Latest stories — Page 19

Why Modern Hackers Walk In Through the Front Door of Your Website
Security teams have spent years locking up their networks and servers. A new wave of attacks shows that criminals are now coming in through web applications instead, and most defences are not keeping up.

Canadian hacker admits to Snowflake data thefts that hit 165 companies and 100 million people
Connor Moucka pleaded guilty to stealing terabytes from Snowflake customer accounts that had no second login step, extorting $2.5 million in bitcoin from victims including AT&T and Ticketmaster.

Fixing One Hole at a Time Is No Longer Enough: Why Security Must Follow the Full Attack Path
Criminals no longer stop at the front door. They chain together weaknesses across your apps, accounts, and cloud systems, and security teams testing each piece in isolation are missing the bigger picture.

Your Email's Design Layer Can Steal Your Password. No Suspicious Attachment Required.
Security researcher Gareth Heyes found that CSS, the code responsible for how emails look on screen, can be turned into a data-theft tool inside popular webmail services. No malicious files. No links to click.

15 Flaws in TP-Link Kit Put Automatic Network Setup at Risk
Security researchers found 15 vulnerabilities in TP-Link's Omada networking system and warn that the convenient "zero-touch" setup process that millions of organisations rely on could hand criminals the keys to an entire network.

Hackers hid their attack tools inside an Oracle database itself
A rarely seen technique let intruders run commands, steal password data and browse files from within the database, after breaking in through a sloppy search box.

Researchers Cracked Samsung Phones Wide Open by Turning Bixby Against Its Own Device
A five-step exploit chain using Bixby, Samsung Members, and Samsung Account could hand a stranger complete control of your Galaxy phone. Patches are out, but older devices may still be exposed.

Fake Mac Downloads Hide Behind 250+ Domains That Screen Visitors First
Microsoft says a large ClickFix network now checks who is knocking before showing macOS users a booby-trapped installer, keeping researchers and scanners out of view.

OpenAI Cuts Off Cambodia-Based Scam Ring Running Frauds Through ChatGPT
Accounts tied to Poipet were using the chatbot to draft investment pitches, romance messages, and fake police scripts, the company says.

Fake COLDCARD 'Security Audit' Emails Push Remote Access Tool After $88M Bitcoin Theft
Phishing campaign impersonates the hardware wallet maker, tricks owners into installing ScreenConnect, and hands attackers full control of the victim's PC.

Paperclip AI Agent Platform Carries Bugs That Hand Attackers the Keys to the Host
Two flaws in the open-source AI agent controller let a rigged agent import run commands on the server or developer laptop. A third leaks control-plane data through unprotected API routes.

Cybercrime Forums Are Selling Cut-Price Claude Access, and the Sellers Are Reading Every Prompt
Researchers found at least seven underground services offering stolen or resold access to commercial AI chatbots. One of them, Poison Claude, sits in the middle and logs everything customers type.

CISA gives federal agencies three days to patch Langflow, N-central and Tomcat flaws under active attack
Three separate bugs, three sets of criminals, one very short deadline. Here is what is being exploited and who should care.

Malicious npm Packages Hide Attacker Servers Inside Empty Ethereum Transactions
Researchers found two booby-trapped code libraries pulling instructions from fake wallet addresses on the Ethereum blockchain, a twist on the EtherHiding trick now dubbed NullReceiver.

Veeam Console Bug Hands Over Agent Credentials; Terraform MCP Server Leaks Tokens Between Users
Eleven fixes across HashiCorp, Veeam and Django include a 9.5-rated Veeam flaw and a cross-tenant Terraform MCP Server bug that reuses one customer's cloud token for the next.

Google's Blogger locks hundreds of legitimate sites in mass false-positive sweep
An automated policy flag hit blogs on August 4, cutting owners out of their dashboards and threatening permanent deletion in three months.

Why Blocklists Can't Keep Up With AI-Built Phishing Sites
Attackers are spinning up throwaway phishing pages faster than defenders can list them. Researchers at Push Security argue the fix is watching what a page does, not where it lives.

Cyber Operations Are Now a Core Part of Modern War, Says CrowdStrike Co-Founder
Dmitri Alperovitch argues that hacking campaigns no longer just support military conflicts, they signal them, shape them, and sometimes replace them.

Kali365 Phishing Kit Turns Microsoft's Own Login Page Against US Firms
A new criminal toolkit tricks staff into approving attacker device codes on genuine Microsoft screens, handing over long-lived access to email and cloud files.

Linux Kernel Flaw 'OVSwrap' Hands Local Users Root on Around 800 Builds
A memory corruption bug in Open vSwitch, tracked as CVE-2026-64531, lets ordinary users on default Linux systems become administrator, and a working exploit is already public.

Three Patched Flaws in Paperclip AI Platform Could Let Attackers Run Code on Developer Machines
Researchers found that self-registering for a free account was enough to start a chain of attacks ending in full remote control of a server.