New research, which its authors call HalluSquatting, turns that habit into an attack: work out the fake names an AI reliably invents, register them first, and wait for the assistant to fetch your trap on a user’s
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
The list of vulnerabilities is as follows –
CVE-2026-50746 (CVSS score: 10.0) – An improper access control vulnerability in UniFi Connect Application that an attacker
3 Ways AI Powers Service Desk Attacks and How to Prevent Them
Webinar Today: Why Email Security Keeps Failing
Live Webinar: Wednesday, July 8, 2026 – Register to Attend You can block every phishing email in the inbox. The campaign still runs. The infrastructure is still live. And the same attacker retargets your organization tomorrow. That’s the gap in how most organizations think about email security: detection without disruption. Stopping the message was never […]
The post Webinar Today: Why Email Security Keeps Failing appeared first on SecurityWeek.
New Ghost Phishing Wave Is Breaking Traditional Email Security
For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365 access, sensitive data, and response time
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verification pages that deceive them into running a malicious command that installs a PowerShell toolkit dubbed
Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations
The “Rogue Agent” vulnerability could have enabled attackers to silently manipulate AI conversations, exfiltrate data, and compromise every Dialogflow CX agent within the same Google Cloud project.
The post Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations appeared first on SecurityWeek.
DuckDuckGo browser now blocks YouTube video ads
GitHub ‘Verified’ Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
Everything a reviewer would check matches. The commit’s hash does not. That matters
The Verification Step Is the New ATO Battleground in 2026
That era is ending. Not because attackers gave up, but because the front door finally got harder to kick in.
Passkeys are now mainstream.
