Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The EU has begun enforcing key provisions of the AI Act, introducing new transparency rules and bans on high-risk AI applications. As of August 2, AI-generated content—including chatbots, deepfakes, and synthetic media—must be clearly labeled, while certain uses, such as non-consensual intimate imagery and child abuse material, are now prohibited.
Ghost credentials, or dormant nonhuman identities such as service accounts, API keys, OAuth tokens, and machine-to-machine certificates, create significant security blind spots in cloud environments. These identities are often provisioned for automation and integrations, then forgotten as teams change and projects evolve, leaving them with excessive privileges that go unmonitored.
Security researcher Aleksandr Krasnov highlights that dormant nonhuman identities can create security blind spots in cloud systems. He plans to release an open source tool at Black Hat USA 2026 that sniffs out trust paths to expose these hidden identity risks.
Ghost credentials, or dormant nonhuman identities such as service accounts, API keys, OAuth tokens, and machine-to-machine certificates, create significant security blind spots in cloud environments. These identities are often provisioned for automation and integrations, then forgotten as teams change and projects evolve, leaving them with excessive privileges that go unmonitored.
Security researcher Aleksandr Krasnov highlights that dormant nonhuman identities can create security blind spots in cloud systems. He plans to release an open source tool at Black Hat USA 2026 that sniffs out trust paths to expose these hidden identity risks.
CubePilot, an Australian drone flight controller manufacturer, suffered a DNS hijacking attack on July 24, 2026, when an attacker gained control of cubepilot.org DNS settings, intercepting traffic intended for internal systems and fraudulently obtaining TLS certificates for all subdomains. This exposed users to credential theft, malware delivery, and phishing — even on pages showing valid HTTPS. CubePilot regained control of its domains the same day, revoked fraudulently issued certificates, preserved evidence, and reported the incident to the Australian Cyber Security Centre and law enforcement.