Risky Bulletin: White House lets private companies carry out offensive cyber ops

In other news: AI hacking campaign breached Taiwan's government; macOS bug exploited over the internet to drop cryptominers; Kenya orders internet cafes to store logs.

Share
Risky Bulletin: White House lets private companies carry out offensive cyber ops

This newsletter is brought to you by enterprise browser maker Island. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.

In a presidential memo this week, the White House has directed the Department of Homeland Security to establish a program through which private sector companies can carry out offensive cyber operations on behalf of the US government against cybercrime organizations.

The new program will run under the DHS National Coordination Center (DHS NCC) and under oversight of both the Department of Justice and the Department of Homeland Security.

Private companies will be able to apply and receive specific tasks from the two agencies on what and who they can hack—to prevent rogue behavior from the private sector.

The DHS NCC was tasked with running and creating the program's actual rules, but the memo contains some guidance on what those rules should be.

  • Companies that apply will need to operate secure facilities, have vetted personnel, and have a proven record and technical proficiency in cyber operations.
  • Both large and small private companies can apply, but they'll need to provide the government with $1 million in escrow to be used to cover damages in case of a botched operation.
  • Contracted companies can sub-contract.
  • The DHS and DOJ will each name their own co-Executive Director to run the program together.
  • Each offensive operation will need to be co-signed by both.
  • Executive Directors will provide "written approval and direction" for each op.
  • Companies can also provide intelligence to the government and suggest possible operations.
  • Offensive ops can target US infrastructure and individuals, if they are involved in large cybercrime operations.
  • Contractors must cease all operations and notify the NCC and DOJ if an offensive op unintentionally disrupted US systems not involved in cybercrime activity and outside of targeting parameters.
  • Operations will be deconflicted to prevent stepping on the toes of other agencies, like the State Department, Treasury, or the US intel community.
  • The memo doesn't say anything about deconfliction with international partners, which opens the door for some random contractor borking Europol or Interpol operations.
  • Operations won't be approved if there's a risk they might cause loss of human life or an armed attack.
  • Companies must immediately notify the DHS NCC if they discover evidence of an "imminent cyber-attack" against US critical infrastructure, or if they believe the op might trigger one.
  • Participating companies have reporting requirements on the success and outcomes of their operations.
  • Companies will go through annual reviews to check if they're still compliant with the program's rules.

Per the presidential memo, the program must be up and running in the next 60 days, which should be around October 11.

The memo is an extension of a White House executive order from March that ordered government agencies to prioritize the fight against online scam compounds, ransomware, and other cybercrime operations operating at a large-scale.

The March EO contained a small paragraph about recruiting private companies from the US' extensive tech sector to help the government fight cybercrime cartels. The memo expands that small reference into an actual program, as well as its place and role within the US government apparatus.

While some program details and requirements have been shared in the memo, we'll learn the actual procedural details in the next two months, when the NCC publishes the actual requirements.

Details on the actual approval process will be essential and they'll dictate if the program will be accessible to regular cybersecurity and pen-testing vendors, or if this will be another closed party between the usual ex-blue badgers, RTX, and the usual government contracting crowd.

The requirement of running secure facilities and using vetted personnel will make all the difference for who might have a chance of getting approved and receive government work. This will likely eliminate all the smaller infosec vendors hoping to finally get a chance to hack back against some of the threat actors they've been tracking for years.

Cybersecurity companies that want to apply will need to make both financial and personnel investments to become eligible. The value of the contracts will also be something to keep an eye on and will determine if there's an appetite from the private sector.

A Mastodon thread from Dave Wilburn warns the private sector and infosec practitioners from trusting that the Trump administration will be able to attribute threat actor infrastructure correctly, or that it will protect them in case something goes wrong.

"You should also consider the unreliability of the Trump regime's designations for targeting. They've routinely designated civilian or even functionally nonexistent organizations as criminal or terrorist organizations. You cannot trust their assurances that the bad guys you're harming are actually bad guys."

Wilburn's post and others have raised the most important question regarding this program and its chances of success, namely that enough effort will be put in correctly identifying threat actor infrastructure and subsequent fallout before a cyber contractor is let loose.

Large paydays might entice contractors from raising objections when operations and attributions seem murky or put together in haste.

While initially the cybersecurity crowd was extremely happy about the possibility of hacking back the threat actors they hate, it is now dawning on many that they will just be a regular contractor with minimum input, working under strict government authority in operations where they might end up carrying some of the legal risks, such as damages or prosecution by foreign states. Having a proficient legal department might end up being one of the hidden requirements in the long run.

Digital Letters of Marque and Reprisal... I'm not sure if this is a good thing, but I'm also not sure how many businesses would want to sign onto this scheme anyway.

[image or embed]

— Nicholas Weaver (@ncweaver.skerry-tech.com) August 13, 2026 at 6:12 AM

I had to read this four times because the writing is so terrible. Bottom line, it’s a perpetual motion machine for billable threats. www.whitehouse.gov/briefings-st...

[image or embed]

— Jason Kikta (@kikta.net) August 13, 2026 at 2:38 AM

Countdown to a European law enforcement agency having a multi-year ransomware operation being upended by a US defence prime doing pew pews

— Jamie MacColl (@jamiemaccoll.bsky.social) August 13, 2026 at 10:53 AM

Risky Business Podcasts

The main Risky Business podcast is now on YouTube with video versions of our recent episodes. Below is our latest weekly show with Pat, James, and special guest co-host Brad Arkin at the helm!


Breaches, hacks, and security incidents

China hackers use AI against Taiwan: Suspected Chinese hackers have used publicly available AI tools to breach Taiwanese government networks. The intrusion is part of a hacking wave that hit multiple governments networks across Asia. The breach of Thailand's Ministry of Finance with AI tools is part of the same campaign. According to Dream Security, the hackers used a framework of Hermes and OpenClaw agents to automate reconnaissance, breaking in, moving laterally, gathering and then exfiltrating data. [Dream // Focus Taiwan // Financial Times]

Colombia's Ministry of Justice hit by ransomware: A ransomware attack has hit Colombia's Ministry of Justice. The hack took down systems related to the Ministry's illicit-drug monitoring and legal processes. The incident took place five days before the country's presidential handover and the installment of a new government. [DarkReading]

Ransomware hits Guatemala Supreme Court: A cyberattack has taken down the internal systems of the Guatemala Supreme Court. [Emisoras Unidas]

Romania restores land registry after cyberattack: The Romania government has restored its land registry agency's database and apps, a full month after a ransomware attack forced authorities to cease all cadastre and real estate activity. [Romania Insider]

AnMed returns online: US non-profit healthcare provider AnMed says staff have access to its IT system again two weeks after a ransomware attack. The organization also took down several social media pages after members of The Gentlemen ransomware group posted some angry messages demanding payment and making threats to leak user data. [AnMed]

LawCare impacted by BeaconCRM hack: Hackers have stolen sensitive data from UK mental health charity LawCare. The charity is one of almost 1,000 organizations impacted by a breach at software provider BeaconCRM. The stolen data includes details on donors, supporters, volunteers, and fundraising contacts. Most of the data belongs to British lawyers, with which the charity has worked to connect to people in need. [LawCare // The Law Society Gazette]

Valid AWS credentials hard-coded into public JS file? Sounds like vibe coding to me. BeaconCRM powers over 1,000 charities (I've had emails from 2 charities now saying my details have been compromised)

[image or embed]

— Mark Williams-Cook (@markwilliamscook.com) August 13, 2026 at 12:33 PM

ICO reprimands ACRO over breaches: The UK's data protection agency has reprimanded the country's criminal records office for getting hacked three times in two years. The breaches took place between 2021 and 2023 and impacted ACRO's customer portal website. The ICO said the breaches allowed hackers to steal the data of almost 11,000 individuals who requested criminal records via the site. The ICO says the agency had failed to patch the portal for known vulnerabilities for years on end, with the last patch being applied in 2019. [UK ICO]

Uber Freight had a breach: Uber is investigating a breach at its freight transport business after hackers posted internal data on the dark web. The Helix group leaked the data after a failed extortion attempt. Helix is a new group that started hacking and extorting companies this month. [WHTC]

RingCentral discloses breach: The ShinyHunters hacking group has leaked the data of 1.6 million customers of AI company RingCentral. The files were stolen during a social engineering attack that took place last month. RingCentral has since notified all affected customers. The company claims to power AI voice assistants for more than 600,000 businesses. [RingCentral // HIBP]

New Trezor hack: Hardware crypto-wallet maker Trezor says hackers stole the data on 14,000 customers after breaching ShipMonk, one of its shipping partners. [Trezor]

Bybit sues North Korea over hack: Cryptocurrency exchange Bybit has sued the North Korean government in a DC court in an attempt to recover $1.5 billion worth of crypto assets stolen in February of last year. The lawsuit accuses the government and its intelligence service of the hack. Bybit has recovered only $48 million of the stolen funds and has another $30 million frozen at other exchanges. This is the first legal case filed against an entire country over a hack. [Bybit // Risky Bulletin]

Coinsbuy crypto-heist: Hackers have stolen $8 million worth of crypto from the Coinsbuy crypto exchange. [FinanceFeeds]

Ravencoin to roll back blockchain after hack: The Ravencoin project is preparing to roll back its blockchain to a state before August 7, when the platform was hacked and lost tens of millions of tokens. The token also crashed 20% in value. [CoinDesk]

Clop lists 43 victims: The Clop data extortion group has listed more than 40 new victims on its dark web leak site. Among the new victims are some large corporations like Shell, Philips, and General Electric. The recent batch of victims were likely hacked using a vulnerability in PTC Windchill and FlexPLM, two software packages for managing factories and production lines. [BNR // Team Cymru]

AI, general tech, and privacy

Blockchain crowd requests frontier AI access: An industry group for the blockchain and cryptocurrency community has sent an open-letter to frontier AI companies requesting access to their recent models to help defend their infrastructure and the funds it stores. [Bitcoin Policy Institute]

CBP workers abused their access: Internal CBP documents obtained by WIRED through a FOIA request have found that the agency's employees abused their access to government tracking tools to search for data on love interests, girlfriends, co-workers, and more. [WIRED]

"In one case, a CBP officer allegedly used government databases to contact a flight attendant. In another, an officer was accused of pulling information from trusted-traveler applications to ask people out." This story is free to read because of FOIA, and disturbing as hell:

[image or embed]

— Katie Drummond (@katie-drummond.bsky.social) August 13, 2026 at 4:33 PM

Twitch to use live streams to train its AI: Game streaming platform Twitch will use live streams to train its AI models. The training is on by default and streamers will have to disable it in their account settings. [Insider Gaming // Twitch Support]

Non-profit sues Meta over spying glasses: A German privacy non-profit has filed a lawsuit against Meta for breaking the country's strict privacy laws and asking the court to ban the company's spyware glasses. [Politico Europe]

Brave adds anti-GPU fingerprinting protection: The Brave browser has added a new feature in v1.39 that will block GPU fingerprinting attempts via the WebGL and WebGPU APIs. [Brave]

Chrome blocks 7b notifications/day: Google says its Chrome web browser is blocking on average around 7 billion spam and malicious notifications each day. The number is staggering even if Chrome automatically revokes notification permissions for sites with which users haven't recently engaged. Google also rolled out rate limits for the servers that handle Chrome's notifications to combat the rising abuse. No site is allowed to send more than 1,000 notifications per minute. [Google]

OpenSSL releases Windows installer: The OpenSSL project has released a Windows installer for its library for the first time ever. [OpenSSL]

WhatsApp Scam Alert feature: Meta is adding an optional feature to WhatsApp that deploys a local LLM to detect possible scam messages. The new Scam Alert feature will not share any WhatsApp messages with Meta but only alert the user. The feature is being rolled out in a limited Beta this week. [Meta]

Meta bans 750k kids accounts in Australia: Meta says it banned more than 750,000 Facebook and Instagram accounts for kids under 16 in Australia to comply with the country's new children social media laws. [Meta]

Signal Automatic Key Verification: Signal has released a new security feature to verify and confirm that you're having a conversation with the intended party. The new Automatic Key Verification ensures the proper association between a phone number, username, and its public encryption key. All verifications are done in the background, without any user interaction. The Automatic Key Verification feature is designed to stop MitM attacks. [Signal // Automatic Key Verification]

Government, politics, and policy

Germany approves new surveillance powers: The German cabinet has approved new surveillance and hacking powers for the country's intelligence agencies. The draft bill now goes to the Parliament. [The Guardian // Risky Bulletin]

Germany wants to hack Russian drone makers: Some German officials want to grant the country's intelligence agencies the power to hack Russian drone makers. Marc Henrichmann, chairman of the Bundestag Parliamentary Control Committee, argues agencies should be allowed to act before Russia launches drone attacks or sabotage operations. A Russian drone loaded with semtex was intercepted at the Leipzig Airport this month before it could hit an Ukrainian plane. [Die Welt // United24]

Kenya orders internet cafes to store logs: Kenya's communications watchdog has ordered all internet cafes to store logs of customer activity. Logs must be kept for the past three years. The Communications Authority of Kenya says the new rule is designed to prevent the abuse of public computers to carry out cybercrime activity. The new rules enter into effect on August 14. [Citizen Digital]

Brazil orders Discord to suspend live streaming: Brazil's data protection agency has ordered Discord to suspend its live streaming feature. Discord is currently under an investigation after it failed to flag a live stream where a 13-year-old girl was harrassed and encouraged to commit suicide. The girl took her life shortly after the stream. Officials believe Discord failed to factor in child safety when rolling out recent features. [ANPD]

Overseas Koreans Agency sees huge spike in attacks: The South Korean government says cyberattacks targeting its Overseas Koreans Agency rose twelve times compared to last year. [The Korea Herald]

Russia to test AI models for "traditional values": The Russian Ministry of Digital Development will test AI models distributed in Russia for compliance with "traditional values." [Vedomosti]

US ends beneficial ownership rule: The US Treasury has ended the requirement for US businesses to report their beneficial owners. Companies are still required to report their beneficial owners if they are foreigners. The Treasury has also deleted the information of all US citizens from the FinCEN beneficial owners database. The decision will hinder investigations into citizens who run networks of shell companies and engage in money laundering and other illegal activities. [US Treasury]

We passed this law - and make no mistake, it is a law, not just an option for the Treasury department to interpret - to ensure people wouldn't hide their identities in nests of LLCs to launder money. Treasury is protecting criminals with this action. home.treasury.gov/news/press-r...

[image or embed]

— Sean Casten (@seancasten.bsky.social) August 12, 2026 at 2:08 PM

In this Risky Business sponsor interview, Catalin Cimpanu talks with Michael Leland, Field CTO of Island, about the company's seamless expansion into SASE and enterprise AI.

Arrests, cybercrime, and threat intel

Montenegro arrests 50 foreigners for high-tech crime: Montenegrin police have arrested 50 foreign nationals on suspicion of "high-tech crime." Most of the suspects were Ukrainian nationals. They were arrested this week in a large house near the capital of Podgorica. Authorities said they seized so many digital devices they needed a cargo vehicle for transport. [Vlada Crne Gore // Balkan Insight]

Ukraine disrupts 94 scam call centers: Ukraine's cyber police force has disrupted 94 call centers involved in cyber scams. The call centers posed as bankers, brokers, and law enforcement officers to trick victims into investing funds or paying non-existent fines. Authorities notified 26 suspects of charges, seized $2 million, and more than 3,300 computers. [Ukraine Cyber Police]

Spain arrests AI face-swapping scammer: Spanish authorities have arrested a man in the city of Murcia for attempted fraud. The suspect allegedly used AI face-swapping technology to try to obtain digital-signing certificates from government agencies. He used the AI technology during video conferences to defeat identity checks. He tried posing as 30 different people. He was caught after the AI software glitched for a second and exposed his real face. [Spain's Interior Ministry] [h/t KitsuneKaa]

New wave of Apple mercenary alerts: Apple has sent out a new wave of notifications to users who were infected with mercenary spyware. No information on who was targeted yet. [John Scott-Railton] [h/t Lorenzo Franceschi-Bicchierai]

TeamPCP stolen creds leak online: More than 78,000 credentials and secrets stolen by the TeamPCP hacking group have leaked online. The creds were stolen from more than 2,500 organizations during a 40-minute window in March as part of the LiteLLM supply chain attack. The data was found in a massive 153GB RAR archive. [Step Security // CloudSEK // Hudson Rock]

Malicious Chrome extensions: Google has removed 737 malicious Chrome extensions from the official Web Store. The extensions posed as VPN services and targeted Russian users seeking to bypass the Kremlin's internet censorship. According to Socket Security, the extensions routed traffic through the same infrastructure, intercepted web traffic, and defrauded users who sought to buy premium access to VPN servers. [Socket Security]

Malware in free VPN tool: Security researchers have found malware in FirewallFalcon Manager, a tool to manage VPN server infrastructure. The free app deployed a backdoor on Linux servers that would hijack servers from companies that deployed the app. According to security firm Flare, the boobytrapped tool appeared to target VPN resellers and infrastructure operators. [Flare]

Vuln-scan campaign poses as AI crawlers: A threat actor is conducting a mass internet scan and hiding the malicious traffic as AI content crawler bots. The malicious activity began on August 3 and most of the traffic is disguised as ClaudeBot. The attacker is looking to steal credentials and configuration data stored in known directory paths used by AI coding tools. [HackeNews // Archived]

Deadbugz campaign tries to poison AI tools: A threat actor is trying to poison MCP projects and tools hosted on GitHub. At least 23 MCP-related projects received malicious code contributions. The code altered MCP server configurations to collect credentials and tokens and hide the behavior from users. None of the malicious pull requests discovered so far have been approved. [Pillar Security]

City-Forum campaign: A threat actor is hacking Salesforce and ServiceNow customer support portals to steal sensitive data. The attacks began this month and originated from just one server. They are different from the ShinyHunters operation that's been targeting Salesforce instances for the past year. [Reco]

Malinsure group: F6 has spotted a new threat actor targeting Russian financial companies. [F6]

More AI tools on hacking forums: The cybercrime underground is seeing an influx of ads for AI-based hacking tools and aids. Tools range from coding assistants that can write malware without guardrails to full offensive AI frameworks. Other tools claim to help cheat during job interviews and use AI to encrypt malware and evade detection. Trellix says that since the start of the year, AI tools advertised on the underground have moved from an experimental phase to commercial, maintained, and active use. [Trellix]

Deno runtime abuse: Sophos says threat actors are increasingly leveraging the Deno JavaScript runtime to execute their malware outside the reach of security software in a tactic the company is calling Bring Your Own Runtime (BYOR). [Sophos]

Dropcatch domain market: Infoblox researchers have published a three-part series on a new type of  criminal market for selling and repurposing expired domains for criminal operations. [Infoblox #1 // Infoblox #2 // Infoblox #3]

Crypter ecosystem: Recorded Future has published a report looking at the malware crypting ecosystem and the current main sellers for crypting services. The company is tracking 24 threat actors selling these kinds of tools. [Recorded Future]

Malware technical reports

Evooo1Bot: Fortinet has discovered a new Mirai-based botnet that actually built new features on top of the old Mirai instead of just doing a copy-pasta job. [Fortinet]

The Gentlemen ransomware: Intel471 looks at the recent TTPs employed by The Gentlemen ransomware in its intrusions, stuff organizations should be detecting. [Intel471]

Akira abuses Safe Mode: The Akira ransomware group has been spotted rebooting Windows systems in Safe Mode as a way to bypass EDRs, since antivirus software does not start in that mode. [Huntress]

ErrTraffic: WatchGuard has published a report on ErrTraffic, a new cybercrime tool to automate the deployment of ClickFix social engineering lures and pages. The latest update is the addition of EtherHiding to harden its infrastructure against takedowns. [WatchGuard]

Lucid Stealer: A new infostealer named Lucid Stealer is using Node.js execution environments to conceal itself on infected hosts. [CyFirma]

JWR phishing kit: Cisco Talos has identified a previously unseen phishing kit called by its developed JWR but which appears to be a new version of The Outsider phishing service. [Cisco Talos]

Octagon Android trojan: A known malware developer has launched and is selling access to a new Android trojan named Octagon for $1,400/month. [iVerify]

RedWing in Russia: While it was rare in previous years to see Android banking trojans target Russia, it is now actually quite common. The latest to support Russian banks is the RedWing family, which launched as a Telegram-based MaaS last month. [F6]

WindRelay: Group-IB researchers have discovered a new Android trojan named WindRelay that can clone NFC card data and relay it to a threat actor waiting to cash it out at an ATM or to pay with it for products at a fake merchant terminal. The malware has been seen in campaigns where it's deployed together with the SpyNote RAT. The RAT was used to take out loans in the victim's name via their local banking app. [Group-IB]

In this sponsored Soap Box edition, Patrick Gray talks to Island CEO Michael Fey about some of the cool tricks in the Island enterprise browser. You can use it to tick off so many compliance boxes, and not just cybersecurity boxes. 

APTs, cyber-espionage, and info-ops

New Armored Likho activity in Russia: Kaspersky says the Armored Likho (Eagle Werewolf) APT group has launched new attacks targeting Russia. The recent campaigns involved new Rust-based malware such as the Still Toolkit. Targets were infected using a malicious app that mimics a service used for donations. Most of the victims were private individuals. [Kaspersky]

APT36's PATCHCORD: A suspected Pakistani APT group has hacked telecoms and critical infrastructure operators in Afghanistan and South Asian countries. The hacked entities were all infected with a new backdoor family tracked as PATCHCORD. [Acronis]

Jewelbug doesn't hide its illegal hacks: A Chinese APT group is running its cyber-espionage operations from the same backend it uses for its private cryptocurrency fraud business. Jewelbug victims include government entities from Southeast Asia and the Middle East, but also Chinese citizens who had their crypto stolen. All victims are controlled from XG-Web, a web panel for managing users infected with the group's backdoors. Broadcom believes the APT is a hired contractor operating out of China's Hunan province. [Broadcom]

Vulnerabilities, security research, and bug bounty

Security updates: Fortinet, Frappe, SonicWall, WordPress.

Academics hack a Boeing: A team of academics from the US has developed a special device that can hack Boeing 737 airplanes. The device needs to be connected to a port accessible via a hatch under the plane. Once connected, the device can tamper with the plane's avionics and show incorrect data to pilots. [WIRED // Paper, PDF]

macOS bug exploited to drop cryptominers: Threat actors are exploiting a macOS vulnerability to gain remote access to devices and install a cryptocurrency miner. The attacks are exploiting a bug that lets them bypass authentication in the Screen Sharing feature and gain access to a device. Apple patched the bug in macOS Tahoe, Sequoia, and Sonoma last week. Users are advised to block access to port 5900 on their macOS devices or disable Screen Sharing. The attacks mark some of the first mass remote exploitation over the internet against macOS devices seen in the wild. [Dutch NCSC // CVE-2026-65400]

New VMware bug exploited in the wild: Hackers are exploiting a new VMware vulnerability to gain access to vCenter servers. VMware patched the bug at the end of July before exploitation began last week. Attacks are targeting a directory traversal bug to run code on the vCenter central management server. German security firm QUIRSO says the hackers have compromised at least 360 servers. [QUIRSO // CVE-2026–59310]

Plug and Pwn attack: A newly developed attack can allow threat actors to gain administrator access over a Windows computer by plugging in a malicious USB device. Named Plug and Pwn, the attack takes advantage of a secret Windows feature that automatically downloads and installs vendor software and drivers when one of their devices is plugged in via USB. The malicious USB can allow threat actors to force Windows into installing vulnerable drivers and then exploiting them to gain elevated privileges. The attack requires no user interaction and can also be executed remotely via RDP USB redirection. [Plug and Pwn]

ShieldBreak zero-day: Security researcher NightmareEclipse has published a new Windows Defender zero-day. The ShieldBreak exploit abuses the Windows Defender security software to gain admin access on Windows systems. It works on both Windows 10 and Windows 11. The researcher timed the release to come after Microsoft released this month's Patch Tuesday security updates. [GitHub // Cyderes]

Zapscape vulnerability: Security researcher Hyunwoo Kim has published a third guest-to-host virtual machine escape. This one's named Zapscape and works on KVM/x86 architectures. Kim previously also discovered the ITscape and Januscape vulnerabilities. [Hyunwoo Kim on GitHub]

CopyEscape vulnerability: Imperva has discovered a container-to-host escape in Docker's cp command. [Imperva]

"A malicious container or sandbox could exploit the copy process to create or overwrite files outside the destination selected by the user, potentially enabling code execution on the machine running the Docker CLI."

Infosec industry

Threat/trend reports: Check Point, CSA, Flashpoint, Kaspersky, and ThreatDown have recently published reports and summaries covering various emerging threats and industry trends.

Rapid7 layoffs: Cybersecurity firm Rapid7 has laid off 12% of its staff, or around 300 employees. Rapid7 had more than 2,600 employees before the layoffs. The cuts come two months after the company named a new CEO in Wael Mohamed. Mohamed said the company is "creating capacity" to invest into AI solutions. [DataBreachToday]

DEFCON 2026 videos: Talks from the DEFCON 2026 security conference, which took place earlier this month, are available on its official website.

Risky Business podcasts

In this edition of Seriously Risky Business, Tom Uren and James Wilson talk about the cybercrime ecosystem shifting towards data theft extortion, stealing sensitive data and extracting ransoms from victims by threatening to leak it.