Latest stories — Page 18

Macro view of a tangled knot of glowing fiber optic cables pulsing with light, set against a dark server room background, with some cables dimming and flickerin
AI Security

Criminals Poisoned a Python Package Downloaded 95 Million Times a Month. AI Developers Were the Target.

On 24 March 2026, attackers slipped malicious code into LiteLLM, a software tool used by AI developers worldwide. Three hours online was enough to reach tens of thousands of companies.

4 min read
Extreme close-up of a glowing smartphone screen showing a software update progress bar, deep shadows around the device, cool blue-white light from the screen il
Vulnerabilities

Microsoft and Apple Rush Out Patches for Flaws That Let Attackers In Without a Password

Several of the Microsoft bugs score a perfect 10 out of 10 for severity. Apple quietly fixed a flaw that lets someone access your screen without logging in.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a sleek matte-black padlock resting on a softly glowing computer keyboard, cool blue and teal rim ligh
AI Security

AI Patches Security Flaws Correctly Only 26% of the Time, 1Password Study Finds

An internal evaluation by the security company 1Password found that AI coding tools produce flawed or incomplete security fixes more than half the time, and sometimes make things worse.

3 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
AI Security

AI Is Making Data Breaches More Expensive. Here's What the Numbers Actually Say.

A new IBM report puts the average global cost of a data breach at $6 million for 2026, up 35% in a year, and for the first time, AI-powered attacks account for one in four of those incidents.

4 min read
Photoreal editorial scene of a dimly lit apartment workstation in a generic Eastern European city at night, multiple monitors glowing with abstract code and ter
Threat Intelligence

The hacking crew behind a big supply-chain attack has been busy since 2020

New research links TeamPCP, the group behind a recent software supply-chain campaign, to years of quiet break-ins on exposed servers.

3 min read
A vast, dimly lit server room filled with towering racks of blinking blue and white lights, shot from a low angle looking down a long corridor of hardware, the
Breaches

3.8 Million People's Medical and Personal Data Stolen in Unlimited Technology Systems Breach

A healthcare billing company lost names, Social Security numbers, diagnoses, and scanned ID documents for nearly four million people after hackers spent five days inside its systems last October.

3 min read
Full-frame 16:9 photoreal editorial shot of a darkened desk with a gaming laptop open, screen glowing with a generic browser window and a translucent overlay su
Vulnerabilities

Google Patches 41 Security Flaws in Chrome 151, Six Rated Critical

The latest Chrome update fixes a cluster of memory-safety bugs that could let attackers crash your browser or run malicious code on your device. Here is what happened and what you should do.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Policy & Regulation

Apple Takes UK Government Back to Court Over Demand to Read Encrypted User Data

Apple has filed a second legal challenge against a British government order requiring access to data so heavily protected that even Apple cannot read it. The case could decide whether end-to-end encryption survives as a meaningful privacy tool in the UK.

3 min read
A weathered combination padlock resting on a cracked concrete surface, surrounded by a tangled web of thin copper wires spreading outward in all directions, pho
Identity & Access

Metro Bank Customer Lost £14,000 to Fraudsters Who Used Stolen Money to Buy AI Chatbot Credits

A Sussex businessman spent months fighting to recover £14,244 after criminals raided his Metro Bank account and spent the proceeds on credits for Claude, Anthropic's AI chatbot. The case raises hard questions about whether banks are doing enough to catch unusual spending patterns before the money is gone.

3 min read
Photoreal news-editorial style 16:9 image of a dark server room with faint green code reflections across black rackmount hardware, a single keyboard resting on
AI Security

OpenAI upgrades ChatGPT for paying users, hands free accounts unlimited chats

The GPT-5.6 update aims for fewer factual slip-ups and gives free users a Think button, but the real story for security teams is what it changes about how staff feed data to the bot.

4 min read
A digital representation of a botnet network with police arrest imagery in the background
Policy & Regulation

Cybercriminals Now Run Like Franchises. Law Enforcement Still Fights Like It's 2015.

At Black Hat 2026, a former White House cybersecurity adviser laid out why coordinated ransomware gangs and scam networks are winning, and what it would take to actually slow them down.

3 min read
Full-frame edge-to-edge 16:9 photoreal news-editorial shot of a dim security operations center with multiple monitors showing abstract source code and dependenc
AI Security

Researcher Claims He Built a Secret Communications Channel Inside ChatGPT's Locked-Down Sandbox

A Palo Alto Networks security researcher showed at Black Hat 2026 how an attacker could trick ChatGPT into running malicious code, steal data from connected accounts, and relay that data out through a backdoor built from failed login messages. OpenAI says the key components have been removed.

4 min read
Full-frame edge-to-edge overhead photograph of a large server room aisle at night, cool blue LED indicator lights along both rows of racks, one rack door left s
Vulnerabilities

The Security Metric That Lies: Why Knowing Your Vulnerabilities Is Not the Same as Reducing Your Risk

Security teams are drowning in vulnerability reports yet still cannot answer the one question that matters: are we actually harder to attack today than we were last year? A growing number of experts say the old way of measuring risk is the problem.

4 min read
Full-frame photoreal editorial image of a dimly lit server room with rows of humming racks, one open cabinet showing a glowing blue cable bundle, subtle red war
Threat Intelligence

Hedge Fund Vishing Attacks Traced to UNC6671, the Group Behind the BlackFile Brand

Google's threat researchers say one core crew is running help-desk phone scams that have hit Point72, Citadel, Two Sigma and Millennium, then stealing data straight from their cloud accounts.

4 min read
Full-frame edge-to-edge overhead photo of an unbranded modern smartphone on a deep slate surface, a subtle illuminated checkpoint barrier graphic implied by a s
Policy & Regulation

Bobmojis, Bobbleheads, and Hardware Keys: How the Democratic National Committee Rebuilt Its Security After a Russian Hack

Two security chiefs who ran the DNC's defences back-to-back told Black Hat 2026 how they turned a politically focused, budget-constrained organisation into one where the chair personally called staff who skipped security enrolment.

4 min read
Photoreal editorial photograph of a large empty industrial tractor assembly hall at dusk, warm overhead lights on green paint bays, no visible logos or text, wi
Breaches

Swiss federal IT office says SharePoint breach exposed 200 accounts

The BIT breach lines up with the July SharePoint bug wave, though attribution remains open.

4 min read
Overhead view of a large server room with rows of illuminated rack-mounted servers bathed in cool blue and orange ambient light, power indicator LEDs glowing in
Vulnerabilities

Zapscape flaw in Linux KVM lets a rogue guest break out to the host

A newly disclosed bug in the Linux kernel's virtualization layer, tracked as CVE-2026-64561, could let an attacker inside a nested virtual machine reach the physical server underneath.

3 min read
Close-up overhead shot of a dense rack of enterprise networking and telephony hardware, blinking amber and red indicator lights visible across multiple units, s
Vulnerabilities

Cisco Patches a Dozen Flaws in SD-WAN and IOS XE, Three Rated Critical

An internal Cisco security review turned up 12 vulnerabilities, including three with a severity score of 9.8 out of 10, in software that runs corporate networks worldwide.

3 min read
An illustration of a network security breach with digital locks and warning symbols
Vulnerabilities

Researchers Sneak Past Spectre v2 by Slipping Between the Kernel's Own Defenses

MIT CSAIL's 'Interrupt Injection' technique re-poisons the branch predictor in the tiny window after the CPU cleans it and before Linux uses it.

4 min read
Full-frame photoreal editorial image of a dimly lit corporate server room with rows of blue-lit racks, a soft red warning glow pulsing from one rack indicating
Vulnerabilities

ABB Ability Zenon ships with a MongoDB version that hasn't been patched since 2020

Industrial software used in energy, water and manufacturing plants bundles an old database with flaws that can leak memory and bypass access controls.

4 min read
Full-frame edge-to-edge overhead photoreal shot of a developer's dark wooden desk at night, a laptop screen glowing with abstract green code, a small physical h
Threat Intelligence

The Week's Attacks Were Cheap, Ordinary, and Very Effective

Opening a repo, installing a package, or previewing a PDF was enough to hand attackers a foothold this week. None of it was sophisticated. All of it worked.

4 min read
© 2026 Threat Vectr