Cybersecurity Archives - 91̽ /category/cybersecurity/ Startup News UK and Tech News UK Wed, 29 Jul 2026 13:51:41 +0000 en-GB hourly 1 https://wordpress.org/?v=7.0.2 /wp-content/uploads/2023/04/cropped-techround-logo-alt-1-32x32.png Cybersecurity Archives - 91̽ /category/cybersecurity/ 32 32 Sweet Security Brings Autonomous Protection To The AI Enterprise With New Blocking Capabilities /cybersecurity/sweet-security-autonomous-protection-ai-enterprise-new-blocking-capabilities/ Wed, 29 Jul 2026 13:51:03 +0000 /?p=156112 -Content by CyberNewswire- Sweet Security, the proactive runtime enforcement company for cloud and AI, today announced its further expansion into...

The post Sweet Security Brings Autonomous Protection To The AI Enterprise With New Blocking Capabilities appeared first on 91̽.

]]>
-Content by CyberNewswire-

, the proactive runtime enforcement company for cloud and AI, today announced its further expansion into AI security with Agentic AI Blocking. Sweet now blocks rogue agent behavior in real time – extending Sweet’s runtime enforcement from the cloud to the AI agents that are acting alongside it.

Eighty percent of the world’s businesses are already AI enterprises, and their agents take on identities, reach sensitive data, and act on their own. Yet no one verifies that the behavior an agent carries out is the behavior that was intended. Every other security tool detects and alerts; by the time a team reads the alert, the agent has already acted.

“AI has collapsed the cost of attack, and it has put autonomous software inside the enterprise. Someone has to decide, in the moment, what an agent is allowed to do,” said Dror Kashti, CEO and co-founder of Sweet Security. “When an agent reaches for data it shouldn’t touch, Sweet stops the action red-handed and provides the team one line: here is what we found, and here is how we stopped it. Nothing bad happened, and nothing is waiting in a queue. That is what lets an enterprise adopt AI with confidence.”

Among Sweet’s new Agentic AI Blocking capabilities:

  • Terminates unauthorised tool calls and sessions at runtime
  • Stops secrets, PII, and sensitive data from leaving through an agent
  • Blocks prompt injections live, before they steer an agent off course

What empowers Sweet customers to use its autonomous protection is its confident runtime knowledge. The Sweet Learning Loop continuously Attacks, Fixes and Defends, leveraging Sweet’s runtime reasoning layer that analyses over one billion runtime events daily to learn what every application and agent is intended to do.

Because Sweet holds each one to a simple bar, “do exactly what your creator intended and nothing more,” it can enforce decisively without breaking live production.

The market is converging on the same conclusion. Leading industry analysts now describe runtime inspection and enforcement as a mandatory capability for securing AI agents, and expect the winners in agent security to be products that automatically prevent risky agent behavior rather than surfacing more dashboards and alerts. Sweet goes further, enforcing across cloud and AI together in a single platform.

Sweet already enforces protection at extreme scale, including at Zoomd, where the platform protects tens of thousands of cloud applications in an environment where disruption is measured in market impact.

“Sweet gave us the confidence to adopt AI across the business,” said Niv Sharoni, CTO at Zoomd. “With most tools, you find out about bad behavior in a report after the damage is done. With Sweet, it’s blocked in runtime, the moment it happens. That’s the difference between monitoring risk and actually removing it.”

-This is a paid press release published via CyberNewswire-

The post Sweet Security Brings Autonomous Protection To The AI Enterprise With New Blocking Capabilities appeared first on 91̽.

]]>
Hackers Could Hijack Your Car Using Bluetooth – What Happens Once They’re In? /cybersecurity/hackers-hijack-car-bluetooth-risk/ Mon, 27 Jul 2026 09:05:57 +0000 /?p=155766 A security flaw affecting an aftermarket anti theft device installed in more than two million vehicles has put Bluetooth security...

The post Hackers Could Hijack Your Car Using Bluetooth – What Happens Once They’re In? appeared first on 91̽.

]]>
A security flaw affecting an aftermarket anti theft device installed in more than two million vehicles has put Bluetooth security in modern cars back in the news.

Popular Science reported that researchers from the University of California, San Diego found they could exploit a weakness in the KARR Security System, a device installed by many dealerships, to unlock doors, flash headlights, sound the horn and stop a vehicle from starting if its engine was already switched off.

The device was originally sold to dealerships as an anti theft tool, making the discovery an ironic one. Researchers found they could communicate with the system over Bluetooth using a custom built application, turning a security feature into a way of gaining access to a vehicle.

KARR Security said it has not seen criminals use the vulnerability to steal cars. The company also released a firmware update on 20 July after learning about the issue from researchers in January 2025.

“Researchers at UC San Diego identified a vulnerability affecting BLE based auto theft devices, including a small percentage of KARR devices with certain Bluetooth related components,” KARR Security told Popular Science. “The vulnerability described in the research is highly complex and presents a low risk to customers under real world conditions.”

The company added, “Nevertheless, we responded promptly and developed a firmware update to address the issue.”

How Does The Bluetooth Hijack Work?

According to Popular Science, the vulnerability comes down to one authentication key shared across every KARR device. Once researchers gained access to one unit, they could communicate with any other device using that same key.

The attack does not let someone start a vehicle using only a phone. Researchers showed that an intruder could unlock the doors over Bluetooth and then use locksmith key cloning tools available online to extract a key from the vehicle’s computer before starting the engine.

Jerry Yu, who worked on the research at the University of California, San Diego, said, “Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth device inside the vehicle, and make it unlock car doors.”

Stefan Savage, a computer science professor at the University of California, San Diego, told Wired that the KARR flaw is “probably the worst” car hacking threat he has seen.

Who Could Be At Risk?

Many drivers may not even know the device is installed because Popular Science reported that dealerships often fitted the KARR Security System before selling vehicles and then offered buyers access to its features as a paid extra. Drivers who declined the service often kept the hardware installed inside the vehicle.

That means many owners may have a vulnerable device connected to their car without ever using it. Anyone who bought a used vehicle during the past nine years could also have inherited the system without realising it.

Aaron Schulman, senior author of the research from the University of California, San Diego Department of Computer Science and Engineering, said, “Many car owners don’t even know that their vehicle is vulnerable. So we wanted to make sure they were aware by publishing this study.”

Drivers can look for a KARR or SWDS sticker on the driver’s side window or a small blinking button beneath the dashboard. Anyone with an active KARR account can install the latest firmware through the company’s app. Owners who never activated the service can also update the device using the app and the last eight digits of the vehicle identification number.

KARR Security told Popular Science, “Active customers may apply the update directly from their phone after securely logging in to the KARR Security app. Vehicle owners of non active systems can still update via the app using their VIN (last 8 digits) as a validation step.”

Schulman also suggested every affected owner should install the update, saying, “This update needs to be installed even if you are a vehicle owner who didn’t activate the system when you bought your car at the dealership.”

Have We Seen Bluetooth Security Flaws Before?

The findings bring back memories of a guide Kaspersky wrote in August last year after researchers disclosed a different Bluetooth vulnerability called PerfektBlue.

That research examined infotainment systems using OpenSynergy Blue SDK software, which Kaspersky said is installed in around 350 million vehicles from manufacturers including Ford, Mercedes Benz, Skoda and Volkswagen.

According to Kaspersky, attackers would first need to pair a device over Bluetooth. If successful, they could send malicious commands to the infotainment system. Depending on the vehicle’s electronic design, this could allow access to information such as contacts stored in the head unit, vehicle location and microphone audio. Kaspersky also explained that, in certain vehicle architectures, access to the CAN bus could theoretically allow someone to interfere with functions such as braking.

The guide explained that most cars ask drivers to approve new Bluetooth connections, making unexpected pairing requests worth treating carefully. Kaspersky also advised owners to install the latest firmware supplied through manufacturers and dealerships because software updates released by OpenSynergy first need to reach car makers before they can reach drivers. Another option is to switch off in car Bluetooth when it is not needed.

Bluetooth attacks against cars are rare, but these two pieces of research tell us that wireless connections deserve the same care as any other connected device. Regular software updates and making sure to decline unexpected Bluetooth pairing requests are good ways for drivers to keep their vehicles protected.

The post Hackers Could Hijack Your Car Using Bluetooth – What Happens Once They’re In? appeared first on 91̽.

]]>
Fake Claude Desktop Ads Hit 29 Organisations With Data-Stealing Malware /cybersecurity/fake-claude-desktop-ads-hit-organisations-data-stealing-malware/ Fri, 24 Jul 2026 14:49:27 +0000 /?p=155735 Cybersecurity firm Huntress has uncovered a malvertising campaign that used a fraudulent listing hosted directly on Anthropic’s Claude.ai domain to...

The post Fake Claude Desktop Ads Hit 29 Organisations With Data-Stealing Malware appeared first on 91̽.

]]>
Cybersecurity firm Huntress has uncovered a malvertising campaign that used a fraudulent listing hosted directly on Anthropic’s Claude.ai domain to trick users into downloading a data-stealing trojan disguised as the Claude Desktop app.

According to a blog post published by Huntress, at least 29 organisations were affected between 21 and 22 July after employees searched for the Claude desktop app on Bing and clicked what looked like a legitimate sponsored link.

Rather than leading straight to a fake external site, the link pointed to a public “Artifact”, a shareable file or mini webpage that anyone can publish on Claude.ai. The malicious page redirected users to an attacker-controlled site where they downloaded a fake ClaudeDesktop.exe installer, which ultimately delivered the SectopRAT stealer. Huntress has dubbed the campaign “FakeAgent.”

Because the initial link sat on Anthropic’s own domain, it carried an unusual degree of trust, users had no obvious reason to suspect anything was wrong before the redirect to the attacker’s infrastructure kicked in. Huntress said the page had racked up 7,100 views before it was reported and taken down.

How The Claude.ai Malware Worked

Once installed, the fake app exploited DLL sideloading, smuggling a tampered malicious file alongside a legitimate, signed executable so the malicious code runs under the guise of a trusted programme. In this case, the attackers abused a genuine JetBrains component to load their payload.

The malware was wrapped in commercial protection software to resist reverse engineering and built in checks, including scanning a machine’s graphics hardware and running timing tests, designed to detect whether it was running inside a virtual machine or analysis sandbox, in which case it would refuse to execute.

Command-and-control instructions were hidden inside blockchain transactions on the Ethereum network, a technique known as “EtherHiding” that makes it far easier for attackers to relocate their infrastructure without losing control of infected machines.

Once decrypted, researchers found the payload matched, or was closely derived from, SectopRAT, a remote access trojan capable of harvesting saved passwords, browser cookies, autofill data, credit card details and files from an infected computer.

Huntress said its own analysts used Claude to help work through some of the more complex reverse-engineering steps during the investigation, including rebuilding parts of the encryption scheme used to protect the malware’s payload.

Investigators also linked the campaign’s registration details to a threat actor behind a similar fake Docker Desktop scam earlier this year, and to infrastructure previously seized as part of Microsoft’s Operation Endgame, an international operation targeting malware distribution networks.

Anthropic Response

Huntress reported the malicious artifact to Anthropic, and the page had been removed by the time the report was published.

The Bigger Picture

The incident highlights a growing trend: as AI tools surge in popularity, their official domains and platforms are becoming attractive targets for malvertising and content abuse, since a link on a trusted domain can bypass the instinctive caution users apply to unfamiliar sites.

Huntress urged users to be cautious with sponsored search results, even ones that appear to point to legitimate domains, and to verify software downloads through official channels rather than search ads.

The post Fake Claude Desktop Ads Hit 29 Organisations With Data-Stealing Malware appeared first on 91̽.

]]>
How AI Slop Is Forcing GitHub To Close Its Doors /cybersecurity/how-ai-slop-is-forcing-github-to-close-its-doors/ Fri, 24 Jul 2026 12:28:19 +0000 /?p=155725 From 27 July 2026, GitHub plans to give public security researchers a rather abrupt reality check on what they can...

The post How AI Slop Is Forcing GitHub To Close Its Doors appeared first on 91̽.

]]>
From 27 July 2026, GitHub plans to give public security researchers a rather abrupt reality check on what they can earn.

Compensation for public researchers drops at every level, capping critical discoveries at $10,000 rather than $30,000 and high-severity findings at $5,000. Medium and low-severity payouts fall to $2,000 and $250 respectively. At the same time, the company is introducing an exclusive VIP programme, directing premium rewards above historical limits to an invited circle of researchers.

GitHub frames the policy change around two specific goals. The internal security team intends to clear away low-value noise to concentrate on critical signals. The second goal is building a structure that serious security professionals find properly lucrative.

A flood of low-effort and AI-generated vulnerability reports has made it impossible to separate legitimate research from automated spam. As the cost of generating a report drops to near zero, the commercial rationale for treating every submission as genuine research disappears.

How Does GitHub Choose Its Security Elite?

Standard application forms won’t open this particular door. GitHub issues golden tickets based purely on historical performance, setting the bar at one confirmed critical vulnerability or roughly seven valid low-tier submissions. The company is also enabling HackerOne’s “signal requirement,” which limits how many reports new researchers can submit before they’ve established a history of legitimate findings. Existing backlog reports will be assessed under the old payout rules.

Structurally, this policy moves the dynamic from an open marketplace of individual reports toward a semi-closed model governed by reputation. Independent researchers without an established track record face worse economics on high-effort work, particularly at the critical end where finding a novel vulnerability can take hundreds of hours. Newcomers are numerically capped on submissions until they demonstrate quality, which reduces the learning-by-doing pathway that many researchers used to build their reputations in the first place.

Analysts have raised concerns about a two-class researcher system. VIP selection criteria are controlled entirely by GitHub, transparency around invitation decisions is limited and there’s a risk that researchers game the system by holding back findings until VIP status is secured.
If the model proves financially effective for GitHub, other large platforms are likely to copy it. The broader public bounty market would shift toward lower public floors and gated premium access.

The Slow Death Of Open Digital Communities Under Infinite Volume

Bug hunters are hardly the only professionals currently watching machine-generated slop pollute their daily workflow.

Academic journals are tightening submission policies and requiring manual identity verification after AI-assisted manuscript factories overwhelmed peer review systems. Legal teams are adding verification layers to manage the volume of AI-drafted discovery documents and filings. Newsrooms are spending more resource on triage of AI-generated pitches than on actual reporting.

Each industry is running into the same wall. Spaces designed around trusted work from dedicated specialists are suddenly buried under cheap volume from users facing near-zero costs to submit content. The community’s quality-control systems, designed for human-scale input, break under machine-scale output. The response is almost always the same: invitation systems, reputation requirements or verified credentials. Communities that were open closed themselves, one gate at a time.

Why GitHub Specifically Matters

GitHub hosts a large share of the world’s open-source software supply chain. How it structures incentives for finding and reporting vulnerabilities has effects beyond its own products. If high-value vulnerability hunting becomes effectively invite-only at major platforms, the distribution of who discovers and discloses critical bugs over time could narrow. This policy influences talent diversity, the speed of bug disclosures and where priced-out researchers ultimately go.

The problem is an authentication gap that closing access doesn’t solve. Most submission systems were built on the assumption that the effort required to produce good work was itself a filter. Remove that effort barrier with AI tools and the filter disappears. Invite-only tiers replace the effort filter with a reputation filter, which works for researchers who already have reputations and makes it more challenging for new ones to develop them. The AI-slop problem gets managed, the access problem it creates is inherited.

The post How AI Slop Is Forcing GitHub To Close Its Doors appeared first on 91̽.

]]>
Are Home Routers Europe’s Most Dangerous Cyber Vulnerability? /cybersecurity/are-home-routers-europes-most-dangerous-cyber-vulnerability/ Wed, 22 Jul 2026 12:45:38 +0000 /?p=155592 European regulators have spent two years building a sprawling legal fortress against advanced technology. The AI Act, the Cyber Resilience...

The post Are Home Routers Europe’s Most Dangerous Cyber Vulnerability? appeared first on 91̽.

]]>
European regulators have spent two years building a sprawling legal fortress against advanced technology. The AI Act, the Cyber Resilience Act and ongoing debates over platform oversight all target future risks. Meanwhile, the actual threat hitting ordinary households today is sitting on the router table, connected to the Wi-Fi and ignored.

The router serves as the ultimate gateway for the modern household. Positioned at the network perimeter, it directs the full spectrum of daily activity, carrying confidential corporate VPN traffic alongside personal media streams. According to ENISA, the EU’s cybersecurity agency, a large proportion of routers across Europe are running outdated firmware, weak or default credentials and exposed remote management interfaces that can be reached from outside the network. None of the devices tested in Fraunhofer’s router security studies were free of security flaws, and some had gone years without receiving a firmware update.

The True Cost Of An Exposed Home Gateway

Compromising a smartphone or laptop exposes a single target. Compromising a router places an attacker squarely between every home device and the outside world. From there, traffic can be intercepted, credentials captured, DNS queries redirected and connections observed without the end user seeing any indication that anything is wrong.

The expansion of remote work escalates the threat to a whole new level. Home networks now process confidential business emails, authentication keys and corporate database traffic as well as personal browsing. This puts domestic hardware firmly on the corporate security frontline. Intercepted credentials from a home gateway open pathways into corporate infrastructure. Attackers gain a position from which sensitive enterprise networks can be reached.

ENISA notes that routers face active exploitation in the wild, meaning a single flaw in a popular firmware component instantly threatens millions of devices worldwide. Botnet operators have used compromised home routers as infrastructure for DDoS attacks and mass credential harvesting for years. The devices are attractive precisely because they’re always on, rarely monitored and seldom updated.

The Broken Incentive Structure Of Router Hardware

The problem starts with how routers reach homes in the first place. Most consumer electronics are bought by the person who uses them. Many routers are provisioned by ISPs and handed to customers as part of a broadband package. The update cycle depends on the ISP’s relationship with the hardware manufacturer and the manufacturer’s willingness to maintain firmware for devices that may have been in the field for five or six years.

Europe’s device market is also highly fragmented. Dozens of manufacturers, hundreds of models, varying firmware bases and different ISP deployment relationships make consistent governance across the continent extremely difficult. The Cyber Resilience Act will impose security requirements on connected products. The enforcement timeline and the long tail of devices already in the field mean existing security gaps might persist for years regardless.

End users are also limited in what they can do. Changing a router password is within most people’s reach. Auditing firmware versions, disabling exposed management interfaces or verifying that automatic updates are enabled is not. The security posture of a home router depends almost solely on decisions made by the ISP and the manufacturer, not the person paying the broadband bill.

The Disconnect Between Regulation And Reality

Europe has devoted enormous regulatory bandwidth to AI governance over the last two years. The debates have been substantive. But none of that attention has been matched by equivalent urgency on the threat at the literal edge of the network.

The identity exposure data from SpyCloud’s 2026 report showed that compromised credentials remain the primary attack vector for breaches affecting both individuals and organisations. A huge share of those stolen logins stems from network eavesdropping instead of targeted device hacks. The humble home router sits at the centre of this threat.

The unglamorous reality of European cybersecurity is that the most immediate risks to many people and businesses aren’t exotic AI-enabled attacks. They’re default passwords on devices that haven’t been updated since 2019, exposed management interfaces that can be reached from anywhere and a fragmented hardware market that has no consistent mechanism for pushing security fixes to the field. That’s the problem that’s hardest to close, and it’s receiving the least attention.

The post Are Home Routers Europe’s Most Dangerous Cyber Vulnerability? appeared first on 91̽.

]]>
Why Are Businesses Still Paying Ransoms If Hackers Keep Demanding More? /cybersecurity/why-businesses-paying-ransoms-hackers-more/ Wed, 22 Jul 2026 09:10:40 +0000 /?p=155551 Every time a ransomware attack makes the news, the advice is almost always the same and that is: don’t pay...

The post Why Are Businesses Still Paying Ransoms If Hackers Keep Demanding More? appeared first on 91̽.

]]>
Every time a ransomware attack makes the news, the advice is almost always the same and that is: don’t pay the criminals.

It sounds like the obvious choice until a business is locked out of its own systems or staff cannot do their jobs and criminals are threatening to publish confidential information. Because of that, many organisations decide paying is the least painful option.

The issue here is that paying often does not bring the attack to an end…

Proofpoint’s new research found that 58% of UK organisations affected by ransomware paid the attackers. Still, 22% of those that handed over the money received another ransom demand. The company’s findings say that today’s ransomware attacks are no longer a one off event because for many victims, they become an ongoing negotiation.

Why Are Businesses Paying If There Are No Guarantees?

Businesses usually pay because they want the problem to disappear as quickly as possible. They want their systems back online, employees working again and customers looked after.

Criminals know that, and hey also know they have another bargaining chip before they even ask for money.

Proofpoint found that 66% of UK organisations had sensitive data stolen during a ransomware attack. That changes the conversation completely. Even if a business manages to recover its systems, hackers can threaten to leak confidential files unless another payment comes through.

The sis could be seen in Proofpoint’s global research as well. The company surveyed 953 cyber security professionals from 12 different countries and found that 54% of affected organisations paid a ransom and 37% were then asked for more money. Paying, it seems, is no promise that the calls from cyber criminals will stop.

How Are Hackers Getting Through The Front Door?

Forget the image of someone frantically breaking through digital defences – Many ransomware attacks begin with something much less dramatic.

An email lands in an inbox with a link that looks genuine. A message claims to come from a trusted colleague or supplier and instantly, someone clicks.


Proofpoint found that phishing emails or other email based social engineering started 24% of ransomware attacks reported by UK organisations. Malicious links were the most common threat, appearing in 40% of incidents. Across the global research, 47% of ransomware attacks began with a malicious link.

AI is making that job much easier for attackers with around 65% of organisations who were affected by ransomware saying AI made the attack more effective.

Employees are also finding it harder to tell the difference between a genuine message and a fake one. In the UK, 24% of organisations said staff did not suspect the attack because it looked authentic, and 31% said users interacted with malicious content. Of all countries surveyed, 40% said employees trusted AI generated attacks because they looked legitimate.

Ryan Kalember, Chief Strategy Officer at Proofpoint, said, “AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware. Today’s attackers are using AI to create highly convincing phishing emails, malware components like scripts, and credential theft campaigns that exploit human trust at scale. Organisations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications.”

Has Ransomware Become A Different Kind Of Crime?

The old ransomware tricks were not this complex – criminals locked a company’s files and demanded money to unlock them – but Proofpoint’s research says that is no longer enough for many attackers.

Stealing sensitive information gives criminals another way to make money because they can ask for another payment or threaten to publish confidential files or even sell the stolen data somewhere else. Encryption has become one bit of a way bigger operation.

That is why paying a ransom no longer guarantees the problem is over. A business may regain access to its systems, but if attackers have already copied valuable information, they still have something to bargain with.

Kalember said, “AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware. Today’s attackers are using AI to create highly convincing phishing emails, malware components like scripts, and credential theft campaigns that exploit human trust at scale. Organisations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications.”

This may be the biggest lesson from Proofpoint’s research for businesses; paying the first ransom does not always buy an ending because in many cases, it just opens the door to the next demand.

The post Why Are Businesses Still Paying Ransoms If Hackers Keep Demanding More? appeared first on 91̽.

]]>
Can Software Developers Still Trust Their Own Vulnerability Scanners? /cybersecurity/can-software-developers-still-trust-their-own-vulnerability-scanners/ Fri, 17 Jul 2026 09:56:18 +0000 /?p=155292 Trivy is the go-to scanner that developers and security teams trust to clean up their code, containers and dependencies before...

The post Can Software Developers Still Trust Their Own Vulnerability Scanners? appeared first on 91̽.

]]>
Trivy is the go-to scanner that developers and security teams trust to clean up their code, containers and dependencies before anything goes live. Because it’s so widely used and tucked into CI/CD pipelines everywhere, it became a massive target. And in a wild twist, hackers actually managed to sneak malicious code inside the very tool meant to catch it.

Security researchers, including Microsoft, have identified a sophisticated supply chain attack whereby attackers compromised Trivy’s distribution channels, poisoned its GitHub Actions tags and pushed malicious dependencies into the trusted release paths developers rely on. The payload, once executed, hunted for secrets: API tokens, cloud credentials, deployment keys. Anything sitting in a CI/CD run that an attacker could use for follow-on access.

The Ultimate Security Irony: Hiding Malware in Plain Sight

The attack took advantage of a blind spot in how developers view security tools.

Trivy runs inside your pipeline and scans everything it touches, so you treat it as part of your security perimeter, not as something that needs to be verified itself. This assumption is the vulnerability, because attackers didn’t break into systems directly. They compromised the distribution mechanism of a tool already trusted and let their own pipeline do the rest.

The technical path involved poisoning Trivy’s GitHub Actions workflow tags and injecting malicious code into Docker images and repository-level artifacts tied to the same campaign. CI/CD systems that pulled the affected versions would execute the payload automatically, without any human review, because the whole point of a pipeline is to run things automatically. The attacker effectively got a legitimate execution path inside developer environments, carrying the right brand name and appearing in the right place.

The credential harvesting element is worth understanding too. When a CI/CD pipeline is compromised the impact goes beyond a single application as it effectively touches everything downstream: source code repositories, cloud provider accounts, container registries, deployment secrets and third-party API keys. An attacker who walks out with a full set of pipeline credentials hasn’t breached one service. They’ve got the keys to a good portion of the organisation’s infrastructure.

Why Supply Chain Attacks On Security Tools Are Particularly Insidious

Open-source tools have been targeted by supply chain attacks before, and this won’t be the last case. But attacks that specifically target security tools carry a particular logic. The teams most likely to be running Trivy are also the teams most likely to take security seriously. Getting malware past a security-conscious team is hard. Getting it into a tool that security-conscious teams already trust is much easier.

Then there’s the detection problem: if your scanner is actually the malware, it’s never going to find itself. The mechanism meant to catch threats is actually being used to deliver them. This isn’t just theory, it’s the real-world scenario this campaign capitalised on, and it’s a key reason why it took so long to uncover.

Open-source security tools find themselves in a tricky spot. They’re widely trusted and baked into sensitive environments yet they’re often maintained by teams that lack the resources to match their massive attack surface. The answer isn’t to ditch these tools, but to verify them with the same rigour applied to production software.

Securing Your Pipeline After The Breach

Teams hit by the attack took the smart path of rotating all credentials, not just the ones that looked most vulnerable. This demonstrates a simple principle: when the extent of an intrusion is unknown, the effort required to over-rotate is small, the potential damage caused by under-rotating would be enormous.

The incident also highlighted a practice many CI/CD configurations still don’t follow: pinning dependencies to a specific commit hash over pulling by a floating tag. Floating tags mean a pipeline automatically consumes whatever the latest version is, including versions that have been tampered with. The compromise exploited exactly this behaviour.

Tooling distributed via GitHub Actions and Docker registries can be signed, and those signatures can be checked automatically in pipelines. The fact that most teams don’t do this is one reason supply chain attacks remain effective, the Trivy incident gives that gap some consequences.

The big lesson security researchers are drawing is clear: open-source tools need the same integrity verification applied to production software. No tool should earn permanent trust simply by being widely used, and the ones running your security checks are no exception.

The post Can Software Developers Still Trust Their Own Vulnerability Scanners? appeared first on 91̽.

]]>
AI Has Stopped Just Assisting Hackers And Now It’s Running The Attacks /cybersecurity/ai-stopped-assisting-hackers-now-running-attacks/ Thu, 16 Jul 2026 12:15:44 +0000 /?p=155193 Cyber criminals are no longer just using AI chatbots to write a better phishing email. According to Check Point Research’s...

The post AI Has Stopped Just Assisting Hackers And Now It’s Running The Attacks appeared first on 91̽.

]]>
Cyber criminals are no longer just using AI chatbots to write a better phishing email. According to Check Point Research’s newly published , artificial intelligence has moved into the driving seat of real cyberattacks; planning intrusions, writing malware and even making operational decisions with little human input.

The security firm’s second annual AI Security Report, based on incident data and original case studies gathered over the past year, argues that the industry has crossed a threshold. A year ago, Check Point described AI mainly as a “force multiplier” that made existing hacking techniques faster and cheaper. Now, the company says, AI is directly running parts of the attack chain itself.

Breaches Run Largely On Autopilot

The report’s most striking case study concerns a breach of nine Mexican government agencies between December 2025 and February 2026, which exposed roughly 400 million records covering tax, civil registry, vehicle, patient and electoral data.

Researchers say a single attacker typed just 1,088 instructions, which an AI coding assistant turned into 5,317 executed commands across 34 sessions, using Claude Code to explore and break into networks and GPT-4.1 to analyse stolen data.

Notably, when the AI initially refused to assist with the attack, the attacker simply pasted hacking instructions into a configuration file that coding assistants automatically trust at the start of every session, permanently bypassing the safety rules without ever needing a fresh jailbreak prompt. Check Point says this trick is now being sold as a ready-made kit on criminal forums.

A similar pattern showed up in a separate case Anthropic disclosed in November 2025, in which a Chinese state-linked espionage campaign reportedly used Claude Code to handle 80–90% of the tactical work, reconnaissance, exploitation, credential theft and lateral movement, across roughly 30 targeted organisations.

Malware Built In Days Not Months

AI is also reshaping malware development. Check Point Research’s own investigation into “VoidLink,” a sophisticated Linux command-and-control framework, initially assumed it had been built by a multi-person team over several months. It later emerged the roughly 88,000 lines of code had been written by a single developer in under a week, using a commercial AI coding tool.

Similar AI-assisted malware has now been linked to groups including Pakistan-based Transparent Tribe, Russian-linked “GREYVIBE,” and North Korea’s KONNI group, the report says.

Criminals Are Also A Target

The flip side, according to the report, is that AI tools themselves have become a fresh attack surface. Because language models process instructions and untrusted content (web pages, documents, emails) as one continuous stream of text, attackers can smuggle in hidden commands, a technique known as prompt injection.

Check Point’s researchers found roughly 15,300 such hidden payloads planted across a scan of 1.2 billion URLs, with most buried in parts of a webpage a human would never see.

The report also flags weaknesses in the “agentic supply chain”, the plug-ins, configuration files and MCP servers that AI coding tools trust automatically. Check Point’s own researchers discovered vulnerabilities in Claude Code that could let attackers run commands the instant a poisoned project was opened and found that roughly 1 in 13 of a sample of exposed developer configuration files contained live login credentials.

Deepfakes And A Broken Identity System

Elsewhere, the report warns that voice, video and document verification can no longer be trusted as proof of identity. It cites a North Korean-linked scheme using AI-generated resumes and deepfaked identity documents to get operatives hired as remote IT workers inside Western companies, an operation the US Treasury says has funnelled close to $800 million towards weapons programmes.

In a controlled study cited in the report, even people trained to spot AI-generated faces only identified fakes about 41% of the time; ordinary viewers managed just 30%.

Data Leakage Climbing Steadily

On the corporate side, Check Point’s telemetry shows the average organisation now uses about ten different AI applications a month, and that the share of “high-risk” prompts, those containing sensitive corporate, personal or regulated data sent to external AI tools, doubled from 2% to 4% of all prompts over the past year.

What Businesses Should Do

Fred Streefland, Check Point’s Global Field CISO, argues in the report that security leaders need to treat AI risk as a permanent, evolving part of running a business rather than a box to tick once during adoption. His recommendations include treating AI as a “live attacker” when stress-testing defences, gaining visibility into how AI tools and agents are actually being used across the organisation, and applying real-time monitoring to catch sensitive data before it reaches external AI services.

The report lands as AI coding agents and assistants become increasingly embedded not just in software development, but, per announcements from Microsoft and Nvidia cited in the report, directly into consumer operating systems and hardware later this year, a shift Check Point says will only widen the attack surface it has been tracking.

The post AI Has Stopped Just Assisting Hackers And Now It’s Running The Attacks appeared first on 91̽.

]]>
What Does The New European Cyber Evaluation Plan Mean For Software Vendors? /cybersecurity/what-does-the-new-european-cyber-evaluation-plan-mean-for-software-vendors/ Tue, 14 Jul 2026 09:35:42 +0000 /?p=155005 The European Commission has presented its Action Plan on Cybersecurity and AI, a mandate that requires mandatory pre-market security evaluations...

The post What Does The New European Cyber Evaluation Plan Mean For Software Vendors? appeared first on 91̽.

]]>
The European Commission has presented its Action Plan on Cybersecurity and AI, a mandate that requires mandatory pre-market security evaluations and third-party risk assessments for advanced AI software before it can be placed on EU markets. The plan puts frontier AI not as a consumer product requiring labelling and transparency disclosures – which is the EU AI Act’s primary approach – but as an active security risk requiring inspection before deployment.

This distinction holds weight for software vendors. Consumer product regulation asks you to describe what your product does and disclose its limitations. Security evaluation asks whether your product can be exploited, what vulnerabilities it introduces into the systems it connects to, and whether it has been assessed by a qualified third party before it goes on sale. These are different compliance requirements, and for most software vendors operating in the EU, the cybersecurity evaluation pipeline is a new layer that didn’t previously apply to software products.

Mapping The Action Plan’s Mandates

The Action Plan’s mandatory elements cover two main areas. Pre-market security evaluations require vendors to assess their AI systems against defined security criteria before launch, covering vulnerability to adversarial inputs, robustness against manipulation and resistance to data poisoning. Third-party risk assessments apply to vendors whose AI products interact with critical infrastructure, government services or high-risk applications – requiring an independent auditor’s sign-off over self-certification.

The plan integrates with existing EU cybersecurity architecture. The Cyber Resilience Act – which entered into force in late 2024 – already established mandatory security requirements for connected products throughout their lifecycle – while the Cybersecurity Act created the ENISA certification framework. By embedding AI-specific security requirements into that existing structure rather than creating a separate regulatory silo – the AI Action Plan means that compliance teams at software companies must assess their products against a layered set of requirements – instead of a single rulebook.

The categories of software most directly affected are those classified as high-risk under the EU AI Act – AI systems used in employment, education, critical infrastructure management, law enforcement or access to essential services – and AI systems that interact with or are implemented within critical infrastructure as defined under the NIS2 directive. General-purpose AI models with significant capability thresholds also fall within scope. Consumer-facing products like productivity tools, creative applications or recommendation systems are less directly affected unless they cross the high-risk use case thresholds.

Navigating Compliance In Practice

The primary compliance challenge is the third-party assessment requirement. Self-certification – where a vendor assesses its own product against a checklist and signs a declaration of conformity – has been the standard model for most software regulation. Third-party assessment requires engaging an accredited conformity assessment body, preparing documentation sufficient for external review and potentially making architectural or security changes based on the findings. That’s a different order of cost and timeline than standard CE marking or GDPR compliance preparation.

The assessment bodies that will conduct these evaluations are being designated under the existing ENISA and national cybersecurity certification frameworks. Vendors will need to identify which body has competence for their product category in the relevant member state and factor the assessment timeline into their launch planning. Waiting for assessment to clear before launch is a real constraint for companies used to iterative software deployment.

For UK software vendors selling into the EU – the post-Brexit reality is that UK conformity assessment bodies are not automatically recognised for EU certification purposes. Vendors may need to engage an EU-based assessment body or pursue mutual recognition arrangements for their specific product category. This is the same issue that UK manufacturers face for CE marking under the Cyber Resilience Act, and the practical effect is an additional step in the compliance process for UK-origin products entering the EU market.

What Does This Development Signal?

The Action Plan is the clearest signal that the EU is moving toward treating advanced AI software as infrastructure rather than as software-as-a-service. Infrastructure gets regulated before it goes live, assessed by third parties and subject to ongoing obligations that don’t end at the point of first sale. This represents a fundamentally different regulatory relationship than the one software vendors have historically operated under.

The timeline for full implementation of the mandatory requirements isn’t set out in a single hard deadline – different elements come into force as the underlying legislation matures. The Cyber Resilience Act’s requirements apply from 2027 for most products. The AI Act’s phased implementation runs through 2026 and 2027. The Action Plan overlaps with both – requiring vendors to map their specific product categories against both frameworks to determine which requirements apply and on what timeline.

For software vendors with AI features on their roadmaps, building compliance preparation into product development is a necessity rather than a pre-launch checklist. The assessment process for a complex AI system will take months and the findings may require architectural changes that are cheaper to make early. The EU market is large enough that most serious vendors won’t walk away from it. The cost of preparing for a compliance pipeline you didn’t anticipate is higher than the cost of planning for one you knew was coming.

The post What Does The New European Cyber Evaluation Plan Mean For Software Vendors? appeared first on 91̽.

]]>
The Most Active Ransomware Group: Who Are The Gentlemen? /cybersecurity/most-active-ransomware-group-who-are-gentlemen/ Fri, 10 Jul 2026 18:14:15 +0000 /?p=154956 Check Point Research, the threat intelligence arm of Check Point® Software Technologies Ltd., today released its Global Threat Intelligence insights...

The post The Most Active Ransomware Group: Who Are The Gentlemen? appeared first on 91̽.

]]>
Check Point Research, the threat intelligence arm of Check Point® Software Technologies Ltd., today released its Global Threat Intelligence insights for June 2026, revealing that organisations worldwide experienced an average of2,270 cyber attacks per week, representing a10% increase month on monthand a17% increase year on year.

June reversed the brief calm observed in May, with attack volumes rising broadly across regions and sectors. Rather than being concentrated in one geography or industry, the increase appeared almost everywhere at once, suggesting attackers expanded their activity across a wider set of targets.

“June’s data shows a broad rebound in cyber activity, not a single isolated spike,” said Mark Mitchell, security engineer at Check Point Software. “Attackers are widening their reach across regions and industries, while ransomware groups continue to reorganise and scale. The rise of The Gentlemen to the top of the ransomware leaderboard is a clear reminder that new operators can rapidly become major global threats. Organisations need prevention-first, AI-driven security that protects networks, users, data and AI workflows before attacks can cause impact.”

Education, Government And Telecommunications Remain Most Targeted Industries

In June, Education remained the most targeted sector globally, with organisations facing an average of 4,816 weekly attacks, a 16% increase compared with June 2025. Open campus networks, constant device turnover and constrained security resources continue to make schools and universities attractive targets for threat actors.

Government followed with 2,836 weekly attacks, up 5% year on year, while Telecommunications ranked third with 2,835 weekly attacks, a 13% increase. Together, these three sectors continue to absorb a disproportionate share of global attack volume, reinforcing a pattern that has remained consistent across recent months.

Every Region Sees Year-On-Year Growth, Led By Latin America

Latin America remained the most attacked region, with organisations reporting an average of 3,501 weekly attacks, a 27% increase compared with June 2025. APAC followed at 3,060 weekly attacks, up 5%, while Africa recorded 3,008 weekly attacks, down 9% year on year but still among the highest-volume regions globally.

Europe and North America also saw sharp increases, rising 22% and 14% respectively. This broad-based growth indicates that the June rebound was not confined to one market but reflected a wider escalation in attacker activity across the global threat landscape.

GenAI Exposure Holds Steady As Healthcare And Telecommunications Carry The Highest Risk

GenAI-related exposure remained a persistent enterprise risk in June. Check Point Research found that one in every 26 GenAI prompts submitted from enterprise networks carried a high risk of sensitive data leakage, equal to a global exposure rate of 3.9%. High-risk prompt activity affected 85% of organisations that regularly use GenAI tools, while a further 27% of prompts contained potentially sensitive information. Each organisation used an average of seven different GenAI tools over the past month, and the average user generated 78 prompts.

Latin America recorded the highest GenAI exposure rate with 5.2% of prompts carrying a high risk of sensitive data leakage, well above the global benchmark, while Europe matched the global average at 3.9%. By industry, Healthcare and Medical carried the highest exposure at 5.7%, followed by Telecommunications and Business Services at 5.1% each, and Information Technology at 4.1%.

Personal data appeared across 80% of affected organisations, followed by network and infrastructure details, legal and regulatory material, financial data, and employee records, showing that GenAI exposure cuts across multiple business functions.

Ransomware Keeps Climbing With Business Services In The Crosshairs

Ransomware attacks totaled 646 in June, a 33% increase compared with the same month in 2025. Business Services remained the most affected industry, accounting for 31% of reported victims, followed by Consumer Goods and Services at 16% and Industrial Manufacturing at 14%. Government also continued to rise as a share of ransomware victims, increasing from 4.0% in April to 5.4% in June.

Notably, APAC saw a sharp rise in the amount of victims, surpassing Europe and becoming the second most impacted region following North America.

The Gentlemen Overtakes Qilin As The Most Active Ransomware Group

The most significant ransomware shift in June came at the group level. The Gentlemen became the most prevalent ransomware group, responsible for 17% of published attacks, overtaking Qilin, which accounted for 11%. LockBit also recorded a notable increase, rising from 1% of published attacks in May to 7% in June, making it the third most prevalent group.

The Gentlemen’s rapid rise reflects the continued ability of emerging ransomware-as-a-service operations to scale quickly through affiliate recruitment, pre-positioned access and evolving evasion techniques.

The post The Most Active Ransomware Group: Who Are The Gentlemen? appeared first on 91̽.

]]>