Latest stories — Page 11

The US Government's Software Flaw Database Is Drowning. Can AI Be the Lifeguard?
The agency that tracks every known software weakness in the world is asking the public whether artificial intelligence can help it cope with a 72% surge in reported flaws.

Seven arrested over €30M Commerzbank fraud that abused a service provider flaw
Investigators say the crew drained customer accounts by exploiting a weakness at a third-party firm that connects to the German bank.

A Survey Company May Have Leaked Scottish Government Workers' Personal Details
A contractor hired to run a government training exercise lost staff data from Scotland's public prosecution service. The real worry: dozens of other agencies probably handed over the same information.

The Tech Risks Hiding in Plain Sight on Every Company's Balance Sheet
Boards spend hours debating growth investments and almost no time on the quiet failures building underneath their feet. A closer look at why that imbalance is getting more dangerous.

Dutch cyber agency warns of live attacks on macOS Screen Sharing flaw
Hackers are breaking into Mac computers exposed to the internet, seizing top-level control, and quietly mining Monero cryptocurrency.

OAuth Tokens Are Quietly Becoming the Skeleton Key to Google Workspace
Phishing gets the headlines, but stolen app tokens can open Gmail and Drive without ever tripping a login alert.

Oracle Releases Free Database Security Tool Amid Growing Pressure From AI-Powered Bug Hunters
Oracle Database Security Central gives organisations a single place to spot risky database settings and unusual access patterns. It is free until February 2027, though the window that prompted its creation is already closing.

Cyera Buys Oasis Security for $1 Billion to Rein In AI Agents Before They Run Wild
Two Israeli-founded security firms are merging to solve a problem most companies haven't fully noticed yet: AI agents that grab every permission they're given and never let go.

Shell probes possible data theft as Clop ransomware crew names it in engineering software raid
The gang claims 89GB of drawings and project files, part of a wider spree hitting PTC Windchill and FlexPLM systems.

North Korean IT Worker Infiltrated a Federal Agency, Boeing 737 Security Flaws Explored, and Refrigeration Systems Found Vulnerable
A roundup of three security stories that deserve more attention: a suspected North Korean operative who got hired at a US government agency, researchers who probed the computers aboard a Boeing 737, and critical flaws in industrial refrigeration controllers.

A New Free Tool Lets You See Who's Actually Tracking You Online
DecryptAds pulls back the curtain on the ad partners and data brokers hiding inside popular websites and apps, including some based in Russia and China.

Most of the 2,500 organisations hit in the LiteLLM attack were actually victims of a different breach entirely
A closer look at the data shows the Trivy scanner compromise, not the LiteLLM package, caused almost all the damage, and stolen credentials are already on sale.

Google Cloud Targets 2029 to Be Quantum-Safe, and Here Is What That Means for You
Google has published a detailed plan to protect its cloud from the coming generation of quantum computers. The work is already underway, but some of it will run well into the 2030s.

ShinyHunters Claims 1.6 Million Records Stolen from RingCentral
The extortion group published 280 gigabytes of alleged RingCentral data after the company refused to pay. Names, addresses, phone numbers and email addresses are now circulating freely.

A Leaked Password Let Hackers Drain the Donor Databases of More Than 1,000 UK Charities
Beacon, a software company that helps charities manage their supporters, left an access key exposed in public code. Criminals found it, used it, and likely walked off with every record in the system.

Your security team's growing backlog is not their fault
When every vulnerability alert lands on the security team's desk, the result is not accountability. It is a queue that never shrinks. A clearer split of duties is the only fix.

Contractor Jailed Two Years After $2.5M Extortion Attempt Against Brightly Software
Cameron Curry stole payroll data on his way out the door, then threatened to report his ex-employer to the SEC unless it paid up.

From Gatekeeper to Growth Partner: What the Modern CSO Role Actually Looks Like
Security chiefs who keep talking about firewalls while their peers talk about revenue will keep getting ignored. Here is what the shift to business-first security leadership looks like in practice.

AmnesiaStealer: New Mac Malware Quietly Drains Passwords and Browser Sessions
A newly identified piece of malicious software targeting Apple Mac computers can lift saved passwords, browser cookies, and sensitive keychain data, and it is written in a programming language that makes it harder for security tools to catch.

Black Hat 2026: Five Security Findings Every Organisation Should Know About
From fake AI tools downloaded 1.7 million times to a flaw that lets attackers hijack internet connections through network devices, this year's hacker conference in Las Vegas carried some practical warnings for businesses of every size.

Apple warns another wave of iPhone users they are being targeted by spyware-for-hire
The company sent a fresh round of high-confidence alerts on 13 August, the latest in a program that has quietly notified targets in more than 150 countries since 2021.