The most famous brand in physical security got pwned by ShinyHunters Hopefully the company secures houses better than it locks down SaaS systems
US bank places trust in ransomware crew that promised to delete its data History suggests this was not wise
Charities remain locked out of CAF Bank online accounts A week into shutdown, 14,000 customers still have no restoration date and some are struggling to pay staff
Scotland's university procurement center confirms cybercrooks broke in APUC investigating after criminals claim historical data theft
Anthropic’s Claude escaped test sandbox to attack three organizations Wrote and published malware during tests, which is apparently OK because leaky test environments were the real problem
Jailed Flock vandal wipes out three cameras, racks up thousands in damages A lesson for aspiring vandals: Take out all the cameras, not just the ones that flout your ideals
Amazon links four poisoned npm packages to one North Korean crew Researchers say Sapphire Sleet socially engineered maintainers before publishing malicious updates through trusted accounts
Russian spies take their half-click email attack from Zimbra to Outlook Opening a booby-trapped message unleashes a browser implant that can survive password changes and device rebuilds
Headteacher had the most guessable username-password combo you could imagine Schools often don't prioritize or understand cybersecurity
Excuses like 'AI did it' don't exist in the eyes of the law If your AI goes rogue, better have a good lawyer
Closed models refuse to help researcher swat Linux bug "I'm sorry, Dave. I'm afraid I can't do that" is an effective sales pitch for open source
Word worm crawls into Copilot, spreads chaos Researcher says months of coordination with Microsoft have yet to produce a robust mitigation
Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems More than 30 facilities disrupted in 'coordinated cyberattack,' though officials have yet to name a culprit
America bans imported robots due to supply chain and security risks Docs point to China’s Unitree as prime example of the foreign clanker threat
MCP gets an enterprise makeover Now happier running in a conventional K8s environment, with `an easier-to-live-with lifecycle
Microsoft and Wiz mind-meld agents catch more than 90% of bugs Secret to their success: Using the right model for the right security job
DEF CON bans Meta-style 'pervert glasses' More organizers prohibit camera-equipped specs, even with prescription lenses
AI-found bugs aren't proving any easier to exploit despite the hype VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage
Bank for charities pulls online services over security fears Customer funds safe, but 14,000 organizations may have to phone in time-sensitive payments
Uncle Sam needs you to fight for 6G leadership and security, lest Beijing get there first Washington rallies allies to shape next-generation networks after spending 18 months rattling them
Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock Unauthenticated command injection scores perfect 10 and may expose managed Edge devices
Microsoft's solution to AI security: more AI and more acronyms MDASH stuffed with MAI-Cyber-1-Flash and a side of GPT-5.4
Tech giants link hands to praise open AI models after OpenAI - Hugging Face attack The Open Security AI Alliance says the Hugging Face/OpenAI mess proves frontier labs can't be trusted to properly secure sensitive systems
Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update One bug disabled the security service on restart, another blocked installation on hardened RHEL systems
Google goes it alone with a new cybercrime crew taxonomy So much for Microsoft and CrowdStrike’s plans for consistent names across the industry
Pope's official prayer app commits cardinal sin, leaks 700K+ users' info (Security) hole-ier than thou
Europol flags 4,340 'horrific' URLs linked to The Com Stop the spread (of online recruiting and propaganda)
Uncle Sam tells overseas cybercrooks their visas are canceled Policy targets online scammers, sextortionists, and potentially their immediate families
OpenAI-Hugging Face attack doesn't mean agents are evil – unless you tell them to be Attack models gonna attack
Researchers replace downloaded macOS apps with evil twins, Apple shrugs Gatekeeper has one job and it's not doing it for some software
Millions of California-bought cars can be hijacked via Bluetooth Aftermarket dealer-installed KARR/SWDS security systems all use the same secure key, say UCSD researchers
Oracle drops 1,449 security patches like it's the new normal Experts say the era of AI bug hunting is here, so defenders will simply have to adapt to busier workloads
Iran-linked crews are probing more flavors of US industrial kit CISA widens alert beyond Rockwell controllers as intruders target internet-facing devices across critical infrastructure
One ChatGPT link could smuggle a rogue AI agent into your company Researchers say OpenAI flaw let phishing bait create an autonomous corporate mole armed with employee access
Swiss train maker tells ransomware crooks to get off at the next stop Stadler refuses $12.3M demand after thieves swipe technical data through supplier platform
Talking smack about a doctor got him access to private medical files Who needs a working security badge when you know how to talk your way into the records room?
OpenAI scored an own goal with Hugging Face attack, showing how open Chinese models are winning Closed models with guardrails can still cause harm, but may also not be able to fix problems they caused
Linux kernel team publishes 432 CVEs in two days Sunday-to-Monday onslaught fuels speculation over AI-assisted bug reports
Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits Move over Flipper. There's a new Dophin X in town
Greedy ransomware crews return for seconds after victims cough up first extortion payments Some never saw their files again either, infosec biz Proofpoint finds
Council worker spared prison after four-day data-snooping spree Herefordshire employee handed suspended sentence for breach of Computer Misuse Act
OpenAI admits it was the source of the agent swarm that attacked Hugging Face Sandboxed experiment found itself a zero day, escaped onto the open internet and validated scary predictions about rogue agents
Kratos phishing-as-a-service kit loses its battle with international law enforcement Alleged developer arrested in Indonesia after more than 200 servers slain
AI music platform Suno hits bum note as 55M users exposed in data breach, claims infosec expert Have I Been Pwned confirms scale for first time
Intel fortifies Foundry with an actual customer: Fortinet Firewall maker looks to safeguard its custom ASIC production with homegrown silicon
OVH reveals semi-secret plan to fix critical Januscape hypervisor bug with mass reboots – and an Australian crash-test dummy French cloud backported a patch into Debian and didn’t seek customer consent, despite chance of downtime
Attackers pummel critical WordPress vuln to create all sorts of mischief Plus dozens of PoCs in the public domain
Scammers impersonate FBI on social media, prey on crime victims IC3 says any account claiming to represent it is fake
Malicious cloud customers can bring down the power grid Datacenters tax utilities normally, so just imagine what they could do if workloads were designed to destroy
Frontier LLMs couldn't help Hugging Face fight off evil agents Chinese open-weight model GLM 5.2 happily obliged
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign Malware hides commands in appointments set for 2050 and uses Redmond's own cloud to phone home
Infosec expert: Paidwork users' data pwned after 23M-record database dumped online HIBP claims leaked info includes bank account numbers, payout histories, and personal details
Chinese President Xi Jinping wants emergency response systems to keep AI in check PLUS: Korean e-tailer Coupang's warehouse burns and burns; Australian Uni expels VMware; India's first private rocket flies first time; And more!
Connecting AI agents to outside services explodes the risk radius Connect all the things and watch what happens
AI spam filters are getting suckered by old-school text salting Turns out decades-old email tricks still work against some LLM-powered email filters
Attackers target critical FortiSandbox flaws as CISA issues patch order Command injection vulns land on exploited list after researchers spot abuse attempts
Ransomware curdles production at Coca-Cola's Fairlife dairy biz No use crying over spilled milk when US plants can't bottle it in the first place
Google fixing Android lock screen bug that lets Gemini send SMS without a PIN A specific multi-touch gesture bypasses an authentication prompt, allowing anyone to send messages
South Korea making its own security-centric AI model Adapting existing local LLM project for security and sovereignty purposes and hopes to one day match Mythos
OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake' Data purges deemed an example of 'misaligned behavior' that upstart is working to avoid
Researcher poisons open-weight AI model for under $100 Models demand trust without offering verification
C'mon, just copy this text string and paste it into your macOS Terminal – it'll fix your computer, honest Newly documented stealer ClickLock comes for the more trusting Mac user with spot of social engineering
Brit Scattered Spider duo handed tickets to prison over Transport for London attack Sentencing bookends the biggest cybercrime conviction in UK history
Windows 10 refuses to die, and the security bill is coming due One in six machines still run the old OS as migration stalls and patch deadlines creep closer
Telegram shortlinks knocked offline over sanctioned VPN connection t.me borked for a day until platform proved it had no ties to service favored by cybercriminals