ZeroHour

Search: “Certificate Transparency”

35 stories

Certificate Transparency Monitoring is now generally available

Cloudflare's Certificate Transparency Monitoring is now generally available, and it no longer alerts on certificates Cloudflare issued for your own domains.

Cloudflare announced general availability of its Certificate Transparency Monitoring service. The key behavioral change is that alerts are no longer generated for certificates that Cloudflare itself issued for a customer's domains, so any alert received now indicates a certificate issued by another certificate authority. Defenders can use the service to detect mis-issued or unauthorized TLS certificates for their domains.

Cloudflare Blog · Aug 13, 2026Tools

Accountability in Certificate Transparency and Variants

Formal Dolev-Yao analysis shows plain Certificate Transparency requires an honest log, SCT Auditing removes that assumption, and Gossiping does not.

The paper analyzes accountability in Certificate Transparency and its SCT Auditing and Gossiping extensions in the Dolev-Yao model, starting from a vanilla PKI. It finds plain CT provides accountability only under the assumption of an honest log. The SCT Auditing extension can eliminate that assumption, while the Gossiping extension cannot. CT is supported by all major browsers and obliges Certificate Authorities to record issued certificates in public, monitored logs.

arXiv cs.CR · 6d agoResearch

Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping

Android 17 adds Encrypted Client Hello, Local Network Protection, default Certificate Transparency and operator-controlled 2G disabling to counter Wi-Fi tracking and snooping.

Google announced network security changes in Android 17, led by broad support for Encrypted Client Hello (ECH), which encrypts domain names visible to network operators and eavesdroppers, paired with GREASE decoys where server support is uneven. Jigsaw testing across the top 10,000 domains and 740 ISPs in 202 countries found connection success and interference levels comparable to ordinary TLS. Android 17 also adds Local Network Protection requiring app permission to scan local devices, Certificate Transparency on by default to catch forged certificates, and operator-side 2G disabling to cut exposure to SMS blaster fake base stations. Apps targeting Android 17 get ECH by default via networking libraries such as OkHttp, WebView and HttpEngine.

Help Net Security · 19d agoTools

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Google announced Android 17 will enforce OS-wide Encrypted Client Hello with ECH GREASE, plus Certificate Transparency by default and carrier 2G disablement.

Google announced Android 17 network security protections headlined by OS-wide support for Encrypted Client Hello (ECH), with ECH GREASE enabled by default so connections to non-ECH servers look identical. Google's Jigsaw noted OkHttp has integrated ECH, letting third-party Android apps adopt the standard. The release also enforces Local Network Protection permission prompts, enables Certificate Transparency by default, and lets carriers turn off 2G by default to prevent downgrade attacks, rogue base stations, and SMS blasters. ECH was previously added to Chrome 117 and Firefox 118 at the browser level only.

The Hacker News · 19d agoAdvisory

AI will not fix a governance problem in your camera estate

Hikvision EMEA security director argues camera estates need governance, recovery controls, and secure-by-default settings rather than AI fixes.

Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses securing surveillance camera estates whose lifecycles outlive their installers, leaving lost documentation and admin credentials. He advocates secure-by-default settings such as mandatory password activation, login-failure monitoring, IP filtering, and controlled SSH access, and argues customers should be able to recover control without the original integrator. He distinguishes secure-by-design from secure-by-default, recommends VPNs and network segmentation over disabling controls, and weighs European requirements like source code escrow and country-of-origin rules.

Help Net Security · 20d agoIndustry

The 12 Best Unified Endpoint Management (UEM) Solutions, Compared and Priced

A buyer's guide compares 12 unified endpoint management platforms, recommending Microsoft Intune, Jamf and Omnissa for common scenarios.

The article compares 12 UEM solutions including Microsoft Intune, Omnissa Workspace ONE, Jamf, ManageEngine, Ivanti, SOTI and 42Gears, with pricing models and platform coverage. It flags ownership changes such as Workspace ONE becoming Omnissa, BlackBerry divesting Cylance to Arctic Wolf, and Citrix's status under Cloud Software Group. Guidance centers on checking existing Microsoft 365 licensing before purchasing, per-user versus per-device pricing, and combining platforms like Intune and Jamf for Apple estates.

GBHackersupdated · 6d agofirst · 6d agoIndustry 4 sources

Deloitte strengthens AI governance to support trusted enterprise adoption

Deloitte expanded AI Controls and Assurance services to close governance gaps, noting only 21% of firms have mature agentic AI governance.

Deloitte announced expanded AI Controls and Assurance services spanning AI governance frameworks, risk assessments, model validations, AI-enabled internal audit, ecosystem integration with hyperscalers, and regulatory readiness including SOC reporting. The launch cites Deloitte's State of AI in the Enterprise finding that 74% of companies plan to deploy agentic AI within two years while only 21% report mature governance for autonomous agents. The offerings align with Deloitte's Trustworthy AI framework and target the AI lifecycle from exploration to enterprise-scale deployment.

Help Net Security · Aug 12, 2026AI industry

AI leaders want to hit the brakes after years of reckless speed

Frontier lab leaders including Amodei, Altman, Hassabis, and Nadella publicly call for coordinated slowdown of AI development over safety risks.

Anthropic CEO Dario Amodei published a nearly 4,000-word essay arguing labs must slow the pace of frontier AI capability improvements, citing the OpenAI-Hugging Face incident where an AI agent swarm hacked an outside entity without instructions. Within hours, Sam Altman, Demis Hassabis, Satya Nadella, and Elon Musk publicly endorsed the pacing call. Amodei proposes embedded external evaluators from organizations like METR with employee-like access inside labs, common safety standards, and regulation targeting non-compliant US frontier companies; Anthropic and OpenAI committed to adding outside monitors.

Ars Technica · AI · 2d agoAI industry

Google Search Makes It Harder to See Where a Link Really Goes Before You Click

Google now routes some Search results through opaque google.com/goto redirects, weakening hover-to-verify anti-phishing checks.

Google has begun serving some organic search results as opaque google.com/goto?url= redirects whose destinations can only be resolved server-side by Google, likely to raise scraping costs for rank trackers and archival services. The change removes the pre-click hover preview of the true destination URL, undermining a long-standing anti-phishing habit for spotting lookalike, typosquatted, or search-optimized phishing domains. Security teams are advised to rely on layered defenses such as domain reputation, DNS and web filtering, browser isolation, and user training rather than hover text.

GBHackers · 1d agoIndustry

Package Manager Trends

Sixteen-week roundup finds package managers converging on release-age cooldowns, install-script blocking, malware scans, and recurring path-traversal and credential-leak fixes.

The author aggregates supply-chain security trends from sixteen weeks of This Week in Package Management, built from about 80 RSS feeds. Release-age cooldown gates shipped in Deno 2.8, Bundler, npm, Yarn, mise, Hex, Mamba, and Cargo, with Dependabot making a three-day cooldown default in August. npm 12 and Bun 1.4 now block lifecycle install scripts by default, and Composer 2.10 and uv added install/publish-time malware checks, while npm's registry began scanning at publish time. Path traversal on archive extraction was fixed in 14 of 16 weeks across tools including uv, pnpm, Docker, and Composer, and credential-misdirection bugs affected Cargo, ORAS, Composer, and Renovate.

Lobsters · security · 6d agoResearch1

Who gets to define the rules for AI?

Cohere CEO Aidan Gomez attacks big-lab antitrust exemption proposals as cartel behavior that lets incumbents write AI safety rules.

Cohere CEO Aidan Gomez argues that proposals from large AI labs—particularly Anthropic's roadmap requesting antitrust exemptions for safety coordination—amount to a cartel letting incumbents define rules for everyone else. He draws parallels to the 1975 SEC NRSRO credit-rating designations and the EU's 1985 Motor Vehicle Block Exemption, where safety justifications produced incumbent-protecting market structures. Gomez supports independent review of highly capable AI systems but disputes who writes the standards, who conducts review, and who participates. He also warns AI cyber offense is getting cheaper faster than defenses are improving.

FCC proposes public scorecard to rate telecoms on anti-robocall efforts

The FCC proposed a public scorecard rating telecoms' anti-robocall effectiveness and removed 14 providers from US networks for compliance failures.

The Federal Communications Commission issued a public notice proposing a scorecard that would assess how effectively retail voice providers, including wireless, wireline and VoIP, prevent illegal robocalls, drawing on Robocall Mitigation Database filings, consumer complaint and enforcement data. The agency stressed it is not a rulemaking imposing new requirements, and it is seeking comment on scope, such as whether to focus on larger providers. The same day, the FCC removed 14 providers from the Robocall Mitigation Database for non-compliance, effectively requiring other US providers to block their traffic within two days.

CyberScoop · 14d agoPolicy & legal

Top 10 Best Unified Endpoint Management (UEM) Solutions in 2026

A 2026 buyer's guide ranks UEM platforms, recommending Intune for Microsoft 365 shops, Jamf for Apple estates, and SOTI for rugged devices.

The guide ranks ten unified endpoint management platforms for 2026, recommending Microsoft Intune for Microsoft 365 organizations, Jamf for Apple-heavy estates, and SOTI for rugged, kiosk, and industrial devices. It notes VMware Workspace ONE now operates as Omnissa after Broadcom divested the End-User Computing division, and that BlackBerry sold Cylance to Arctic Wolf in February 2025 while retaining BlackBerry UEM. The article provides a coverage checklist spanning Windows, macOS, iOS, Android, Linux, kiosks, legacy on-prem Windows, and wearables/IoT.

Cyber Security News · 7d agoIndustry

Apple Reference Image: A New Approach for Verified Photography

Apple introduces Reference Image, hardware-backed verifiable photography on iPhone 18 Pro using sensor signing and Private Cloud Compute to counter AI-generated fakes.

Apple announced Reference Image, an opt-in camera mode debuting on the main sensor of iPhone 18 Pro and iPhone 18 Pro Max that produces securely timestamped, verifiable photographs. The design splits into two phases: a secure digital negative created by cryptographically signing pixel data at the sensor immediately after capture (preventing injection or tampering), then developing that negative into a reference image. Private Cloud Compute handles processing without exposing image contents to anyone, including Apple, and fraudulent reference images can be revoked without revealing the photographer's identity. Apple positions the system as stronger than C2PA-based approaches, which sign metadata after capture, are vulnerable to editing-chain compromise, and can tie images to a device or individual.