US government authorizes private security firms to hack overseas cybercriminals

The Trump administration has issued a National Security Presidential Memorandum authorizing private security firms to conduct offensive cyber operations against overseas criminal organizations. The program, managed by the National Coordination Center under the Homeland Security Task Force, marks the first time the US government has formally delegated offensive cyber authority to the private sector. Under […]

OpenAI and Anthropic slash prices as Chinese AI rivals close the gap

OpenAI and Anthropic are slashing prices on their mid-tier AI models as cheaper Chinese alternatives gain traction among cost-conscious businesses and developers. The price cuts mark a shift from competing purely on model performance to competing on cost, with Chinese labs like DeepSeek and Moonshot forcing the market down. OpenAI cut prices on GPT-5.6 Luna, […]

Anthropic starts watermarking Claude text using DeepMind’s SynthID

Anthropic has started rolling out invisible watermarks on text generated by its Claude models, joining Google and OpenAI in deploying content provenance technology ahead of the EU AI Act’s transparency requirements. The watermarking, which uses Google DeepMind’s SynthID-Text approach, is designed to travel with text when it is copied and pasted, surviving basic edits. The […]

AKS control plane metrics now generally available with Managed Prometheus

Azure has made control plane metrics collection for AKS generally available, and it runs on Azure Monitor Managed Service for Prometheus. Until now, getting visibility into the managed Kubernetes control plane meant either accepting whatever Azure surfaced in its own dashboards or standing up your own Prometheus and scraping whatever you could reach. This closes […]

Critical VMware vCenter RCE exploited via reverse SSH

A critical remote code execution vulnerability in VMware vCenter’s Syslog Server is under active exploitation right now. Tracked as CVE-2026-59310, the flaw carries a CVSS 3.1 score of 9.8 and is being used in a live campaign that drops an open source reverse SSH tool onto compromised hosts for persistence and remote access. If you […]

DeepSeek Harness: the plugin first framework for AI agents

DeepSeek’s open source agent framework, DeepSeek Harness, exploded onto GitHub this week and picked up close to 70,000 stars in a single day. The repo’s tagline is simple and a little audacious: “everything is a plugin.” That phrasing is doing a lot of work, and it’s worth unpacking what the project actually ships, because the […]

Batch Rule Updates for Azure Front Door Are Now Generally Available

Anyone who has managed Azure Front Door for any length of time has felt the pain of touching a rule set. Rule sets are where you define how traffic gets inspected, rewritten, and routed, and they sit right at the edge of your application where a bad change is immediately visible to real users. Historically, […]

Pass-ta-key: What the New Passkey Attack Actually Does

Passkeys were supposed to end the era of phishing. They are cryptographic, they do not rely on passwords you can type into a lookalike website, and the big platform vendors have spent years pushing them as the replacement for credentials. So when a new attack with the catchy name “Pass-ta-key” hit the news, it was […]

Tailscale Traced Database Corruption to a 16-Year-Old SQLite Bug

SQLite is about as close to “boring, reliable” as a database gets. It sits inside phones, browsers, and countless desktop apps, and most developers never think about it twice. So when Tailscale, a company that runs a mesh VPN used by thousands, started seeing their SQLite databases get corrupted, the last thing anyone expected was […]

Researchers pull hidden reasoning out of Claude, GPT, and Gemini

Advanced AI models do not give you a straight answer all at once. They break a problem into pieces and work through them step by step, in a chain of thought that providers deliberately keep hidden. That hidden reasoning is valuable, because it is exactly what you would want if you were training your own […]

Cisco ClamAV flaws with public exploits leave a detection gap

Cisco has warned about a batch of vulnerabilities in the ClamAV engine that ships inside its Secure Endpoint Connector. Seven flaws, disclosed on August 7, all let an unauthenticated remote attacker crash the malware scanner by feeding it a crafted file. Two of them already have public proof-of-concept code, which is why the advisory is […]

DeadLock ransomware uses blockchain to shrug off takedowns

Ransomware groups have spent years moving their leak sites around the internet, hopping from domain to domain as takedowns land. DeadLock tries to remove the weak point entirely. It spreads its command structure across a blockchain, so there is no single server for police to seize and no domain name to sinkhole. How it stays […]