Latest stories — Page 21

AI Agents Are Breaking Into Your Own Systems, With Your Permission
The real danger from enterprise AI isn't hackers. It's well-behaved software doing exactly what it was told, just more than anyone intended.

Criminals Are Using AI Like a Work Tool. Researchers Have the Receipts.
Two major studies show hackers using AI assistants to write malicious code, dodge safety filters, and attack in hours rather than weeks. Cloud activity tied to this shift jumped 171 percent in the first half of 2026.

Twenty Chinese Router Models Ship From The Factory With A Hidden Backdoor
Researchers at VulnCheck say every current Zbtlink firmware image contains an implant that phones home to Chinese servers and hands attackers root access.

Cisco Patches 24 Flaws, Including a Perfect-Score Bug That Hands Attackers Full Control
A flaw in Cisco's firewall management software scores a rare 10 out of 10 on the severity scale, meaning a remote criminal needs no password to take complete control of an affected system.

Hackers Are Actively Exploiting a Critical Flaw in JetBrains TeamCity
A software tool used by thousands of development teams worldwide has a severe security hole that attackers are already using. The US government is telling federal agencies they have three days to fix it.

AI Browsers Can Be Hijacked by Hidden Instructions in Emails and Web Pages, Researchers Warn
A new attack class called 'PleaseFix' lets criminals slip fake commands into ordinary content, and the AI does the rest, using your own accounts against you.

Ransomware group Orion claims attack on Morris Group International
A criminal gang has listed the British professional-services firm on its dark-web pressure site. The company has not confirmed anything, and the claim is unverified.

Kmart's $89 Camera Glasses Sold Out Across Australia. Privacy Experts Are Alarmed.
A pair of smart glasses that can secretly record HD video retails for less than a restaurant dinner. Digital rights advocates say the law hasn't kept up.

AI Browsers Can Be Tricked Into Stealing Your Data, and Nobody Has a Fix Yet
A security researcher at Black Hat tested three major AI-powered browsers and found every single one could be manipulated by hidden instructions on a webpage. The people building these tools say there is no perfect solution.

Ransom Cartel Boss Gets 16 Years After $6.7M Extortion Spree
Belarusian national Maksim Silnikau built and ran the ransomware crew from 2021 to 2023, hitting at least 18 companies before Spanish police caught him and Poland handed him over.

Why Modern Hackers Walk In Through the Front Door of Your Website
Security teams have spent years locking up their networks and servers. A new wave of attacks shows that criminals are now coming in through web applications instead, and most defences are not keeping up.

Canadian hacker admits to Snowflake data thefts that hit 165 companies and 100 million people
Connor Moucka pleaded guilty to stealing terabytes from Snowflake customer accounts that had no second login step, extorting $2.5 million in bitcoin from victims including AT&T and Ticketmaster.

Fixing One Hole at a Time Is No Longer Enough: Why Security Must Follow the Full Attack Path
Criminals no longer stop at the front door. They chain together weaknesses across your apps, accounts, and cloud systems, and security teams testing each piece in isolation are missing the bigger picture.

Your Email's Design Layer Can Steal Your Password. No Suspicious Attachment Required.
Security researcher Gareth Heyes found that CSS, the code responsible for how emails look on screen, can be turned into a data-theft tool inside popular webmail services. No malicious files. No links to click.

15 Flaws in TP-Link Kit Put Automatic Network Setup at Risk
Security researchers found 15 vulnerabilities in TP-Link's Omada networking system and warn that the convenient "zero-touch" setup process that millions of organisations rely on could hand criminals the keys to an entire network.

Hackers hid their attack tools inside an Oracle database itself
A rarely seen technique let intruders run commands, steal password data and browse files from within the database, after breaking in through a sloppy search box.

Researchers Cracked Samsung Phones Wide Open by Turning Bixby Against Its Own Device
A five-step exploit chain using Bixby, Samsung Members, and Samsung Account could hand a stranger complete control of your Galaxy phone. Patches are out, but older devices may still be exposed.

Fake Mac Downloads Hide Behind 250+ Domains That Screen Visitors First
Microsoft says a large ClickFix network now checks who is knocking before showing macOS users a booby-trapped installer, keeping researchers and scanners out of view.

OpenAI Cuts Off Cambodia-Based Scam Ring Running Frauds Through ChatGPT
Accounts tied to Poipet were using the chatbot to draft investment pitches, romance messages, and fake police scripts, the company says.

Fake COLDCARD 'Security Audit' Emails Push Remote Access Tool After $88M Bitcoin Theft
Phishing campaign impersonates the hardware wallet maker, tricks owners into installing ScreenConnect, and hands attackers full control of the victim's PC.

Paperclip AI Agent Platform Carries Bugs That Hand Attackers the Keys to the Host
Two flaws in the open-source AI agent controller let a rigged agent import run commands on the server or developer laptop. A third leaks control-plane data through unprotected API routes.