Latest stories — Page 18

Criminals Poisoned a Python Package Downloaded 95 Million Times a Month. AI Developers Were the Target.
On 24 March 2026, attackers slipped malicious code into LiteLLM, a software tool used by AI developers worldwide. Three hours online was enough to reach tens of thousands of companies.

Microsoft and Apple Rush Out Patches for Flaws That Let Attackers In Without a Password
Several of the Microsoft bugs score a perfect 10 out of 10 for severity. Apple quietly fixed a flaw that lets someone access your screen without logging in.

AI Patches Security Flaws Correctly Only 26% of the Time, 1Password Study Finds
An internal evaluation by the security company 1Password found that AI coding tools produce flawed or incomplete security fixes more than half the time, and sometimes make things worse.

AI Is Making Data Breaches More Expensive. Here's What the Numbers Actually Say.
A new IBM report puts the average global cost of a data breach at $6 million for 2026, up 35% in a year, and for the first time, AI-powered attacks account for one in four of those incidents.

The hacking crew behind a big supply-chain attack has been busy since 2020
New research links TeamPCP, the group behind a recent software supply-chain campaign, to years of quiet break-ins on exposed servers.

3.8 Million People's Medical and Personal Data Stolen in Unlimited Technology Systems Breach
A healthcare billing company lost names, Social Security numbers, diagnoses, and scanned ID documents for nearly four million people after hackers spent five days inside its systems last October.

Google Patches 41 Security Flaws in Chrome 151, Six Rated Critical
The latest Chrome update fixes a cluster of memory-safety bugs that could let attackers crash your browser or run malicious code on your device. Here is what happened and what you should do.

Apple Takes UK Government Back to Court Over Demand to Read Encrypted User Data
Apple has filed a second legal challenge against a British government order requiring access to data so heavily protected that even Apple cannot read it. The case could decide whether end-to-end encryption survives as a meaningful privacy tool in the UK.

Metro Bank Customer Lost £14,000 to Fraudsters Who Used Stolen Money to Buy AI Chatbot Credits
A Sussex businessman spent months fighting to recover £14,244 after criminals raided his Metro Bank account and spent the proceeds on credits for Claude, Anthropic's AI chatbot. The case raises hard questions about whether banks are doing enough to catch unusual spending patterns before the money is gone.

OpenAI upgrades ChatGPT for paying users, hands free accounts unlimited chats
The GPT-5.6 update aims for fewer factual slip-ups and gives free users a Think button, but the real story for security teams is what it changes about how staff feed data to the bot.

Cybercriminals Now Run Like Franchises. Law Enforcement Still Fights Like It's 2015.
At Black Hat 2026, a former White House cybersecurity adviser laid out why coordinated ransomware gangs and scam networks are winning, and what it would take to actually slow them down.

Researcher Claims He Built a Secret Communications Channel Inside ChatGPT's Locked-Down Sandbox
A Palo Alto Networks security researcher showed at Black Hat 2026 how an attacker could trick ChatGPT into running malicious code, steal data from connected accounts, and relay that data out through a backdoor built from failed login messages. OpenAI says the key components have been removed.

The Security Metric That Lies: Why Knowing Your Vulnerabilities Is Not the Same as Reducing Your Risk
Security teams are drowning in vulnerability reports yet still cannot answer the one question that matters: are we actually harder to attack today than we were last year? A growing number of experts say the old way of measuring risk is the problem.

Hedge Fund Vishing Attacks Traced to UNC6671, the Group Behind the BlackFile Brand
Google's threat researchers say one core crew is running help-desk phone scams that have hit Point72, Citadel, Two Sigma and Millennium, then stealing data straight from their cloud accounts.

Bobmojis, Bobbleheads, and Hardware Keys: How the Democratic National Committee Rebuilt Its Security After a Russian Hack
Two security chiefs who ran the DNC's defences back-to-back told Black Hat 2026 how they turned a politically focused, budget-constrained organisation into one where the chair personally called staff who skipped security enrolment.

Swiss federal IT office says SharePoint breach exposed 200 accounts
The BIT breach lines up with the July SharePoint bug wave, though attribution remains open.

Zapscape flaw in Linux KVM lets a rogue guest break out to the host
A newly disclosed bug in the Linux kernel's virtualization layer, tracked as CVE-2026-64561, could let an attacker inside a nested virtual machine reach the physical server underneath.

Cisco Patches a Dozen Flaws in SD-WAN and IOS XE, Three Rated Critical
An internal Cisco security review turned up 12 vulnerabilities, including three with a severity score of 9.8 out of 10, in software that runs corporate networks worldwide.

Researchers Sneak Past Spectre v2 by Slipping Between the Kernel's Own Defenses
MIT CSAIL's 'Interrupt Injection' technique re-poisons the branch predictor in the tiny window after the CPU cleans it and before Linux uses it.

ABB Ability Zenon ships with a MongoDB version that hasn't been patched since 2020
Industrial software used in energy, water and manufacturing plants bundles an old database with flaws that can leak memory and bypass access controls.

The Week's Attacks Were Cheap, Ordinary, and Very Effective
Opening a repo, installing a package, or previewing a PDF was enough to hand attackers a foothold this week. None of it was sophisticated. All of it worked.