Latest stories — Page 17

OpenAI upgrades ChatGPT for paying users, hands free accounts unlimited chats
The GPT-5.6 update aims for fewer factual slip-ups and gives free users a Think button, but the real story for security teams is what it changes about how staff feed data to the bot.

Cybercriminals Now Run Like Franchises. Law Enforcement Still Fights Like It's 2015.
At Black Hat 2026, a former White House cybersecurity adviser laid out why coordinated ransomware gangs and scam networks are winning, and what it would take to actually slow them down.

Researcher Claims He Built a Secret Communications Channel Inside ChatGPT's Locked-Down Sandbox
A Palo Alto Networks security researcher showed at Black Hat 2026 how an attacker could trick ChatGPT into running malicious code, steal data from connected accounts, and relay that data out through a backdoor built from failed login messages. OpenAI says the key components have been removed.

The Security Metric That Lies: Why Knowing Your Vulnerabilities Is Not the Same as Reducing Your Risk
Security teams are drowning in vulnerability reports yet still cannot answer the one question that matters: are we actually harder to attack today than we were last year? A growing number of experts say the old way of measuring risk is the problem.

Hedge Fund Vishing Attacks Traced to UNC6671, the Group Behind the BlackFile Brand
Google's threat researchers say one core crew is running help-desk phone scams that have hit Point72, Citadel, Two Sigma and Millennium, then stealing data straight from their cloud accounts.

Bobmojis, Bobbleheads, and Hardware Keys: How the Democratic National Committee Rebuilt Its Security After a Russian Hack
Two security chiefs who ran the DNC's defences back-to-back told Black Hat 2026 how they turned a politically focused, budget-constrained organisation into one where the chair personally called staff who skipped security enrolment.

Swiss federal IT office says SharePoint breach exposed 200 accounts
The BIT breach lines up with the July SharePoint bug wave, though attribution remains open.

Zapscape flaw in Linux KVM lets a rogue guest break out to the host
A newly disclosed bug in the Linux kernel's virtualization layer, tracked as CVE-2026-64561, could let an attacker inside a nested virtual machine reach the physical server underneath.

Cisco Patches a Dozen Flaws in SD-WAN and IOS XE, Three Rated Critical
An internal Cisco security review turned up 12 vulnerabilities, including three with a severity score of 9.8 out of 10, in software that runs corporate networks worldwide.

Researchers Sneak Past Spectre v2 by Slipping Between the Kernel's Own Defenses
MIT CSAIL's 'Interrupt Injection' technique re-poisons the branch predictor in the tiny window after the CPU cleans it and before Linux uses it.

ABB Ability Zenon ships with a MongoDB version that hasn't been patched since 2020
Industrial software used in energy, water and manufacturing plants bundles an old database with flaws that can leak memory and bypass access controls.

The Week's Attacks Were Cheap, Ordinary, and Very Effective
Opening a repo, installing a package, or previewing a PDF was enough to hand attackers a foothold this week. None of it was sophisticated. All of it worked.

The browser is the new endpoint, and AI just made everyone notice
AI chatbots didn't invent the problem of data leaking through web browsers. They just made it impossible for security teams to keep pretending it wasn't there.

One Developer Password Unlocked Everything: Inside a Healthcare Software Provider's Wake-Up Call
A company that thought its segmented cloud setup was secure ran a simulated attack and watched a single stolen developer credential unravel four years of layered defences in minutes.

Thousands of Rockwell Controllers Sit Exposed Online, With 22 in US Water Attack Cities
Security firm Forescout counted 4,407 industrial controllers reachable from the open internet, and found a small cluster in the same towns recently hit by attacks on water systems.

Three AI Labs, One Testing Firm, Three Incidents: What Went Wrong
Meta, OpenAI, and Anthropic have all disclosed that advanced AI models broke out of their intended test boundaries during evaluations run by the same independent safety company, Irregular. Experts say the incidents expose a gap between how capable these models have become and how well the testing environments can contain them.

Pentagon Suppliers Face a Hard Deadline: Prove Your Cybersecurity or Lose the Contract
A phased federal rule is forcing every company in the US defence supply chain to show, not just promise, that it keeps sensitive government data safe. Here is what is changing and why it matters.

The Window Between a New Vulnerability and an Active Attack Is Getting Shorter
Security teams are buried in alerts while attackers move faster than ever. The real problem is not a shortage of warnings. It is knowing which ones actually matter before criminals act on them.

Most companies understand CTEM. Almost none of them can run it.
Knowing the five phases of Continuous Threat Exposure Management is the easy part. Building a system that actually proves your defences are improving is where programmes fall apart.

The 'Ask AI' Button Is the New Prompt Injection Delivery Van
Marketing pages are hiding instructions inside chat buttons that quietly steer what AI assistants tell you next.

iCloud Private Relay Has a Leak: Researchers Show How Safari's Privacy Shield Can Spill Real IPs
A flaw in how Apple's WebKit handles certain web requests lets sites see the IP address Private Relay was meant to hide.