The Latest

Siri AI is the biggest feature of Apple's upcoming suite of updates. Whether you're running iOS 27, macOS 27, or even watchOS 27, the thing that you'll likely notice first (assuming you're running a compatible device) is that Siri is much smarter now, and even more capable than it was in previous versions. If the beta previews have been any indication, this really is the biggest upgrade Apple has ever given Siri.

But it seems that the company isn't limiting itself to the upgrades it already announced. As it continues beta testing these new updates, and with them, Siri AI itself, Apple seems to be tinkering with its new AI-powered assistant, quietly planting new features that beta testers need to discover for themselves. One such feature? A new Siri AI menu that appears whenever you highlight text in macOS 27.

How Siri AI's hidden menu works in macOS 27

As reported by MacRumors, this new menu appears whenever you select text in macOS 27. When you do, you'll see a floating menu in the top left of your highlighted text. If you move your cursor over it, the menu expands to reveal options, such as "Proofread," "Rewrite," "How does this sound?" and "Edit with Siri." You can also ask Siri AI to pull out key points from the text, or summarize it completely. Depending on the text, you might see other options, too: If you highlight a text from a friend, Siri AI might show you contact info; if the text contains a date, Siri AI might prompt you to create a Calendar entry. It plays into Siri AI's contextual awareness, which is part of Apple's mission to make its assistant more useful in specific scenarios.

The thing is, this menu is disabled by default, as least as of macOS 27 developer beta 3 and public beta 1. Apple did not include it in the release notes, either; instead, a Redditor stumbled upon it, and shared instructions for turning it on on r/MacOSBeta.

How to enable Siri AI's menu in macOS 27

Keep in mind, this feature, as with macOS 27 as a whole, is in beta testing. MacRumors says that the feature does not always work, so you may run into odd bugs or glitches after turning it on. Still, if you're already running the beta and are curious, this is an interesting feature to explore.

To try it out, you'll need to open your Mac's Terminal app. Then, paste and run the following command: sudo mkdir -p /Library/Preferences/FeatureFlags/Domain && sudo defaults write /Library/Preferences/FeatureFlags/Domain/WritingTools LightweightUI_macOS -dict Enabled -bool true

You'll need to restart your Mac for the feature to take effect. But once you do, you should see the menu whenever you highlight text—albeit with some possible hiccups. If the feature is too unstable at this point, or you simply don't like it, you can undo it by pasting the following command into Terminal: sudo defaults write /Library/Preferences/FeatureFlags/Domain/WritingTools LightweightUI_macOS -dict Enabled -bool false


from Lifehacker https://ift.tt/cnKH5Na

Picture-in-picture (PiP) is great for us multitaskers. While some prefer to pay full attention to their content, others prefer to keep videos running while attending to other tasks. I frequently have a video playing in PiP on both my iPhone and Mac, while I scan headlines, chat with friends, or take care of any to-do that only requires half my focus.

While there are ways to manually trigger PiP, it's best on mobile, as most video player apps have adopted a natural method: When you play a video, you can simply leave the app, and the video continues playing in a PiP window. It's now muscle memory for me on iOS: I head to YouTube, choose a video, and swipe out of the app, knowing my video will keep running as I move to other apps on my iPhone.

YouTube PiP is broken (especially on iOS)

Of course, like most things, PiP is only good when it works. You might have recently tried the exact shortcut I just described, only to find that nothing actually happens. You close out of YouTube, but your video doesn't follow in a PiP window. (Though it may still continue to play in the background.) And while some of you might be Android users, I'd be willing to bet most are on iPhones. What gives?

As reported by 9to5Google, YouTube is currently experiencing issues with PiP. This isn't something only a handful of users are dealing with. The problem is apparently so widespread, YouTube has confirmed the issue directly. In a statement on YouTube Help, a Google employee shared the following:

"We're aware that some of you are experiencing issues with the Picture-in-Picture (PiP) feature failing to trigger when exiting the YouTube app. While the vast majority of these reports are coming from iOS users, we are also seeing a significantly lower volume of reports from Android users...Our teams are actively investigating the issue, and we'll update this thread as soon as we have more information." At the time of writing, over 11,600 users hit the "I have the same question" button on this YouTube Help post.

Is there any way to fix PiP in the YouTube app?

Unfortunately, it doesn't seem like there is any workaround. For what it's worth, PiP was intermittent for me this morning in the YouTube app on iOS. I had no problem swiping out of a video into PiP mode during an ad, but once the video started playing, PiP didn't work. Not only that, but playback stopped as well. I went back to YouTube, played the video again, and when I left the app this time, PiP kicked in. This continued on and off, not working one time, but working the next.


from Lifehacker https://ift.tt/rGfnaTv

Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused.

About the vulnerability

ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows.

CVE-2026-6875 is a code injection vulnerability that lets unauthenticated attackers escape ServiceNow’s script sandbox and execute code remotely on a targeted instance.

The vulnerability was unearthed by Searchlight Cyber researchers and reported to ServiceNow in early April 2026.

The latter company pushed out a security update to hosted instances the very next day, and made available patches and security updates to self-hosted customers and partners last week.

The existence of CVE-2026-6875 was publicly revealed on July 13. The security advisory and warning were followed by Searchlight Cyber’s very technical post detailing the flaw.

Researcher Adam Kues describes it as exploitable in high-complexity attacks, but allowing unauthenticated code execution and full compromise of the ServiceNow instance and any connected proxy servers.

Exploitation in the wild

Defused researchers say the first exploitation attempts appeared on Friday and confirmed active in-the-wild abuse over the weekend.

They said that the observed payloads hit the same pre-authentication endpoint (/assessment_thanks.do) that Searchlight Cyber documented in its public research, but the attackers’ sandbox-escape gadget reaches the same code-execution primitive by a different route than the one in the published proof-of-concept.

With this in mind, administrators of self-hosted instances who have not yet applied the July 13th update should do so now.

The security updates also carry Guarded Script, a new feature that restricts the type of code that can run in sandbox contexts, thus making future sandbox escapes less likely.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!


from Help Net Security https://ift.tt/5eql1pa

ZoneAlarm Mobile Security is a security app from Check Point designed to protect mobile devices against phishing, malicious websites, unsafe networks, and fraudulent links. It is available for iPhone, iPad, Android, and can run on Apple silicon Macs through the App Store.

ZoneAlarm Mobile Security

Getting started

The onboarding process begins with a request for notification permissions, followed by instructions for enabling the Safari extension. Once enabled, the extension checks websites before they load to help protect browsing sessions. The app recommends granting permission for all websites to provide continuous protection.

During testing, the initial scan checked the device configuration, operating system status, SMS phishing protection, and signs of phone tampering. Results are displayed immediately after the scan, together with the time of the last check.

ZoneAlarm Mobile Security

Web and network protection

Web protection includes Link Scanning, which lets users paste a URL or scan a QR code before opening it. Each scan returns a verdict, risk level, website category, and options to open the link, report it, or dismiss the result. The app identified a standard Google URL as safe and classified it as a search engine with a low risk rating.

ZoneAlarm Mobile Security

The app includes Content Filtering, which allows users to block websites by category. Available groups include Security, Inappropriate Content, Streaming and File Sharing, Social and Gaming, and General Web Content. Each category contains configurable subcategories, allowing users to tailor filtering to their requirements.

ZoneAlarm Mobile Security

The Network section monitors encryption integrity, browsing encryption, and Wi-Fi encryption. Settings include a background security monitor, Wi-Fi Network Advisor, browser compatibility mode, and an option to extend web protection beyond Safari.

ZoneAlarm Mobile Security

ZoneAlarm Mobile Security

Final thoughts

ZoneAlarm Mobile Security offers a well-organized interface, phishing and link protection, and a comprehensive content filtering system with a wide selection of configurable categories and subcategories. Combined with QR code scanning, network security checks, and background monitoring, it provides a solid set of tools for users looking to strengthen their mobile security.


from Help Net Security https://ift.tt/2gTFStx

Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles as model capability improves.

open source AI adoption

Open source AI in 2026, in four numbers. (Source: Mozilla)

“Without investment in the infrastructure, tooling, and governance around open models, we risk locking in a system where only restrictive, closed AI can scale – and that doesn’t serve the public interest, or sovereignty over tech policy decisions,” said Raffi Krikorian, Mozilla’s Chief Technology Officer.

The capability gap between leading open and closed models has narrowed to an average of 3.3 points on Chatbot Arena, giving organizations a wider choice for production workloads. The average hides differences across tasks: open models are at or near parity in coding, instruction-following and general knowledge, while closed models retain an edge in reasoning, long-context retrieval and agentic tasks.

The price of the cheapest model offering GPT-4-class performance fell 50-fold over 36 months, from about $20 to $0.40 per million tokens. This measure uses blended API list prices and does not represent every inference workload.

Open-weight models accounted for about one-third of all tokens routed through OpenRouter by late 2025. The figures cover routed traffic and exclude first-party services such as ChatGPT and Gemini.

Deployment continues to lag adoption

79% of developers use open models, and 89% of organizations use open components somewhere in their software stack.

Just over half of organizations using open models have moved them into production. Closed models continue to reach production more often, indicating that deployment barriers extend beyond model capability.

Deployments completed with vendor partners reach production more frequently than internally developed implementations. Mozilla identifies operational tooling and organizational trust as the primary factors separating experimentation from production use.

Community support, ease of adoption and model capability receive stronger scores than standardization and enterprise readiness. The weakest results appear in safeguards, where governance, operational consistency and production maturity trail other parts of the ecosystem.

Organizations don’t spend most of their evaluation effort deciding which model to use, they integrate them into production environments that meet operational and security requirements. Small organizations recorded similar production rates for open and closed models. The difference widened among mid-size and enterprise adopters. Additional staff and infrastructure coincided with higher production rates for both model types, and the open deployment rate remained below the closed deployment rate in each larger group.

Companies need hosting, maintenance, integration, support and controls that fit their own systems.

Security and operations drive deployment friction

Developers identified infrastructure costs as a challenge, although security, privacy and compliance followed closely behind. Maintenance, deployment complexity and system integration also ranked as the most common operational concerns.

Developers who stopped using open models reported these operational issues more often than developers who continue using them. Maintenance requirements and integration challenges showed the largest increases, suggesting that production operations are a significant source of friction after initial experimentation.

The harness becomes the next control layer

Mozilla describes the agentic harness as the next major development layer. It includes orchestration, tools, memory, execution environments, permissions, identity, evaluation, observability and governance.

The harness has become the primary area where organizations differentiate production deployments. Model weights improve and become more widely available, the surrounding software determines how models are governed, monitored and connected to other systems.

Model evaluation often focuses on capability, accuracy and benchmark performance. Production deployments introduce further requirements, including identity, permissions, auditability, budget controls and operational oversight across multiple AI components.


from Help Net Security https://ift.tt/XlRjzh3

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

Week in review

Two new high severity WordPress vulnerabilities, patch immediately!
The 7.0.2 WordPress security release addresses one critical and one high severity security issue.

Cynative: Open-source deep research agent
Running a large language model against a live cloud account to hunt for security holes comes with an obvious hazard. An agent that holds real credentials and a mandate to poke around can delete a bucket, flip a permission, or leak a secret on its way to a finding. Cynative, an open-source security research agent, answers that hazard by refusing to write anything by default, and by checking that refusal on every single call it makes.

Fake OAuth client IDs are helping attackers slip past sign-in logs
Attackers running account enumeration against Microsoft cloud tenants have added a step that keeps their probing out of the usual telemetry. They spoof the OAuth client ID, the globally unique identifier assigned to an application and passed as client_id in an authentication request. Microsoft Entra ID records that value as the application ID in its sign-in logs, and the way it handles unfamiliar identifiers opens a gap that operators have started to work through.

The best defense against AI attacks turns out to be a skeptical human
Analysts across the security industry now run generative AI through their daily work, from log triage to incident write-ups. Active use in cybersecurity strategy reached 78% of practitioners in 2026, up from half the field a year earlier. The 2026 SANS AI Survey, drawn from 536 IT and security professionals, describes what that commitment costs to keep.

No one knows how many old shims can still bypass UEFI Secure Boot
Most UEFI systems trust a Microsoft-signed first-stage bootloader called Shim, which enables Linux and other boot tools to work with Secure Boot. ESET discovered that 11 outdated Shim versions (0.9 and earlier) contained vulnerabilities that could undermine Secure Boot. Microsoft revoked trust in those versions as part of its June 9, 2026 Patch Tuesday update.

“Context bombs” can frustrate AI-driven attacks, researchers found
A new approach tried out by Tracebit researchers has proven very effective at stopping AI agents from fully compromising targeted environments. What makes it notable isn’t the technique – prompt injection is old news – but the direction it’s pointed: not to hijack AI agents, but to defend against them.

GPT-Red beat human red teamers on a prompt injection test
GPT-Red is an automated red-teaming model that OpenAI trains to find prompt injection weaknesses. It works the way a human red-teamer does. It sends a prompt, watches how a GPT model responds, and iterates toward a goal such as a successful data exfiltration.

Companies keep getting breached by vulnerabilities they already knew about
Scanning tools have gotten good at their work. Organizations now find more weaknesses across more of their systems than at any earlier point in the industry’s history. A survey from the security firm Vicarius points to a gap that opens after that discovery, in the work of assigning, approving, deploying, and confirming a fix.

Ransom demands are down, email is the top way attackers get in
An employee opens what appears to be a legitimate email, clicks a link, and unknowingly hands over their password. That stolen login gives attackers deeper access to the network, and days later, files become inaccessible. Malicious email and phishing now account for half of all ransomware incidents, according to a survey of 2,158 IT and security leaders whose organizations were hit in the past year.

What public money does to open-source projects
Most of the software running inside a typical company was written by volunteers the company never paid. Open-source code sits under web apps, build pipelines, and the machine learning stacks getting so much attention right now. Roughly 96 percent of codebases carry some of it.

Reading between the lines of a cyber insurance policy
Enterprises in regulated industries often carry cyber insurance policies because contracts require it or boards ask for documented risk transfer. The global market for these policies reached about $16 billion in premiums in 2024. Coverage has become widespread. Payouts have grown less predictable.

The five step plan that cuts security budget waste
In this Help Net Security video, Viktor Bulanek, CTO of Penetrify, explains where security budget waste comes from. Budgets get built around vendor categories, compliance checkboxes, and last year’s headlines. Attackers work along attack paths, and that mismatch is where the money goes. He walks through the two big leaks, overlapping tools that flag the same issue three times, and shelfware that covers a third of the estate at 100% of the invoice.

Ransomware attack halts Coca-Cola’s Fairlife US milk production
A ransomware attack has stopped milk production at Fairlife, the Coca-Cola dairy brand known for its high-protein milk, protein shakes, and nutrition drinks. Coca-Cola disclosed the incident on July 16, 2026, in a Form 8-K filed with the U.S. Securities and Exchange Commission (SEC).

Claude can now sign into websites with 1Password without exposing your credentials
1Password has introduced 1Password for Claude, a beta integration that lets Anthropic’s AI assistant complete browser tasks requiring authentication without accessing users’ passwords or other secrets.

Scammers weaponize FaceTime to drain bank accounts
Apple is warning iPhone and iPad users that scammers are using FaceTime calls to trick them into handing over money and account details.

Spirals ransomware locks down victim systems in under 24 hours
A previously unknown ransomware strain called Spirals was used last month in an attack against an IT services company in South Asia, where attackers went from initial access to data theft and encrypting the network in less than 24 hours, according to Symantec’s Threat Hunter Team.

Security threat prompts Progress to disable ShareFile accounts, tell customers to shut down servers
A “credible external security threat” targeting Progress Software’s ShareFile Storage Zone Controllers (SZC) – the on-premises, customer-managed server components where organizations store files shared via this popular enterprise platform – has spurred the company to disable access to ShareFile accounts that are using them. The warning was sent to customers via email on July 10, urging them to manually shut down the server that is hosting their Storage Zone Controllers.

SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)
SonicWall has fixed two actively exploited vulnerabilities (CVE-2026-15409, CVE-2026-15410) affecting its Secure Mobile Access (SMA) 1000 Series appliances, and is urging customer organizations to upgrade to a fixed firmare version and search for evidence of potential compromise.

AI-driven bug hunting fuels record Microsoft Patch Tuesday
Microsoft has released patches for 570+ vulnerabilities on July 2026 Patch Tuesday, including two that are being leveraged by attackers (CVE-2026-56155 and CVE-2026-56164), and one that was previouly disclosed (CVE-2026-50661). The release was once again followed by Nightmare Eclipse publishing a stripped down proof-of-concept exploit for an unpatched Windows elevation of privilege (EoP) vulnerability, which the researcher dubbed LegacyHive.

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware
A financially motivated threat actor is impersonating hundreds of brands on GitHub and pushing a smash-and-grab infostealer masquerading as legitimate downloads of popular software, Arctic Wolf threat researchers have warned.

Why SBOMs, signing, and provenance still don’t tell you if software is safe
Software supply chain security has improved with better visibility into software components, stronger code signing, and build provenance, driven in part by Executive Order 14028. While these measures strengthen software integrity and authenticity, they still leave a critical gap: they do not reveal what the software is actually capable of doing once it runs.

The MDR renewal question: What changes when AI can handle the alerts
For most of the past decade, the managed detection and response (MDR) decision was a simple one: teams that couldn’t staff a 24/7 SOC outsourced detection and response to a provider who could. It solved a resources problem, and the alternatives (hiring a team you couldn’t afford or keeping a functional set of SOAR playbooks across an expanding alert surface) were worse.

Product showcase: Trust Chain TPRM turns vendor compliance evidence into verified assurance
Trust Chain is an AI-native third-party risk management (TPRM) solution by Strike Graph that replaces the security questionnaire model with validated evidence of compliance. Rather than asking vendors to self-report their security posture, Trust Chain requires vendors to submit evidence, which is then evaluated using Strike Graph’s patent-pending Verify AI technology.

Your vendor’s vendor might be the real breach risk
In this Help Net Security video, Chris Boehm, Field CTO, Zero Networks, breaks down how a vendor breach can become your breach. He explains that attackers now target the subcontractors behind your trusted vendors. A compromised credential at a company you have never heard of can open access into your systems, because your vendor’s vendor holds keys you never vetted.

A hardware security AI assistant that checks chips for hidden backdoors
Chip designers often license circuitry from third-party vendors, creating a risk that hidden hardware trojans could be embedded in otherwise functional designs. Researchers at the University of Florida developed VeriChat, an AI assistant that helps hardware security engineers detect these threats by answering security questions and running verification tools on uploaded chip designs.

Ransomware negotiator who betrayed clients sentenced to 70 months in prison
A former ransomware negotiator at incident response firm DigitalMint has been sentenced to 70 months in prison after admitting he shared confidential client information with the BlackCat ransomware group and later helped carry out ransomware attacks.

EU and UK blacklist Russia’s cyber operators over efforts to destabilize Europe
The EU and the UK jointly sanctioned dozens of Russian individuals and entities, accusing Moscow of coordinating a malicious cyber ecosystem targeting Europe, its member states, and international partners. The UK sanctioned 24 individuals and entities, while the EU imposed restrictive measures on nine individuals and four entities.

Hackers breach Lidl’s IT service provider, steal customer data
German discount supermarket chain Lidl has notified customers in Germany, Belgium, and the Netherlands that customer data was stolen after attackers breached one of its IT service providers. In notices published on its support websites in Belgium and the Netherlands, Lidl said it was informed of the incident last week.

New tutorials on underground hacking forums have roughly doubled
Underground hacking forums are producing more original tutorials again, with growing attention on financial fraud, particularly the theft and fraudulent use of payment card data, known as carding, and cash-out techniques. Radware analyzed 8,870 tutorial posts published across 24 deep- and dark-web forums between December 2022 and April 2026. After removing reposts, the dataset contained 3,034 unique hacking and fraud guides.

UK charges five persons linked to fraud platform behind more than a million scam calls
Five people have been charged in the UK following a National Crime Agency (NCA) investigation into Russian Coms, a caller ID spoofing service used by fraudsters.

New macOS malware steals passwords by posing as Apple’s crash-reporting tool
Jamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple’s crash-reporting tool to steal passwords, Keychain data, and cryptocurrency wallets. The malware was first spotted in May while it was still under development. By early July, Jamf was seeing in-the-wild detections, indicating it had moved into active use.

ClickFix is changing the economics of social engineering
ClickFix has moved from a one-off social engineering trick into an industrialized attack ecosystem that is outpacing conventional antivirus and endpoint defenses, according to ReversingLabs.

Spanish police dismantle €140 million cybercrime network
Spanish National Police have dismantled a cybercrime network accused of stealing and laundering about €140 million through fake investment platforms, CEO fraud, invoice fraud, and man-in-the-middle attacks.

LabubaRAT malware infiltrates Windows systems while posing as NVIDIA software
LabubaRAT, a previously undocumented Rust-based remote access tool (RAT) masquerading as NVIDIA software that enables post-compromise operations on Windows systems, has been uncovered by Blackpoint Cyber.

Police take down investment fraud network that stole €100 million a month
Dutch police, working alongside Belgian authorities and Europol, have dismantled a major criminal network accused of operating a global investment fraud scheme through dozens of fraudulent call centers.

Claude Code users keep 50% higher limits until July 19
Anthropic has extended a limited-time promotion that increases weekly usage limits in Claude Code by 50% through July 19, 2026, at 11:59 PM PT. When the promotion ends, weekly usage limits will return to their standard levels without any changes to users’ plans or billing.

Debian 13.6 security update patches over a hundred advisories in trixie
Most PCs still run with a UEFI Secure Boot certificate authority, installed by default since 2013, that has now expired. That certificate signed the bootloaders letting machines start with Secure Boot turned on. Its expiry sits at the center of the sixth update to Debian 13, codenamed “trixie.” The point release carries mostly security corrections along with a few fixes for serious problems.

Enterprises are rethinking where their AI applications run
Growing demand for compute capacity, power, cooling and low-latency connectivity is prompting organizations to reassess where AI applications run, according to CoreSite.

99.9% of fixable AI vulnerabilities remain unpatched
Organizations build, deploy, and operate AI in the cloud, but basic cybersecurity hygiene is often sacrificed for speed, according to Orca Security’s 2026 State of AI Security Report.

Microsoft demystifies how Windows updates work
Microsoft has published a guide explaining the Windows servicing model, outlining the purpose of monthly security updates, optional preview releases, hotpatch updates, and the mechanisms used to deliver new features throughout the year.

Claude Code users keep 50% higher limits until July 19
Anthropic has extended a limited-time promotion that increases weekly usage limits in Claude Code by 50% through July 19, 2026, at 11:59 PM PT. When the promotion ends, weekly usage limits will return to their standard levels without any changes to users’ plans or billing.

Chatto: Open-source team messenger with privacy at its core
Teams that want their group chats off commercial platforms have a growing menu of self-hosted options. Chatto joined that group when its developer released the code under an open-source license and posted binaries for anyone to run on their own hardware. The software aims at the same ground as the large team messaging services, and it keeps message data on infrastructure the operator controls.

Fake smart home residents could stand in for real ones in security research
Smart home security research runs on a scarce ingredient: recordings of how real people use the gadgets in their homes. Getting that data means wiring up someone’s house and watching for months, which is slow, costly, and about as invasive as it sounds. So the datasets stay small and cover a thin slice of how people live.

Microsoft Entra ID authentication overhaul to start in September 2026
Microsoft will begin rolling out passkeys as the default authentication experience for Microsoft Entra ID in the public cloud on September 1, 2026. Organizations with SMS or voice authentication enabled will automatically be enabled for passkeys. The next time users complete MFA, they will be prompted to register a passkey.

Google adds FIDO2 keys and phone passkeys to Windows login via GCPW
Google has started rolling out FIDO2-compliant physical security key support as a second factor for authentication in Google Credential Provider for Windows (GCPW) to all Google Workspace customers.

AI used to help plan the break-in, now it’s doing the break-in
Over the past twelve months, researchers documented intrusions in which AI ran exploitation workflows autonomously, generating thousands of commands across dozens of sessions with minimal human direction, according to Check Point’s AI Security Report 2026.

An AI overthinking attack can tie a robot up for over a minute
Robots that read the world through cameras now lean on large vision-language models to interpret what they see and decide what to do next. These models handle images and text together, so any words that fall inside the camera frame become part of the input. A stop sign, a street name, a sticker on a wall. Researchers at Michigan Technological University have shown that this reading habit opens a door for attackers, and the door leads to a denial-of-service problem that looks nothing like the ones most defenders track.

SingGuard-NSFA: Open-source guardrails for agentic AI
SingGuard-NSFA is an open-source guardrail framework aimed at operational threats in agent workflows. Four models ship at 0.8B, 2B, 4B, and 9B parameters, all built on Qwen3.5 base backbones.

FreeRDP 3.29.0 security update resolves 22 advisories
FreeRDP is a free implementation of the Remote Desktop Protocol, released under the Apache license, and it runs on a large share of workstations and servers through the many tools built on it. The 3.29.0 version is a security, bugfix, and maintenance update that resolves 22 advisories.

AWS retools Security Hub for AI and multicloud threats
AWS added AI workload protection and Microsoft Azure security monitoring to Security Hub, its centralized security platform for collecting and prioritizing security findings across cloud environments. Support for additional cloud platforms will follow.

Finance phishing works because it sounds boringly normal
Finance departments handle a constant flow of invoices, contracts, payment notices, and procurement emails, making email a common initial access vector for threat actors. According to Cofense, attackers exploit these workflows with phishing emails that mimic legitimate business correspondence, allowing them to bypass AI-based secure email gateways (SEGs) and other email security technologies.

VS Code agent host runs Copilot, Claude, and Codex in a dedicated process
Developers who lean on AI coding agents often keep several editor windows open at once, each tied to its own session. The 1.129 release of Visual Studio Code reworks that setup with a dedicated agent host.

Microsoft makes Windows SSO prompts easier to manage
Microsoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID.

Download: The ultimate guide to network operations management
T and security teams are managing growing complexity across networks, infrastructure, tools, and workflows. The result? Slower response, duplicated effort, and operational friction. This guide explores how intelligent workflows help teams reduce manual work, improve visibility, and move faster across network operations.

Cybersecurity jobs available right now: July 14, 2026
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.

New infosec products of the week: July 17, 2026
Here’s a look at the most interesting products from the past week, featuring releases from Cloudflare, Lineation.ai, Nudge Security, and Polygraf AI.


from Help Net Security https://ift.tt/KQxZPyn

The 7.0.2 WordPress security release addresses one critical and one high severity security issue.

wp2shell CVE-2026-60137 CVE-2026-60137

The vulnerabilities reported to the WordPress security team include:

  • CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo
  • CVE-2026-60137 – A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at Assetnote / Searchlight Cyber

Which versions of WordPress are vulnerable?

  • WordPress 6.9 is affected by both vulnerabilities. Version 6.9.5 has been released containing fixes for both.
  • WordPress 6.8 is only affected by the first vulnerability. Version 6.8.6 has been released containing a fix.
  • The beta release of WordPress 7.1 is affected by both vulnerabilities. Version 7.1 beta2 has been released containing fixes for both.

Versions of WordPress prior to 6.8 are not affected.

Emergency temporary mitigation

If this isn’t possible, Security Researchers at Searchlight Cyber note you can temporarily protect your instance by blocking anonymous access to the batch API, either by:

  • Installing a plugin that blocks anonymous access to the rest API entirely; or
  • Blocking /wp-json/batch/v1 and ?rest_route=/batch/v1 at a WAF level.

Note that both these solutions may have impact on legitimate use of the site and should only be considered emergency temporary measures until you can update.


from Help Net Security https://ift.tt/spXHBrk