The Source Signals
Tech news is everywhere. Intelligence isn't.
What 170,000 job cuts have done to the credentials nobody was tracking
With 109 machine identities for every human, the accounts and keys that departing engineers created are surviving restructuring after restructuring, because the people who could explain what they do have already gone.
Attackers have stopped hunting for vulnerabilities and started hunting for relationships
BeyondTrust's first Phantom Labs Research Index accounts for more than 400 projects across cloud, SaaS and AI systems, and points to inherited access as the condition defining enterprise exposure.
Microsoft puts its first cybersecurity model into production as the AI defence race turns on cost
MAI-Cyber-1-Flash and Project Perception enter public preview on 3 August, scoring 96% on CyberGym at half the cost of Microsoft’s own previous configuration.
Ransomware becomes an identity crisis: 79% of attacks now start with stolen credentials
Sophos' seventh State of Ransomware report finds exploited software flaws dethroned as the top attack route, as email and identity compromise take over and falling ransom figures mask a harder shift in how attackers get in.
Sophos bets against the market on Fusion, the AI-native defence system built to stop short of full autonomy
Sophos has launched Fusion, unifying security operations, endpoint, identity, email, and cloud into one AI-native system where humans stay accountable and third-party tools feed one shared data layer.
Half of Security Leaders Report an AI Risk Programme. Their Practitioners Cannot Find It
The 2026 SANS AI Survey asked 57 CISOs and 536 practitioners the same questions about AI governance and got a 14-point gap in return, alongside a leadership priority shift that the survey's own attack data contradicts.
OPSWAT flies air-gapped cyber kiosk toward space in prevention-first test
A near-space validation flight processed thousands of malware samples in freefall, staking a claim that mission-critical systems can no longer assume a human on Earth will fix them
The Ransom Reckoning: Why Paying Was Never a Recovery Strategy
With payment bans spreading across jurisdictions and the data showing that paying buys neither safety nor silence, security leaders are confronting a harder question than whether to pay: how they became the target in the first place, and whether they can recover without negotiating at all.
Vulnerabilities by the minute: TrendAI’s UAE debut and the race to secure agentic AI
Trend Micro’s enterprise security business has launched in the UAE as TrendAI, warning that frontier models will soon surface vulnerabilities at machine speed and pairing the rebrand with an Anthropic partnership and an unresolved agentic governance challenge.
Media groups and exiled journalists bear the heaviest concentration of cyberattacks against civil society, Cloudflare data shows
New research drawn from more than 3,400 protected domains reveals DDoS campaigns lasting days rather than minutes, vulnerability probing at more than seven times the rate of other customers, and phishing emails that slip past standard authentication before being caught.
Business as Usual: How Attackers Are Turning IT Tools Into Backdoors
HP threat researchers found criminals using LogMeIn and ScreenConnect, tax-themed phishing, and AI-assisted scripts to take over PCs without triggering alarms that detect conventional malware.
AI security has a detection problem, and Check Point’s 2026 report puts a number on it
Only 13% of organisations can block a malicious prompt and just 5% can stop unsafe AI outputs, according to Check Point’s 2026 Cloud Security Report. Why detection has outpaced prevention.
The 2026 World Cup Is the Most Predictable Cyberattack Window Ever Handed to Adversaries
A Palo Alto Networks assessment finds disruptive intrusions, fraud at scale and hacktivist operations against the tournament are highly likely, with an active Iran-nexus campaign already targeting the municipal infrastructure 16 host cities will run under tournament load.
The biggest AI risk inside enterprises is the person at the keyboard, not the model, Optro report
With 82% of organisations reporting more AI-enabled attacks in the past year, new Optro research argues the dominant threat is no longer technical model failure but everyday human decisions made inside ungoverned AI tools.
From Backup to AI Trust: What Veeam Announced at VeeamON New York and Why It Matters
Three announcements in three days: a new platform built from the Securiti AI acquisition, a preview of Data Platform v13.1, and a governance framework exposing the gap between AI confidence and AI readiness.
The AI Labs Built the Threat. Now They Are Selling the Defence
OpenAI's Daybreak launch brings a second AI lab into a cybersecurity race that Anthropic opened with Claude Mythos five weeks ago. For the security industry, the contest raises questions that go well beyond which model performs better.
275 Million Students, One Point of Failure, and No Way Out
The Canvas ransomware attack exposed what happens when a platform becomes too dominant to avoid and too architecturally fragile to trust — and students had no choice about being in either position.