The Latest

We may earn a commission from links on this page.

As much as Hollywood has been wringing its hands over franchise fatigue, consider this: In July, a Spider-Man movie made $168 million at the box office in one day, and the top streaming series was a Game of Thrones spinoff.

Fortunately, if you are hungering for something original, you can still catch innovative comedy series like The Bear and Widow's Bay, or tense thrillers like FROM and Cape Fear (well, OK, that last one is a remake of a 1990 Martin Scorsese movie that was a remake of a 1962 Gregory Peck movie that was an adaptation of a book, but the point stands). Here are all of July's most-watched series, according to data from streaming information repository JustWatch.


House of the Dragon

Seems we still aren't sick of dragons and incomprehensible political intrigue: The third season of House of the Dragon, the Game of Thrones prequel based on a fake history tome by George R.R. Martin, came roaring back to the top of the streaming charts. With the season finale landing this weekend, fantasy fans will have to wait until the arrival of season two of A Knight of the Seven Kingdoms for their next Westeros fix. You can stream House of the Dragon on HBO Max.

Silo

Another book adaptation returning for a third season, Apple TV's Silo continues to track the downward spiral of the dregs of humanity, living together underground in a cavernous edifice that goes all the way down. If you've been wondering how things got so bad, this season goes back in time to reveal the source of humanity's downfall. (Unsurprisingly, humans are to blame.) You can stream Silo on Apple TV.

The Bear

Across four seasons, we've watched neurotic chef Carmy (Jeremy Allen White) flame out as an elite chef, return to his humble beginnings in his family's Chicago sandwich shop, try to turn said sandwich shop into a fine dining establishment, experience ups and downs in his business and personal life, and finally, at the end of season four, quit the food industry altogether. Taking place mostly over the course of a single day, the fifth and final season explores the immediate aftermath of that monumental decision—on Carmy, and the rest of the restaurant's partners and kitchen staff. It's a fitting goodbye for one of the most lauded TV series ever. You can stream the final season of The Bear on Hulu.

Widow's Bay

This series from Apple TV has won nearly unanimous praise from both critics and audiences. It's a rare horror-comedy that manages to be genuinely scary and really funny. In the island town of Widow's Bay, literally everything is haunted, cursed, and otherwise beset with unspeakable evil, but Mayor Tom Loftis (Matthew Rhys) still really wants to bring tourism to the island. Mayor Tom is so married to his vision of Widow's Bay as the next Martha's Vineyard, he ignores the sea hags, fog monsters, and serial-killer ghosts surrounding him. The great Stephen Root plays Wyck, an old-timer who's always there to remind everyone that time is short and everyone is doomed. You can stream Widow's Bay on Apple TV+.

Lucky

Based on the bestselling novel by Marissa Stapley, Apple TV's latest hit stars Anya Taylor-Joy as the titular con artist. Her name proves to be a tad ironic after her latest job goes wrong and she finds herself the prime target of both the cops and the dangerous crime boss—who also happens to be her mother-in-law. Annette Bening is clearly having a grand time playing the ruthless Priscilla Masterson, who blames Lucky for the loss of $10 million she and Priscilla's son Cary (Drew Masterson) stole—never mind that Cary eventually ran away with it. With a supporting cast that includes Aunjanue Ellis-Taylor and Timothy Olyphant, it's a fast-moving thriller with a sense of humor and an irresistible lead character. You can stream Lucky on Apple TV.

Ride or Die

This London-set series stars the ultimate odd couple. Octavia Spencer plays Debbie, the American wife of a British politician, and Hannah Waddingham plays her good friend Judith, who happens to be a master assassin. After a hit gone wrong, Judith must go on the run to stay ahead of another assassin working against her, and to avoid running afoul of the ruthless agency (literally called The Agency) that employs her. Obviously, Debbie gets pulled along for the ride. It's a fast, tense, and funny thriller series. You can stream Ride or Die on Prime Video.

I Will Find You

Like Max Cady in Cape Fear, the main character in I Will Find You has been imprisoned for a murder he did not commit. But unlike Max Cady, David Burroughs (Sam Worthington) doesn't set out to murder his lawyer. He was accused of killing his own son, and when he sees evidence that the boy is alive, he escapes prison to find his child. It's a modern take on The Fugitive: with the authorities on his trail, David must unravel a twisting conspiracy to clear his name and bring his child home. I Will Find You is a perfect summertime thriller. You can stream I Will Find You on Netflix.

FROM

The residents of the unnamed town at the center of FROM cannot catch a break. If it's not worms crawling around under their skin, it's the mysterious Man in Yellow stealing people's souls. Season four of this mystery-heavy show from the executive producers of Lost sees the survivors pushed to their limits as the veil between the strange town and the real world gets thinner. You can stream FROM on MGM+.

Cape Fear

Executive-produced by Steven Spielberg and Martin Scorsese, Cape Fear is a 10-episode reimagining of a classic novel that has previously been adapted into two celebrated films. In this extended version, Amy Adams plays Anna Bowden, a defense attorney who unsuccessfully defended murder suspect Max Cady 17 years previously. Turns out he wasn't guilty, and Cady has had nearly two decades to plan his revenge against the woman he blames for putting him behind bars. Javier Bardem brings unsettling energy to the role of Cady, previously played by Robert Mitchum, Robert De Niro, and Sideshow Bob. If you like slow-burn suspense that gradually ratchets up tension, you'll like Cape Fear. You can stream Cape Fear on Apple TV+.

The Agency

The spy thriller returns for its second season. Michael Fassbender plays Brandon Colby (code name Martian), a former CIA field agent who now runs operations for London Station, the agency's home office in the U.K. This season, the spy action grows more intricate, as Martian works to clear the name of his lover (Jodie Turner-Smith) while also going head-to-head with a possible double agent within the Agency's own ranks. You can stream The Agency on Paramount+ With Showtime.


from Lifehacker https://ift.tt/2sMl8EU

Stellar Cyber, the full-cycle AI-native security operations platform company, today released results from an independent study of 124 days of customer trials of its Agentic Auto Triage capability.

Stellar Cyber Agentic Auto Triage

The independent study based on customer trials evaluated 138,475 real security alerts and reached the same verdict as human analysts 99.7% of the time. The findings, drawn from customer-submitted end-of-trial reports, addressed the central question facing every security team weighing autonomous SOC technology: Can AI actually be trusted to make decisions?

AI-driven tools have made it easier than ever for adversaries to design highly convincing phishing and ransomware attacks. In response, organizations have doubled down on security awareness and training, resulting in a surge in reports of potential threats. The World Economic Forum reports potential security threats have surged dramatically over the last two years, with ransomware attacks jumping by up to 48% year-over-year and phishing attempts exploding by 1200% since late 2022. This escalation is largely driven by GenAI-enhanced tactics. Automatic Triage, powered by Agentic AI, levels the playing field for human security analysts by automatically ingesting, correlating, analyzing, and prioritizing suspicious events from the user’s environment.

Finding #1: Auto Triage returns 19 minutes of every hour, translating to 1 day a week of productivity

Across the trials, Auto Triage returned roughly 19 minutes of every analyst hour to higher-value work, including working more cases per shift and dedicating more time to exposure management, anticipating adversary behavior, and closing exposures. This time translates to about one day per week per analyst, or the equivalent of 1.5 full-time analysts reclaimed annually.

By closing out confident false positives and surfacing real threats before a human ever opens them, Auto Triage reduces noise, helps teams move from an alert-centric mode to a case-management mode, and transforms the job of the human security analyst. This shift helps improve MTTD and MTTR while giving analysts time to think like attackers, anticipate likely attack paths, and close visible gaps before they are exploited.

“Security operations have reached a tipping point. The volume and complexity of alerts are simply beyond what human analysts can manage alone,” said Aimei Wei, CTO at Stellar Cyber. “This real-world study proves that our approach of combining machine-speed analysis with human judgment is the right way forward. These results show what that looks like in practice: the AI does the alert work at scale, the analyst stays in control, and they almost always agree—freeing analysts to manage more cases and get ahead of emerging exposure.”

Finding #2: 64% of False Positives closed; 15% of True Positives escalated

Using machine learning models trained on real-world phishing patterns, the platform delivers reliable, actionable verdicts in seconds. Auto Triage assigns each alert a decision through an AI-driven Verdict Signal Check, with human-in-the-loop oversight and a closed-loop learning process that improves accuracy over time.

During the trials, the system analyzed 138,475 alerts, disposing of 64% of them as confident false-positive closures. Auto Triage escalated 15% of the alerts as true positives for human analyst review, and routed the remainder as informational, clearing noise before it reached a person.

“The Agentic AI built into Auto Triage is designed to address one of the most pressing challenges security analysts deal with on a daily basis: tuning out the noise and focusing on legitimate threats to the business,” said Christopher M. Steffen, CISSP, CISA, CCZT, VP of Research, Information Security, Risk, and Compliance Management at EMA. “This study proves that Stellar Cyber’s approach of automatic ingestion and analysis, AI-driven prioritization, and highly accurate decision-making has the power to transform the way analysts work in the enterprise SOC—from processing alerts to managing cases, moving from MTTD and MTTR, towards MTTN – mean time to neutralize, and spending more time proactively reducing exposure.”

Lean security teams at enterprise SOCs and MSSPs face mounting alert volumes without the budget to scale headcount. For MSSPs, reclaimed analyst capacity translates directly into broader coverage, better customer service, and protected margins.

“The results from this study underscore what we’ve experienced in our own SOC. For an MSSP, the math of human-only security operations simply can’t scale against today’s alert volumes,” said Chant Vartanian, CEO, M-Theory Group. “Auto Triage effectively returns a full day of productivity per analyst and successfully closes 64% of false positives. That data is truly transformative for organizations like ours. It allows us to shift our team’s focus to high-value threat investigation and exposure management, work more cases per shift, which directly improves our service margins and enables us to provide broader, more consistent coverage for our clients without the need for costly headcount expansion.”

Auto Triage is available now as part of the Stellar Cyber AI-native SecOps platform. Stellar Cyber will showcase Auto Triage and the results of this independent study live at Black Hat USA (Booth #5542), August 1-6, 2026, in Las Vegas. Book a demo today!


from Help Net Security https://ift.tt/EtqeCxT

We may earn a commission from links on this page.

Amazfit's Cheetah 2 Ultra is a premium titanium-and-sapphire trail running watch, with a $599.99 price that feels pretty steep for a brand otherwise known for its budget options. And while Amazfit's Cheetah line isn't exactly my favorite, the Cheetah 2 Ultra is still an incredibly solid choice for any runner who wants a watch that looks and feels top-of-the-line.

Like with the Cheetah 2 Pro, there's more than meets the eye with this surprisingly feature-rich watch. Here are five features in the Cheetah 2 Ultra that go a bit beyond the manual.

Unlock a secret developer mode in your Amazfit watch

Your Zepp app has a hidden menu you probably wouldn't stumble upon by accident. Go to Profile, then Settings, then About, and tap the Zepp logo seven times in a row. This unlocks developer mode, which lets you dig into device information and debugging options that aren't normally visible in the consumer-facing app. It's not going to unlock secret hardware, but it's a useful place to check firmware details or troubleshoot a stubborn sync issue, and it's fun rabbit hole if you like poking around under the hood.

Developer mode also lets you install custom watch faces, rather than relying on the existing native watch face library and upload a custom face on your computer, scan a generated QR code, and install it directly onto your watch.

Prepare for difficult elevation at a glance on your Amazfit Cheetah 2Ultra

If you're planning a route with serious hills, this is one of the Ultra’s best hacks. The watch includes an elevation overview tool that color-codes slope difficulty across a route, so instead of squinting at a raw elevation profile and trying to guess where the brutal climbs are, you get a more accessible visual for where the terrain gets steep. This feature is easy to miss if you're not a dedicated trail runner, but it's worth pulling up before any route, so you know what you're walking into (before the hill tells you itself, the hard way).

Here's how to use the color-coded elevation glance on your Amazfit Cheetah 2 Ultra:

  1. Create your route: Open the Zepp App, go to the Workout tab, select Create Route, and save your path.

  2. Send the route to your watch: Sync your devices and check that the route successfully transfers to your watch.

  3. Open Trail Mode: On your watch, launch the Trail Run sports profile before you start running.

  4. Activate your route: While in trail mode, go to Settings, select Navigation, choose My Route, and select the route you created. Swipe to the elevation profile to see your color-coded preview.

If you want to see this elevation profile during your run, you can add elevation as a data screen. Here's how to customize your data screens on your Amazfit:

  1. Select Workout on your watch and select your activity (like Outdoor Running).

  2. Go to Settings > More > Data Page.

  3. Tap whichever data field you want to show the elevation. You can swipe through your existing data pages or tap Add Page to create a new one.

Use the flashlight's boost mode when you need extra light (and practice the SOS feature)

Every Ultra user loves their watch's built-in flashlight, but there's even more to get out of it. The Ultra's flashlight includes white, red, SOS, and boost lighting modes, not just a single beam. The boost mode is there for when you need maximum brightness, like scanning a dark trail, while the SOS mode is a safety feature and needs to send a clear flashing signal in the dark. Cycle through the modes with repeated presses rather than assuming it's a one-setting tool.

After you press and hold the top-left button to turn on the flashlight, use the UP or DOWN buttons to cycle through the white brightness settings until you reach the red light mode. You can also swipe down from the watch face to open the Control Center and tap the flashlight icon.

Use your Cheetah 2 Ultra to browse new maps

You might assume your options are limited to whatever maps Amazfit preloads or offers through the Zepp app's map store—which includes plenty of options already. But you can go a little further. The Cheetah 2 Ultra can be used as a map browsing tool when you import OSM (OpenStreetMap) map files, which means if you're headed somewhere obscure that isn't well covered by the default map set, you have a nifty workaround. Just keep in mind the downloaded map needs to actually match your real location to be usable, so this is a plan-ahead hack, not something you sort out mid-trail.

Use the extra storage on your Amazfit Cheetah 2 Ultra to load MP3 files

Even though the Ultra doesn't download music directly from streaming services like Spotify or Amazon Music the way some competitors do, you can manually load MP3 files onto the watch yourself. This is notable because the Cheetah 2 Ultra doubles the Pro's storage to 64GB, which means plenty room for saved running routes, offline maps, and mp3 files for music. It's an extra step compared to a simple streaming sync, but for anyone who wants a truly phone-free long run, it's a hack worth knowing about. To load music, head to your Amazfit Cheetah 2 Ultra device page in your Zepp app > Select "Music" > select .mp3 files from your phone and transfer them to the watch.


from Lifehacker https://ift.tt/TnYrp2N

Malware is everywhere these days. You might expect to find it when downloading strange programs from dark corners of the internet, but these are far from the only locations that can infect your devices. Despite strict review processes, official app marketplaces like Google's Play Store and Apple's App Store can feature apps containing malware. Now, that also extends to smart TV app marketplaces, as well.

Some apps were turning your Samsung TV into a "resproxy" network

As reported by TechCrunch, Samsung recently banned apps that share the users' internet connections with "strangers." Before the ban, "hundreds of millions" of users may have downloaded these apps onto their smart TVs, which put a huge fraction of Samsung's customers in jeopardy. These apps weren't necessarily shady, either. At least one of these apps, a Pac-Man game, was actually promoted by Samsung itself: The company featured it in an "Editor's Choice" area that customers would see on their smart TVs.

The issue, as discovered by security firm Mnemonic, comes from a data collection company called Bright Data. This company's code hides processes that would allow strangers to route their web traffic through your home internet. Once set up, the malicious apps wouldn't even need to be open for outsiders to tap into your network, which they could use for any purpose they wish. As TechCrunch highlights, these "resproxy" networks are being used more frequently for cybercrime, as it makes it difficult to trace this activity. Someone in England could route their activity through your home internet in Arizona, which would make it nearly impossible to discover their actual whereabouts.

It might seem surprising that Samsung would allow such apps on its official app marketplace, but many of these apps had clever tricks to evade capture. Many were extremely simple programs and only contained a handful of lines of code. These apps would pull in content from a remote server, creating the illusion that they were fully functioning apps. But from Samsung's point of view, these apps were simple and safe. This isn't a Samsung issue, either: LG also banned respoxy apps, shortly after it came out that over 40% of the apps on its marketplace added users' smart TVs to proxy networks.

Also complicating matters is that legitimate apps contain Bright Data's code. Play.Works, which licenses games like Pac-Man, but also Space Invaders, Tetris, Doodle Jump, and SpongeBob, included Bright Data's code in their ports. You'd likely assume downloading an official SpongeBob app to your TV would be safe, but, unbeknownst to you, it actually contains this sleeper resproxy code.

How to protect yourself from malicious smart TV apps

The good news in this case is Samsung has banned these apps from its app marketplaces. As such, you shouldn't have to worry about installing apps that will let outsiders tap into your internet connection. The same goes for LG as well. But not all smart TV manufacturers may have caught up yet, which means there is a risk that the apps you download on your TV could be malicious.

Researchers also found that simply installing these apps won't turn your TV into a respoxy device. While the code may load on your TV, you need to explicitly agree to a consent screen before you activate the code and turn your TV into a network node. As such, stay vigilant with any pop-ups on your smart TV apps, and deny consent to anything you either don't understand or don't feel is necessary to the function of the app. In addition, delete any suspicious apps, or any you no longer use: While the code can run without the app open, it gets deleted when you remove the app.

From here, general best practices will go a long way. Before you install an app on your smart TV (or, really, any device), inspect it carefully and exercise skepticism. Look through its app store listing, and make sure the description is free of spelling or grammatical errors. Look at the images, and note whether they appear high or low-quality, or whether they match the description for the app. Scan reviews, both for negative feedback from users, as well as obvious fakes inflating the overall rating. Investigate the app developer: Do they make other apps? Do those apps appear legitimate?

But as far as app marketplaces go, smart TVs have a poor reputation. As a general rule of thumb, it's probably best to avoid smart TV apps as much as possible. While mainstream streaming apps should be safe, there are too many possible loopholes present to say for sure whether various games and utility apps are secure.


from Lifehacker https://ift.tt/GRJe3xc

We may earn a commission from links on this page.

When I raced Hyrox earlier this summer, I opted for my Amazfit Cheetah 2 Pro—and I was quite pleased with the results. While Amazfit's Cheetah line isn't exactly my favorite, the Cheetah 2 Pro is a solid choice for any runner who wants a watch that looks and feels top-of-the-line (albeit with some mid-tier tradeoffs). And while the Cheetah 2 Pro has a no-nonsense marathon-watch exterior, there's a surprising amount of software most owners never touch. Here are five features that go beyond the manual.

Unlock a secret developer mode in your Amazfit watch

Buried inside the Zepp app is a hidden menu most people will never find by accident. Go to Profile, then Settings, then About, and tap the Zepp logo seven times in a row. This unlocks developer mode, which lets you dig into device information and debugging options that aren't normally visible in the consumer-facing app. True, it won't turn your watch into a hacking tool, but it's a fun rabbit hole if you like poking around under the hood, and it can occasionally be useful for troubleshooting sync issues or checking firmware details that the standard interface hides from you. 

Developer mode also lets you install custom watch faces, rather than relying on the existing native watch face library and upload a custom face on your computer, scan a generated QR code, and install it directly onto your watch.

Overcome jet lag with guidance from your Cheetah 2 Pro

If you travel for races, this one is a true hidden gem: Your Cheetah 2 Pro includes a “jet lag manager.” This feature may not be something you'd think to look for on a running watch, but if you've ever shown up groggy to a marathon expo, you know you'll try anything to help you adjust your sleep and training schedule ahead of race day. 

To use this feature, the watch will have you input your travel details to receive an Amazfit "Adaptedness" score (although I’m not quite sure what goes into this score, so please take it with a hefty grain of salt). While that number itself might not be worth paying too much attention to, your watch will then generate suggestions for when to sleep, be active, and get light exposure. When you have so many other travel logistics on your mind, it could be nice to get real-time alerts on your watch designed to help you adapt faster and make the most of your trip.

On your phone, open your Zepp App > Device Page > Amazfit Cheetah 2 Ultra > Jet Lag Manager to input travel details and view potential schedules. Then you can open the Jet Lag Manager app directly from your watch's app list—after scrolling down a good bit to find it—and view your personalized schedule and adaptation readiness starting 72 hours before departure.

Protect your eyes with your watch's red light option

Most users know their Cheetah 2 Pro has a built-in flashlight, activated with a long press of the function button. What’s extra-nifty is that it isn't just a single white beam. It uses two white LEDs, plus an additional red LED, and the red option gives you a glare-free alternative for the dark so you're not blinding yourself or wrecking your night vision. There's also a strobe function built in, which is worth knowing about if you ever need to be visible to traffic on a pre-dawn or post-sunset run, rather than just seeing what's in front of you. 

After you press and hold the top-left button to turn on the flashlight, use the UP or DOWN buttons to cycle through the white brightness settings until you reach the red light mode. You can also swipe down from the watch face to open the Control Center and tap the flashlight icon.

Get the notifications you still want, and none of the ones you don't

The Cheetah 2 Pro lets you personalize your notifications beyond all-or-nothing enabling/disabling. This way, any critical alarms or low-battery warnings still function even when everything else is muted. For example, if you go to Settings > Notifications > Calendar on your watch, and turn off "Allow notifications," then calendar-related reminders will no longer pop up. Easy!

What I do is disable all notifications, and then go in and enable only the handful of apps I actually care about (like text messages), while keeping the rest quiet during a long run.

In a similar vein of "less is more," the Cheetah 2 Pro defaults to more data collection than most runners need on a daily basis. These are the three features I dial back in order to save battery:

  • When you're not actively exercising, reduce heart rate measurement frequency from every one minute down to every five or 10 minutes.

  • Turn off "Automatic Stress Monitoring" and "Auto Blood Oxygen" tracking unless you specifically rely on that data.

  • Disable continuous location tracking and heart rate logging when you're not working out. Just remember to re-enable both when you start a workout.

These quick settings changes will help stop your watch from unnecessarily draining battery in the background, and you really aren't sacrificing much in terms of data.

Fix your Cheetah 2 Pro's accidental workout pauses

If you're using your Cheetah 2 Pro during strength training, this is a life-saver. One thing I've noticed across Amazfit watches is that the crown (aka the top right button) is either bigger or more sensitive, meaning the watch thinks I'm constantly pausing mid-workout whenever I accidentally bump against it. I pretty much couldn't swing a kettlebell without bumping the button in some way.

Here's my fix: Head into Workout Settings and switch the pause mechanism from a "simple press" to "Long Press." The long press did take me some getting used to when I do want to pause, but I'm grateful that I don't have to worry about any more accidental pauses caused by natural wrist movement.

Bonus hack: Clear water out of your watch quickly and easily

I'd like to leave you with a bonus hack, since I'm about to head out for a run in the pouring rain: Amazfit has a built-in water ejection feature. Water can linger in your watch's microphone and speaker ports, muffling sound or triggering false touches. Here's what to do: Swipe down from the main screen to open the Control Center, tap the Droplet icon, and hold your watch with the speaker facing downward. The watch will vibrate at specific frequencies designed to physically push moisture out of the ports. Like all the hacks above, this is one of those features it's good to know about now, so you're ready for the moment you really need it.


from Lifehacker https://ift.tt/mWKaxQH

In this Help Net Security video, Mike Boyle, VP of Business Units at GMO GlobalSign, and Rahul Powar, CEO and founder of Red Sift, unpack the evolution of email security and why it matters for business trust. With a combined 45+ years worth of experience in tech, they dissect email from the very beginning, before SPF, spam filtering and DMARC, up to today’s modern security standards. The reveal why most organizations are still struggling with … More

The post AI cut phishing from hours to seconds, which is where DMARC and BIMI come in appeared first on Help Net Security.


from Help Net Security https://ift.tt/6Gg0sA9

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

Week in review

Nono: Open-source sandbox for AI agents
AI coding agents run with the same permissions as their users, meaning they can access sensitive files, credentials, and production systems. A prompt injection, hallucinated command, or simple mistake can quickly turn that access into a security incident. To reduce the risk, Luke Hinds and Stephen Parkinson co-founded nolabs and released Nono, an open-source runtime that sandboxes AI agents at the operating system kernel, limiting what they can access and do.

Marathon Petroleum’s CISO on OT security automation, supply chain risk
In this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, pipelines, and terminals. She explains why the old idea of air-gapped operational technology has faded, how the Purdue model helps her team apply controls without stopping production, and where supply chain risk sits when vendors and their vendors hold the keys.

Shadow AI incident response begins with logs that may already be gone
In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound traffic to AI platforms are often gone before responders arrive, and what regulators look for when they assess whether a company did enough.

Your AI agents can reach data no one approved
A credential expired. An AI agent kept using it anyway, and a mid-sized company’s systems went down for a quarter’s worth of trouble before anyone traced the failure back to a non-human account no one had been logging.

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced
A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets encrypted processes and altered configurations. The outage runs into weeks, and the losses travel down the supply chain in both directions. Refineries, chemical plants and pipeline operators carry this exposure across control systems that run 20 to 40 years.

An AI agent can pass every safety check and still leak secrets
A pull request lands with a tidy bug report in the description. A bot reads it before any person does, pulls a few shell commands out of it, gets them approved, and posts the output back on the thread. The maintainer reads the whole exchange the next morning. Elad Meged, a founding engineer at Novee Security, ran that sequence against three vendors’ own repositories, in the configurations those vendors ship by default.

Top companies to visit at Black Hat USA 2026
Black Hat USA 2026 returns to Mandalay Bay with a re-engineered six-day program designed to spark innovation, challenge assumptions, and unite the global security community. From cutting-edge innovators to industry veterans launching new offerings to rising stars shaking up the status quo, these exhibitors are bringing something special to the floor this year. Make time in your schedule to stop by, because your next big opportunity might be waiting.

200 new CVEs a day and no realistic way to patch them all
Ryan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor network, AI triage, and human verification in a lab before a vulnerability reaches the public feed.

Data breach cost 2026 averaged $4.99 million, AI attacks ran higher
More than one in four organizations hit by a malicious attack over the past year say AI drove it. Those breaches averaged about $1 million above the malicious attacks that ran without AI.

Aviation cyber risk sits on the ground, the blindness sits in the air
In this interview with Help Net Security, Eliran Almog, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He walks through GNSS jamming that leaves no trace in a SIEM, and a PX4 Autopilot flaw his team disclosed where drone command channels accept unsigned messages.

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)
Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw.

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)
JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible.

Hugging Face breach reignites open-weights debate, raises liability questions
The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident post-mortem compiled with the input from Hugging Face and several hundred members of Cloud Security Alliance’s CISO community, the nonprofit organization laid out the most salient points for security leaders and advised on what they should do next.

Cisco FMC static credentials exploited by attackers (CVE-2026-20316)
A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco Secure Firewall devices across a network, is being leveraged by attackers, CISA warned.

Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)
Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange, to target US and European government entities and a variety of private sector organizations via email. The warning comes from Proofpoint, who detected emails carrying the concealed exploit hitting inboxes.

What the identity attack surface looks like when trust becomes the target
In this Help Net Security video, Joel Moses, VP, Strategic Engineering at F5, explains how attackers use identity instead of breaking through it. He walks through MFA fatigue, session token theft, and consent given to malicious applications, using the 2022 Uber breach as an example.

Impersonation protection: How to protect your executives when the truth isn’t clear
How do you protect your executives when truth doesn’t seem to be truth anymore? It’s a question BlackCloak Founder and CEO Dr. Chris Pierson recently discussed with SVP of Product Matt Covington.

GitHub delays version updates so malware gets caught first
Automated dependency update tools normally open pull requests as soon as a new package version is released, but that speed can backfire. In September 2025, attackers published malicious versions of popular npm packages such as chalk and debug, and although they were removed within about two hours, that was enough time for update bots to propose them to downstream projects. To reduce this risk, GitHub introduced Dependabot cooldown, which delays non-security update pull requests for at least three days by default.

Google changes how it names cyber threat actors
Google Threat Intelligence Group (GTIG) has started using a new naming system for the threat actors it tracks. The change comes after Mandiant and Google’s Threat Analysis Group (TAG) merged into one unit, leaving the company with two separate naming schemes built up over years.

Tech giants form alliance to put open AI in cyber defenders’ hands
NVIDIA and a group of tech companies have formed an alliance to promote the use of open AI models in cybersecurity, days after OpenAI disclosed that one of its own AI models breached Hugging Face’s systems during an internal security evaluation. The new group, called the Open Secure AI Alliance, builds on work already underway at the Linux Foundation’s Akrites initiative and the Open Source Security Foundation (OpenSSF).

Microsoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the cost
Microsoft has introduced MAI-Cyber-1-Flash, a security-focused AI model built into MDASH, the company’s multi-agent vulnerability identification and remediation system.

Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts
Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway, Malwarebytes researchers have warned. Victims are asked to log in with their email address and password to claim free Call of Duty Points (CP), the game’s premium currency, before being redirected to a second page requesting their 2FA code.

AI took more than junior developer jobs and the bill comes later
A ticket comes in for a small bug fix. Hand it to the junior on your team and you wait a day, review something that half works, and sit down to explain what went wrong. Describe it to Claude and the patch merges before lunch.

Coca-Cola confirms hackers stole data in Fairlife ransomware attack
Coca-Cola has confirmed that the ransomware attack on its dairy subsidiary Fairlife involved the theft of company data, weeks after the incident temporarily halted production at its US facilities.

VERITAS project could change the way scientists secure AI
The AI models, datasets, and automated systems researchers depend on can be compromised in ways conventional cybersecurity tools aren’t designed to detect. A new project called VERITAS (VERified Infrastructure for Trustworthy AI in Science) aims to close that gap by establishing AI Assurance as a core function of scientific research infrastructure.

Exposed BMCs hand out password hashes before login
An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part of the IPMI 2.0 handshake, built on an authentication protocol introduced in 2004.

WhatsApp brings end-to-end encrypted voice and video calls to the web
WhatsApp has launched support for voice and video calls on the web, allowing users to make and receive calls directly from their browser without installing the desktop app.

Stolen Meta and Google ad accounts are worth more than the money they hold
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy complete with tiered pricing, escrow services, and money-back warranties for stolen accounts. Public reporting on this topic tends to focus on drained ad budgets, but according to Mimecast, that’s often a short-lived gain for attackers.

Cloudflare reveals what’s behind major internet outages
Storms, earthquakes, and infrastructure failures disrupted internet access throughout the second quarter, while governments deliberately shut networks down, according to Cloudflare’s latest Internet Disruption Summary.

Tengu botnet reboots Linux devices to survive removal
A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found.

Coordinated cyberattack hits more than 30 Minnesota water utilities
A coordinated cyberattack on July 26 and 27 hit operational technology (OT) systems at more than 30 community water utilities across Minnesota, prompting an immediate response from Minnesota IT Services (MNIT) to contain the threat.

Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks
Attackers are moving away from fake Microsoft login pages in favor of abusing Microsoft’s own authentication system, letting phishing campaigns slip past the warning signs employees are trained to spot, according to Check Point.

AI takes on a bigger role in finding Chrome vulnerabilities
Google has expanded the use of AI in Chrome’s security workflow, using it to find vulnerabilities, triage bug reports, generate patches, and review code to shorten the time between discovering software flaws and delivering security updates.

Anthropic’s Claude breached three companies during security tests
Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure follows OpenAI’s July 21 announcement that some of its models had escaped an isolated testing environment by exploiting a previously unknown vulnerability and reached the systems of Hugging Face, the open-source machine learning platform.

Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire
A security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years. According to Bitsight, the operation, named Fuyao, uses preinstalled Android apps, device identity spoofing, AI-generated websites, and residential proxy services to generate advertising revenue without device owners’ knowledge.

Claude Opus 5 sharpens coding and cybersecurity work on AWS
Claude Opus 5 went live on Amazon Bedrock and Claude Platform on AWS. Anthropic says the model improves on Claude Opus 4.8’s cyber capabilities, coding through cybersecurity. Anyone with an AWS account in a supported region can call it. On higher-risk requests, Opus 5 hands the job back to Opus 4.8, the older model. The user sees a notice when that happens. API customers can configure the fallback.

Product showcase: LastPass Authenticator brings Face ID, Apple Watch, and cloud backup to 2FA
LastPass Authenticator is a free app that provides two-factor authentication (2FA) for accounts and any service that supports time-based one-time passwords (TOTP). It supports push notifications for one-tap approvals and generates six-digit verification codes for online accounts. The app is available for iPhone, iPad, Apple Watch, and Android devices.

AWS gives DevOps teams an AI investigator for firewall incidents
AWS DevOps Agent helps administrators inspect logs, review firewall rules and network paths, identify configuration changes that caused AWS Network Firewall to block traffic, and restore connectivity. The service is an AI-powered operations assistant for DevOps and SRE teams that investigates and troubleshoots application and infrastructure issues.

ChatGPT joins the most impersonated brands in phishing attacks
Microsoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the five brands together making up more than half of all brand phishing attempts tracked during the quarter, according to Check Point’s Q2 2026 Brand Phishing Report.

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027
AWS Shield Advanced, a managed service that protects applications from external threats, is adding the Anti-DDoS managed rule group, designed for application-layer (L7) DDoS protection, to eligible web access control lists (ACLs) in Count mode.

Android malware detection collapses when the context stage comes out
A phone backup app requests storage, contacts, SMS, and call logs. A device management app requests even more. Run either through an Android malware detector, and it may be flagged as malicious. Researchers at Singapore Management University and Nankai University found that six widely used Android malware detectors.

Specter: Open-source NFC reader bug sweep for Flipper Zero
Specter is a Flipper Zero app that finds powered NFC readers by listening for the radio field they give off. The readers it hunts work at 13.56 MHz. The onboard ST25R3916 carries a hardware external-field detector, the same circuit that lets the device emulate a card and register when a reader starts talking to it. Specter reads that one bit, hundreds of times a second, with its own transmitter dark.

Exposed credentials are giving attackers a head start many organizations don’t see
Compromised credentials can remain active long after passwords are created, leaving organizations trying to identify exposed accounts before attackers can use them. The 2026 Credential Risk Report from Enzoic shows growing awareness of the problem, but monitoring and response capabilities continue to lag.

Product showcase: Dashlane Password Manager is more security toolkit than password vault
Dashlane is a password manager for individuals and families that stores passwords, passkeys, payment cards, personal information and secure notes in an encrypted vault. It also includes a password generator, password health reports, an authenticator, credential sharing, dark web monitoring and phishing protection.

CISA sets a new SBOM baseline
The US Cybersecurity and Infrastructure Security Agency (CISA), together with its co-authoring partners, has released the 2026 Minimum Elements for a Software Bill of Materials (SBOM), replacing the 2021 guidance published by the National Telecommunications and Information Administration (NTIA).

AI agents are changing where cybersecurity seed funding lands
Founders pitching a cybersecurity seed round this summer are joining a line that keeps getting longer. Product Hunt launches hit their highest level since late 2023 last quarter, and the Census Bureau’s count of high-propensity business applications kept climbing. Seed deal volume in cyber ticked down. Those figures come from the Q2 2026 Insights report published by DataTribe, an early-stage cybersecurity investor.

Companies push AI, sysadmins keep it on a short leash
In 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years. Action1’s 2026 Survey Report: AI Impact on Sysadmins found that those expectations proved overly optimistic.

Cybercrime goes subscription: AI, malware and infrastructure on demand
Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide anonymity, plausible deniability, and access to short-lived infrastructure that is difficult to detect, attribute, and disrupt, enabling low-skilled actors to operate at scale, according to the Infoblox 2026 Threat Landscape Report.

Download: The High-Performance Team Playbook
Get practical insight from teams who’ve built, scaled and handed over engineering functions at enterprise level.

ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility
Research from Aryon reveals that each year, 3,731,699 short-lived cloud resources containing highly sensitive information are publicly exposed. This impacts any organization using AWS services that support public sharing.

Cybersecurity jobs available right now: July 28, 2026
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.

New infosec products of the week: July 31, 2026
Here’s a look at the most interesting products from the past week, featuring releases from BlackCloak, Contrast Security, Dropzone AI, PortSwigger, Realm Security, Reco, Root Evidence, and ZeroFox.


from Help Net Security https://ift.tt/mwXIchZ