Feed
Enterprise technology news for the people who buy and run it. Our editors pick stories from company newsrooms and trusted trade press, and every one credits and links its source. You’re seeing Top: recent stories ranked by what readers open, save and discuss. Nobody pays to rank. How ranking works
Narrow it by category below, or follow companies and categories to get their stories in For you and the Monday brief.
Matching stories
Threat Actors Use Google Ads To Target Ledger Users
In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake…
Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
Two Things Every Cyber Asset Attack Surface Management (CAASM) Tool Needs to Get Right
Cyber Asset Attack Surface Management (CAASM) solved a significant problem. Security teams can now say with confidence what they own. But, two things separate a CAASM tool that stops there from one that actually moves the needle on risk. The first is what the inventory itself carries. The second is what it connects to. 1. An inventory needs to do more than list what exists A list of assets is…
Agents can now set up your website’s security with Turnstile Spin
Misconfiguring Turnstile by skipping backend validation leaves sites exposed to bots. Turnstile Spin fixes incomplete setups by using your preferred AI coding agent to wire up server-side verification.
Darktrace / SECURE AI: Behavioral Security for the AI enterprise
Discover how Darktrace / SECURE AI applies behavioral security to AI usage, prompts, agents, and development to help organizations adopt AI securely.
Wiz Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026
Forrester’s Proactive Security Platforms evaluation rated Wiz with top scores across eight areas, reflecting our commitment to securing the AI era
How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
External security researchers at Accomplish identified a vulnerability in Cloudflare Containers that could expose residual disk data from previous workloads. We explain how the issue worked, how we investigated it, and the steps we took to remediate it.
When Business Email Compromise Starts Rewriting Reality
Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets. This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details…
A Decision Model Breaks Like Any Other Language Model: A First Look at Jev
A new kind of AI model returns decisions instead of text. We spent a day trying to change its mind. It cost about 50 cents. In this article Jev is a new kind of AI model that returns typed decisions instead of text, built for software to call rather than for people to read. We put it inside a realistic application and tried to change its verdict from the outside. →every configuration we tested…
Scan for Good: Using AI to discover and fix high-priority exposures across public services and critical infrastructure
New initiative partners with under-resourced organizations to uncover, remediate exploitable risk at scale.
Can We Control Every AI Agent Before It Becomes Our Next Privileged Insider?
AI agents are moving into the enterprise much faster than most security programs were designed to handle. They are no longer just answering questions or generating content. Agents can read email, access SaaS applications, query databases, invoke APIs, use MCP tools, modify records and execute business workflows. In other words, AI is moving from generating answers to taking actions. For CISOs and…
Should you let AI shop for you this holiday season? Here’s what TrendLife found
Should you let AI shop for you? TrendLife tested six AI tools through the same set of realistic shopping tasks. Here's what we found: The post Should you let AI shop for you this holiday season? Here’s what TrendLife found appeared first on TrendLife Blog .
CrowdStrike Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026
Agent Hijacks: How Conversation History Poisoning Can Turn AI Agents Into Attackers
Darktrace researchers demonstrate how conversation history poisoning can hijack agentic harnesses, convincing AI agents to perform offensive cyber operations with little to no human interaction.
CISA BOD 26-04 Timelines for Three Linux Kernel CVEs
Executive Summary CISA added three actively exploited Linux kernel vulnerabilities: CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV Catalog on September 18, 2026, triggering a 3-day remediation deadline that passed on September 21. Under CISA BOD 26-04, a 3-day window applies to CVE-2025-39682 across all assets, and for the other two, the deadline is 3 days […]
How dynamic application security testing validates risk at runtime
Security teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce the attack, and give developers enough evidence to fix it? Dynamic application security testing (DAST) helps answer those questions by testing applications as an attacker encounters them. The IDC…
Workforce AI Security Policy Management Is Now Conversational
In this article The new Workforce AI MCP is Check Point’s own Model Context Protocol server for Workforce AI Security. Connect a compatible AI client and you can query, analyze, and manage your employee AI usage policy in natural language instead of working through filters, screens, and individual rule checks. →ask plain questions such as which rule applies to a given user and application, or…
CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM
Overview On September 22, 2026, F5 published a security advisory for CVE-2026-94127 , a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted…
Detecting Rogue AI Agents: When Enterprise Agents Turn to Hacking
Darktrace researchers found that AI agents tasked with solving impossible challenges frequently resorted to hacking techniques. Learn how Darktrace detects and disrupts rogue agent behavior in real time.
We just shipped support for the ugliest part of HTTP: Vary
Vary support is now available in Cache Rules on every plan. You can normalize known negotiation headers, pass exact values through to the origin when those small differences matter, or bypass cache when the variation is too unpredictable.
Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616
As part of Check Point’s Frontier AI Readiness Program, we continue to release Jumbo hotfixes with security fixes and hardening improvements for our Firewall and Management products. This advisory addresses the active exploitation described below, and the immediate steps customers should take to protect affected systems. Check Point Research has identified active exploitation of two…
Introducing Worker Previews: Isolated preview environments for every change your agent makes
Worker Previews gives every branch its own URL, configuration, state, and observability, so you and your agents can test changes in parallel without affecting production.
Introducing Unit 42 Continuous Frontier AI Defense
Cybersecurity is in the middle of a generational shift. AI has disrupted a 30-year balance of power between defenders and adversaries. Armed with agentic AI tools and open-weight models stripped of safety … The post Introducing Unit 42 Continuous Frontier AI Defense appeared first on Palo Alto Networks Blog .
Growing the WIN AI Ecosystem with Agent Integrations
WINning AI with AI: How the Wiz MCP for WIN partners accelerates a connected ecosystem
Proofpoint Stops the Attacks Traditional Defenses Miss in the AI Era
Proofpoint Breaks Down the Divide Between Data Security and AI Security with the Industry’s First Unified Agentic System
The fake “your cloud is almost full” text hitting phones right now
Got a text saying that your cloud drive is full and that your files will disappear in six hours unless you tap the link? It's a scam. The post The fake “your cloud is almost full” text hitting phones right now appeared first on TrendLife Blog .
Human Judgement in the Agentic AI Age | Darktrace
As AI agents take on more decisions, human judgement becomes critical. Explore the challenges of AI governance and how behavioral security can help.
Vidar Adds Virtual Machine and Custom Stream Ciphers For String Obfuscation
Vidar is an information stealer that was first observed in 2018. Across its iterations, Vidar has continued to improve its string obfuscation to make detection and analysis more difficult by changing deobfuscation algorithms, constants, and primitives. From May through early September 2026, Zscaler ThreatLabz tracked Vidar’s string obfuscation as it evolved from basic XOR to ChaCha20,…
Python Workers are now generally available
Python Workers allow developers to run Python web frameworks and AI orchestration libraries natively in the Cloudflare Workers runtime. You can seamlessly integrate with Cloudflare's ecosystem including D1, R2, and Workers AI without writing any JavaScript glue code.
Proofpoint Recognizes 2026 Global Partner Award Winners at Flagship Event
Defining the Standard for AI Security
Palo Alto Networks Named a Market Shaper in 2026 September Gartner® Emerging Market Quadrant for AI Application Security — Established Vendors. When we set out to solve AI security, we knew it … The post Defining the Standard for AI Security appeared first on Palo Alto Networks Blog .
The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Era
AI-driven threats are outpacing traditional audits. Discover how continuous monitoring, automated evidence collection, and risk-based remediation help security teams close compliance gaps and maintain audit readiness as environments change daily.
The Autonomous Engine Behind Remediation, and What Finally Makes It Safe
Executive Summary Vulnerability exploitation now happens at a speed that manual, ticket-based remediation can’t match. Qualys’s Enterprise TruRisk Management Platform closes that gap with autonomous remediation: exposures are prioritized by threat, business, and environmental context, then validated by TruConfirm and Agent Val before any resource is committed, eliminating over 90% of remediation…
Exploring the new AWS Sign Up experience
This post will explore what this new concept does, how it works with the new Account Access capability, and why a strong security posture still requires upgrading out of the sandbox.
Building an AI Detection Engine That Understands Agent Intent
Analyzing model input and output logs in an AI-native detection pipeline to understand and uncover malicious AI agent behavior
We joined the viral 1980s AI photo trend. Here’s what it tried to charge us.
1980s AI photo trend across social media: TrendLife tested how the trend can be exploited and shared steps to protect yourself. The post We joined the viral 1980s AI photo trend. Here’s what it tried to charge us. appeared first on TrendLife Blog .
CrowdStrike Named a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026
CrowdStrike SafeMind: When the Best Offense Builds the Best Defense
Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
In August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January 2026, APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense…
Oracle Critical Security Patch Update, September 2026 Review
Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. Out of the 673 security updates published, a total of 104 […]
CrowdStrike Accelerates Real-Time Data Classification with On-Device AI
Oracle September 2026 Critical Security Patch Update addresses 672 CVEs
Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at…
Before You Patch. Why Patch Reliability Matters for Confident Deployment
Executive Summary Microsoft’s September 2026 security updates – KB5124008, KB5124012, and KB5123099 have been linked to significant issues, underscoring the operational risks associated with security patching. Five known problems emerged after deployment: domain-joined devices losing their secure trust relationship with the domain, USB audio devices failing to start or producing no sound, host…
Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.
Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture. Key takeaways The Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series…
CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
Overview On September 14, 2026, Cisco published a security advisory for CVE-2026-76461 , a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance. Cisco Secure…
PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting
The industry turned XDR and SIEM into categories. Sophos turned them into outcomes.
Sophos Next-Gen SIEM, now generally available as part of Sophos Fusion, brings security operations and compliance together through shared context.
Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation
Messageboards are all they need
This article was first published on LinkedIn.
FedRAMP Moderate Authorization for Palo Alto Networks Quantum-Safe Security
Palo Alto Networks has achieved FedRAMP Moderate authorization for Quantum-Safe Security (QSS), a turnkey Automated Cryptography Discovery and Inventory (ACDI) solution. With this certification, federal agencies can deploy QSS immediately. The authorization … The post FedRAMP Moderate Authorization for Palo Alto Networks Quantum-Safe Security appeared first on Palo Alto Networks Blog .
ATT&CK grew a 15th tactic: A practical DFIR field guide to the Stealth / Defense Impairment split
Artifacts and tooling for the new Enterprise MITRE ATT&CK matrix tactics, distilled from the field.
Palo Alto Networks Named a Leader in the 2026 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
Securing Every Environment at the Speed of Frontier AI Recognized as a Leader for the second consecutive time and positioned furthest for Completeness of Vision. Palo Alto Networks is advancing hybrid mesh … The post Palo Alto Networks Named a Leader in the 2026 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall appeared first on Palo Alto Networks Blog .
SloppyRAT: A New Tool For Ransomware Attacks
In June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage ClickFix infection chain. The malware supports a variety of features including a large number of built-in PowerShell-like commands, encrypted code blocks, EtherHiding…
Secure AI Coding: Governing every agent, artifact, and identity
Enterprises are seeing an unprecedented surge in AI coding adoption with spend on AI coding tools projected to top $13 billion in this calendar year1, compounding at more than 60% annually. For … The post Secure AI Coding: Governing every agent, artifact, and identity appeared first on Palo Alto Networks Blog .
Proofpoint Expands AI-Powered Investigations to Microsoft 365 and Deepens Insider Risk Visibility into AI Activity
The agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the rails
Learn why Tenable treats agentic LLMs as untrusted insiders, and how we’ve made sure you can control and monitor the AI agents making changes in your production security environment Key takeaways AI models can quickly understand data, but not your business. While modern AI models are great at reasoning, they don’t automatically understand your unique environment or who is allowed to do what. The…
TrendLife’s 2026 guide to identifying deepfakes
Check out TrendLife's 2026 guide to identifying deepfakes and top tips to stay safe from AI face-swapping video calls and scams. The post TrendLife’s 2026 guide to identifying deepfakes appeared first on TrendLife Blog .
Four groups caught using the same Chrome and Windows exploit kit
Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI
Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the CyberAgents Exchange AI Inspector. Key takeaways The Exchange Inspector combines Tenable’s exposure…
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
104 Critical 860 Important 0 Moderate 0 Low Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild. Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important. This month’s update includes patches for:…
Simple ways to protect the family member scammers are counting on
It's hard to be with every family member. Here are some simple ways to protect the family member who scammers are counting on. The post Simple ways to protect the family member scammers are counting on appeared first on TrendLife Blog .
The State of Ransomware in Education 2026
Insights from 226 IT and cybersecurity leaders across the education sector in 17 countries whose organizations were hit by ransomware in the past year.
Why Trust is the New Attack Surface: Mid-Year Threat Update 2026
Darktrace’s analysis of the first half of 2026 shows attackers increasingly exploiting trust rather than bypassing security controls. For defenders, context and behavioral analysis remain essential foundations of security.
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
In July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary…









