Information

Palo Alto Networks Acquires AI Agent Platform Console

Palo Alto Networks (NASDAQ: PANW) on Tuesday announced that it has acquired Console, an AI-native platform designed to help organizations build agentic workflows and automate operational tasks using natural language. The cybersecurity giant said Console will deepen the agentic capabilities of its Cortex platform, allowing security teams to investigate signals, prioritize work, and automatically take action across enterprise environments. Console’s technology enables users to describe an operational objective in natural language, with AI agents then…

Read More

Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit

The researcher known as Nightmare Eclipse has dropped another zero-day — this time a privilege escalation exploit targeting a Kaspersky endpoint security product. Nightmare Eclipse, also known as Chaotic Eclipse, has released PoC exploits for many vulnerabilities in recent months, mainly Windows and Microsoft Defender flaws.  The researcher started dropping zero-days after growing frustrated with Microsoft’s handling of vulnerability reports. While many of the exploits remained at the PoC stage, a few ended up being…

Read More

AI-driven OSINT in the wrong hands – and why everyone could be a target for fraud

It’s getting cheaper and easier for cybercriminals to research potential victims. Here’s what’s still in your control. Phil Muncaster 27 Aug 2026  •  , 5 min. read AI is changing the threat landscape, one model at a time. The pace at which the technology is evolving means activities that once took a skilled cybercriminal several hours or even days to achieve can now be done in a fraction of that time by someone with little…

Read More

Hasbro Data Breach Exposed Employee Personal Information

Toy and game giant Hasbro is notifying employees that their personal information may have been compromised in a data breach. The notifications sent to affected individuals contain little detail, but they indicate that the exposed information, which varies by individual, may include names, email addresses, postal addresses, phone numbers, national ID numbers, and financial information.  The information comes from notification letters that Hasbro submitted to the Massachusetts Attorney General’s Office.  It’s unclear how many individuals…

Read More

In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights:  Developers say Log4j vulnerability alert overblown An Apache Log4j 2 vulnerability…

Read More

ATF Confirms Cyber Incident After Ransomware Group Claims Attack

The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed suffering a cybersecurity incident after the Qilin ransomware group claimed to have targeted the agency. In a statement on its website, ATF said the incident affected a standalone system, which was disconnected after the intrusion was discovered.  “The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF…

Read More

Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear

President Trump issued Executive Order 14420 on Wednesday, declaring a national emergency to mitigate vulnerabilities in the United States’ bulk power system arising from foreign-supplied electrical equipment. The order attributes the heightened emergency status to rapid growth across data centers, AI, advanced manufacturing, and defense production.  Officials noted that dependence on grid reliability magnifies the impact of foreign supply chain disruptions or targeted attacks that exploit built-in backdoors for remote access. The order covers critical…

Read More

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.” The…

Read More

AI Speeds Up Malware Development, Not Its Success Rate: Analysis

Palo Alto Networks’ Unit 42 team analyzed 405 malware samples tied to AI in some way, from ransomware partly written with the help of LLMs to installers that simply borrowed the name of a popular AI app. The researchers found that roughly 97% of the samples in the dataset never left a sandbox, research repository, or internal testing environment to reach a real target. Unit 42 cross-referenced the 405 file hashes against endpoint telemetry, network…

Read More

Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation

The Linux Foundation said Tuesday it will take on governance of TRACE (Trust, Runtime Attestation and Compliance Evidence), a new open specification for producing verifiable evidence of how AI agents and other confidential workloads run.  Contributed by confidential computing vendor OPAQUE, the specification was developed jointly with AMD, Intel, Microsoft, and the Technology Innovation Institute (TII). TRACE creates a hardware-backed, cryptographically verifiable record that ties together the runtime environment, the software executed, the policies applied,…

Read More