Comp AI sets eyes on a continuously agentic future for security and compliance
techcrunch.com

Comp AI sets eyes on a continuously agentic future for security and compliance

Comp AI, a cybersecurity and compliance startup founded in January by Lewis Carhart, Claudio Fuentes and Mariano Fuentes, announced a $34 million Series A financing led by Roo Capital and Grand Ventures, bringing its total funding to $37.5 million. Drawing on lessons from their previous venture LeapAI—where manual SOC 2 compliance slowed product development—the trio built an “agentic” platform that automates policy drafting, evidence collection and continuous monitoring of compliance controls. The system also offers AI‑driven penetration testing and aims to keep security postures [...]
Best Antivirus for Windows 2026: 5 to Install, 1 to Avoid
gizmodo.com

Best Antivirus for Windows 2026: 5 to Install, 1 to Avoid

A 2026 review ranks five paid Windows antivirus products and Microsoft Defender. Norton 360 tops the list, completing a full scan in 13 minutes 22 seconds and offering a robust firewall and 250 GB cloud backup. Bitdefender excels on older PCs, keeping CPU usage at 11 % and memory at 183 MB during a sweep. Avast One delivers a free, lab‑certified solution. NordVPN Threat Protection Pro provides full Windows protection for VPN subscribers. McAfee + offers unlimited device coverage but has the slowest scan. Microsoft [...]
Major Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program
infosecurity-magazine.com

Major Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program

SE Labs, a UK security testing firm, announced its six‑month PIVOT program on September 15 to benchmark cybersecurity vendors against the world’s most dangerous threat actors. The program employs a team of ethical hackers who simulate nation‑state and ransomware groups, testing vendors’ detection, interruption, and containment capabilities across full attack chains. Participants include Broadcom (Symantec, Carbon Black), CrowdStrike, Fortinet, Palo Alto Networks, and Sophos. Testing began in July, will finish in October, and results are slated for [...]
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
thehackernews.com

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers uncovered the KREMLIN banking malware, active since May 2025, that lures Brazilian bank customers with fake documents and installs a malicious browser extension on Chrome and Edge. The multi‑stage payload uses JavaScript loaders, custom C++ installers, and blockchain‑based command‑and‑control via Ethereum smart contracts to evade detection. The extension bypasses Chromium integrity checks, harvests credentials, session tokens, and browser data, and exfiltrates it to a C2 server while maintaining persistence through scheduled tasks.
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
thehackernews.com

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

Cybersecurity researchers uncovered BambooToken, a multi‑platform malware that has operated since February 2023, targeting Windows and Linux systems across Asia and South America. The campaign uses the MQTT protocol for command‑and‑control, a rare choice for malware. BambooToken is delivered via Tendyron’s OnKey USB security token, exploiting DLL sideloading to evade detection. The malware collects extensive system data, exfiltrates antivirus information, and has been observed communicating from Chinese IP addresses and Cloudflare‑proxied domains.
Cybersecurity shares advance as AI safety debate widens
thearabianpost.com

Cybersecurity shares advance as AI safety debate widens

Cybersecurity stocks surged on Monday as concerns about AI development prompted investors to shift from chip makers to firms expected to benefit from increased spending. CrowdStrike closed up 13.9% and Palo Alto Networks rose 13.1%, making them the top gainers in the S&P 500, while Nvidia, AMD and other chipmakers slipped. The rally extended to Zscaler, SentinelOne, Okta and Fortinet, and the iShares Expanded Tech‑Software Sector ETF jumped more than 5%, underscoring software outperformance. The move follows a [...]
Entrust Turns CBOM Data Into Action With Expanded Cryptographic Security Platform
thequantuminsider.com

Entrust Turns CBOM Data Into Action With Expanded Cryptographic Security Platform

Entrust expanded its Cryptographic Security Platform (CSP) by adding CBOM import and export functions, enabling organizations to link cryptographic inventories with governance, risk assessment, and remediation. The update includes Ansible‑based certificate lifecycle automation, broader composite algorithm support, and SPIRE‑driven machine and AI identity capabilities. CSP is offered as a service or on‑premises, with options for post‑quantum migration and data sovereignty compliance. The move addresses regulatory demands such as U.S. Executive Order, EU DORA, and NIS2, which mandate [...]
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
thehackernews.com

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

WordPress announced an automated security review for every plugin release distributed via its update API, aiming to detect vulnerabilities before they reach users. The system, part of the Protect The Shire initiative, introduced a six‑hour cooldown period for updates, down from 24 hours, and automatically blocks high‑risk releases. On July 28, 2026, the review flagged a backdoor in a plugin with roughly 20,000 active installs, preventing its distribution. Developers must address findings to lift the block, while WordPress [...]