Adobe patched CVE-2026–48294 after malicious pages could abuse its Acrobat Chrome extension to expose rendered WhatsApp Web chat data.
Get the latest international news and world events from around the world.
Why Modern SOCs Need MultiLayered Detections
Endpoint, identity, and cloud platforms each offer a valuable perspective on corporate security. Host tools track processes in memory, identity solutions monitor credentials, and cloud environments log configuration changes. While each source provides visibility, these systems operate in isolation, leaving gaps in visibility that attackers can easily exploit.
Each tool sees only its fragment of the attack chain. Threat actors can compromise a workstation, leverage blind spots between endpoint and identity systems to hide credential theft, move laterally into cloud infrastructure, and exfiltrate data before the SOC is aware. That is why unified, correlated telemetry across these domains is essential to revealing the full picture.
Network Detection and Response (NDR), validates, enriches, and connects these separate signals using network data. Because it’s collected out of band, the data remains immutable even when local agents go dark or when threat actors disable endpoint tools. And because it captures traffic across the entire enterprise, NDR provides vital context, recording every conversation, transaction, and data transfer, delivering the undeniable proof defenders require to respond.
How enterprise GenAI can amplify ransomware risk — and how to contain it
Enterprise AI will continue expanding because the business benefits are clear. The challenge is ensuring that productivity gains do not come at the expense of security.
The most effective approach is to incorporate AI into existing identity, data protection and incident response strategies rather than treating it as a separate security domain. Organizations should evaluate AI security controls based on how well they integrate with existing governance and security operations while providing visibility into AI usage, permissions and policy violations.
For managed service providers (MSPs) and enterprise security teams, there is an opportunity to extend cyber resilience strategies to include AI governance.
Windows LegacyHive zero-day flaw gets free, unofficial patches
Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems.
The vulnerability (dubbed LegacyHive and without a CVE ID for easy tracking) was found by a security researcher using the “Nightmare Eclipse” handle in the Windows User Profile Service.
Nightmare Eclipse disclosed it the day Microsoft released its July 2026 Patch Tuesday updates, together with a stripped proof-of-concept exploit designed to make it harder for threat actors to weaponize this security issue in attacks.
Microsoft shares manual fix for WSUS sync delays and timeouts
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out.
This known WSUS sync issue affects both client (Windows 10, version 1,607 and later) and server (Windows Server 2012 and later) platforms.
On impacted WSUS servers, admins are not able to deploy the latest Windows updates via WSUS or Configuration Manager due to increased synchronization times or sync operation timeouts caused by a buildup of publishing metadata.
Anthropic accuses Chinese AI labs of mining Claude as US debates AI chip exports
As one legal analyst noted, the settlement may be seen by the tech industry as simply “a price of conducting business in a fiercely competitive space”—a cost of doing business rather than a genuine deterrent. Meanwhile, the fair-use ruling on training means Anthropic retains the legal right to train on copyrighted works, as long as it doesn’t pirate them to do so.
Anthropic is accusing three Chinese AI companies of setting up more than 24,000 fake accounts with its Claude AI model to improve their own models.
The labs — DeepSeek, Moonshot AI, and MiniMax — allegedly generated more than 16 million exchanges with Claude through those accounts using a technique called “distillation.” Anthropic said the labs “targeted Claude’s most differentiated capabilities: agentic reasoning, tool use, and coding.”
The accusations come amid debates over how strictly to enforce export controls on advanced AI chips, a policy aimed at curbing China’s AI development.
Selfmonitoring of fat metabolic status with smartphoneassisted breath acetone detector
S. Hersberger et al. present a smartphone-guided handheld breath acetone detector for self-monitoring of fat metabolism at home. The device combines volume-controlled end-tidal breath sampling with humidity-robust sensor performance and was validated against proton transfer reaction time-of-flight mass spectrometry (PTR-MS) across 312 human breath samples during exercise and dietary interventions.
How a pandemic detour helped researchers uncover clues to a mysterious disease
When the COVID-19 pandemic shut down international travel in 2020, Michigan State University researcher Eric Benbow faced a problem. A $2.5 million research project designed to study an environmental pathogen in South America was suddenly on hold. With fieldwork canceled and uncertainty surrounding when travel might resume, Benbow and his collaborators needed a new plan.
That unexpected detour led to a surprising discovery—and new insights into a disease that has puzzled scientists for decades.
In their study published in Communications Medicine, the international team of researchers examined the environmental and human factors that influence the distribution of Buruli ulcer, a neglected tropical disease caused by the bacterium Mycobacterium ulcerans. The work helps explain how ecosystems, climate, land use and human activities interact to shape disease risk.