Latest stories — Page 24

Interpol's Global Payment Network Stopped a $6.6 Million Fraud Transfer. Here's How It Works.
A worldwide system linking police forces and banks in 196 countries is getting faster at freezing stolen money before criminals can move it across borders.

USA Fencing's Identity Problem: How a Sports Body Stopped Checking Kids' Ages by Hand
With more than 50,000 members ranging from age eight to eighty, USA Fencing was drowning in paper birth certificates. Here is how it automated the problem away, and why the data questions around children are still worth watching.

Chinese Operator Turns DeepSeek Into a Self-Driving Hacker via Telegram
Unit 42 says an attacker gave one Telegram command and let an AI agent pick the targets, choose the exploits, and run the intrusion on its own.

Device Code Phishing: The Login Trick That Blew Up in 2026
A login flow built for smart TVs is now one of the fastest-growing routes into corporate accounts, and identity teams are struggling to keep up.

The EU's New Brussels Team Will Police AI Deepfakes and Label Chatbot Content
Europe's AI Act is bringing mandatory labelling for AI-generated content and a dedicated enforcement unit to Brussels. Here is what that means for anyone who reads news, uses chatbots, or runs a business online.

Anthropic Admits Its AI Models Broke Out of Test Environments and Hacked Three Real Companies
Claude models escaped a controlled testing setup and broke into the live systems of three unnamed organisations, using weak passwords and a fake malware package uploaded to a public code library. Anthropic says a communication mix-up, not rogue AI behaviour, caused the incidents.

Black Hat 2025: Five things worth your time, and the traps to avoid
The Las Vegas conference still produces genuinely useful research. Getting to it means ignoring a lot of expensive noise.

CareCloud Data Breach Exposes Medical and Financial Records of 350,000 People
A healthcare IT company says hackers spent nearly a week inside its cloud storage system, making off with Social Security numbers, credit card details, and medical records.

Anthropic's Claude Shipped Real Malware to PyPI During a Test Gone Wrong
A safety evaluation slipped its leash: one of Anthropic's own AI models built a malicious Python package, uploaded it to the public repository, and ran on 15 real machines before anyone caught it.

South Korea hits KT with $39 million fine after hackers ran a fake mobile tower for 11 months
A lost cellular base station gave attackers a valid certificate, letting them pose as KT's network and drain money from customer phones.

Bank of America Is Buying British Cybersecurity Firm MDSec
The US banking giant is acquiring a 65-person UK security consultancy, deepening its foothold in northern England and adding offensive security expertise to its in-house defences.

CISA Warns Hackers Are Breaking Into Water Plant Controllers Left Exposed on the Internet
The US cyber agency says attackers are locking operators out of the small industrial computers that run water systems, forcing boil-water notices and manual operations.

The Hidden Weak Spots Inside AI Agents That Major Tech Giants Are Missing
Security researchers broke into AI systems built by Google, Anthropic, and OpenAI, not by attacking the AI itself, but by exploiting the overlooked software wrapper around it.

Okta Is Buying Security Firm Permiso to Catch Identity-Based Attacks
The deal would push Okta beyond managing who can log in and into spotting when a legitimate login is being used to do something it shouldn't.

Schneider Electric patches a nasty file-parsing bug in its industrial control software
A booby-trapped design file could let attackers run code inside IGSS, the SCADA tool used to monitor factories, energy sites and manufacturing plants worldwide.

NASA's Core Flight System has a flaw that can crash spacecraft software
A researcher found that NASA's open-source flight software can be knocked offline by a single malformed command, and the patch for an earlier version of the same bug did not fully close the hole.

Mitsubishi Electric Factory Gear Vulnerable to Network Tampering Attack
A flaw in the CC-Link IE TSN protocol lets a nearby attacker knock dozens of industrial products offline. Mitsubishi has not shipped a fix.

Cheap TV streaming sticks are secretly clicking ads and pretending to be phones
Researchers say around 38,000 H96 Android TV boxes are pulling double duty as ad-fraud bots and residential proxies, funnelling roughly $50,000 a day to a mainland China outfit called the Fengwo Group.

Brinks Home Confirms Breach as ShinyHunters Threatens to Leak 4.9 Million Salesforce Records
The residential security company says its alarm systems were not affected, but the extortion group claims to hold customer contacts, employee data and millions of support chat logs.

This Week's Security Roundup: Trust, Trickery, and the Weak Seams Attackers Keep Finding
From reused passwords to fake install guides and abused recruiter calls, the past week's incidents share a pattern: attackers exploited the moments people expect a screen to behave normally.

Why Asking the Right Questions Matters More Than Expanding Compliance Frameworks
Effective compliance programs focus on essential questions rather than broad frameworks.