AWS Certificate Manager sets 2027 end date for email-validated certificate renewals

AWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027, ahead of the Certification Authority/Browser (CA/B) Forum’s March 15, 2028 deadline for ending email-based domain validation. The CA/B Forum sets sta… Continue reading AWS Certificate Manager sets 2027 end date for email-validated certificate renewals

The hardest part of agentic AI may be rebuilding the business

Organizations expect AI agents to change how work gets done, driving productivity and growth while allowing employees to focus on higher-value tasks. Few, however, have the processes and workflows needed to realize those benefits, according to Deloitte… Continue reading The hardest part of agentic AI may be rebuilding the business

Weak IAM affects up to 98% of cloud environments

Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now mandates baseline cloud… Continue reading Weak IAM affects up to 98% of cloud environments

17 draft Cyber Resilience Act standards are open for comment

A company selling a connected toy in Europe must show by the end of 2027 that the product meets the Cyber Resilience Act. The law states what manufacturers have to achieve and stops there, which leaves the toymaker to work out the technical detail alon… Continue reading 17 draft Cyber Resilience Act standards are open for comment

DDoS attacks hit record scale as 1 Tbps+ campaigns become more common

DDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Cloudflare’s H1 2026 DDoS Threat Report shows threat actors relying on multi-vector techniqu… Continue reading DDoS attacks hit record scale as 1 Tbps+ campaigns become more common

Product showcase: Is this image real? Slop or Not investigates

Slop or Not is an AI text and image detector for iPhone and Mac that runs entirely offline, with no account required. It uses on-device AI models powered by the Apple Neural Engine to detect AI-generated content. According to a recent survey, 85% of pe… Continue reading Product showcase: Is this image real? Slop or Not investigates

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers

Wireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that reads a capture off disk before any dissection begins: pcapng, Endace ERF, Tek… Continue reading Wireshark 4.6.8 patches 28 security bugs, nine in file parsers

Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily

Google Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping reduce scams, phishing attempts, and other deceptive content. Abusive not… Continue reading Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily

PentestGPT: Open-source automated penetration testing agentic framework

PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then walkthrough, each stage feeding the next. Switch it to pentest mode and the st… Continue reading PentestGPT: Open-source automated penetration testing agentic framework