The new XRP card is a margin loan with a Visa logo
Visa Stablecoin Treasury Engine Pushes Settlement Deeper Into Institutional Finance
Visa has launched a stablecoin treasury engine for financial institutions, marking another step in the shift from crypto payment experiments to real institutional settlement infrastructure.
The service is designed to let financial institutions settle merchant network balances using stablecoins such as USDC and EURC. That matters because Visa is not pitching this as a retail crypto wallet or a speculative trading product. It is a treasury and settlement tool for institutions already operating inside the payments system.
The difference is important.
Stablecoins have proven useful in crypto markets for years, but the more interesting development is their movement into traditional financial plumbing. If banks, payment firms, and merchants can settle balances using stablecoins behind the scenes, blockchain-based dollars and euros become less of a crypto-native novelty and more of an operational settlement layer.
Visa has been testing stablecoin settlement for years, but the market pays closer attention when those tests begin moving toward operational products.
The reason is simple: Visa sits at the centre of global payments. When it experiments with stablecoins, it does not need to convince the world that payments exist. It is trying to make settlement faster, more flexible, and more programmable inside an existing financial network.
That is very different from a startup trying to replace the card system.
A stablecoin treasury engine can help financial institutions manage balances in digital dollars or euros while still operating within a familiar settlement environment. For institutions, that can make stablecoin adoption feel less like a crypto bet and more like an infrastructure upgrade.
It also speaks to one of stablecoins’ strongest use cases: settlement speed.
Traditional payment settlement can involve multiple intermediaries, cut-off times, and currency-specific banking rails. Stablecoins can move continuously and settle directly on blockchain networks, depending on the setup.
Visa’s role is to make that capability usable by institutions that cannot simply plug into crypto rails casually.
Most retail users think about stablecoins as trading dollars.
Institutions think about them differently. They care about settlement, liquidity, reconciliation, counterparty exposure, balance management, compliance, and how money moves between entities.
That is why the word “treasury” matters here.
If stablecoins become part of treasury operations, they can sit behind payment flows without end users necessarily realizing a blockchain is involved. A merchant may care that settlement is faster or cheaper. It may not care whether the underlying balance moved through USDC, EURC, or a traditional banking transfer.
This is how crypto infrastructure often becomes mainstream: not by demanding attention, but by solving a back-office problem.
Visa’s stablecoin treasury engine points in that direction. It gives institutions a controlled way to use stablecoins where they make operational sense, while still keeping the product inside a professional financial framework.
The inclusion of both USDC and EURC is notable because stablecoin settlement is becoming more than a dollar-only story.
Dollar stablecoins dominate the market, but euro stablecoins are increasingly important for European payments, MiCA-era compliance, and multi-currency settlement use cases. If institutions want to use stablecoins for treasury management, they will eventually need access to more than one currency.
That is one reason Visa’s move matters.
Multi-stablecoin infrastructure can support more flexible settlement between regions, merchants, and financial institutions. It can also reduce the need for every transaction to route through dollar liquidity if another currency is more appropriate.
The stablecoin market is still heavily dollar-based, but institutional settlement may push more demand toward regulated non-dollar tokens over time.
That could become especially relevant in Europe, where MiCA has created a clearer framework for stablecoin issuers and service providers.
The product should be framed carefully.
Visa is not launching a consumer-facing app that lets everyday users speculate on stablecoins. This is an institutional treasury framework. It is designed for financial institutions and settlement operations, not retail trading.
That makes it less flashy, but more important.
The biggest stablecoin adoption may not come from people choosing to hold stablecoins in a wallet. It may come from stablecoins being used quietly inside payment networks, merchant settlement systems, institutional treasury desks, and cross-border liquidity management.
That is where Visa has influence.
For crypto markets, the signal is clear: stablecoins are moving deeper into mainstream financial infrastructure. The sector has spent years proving that tokenized dollars can move quickly on-chain. The next phase is about whether large financial networks can safely use that speed inside regulated systems.
Visa’s stablecoin treasury engine is another step in that direction.
This article is based on Visa newsroom materials.
This article was written by the News Desk and edited by Samuel Rae.
This report is based on information released in official primary source disclosures at primary source documentation.
In this episode of the podcast, host Paul Roberts interviews Nishawn Smagh of the firm GreyNoise Intelligence about the findings of their State of the Edge report, an analysis of GreyNoise data on risks stemming from compromised edge devices such as broadband routers, VPN gateways, smart home devices and more. Shawn and Paul talk about how attackers are turning edge devices into their favorite entry point, and strategies for organizations to counter the growing risk of compromised edge devices.
The post Edge Devices Are Your Cyber Underbelly. Here’s Why. appeared first on The Security Ledger with Paul F. Roberts.

Why Every Cybersecurity Professional Should Read the Original Records By Gary S. Miliefsky Publisher, Cyber Defense Magazine For more than a decade, cybersecurity professionals have watched researchers at DEF CON’s...
The post Hacking US Elections: The First Tranche of Declassified Election Integrity Documents appeared first on Cyber Defense Magazine.

© The Associated Press
Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days.
The post CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities appeared first on SecurityWeek.


Many older hackers will have at some point gotten rid of an old piece of hardware that they later ended up regretting. All those ISA cards were next to useless back in 2006, but now their relative rarity plus the popularity of retrocomputing makes them sought-after. But if it’s a sound card you’re after then never fear! [Schlae] has got you covered, with the Beavis Ultrasound. It may have a name reminiscent of a ’90s cartoon series, but it’s a clone of the Gravis Ultrasound from back in the day.
There is of course a snag, to build one you need an AMD AM78C201. Assuming you’ve found one in a surplus supplier though, the rest of the card is analogue, some glue logic, and a ROM for samples. There is also a GAL for driving the IDE CD-ROM interface, from the days when sound cards came with such things.
New ISA cards are cropping up here from time to time, such as this very handy storage and network card.
The federal government is warning users of home and small office routers to secure their devices as Russia state hackers continue to mass-compromise them for use in obscuring nefarious actions against sensitive organizations in the public and private sectors.
Both the Russian and Chinese governments have been compromising routers for years, sometimes in prolonged tugs-of-war to wrest control of devices the other has already commandeered. The US government has occasionally issued covert commands and taken other steps to disinfect routers. Google and other companies have also worked to disrupt the massive botnets that control compromised routers in lockstep. The actions to date are little more than whack-a-mole exercises as the operators simply replace their botnets with new ones.
“Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks,” the Cybersecurity and Infrastructure Security Agency said Monday. The hacking groups are tracked under various names, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. The advisory was co-issued by governments from around the world, including Australia, Denmark, New Zealand, and the UK.


© Getty Images | BernardaSv

The Januscape vulnerability allows a user in a guest VM managed by the Linux Kernel Virtual Machine (KVM) to corrupt memory in the host system and break out of isolation.
KVM virtualization is used by major hosting platforms like Amazon AWS, Google GCP, Digital Ocean, and many more. All of the shared hosting platforms count on virtualization to isolate untrusted guest systems from the physical hardware and each other; being able to corrupt memory for all guests or break isolation presents a major threat.
The bug report says the error has been present for 16 years, which is nearly the entire lifetime of the KVM subsystem in Linux. Fixes are available in mainline, and major hosting providers who count on KVM are likely already updating.
Micro solar, or “balcony solar”, installs have been gaining traction in Europe as a way to offset rising electrical costs by connecting solar and battery systems to a house or apartment power system.
Vulnerabilities have been found in the popular Hoymiles micro-inverter, which uses a proprietary RF radio protocol to manage the devices. Unfortunately, it looks like this protocol has no encryption or authentication beyond validating the serial number, and the serial number is also available over a wireless probe command.
Armed with a Nordic nRF radio researchers were able to discover nearby inverters in the wild and collect the serial numbers, though of course they stopped short of issuing commands to random users.
The wireless management control allows controlling the device power and output levels, as well as setting a lockout PIN, which the researchers suspect could be used to disable devices and lock the legitimate owners out completely.
There are an estimated 500,000 units in use, and currently the only known mitigation is to unplug the device entirely and disconnect the solar panels, though the team suggests that setting an anti-theft PIN may also help – or at least prevent an unknown PIN being set.
Be sure to check out the link for an in-depth analysis of the protocol and the surprising lack of protection.
OpenSSH 10.4 is out, bringing a handful of security fixes and new features.
The most interesting security fixes appear to be to file handling in the sftp and scp file transfer tools, a malicious remote server could cause the files to be downloaded to the wrong directories. Besides those, the security fixes seem relatively calm, making behavior more consistent when forwarding and tunneling options were in conflict, mitigating a potential denial of service, and cleaning up other behavior.
OpenSSH 10.4 introduces some experimental support for additional post-quantum encryption standards, but beyond that seems to be a normal update.
According to CVE-2026-11405, Tenda brand routers may have a deliberate backdoor in the web interface.
The vulnerability report claims that the httpd binary contains a fallback to a plaintext, hardcoded password that allows anything on the internal network to bypass authentication and reconfigure the router. This seems entirely plausible, based on issues found in other router firmwares, however additional reports raise doubts about the pervasiveness of the backdoor, or if it exists in all firmware versions.
If you have a Tenda brand router and are so inclined, now might be a great time to investigate OpenWRT or other alternate, updated firmware, but there’s probably not a reason to panic just yet.
Can we go a week without discussing prompt injection in AI agents? Apparently the answer is no.
Noma Labs reveals how they were able to use prompt injection against the GitHub support agent to reveal private repositories of an organization. Leveraging the GitHub Agentic Workflows that link workflows with AI agents, Noma Labs were able to file an issue in a public repository that exposed private repositories in the same organization.
The attack appears to be as simple as filing an issue in the public repo, and requesting the contents of files in both the public and private repo, which the agent happily provided. Not only did the AI agent provide the file content of private repos, but it put it in a public issue in the public repository!
Noma Labs says in the writeup that GitHub had instituted guardrails to prevent an agent from accessing private repositories, but simply including the request to “additionally” perform other tasks was sufficient to bypass. This makes GitHub the latest in a seemingly endless chain of AI agents happily helping bypass corporate security, and it doesn’t seem like a trend that will slow down for a while.
Windows installs contain a globally unique identifier generated during the initial install, which is used to track device behavior across Microsoft platforms. Toms Hardware reports that during an investigation of the “Scattered Spider” ransomware group, Microsoft provided records tracking the GDID of one of the ransomware operators, allowing the identification and arrest of one of the groups members.
Scattered Spider has been responsible for millions of dollars in ransomware attacks globally, including high-profile ransomware attacks against major Las Vegas resorts, Qantas airlines, Visa, and hundreds of other companies.
Court documents reveal that following the arrest of one of the suspected members of the group, the Windows global ID was used to link other behavior across Azure, video games, and other telemetry.
Mentioned here in May, the US government cybersecurity agency (CISA) suffered a disclosure of authentication tokens, cloud infrastructure, and plaintext passwords via a public GitHub repository named “Private-CISA” and operated by a contractor.
CISA has published the results of their internal review. Unsurprisingly, as a large government agency, CISA essentially followed the playbook for dealing with incidents: identify the most critical issues and disable the access of the contractor who exposed credentials, determine the full scope of disclosed data, and terminate accounts, change passwords, and expire authentication tokens which were exposed.
Opensource Malware reports on additional infostealer malware uploaded to the NPM repository. Like most NPM-based malware, these packages rely on the install script mechanism to trigger arbitrary commands, firing immediately during package install with no additional interaction.
All of the malware packages mimic existing popular packages and depend on user typos or confusion to get selected. Once triggered, the malware collects a machine fingerprint, git user information, GitHub account information, SSH account information, and corporate identifiers. The packages are largely nonfunctional – the code in the package itself is irrelevant, once a victim triggers the install the malware payload is fired.
All of the packages were uploaded by the same source, tracked to the owner of a cybersecurity company. It is unclear if this is a misguided attempt to generate leads or hype, or if this is a research project gone wrong, but the payload of the malicious packages has been developed and tuned over time. For a company trying to build a reputation or trust, this is surely the wrong way to do it.
Google announced that it helped take down NetNut, a 2 million strong malicious residential proxy network. The incident highlights the growing risks posed by residential proxy networks that quietly conscript consumer devices into services used by cybercriminals and nation-state actors alike.
The post Residential Proxy Risks: Understanding Google’s Latest Action Against 2 Million Strong NetNut appeared first on The Security Ledger with Paul F. Roberts.

This week Jonathan chats with Andrea Gallo about RISC-V! What does it mean for RISC-V to be an Open ISA? Where is RISC-V popping up, and what’s the new frontier? Watch to find out!
Did you know you can watch the live recording of the show right on our YouTube Channel? Have someone you’d like us to interview? Let us know, or have the guest contact us! Take a look at the schedule here.
Direct Download in DRM-free MP3.
If you’d rather read along, here’s the transcript for this week’s episode.
Theme music: “Newer Wave” Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
Two newly disclosed critical vulnerabilities in Adobe ColdFusion and Langflow join two Joomla extension flaws in CISA's Known Exploited Vulnerabilities catalog, with federal agencies given until July 10 to patch.
The post CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws appeared first on SecurityWeek.
Apple is restoring card payments for users in India after updating its systems to comply with RBI tokenization rules.
The post Apple Reopens Card Payments in India After Four-Year Halt appeared first on TechRepublic.
Apple is restoring card payments for users in India after updating its systems to comply with RBI tokenization rules.
The post Apple Reopens Card Payments in India After Four-Year Halt appeared first on TechRepublic.
For readers tracking where the market is actually changing, this is the part that matters. Ripple Joins Open USD Stablecoin Consortium Backed by Visa and Mastercard gives Bitcoinist readers a clean angle on Ripple at a point where the market is trying to separate durable signals from short-lived noise.
According to the source material reviewed for this report, the story turns on a few concrete details rather than vague sentiment. That matters because crypto headlines can move quickly, but the pieces that tend to last are the ones backed by filings, official releases, data dashboards, or protocol-level records.
TL;DR
The immediate relevance is that this development fits into one of the market’s main themes for the day: institutional positioning, network usage, regulatory pressure, protocol development, or asset-specific rotation. In this case, the key topic is Ripple, which is why it deserves a dedicated read rather than being buried inside a broader market recap.
For traders, the useful part is not simply that the headline exists. It is the way the facts line up with the current market backdrop. When official sources, market data, or protocol records show a fresh shift, readers get a better sense of whether the move is just a one-day reaction or part of something more structural.
The core source for this story is ripple.com with supporting data from ripple.com. That source trail is important because the final article should not rely on discovery-only media links or second-hand summaries.
Ripple joined the Open USD (OUSD) stablecoin consortium.
The consortium includes traditional financial players like Visa, Mastercard, and BlackRock.
The group's stablecoin product (OUSD) does not run directly on the XRP Ledger, creating questions about the direct impact on XRP.
The numerical claims in the pack were tied back to specific source material before writing. '140 companies' sourced from Open Standard OUSD consortium official founding release; 'June 30, 2026' sourced from Open USD stablecoin consortium launch announcement date
The caution is just as important as the headline. Avoid stating XRP is replaced by OUSD; they are complementary products.
That means the cleaner read is to treat this as a confirmed development with a defined scope, not as proof of a guaranteed price move or a sweeping market shift. In crypto, the difference matters. A verified data point can strengthen a thesis, but it does not remove execution risk, liquidity risk, regulatory uncertainty, or the possibility that traders fade the initial reaction.
For now, the story gives the market another piece of evidence to weigh. If follow-up filings, dashboard updates, protocol records, or official statements confirm further momentum, the angle can develop into something larger. If not, it still stands as a useful snapshot of where activity is concentrating today.
This report is based on information from ripple.com and ripple.com.
This article was written by the News Desk and edited by Samuel Rae.
Source: Ripple
