security The most famous brand in physical security got pwned by ShinyHunters Hopefully the company secures houses better than it locks down SaaS systems
SECURITY Anthropic and OpenAI are competing to see whose agents can go rogue harder Whoever wins, we lose
SECURITY Charities remain locked out of CAF Bank online accounts A week into shutdown, 14,000 customers still have no restoration date and some are struggling to pay staff
AI AND ML Anthropic’s Claude escaped test sandbox to attack three organizations Wrote and published malware during tests, which is apparently OK because leaky test environments were the real problem
Security Jailed Flock vandal wipes out three cameras, racks up thousands in damages A lesson for aspiring vandals: Take out all the cameras, not just the ones that flout your ideals
security Russian spies take their half-click email attack from Zimbra to Outlook Opening a booby-trapped message unleashes a browser implant that can survive password changes and device rebuilds
Security Headteacher had the most guessable username-password combo you could imagine Schools often don't prioritize or understand cybersecurity
LEGAL Excuses like 'AI did it' don't exist in the eyes of the law If your AI goes rogue, better have a good lawyer
AI and ML Closed models refuse to help researcher swat Linux bug "I'm sorry, Dave. I'm afraid I can't do that" is an effective sales pitch for open source
security Word worm crawls into Copilot, spreads chaos Researcher says months of coordination with Microsoft have yet to produce a robust mitigation
Security Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems More than 30 facilities disrupted in 'coordinated cyberattack,' though officials have yet to name a culprit
security America bans imported robots due to supply chain and security risks Docs point to China’s Unitree as prime example of the foreign clanker threat
AI and ML MCP gets an enterprise makeover Now happier running in a conventional K8s environment, with `an easier-to-live-with lifecycle
Security Microsoft and Wiz mind-meld agents catch more than 90% of bugs Secret to their success: Using the right model for the right security job
security DEF CON bans Meta-style 'pervert glasses' More organizers prohibit camera-equipped specs, even with prescription lenses
SECURITY AI-found bugs aren't proving any easier to exploit despite the hype VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage
SECURITY Bank for charities pulls online services over security fears Customer funds safe, but 14,000 organizations may have to phone in time-sensitive payments
NETWORKS Uncle Sam needs you to fight for 6G leadership and security, lest Beijing get there first Washington rallies allies to shape next-generation networks after spending 18 months rattling them
Security Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock Unauthenticated command injection scores perfect 10 and may expose managed Edge devices
Security Microsoft's solution to AI security: more AI and more acronyms MDASH stuffed with MAI-Cyber-1-Flash and a side of GPT-5.4
ai and ml Tech giants link hands to praise open AI models after OpenAI - Hugging Face attack The Open Security AI Alliance says the Hugging Face/OpenAI mess proves frontier labs can't be trusted to properly secure sensitive systems
PATCHES Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update One bug disabled the security service on restart, another blocked installation on hardened RHEL systems
Security Google goes it alone with a new cybercrime crew taxonomy So much for Microsoft and CrowdStrike’s plans for consistent names across the industry
Security Pope's official prayer app commits cardinal sin, leaks 700K+ users' info (Security) hole-ier than thou
Security Europol flags 4,340 'horrific' URLs linked to The Com Stop the spread (of online recruiting and propaganda)
Security Uncle Sam tells overseas cybercrooks their visas are canceled Policy targets online scammers, sextortionists, and potentially their immediate families
Security OpenAI-Hugging Face attack doesn't mean agents are evil – unless you tell them to be Attack models gonna attack
Security Researchers replace downloaded macOS apps with evil twins, Apple shrugs Gatekeeper has one job and it's not doing it for some software
security Millions of California-bought cars can be hijacked via Bluetooth Aftermarket dealer-installed KARR/SWDS security systems all use the same secure key, say UCSD researchers
Security Oracle drops 1,449 security patches like it's the new normal Experts say the era of AI bug hunting is here, so defenders will simply have to adapt to busier workloads
SECURITY Iran-linked crews are probing more flavors of US industrial kit CISA widens alert beyond Rockwell controllers as intruders target internet-facing devices across critical infrastructure
Security One ChatGPT link could smuggle a rogue AI agent into your company Researchers say OpenAI flaw let phishing bait create an autonomous corporate mole armed with employee access
Security Swiss train maker tells ransomware crooks to get off at the next stop Stadler refuses $12.3M demand after thieves swipe technical data through supplier platform
SECURITY Talking smack about a doctor got him access to private medical files Who needs a working security badge when you know how to talk your way into the records room?
AI and ML OpenAI scored an own goal with Hugging Face attack, showing how open Chinese models are winning Closed models with guardrails can still cause harm, but may also not be able to fix problems they caused
security Linux kernel team publishes 432 CVEs in two days Sunday-to-Monday onslaught fuels speculation over AI-assisted bug reports
Security Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits Move over Flipper. There's a new Dophin X in town
Security Greedy ransomware crews return for seconds after victims cough up first extortion payments Some never saw their files again either, infosec biz Proofpoint finds
SECURITY Council worker spared prison after four-day data-snooping spree Herefordshire employee handed suspended sentence for breach of Computer Misuse Act
AI AND ML OpenAI admits it was the source of the agent swarm that attacked Hugging Face Sandboxed experiment found itself a zero day, escaped onto the open internet and validated scary predictions about rogue agents
AI and ML AI's cheatin' heart will make you weep Trust but verify doesn't work when verification is difficult
Security Kratos phishing-as-a-service kit loses its battle with international law enforcement Alleged developer arrested in Indonesia after more than 200 servers slain
security AI music platform Suno hits bum note as 55M users exposed in data breach, claims infosec expert Have I Been Pwned confirms scale for first time
Security Intel fortifies Foundry with an actual customer: Fortinet Firewall maker looks to safeguard its custom ASIC production with homegrown silicon
virtualization OVH reveals semi-secret plan to fix critical Januscape hypervisor bug with mass reboots – and an Australian crash-test dummy French cloud backported a patch into Debian and didn’t seek customer consent, despite chance of downtime
security Attackers pummel critical WordPress vuln to create all sorts of mischief Plus dozens of PoCs in the public domain
security Scammers impersonate FBI on social media, prey on crime victims IC3 says any account claiming to represent it is fake
AI and ML Malicious cloud customers can bring down the power grid Datacenters tax utilities normally, so just imagine what they could do if workloads were designed to destroy
CYBER-CRIME Frontier LLMs couldn't help Hugging Face fight off evil agents Chinese open-weight model GLM 5.2 happily obliged
security Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign Malware hides commands in appointments set for 2050 and uses Redmond's own cloud to phone home
AI and ML Connecting AI agents to outside services explodes the risk radius Connect all the things and watch what happens
security AI spam filters are getting suckered by old-school text salting Turns out decades-old email tricks still work against some LLM-powered email filters
security Attackers target critical FortiSandbox flaws as CISA issues patch order Command injection vulns land on exploited list after researchers spot abuse attempts
Security Google fixing Android lock screen bug that lets Gemini send SMS without a PIN A specific multi-touch gesture bypasses an authentication prompt, allowing anyone to send messages
AI AND ML South Korea making its own security-centric AI model Adapting existing local LLM project for security and sovereignty purposes and hopes to one day match Mythos
AI and ML OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake' Data purges deemed an example of 'misaligned behavior' that upstart is working to avoid
AI and ML Researcher poisons open-weight AI model for under $100 Models demand trust without offering verification
cyber-crime C'mon, just copy this text string and paste it into your macOS Terminal – it'll fix your computer, honest Newly documented stealer ClickLock comes for the more trusting Mac user with spot of social engineering
Cyber-crime Brit Scattered Spider duo handed tickets to prison over Transport for London attack Sentencing bookends the biggest cybercrime conviction in UK history
OS PLATFORMS Windows 10 refuses to die, and the security bill is coming due One in six machines still run the old OS as migration stalls and patch deadlines creep closer
Security Telegram shortlinks knocked offline over sanctioned VPN connection t.me borked for a day until platform proved it had no ties to service favored by cybercriminals
SECURITY Law firm insisted on one password to rule them all Using the admin password, you could be anyone and see anything
cyber-crime Tech support scam caused massive data breach at Australian airline Qantas It’s possible to leak PII describing 5.7 million people without breaching privacy rules
Security Cyberattack threatens utterly critical infrastructure in Japan: KFC The Colonel stops taking online orders and may close stores after logistics partner’s systems go down
Security CISA sounds alarm over trio of exploited SharePoint flaws Three bugs are under active attack, and two more critical holes could add to the pain
os platforms Microsoft cancels Patch Tuesday for some Dell users over surprise shutdowns, overheating devices Mega hardware vendor reports problems - but Windows maker isn't yet naming affected models
Security LegacyHive: 'Bone-shattering' zero-day from Microsoft's serial tormentor not the haymaker that was promised Experts say it’s a useful post-compromise tool, for those with the brain cells required to put it together
security Patchpocalypse Now: Microsoft tops last month's record with 622 Patch Tuesday CVEs Remember when last month's 206 CVEs seemed eye-watering? Yeah, those were the days
Security Welsh Doxbin admin jailed for egging on swatters from behind a screen Callum Dare encouraged others to carry out dangerous hoaxes, made mini-movies from the footage
AI and ml Musk promises purge after Grok Build caught sending entire repos to the cloud Researcher confirms the uploads have stopped, but says xAI's privacy command was not what fixed them
RESEARCH 'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes Human did 10% of the job, AI did 90%
security Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websites Flaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide
Security EU and UK officially blame Russian spies for cyberattack on Poland's power grid Sweeping sanctions and condemnation follow op that could have left half a million without power in the depths of winter
Security World Cup grudge attackers may have scored Argentine FA access via year-old infostealer infection Footie fans? Overreacting? There's a first time for everything
Security Progress orders emergency ShareFile server shutdown over mystery security threat Vendor insists there's no evidence of unauthorized access, but it's asking customers to take one of the most drastic precautions available
security Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package Microsoft says GigaWiper combines at least 3 malware families into one modular tool
security Fashion mart Miinto unzips breach details, warns shoppers to watch for phisherfolk Copenhagen company ‘sorry’ after 'perpetrator' pops order management system
Security Scot NHS Trust probes email stuffup involving maternity patients' data NHS Forth Valley is the latest health board to bungle basic email data protection principles
Security Microsoft warns customers AI will mean busier Patch Tuesdays More patches mean more reasons to buy Redmond’s auto-patching tools
CYBER-CRIME An unnamed US county – perhaps in Ohio – paid $1M extortion demand to cybercriminals Leaked negotiations spill the tea
Security EU 'Chat Control' snoopfest returns after vote to kill it falls short Opponents won the count but missed the 360-seat threshold needed to stop the interim CSAM-scanning rule
security Microsoft closes book on Nightmare Eclipse's RoguePlanet zero-day Weeks after the exploit code dropped, Redmond has finally ships a fix for the Defender zero-day
Security Thief posed as Wi-Fi fixing hero, then stole priceless trophy If people think you are doing a legitimate job, you can get away with anything
Security Suspected Chinese snoops caught breaking into universities' Roundcube mailservers Proofpoint researcher tells The Reg: 'We estimate the total volume of targets would be a few dozen'
security GitHub Copilot: Sorry Dave, I can't do that harmful thing - unless you ask me in code More fun with AI jailbreaks, this time at the workflow level
Security Bug in top AI coding agents shows that Unix-era security headaches never really die 'GhostApproval' problem highlights human-in-the-loop fails
Security China tells devs to ditch Claude Code over 'backdoor code' fears National vulnerability database claims monitoring mechanism can forward Chinese users' data to remote servers
cyber-crime Windows is watching: Anti-piracy tool fingers Scattered Spider suspect Along with other telemetry, Windows GDID makes online activity more traceable
Security GitHub AI agent leaks private repos when asked nicely Per usual, there's no fix – or even any documentation – for GitLost
LEGAL Startup sues Palo Alto Networks' Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage
security Microsoft said exploitation was 'less likely' ... but CISA just added SharePoint RCE to KEV list
cyber-crime Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released
Security Huntress CEO says threat hunter used 'poor judgment' in alerting ransomware crim about law enforcement probe
security India’s central bank mandated use of .bank domains to enhance trust – but its registry leaked sensitive info
AI and ML Security researchers tricked LLMs into giving them cocaine recipes by abusing role models for prompt injection
Security It's looking like a hot, messy summer for security teams as AI finds countless previously hidden vulns
security Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs
Cyber-Crime Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues
security Nation-state actors cracked critical Australian infrastructure to ‘cripple it at a time of their choosing’
Cyber-Crime You have got to be KDDI-ng – Japanese telco exposes 14.2 million managed email credentials
Security Five Eyes spooks warn AI means infosec incidents can become ‘major operational and financial crises’
security Rights groups brand Home Office's AI age guesser for asylum-seekers as biased and inaccurate
Cyber-crime Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic
security Feds freaked over Fable 5 after simple 'fix this code' prompt, not jailbreak, says researcher
RESEARCH PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data
SECURITY Microsoft has mostly repaired flaw in Surface hardware that allowed unprotected devices to be bricked by a single packet
personal tech Apple’s iOS 27 goes all agentic on compromised passwords, promises to change them with one tap
Security Norks blast 250+ fake job offers to developers over 6 weeks to try and snarf creds and crypto
security GitHub nukes 70+ Microsoft repos, breaks CI/CD pipelines, following suspected worm infections