Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AppTrana Adds Post-Quantum Cryptography Support with X25519MLKEM768

Quantum computers could very soon undermine the public-key cryptography that secures financial transactions, health records, and other sensitive data moving over TLS today. When that happens, encrypted information protected by vulnerable cryptography could become accessible. Encrypted traffic can be intercepted and stored today, with the expectation that it will be decrypted once a sufficiently capable quantum computer exists.

The only perfect Endpoint Prevention and Response (EPR) score in 2026 belongs to Elastic

Elastic sits at the very top of this year’s AV-Comparatives' CyberRisk Quadrant within the 2026 Endpoint Prevention and Response (EPR) test with the only protection scores at 100%, combined with both the lowest modelled operational footprint of any tested product and zero false alerts.

Red Teaming Agentic AI: Why Testing the Model Is No Longer Enough

In January 2025, NIST's Center for AI Standards and Innovation published red team results that should have changed how enterprises test autonomous systems. Against an AI agent operating in simulated workspace, travel, Slack and banking environments, the strongest previously known hijacking attack succeeded 11% of the time. The strongest new attack developed by the red team succeeded 81% of the time. The model had not changed. The evaluation had.

Ranked: The 10 Best AI SEO Agencies for 2026

SEO is having a bit of a moment. Getting onto page one of Google still matters, of course, but that is no longer the whole picture. Brands now also need to think about whether they are being mentioned in AI-generated answers, summaries, recommendations, and conversational search results. That is where AI SEO comes in. The strongest agencies in 2026 are not throwing traditional SEO out the window. They are combining the fundamentals that still work with newer strategies built around AI search visibility, authority, brand mentions, and genuinely useful content.

ATT&CK grew a 15th tactic: A practical DFIR field guide to the Stealth / Defense Impairment split

Artifacts and tooling for the new Enterprise MITRE ATT&CK matrix tactics, distilled from the field. This article is part of an ongoing series from Sophos frontline security operations specialists, sharing the expertise they use to strengthen our industry-leading Managed Detection and Response (MDR) service and defend customers against evolving AI Era threats. If you’ve opened the Enterprise ATT&CK matrix recently, you may have done a double-take. The familiar Defense Evasion column is gone.

Devil's advocate? Uncensored Luciferus AI service advertised underground

On August 24, 2026, Counter Threat Unit (CTU) researchers observed an Exploit underground forum persona named “Optimus_Prime” advertising an uncensored AI subscription service named Luciferus. The persona joined Exploit on April 18, and their profile displays a “coding / coder” activity label. As of September 4, the persona has published 21 posts on the forum.

Cybersecurity is Getting Faster at the Wrong Thing

Reaction remains cybersecurity’s default posture. Rather than question that approach, the industry has focused on making it faster. The instinct is understandable. Cybersecurity has always been about understanding threats. What has changed is their sheer scale, and the growing gap between what organisations can see and what they can realistically act on. Somewhere along the way, we started calling faster detection, richer analysis and AI-powered response proactive security.

CVE-2026-84869: ConnectWise ScreenConnect Client Vulnerability Critical Remote Session File Transfer Exploitation Risk

A critical security weakness (CVE-2026-84869) has been identified in the ConnectWise ScreenConnect client (prior to version 26.6.5), where missing authorization controls and improper privilege management allow file transfers and execution through active remote sessions without host confirmation.