❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Visa Stablecoin Treasury Engine Pushes Settlement Deeper Into Institutional Finance

21 July 2026 at 11:00

Visa Stablecoin Treasury Engine Pushes Settlement Deeper Into Institutional Finance

Visa has launched a stablecoin treasury engine for financial institutions, marking another step in the shift from crypto payment experiments to real institutional settlement infrastructure.

The service is designed to let financial institutions settle merchant network balances using stablecoins such as USDC and EURC. That matters because Visa is not pitching this as a retail crypto wallet or a speculative trading product. It is a treasury and settlement tool for institutions already operating inside the payments system.

The difference is important.

Stablecoins have proven useful in crypto markets for years, but the more interesting development is their movement into traditional financial plumbing. If banks, payment firms, and merchants can settle balances using stablecoins behind the scenes, blockchain-based dollars and euros become less of a crypto-native novelty and more of an operational settlement layer.

TL;DR

  • Visa has launched a stablecoin treasury engine for financial institutions.
  • The service supports institutional settlement using stablecoins including USDC and EURC.
  • This is a B2B treasury product, not a retail wallet launch.

Why Visa’s Move Matters

Visa has been testing stablecoin settlement for years, but the market pays closer attention when those tests begin moving toward operational products.

The reason is simple: Visa sits at the centre of global payments. When it experiments with stablecoins, it does not need to convince the world that payments exist. It is trying to make settlement faster, more flexible, and more programmable inside an existing financial network.

That is very different from a startup trying to replace the card system.

A stablecoin treasury engine can help financial institutions manage balances in digital dollars or euros while still operating within a familiar settlement environment. For institutions, that can make stablecoin adoption feel less like a crypto bet and more like an infrastructure upgrade.

It also speaks to one of stablecoins’ strongest use cases: settlement speed.

Traditional payment settlement can involve multiple intermediaries, cut-off times, and currency-specific banking rails. Stablecoins can move continuously and settle directly on blockchain networks, depending on the setup.

Visa’s role is to make that capability usable by institutions that cannot simply plug into crypto rails casually.

Stablecoins Are Becoming Treasury Tools

Most retail users think about stablecoins as trading dollars.

Institutions think about them differently. They care about settlement, liquidity, reconciliation, counterparty exposure, balance management, compliance, and how money moves between entities.

That is why the word β€œtreasury” matters here.

If stablecoins become part of treasury operations, they can sit behind payment flows without end users necessarily realizing a blockchain is involved. A merchant may care that settlement is faster or cheaper. It may not care whether the underlying balance moved through USDC, EURC, or a traditional banking transfer.

This is how crypto infrastructure often becomes mainstream: not by demanding attention, but by solving a back-office problem.

Visa’s stablecoin treasury engine points in that direction. It gives institutions a controlled way to use stablecoins where they make operational sense, while still keeping the product inside a professional financial framework.

USDC And EURC Show The Multi-Currency Direction

The inclusion of both USDC and EURC is notable because stablecoin settlement is becoming more than a dollar-only story.

Dollar stablecoins dominate the market, but euro stablecoins are increasingly important for European payments, MiCA-era compliance, and multi-currency settlement use cases. If institutions want to use stablecoins for treasury management, they will eventually need access to more than one currency.

That is one reason Visa’s move matters.

Multi-stablecoin infrastructure can support more flexible settlement between regions, merchants, and financial institutions. It can also reduce the need for every transaction to route through dollar liquidity if another currency is more appropriate.

The stablecoin market is still heavily dollar-based, but institutional settlement may push more demand toward regulated non-dollar tokens over time.

That could become especially relevant in Europe, where MiCA has created a clearer framework for stablecoin issuers and service providers.

This Is Not A Retail Crypto Product

The product should be framed carefully.

Visa is not launching a consumer-facing app that lets everyday users speculate on stablecoins. This is an institutional treasury framework. It is designed for financial institutions and settlement operations, not retail trading.

That makes it less flashy, but more important.

The biggest stablecoin adoption may not come from people choosing to hold stablecoins in a wallet. It may come from stablecoins being used quietly inside payment networks, merchant settlement systems, institutional treasury desks, and cross-border liquidity management.

That is where Visa has influence.

For crypto markets, the signal is clear: stablecoins are moving deeper into mainstream financial infrastructure. The sector has spent years proving that tokenized dollars can move quickly on-chain. The next phase is about whether large financial networks can safely use that speed inside regulated systems.

Visa’s stablecoin treasury engine is another step in that direction.

This article is based on Visa newsroom materials.

This article was written by the News Desk and edited by Samuel Rae.

This report is based on information released in official primary source disclosures at primary source documentation.

Edge Devices Are Your Cyber Underbelly. Here’s Why.

20 July 2026 at 07:00

In this episode of the podcast, host Paul Roberts interviews Nishawn Smagh of the firm GreyNoise Intelligence about the findings of their State of the Edge report, an analysis of GreyNoise data on risks stemming from compromised edge devices such as broadband routers, VPN gateways, smart home devices and more. Shawn and Paul talk about how attackers are turning edge devices into their favorite entry point, and strategies for organizations to counter the growing risk of compromised edge devices.

The post Edge Devices Are Your Cyber Underbelly. Here’s Why. appeared first on The Security Ledger with Paul F. Roberts.

πŸ’Ύ

Russian hackers keep finding their way into critical networks through neglected routers

15 July 2026 at 07:31
Russian state-backed hackers are exploiting neglected routers to access critical infrastructure networks, prompting agencies worldwide to urge organizations to replace outdated equipment and tighten basic network security.

Can’t Find That ISA Sound Card? No Worries!

13 July 2026 at 22:00

Many older hackers will have at some point gotten rid of an old piece of hardware that they later ended up regretting. All those ISA cards were next to useless back in 2006, but now their relative rarity plus the popularity of retrocomputing makes them sought-after. But if it’s a sound card you’re after then never fear! [Schlae] has got you covered, with the Beavis Ultrasound. It may have a name reminiscent of a ’90s cartoon series, but it’s a clone of the Gravis Ultrasound from back in the day.

There is of course a snag, to build one you need an AMD AM78C201. Assuming you’ve found one in a surplus supplier though, the rest of the card is analogue, some glue logic, and a ROM for samples. There is also a GAL for driving the IDE CD-ROM interface, from the days when sound cards came with such things.

New ISA cards are cropping up here from time to time, such as this very handy storage and network card.

The US government warns that Russia state hackers are coming after your router

13 July 2026 at 17:03

The federal government is warning users of home and small office routers to secure their devices as Russia state hackers continue to mass-compromise them for use in obscuring nefarious actions against sensitive organizations in the public and private sectors.

Both the Russian and Chinese governments have been compromising routers for years, sometimes in prolonged tugs-of-war to wrest control of devices the other has already commandeered. The US government has occasionally issued covert commands and taken other steps to disinfect routers. Google and other companies have also worked to disrupt the massive botnets that control compromised routers in lockstep. The actions to date are little more than whack-a-mole exercises as the operators simply replace their botnets with new ones.

Proxy networks: The go-to tool

β€œRussian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks,” the Cybersecurity and Infrastructure Security Agency said Monday. The hacking groups are tracked under various names, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. The advisory was co-issued by governments from around the world, including Australia, Denmark, New Zealand, and the UK.

Read full article

Comments

Β© Getty Images | BernardaSv

US cybersecurity agency CISA had to build its incident playbook during the incident, agency reveals

10 July 2026 at 21:01
Independent cybersecurity journalist Brian Krebs reported in May that a security researcher with cyber firm GitGuardian alerted him to reams of exposed passwords stored in a publicly accessible GitHub repository, which an employee of a CISA contractor had uploaded.

This Week in Security: Escaping Linux VMs, Vulnerable Solar, Confusing AI (Again), and Confusing NPM Malware

10 July 2026 at 10:00

The Januscape vulnerability allows a user in a guest VM managed by the Linux Kernel Virtual Machine (KVM) to corrupt memory in the host system and break out of isolation.

KVM virtualization is used by major hosting platforms like Amazon AWS, Google GCP, Digital Ocean, and many more. All of the shared hosting platforms count on virtualization to isolate untrusted guest systems from the physical hardware and each other; being able to corrupt memory for all guests or break isolation presents a major threat.

The bug report says the error has been present for 16 years, which is nearly the entire lifetime of the KVM subsystem in Linux. Fixes are available in mainline, and major hosting providers who count on KVM are likely already updating.

Vulnerabilities In Balcony Solar

Micro solar, or β€œbalcony solar”, installs have been gaining traction in Europe as a way to offset rising electrical costs by connecting solar and battery systems to a house or apartment power system.

Vulnerabilities have been found in the popular Hoymiles micro-inverter, which uses a proprietary RF radio protocol to manage the devices. Unfortunately, it looks like this protocol has no encryption or authentication beyond validating the serial number, and the serial number is also available over a wireless probe command.

Armed with a Nordic nRF radio researchers were able to discover nearby inverters in the wild and collect the serial numbers, though of course they stopped short of issuing commands to random users.

The wireless management control allows controlling the device power and output levels, as well as setting a lockout PIN, which the researchers suspect could be used to disable devices and lock the legitimate owners out completely.

There are an estimated 500,000 units in use, and currently the only known mitigation is to unplug the device entirely and disconnect the solar panels, though the team suggests that setting an anti-theft PIN may also help – or at least prevent an unknown PIN being set.

Be sure to check out the link for an in-depth analysis of the protocol and the surprising lack of protection.

OpenSSH 10.4

OpenSSH 10.4 is out, bringing a handful of security fixes and new features.

The most interesting security fixes appear to be to file handling in the sftp and scpΒ file transfer tools, a malicious remote server could cause the files to be downloaded to the wrong directories. Besides those, the security fixes seem relatively calm, making behavior more consistent when forwarding and tunneling options were in conflict, mitigating a potential denial of service, and cleaning up other behavior.

OpenSSH 10.4 introduces some experimental support for additional post-quantum encryption standards, but beyond that seems to be a normal update.

Tenda Routers (may) Have Backdoor

According to CVE-2026-11405, Tenda brand routers may have a deliberate backdoor in the web interface.

The vulnerability report claims that the httpd binary contains a fallback to a plaintext, hardcoded password that allows anything on the internal network to bypass authentication and reconfigure the router. This seems entirely plausible, based on issues found in other router firmwares, however additional reports raise doubts about the pervasiveness of the backdoor, or if it exists in all firmware versions.

If you have a Tenda brand router and are so inclined, now might be a great time to investigate OpenWRT or other alternate, updated firmware, but there’s probably not a reason to panic just yet.

Tricking the GitHub Agent With Prompt Injection

Can we go a week without discussing prompt injection in AI agents? Apparently the answer is no.

Noma Labs reveals how they were able to use prompt injection against the GitHub support agent to reveal private repositories of an organization. Leveraging the GitHub Agentic Workflows that link workflows with AI agents, Noma Labs were able to file an issue in a public repository that exposed private repositories in the same organization.

The attack appears to be as simple as filing an issue in the public repo, and requesting the contents of files in both the public and private repo, which the agent happily provided. Not only did the AI agent provide the file content of private repos, but it put it in a public issue in the public repository!

Noma Labs says in the writeup that GitHub had instituted guardrails to prevent an agent from accessing private repositories, but simply including the request to β€œadditionally” perform other tasks was sufficient to bypass. This makes GitHub the latest in a seemingly endless chain of AI agents happily helping bypass corporate security, and it doesn’t seem like a trend that will slow down for a while.

Windows Device Identifier Catches Ransomware Operator

Windows installs contain a globally unique identifier generated during the initial install, which is used to track device behavior across Microsoft platforms. Toms Hardware reports that during an investigation of the β€œScattered Spider” ransomware group, Microsoft provided records tracking the GDID of one of the ransomware operators, allowing the identification and arrest of one of the groups members.

Scattered Spider has been responsible for millions of dollars in ransomware attacks globally, including high-profile ransomware attacks against major Las Vegas resorts, Qantas airlines, Visa, and hundreds of other companies.

Court documents reveal that following the arrest of one of the suspected members of the group, the Windows global ID was used to link other behavior across Azure, video games, and other telemetry.

CISA reviews lessons learned

Mentioned here in May, the US government cybersecurity agency (CISA) suffered a disclosure of authentication tokens, cloud infrastructure, and plaintext passwords via a public GitHub repository named β€œPrivate-CISA” and operated by a contractor.

CISA has published the results of their internal review. Unsurprisingly, as a large government agency, CISA essentially followed the playbook for dealing with incidents: identify the most critical issues and disable the access of the contractor who exposed credentials, determine the full scope of disclosed data, and terminate accounts, change passwords, and expire authentication tokens which were exposed.

More NPM malware packages

Opensource Malware reports on additional infostealer malware uploaded to the NPM repository. Like most NPM-based malware, these packages rely on the install script mechanism to trigger arbitrary commands, firing immediately during package install with no additional interaction.

All of the malware packages mimic existing popular packages and depend on user typos or confusion to get selected. Once triggered, the malware collects a machine fingerprint, git user information, GitHub account information, SSH account information, and corporate identifiers. The packages are largely nonfunctional – the code in the package itself is irrelevant, once a victim triggers the install the malware payload is fired.

All of the packages were uploaded by the same source, tracked to the owner of a cybersecurity company. It is unclear if this is a misguided attempt to generate leads or hype, or if this is a research project gone wrong, but the payload of the malicious packages has been developed and tuned over time. For a company trying to build a reputation or trust, this is surely the wrong way to do it.

Residential Proxy Risks: Understanding Google’s Latest Action Against 2 Million Strong NetNut

3 July 2026 at 08:00

Google announced that it helped take down NetNut, a 2 million strong malicious residential proxy network. The incident highlights the growing risks posed by residential proxy networks that quietly conscript consumer devices into services used by cybercriminals and nation-state actors alike.

The post Residential Proxy Risks: Understanding Google’s Latest Action Against 2 Million Strong NetNut appeared first on The Security Ledger with Paul F. Roberts.

FLOSS Weekly Episode 874: Really, We Do PDFs

8 July 2026 at 14:30

This week Jonathan chats with Andrea Gallo about RISC-V! What does it mean for RISC-V to be an Open ISA? Where is RISC-V popping up, and what’s the new frontier? Watch to find out!

Did you know you can watch the live recording of the show right on our YouTube Channel? Have someone you’d like us to interview? Let us know, or have the guest contact us! Take a look at the schedule here.

Direct Download in DRM-free MP3.

If you’d rather read along, here’s the transcript for this week’s episode.

Places to follow the FLOSS Weekly Podcast:


Theme music: β€œNewer Wave” Kevin MacLeod (incompetech.com)

Licensed under Creative Commons: By Attribution 4.0 License

CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws

8 July 2026 at 06:45

Two newly disclosed critical vulnerabilities in Adobe ColdFusion and Langflow join two Joomla extension flaws in CISA's Known Exploited Vulnerabilities catalog, with federal agencies given until July 10 to patch.

The post CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws appeared first on SecurityWeek.

Ripple Joins Open USD Stablecoin Consortium Backed by Visa and Mastercard

3 July 2026 at 01:05

For readers tracking where the market is actually changing, this is the part that matters. Ripple Joins Open USD Stablecoin Consortium Backed by Visa and Mastercard gives Bitcoinist readers a clean angle on Ripple at a point where the market is trying to separate durable signals from short-lived noise.

According to the source material reviewed for this report, the story turns on a few concrete details rather than vague sentiment. That matters because crypto headlines can move quickly, but the pieces that tend to last are the ones backed by filings, official releases, data dashboards, or protocol-level records.

TL;DR

  • Ripple joined the Open USD (OUSD) stablecoin consortium.
  • The consortium includes traditional financial players like Visa, Mastercard, and BlackRock.
  • The group's stablecoin product (OUSD) does not run directly on the XRP Ledger, creating questions about the direct impact on XRP.

What Changed

The immediate relevance is that this development fits into one of the market’s main themes for the day: institutional positioning, network usage, regulatory pressure, protocol development, or asset-specific rotation. In this case, the key topic is Ripple, which is why it deserves a dedicated read rather than being buried inside a broader market recap.

For traders, the useful part is not simply that the headline exists. It is the way the facts line up with the current market backdrop. When official sources, market data, or protocol records show a fresh shift, readers get a better sense of whether the move is just a one-day reaction or part of something more structural.

Why It Stands Out

The core source for this story is ripple.com with supporting data from ripple.com. That source trail is important because the final article should not rely on discovery-only media links or second-hand summaries.

Ripple joined the Open USD (OUSD) stablecoin consortium.

The consortium includes traditional financial players like Visa, Mastercard, and BlackRock.

The group's stablecoin product (OUSD) does not run directly on the XRP Ledger, creating questions about the direct impact on XRP.

The numerical claims in the pack were tied back to specific source material before writing. '140 companies' sourced from Open Standard OUSD consortium official founding release; 'June 30, 2026' sourced from Open USD stablecoin consortium launch announcement date

What Comes Next

The caution is just as important as the headline. Avoid stating XRP is replaced by OUSD; they are complementary products.

That means the cleaner read is to treat this as a confirmed development with a defined scope, not as proof of a guaranteed price move or a sweeping market shift. In crypto, the difference matters. A verified data point can strengthen a thesis, but it does not remove execution risk, liquidity risk, regulatory uncertainty, or the possibility that traders fade the initial reaction.

For now, the story gives the market another piece of evidence to weigh. If follow-up filings, dashboard updates, protocol records, or official statements confirm further momentum, the angle can develop into something larger. If not, it still stands as a useful snapshot of where activity is concentrating today.

This report is based on information from ripple.com and ripple.com.

This article was written by the News Desk and edited by Samuel Rae.

Source: Ripple

Visa, Mastercard, And Over 140 Companies Launch Stablecoin Open USD

30 June 2026 at 13:27

Bitcoin Magazine

Visa, Mastercard, And Over 140 Companies Launch Stablecoin Open USD

A coalition of more than 140 companies β€” among them Visa, Stripe, Mastercard, BlackRock, and Coinbase β€” announced today the formation of Open Standard and the launch of Open USD (OUSD), a new dollar-pegged stablecoin built to redistribute the economics of the $300 billion stablecoin market.

The project is led by Zach Abrams, co-founder of Bridge, the stablecoin infrastructure firm that Stripe acquired in 2024.Β 

β€œExisting stablecoins have great strengths,” Abrams said in a statement, β€œBut to use them at scale, businesses need something that’s open, low-cost, high-throughput, broadly accessible, and aligned to their interests.”

The announcement sent Circle shares down as much as 15% Tuesday, a sign of how directly Open USD targets the USDC issuer’s business model.

The core proposition of Open USD is straightforward: no minting fees, no redemption fees, no volume limits β€” and most of the interest generated by the stablecoin’s reserves goes to the companies using it, minus a management fee retained by Open Standard.

That reserve income is what makes Circle and Tether profitable. Both issuers park stablecoin backing in short-term U.S. Treasuries and keep the yield themselves. Circle’s USDC carries a market cap of roughly $73 billion; Tether’s USDT sits at around $145 billion. Open USD proposes to share that yield with its distribution network instead.

Governance follows the same logic. Rather than a single issuer calling the shots, Open Standard will be managed by an independent organization with decision-making shared among partner companies.

Who is backing Open USD

The partner list spans nearly every corner of finance. Payment networks include Visa, Mastercard, American Express, and Discover. Banks include BNY, Standard Chartered, DBS, and U.S. Bank. On the technology side: Google, Shopify, and IBM. Crypto firms include Coinbase, Ripple, MetaMask, Aave, Bybit, OKX, Galaxy, Fireblocks, and Anchorage Digital.

β€œToday, we announced Visa is joining Open Standard alongside Stripe, Coinbase, Mastercard, American Express, BlackRock, U.S. Bank, BBVA, Standard Chartered and 100-plus initial partners with the mission of issuing Open USD,” Visa’s head of crypto, Cuy Sheffield, wrote on X.

Open USD is expected to go live later in 2026 on Solana, Stellar, Base, and Polygon. Tempo CEO Matt Huang confirmed OUSD will be natively issued on its network from day one, with support for payments, liquidity, exchanges, and DeFi.

Open Standard is not the first consortium to try this model. Paxos leads the Global Dollar Network (USDG) β€” backed by Robinhood, Kraken, and Galaxy Digital β€” on the same premise: share reserve income, grow adoption.Β 

In Europe, 37 banks and payment providers have organized around Qivalis, a euro-denominated stablecoin, as institutions push back against U.S. dollar dominance in the digital asset space.

The timing is not accidental. Stablecoins have migrated out of crypto trading and into cross-border payments, merchant settlements, and corporate treasury operations.Β 

Citi projects the market will reach $4 trillion by 2030.Β 

This post Visa, Mastercard, And Over 140 Companies Launch Stablecoin Open USD first appeared on Bitcoin Magazine and is written by Micah Zimmerman.

❌
❌