
Top story
Inward fraud & financial crime, explained for Gen Z

Apple Pay officially launched in the Philippines on Tuesday, allowing cardholders from Chinabank, GOtyme, Metrobank and UnionBank to make contactless payments on iPhones, Apple Watches, iPads and Macs, Visa and Mastercard announced. Additional banks are expected to join in coming months.
The launch intensifies competition with Google Pay, which rolled out nearly a year earlier. Both services let users store card numbers in encrypted device accounts rather than physical wallets, with Apple saying it does not retain transaction data linked to a user's identity and does not charge consumers fees. "The launch of Apple Pay enables secure, seamless, and convenient payment experiences for consumers in the Philippines," said Jason Crasto, Mastercard's country manager, Inquirer business (PH) reports.

Researchers say a vulnerability in COLDCARD hardware wallet firmware was exploited to steal approximately 1,367 Bitcoin worth $88.6 million from 4,585 wallets, with the thefts occurring across three waves beginning July 30, according to Galaxy Research and Chainalysis.
Block's Bitcoin Engineering and Security teams traced the issue to an integration error in COLDCARD's random number generation code that caused the device to use a deterministic software generator instead of its hardware RNG. The fallback generator relied on the device's microcontroller identifier and system timing values, allowing attackers to generate possible wallet seeds offline, match them against blockchain addresses, and steal funds from affected wallets.
Coinkite disclosed the flaw on July 31, two days after researchers identified it. Affected devices include Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9, Mk4 and Mk5 devices before version 5.6.0, and Q devices before version 1.5.0Q. Updated firmware is available, Lawrence Abrams reports for BleepingComputer.

A China-based threat actor is using the DeepSeek AI model and open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with minimal human involvement, according to Palo Alto Networks' Unit 42. The researcher, operating under aliases "knaithe" and "KnYuan," configured the agent to accept instructions via Telegram and search for vulnerable systems using the FOFA internet asset search engine.
In a May 2026 session recovered by Unit 42, the agent independently researched vulnerabilities, targeted internet-exposed Langflow and n8n servers, downloaded exploit code, and attempted attacks within minutes—work that would normally require many hours of manual analysis. The agent identified 84 exposed Langflow instances and more than 647,000 n8n instances but failed to compromise any targets, as discovered forms required authentication the attacks could not bypass.
"The workflow confirms a functional, end-to-end autonomous offensive capability," Unit 42 said. The researchers noted the agent operates in "Yolo" mode, executing commands without requesting permission, and that the threat actor also conducted manual attacks against more than 460 systems separately, Lawrence Abrams reports for BleepingComputer.

A coalition of 19 government agencies across nine countries warned on Friday that North Korea is deploying IT workers under stolen identities to generate illicit revenue for its nuclear weapons and ballistic missile programmes, Reuters reports.
The statement, signed by the US, South Korea, Japan, the UK, France, Germany, Italy, the Netherlands and New Zealand, said Pyongyang uses artificial intelligence to expand its network of fraudulent remote workers who obtain employment on global freelancing platforms. The advisory warned that the workers pose escalating insider security threats, engaging in corporate data theft, cryptocurrency theft and espionage.
"North Korean IT workers employ increasingly sophisticated methods, including the integration of AI, to obfuscate their identities and expand their activities globally," the coalition said, urging hiring platforms and employers to strengthen identity verification. Operatives typically access company devices remotely through VPNs via "laptop farms" in North Korea, China, Russia and Southeast Asia, according to the advisory, Al Jazeera reports.
The US Cybersecurity and Infrastructure Security Agency has published new guidance on securing open source software, which it says is now embedded in nearly every modern system from business applications to critical infrastructure.
The guidance covers risk management across the full lifecycle of open source software, introduces a C4 Framework for trust assessment, and provides recommendations for vulnerability management, software bills of materials, secure development and handling of open source AI systems, CISA reports.

Google says artificial intelligence helped patch 1,072 security vulnerabilities across Chrome 149 and Chrome 150, surpassing the total fixed in the previous 23 releases combined, according to a statement from the company.
Google uses large language models throughout its vulnerability management process, including discovering flaws, reproducing reports, determining severity and generating patches. The company began using LLMs for security fuzzing in 2023 and has since developed AI-powered systems including Big Sleep, which found flaws in Chrome's V8 JavaScript engine, and a Gemini-powered agent that searches the broader codebase. One vulnerability discovered by the system was a Chrome sandbox escape that had remained in the code for more than 13 years.
Google is also automating vulnerability triage, including filtering duplicates and assigning severity ratings. The company estimates this automated process saves hundreds of hours of developer time each month. In May, these systems prevented more than 20 vulnerabilities from reaching production, including one classified as critical, Google said, Lawrence Abrams reports for BleepingComputer.
Every briefing is also an episode. Click to play — audio streams from Substack in the player at the bottom of the page.
Prefer your own app? Follow on Substack, Apple Podcasts and Spotify.
One email each weekday on what the day’s politics and money decisions do to your rent, your HECS debt, your visa and your bills. No jargon. No filler.
Free. Delivered by Substack — unsubscribe in one click, any time.