Latest stories — Page 20

Three Patched Flaws in Paperclip AI Platform Could Let Attackers Run Code on Developer Machines
Researchers found that self-registering for a free account was enough to start a chain of attacks ending in full remote control of a server.

Leaked n8n Tokens Left 321 Live Automation Servers Open to Anyone With a GitHub Search
GitGuardian found thousands of API keys for the popular workflow tool spilled into public code repositories, handing attackers a straight path to connected apps and stored secrets.

311,000 People's Medical and Financial Records Stolen from Brown Health Medical Group in Massachusetts
A hack at the group's Hawthorn location last December exposed Social Security numbers, credit card details, and medical records for more than 311,000 patients and staff. The breach sat undiscovered for six months.

Cybersecurity Groups Draft 'SAFE' Rules for Sharing AI Incident Data
A coalition of more than 120 companies, including Nvidia, Cisco and Amazon, is asking for public feedback on a proposed framework that would let organisations quietly report AI security failures and share what they learned with everyone else.

One C2 Kit, 30 Customers, Two Governments: How Criminal Infrastructure Is Hiding State Hackers
A security researcher traced a single command-and-control tool to roughly 30 separate operators, including two with suspected government ties. The finding breaks a core assumption most security teams quietly rely on every day.

The AI framework you choose is also a security choice
A researcher ran the same attacks against four popular AI agent frameworks and found the most vulnerable was 2.6 times more likely to be broken than the most resistant, using the identical AI model throughout.

CISA Adds Three Actively Exploited Bugs to Its Must-Patch List
A critical Langflow flaw joins Apache Tomcat and N-central issues on the U.S. government's Known Exploited Vulnerabilities catalog after evidence of live attacks.

Angola's Biggest Mobile Network Hit by Cyberattack on the Day It Went Public
Unitel, which carries more than two-thirds of Angola's mobile traffic, suffered a crippling attack on July 28, the same morning its shares began trading on the stock exchange. Four days later, 4G and 5G service was still down.

The Essential Role of Kill Switches in AI Systems
Recent incidents highlight the need for quick shutdown mechanisms in AI, emphasizing both security and cost management.

AI Agents Are Going Rogue, and Security Teams Are Scrambling to Keep Up
From OpenAI models breaking out of their sandboxes to malicious instruction files turning AI assistants into data thieves, a wave of new research shows the AI threat landscape is moving faster than most defences can follow.

Trojanised QuickFox VPN installer plants stealth backdoor on users' PCs
Fortinet researchers say a tampered version of the China-focused VPN app has been serving the FDMTP backdoor since at least August 2025, with tradecraft that overlaps activity tracked as Silver Fox.

OpenAI's Software 'Went Rogue' and Hacked Hugging Face, CEO Says
The head of AI startup Hugging Face told CBS News that technology built by OpenAI broke into his company's systems without authorisation. It is a rare public accusation that AI tools can act in ways their makers never intended.

XCSSET Malware Returns With Chrome Hijacker and Fake Telegram App, Hitting Mac Developers
A refreshed version of the XCSSET macOS malware is spreading through poisoned Xcode projects on GitHub, stealing credentials and hijacking cryptocurrency payments.

Hackers Are Using a Legitimate Remote-Access Tool to Spy on Companies, and Your Antivirus Won't Notice
A campaign called Smoke#Screen tricks employees into installing ScreenConnect, a genuine remote-support program, which then hands criminals full control of the victim's computer while looking completely normal to security software.

77 fake developer tools on Open VSX quietly mapped coders' machines for a week
The counterfeit extensions copied real names from AMD, Azure, Salesforce and others, then phoned home to a domain registered days earlier.

Greatness Phishing Kit Adds a New Trick to Steal Logins Without Passwords
The rented phishing toolkit now abuses Microsoft's own login flow to walk around multi-factor authentication.

Airlock Digital Wants to Watch What Your AI Assistant Actually Does, Not Just Whether It's Allowed to Run
A new product layer from Airlock Digital aims to track AI agents command by command, in real time, on the devices where they do their work.

Are Your AI Safety Tools Actually Watching What Employees Type?
Most companies use security tools designed for files and websites, not live AI conversations. That gap is becoming a serious problem.

Tel Aviv Security Firm Oligo Raises $60 Million to Catch Hackers in the Act
Oligo Security has now raised $140 million total to build software that watches running apps in real time and blocks attacks the moment they happen, rather than waiting for a patch.

Burnout, Courage, and 'Good Enough': What One Top Security Chief Learned on the Way to the C-Suite
Ping Identity's CISO Russ Kirby opens up about the mindset that kept him going through a decade of high-pressure security roles, and what still worries him today.

Varonis pitches 'intent-based' guardrails for AI agents that stray off task
Agent IBAC watches what an AI agent is trying to do, not just what it is allowed to touch, and pulls the brakes when the two drift apart.