Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Apple Warns Users to be Wary of Unsolicited FaceTime Calls

Apple is warning users to be wary of unsolicited FaceTime calls amidst a wave of scams impersonating Apple Support, Malwarebytes reports. The scammers inform the user that there’s been fraudulent activity or a technical problem associated with their account, and trick the victim into handing over payment card details, banking credentials or Apple ID logins.

Everyone's a Builder Now. That Changes Security Training.

I've spent my career figuring out what makes content stick, from early work for brands like Apple and onward across two decades across film, animation and generative AI. Different tools every few years, same question underneath. What makes someone lean in instead of tuning out? Turns out that question sits at the center of a problem the security industry has wrestled with for 15 years. How do you build a culture where people actually change how they behave? Not comply. Not click "complete." Change.

New Phishing Kits Use Open-Source Tools to Bypass MFA

Researchers at Lexfo are tracking three sophisticated phishing kits that were built using open-source components, primarily based on the publicly available adversary-in-the-middle (AiTM) attack framework “Evilginx.” The phishing kits are designed to proxy “live Microsoft 365 authentication sessions to capture session cookies and OAuth tokens in real time, bypassing MFA entirely.” The kits also use AI to generate personalized phishing lures with a variety of different delivery metho

Beyond Remote Access: The Next High-Growth MSP Service

The workplace has fundamentally changed. Employees work from home, customer locations, airports, coffee shops, hotels, and virtually anywhere with an internet connection. At the same time, the applications they depend on are spread across Microsoft 365, SaaS platforms, private cloud environments, corporate data centers, and on-premises business applications. For managed service providers (MSPs), this represents one of the largest recurring revenue opportunities available today.

An API for MoQ: provision your own isolated relays

Last year, we enabled Media over QUIC (MoQ) on every Cloudflare server and opened the network for anyone to test. It provided a global MoQ endpoint, but not the isolation and access controls needed to run an application. Today, we’re adding those isolation and access controls. The new MoQ provisioning API lets you create an isolated relay for your application and issue separate credentials for publishers and subscribers.

The Hugging Face Incident: A CISO Wake-Up Call for the Agentic Era

Earlier this month, Hugging Face, an AI and machine learning platform company, revealed that an autonomous AI system had breached part of its production environment. The intrusion began in the platform’s dataset-processing environment and eventually involved higher-level access, credential exposure, and movement into internal clusters.

The UK Has a Foreign Vendor Problem. The Case Studies Are Piling Up.

The NHS, MoD, and Metropolitan Police have each built deep operational dependency on Palantir through contracts largely awarded without competitive tender. Parliament has called it "an unacceptable point of weakness," Sadiq Khan blocked a £50 million Met Police deal, and the pattern keeps repeating: enter below scrutiny thresholds, build dependency, make exit expensive.

How Do I Check My iPhone for Malware: A Complete Guide

If your iPhone suddenly feels wrong, slower, hotter, or louder in the background, don't waste time hunting for a magic antivirus button. How do I check my iPhone for malware is the wrong question if you expect a desktop-style scan, because iOS doesn't work that way. The right question is, what did the attacker leave behind, and what changed in the device's behavior or configuration? That's the triage mindset security teams use on endpoints, and it fits iPhone incidents too.

Torq Named a Leading Innovator in SACR 2026 AI SOC Market Report

Software Analyst Cyber Research (SACR) just published its 2026 AI SOC Market Report, offering an independent assessment of vendors competing in what has rapidly become the most consequential category in enterprise security. Torq features prominently, and the report’s framing is worth unpacking because it illuminates what makes the AI SOC category hard to evaluate and why Torq’s approach is consequential.

The Best Cybersecurity Risk Assessment Tools of 2026

Cybersecurity risk assessment has fragmented into distinct categories of tooling, and no single platform covers every dimension enterprise programs need. Governance, risk, and compliance platforms handle framework mapping and audit workflows. Vulnerability management tools scan technical exposure at the infrastructure layer. ‍