Microsoft is rewriting Windows patch guidance because of AI

Microsoft is recommending that organizations shorten Windows update deployment timelines, warning that advances in AI are reducing the time attackers need to identify and exploit vulnerabilities after security updates are released. The company says org… Continue reading Microsoft is rewriting Windows patch guidance because of AI

Only 28% of financial workforce MFA is phishing-resistant

Passwords remain part of many workforce authentication flows in financial organizations, making phishing and credential theft major identity security risks, according to a new Secret Double Octopus report. Key challenges preventing universal implementa… Continue reading Only 28% of financial workforce MFA is phishing-resistant

The fake report message that ends with a stolen Reddit account

A direct message arrives on Reddit from a stranger, and it invites a reply. That reply is the point. This scheme runs on social engineering, with no malware and no malicious links, and it has spread across Reddit, Discord, and similar platforms. The go… Continue reading The fake report message that ends with a stolen Reddit account

Product showcase: Protect your iPhone with McAfee Mobile Security

McAfee Mobile Security for iOS combines scam protection, web protection, VPN, Wi-Fi security, and device security checks in a single app. It is also available for Android. After downloading the app from the App Store, I created an account and completed… Continue reading Product showcase: Protect your iPhone with McAfee Mobile Security

Wireshark 4.6.7 patches a dozen security flaws

Network analysts who open packet captures in Wireshark push untrusted data through a large set of protocol dissectors, and each parser is a spot where a malformed frame can trip up the software. The 4.6.7 maintenance release closes twelve of those weak… Continue reading Wireshark 4.6.7 patches a dozen security flaws

Thousands of malicious AI skills found capable of stealing data, running malware

AI agents can browse the web, use external tools, execute commands, and perform tasks on behalf of users. Many rely on skills that define how they interact with services and data. Malicious skills can abuse those capabilities to steal data, execute mal… Continue reading Thousands of malicious AI skills found capable of stealing data, running malware

Claude Cowork turns your phone into a remote control for AI work

Anthropic started rolling out Claude Cowork, an AI agent that completes multi-step tasks, in beta for Max users on mobile and the web. They describe a goal, and Claude plans the work, uses the required tools, and produces outputs such as documents, spr… Continue reading Claude Cowork turns your phone into a remote control for AI work

20 open-source cybersecurity tools to keep your team ready for anything

AI is changing how security teams find vulnerabilities, analyze code, test applications, and protect infrastructure. Developers are building tools to secure AI systems themselves, from coding agents and memory protection to model exposure discovery. Th… Continue reading 20 open-source cybersecurity tools to keep your team ready for anything