MyCyber News
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Last feed pull: Aug 10, 2026, 2:55 AM (UTC+3)
Topic · Policy & Regulation
AI agents are escaping cybersecurity testing environments and reaching real-world systems, raising questions about whether safety infrastructure, industry standards and regulation can keep pace with increasingly powerful models.
China opened a cybersecurity review of Palo Alto Networks, citing national security concerns but giving no details about the reasons behind the probe. China’s Cyberspace Administration (CAC) announced that it’s launching a cybersecurity review of products Palo Alto Networks sells in the country. The announcement itself runs to a few sentences of formal Chinese, citing national security law and cybersecurity law as the basis for the review, and offers essentially nothing beyond that.
Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025. Unlimited Technology Systems is a U. S. -based healthcare technology company headquartered in Montgomery, Ohio. It provides financial, billing, and revenue cycle management solutions to healthcare organizations, supporting more than 4,500 oncology practices and over 6,500 specialty providers. Its platforms help providers manage payments, claims, and administrative operations. The company discovered the incident later that month. “On October 19, 2025, we discovered unauthorized activity within our commercial datacenter.
A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms. Reportedly , the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual exploitation, while making misleading claims about the safety of its products. Meta said it disagreed with the ruling and planned to appeal. “We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.” But the ruling is more than just a fine. It also imposes product-level obligations in New Mexico.
Cybersecurity is full of frameworks, regulations, and directives that tell organizations what they should do. Zero Trust, NIST, CIS Controls, CMMC, DORA, NIS2, and now Continuous Threat Exposure Management (CTEM) all provide valuable guidance and describe desired outcomes. The challenge is that most stop at the “what.” They rarely explain the “how.” That is not a criticism. It is by design. Frameworks establish principles, define expectations, and describe desired outcomes. They are not implementation guides. As a result, security leaders and practitioners are left figuring out how to translate principles into processes, assign ownership, establish accountability, and measure success. Those decisions often determine whether a framework delivers results or becomes another initiative that never moves beyond good intentions.
Most organizations assume remediation reduces risk. It’s a reasonable assumption. A vulnerability is identified, a patch is applied, the scanner comes back clean, and the ticket is closed. The workflow is complete, the metrics improve, and the issue is considered resolved. The problem is that attackers don’t care about remediation workflows. They care about outcomes. A scanner may no longer report the vulnerability, but those activities do not matter if an attacker can still achieve the same objective through the same attack path, excessive privileges, or a different weakness that was never addressed in the first place. Many security programs measure whether work was completed, but they don’t always measure whether risk was actually reduced.
OnlyFans creators are used to posting adult videos of themselves online, but what happens if someone takes control of their images and uses them for fraud? This week, USA Today revealed how criminals are impersonating OnlyFans creators using AI tools. They use deepfake content to lure the real models’ fans with fake promises of live chats, and then ghost them after the followers pay up in advance. How the catfishers hook their bait This is a form of catfishing , in which an attacker impersonates someone online and engages in romantic or sexual interactions for ulterior motives. In this case, the scammers create fake accounts on platforms like TikTok, using material lifted from a real creator’s photos and given a synthetic voice. They’ll use that to nudge viewers into a direct message conversation on services like Snapchat.
Shortly after OpenAI publicly acknowledged the Hugging Face breach on July 21, Reuters journalist Raphael Satter called me for comment on a story which would reveal shocking new details about OpenAI’s “rogue model” incident: The agent hadn’t just slipped its leash for a few hours, as many assumed, but had in fact been wreaking havoc for days without the company’s knowledge. When I hung up, I immediately called a close friend who has worked inside frontier‑AI labs since before the term even existed. When she heard the timeline, she was stunned. In her view, “If proper industry regulations were in place, those four days would be grounds to terminate OpenAI’s R&D GPU clusters until they get a full independent audit.”
Michigan dispensary faces sanctions after blocking Flock camera with “No Flock Zone” sign Cybernews
The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing Artificial Intelligence (AI) systems. From August 2, what you’ll likely notice are more “this is AI” labels, clearer rules for powerful foundation models, and new ways for users and researchers to complain when systems go off the rails. The AI Act moved from theory to practice for three big areas: • General‑purpose AI (GPAI) models: The new AI Office in Brussels, together with national regulators, can now enforce rules on providers of general‑purpose AI models (think large language models and other foundation models behind many tools).
When a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out.
Black Hat USA returns to Mandalay Bay in Las Vegas this August, bringing together security practitioners, researchers, and leaders from around the world. Rapid7 will be there in the Business Hall, with new capabilities, live demonstrations, expert-led sessions, and two days of activities at the Border Grill . This year, our focus is preemptive security: helping security teams anticipate credible risk, respond at machine speed, and maintain an accurate view of their security and compliance posture as their environment changes. Visit the Rapid7 booth at Black Hat USA You can find Rapid7 at booth #2445 in the Mandalay Bay Business Hall, open and running on the following days and times: • Tuesday, August 4: 4:00–7:00 p.m. • Wednesday, August 5: 9:00 a.m.–6:00 p.m. • Thursday, August 6: 9:00 a.m.–4:00 p.m.
Socket is a launch sponsor of the new Composer and Packagist sponsorship program , announced by Nils Adermann, Jordi Boggiano, and the team that keeps PHP's package infrastructure running. Like many other widely used open source registries, Packagist has been under mounting pressure to sustain critical infrastructure as the demands on it grow. "Usage keeps rising, supply chain attacks have increased in both frequency and sophistication, regulatory and compliance requirements around software supply chains are expanding, and AI accelerates both legitimate consumption and attacks," Packagist founders Adermann and Boggiano said. For the first time, Packagist is expanding its funding beyond Private Packagist, the maintainers' own commercial product, which has covered most of the cost along with donated infrastructure.
The U. S. federal consumer watchdog said Hims & Hers, which prescribes for sexual wellness and mental health conditions, used website trackers to share customers' information with advertisers.
Proving a Negative How do you prove a negative in cybersecurity? How do you prove that you weren’t attacked, or that there is no intruder in your network? These are questions that security teams have been forced to ask for a while, but there is a new question that is becoming increasingly common: How do you prove that files weren’t stolen from your network? Or, even more of a challenge, how do you prove that files weren’t stolen from your partners, vendors, or their partners or vendors? This is a surprisingly challenging question to answer. Finding the answer is also more difficult because data governance has not been the traditional purview of security teams. Data governance has long been thought of as a compliance problem, unfortunately that is no longer the case. Security teams are now, whether they want to be or not, need to consider data governance.
Executive Summary The United States (US) will almost certainly remain at heightened threat from physical threat activities conducted by homegrown and domestic violent extremists (HVEs and DVEs, respectively) during the next twelve months. Since the last installation of this report in July 2025, there has been a substantial increase in mass-casualty attacks and attack plots by Islamic State (IS) supporters, assassinations and attempted assassinations of US government officials and high-profile public figures by anti-government and anti-authority violent extremists (AGAAVEs), and multiple plots by anarchist violent extremists (AVEs) to cause substantial damage to facilities using destructive devices.
Amazon Web Services (AWS) is excited to announce that the latest version of Information Security Registered Assessors Program (IRAP) report (Phase 1a – full assessment) is now available through AWS Artifact . An independent Australian Signals Directorate (ASD) certified IRAP assessor completed the IRAP assessment of AWS in June 2026. The new IRAP report includes four additional AWS services that are now assessed at the PROTECTED level under IRAP. This brings the total number of services assessed at the PROTECTED level to 167. The four newly assessed services are: • Amazon Bedrock AgentCore • AWS Parallel Computing Service • AWS Resilience Hub • AWS Security Incident Response For the full list of services, see the IRAP tab on the AWS Services in Scope by Compliance Program page.
Compliance has become one of the biggest operational drains on modern security teams. CISOs are being asked to manage a growing sprawl of frameworks, prove control effectiveness more often, respond to more customer assurance requests, track risk across a growing web of third parties, and give executives and the board a clearer answer on whether cyber risk is actually going down. Most of that pressure does not come from the frameworks themselves. It comes from the way compliance is still handled in many organizations, with security work happening in one set of tools and governance, risk, and compliance workflows managed somewhere else. Security teams detect exposures, investigate threats, validate risk, and drive remediation in active systems.
Claudia Zoon is Senior Manager, Channel Sales at Rapid7. Across Belgium, the Netherlands, and Luxembourg, organizations are accelerating digital transformation through AI, cloud adoption, and increasingly connected business operations. These investments are creating new opportunities for innovation, but also reshaping the cybersecurity landscape. In this dynamic environment, Rapid7 is excited to announce an expanded strategic distribution partnership with Exclusive Networks across the Benelux region. Why now? Because as organizations grow, so too do the expectations of security teams. As attack surfaces expand, more sophisticated AI-enabled threats emerge; as compliance requirements evolve, leaders expect security to scale right along with the business – all without adding unnecessary complexity.
AWS Security Assurance Services is announcing the release of the Cloud Security Alliance (CSA) Compliance Guide on Amazon Web Service (AWS) , a new resource that maps the 17 control domains and 207 control objectives of the Cloud Controls Matrix v4. 1 (CCM) to AWS services and recommended implementation practices. The guide is intended to help organizations using AWS plan, implement, and evidence the controls relevant to their CCM scope, including those pursuing or maintaining CSA STAR certification. What is the Cloud Controls Matrix? The Cloud Security Alliance is a not-for-profit organization dedicated to defining and raising awareness of best practices for cloud security. AWS maintains CSA STAR Level 2 certification , which couples the requirements of ISO/IEC 27001:2022 with the CCM.
Key takeaways • You can only review what you collect. Review doesn’t create evidence; it reveals evidence that was collected. If critical data isn’t acquired during collection, it won’t exist for investigators or attorneys to find later. • The goal is the relevant data, not more data. Targeted collection and thoughtful culling help teams avoid over-collection while still capturing what matters, and effective discovery scoping balances date and time ranges, data types, and context. • The depth of your collection determines the depth of your evidence. A full file system extraction reaches the encrypted apps and system-level artifacts that prove who was behind a device, and mobile and cloud are increasingly where the evidence lives. • Engage digital forensics early.
Threat intelligence is becoming more powerful and more accessible than ever. As the industry evolves, so do the questions surrounding how intelligence should be collected, shared, and used responsibly. That’s why we’ve completed our annual update to Flare Policy on Ethical Use of Threat Intelligence. This policy describes the principles that guide how we collect, structure, protect, and make threat intelligence available across our platform. It also explains the safeguards we use to help ensure that threat intelligence supports legitimate cybersecurity objectives while respecting privacy, human rights, and responsible governance. The latest update reflects how both the threat landscape and regulatory expectations continue to evolve.
The export controls imposed on Anthropic’s Fable model mark a significant shift in United States (US) artificial intelligence (AI) policy. The controls set a precedent for treating frontier AI models as strategic assets rather than ordinary software products, creating uncertainty for enterprises adopting advanced AI. Security leaders should respond by investing in resilient, interoperable AI strategies rather than simply chasing the most powerful model available. The Saga of the Fable Export Controls Because the US is home to most of the companies building leading models, US AI policy has an outsized impact on global access. The Trump administration’s public posture on AI has largely favored accelerating the frontier.
A fast-growing scam impersonates city and county planning departments, sending property owners real-looking invoices for fake permit fees and pressuring them to wire payment on a deadline. Because the victim authorizes the transfer, payments commonly clear the behavioral checks built to catch fraud, making beneficiary accounts one of the most reliable signals to track this campaign. Research from CYBERA, the partner behind Recorded Future® Money Mule Intelligence, maps a single active ring down to the verified accounts it used, and shows why direct, fraudster engagement and account-level intelligence catches what scoring misses. The FBI sounded the alarm. Issuers still can't see it On March 9, 2026, the FBI's Internet Crime Complaint Center issued a public alert about criminals impersonating city and county officials to collect fraudulent planning and zoning permit fees.
Hey there, I hope you’ve been doing well! 🤘 Hackathon This week Semgrep friends have flown in from all over the world to crazily build together. Engineers, security researchers, designers, and, as we are generous of spirit, even product managers. The fact that we do this every few quarters is one of my favorite things about Semgrep. A number of our coolest features came from a hack week: new engine features, AI triage before it was cool, and even Semgrep itself (back before that was the company’s focus, or name). I also really appreciate the in person time for learning about who people are outside of work.
Hey there, I hope you’ve been doing well! 😅 Bug Hunters Be Like I was going to open with a fun, personal story, but then I got caught up trying to cover a round-up of what a bunch of folks are saying about Mythos and frontier of LLM-driven vulnerability discovery, and now it’s past midnight 😅 So for now I leave you this meme, H/T buherator : Sponsor 📣 (Free!) Community Edition: Ready your attack surface for AI with runZero Gearing up for a deluge of AI-powered exploits? You’re gonna need fast, accurate visibility into all your assets.
It was great to attend the 39C3 - Power Cycles in Hamburg this year. The Chaos Communication Congress was once again packed with great talks, amazing people, awesome events and side quests - and I even got to present! You can watch the talk with translation options on media. ccc. de . I also uploaded the English version to the Embrace The Red YouTube channel. I hope it’s interesting and helpful. The talk is titled “Agentic ProbLLMs: Exploiting AI Computer-Use and Coding Agents” and is about my security research on vulnerabilities in agentic systems and the Month of AI Bugs with lots of demos.
Ghosts in the Machine: The Fight for Privacy After Death Photo: Panyawat Auitpol / Unsplash In the early hours of 6 June 2020, Nicole Smallman and her sister Bibaa Henry had just finished celebrating Bibaa's birthday with friends in a park in London. Alone and in the dark, they were both fatally and repeatedly stabbed 36 times. Guest Contributor Please welcome Peter Marsden as a first-time guest contributor! Privacy Guides does not publish guest posts in exchange for compensation, and this tutorial was independently reviewed by our editorial team prior to publication. But the police didn’t just fail them in life—they failed them in death too. PC Deniz Jaffer and PC Jamie Lewis, both of the Metropolitan Police, took selfies with the dead bodies of the victims, posting them on a WhatsApp group. And no privacy laws prevented them from doing so.
Chat Control Must Be Stopped, Act Now! Illustration: Em / Privacy Guides • Photo: Ramaz Bluashvili / Pexels If you've heard of Chat Control already, bad news: it's back. If you haven't, this is a pressing issue you should urgently learn more about if you value privacy, democracy, and human rights. This is happening right now, and we must act to stop it right now. Take a minute to visualize this: Every morning you wake up with a police officer entering your home to inspect it, and staying with you all day long. The agent checks your bathroom, your medicine cabinet, your bedroom, your closets, your drawers, your fridge, and takes photos and notes to document everything. Then, this report is uploaded to the police's cloud. It's "for a good cause" you know, it's to make sure you aren't hiding any child sexual abuse material under your bed. Every morning. Even if you're naked in bed.
Part of my default test cases for coding agents is to check how MCP integration looks like, especially if the agent can be configured to allow setting fine-grained controls for tools. Sometimes there are basic security controls missing. Especially when running an agent on your local computer. Stakes are much higher. And it seems important to empower users to be able to configure which actions an AI should be able to take automatically, and which ones should be suggestions that the user reviews before executing.
July 1, 2025 DF/IR: This *Stuff* Isn’t For Everybody "Difficulties strengthen the mind, as labor does the body.” -Seneca Letters from a Stoic Some of those who have been reading my posts and other ramblings on LinkedIn and X know that I’m still fortunate enough to keep in touch with the law enforcement community through teaching active shooter response for a Nationwide training provider. In this notably specialized “side-hustle”, which is no doubt a departure from DF/IR (don’t worry – I’ll get there), I have the opportunity to connect and work with professionals from law enforcement and military circles, many of whom I stand in awe because of what they’ve been able to accomplish in their careers through mental toughness, physical conditioning and honing their craft to surgical precision.
This week, the theme is API authorization gone wrong. Guest contributor Rob Spectre kicks off a new interview series exploring real-world authorization failures. We also dive into case studies with key lessons for API security teams, including a look at the missteps that led to a £2. 3M fine for 23andMe, and data exposure from the Asana MCP. Finally, we highlight a new resource on securing OAuth for cloud native APIs. Case Study: True Nightmares of Authorization By guest contributor Rob Spectre , DevRel at Oso. It’s 5:45pm on a Friday. A small uptick in HTTP 400s and 500s pops up on an internal customer management tool. Within the hour, the entire engineering team at a hypergrowth startup scrambles to respond to a security intrusion – one that this technical leader will never forget.
June 1, 2025 Checks & Balances in DF/IR " Freedom is not secured by the fulfilling of one’s desires, but by the removal of desire where it is not appropriate. " -Epictetus Discourses AUTHOR’S NOTE : As some of you may have seen, I was away for the first of the month, so I posted a place-holder for this article. My apologies… I was out seeing some of our beautiful country. One of the benefits to writing, speaking & posting regularly is that I have the built-in opportunity to network with other DF/IR professionals. I’m also fortunate that I can combine these activities with things that are of value to me professionally and to my employer. What inevitably comes from these networking opportunities are conversations on a litany of topics that affect our practice areas.
The Background…and NIST’s Plan for Improving IoT Cybersecurity The passage of the Internet of Things (IoT) Cybersecurity Improvement Act in 2020 marked a pivotal step in enhancing the cybersecurity of IoT products. Recognizing the increasing internet connectivity of physical devices, this legislation tasked NIST with developing cybersecurity guidelines to manage and secure IoT effectively. As an early building block, we developed NIST IR 8259, Foundational Cybersecurity Activities for IoT Device Manufacturers, which describes recommended activities related to cybersecurity for manufacturers
This week we’re celebrating National Small Business Week—which recognizes and celebrates the small and medium-sized business (SMB) community’s significant contributions to the nation. SMBs are a substantial and critical part of the U. S. and global economic and cybersecurity infrastructure. According to the U. S. Small Business Administration’s Office of Advocacy, [1] there are 34. 8 million SMBs in the United States (making up 99% of all U. S. businesses). Of those, 81. 7% are non-employer firms with no paid employees other than the owners of the business. These businesses, though small in size
May 1, 2025 Due Diligence In The Search For & Practice of Digital Forensics "If someone is able to show me that what I think or do is not right, I will happily change, for I seek the truth, by which no one was ever truly harmed. It is the person who continues in his self-deception and ignorance who is harmed." -Marcus Aurelius Meditations There’s been a lot of chatter lately about the qualifications, credentials, experience, education and credibility of digital forensic practitioners. If you don’t know what I’m talking about, I suggest searching on LinkedIn or other related platforms. Notably, a longtime practitioner in the Midwest has recently been placed under investigation by the FBI for essentially perjuring himself with regard to many of these listed characteristics, a definite bellwether for bad tidings and a position I don’t think anyone reading this post would want to be in.
April 1, 2025 The Business of Digital Forensics & Incident Response: A Brief Guide For Law Enforcement & Private Sector Practitioners "It is not from the benevolence of the butcher, the brewer, or the baker that we expect our dinner, but from their regard to their own interest." -Adam Smith The Wealth of Nations I read a lot of your posts. Yes, yours. Virtually all of you in DF/IR, in the practice both in and outside of law enforcement. A bunch of you in professional litigation support and incident response services. Those of you who run, operate and work with digital forensic teams across the US and across the World. I read the posts about the psychological toll that DF/IR work can take on a person. I read the posts about the new artifacts that are discovered in iOS. I read the deep-dives into location data and SEGB files.
The Pyramid of DF/IR Expertise "First say to yourself what you would be; and then do what you have to do." -Epictetus I woke up one day and realized I’m an Executive at a Nationwide Digital Forensic & E-Discovery professional services firm. How did that happen? I also woke up one day and realized I have 25 years in the justice system. If I’d stayed in law enforcement, I could retire this year. All of these things are simultaneously shocking and sobering. They cause one to really reflect on the steps that it took to get them to where they have arrived. It also causes one to take inventor of all of the opportunities, successes, mistakes, failures, training, experience, case work and daily practice – both mental and practical – that go into building a body of work. It also makes one feel old all of a sudden, but “old(er)” doesn’t have to equal bad, as I’ve come to learn.
As the year comes to a close, NIST continues to engage with our international partners to strengthen cybersecurity, including sharing over ten new international translations in over six languages as resources for our stakeholders around the world. These efforts were complemented by discussions on opportunities for future enhanced international collaboration and resource sharing. Here are some updates from the past few months: Our international engagement continues through our support to the Department of State and the International Trade Administration (ITA) during numerous international
This week, we look at the growing number of penalties that companies can now face in the event of a data breach. We also learn about critical API vulnerabilities discovered in Cisco and Traccar products. VicOne recently published a white paper on automotive API security, and we also want to highlight a LinkedIn post on the crucial role of APIs in the financial sector. Article: Costly Breaches at National Public Data and T-Mobile National Public Data (NPD) in the US has been in the news recently due to a massive data breach. A report by BiometricUpdate. com indicates a breach that includes 272 million Social Security numbers. While the cause of the breach remains unclear, a recent update from KrebsOnSecurity suggests that a sister site to NPD may have accidentally published its own site passwords in a publicly accessible file.