Security Buzz
Online/Digital
Our mission at Security Buzz is to deliver accurate, timely, and actionable information to help IT professionals and the general public navigate the complex world of cybersecurity. By offering a mix of breaking news, expert insights, and practical resources, we aim to empower our readers to make informed decisions and enhance their cyber defense strategies. Source
Actions
Media Outlet details
| Scope | Trade/B2B, Consumer |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesU.S. Deputizes Private Companies for Offensive Cyber Operations Against Criminal Networks
On August 12th, 2026, a presidential memorandum was published authorizing Participating Companies—vetted private contractors—to conduct government-directed cyber operations. The new program covers both Cyber Surveillance Operations and Cyber Effects Operations. While Surveillance Operations include intelligence and data collection, Effects Operations explicitly include the manipulation, disruption, degradation, and destruction of information systems.
New Python Implant Uses Microsoft Services to Hide C2 Traffic
A newly identified Python malware framework uses Microsoft services to conceal its command-and-control (C2) activity, according to researchers at Ontinue. Dubbed TWINLOOT, the malware routes traffic through SharePoint and Teams infrastructure and uses a headless Microsoft Edge process to help disguise some communications. Ontinue discovered TWINLOOT while responding to a July 2026 intrusion that began with a voice phishing, or vishing, call placed through Microsoft Teams.
OpenAI Can't Rule Out Astra Has Reached Critical Cyber Capability
OpenAI’s Astra model has been flagged for possible critical cyber capability, as the company states that it “cannot rule out” the possibility under its current Preparedness Framework. This is the first model to approach the top tier in the existing framework, which was first published in December 2023. In response to the advanced level of the model, internal activities have been paused pending the addition of stronger safeguards to account for Astra’s capabilities.
Fortinet Acquires Virtue AI to Secure Autonomous Agents at Runtime
In recent years, the explosive growth of artificial intelligence (AI) tools and agents has reshaped the digital landscape and brought on many new and evolving risks. The deployment of autonomous AI agents in business environments extends risk beyond networks and endpoints, as these agentic tools are typically over-permissioned and under-monitored.
Gunra Ransomware Altered MFA to Maintain Access
Attackers using the Gunra ransomware altered a victim’s authentication system to create a persistent way around multi-factor authentication, according to a new joint U.S.-South Korean government advisory. The Aug. 10 warning from the FBI, CISA, NSA, U.S. Secret Service, Department of Defense Cyber Crime Center, and South Korea’s National Police Agency details Gunra’s tactics across multiple sectors and regions.
Google Cloud Maps Migration for Post-Quantum Cryptography
Securing infrastructure and services against the cryptographically relevant quantum computer of the future presents a major concern for the IT industry. Every encrypted connection will present a liability. The nation-state adversaries and organized threat actors who keep harvesting encrypted traffic are betting that a future quantum computer will hand them decryption keys. This strategy turns post-quantum cryptography from an academic exercise into a hard migration deadline.
Paperclip Vulnerabilities Show How AI Agent Configuration Becomes Code
Open-source AI company Paperclip plays a significant role in orchestrating autonomous AI agents at scale, enabling organizations to centrally manage a company of AI agents. A design choice causes Paperclip to treat agent configuration as trusted data, implicitly assuming that configuration data is controlled by an authenticated and authorized user, although this is by no means guaranteed. This choice sets up three separate vulnerabilities recently discovered by researchers at Oasis Security.
Open Secure AI Alliance Targets Security Risks Exposed by Hugging Face Breach
NVIDIA says it and more than 100 organizations, including Microsoft, IBM, CrowdStrike, Dell Technologies, Palo Alto Networks, HPE, Red Hat, and Hugging Face, have formed the Open Secure AI Alliance to develop and share open tools for securing software and AI agents.
Okta Buys Permiso for $200 Million to Police AI Agents After Login
Identity and access management (IAM) company Okta recently signed a definitive agreement to acquire Permiso Security, with the deal expected to close in Q3 of Okta’s 2027 fiscal year. While the exact terms of the deal have not been disclosed or confirmed by either company, it has been reported that the price is just under $200 million, almost all in cash. This deal will allow Okta’s identity strategy to grow beyond login and extend into behavior.
Research Finds Most Attacks Exploit Identity Trust, Not Bugs
BeyondTrust’s Phantom Labs was founded in 2025 to conduct research and share intelligence pertinent to the company’s security efforts. The recently released Phantom Labs Research Index explores the fruits of the first year of Phantom Labs’ work, including over 400 research ideas and 31 published articles and findings. Of the completed investigations, 75% have been tied to identity or privilege, underlining the importance of identity security in modern environments.