Latest stories — Page 14

Marcus Hutchins: The Accidental Hero Who Once Wrote the Code He Later Helped Stop
The man who halted one of history's most damaging cyberattacks spent years on the wrong side of the line first. His story is worth understanding.

Mozilla Accidentally Put a Firefox Signing Key on GitHub. Here's Why You're Probably Fine.
A private key used to authenticate Firefox and Thunderbird downloads was briefly stored in the wrong place. Mozilla has replaced it and found no sign anyone misused it.

A human and an AI teamed up to find hundreds of hackable websites. The results rewrote the rulebook.
A PortSwigger researcher built an AI system called HTTP Terminator, guided it step by step, and together they uncovered a brand-new class of web vulnerability affecting banks and government systems.

UK Children Report Surge in Explicit Deepfake Images of Themselves
A service that helps young people remove intimate photos from the internet says digitally faked images are rising fast. Regulators warn AI tools are making the problem worse.

New Zealand Sanctions 33 Russia-Linked Cyber Operators and Child Abduction Networks
Wellington's latest penalties name hackers and individuals tied to the forced removal of Ukrainian children, signalling that digital warfare now sits alongside human-rights abuses on the sanctions list.

Train companies target 'donutters' and last-minute digital ticket fraud
A simple double-tap on a smartphone is costing UK rail operators millions. Here is how the schemes work and what operators plan to do about it.

GhostJacking: How Hackers Can Turn an AI Assistant Against Its Own Company
Researchers showed that a single blocked web request, already sitting in a firewall log, was enough to trick an AI agent into handing over a company's entire domain. Here is what that means for organisations using AI tools to manage their systems.

Hackers hijacked BdThemes WordPress plugins to quietly create secret admin accounts
A poisoned promotional feed pushed malicious code to admin dashboards, spawning hidden accounts on sites running Element Pack and other BdThemes plugins.

OpenAI hands a specialised hacking AI to a small club of security firms
GPT 5.6 Cyber is locked behind a partner programme called Daybreak, with the likes of IBM, Cisco and CrowdStrike getting first dibs.

AI Found Thousands of Flaws in Days. Humans Can't Patch Them Fast Enough.
Anthropic's Claude Mythos model discovered more security holes in major software than years of human review had caught. That's exciting for defenders and terrifying for everyone else, because the gap between finding a flaw and fixing it is already dangerously wide.

Two iPhone Exploit Tools Once Owned by Governments Are Now in the Hands of Ordinary Criminals
Coruna and DarkSword, sophisticated iPhone attack kits that began as nation-state spy tools, are spreading fast. Security researchers have found roughly 17,000 websites hosting them, and criminals are already making them worse.

Old Medusa Hand, New Locker: Storm-1175 Rolls Out StormEncryptor via N-central Flaw
Microsoft says a China-linked crew is exploiting a critical bug in N-able's remote management tool to plant a fresh ransomware strain, sometimes within days of breaking in.

A 1990 Law Could Send Ethical Hackers to Prison. Dozens of Countries Are Fixing That.
Researcher Katharina Sommer mapped which nations protect good-faith security work and built a five-point blueprint to push the UK's creaking Computer Misuse Act into the present day.

Weekly Recap: A Metabase Zero-Day, Poisoned AI Plugins, and Routers Left Wide Open
Old bugs are back, supply chains are getting stranger, and the shortest exploit paths are once again the ones nobody guarded.

The World's Greatest Detective Was Also the World's Greatest Con Artist
A cybersecurity professor dressed as Sherlock Holmes walked a DEF CON audience through why the tricks criminals use to manipulate people today are identical to what a Victorian fictional detective pulled off in the 1890s.

US and Korean agencies warn about Gunra, a fast-growing ransomware gang built from leaked Conti code
The FBI, CISA and Korea's National Police Agency say Gunra has hit hospitals, utilities, banks and manufacturers across five continents since April 2025.

UK member of 'The Com' jailed for two years after blackmailing 117 girls online
Justin Swaddle, 20, used Snapchat, Telegram and Discord to coerce teenage girls into self-harm and abuse images, purely to boost his standing in a sprawling online cybercrime collective.

Kimsuky Goes Offline: North Korean Spies Build Their Own Private AI Toolkit
South Korean researchers say the Kimsuky group has stopped relying on public chatbots and is now running AI on its own servers to sharpen phishing and speed up malware writing.

Ransomware crews are now breaking into SonicWall VPN boxes through two July flaws
CISA says gangs are exploiting a maximum-severity SonicWall SMA1000 bug that has been patched since mid-July. Roughly 380 appliances are still sitting online.

A New Security Startup Says AI Chips Have a Blind Spot. It Wants to Fix That.
Stealthium is building tools to spot attacks hiding inside the specialised computer chips that power artificial intelligence, a corner of corporate IT that most security software cannot see.

Passwords Are Getting Easier to Fake. Device Trust Is the Fix Companies Are Reaching For.
As AI turbo-charges phishing and credential theft, the old signals that told a company 'this login is fine' are quietly failing. Here's what's replacing them.