Vulnerabilities & PatchesEmerging1 src
Voting machine researchers say federal work abruptly ended after Trump ally pushed back on their findings
LAS VEGAS — After spending roughly six weeks analyzing Dominion voting systems used in Puerto Rico’s 2024 elections, Mojave Research came back to the Trump administration with findings that startled its researchers.
The systems contained at least a dozen high- or critical-severity software vulnerabilities. Passwords were reused, firewalls were disabled and basic cryptographic protections were poorly implemented. And in Puerto Rico, active cellular hardware modems opened additional pathways into underlying software that was thought to be isolated.
But the small cybersecurity firm found no evidence that any of those weaknesses had actually been exploited, or that votes had been changed. The company still wanted more time to be certain.
Federal officials initially seemed willing to give them considerably more of it.
Vendors & MarketEmerging1 src
Wine 11.15 Released With Wayland Fixes, Fix For A 20 Year Old MSXML3 Bug
Making its debut this Saturday rather than the usual bi-weekly Friday release regiment, Wine 11.15 is out today as the newest development release for this open-source software enabling Windows games and applications to run on Linux...
Vulnerabilities & PatchesEmerging1 src
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims.
Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own advisory says the vulnerability carries a CVSS score of 10. 0, and it let an unauthenticated attacker inject arbitrary SQL straight into the Metabase application database.
“We recently identified that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1. 58 and above.” reads the advisory. “We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability.”
Vendors & MarketEmerging1 src
TTM Memory Management For Graphics To Be More Aggresive With Linux 7.3
This week a final batch of DRM-Misc-Next feature material was submitted for DRM-Next to queue ahead of the Linux 7. 3 merge window opening later in the month. Most notable is the TTM memory management code is now being more agressive when allocating below protection limits. This is an improvement coming thanks to Valve's open-source Linux graphics team...
Vendors & MarketEmerging1 src
Intel Makes Progress On HDMI 2.1 FRL With Their Linux Driver For Meteor Lake & Newer
Following AMD making progress with HDMI Fixed Rate Link (FRL) and other HDMI 2. 1 functionality for their open-source Linux kernel graphics driver, Intel is out today with a big set of 44 patches working on HDMI 2. 1 FRL support for their kernel graphics driver with Meteor Lake hardware and newer...
Vendors & MarketEmerging1 src
What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience
Certifications and years of experience can only take you so far in cyber now. Automation means new skills are coming to the fore.
Vendors & MarketEmerging1 src
Growing Up The Hard Way
Open Source had a great childhood.
For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need, pay me back whenever, no need to leave a name. It was idyllic. It was also, in retrospect, a little feral.
Then,
Vendors & MarketEmerging1 src
NetworkManager Adopts Policy For AI Coding Assistants
The latest high profile open-source project to commit to an AI coding policy is NetworkManager, the widely-used software for Linux network configuration...
Vendors & MarketEmerging1 src
AMD ROCm Spur: Providing AI-Native, Rust-Based Job Scheduling
The newest ROCm component for AMD's open-source GPU compute stack is Spur as an AI-native, Rust-written job scheduler for scaling up GPU workloads to multi-thousand GPU clusters...
Vendors & MarketEmerging1 src
AMD Updates HDMI 2.1 VRR & ALLM Patches But Will Miss Out On Linux 7.3
Complementing the HDMI 2. 1 Fixed Rate Link (FRL) support that AMD already upstreamed to the Linux kernel, AMD engineers have been further ironing out their HDMI 2. 1 implementation for the open-source AMDGPU Linux kernel driver. The latest quest has been getting HDMI 2. 1 variable rate refresh (VRR) support upstreamed along with HDMI Auto Low-Latency Mode (ALLM)...
Vendors & MarketEmerging1 src
Still using Google Assistant? It’s time to look for a replacement - Cybernews
Still using Google Assistant? It’s time to look for a replacement Cybernews
Vendors & MarketEmerging1 src
5 Best AI Detection & Response Platforms for 2026 - Hackread
5 Best AI Detection & Response Platforms for 2026 Hackread
Vendors & MarketEmerging1 src
“I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails - Hackread
“I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails Hackread
Vendors & MarketEmerging1 src
New Research: The Confidence Gap Between CISOs and Their Boards Is Real, and It's Measurable - Hackread
New Research: The Confidence Gap Between CISOs and Their Boards Is Real, and It's Measurable Hackread
Vendors & MarketEmerging1 src
Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance - Hackread
Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance Hackread
Vendors & MarketEmerging1 src
Android app developers may be unwittingly sharing their users’ location data with advertisers
New findings by the Electronic Frontier Foundation aim to warn app developers that some of the third-party code they place in their apps may also collect their users' location data when they grant permission to the app.
Vendors & MarketEmerging1 src
WhatsApp Scam Hijacks Accounts via Linked Devices Feature
WhatsApp scam abused the Linked devices feature to hijack accounts without stealing any passwords
Vendors & MarketEmerging1 src
Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions
Talos read attacker prompt logs and found guardrails fell to task splitting and ownership claims
Vendors & MarketEmerging1 src
Online backlash ends in Google rolling back Google Earth AI tool after a day
Google has walked back an AI feature that allowed users to generate artificial images inside Google Earth, after a predictable flurry of deepfakes.
Google switched on the AI image generation feature inside Google Earth’s web version on July 30. It was available to everyone.
The system used Google’s Nano Banana 2 image generator to create its images. That tool can already generate images from simple text input, but the advantage of doing it in Google Earth is that it can use the real satellite images as the basis for its deepfake versions. That makes it easier to make AI pictures with real, accurate building and landscape details.
In its initial blog post on the launch, it said that students could use it to “bring history to life”, while realtors could use it to produce professional real estate plans. However, others warned that the system could be used to mislead people.
Vendors & MarketEmerging1 src
AI Accounts for Over Half of Cybercrime in Africa, Says Interpol
Interpol claims AI is driving a surge in cybercrime in Africa, with related losses doubling
Vendors & MarketEmerging1 src
Midnight Blizzard Targets Travelers via Captive Portals
Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens
Vendors & MarketEmerging1 src
Samsung bans smart TV apps that share users’ internet connections with strangers
New security research offers a rare view inside residential proxy networks, which rely on apps that share a person's internet connection with someone else.
Vendors & MarketEmerging1 src
ISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd)
ISC Stormcast For Monday, August 3rd, 2026 https://isc. sans. edu/podcastdetail/10034 (Mon, Aug 3rd)
Vendors & MarketEmerging1 src
CareCloud begins to notify hundreds of thousands after hackers stole medical records
The health tech data giant, which handles vast amounts of patients' medical data, said hackers struck one of its protected health data stores.
Vendors & MarketEmerging1 src
US government bans new foreign-made humanoids, robot dogs, and solar inverters, citing risks to national security
The ban largely affects U. S. imports from China, which currently dominates the global market for making humanoid robots and solar inverters.
Vulnerabilities & PatchesEmerging1 src
Rapid7 Analysis: Check Point SmartConsole Authentication Bypass (CVE-2026-16232)
Overview
On July 22, 2026, Check Point published a security advisory for CVE-2026-16232 , an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS).
By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires network access to the Management Server and for a Trusted Clients configuration that does not restrict GUI clients, which in our testing was a default setting.
This vulnerability was reported as being exploited in the wild as a zero-day vulnerability at the time of disclosure.
Policy & RegulationEmerging1 src
Rapid7 and Exclusive Networks expand partnership to modernize security operations and accelerate customer success
Claudia Zoon is Senior Manager, Channel Sales at Rapid7.
Across Belgium, the Netherlands, and Luxembourg, organizations are accelerating digital transformation through AI, cloud adoption, and increasingly connected business operations. These investments are creating new opportunities for innovation, but also reshaping the cybersecurity landscape.
In this dynamic environment, Rapid7 is excited to announce an expanded strategic distribution partnership with Exclusive Networks across the Benelux region. Why now? Because as organizations grow, so too do the expectations of security teams.
As attack surfaces expand, more sophisticated AI-enabled threats emerge; as compliance requirements evolve, leaders expect security to scale right along with the business – all without adding unnecessary complexity.
Vendors & MarketEmerging1 src
Week 30 – 2026
If your organisation is interested in sponsoring an upcoming post then reach out via the contact form! No sponsor this week
Vendors & MarketEmerging1 src
Independence is the moat
Why the independent layer keeps winning as the models get better, not despite them.
This series has been building to one question, and it is the objection every honest reader has been holding since the first piece. If the frontier models keep getting better this fast, why does an independent security layer keep winning? Why not wait for the model that writes safe code and verifies its own work?
The trust argument , the cost argument , and the real intrusion all pointed the same direction, but they left the hardest question for last. Not why independence matters today, but why it keeps mattering as the models improve.
The answer is that independence is not a gap the models are closing. It is a property they structurally cannot have. And the specific advantages that make it real, the data, the breadth, the neutrality, all compound as generation accelerates.
Vendors & MarketEmerging1 src
RiskX interview video featuring Colin Mahony and Mastercard's Aditi Sawhney
At RiskX Singapore 2026, Recorded Future CEO Colin Mahony and Mastercard's Aditi Sawhney discussed why payment fraud has become an ecosystem problem that spans cyber and financial crime. The fraudulent transaction is the visible end of a chain that began weeks or months earlier, with harvested credentials, registered lookalike domains, and infected merchant sites.
This post looks at how connecting cyber and fraud signals lets defenders intervene before monetization, and how Recorded Future’s Payment Fraud solution maps to each stage of that chain.
https://www.youtube.com/watch?v=NTqcdZrx0ic
Vendors & MarketEmerging1 src
5 Cybersecurity Lessons From Taylor & Travis’s Wedding
“Long Live” strong security! Taylor Swift & Travis Kelce’s wedding offers real cybersecurity lessons on layered defense, MFA, deception tools, and more.
Vendors & MarketEmerging1 src
AI Arms Race in Recruiting
Recruiters and candidates are both using AI to game the process. Here's what that means for hiring quality, and what to do about it.
Vendors & MarketEmerging1 src
Lateral Movement Attack: Techniques, Detection & Prevention
Huntress explains lateral movement attacks, how attackers move through networks, common techniques like pass-the-hash, and how Managed EDR stops lateral movement.
Vendors & MarketEmerging1 src
8 Questions to Ask Before Choosing an Incident Response Retainer
Before you sign an incident response retainer, ask about SLA definitions, scope, hidden costs, threat profile fit, and post-incident support. Here is what to look for.
Vendors & MarketEmerging1 src
Hack The Box wins 2026 industry awards as it builds the future of cyber readiness
Hack The Box wins 2026 industry awards as it builds the future of cyber readiness
Vendors & MarketEmerging1 src
Turning Geopolitical Tension into Actionable Intelligence
Intel 471’s updated Geopolitical Intelligence solution is designed to translate volatile global dynamics into timely, actionable insights.
Vendors & MarketEmerging1 src
Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk
To empower organizations against the growing complexity of their attack surface, Intel 471 is introducing the Cyber Threat Exposure Bundle.
Vendors & MarketEmerging1 src
Blue team resilience: The skills, simulations, and reporting SOCs actually want
Explore emerging blue team needs shaping enterprise security, including continuous readiness, real SOC simulations, improved defensive skills training, and modern performance measurement.
Vendors & MarketEmerging1 src
HTTP/1.1 must die: the desync endgame
Abstract Upstream HTTP/1. 1 is inherently insecure and regularly exposes millions of websites to hostile takeover. Six years of attempted mitigations have hidden the issue, but failed to fix it. This p
Vendors & MarketEmerging1 src
Document My Pentest: you hack, the AI writes it up!
Tired of repeating yourself? Automate your web security audit trail. In this post I'll introduce a new Burp AI extension that takes the boring bits out of your pen test. Web security testing can be a