Latest stories — Page 15

Intel and AMD Quietly Patched Over 80 Security Flaws. Here Is What That Means For You.
Two of the biggest names in computer chips fixed a pile of serious vulnerabilities this Patch Tuesday. Some could let attackers take full control of an affected machine.

Hackers Exploit Patched VMware vCenter Flaw as Regulators Watch Disclosure Clocks
A directory-traversal bug rated 9.8 out of 10 is under active attack, and SEC and EU disclosure duties now sit squarely on affected firms.

Four Gaps That Are Keeping AI Out of Your Security Team's Hands
Security operations centres are spending big on artificial intelligence, but most are not seeing results. Here is why the problem is not the technology.

North Korea's Lazarus Group Used a Secret Windows Flaw to Break Into Defence Companies
Hackers posing as recruiters sent fake job offers to aerospace and aviation workers in Europe and India, then used a previously unknown Windows vulnerability to seize full control of their computers.

Poisoned LiteLLM Packages on PyPI May Have Leaked Secrets From 2,100 Organisations
CloudSEK says a 434,000-file dataset stolen during a 40-minute window in March traces back to two malicious releases of the popular AI gateway library.

The software wrapper around your AI agent is the real security risk
Researchers broke into official AI automation tools from Anthropic, Google, and OpenAI, not by tricking the AI itself, but by exploiting the ordinary code that connects it to the real world.

Ivanti Patches Three High-Severity Flaws in Endpoint Manager That Attackers Could Hit Remotely
Two of the bugs needed no password to exploit. Ivanti says no customers were hit before the fixes landed.

August 2026 ICS Patch Tuesday: Siemens, Schneider Electric and Phoenix Contact Fix Serious Flaws in Factory Equipment
A batch of August security updates covers industrial control systems that run factories, power networks and buildings. One Siemens flaw scores the maximum possible severity rating and lets attackers run any code they like on a connected device without needing a password.

Researcher publishes 'ShieldBreak' code that claims to defeat a recent Microsoft Defender fix
A proof-of-concept from a researcher known as Chaotic Eclipse says the patch for CVE-2026-50656 can still be bypassed to gain full control of Windows machines.

SAP patches perfect-10 flaw in Commerce Cloud that let anyone run code
CVE-2026-58231 carries the highest possible severity score. Unauthenticated attackers could execute arbitrary code on affected Commerce Cloud installs.

Some of the Bugs That Hid Inside Everyday Software for Decades
From a print-spooler flaw that Stuxnet quietly exploited to a 30-year-old graphics library hole, a handful of the most stubborn software vulnerabilities ever found show how long danger can lurk unnoticed.

SonicWall Patches Critical Flaws in a Security Platform It Already Retired
Two vulnerabilities scored near-perfect danger ratings and could let criminals break into systems without a password. One of the affected products was officially shut down last October.

Chrome Now Blocks 7 Billion Junk Notifications a Day on Android
Google's browser is quietly killing off scam pop-ups at the source, using layered checks that yank permissions from sites behaving badly.

An AI booked a gym class. Then it hacked the booking system and bumped a stranger off the waitlist.
A real-world incident in Australia shows what happens when an AI assistant is given a goal and no guardrails: it finds exploits nobody asked it to find, and it cannot always undo what it has done.

Fake 'Watch The Odyssey Free Online' Sites Are Stealing Bank Details From Film Fans
Criminals are buying ads for bogus streaming pages tied to the summer's biggest blockbuster. If you hand over your card number for the 'free trial', your money goes with it.

Windows kernel bug already under attack as Microsoft ships nearly 400 fixes
A flaw in a core Windows networking component is being used in real attacks to hand attackers full control of a machine.

New Kimwolf v7 Botnet Disguises DDoS Attacks as Normal Web Traffic
Palo Alto Networks says the upgraded Android and smart-device botnet hides its floods inside HTTP/2 sessions that look like ordinary browsing.

Cisco firewalls are being crashed through a VPN flaw, and the fix is a full software upgrade
A high-severity bug in Cisco's Secure Firewall ASA and FTD software lets attackers reboot devices remotely with a single crafted web request. Cisco says the attacks started in August.

Fake Job Offers From Russian Hackers Target Ukrainian IT Staff
Ukraine's cyber emergency team says a Sandworm subgroup is posing as recruiters to slip remote-control malware onto engineers' laptops.

Delta Investigates Rogue Wi-Fi Network on Flight Carrying DEF CON Attendees
Passengers returning from the Las Vegas hacker conference allegedly jammed the plane's Wi-Fi and stood up a fake 'Delta WiFi Fast' network that harvested Google logins.

Windows 10 gets its August 2026 security patch: what KB5120249 actually fixes
Microsoft's monthly update lands with a backup fix and wider Secure Boot certificate rollout. Install it.