU, where decisions about your products’ cybersecurity are predominantly taken. Choose the wrong one and the notification may be invalidated and has to be resubmitted to the correct coordinator.

Registration runs on an EU Login account with multi-factor authentication. Each manufacturer gets one Primary Assigned Representative and up to 20 Secondary ARs, and the designated CSIRT validates the association. An AR whose association is still pending may file up to 20 notifications before verification becomes mandatory.

“The streamlined reporting and sharing of information on actively exploited vulnerabilities and severe incidents helps to build a more resilient Digital Single Market,” said ENISA Executive Director Juhan Lepassaar.

What the first release leaves out

No API ships with this version, so notifications go through the web interface. ENISA says organizations can automate their internal workflows and may get API functionality in a future phase. A vendor with several affected product lines still types one notification per event into a form, and coordinates across its branches and subsidiaries so that exactly one goes in.

The platform is in English at launch, with translations of the supporting material to follow. Voluntary reports of vulnerabilities, cyber threats, incidents and near misses under Article 15 are planned for a later phase. Open-source software stewards come under the same obligation on 11 December 2027.


from Help Net Security https://ift.tt/iPFHjI6

Cybersecurity attention often rises after an incident, then recedes as organizations return to their existing priorities and practices, according to a new ManageEngine survey of 700 IT and cybersecurity leaders in the US and Canada.

cybersecurity breach confidence

(Source: ManageEngine)

All of them had already been through a breach or incident. Still, 91% said they trust their organization’s current cybersecurity posture. Only 8% said cybersecurity becomes a permanent priority once the incident is behind them.

“The belief that breaches are inevitable has lowered the bar for security,” said Dr. Erik Huffman, a cyberpsychology researcher who commented on the findings. “We’ve said ‘it’s not a matter of if, but when’ for far too long. But we still have control over the security processes that directly influence the outcome.”

Confidence that outpaces prevention

A third of respondents believe a major incident is inevitable regardless of their defenses, and a similar share accept the risks they consider manageable. Known gaps often stay open until an audit or an actual incident forces the issue. Only a minority said security gets consistent attention throughout the year, outside the aftermath of an incident.

“It is unfortunate that we have accepted the idea that bad things will happen no matter what we do,” he said. “Many organizations buy security tools in pursuit of the outcome of being ‘secure.’ But security cannot simply be bought or sold. It is an ever-evolving process and should be treated as such.”

The urgency fades fast

Right after a breach, organizations do react. Process discussions ramp up, urgency spreads through the team, and technical fixes go in, such as patching, access reviews, and backup improvements. That attention rarely lasts. Eighty percent of respondents said increased focus on cybersecurity holds for only one to six months before it fades.

Close to half of organizations kept their existing structures and strategy in place after the incident, making no wider change at all. A smaller share made targeted fixes aimed at the specific gap that caused the incident, and fewer still made broader, long-term changes to governance, training, or escalation.

Business priorities are often the reason why. A majority of respondents said competing demands regularly cause security initiatives to be postponed or downgraded, and one in five named exactly that as the leading factor behind their most recent incident.

Fear shapes what gets said after the fact

Most employees, according to respondents, report a mistake immediately when it happens. 83% admitted that fear of consequences influences how the incident is handled once it’s reported, and a notable share described their organization’s response as blame-focused.

“Cybersecurity has had a fear-based culture for a long time, and it has created an environment many people want to avoid,” Huffman added. “Incident response should not be about who did what. The focus should be on what happened, why it happened, and who it impacts.”

Part of the problem, according to the survey, is that ownership itself is unclear. Close to one in five respondents said they weren’t sure whether security, IT, or business teams should be responsible for a given failure. That uncertainty carries a cost, including delayed remediation, business disruption, and a higher risk that data ends up exposed before anyone closes the gap.

AI recommendations often go unchecked

AI use is widespread among these organizations, running incident response automation, threat intelligence, penetration testing, and vulnerability scanning. A large majority said it has made decisions easier to reach, and more than half credit it with greater efficiencies or stronger security capabilities. AI has also made a majority of respondents more willing to accept cyber risk.

Among organizations using AI in cybersecurity, about two in three said they often or always act on its recommendations without additional verification.

“AI undoubtedly introduces new risks for organizations,” Huffman noted. “LLMs are frequent targets for attackers because of the level of trust people place in the information they receive from AI systems. We need to move from ‘trust but verify’ to ‘verify, then trust.'”

“Organizations that genuinely learn from incidents aren’t just the ones that respond quickly. They’re the ones that preserve visibility after the crisis, make risk decisions explicit, and turn temporary urgency into lasting discipline,” researchers concluded.


from Help Net Security https://ift.tt/9rMPpRs

AWS’ Deception Benchmark measures how well AI models distinguish genuine security vulnerabilities from code that looks risky but is safe. AWS is making it publicly available so researchers can use the dataset and evaluation process without repeating the cost of generating and refining the samples.

Security teams use AI for vulnerability triage, penetration testing, threat modeling, incident response, and code review. High false-positive rates can create more work, increase alert fatigue, and reduce confidence in legitimate findings.

The benchmark contains 14,822 samples across 16 programming languages and more than 70 Common Weakness Enumeration (CWE) categories. AWS evaluated 12 models from five providers.

Why another security benchmark?

Existing benchmarks test AI on a range of cybersecurity tasks. CyberGym includes more than 1,500 realistic tasks, Meta’s CyberSecEval covers capabilities such as exploit generation, and CYBENCH focuses on capture-the-flag challenges. ExploitGym tests whether models can go from finding a vulnerability to producing a working exploit.

AWS’ benchmark focuses on a different problem: When a model says code is vulnerable, can it tell a real vulnerability from a false positive?

That can be difficult because code may contain a dangerous pattern while another control prevents it from being exploited. The model has to understand both the code and the protections around it.

How the benchmark works

AWS calls it the Deception Benchmark because its safe samples are designed to mislead models. They contain real vulnerability patterns alongside protections that prevent exploitation. Models must decide whether each sample is vulnerable or safe without being given hints.

“Production tools rely on multi-step loops and agentic workflows to compensate, but that scaffolding masks whether the model itself understands the code. This benchmark strips the scaffolding away and asks the model to make the call in a single pass, so what it measures is understanding, not how many tries a harness takes to get there,” Anshumali Shrivastava, Amazon Scholar, and Neha Rungta, Applied Science Director at AWS Identity, explained.

AWS generated examples, tested them against frontier models, and made them harder when models classified them correctly. Samples that models could easily classify were excluded. According to AWS, generating and refining the samples consumed tens of billions of tokens.

Of the 14,822 samples, 9,695 are scored. These include 6,988 code-level and 2,707 environment-gated challenges.

Code-level challenges have vulnerable and safe versions separated by a small change. Both may look unsafe, but only one can be exploited.

Environment-gated challenges test the same kind of code under different deployment conditions. For example, a Kubernetes Network Policy may block an SSRF attack that appears possible from the code alone. The model must take those protections into account.

AWS publicly releases the samples but withholds their labels. The dataset also includes 5,127 unscored samples mixed with the scored ones. Users submit their predictions to AWS for verified scoring. This setup is intended to make it harder to optimize specifically for the benchmark.

Checking the labels

Multiple independent reviewers check each label without seeing other reviewers’ decisions or the reasoning behind the original label. Disagreements receive further review, and unresolved cases go to human reviewers.

AWS repeats this process until fewer than 3% of scored samples remain contested by independent reviewers, with a target of fewer than 1% surviving human review. Samples that remain disputed are moved to the unscored set instead of being relabeled.

The company also reports that a human review of 100 randomly selected scored samples found no labeling errors.

Models struggle with false positives

The benchmark is roughly balanced between vulnerable and safe samples, so random guessing would score about 50%. AWS considers false-positive and false-negative rates below 10% a minimum bar for production use. None of the tested configurations met both thresholds.

AWS Deception Benchmark

FPR compared to FNR for 12 models across two prompting strategies. No model reaches the generous bar. (Source: AWS)

With direct prompting, models generally found nearly all real vulnerabilities, but incorrectly flagged 41% to 99% of safe code. Precision ranged from 52% to 71%. Asking models to prove that a vulnerability could actually be exploited reduced false positives by 17 to 74 percentage points. The downside was more missed vulnerabilities, with false-negative rates ranging from 7% to 44%. Models had the most difficulty when external security controls made suspicious-looking code impossible to exploit.

AWS tested general-purpose models with single-turn prompts, not purpose-built security systems that use tools and multiple validation steps. The results therefore should not be treated as a direct measure of how complete security products perform.


from Help Net Security https://ift.tt/o4FwXxN

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

Week in review

Zero trust AI agents demand a different kind of security
In this interview, Chris Webber, VP, Product Marketing at Teleport, explains why zero trust principles need to change for AI agents. He covers how agents act fast, unpredictably, and continuously, and why old ideas like least privilege and point-in-time verification fall short.

AI-Infra-Guard: Open-source security scanner for AI systems
Tencent’s Zhuque Lab built AI-Infra-Guard, an open-source security scanner for AI systems. It fingerprints running services such as Ollama, vLLM and ComfyUI and checks them against more than 1,600 known CVEs, inspects MCP servers and agent skills across 14 categories of risk, and runs jailbreak evaluations against a target model.

Kevin Mandia joins the Amazon board with 30-plus years in cybersecurity
Amazon elected Kevin Mandia to its Board of Directors on September 8. Mandia founded Mandiant and served as its CEO before Google acquired the firm in September 2022, and he has worked against cyber threats in the public and private sectors for more than 30 years.

Getting a stranger’s phone kicked off the cellular network costs a few dollars
Researchers at Michigan State University and three partner schools bought a Samsung Galaxy Z Fold 7, copied the identification number printed on the sealed box, and reported the phone to its carrier as lost. Then they opened the box and set the phone up the way a launch-day buyer would. It would not connect. The phone was new, unopened, and sitting on a lab bench the entire time. The team found six weaknesses in the system carriers use to shut off lost and stolen phones, spanning the devices themselves, the carrier systems that take the reports, and the machinery carriers use to share block lists.

Trezor customers hit with phishing calls and letters after shipping-partner breach
Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone numbers, and shipping addresses were exposed.

“Zero-click” WeChat worm could hijack accounts and spread via a single call
Researchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create “WeWorm”, a worm that spreads via WeChat calls without any user interaction.

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor
September 2026 Patch Tuesday is here, with Microsoft delivering another record-breaking number of patches, including those for two vulnerabilities that have been exploited as zero-days.

Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a network.

What breach and attack simulation needs to become in the AI era
Breach and attack simulation (BAS) has always had a supply chain. Somebody has to read the threat report, pull out the techniques, and turn them into something that will actually run against your controls. That somebody has always been a human red team. Up until a few months ago, turning a major new threat into working simulation content within 24 hours counted as very fast.

Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results
Gartner predicts that by 2028, 70% of large SOCs will pilot AI agents, but only 15% will see measurable gains without structured evaluation. The technology has already moved from Gartner’s Innovation Trigger to the Peak of Inflated Expectations. Prophet Security reports that 40% of security teams use AI daily, 56% are evaluating or piloting it, and just 4% have no plans to adopt.

Ransomware negotiation tactics have turned into a business process
In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware negotiations.

Building a ransomware decision tree before the call comes in
In this Help Net Security video, Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walks through the ransomware decision tree in this video. She covers four areas where decisions need settling in advance, starting with containment.

18 ways to check whether data can be trusted for AI
ETSI has published TR 104 180, a technical report that defines 18 metrics for measuring data quality, giving companies a way to check whether their data is good enough for AI before they use it. The report defines each metric and includes the formulas needed to calculate it.

Attackers use rogue ScreenConnect clients to spread malware
A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed. Until a fix is available, ConnectWise recommends that partners disable file transfers for technicians.

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)
N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular with managed service providers (MSPs). In its release notes, N-able described CVE-2026-86218 as a “critical-CVSS-rated vulnerability that could allow for pre-authenticated remote code execution on the N-central server.”

Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication
Attackers are exploiting a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH open to the internet, CERT Polska found. They have discovered six vulnerabilities in RouterOS and coordinated their disclosure with MikroTik. Among the six, two combined let an attacker take full control of a device without authentication, provided the device has SSH accessible from the internet. They named this exploit chain MikroTrick.

Mathspace breach exposes data on over a million students and parents
Mathspace has confirmed that attackers broke into its internal reporting system through an unpatched Metabase vulnerability and stole data belonging to more than a million students, parents, and school staff. The Sydney-based maths education company wrote in a blog post that the vulnerability, in its self-hosted installation of Metabase, allowed attackers to obtain administrator access to the system without a legitimate login.

IT help-desk vishing tricks executives into handing over Microsoft 365 access
IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and other SaaS accounts, according to Arctic Wolf.

Threat actors are giving AI agents a bigger role in cyberattacks
AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker.

Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)
Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. The fix has been shipped in Chrome 153.0.8010.36 and .37 for Windows and macOS and Chrome 153.0.8010.36 for Linux.

Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory
A rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos. F5 BIG-IP APM provides access policy enforcement to secure access to apps, APIs, and data. It’s primarily used by enterprises, financial institutions, government agencies, and public sector organizations.

$245 million in stolen crypto funded racketeering crew’s lavish lifestyle
A 22-year-old man built his fortune by breaking into strangers’ digital wallets, then spent it on nightclub tabs, private jets, and a fleet of cars worth millions. Malone Lam, a Singapore citizen, pleaded guilty this week in a Washington D.C. federal court to running a racketeering conspiracy that stole and laundered more than $245 million in cryptocurrency.

OpenSSL’s new alpha build speeds up post-quantum crypto
The OpenSSL project released the first alpha of OpenSSL 4.1.0, giving developers an early look at a version built for encrypted communication over unreliable connections and faster post-quantum cryptography. This marks the opening test build for a version still months from general availability.

Cybercriminals are building phishing pages that exist only inside victims’ browsers
A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, according to researchers at Barracuda.

Fake GTA 6 download delivers malware-packed bundle to impatient gamers
Grand Theft Auto VI (GTA 6) is still three months from release, but cybercriminals are not waiting for the launch date. Security firm Huntress found malware disguised as a leaked copy of the game, aimed at fans hoping to get their hands on it early.

Attackers call employees’ personal phones to break into Microsoft 365 accounts
Attackers are calling or texting employees on their personal phones, posing as internal IT staff, in a social engineering campaign that tricks them into handing over access to corporate cloud accounts. Once inside, they pull files and email from Microsoft 365 apps, SharePoint, OneDrive, and inboxes, for weeks at a time, according to Microsoft Security Research.

IDScan confirms breach after 153 million driver’s licenses leak on dark web
Days after reports linked IDScan to a dark web database holding more than 153 million driver’s license scans, the identity verification company has confirmed hackers accessed customer data stored on its cloud platform.

AI agents exploited PaperCut flaws to breach 395 organizations
A threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the work on their own, according to GreyNoise.

ToolHive: The open-source way to run any MCP server securely
ToolHive is an open-source platform that runs Model Context Protocol servers inside containers. An MCP server is the connector that lets an AI client like Cursor or Claude Code reach an outside tool, and Stacklok ships ToolHive under Apache 2.0, so the runtime, the Kubernetes operator, and the registry cost nothing to self-host.

OpenAI just hit a milestone on the road to self-improving AI
OpenAI has announced that it has reached a goal set last fall of having an automated research intern by September 2026. The milestone means a system can carry out well-defined research tasks under human direction, including work that would take a skilled researcher several days. The company is also working toward creating an automated AI researcher by March 2028.

Microsoft’s Project Zenith puts large AI models directly on developer PCs
Microsoft’s Project Zenith is a ready-to-code Windows 11 experience for developer-class PCs capable of running AI models with more than 30 billion parameters locally without relying on metered cloud tokens. Designed for systems with at least 64 GB of unified memory and 250 GB/s or more of memory bandwidth, it pairs powerful hardware with a preconfigured software environment for coding, testing, and experimentation.

Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins
Jellyfin shipped version 12.0 of its media server. Several of the security fixes in it block requests built to reach files outside the folders the server is supposed to hand out. The rest of the security work touches first-run setup, plugin installs, parental controls, and the web interface.

BleachBit 6.0.4 fixes secure wiping that skipped clusters on Windows
The open source cleaner BleachBit reached version 6.0.4 this week, erasing caches, browser traces, and files on Windows, Linux, and now macOS. If you shredded a sensitive file on Windows with an earlier build, parts of it may still sit on the disk where the wipe missed. Fragmentation is the ordinary case, since Windows scatters a file across noncontiguous clusters whenever it cannot find one open run large enough to hold it.

AWS spent years rebuilding its routing control plane without taking the network down
Every AWS API call, CloudFront video stream, and Route 53 lookup crosses the same infrastructure, which AWS calls its border network. It now runs on a routing system rebuilt from scratch over several years.

Chinese AI firms are siphoning capabilities from American models, CISA warns
China-based AI companies are using large-scale knowledge distillation campaigns to copy capabilities from leading U.S. AI models, according to a joint cybersecurity advisory from the CISA, NSA, and FBI.

A new open standard locks AI weights to approved hardware
OPAQUE, a confidential computing company that runs AI workloads inside hardware-isolated environments so operators cannot inspect them, released an open standard that lets AI model builders decide when and where their weights can be decrypted once those weights leave the builder’s own servers. The standard, called Weight Custody Manifest, ships as a developer-preview specification, a Python SDK, and a public test suite covering 91 cases.

AI adoption brings new security headaches for already stretched CISOs
CISOs are taking on AI governance without a matching increase in resources or expertise, adding to an already broad remit spanning data protection, identity, resilience and compliance, according to Proofpoint’s 2026 Voice of the CISO report.

Apple is building photo verification for the people who need it most
Apple has introduced Apple Reference Image, an opt-in feature designed to verify the authenticity of photos taken with iPhone 18 Pro models. The company will also add support for the SynthID standard in a software update later this year, helping identify images generated or edited using AI.

WordPress adds automated security checks to block risky plugin releases
WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential security risk will be blocked automatically.

Your passkeys can now move between password managers on Android
Google turned on a transfer feature in Android that moves passwords and passkeys straight from one password manager to another, with no file to download along the way. You start it from inside the app you are switching to, and Google says the data moves between the apps in a few seconds.

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors
Canonical shipped Ubuntu 24.04.5 LTS, bundling security updates and fixes for high-severity bugs into new installation media for the “Noble Numbat” release. Anyone installing fresh now gets those corrections baked in from the start, cutting the batch of updates that would normally follow setup.

AI is changing what Salesforce security needs to govern
Existing security and governance practices have largely focused on identities, permissions, access, configurations and controls. WithSecure’s Navigating Trust in the Modern Salesforce Ecosystem paper says Salesforce environments also require organizations to understand what information they rely on, how trust extends across connected systems, what actions are performed and what outcomes those actions produce.

Companies may be measuring phishing resilience the wrong way
Companies that judge phishing simulation programs by how often employees click simulated attack emails may be overlooking more important indicators of cyber resilience, according to Pistachio’s Phishing Behaviour Report 2026.

Product showcase: Doppler secures secrets for humans, pipelines, and AI agents
AI agents have expanded the secrets management challenge. Coding agents, automated workflows, and MCP servers create more identities that need credentials, and more places those credentials can leak. Doppler centralizes credentials for engineers, pipelines, and AI agents in one easy-to-use control plane. It gives security teams a critical secrets management tool developers use, available in the cloud or on-prem.

Product showcase: GitGuardian Honeytoken catches credential theft as it happens
GitGuardian turns credential harvesting into an immediate, high-confidence detection signal. It deploys honeytokens across developer fleets so that when an infostealer scans a machine and validates a decoy, defenders know within seconds.

Cybersecurity jobs available right now: September 8, 2026
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.

New infosec products of the week: September 11, 2026
Here’s a look at the most interesting products from the past week, featuring releases from Akeyless, Orchid Security, Scytale, and Securin.


from Help Net Security https://ift.tt/CT3gqIJ