Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default Researchers scour social media to measure developer concerns about AI coding tools
OpenAI pledges to add Astra security as Anthropic loosens Fable's leash Or how I learned to stop worrying and love dangerous AI
Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks Calling all defenders
Ransomware attacks spike as world distracted by AI What, you didn't think the top gangs were busy watching agents escape their sandboxes too, did you?
N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again
ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they've dumped 10.9M email addresses Cancer diagnostics breach spills personal and health info as extortion crew says healthcare giant ‘should’ve paid the ransom’
MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs Timer interrupts reopen branch predictor poisoning window, with a working Zen 2 exploit to prove it
Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder Investigation into whether staff improperly accessed Minnie Merriman’s file after she was named for the first time this week
Attacker phished way into US defense supplier's Microsoft 365 account Intruder gained access to engineering files and potentially export-controlled technical data
Intrusion at US healthcare software provider puts 3.8M people's data at risk Unlimited Technology Systems says names, Social Security numbers, diagnoses, and insurance details may have been swiped
'Asimov was right' about rules for robots, says ex-US Cyber Director Humans will get the AI models they deserve
China launches mysterious probe into security of Palo Alto Networks' products Beijing’s not saying why, which is just what happened when it investigated Micron
How the famed USENIX Security conf is managing a flood of papers in the AI era AI usage is evident but isn't yet a serious problem
AI struggles to patch vulns without adult supervision Left alone, autonomous fixes often fail to fully remediate flaws
Humans in the loop miss a third of dangerous AI coding agent requests You wouldn't let Claude Code cat your AWS credentials or Kubernetes config on request, would you?
Snowflake extortionist admits 165-victim cloud crime spree – and squeezing one target twice Connor Moucka pleads guilty over sprawling 2024 campaign that looted billions of records
IT department put sticky notes on the laptops to help employees log in Leaving this information exposed allowed someone else to gain access
Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway It’s just a remote maintenance function, says Zbtlink
OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack It started with an 'impossible task' and led to AI deciding it needed to act as a collective intelligence
Prompt injection isn't the bug, AI agent frameworks are Check Point researchers tried to break the frameworks enterprises use to build AI apps. Now they're telling Black Hat attendees what they found
IBM's agentic AI platform is under active attack - patch now A critical Langflow flaw allowing RCE on default deployments is being exploited, says the CISA
London cops handed victim's new address and number to her stalker, watchdog says Met ordered to improve safeguards after two preventable data breaches
UK charities count the cost of Beacon CRM cyberattack Database backups likely stolen, potentially exposing donor, supporter, and service user details
AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project Models used social engineering and collaborated among themselves to solve a security challenge
Bypassing AI guardrails is so easy a script kiddie can do it Claiming 'it's my server' was often enough to persuade models to help
This one time, at Hacker Summer Camp … What to expect as BSides, Black Hat, and DEF CON descend on Las Vegas
Feds get 3 days to patch N-able God mode flaw under active exploit Experts warn hotfix not optional. MSPs warned attacker gains 'full administrative access to an N-central console'
AI helps Microsoft bug hunters chase a record $20M payday Broader bounty rules added to a swelling volume of machine-assisted vulnerability reports
Tennessee congressional hopeful accused of shooting license plate cameras Cops arrest budding politician for allegedly dealing with Flock's expansion the American way
CAF Bank reopens online service but warns of further outages Customers told traffic may be limited at certain times following more than ten days offline
Cloudflare has mostly ditched third party security tools, suggests not trying that at home Automates bug bounty triage with Sonnet for $58 a month, CSO says Mythos would cost $200k
Google dev kit spurs first-ever agent-on-agent violence Poisoned pull requests contain prompt injection that allows one to control another
AI slop pollutes the CVE pipeline with fake vulns With NIST still buried under its backlog, expect AI-generated bogus reports to continue
Russian spies turn public Wi-Fi into malware delivery systems Keyloggers, audio-visual surveillance, and token theft on CaptivePortal's agenda as hospitality sector put on alert
Police National Legal Database confirms data theft after dark web leak ExfilSquad claims 135,000 contact records weeks after hitting the Department for Education
Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict Trump rejects Tehran theory, blames 'grossly incompetent' governor of Minnesota instead
UK government investment arm cops to 40-hour leak of officials' contact details Employee failed to follow security policy, leaving internal management file open to the public
AI is 'both the weapon and the target' in latest wave of cyberattacks CrowdStrike tracks 89% surge in machine-assisted activity as patch windows shrink to 48 hours
The most famous brand in physical security got pwned by ShinyHunters Hopefully the company secures houses better than it locks down SaaS systems
US bank places trust in ransomware crew that promised to delete its data History suggests this was not wise
Charities remain locked out of CAF Bank online accounts A week into shutdown, 14,000 customers still have no restoration date and some are struggling to pay staff
Scotland's university procurement center confirms cybercrooks broke in APUC investigating after criminals claim historical data theft
Anthropic’s Claude escaped test sandbox to attack three organizations Wrote and published malware during tests, which is apparently OK because leaky test environments were the real problem
Jailed Flock vandal wipes out three cameras, racks up thousands in damages A lesson for aspiring vandals: Take out all the cameras, not just the ones that flout your ideals
Amazon links four poisoned npm packages to one North Korean crew Researchers say Sapphire Sleet socially engineered maintainers before publishing malicious updates through trusted accounts
Russian spies take their half-click email attack from Zimbra to Outlook Opening a booby-trapped message unleashes a browser implant that can survive password changes and device rebuilds
Headteacher had the most guessable username-password combo you could imagine Schools often don't prioritize or understand cybersecurity
Excuses like 'AI did it' don't exist in the eyes of the law If your AI goes rogue, better have a good lawyer
Closed models refuse to help researcher swat Linux bug "I'm sorry, Dave. I'm afraid I can't do that" is an effective sales pitch for open source
Word worm crawls into Copilot, spreads chaos Researcher says months of coordination with Microsoft have yet to produce a robust mitigation
Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems More than 30 facilities disrupted in 'coordinated cyberattack,' though officials have yet to name a culprit
America bans imported robots due to supply chain and security risks Docs point to China’s Unitree as prime example of the foreign clanker threat
MCP gets an enterprise makeover Now happier running in a conventional K8s environment, with `an easier-to-live-with lifecycle
Microsoft and Wiz mind-meld agents catch more than 90% of bugs Secret to their success: Using the right model for the right security job
DEF CON bans Meta-style 'pervert glasses' More organizers prohibit camera-equipped specs, even with prescription lenses
AI-found bugs aren't proving any easier to exploit despite the hype VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage
Bank for charities pulls online services over security fears Customer funds safe, but 14,000 organizations may have to phone in time-sensitive payments
Uncle Sam needs you to fight for 6G leadership and security, lest Beijing get there first Washington rallies allies to shape next-generation networks after spending 18 months rattling them
Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock Unauthenticated command injection scores perfect 10 and may expose managed Edge devices
Microsoft's solution to AI security: more AI and more acronyms MDASH stuffed with MAI-Cyber-1-Flash and a side of GPT-5.4
Tech giants link hands to praise open AI models after OpenAI - Hugging Face attack The Open Security AI Alliance says the Hugging Face/OpenAI mess proves frontier labs can't be trusted to properly secure sensitive systems
Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update One bug disabled the security service on restart, another blocked installation on hardened RHEL systems
Google goes it alone with a new cybercrime crew taxonomy So much for Microsoft and CrowdStrike’s plans for consistent names across the industry
Pope's official prayer app commits cardinal sin, leaks 700K+ users' info (Security) hole-ier than thou
Europol flags 4,340 'horrific' URLs linked to The Com Stop the spread (of online recruiting and propaganda)
Uncle Sam tells overseas cybercrooks their visas are canceled Policy targets online scammers, sextortionists, and potentially their immediate families
OpenAI-Hugging Face attack doesn't mean agents are evil – unless you tell them to be Attack models gonna attack
Researchers replace downloaded macOS apps with evil twins, Apple shrugs Gatekeeper has one job and it's not doing it for some software