Latest stories — Page 16

The fake new hire problem: how criminals slip in through remote onboarding
Gaps between background checks, laptop delivery and account setup are letting impostors join companies as staff. Here's how the trick works, and what stops it.

Ransomware Hit Colombia's Justice Ministry Five Days Before a New President Took Office
Files were encrypted, services went down, and ColCERT had warned about exactly this kind of attack the day before. Here is what happened, and why Colombia keeps ending up in the crosshairs.

Attackers Slip Past the Perimeter, Then Run Free Inside: Blue Report 2026
Companies are blocking more attacks at the front door than ever. Once inside, the criminals barely need to try.

Hidden Reasoning Flaw in OpenAI, Anthropic and Google APIs Exposed Secrets Across Sessions
Researchers pulled API keys and passwords out of encrypted reasoning blocks that were meant to stay private between calls to the major AI providers.

Mindgard Raises $30 Million to Test AI Systems for Security Flaws
The London-and-Boston startup has already found more than 150 vulnerabilities in popular AI products, including a previously unknown flaw in a widely used code editor. Fresh capital will expand its engineering and sales teams.

WhatsApp's New Scam Alert Reads Your Messages Without Leaving Your Phone
WhatsApp is testing a feature that flags suspicious messages using an AI model that runs entirely on your device. Signal is also rolling out automatic checks to confirm nobody has secretly intercepted your conversations.

Hackers Used Guest Access to Quietly Steal Data From Salesforce and ServiceNow
A newly spotted campaign, tracked as 'City-Forum', used anonymous login features built into two widely used business platforms to map and copy out sensitive data, no stolen password required.

How Walmart's Security Chief Stopped Saying No and Started Saying 'Yes, and…'
Walmart's global head of security operations explains why friction is the enemy, why trust is the currency, and what the rest of the retail sector can learn from running cybersecurity at a $700 billion company.

Signal Rolls Out Automatic Key Verification to Blunt Interception Attempts
The messaging app adds a key transparency layer, audited by Cloudflare and Trail of Bits, following a year of targeted phishing linked to Russian state-aligned clusters tracked as UNC5792 and UNC4221.

Fake CCleaner site turns Chrome into a spying and password-theft tool
Criminals built a convincing copycat download page for one of the world's most-downloaded PC tools, then used it to silently hijack Google Chrome and steal passwords, bank details, and screenshots.

Intel and AMD Quietly Patched Over 80 Security Flaws. Here Is What That Means For You.
Two of the biggest names in computer chips fixed a pile of serious vulnerabilities this Patch Tuesday. Some could let attackers take full control of an affected machine.

Hackers Exploit Patched VMware vCenter Flaw as Regulators Watch Disclosure Clocks
A directory-traversal bug rated 9.8 out of 10 is under active attack, and SEC and EU disclosure duties now sit squarely on affected firms.

Four Gaps That Are Keeping AI Out of Your Security Team's Hands
Security operations centres are spending big on artificial intelligence, but most are not seeing results. Here is why the problem is not the technology.

North Korea's Lazarus Group Used a Secret Windows Flaw to Break Into Defence Companies
Hackers posing as recruiters sent fake job offers to aerospace and aviation workers in Europe and India, then used a previously unknown Windows vulnerability to seize full control of their computers.

Poisoned LiteLLM Packages on PyPI May Have Leaked Secrets From 2,100 Organisations
CloudSEK says a 434,000-file dataset stolen during a 40-minute window in March traces back to two malicious releases of the popular AI gateway library.

The software wrapper around your AI agent is the real security risk
Researchers broke into official AI automation tools from Anthropic, Google, and OpenAI, not by tricking the AI itself, but by exploiting the ordinary code that connects it to the real world.

Ivanti Patches Three High-Severity Flaws in Endpoint Manager That Attackers Could Hit Remotely
Two of the bugs needed no password to exploit. Ivanti says no customers were hit before the fixes landed.

August 2026 ICS Patch Tuesday: Siemens, Schneider Electric and Phoenix Contact Fix Serious Flaws in Factory Equipment
A batch of August security updates covers industrial control systems that run factories, power networks and buildings. One Siemens flaw scores the maximum possible severity rating and lets attackers run any code they like on a connected device without needing a password.

Researcher publishes 'ShieldBreak' code that claims to defeat a recent Microsoft Defender fix
A proof-of-concept from a researcher known as Chaotic Eclipse says the patch for CVE-2026-50656 can still be bypassed to gain full control of Windows machines.

SAP patches perfect-10 flaw in Commerce Cloud that let anyone run code
CVE-2026-58231 carries the highest possible severity score. Unauthenticated attackers could execute arbitrary code on affected Commerce Cloud installs.

Some of the Bugs That Hid Inside Everyday Software for Decades
From a print-spooler flaw that Stuxnet quietly exploited to a 30-year-old graphics library hole, a handful of the most stubborn software vulnerabilities ever found show how long danger can lurk unnoticed.