ZeroHour

Search: “personalization”

176 stories

Top 10 Best Mobile Device Management (MDM) Solutions in 2026

A 2026 MDM buyer guide ranks ten solutions, recommending Microsoft Intune for Microsoft 365 estates and Jamf for Apple-only environments.

A 2026 buyer guide evaluates ten mobile device management solutions, leading with Microsoft Intune as the default for Microsoft 365 organizations and Jamf for Apple estates. It recommends choosing the enrolment model before selecting a vendor and clarifying BYOD visibility to prevent privacy disputes. Kandji, Mosyle, Omnissa Workspace ONE, ManageEngine, Scalefusion, and Hexnode are covered as alternatives. Guidance ties MDM to Zero Trust data access policies via Apple User Enrolment and Android work profiles.

Cyber Security News · 8d agoIndustry

Peers ask why UK cyber bill leaves execs off the personal liability hook

UK peers propose amendments to the Cyber Security and Resilience Bill adding personal executive liability and board-level cyber responsibility; government defends fines-only approach.

Baronesses Kidron and Ludford backed amendments to the UK Cyber Security and Resilience Bill that would introduce personal civil liability for senior executives and mandate board-level cybersecurity responsibility, citing NIS2 and financial-sector accountability rules. Cybersecurity minister Baroness Lloyd defended the bill's existing regime of fines up to £17 million or 4% of annual turnover, with governance requirements to come via secondary legislation. Peers also debated the bill's 24-hour and 72-hour incident reporting requirements, with Baroness Harding proposing an additional 14-day intermediate report and a one-month final report.

The Register · Security · 10d agoPolicy & legal

Engineered Persuasion: Evaluating Personalized Pretexts in LLM-Generated Spear Phishing

A study of 180 US workers found each LLM phishing personalization level raised click-intention odds by 28%, but credibility depends on context fit.

The arXiv paper evaluates how personalized pretexts in LLM-generated spear phishing affect perceived credibility, using 180 US working adults across 1,436 evaluations of emails with four cumulative personalization levels, from workplace context to shared-project details. Convincingness rose 2.40 points per level in sensitivity analysis and click-intention odds increased 28% per level, while non-clickers shifted toward deleting rather than reporting. Qualitative coding showed details matching the recipient's role and routines supported credibility, whereas incorrect, vague, or channel-inappropriate details raised suspicion. The authors argue personalization effectiveness depends on pretext fit, with implications for workplace security training.

arXiv cs.CR · 13d agoResearch

Phishing 3.0: The Fight Moves to Agent Versus Agent

Agentic AI transforms phishing economics, enabling personalized multi-channel attacks with deepfakes like the $25M Arup deepfake heist.

The article argues phishing has evolved through three stages: from malicious content, to intent-based BEC, to AI-powered multi-channel campaigns where attacker agents autonomously conduct reconnaissance and generate tailored lures. The widely reported Arup case saw a deepfake video call impersonating colleagues convince an employee to approve transfers worth roughly $25 million. An Osterman Research study of 128 security leaders found 88% experienced trust-undermining incidents, while Microsoft 365 EOP and Google Workspace were measured missing hundreds of phishing messages per 100 mailboxes monthly. The author argues defenders must adopt their own agents to match attacker speed.

The Hacker News · 28d agoPhishing & fraud2

GraphProfiler: Source-Linked Sensitive Attribute Inference via Personal Knowledge Graphs

GraphProfiler links LLM attribute inferences to source posts via personal knowledge graphs, enabling targeted redaction of privacy-leaking content.

GraphProfiler represents a user's post history as a source-linked personal knowledge graph where nodes and edges trace back to originating posts, making LLM-based attribute inference auditable. It reaches 86.7% attack success rate on the eight-attribute SynthPAI benchmark and 84.6% on PANDORA, within two points of strong text-only baselines, while citing supporting evidence for over 98% of predictions. Ablation experiments show removing cited posts reduces attack success substantially more than removing random posts, supporting targeted privacy mitigation.

arXiv cs.CR · 6d agoResearch2

35 Actionable Password Statistics for Businesses in 2026 | Huntress

Huntress compiles 2026 password statistics showing 94% of 19 billion leaked passwords were reused and 37% of identity threats used stolen credentials.

Huntress published a compilation of password security statistics drawing on sources including Cybernews, Verizon's 2026 DBIR, IBM, and Bitwarden. Cybernews found 19 billion exposed passwords from roughly 200 incidents between April 2024 and April 2025, with only 6% unique and 94% reused across accounts. Huntress telemetry reports 37% of identity-based threats in 2026 involved stolen or suspicious credentials, while Verizon cites credential abuse in 39% of breaches. The piece argues weak and reused passwords remain a top entry point and recommends improved password hygiene.

Huntress · 6d agoIndustry

AWS Console Private Access can block sign-ins to personal accounts

AWS Console Private Access goes GA, letting internet-isolated VPCs reach the console fully over PrivateLink and blocking personal account sign-ins.

AWS Console Private Access became generally available on August 28, allowing the AWS Management Console, sign-in flows, static assets, and console-only APIs to run entirely over PrivateLink endpoints from VPCs with no internet connectivity. Deployment requires three interface endpoints per Region, correct Private DNS and security group settings, and uses aws:PrincipalOrgID policies plus sign-in resource control policies to deny authentication from unexpected networks, which blocks corporate-network users from signing into personal AWS accounts. IAM Identity Center sign-in and consoles for services without PrivateLink support still need internet access, and a misconfigured policy can lock out the whole organization, so AWS recommends an excluded break-glass role; CLI and SDK SigV4 requests bypass these policies and serve as a recovery path.

Help Net Security · 17d agoTools

Closing the Blind Spot: Securing Personal Repositories in the Software Supply Chain

Wiz highlights personal developer repositories as a supply chain blind spot leaking corporate secrets, offering correlation-based risk validation and remediation.

Wiz argues that developers' personal code repositories are a blind spot in software supply chain security where corporate secrets quietly escape. The company describes an approach that correlates personal repositories to specific developers, validates the actual risk, and drives remediation. No specific incident or vulnerability is disclosed in the announcement.

Wiz Blog · Aug 13, 2026Tools2

Mapping out your unknown: A threat hunter’s guide to GitHub

Datadog Security Labs publishes a threat-hunting guide with audit-log queries to detect GitHub token theft, device code phishing, and source code exfiltration.

Datadog's threat-hunting guide covers GitHub audit log queries for detecting compromised accounts, stolen personal access tokens, and malicious OAuth app authorizations. Attackers typically obtain credentials through phishing, credential stuffing, leaked secrets, or device code phishing, then map private repositories, exfiltrate source code, and pivot into connected cloud and CI/CD environments. The guide maps detections to MITRE techniques like T1078 and T1528 and documents GitHub logging quirks affecting attribution, token metadata, and visibility fields.

Datadog Security Labs · 1d agoResearch in the wild1

50% of CISOs see Mythos as a sign to exit the profession

Survey of 1,001 US and UK CISOs finds 50% consider leaving the profession amid AI-driven pressure, personal liability concerns and burnout.

A survey of 1,001 CISOs in the US and UK found 50% say Anthropic's Mythos and similar cyber-capable AI models have made them consider exiting the profession, while 60% say board pressure to adopt AI is outpacing their governance capability. Average CISO tenure is cited at 18 months, and 78% worry about personal liability for security incidents, up from 56% a year earlier. Executives from BlackBerry, Databricks and IDC discuss D&O insurance, agentic security operations and phased low-risk AI adoption as partial responses.

CSO Online · 8d agoIndustry

You Shall Not Pass into Ring-0! A User Privacy-Friendly Anti-Cheat Architecture for Personal Computers

Tirith replaces invasive kernel-level game anti-cheats with protected VMs and a dual-trusted virtualization monitor, preserving detection and near-native performance.

Researchers present Tirith, an anti-cheat architecture that runs video games in Protected Virtual Machines, sandboxing computations from untrusted root admins, and uses a virtualization monitor trusted by both players and developers to watch for malicious drivers. This removes the need for privacy-invasive ring-0 kernel anti-cheat components while matching their protection against a wide range of cheating mechanisms. To overcome VM stack limitations, the work contributes a security-focused Library OS kernel for games and an efficient graphics sharing pipeline for near-native rendering performance.

arXiv cs.CR · 1d agoResearch

25 Years of Mass Surveillance Is Enough

Bruce Schneier and Cindy Cohn argue post-9/11 mass surveillance expanded far beyond its counterterrorism justification and should be reevaluated for costs to rights.

An essay by Bruce Schneier and Cindy Cohn (originally in Lawfare) traces the post-9/11 shift from targeted surveillance to mass collection of telephone and internet metadata. It cites the Section 215 bulk phone records program, struck down in interpretation by the Second Circuit in 2015 and curtailed by the USA Freedom Act, and the NSA's Upstream program under Section 702 of the 2008 FISA Amendments Act, which ended content searches in 2017. The authors note mass surveillance now serves routine law enforcement and immigration actions, with FBI Director Kash Patel confirming purchases of Americans' data from brokers, and private systems like Flock license plate readers and venue facial recognition feeding government access.

Schneier on Security · 1d agoPolicy & legal

15 Minutes Saved Per Alert: How a Lean German Manufacturer Protects 10,000 Endpoints with ANY.RUN

A five-person security team at a German manufacturer protecting 10,000 endpoints cut triage time by 15 minutes per alert after adopting ANY.RUN's cloud sandbox.

Philipp Z., Security Lead at a leading German manufacturer, described how a five-person team protects 10,000 endpoints and users using ANY.RUN's Interactive Sandbox in a private cloud. The firm previously relied on a single air-gapped forensic laptop running Flare VM, which caused 5-10 minute setup delays, single-user bottlenecks, and selective triage. The switch reportedly saved roughly 15 minutes per alert and reduced forced wiping and reimaging of user machines. ANY.RUN data cited in the piece puts manufacturing security workloads 22% above other major industries.

ANY.RUN · 8d agoIndustry

Switching Password Managers in 2026

An Apple password-management engineer (writing personally) explains switching password managers via iOS direct app-to-app export, crediting FIDO Credential Exchange for passkey portability.

Ricky Mondello, an Apple engineer in password management and authentication (writing personally, not for Apple), demonstrates moving 100 items from 1Password to Apple Passwords via the iOS system export, which transfers passwords, passkeys, verification codes, and notes directly between apps with Face ID confirmation and no intermediate files. He credits the FIDO Alliance's Credential Exchange format (first draft May 2024, now an open spec) and iOS 26/macOS 26 for enabling phishing-resistant credential transfer between apps like 1Password, Bitwarden, Dashlane, DuckDuckGo, and Devolutions. The post is advice rather than news, recommending bulk transfer on the existing device, switching AutoFill to the new app, and treating the new manager as the source of truth.

Lobsters · security · 8d agoIndustry1

Man Charged With 3 Felonies For Breaking 3D

Oviedo, Florida police charged a man with three felonies for cutting down an officer's 3D-printed decoy Flock surveillance camera.

After several real Flock Safety cameras were stolen in Oviedo between July 23 and August 3, 2026, police replaced them with 3D-printed decoys built by an officer at home and monitored the fakes. Evan Meyer was arrested after midnight and charged with attempted grand theft, criminal mischief over $1,000, and property crimes against computer equipment, despite the decoy costing only a few dollars of filament. Mayor Megan Sladek said she had no idea the sting was underway, and the department claims no records of the decoy's creation exist, citing an ongoing investigation.

404 Media · 22d agoPolicy & legal

Grindr settles HIV status data-sharing lawsuit for $35 million

Grindr agreed to pay about $35 million to settle a UK privacy suit alleging it shared users' HIV status and sensitive data with advertisers without consent.

The claim, brought by London firm Austen Hays on behalf of roughly 12,000 UK users, alleges Grindr breached privacy and data-protection laws during a period ending in early 2020, when it was owned by Beijing Kunlun Tech. Shared data may have included ethnicity, HIV status, last HIV test date, and PrEP use. Per an SEC filing, Grindr will make two payments of £13 million (totaling about $35 million), one by December 31, 2026 and one by March 31, 2027, without admitting liability. The settlement follows a Norwegian Data Protection Authority enforcement finding over ad sharing without a valid legal basis.

Malwarebytes Labs · 8d agoPolicy & legal

New infosec products of the week: September 4, 2026

Weekly roundup covers F5's AI-powered WAF enhancements, Ping Identity's personal AI agent access, Superna 2.15 cyberstorage, and BugBase Pentest Copilot Enterprise.

This week's product roundup features releases from BugBase, F5 Networks, Ping Identity, and Superna. F5's WAF for Distributed Cloud adds anomaly detection and agentic threat intelligence for real-time virtual patching, Ping Identity launched Enterprise Personal Agent Access for securing personal AI agents, Superna 2.15 adds guided event-closing workflows for cyberstorage operations, and BugBase's Pentest Copilot Enterprise automates black-box pentesting across 100 vulnerability types using real Chromium browsers.

Help Net Security · 13d agoTools

Keepnet launches free SMS/Call Reporter for iOS

Keepnet launched a free iOS app, SMS/Call Reporter, letting users one-tap report smishing and vishing into corporate incident response pipelines.

Keepnet released the free SMS/Call Reporter app for iOS, letting users report suspicious SMS and voice phishing with one tap. For enterprise customers, reports flow into Keepnet Incident Responder alongside email phishing reports. The company cites Verizon 2026 DBIR data showing mobile phishing simulations achieve a 40% higher median click rate than email, and FBI IC3 2025 counted $798 million in smishing and vishing losses. An Android version is planned.

Help Net Security · 15d agoTools

The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

Rapid7 analyzes how fraud marketplaces are fragmenting into specialized shops after larger marketplaces were dismantled, aided by new MITRE F3 framework

Rapid7 reports a shift from large known fraud marketplaces to a fragmented environment of smaller specialized storefronts such as Xleet, Blackpass, Infodig, and Styx, operating across dark web channels, Telegram, and P2P options. These Fraud-as-a-Service shops sell stolen accounts, PII, synthetic identity generation, infrastructure, and money laundering support, supporting schemes like business email compromise. MITRE's Fraud Fighting Framework (F3), introduced in early 2026, aims to help security teams prioritize monitoring of fraud TTPs, particularly account takeover techniques. Fraud damages are anticipated to approach hundreds of billions of USD.

Rapid7 Blog · 5d agoPhishing & fraud

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

Hacker News ThreatsDay digest: malicious browser extensions, AI-agent intrusions, NCSC shadow AI warning, M&A wire fraud, and 119,000-domain fake shops.

Socket found four malicious Chrome and Firefox extensions (J7Tracker, VREO, Orbit Tracker) stealing session tokens and wallet data from Axiom Trade and Padre users via attacker-controlled Vercel deployments. Hunt.io reported a Chinese-speaking operator using Claude Code, Alibaba Qwen, and DeepSeek with the SecFlow orchestration framework to automate intrusions against government and financial targets in Afghanistan, Thailand, Taiwan, and the US. The UK NCSC warned shadow AI use risks breaches and regulatory failure, Microsoft announced privacy-preserving Windows Age APIs, and Gen Digital described fake M&A wire-fraud scams. A 119,000-domain fake-shop operation called DoppelCart was also highlighted.

The Hacker News · 6d agoIndustry in the wild

MFA's Weakest Link: Account Recovery Is the New Attack Path

Help desk account recovery is increasingly the weakest link in MFA-protected identities, as Scattered Spider's impersonation-driven Marks & Spencer attack demonstrated.

As MFA, conditional access, and phishing-resistant factors raise the cost of direct account takeover, attackers increasingly target the recovery process, convincing service desk staff to reset passwords or re-register MFA on attacker-controlled devices. CISA, FBI, and partner advisories describe Scattered Spider posing as employees to trigger such resets; the 2025 Marks & Spencer attack began this way and led to ransomware with an estimated £300 million profit impact. Microsoft now describes Entra ID account recovery as a high-assurance process, and the article promotes Specops Secure Service Desk for verified identity workflows.

BleepingComputer · 7d agoPhishing & fraud

WordPress Security Plugins: How to Choose the Right One

Sucuri's guide breaks WordPress security plugins into hardening, malware scanning, integrity monitoring, and filtering types, and explains how to evaluate and layer them.

The Sucuri guide explains that WordPress security plugins bundle five capabilities - hardening, malware detection, integrity monitoring, activity logging, and application-level filtering - and that plugins run only after WordPress loads, unlike server-level firewalls. It lists leading causes of compromise: outdated plugins and themes, weak or reused credentials, nulled premium software, insecure configuration, and shared-hosting cross-contamination. It concludes with evaluation criteria and a post-installation security checklist for owners without dedicated security teams.

Sucuri Blog · 12d agoIndustry

Stop playing with the CISO role. Fix cybersecurity leadership

Op-ed argues the CISO role is overloaded and advocates elevating a business-first Chief Security Officer above it.

The author contends that business-alignment failures in cybersecurity are structural rather than communication problems, with CISOs expected to act simultaneously as technologists, strategists, risk executives, and board advisers. The piece proposes a distinct Chief Security Officer role focused on enterprise protection, business continuity, and cross-functional decision authority, with the CISO retaining technical cybersecurity responsibility and potentially reporting to the CSO. It argues this model would give executive ownership of business protection while preserving technical depth.

CSO Online · 14d agoIndustry

Terminated employee cost company hundreds of thousands of dollars because nobody revoked access

A terminated employee's unrevoked access let him delete files and corrupt a database, costing the company hundreds of thousands of dollars and weeks of delays.

The Register's PWNED column recounts an anecdote from Yad Senapathy, CEO of the Project Management Training Institute, about a company with 1,000+ employees where a terminated employee's credentials were never revoked. The former worker retained shared admin credentials and used them to delete files, lock accounts, and corrupt a database, causing hundreds of thousands of dollars in damage and weeks of project delays. The takeaway is that unclear offboarding responsibility and unreviewed admin access enabled the sabotage.

The Register · Security · 14d agoIndustry

German Manufacturer Shrinks Security Alert Response While Protecting 10,000 Endpoints

Vendor case study: a German manufacturer's five-person SOC cut alert triage time using ANY.RUN's cloud sandbox across 10,000 endpoints.

ANY.RUN published a case study in which a five-person security team at an unnamed German manufacturer replaced an air-gapped forensic laptop with its cloud-managed interactive sandbox, protecting roughly 10,000 endpoints and 10,000 users. The vendor claims a median 15 minutes saved per alert, 20-40 daily tasks processed, a 2.5-minute alert-to-isolation target, and a 95% agreement rate between analyst and sandbox verdicts; all figures are vendor-supplied with the customer identity withheld. The writeup also describes detonating a multi-stage phishing chain from a PDF link to a password-protected ZIP to malware execution.

Cyber Security Newsupdated · 2h agofirst · 19h agoIndustry 3 sources

Kiteworks expands runtime data governance with Bonfy.AI acquisition

Kiteworks acquired Bonfy.AI to add runtime, context-aware classification and enforcement of data exchanges by people, machines, and AI agents.

Kiteworks acquired Bonfy.AI to extend its Data Control Plane with inline, runtime data governance at the moment data is exchanged via email, file sharing, APIs, and AI agents. Bonfy.AI's technology evaluates sender, recipient, counterparty, channel, and business purpose to apply policy before a send completes, aiming to reduce false positives versus pattern-matching prevention tools. This is Kiteworks' eighth acquisition in under five years, with compliance framing around provable control for CMMC 2.0, HIPAA, and GDPR.

Help Net Securityupdated · 5d agofirst · 6d agoIndustry 2 sources1

Korea raises data breach fines to 10% of revenue

South Korea's privacy regulator will impose fines up to 10% of revenue for data breaches leaking personal data of 10 million or more people.

South Korea's privacy regulator is sharply raising penalties for data breaches, with fines reaching 10% of a company's revenue. The higher fines take effect Friday for companies found to have leaked personal data of 10 million or more people through intent or gross negligence. The regulator aims to push companies to treat data protection as a preventive investment rather than a routine cost of doing business.

DataBreaches.net · 6d agoPolicy & legal

FTC rescinds policy requiring health apps to notify customers after a breach

The FTC unanimously rescinded its 2021 policy statement that required health and fitness apps to notify users after health-data breaches.

The FTC voted to rescind a September 2021 Biden-era policy statement that extended federal health-data breach notification rules to health apps, fitness trackers, and connected devices, which had exposed violators to fines of $43,792 per violation per day. The 2021 statement, adopted in a divided 3-2 vote under then-chair Lina Khan, cited HIPAA coverage gaps for consumer health applications. The commission said the statement provided minimal benefit, was superseded by rulemaking, and aligns with the White House deregulatory agenda.

CyberScoop · 7d agoPolicy & legal

Safe word: What is it and why do you need one?

ESET recommends pre-agreed family safe words to counter AI voice-clone scams such as virtual kidnapping, as one-in-four Americans report receiving deepfake calls.

ESET outlines how scammers use just seconds of audio scraped from social media or work content to create convincing voice clones, with a Hiya report finding one-in-four Americans received a deepfake voice call in the past 12 months. Common schemes include virtual kidnapping calls mixing cloned voices with sobbing and background noise. A pre-agreed, non-OSINT-discoverable safe word, plus callback verification via known numbers and 2FA, reduces success rates of these frauds.

ESET WeLiveSecurity · 8d agoPhishing & fraud in the wild

In most cities, nobody owns the whole network

Former Waco CIO argues cellular-connected water controllers sit outside scanned networks, and accountability plus operating-budget funding—not technology—block segmentation.

Writing as Waco, Texas's former CIO, the author describes July water-sector intrusions that CISA linked to over 100 compromised systems, typically controllers on public cellular links absent from asset lists. The FBI and EPA reported incidents at utilities in at least seven states since July 27, and a Clayton County, Georgia pump station failure triggered a boil-water advisory. He argues accountability and funding—using mechanisms like the Texas Water Development Board's new cybersecurity scoring criteria—are the binding constraints, citing Waco's 43-day segmentation of five treatment plants with operating funds.

CyberScoop · 9d agoIndustry in the wild

Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

Grindr will pay £26 million ($35.1M) to settle U.K. claims from 10,000+ users over pre-2020 sharing of HIV status and other sensitive data.

Grindr agreed to pay £26 million ($35.1 million) to settle a U.K. lawsuit brought on behalf of more than 10,000 claimants over sharing users' HIV status, last tested date, and other personal data with third parties for advertising before 2020, when the app was owned by China's Kunlun. The settlement, disclosed in a September 2 SEC filing, includes no findings or admission of liability, with £13 million due by December 31, 2026 and the rest by March 31, 2027. Norway's data protection authority previously fined Grindr £8.6 million (reduced to £5.5 million) under GDPR, a decision upheld on appeal last October.

The Hacker News · 9d agoPolicy & legal

Governing Bring Your Own AI: A Parameterized Maturity Model

Researchers propose a parameterized governance model and maturity ladder for Bring Your Own AI, finding data exposure and compliance dominate BYOAI risks.

The paper studies Bring Your Own AI (BYOAI), where employees use personal generative AI accounts such as ChatGPT, Gemini, and Claude outside enterprise identity and security controls. Drawing on a curated corpus of 30 records (24 studies and 6 framework documents), the authors build a risk taxonomy, a five-level governance maturity ladder, and a parameterized model linking control-layer coverage to residual risk. Findings highlight data exposure and compliance as the most prominent risks, inconsistent framework engagement, and evidence that layered technical controls reduce modeled exfiltration risk more than prohibition-based approaches.

arXiv cs.CR · 12d agoResearch

ICE Wants to Know Everyone Who Bought a Certain Green Beanie From REI in the Last 2 Years

DHS subpoenaed REI for all Minneapolis-area customers who bought a specific green beanie since 2024, part of an investigation into 39 ICE protest defendants.

Court filings allege Homeland Security Investigations agents subpoenaed REI in March for transaction records of all persons in the greater Minneapolis–St. Paul area who purchased a specific dark green beanie since 2024. The subpoena was one of 92 sent in a federal case against 39 people, including journalists, who attended an ICE protest at a church. Companies responded differently: T-Mobile handed over six months of a defendant's call and text logs, Google refused a request for YouTube viewers, Reddit withdrew after a First Amendment objection, and Meta pushed back on at least one summons. The 1509 customs summonses require no judicial oversight, and the total number issued under the Trump administration is unknown.

WIRED · Security · 13d agoPolicy & legal

Scammers have figured out the best time to text you

Malwarebytes threat data shows scammers tailor platforms per scam, with the web as top channel, Friday midday peaks, and MrBeast the most impersonated person.

Malwarebytes analyzed its threat data from April 15 to July 14, 2026 across more than 20 scam categories, finding scammers match platforms to scam types: job scams via email, romance scams via social media, and tech support scams via phone. The web is the top delivery channel ahead of email and SMS, and Malwarebytes says it blocks about 500,000 phishing sites a day. Scam texts peak at 12:00 pm ET, roughly 874% above the quietest hour, with volume peaking on Fridays about 50% higher than the start of the week. MrBeast (Jimmy Donaldson) appears in about 30% of impersonation scams, and the most impersonated brands are Google, Microsoft, Apple, Roblox and Amazon.

Help Net Security · 13d agoPhishing & fraud in the wild

Shadow AI in Financial Services | Risk & Governance

Huntress warns financial services firms that unsanctioned 'Shadow AI' tool use creates data leakage and compliance risks faster than governance controls can keep pace.

Huntress argues Shadow AI — employee use of unapproved AI tools such as ChatGPT and Microsoft Copilot — is spreading across financial services faster than visibility and controls. Uploading regulated customer data into public generative models risks breaches of client confidentiality, data protection rules, and market conduct obligations. The piece recommends secure web gateways, DNS filtering, DLP, application allowlisting, and corporate SSO/MFA for approved tools rather than outright bans, which can push usage onto personal devices.

Huntress · 13d agoIndustry

Hackers Frequently Target Healthcare and Finance Orgs

A new Huntress survey indicates threat actors frequently target healthcare organizations and banks because of the highly personal data they hold.

Huntress published survey findings indicating that healthcare organizations and banks are frequent targets for threat actors. The piece attributes this to the highly personal information these sectors handle. The article is framed around cyberattack readiness rather than a specific incident.

Huntress · 15d agoIndustry

When the Algorithm Fires You: Uber Faces €825M Fine

Dutch regulators fined Uber 825 million euros under GDPR for suspending drivers via fully automated decisions without human review or disclosure.

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) fined Uber 824,990,000 euros (~$964M) for making fully automated decisions to deactivate drivers' accounts between 2018 and 2022 without any human review, violating GDPR limits on automated decision-making, and for failing to inform drivers that automated systems were deciding. The penalty is Uber's fourth from the Dutch regulator and exceeds its previous record 290 million euro fine from 2024 over data transfers to the US. Uber says it has stopped the cited practices and is appealing both the decision and the fine amount.

Security Affairs · 22d agoPolicy & legal

The County Prosecutors Who Became ICE Informants

Illinois county prosecutors shared defendants' personal data with federal ICE agents without warrants, disclosure, or oversight, WIRED reports.

WIRED reports that county prosecutors in Illinois effectively became informants for federal immigration agents. Defendants' personal data was shared without criminal warrants, public disclosure, or legislative oversight. The story raises privacy and accountability concerns around government handling of personal data.

WIRED · Security · 22d agoPolicy & legal

Lawmakers seek watchdog review of federal hacking of Americans

Sen. Wyden and Rep. Casar asked the GAO to review the federal government's use of spyware and hacking tools against Americans.

Sen. Ron Wyden and Rep. Greg Casar sent a letter to the Government Accountability Office requesting a review of federal law enforcement hacking operations, including spyware use, Rule 41 hacking powers, and acquisition of hacking tools. The letter cites ICE's confirmed work with spyware vendor Paragon and concerns about abuse of invasive surveillance capabilities. The lawmakers note the government publishes no annual reports on hacking operations unlike wiretaps.

CyberScoop · 26d agoPolicy & legal

AI is making fraud harder to spot and identity harder to prove

Experian's 2026 report finds AI-generated scams, deepfakes and synthetic identities spreading across digital channels, pushing businesses toward adaptive identity verification and 'Know Your Agent' checks.

Experian's 2026 US Identity & Fraud Report, based on consumer and business surveys, found 60% of consumers aware of AI-generated image/video scams, 53% of AI phishing, and 47% of deepfake voice impersonation. 80% of US businesses already use machine learning or generative AI in fraud management, while AI chatbot account openings rose from 16% in 2025 to 27%. The report highlights adaptive authentication, behavioral biometrics, and emerging 'Know Your Agent' controls as AI agents begin acting on behalf of customers.

Help Net Security · 28d agoPhishing & fraud