Latest stories — Page 25

Burnout, Courage, and 'Good Enough': What One Top Security Chief Learned on the Way to the C-Suite
Ping Identity's CISO Russ Kirby opens up about the mindset that kept him going through a decade of high-pressure security roles, and what still worries him today.

Varonis pitches 'intent-based' guardrails for AI agents that stray off task
Agent IBAC watches what an AI agent is trying to do, not just what it is allowed to touch, and pulls the brakes when the two drift apart.

Fake Adobe and Zoom Update Prompts Slip Remote-Control Software Onto Victim PCs
Securonix researchers say the SMOKE#SCREEN campaign is tricking staff into installing ConnectWise ScreenConnect, handing attackers a quiet way back in.

Credential-Stealing Worm Spreads Across npm Packages
A worm targeting npm packages has affected hundreds of software components, raising security concerns for developers.

Your Email AI Assistant Could Be Turned Against You, Researchers Warn
Security researchers have shown how the AI chatbots built into modern email platforms can be hijacked to impersonate colleagues, steal account access, and set up financial fraud, all without sending a single suspicious link.

AI Meeting Bot Tl;dv Left Government and Corporate Calls Wide Open
A security researcher found a misconfigured database in the popular meeting-recording app tl;dv that let anyone see live government and corporate video calls, and, in most cases, join them uninvited.

When Anyone Can Hack: How AI Is Turning Beginners Into Capable Attackers
The old ranking of hackers by skill is breaking down as chatbots hand novices tools that used to take years to learn.

Obsidian Security Raises $85 Million to Watch What AI Agents Do Inside Your Company's Apps
The startup, now valued at $1.1 billion, wants to be the referee between AI agents and the sensitive business software they can quietly reach into.

Fifteen Flaws in TP-Link's Auto-Setup System Could Hand Hackers Control of an Entire Business Network
Security firm Forescout found serious weaknesses in the technology TP-Link uses to automatically configure routers, switches, and cameras. Some flaws can be chained together to let an outsider quietly seize control of every device on a network.

cPanel patches critical database flaw that let hosting customers run SQL as root
A newly disclosed bug, CVE-2026-58048, crossed the line between a single hosting account and the server's master database identity. cPanel has shipped a targeted fix.

Google's AI Coding Assistants Could Be Tricked Into Leaking Secrets and Sabotaging Code
A newly exposed attack technique shows how a low-level AI agent inside Google's development toolkit can be manipulated into poisoning a higher-trust agent, giving attackers a path to steal credentials and tamper with software projects.

Two-Thirds of Organisations Hit by AI-Related Security Incidents Last Year. The Weak Link Is the API.
A surge in AI adoption has quietly created a new kind of back door into company systems. Experts say most businesses are focused on the wrong part of the problem.

The criminals behind the Minnesota water attacks may have a better backup of your plant than you do
Hackers hit more than 30 small water utilities in two days. The most alarming detail isn't how they got in, it's that they may have walked out with the only complete copy of control logic the operators ever had.

Madera Community Hospital Breach: 150,000 People's Medical and Financial Data Stolen
A California hospital spent nearly a year reviewing stolen files before telling patients their Social Security numbers, health records, and bank details had been taken. The criminal group that attacked them eventually dropped its ransom demand.

Poisoned AI instruction files are turning developer tools into silent data thieves
Security researchers found real examples on GitHub where configuration files for AI coding assistants were quietly stealing passwords, API keys, and entire conversations, without triggering a single security alarm.

Microsoft Paid Out $20 Million in Bug Bounty Rewards This Year
More than 560 security researchers from 64 countries were paid to find and report software flaws. Not everyone is happy about how the company handled the work.

New York Hands $9 Million to 153 Water Utilities to Plug Cyber Gaps
The grants come as hackers step up attacks on water and wastewater systems across multiple US states. Here is what the money buys, and what it means for the people who drink the water.

Russian hackers turn hotel Wi-Fi into a trap for Microsoft 365 logins
Microsoft says APT29 sub-group Storm-2945 has been hijacking guest Wi-Fi at hotels and conference centres since May, planting two new malware families to steal corporate accounts.

A Decade of Iranian Cyberattacks on America: What We Know
From wiping casino hard drives to targeting children's hospitals, a pattern of disruptive attacks tied to Iran stretches back more than a decade. Now investigators are asking whether the same playbook was used against water systems in seven US states.

UK Government Investments Agency Exposed Data on 51 Officials for 40 Hours
A security failure at the public body that manages taxpayer stakes in companies like Channel 4 and the Post Office left sensitive management records and personal details of more than 50 civil servants sitting openly accessible online for nearly two days.

Fake RingGo Texts Are Tricking Drivers Into Handing Over Bank Details
Scammers are sending fraudulent parking-fee demands that impersonate the RingGo app, banking on the fact that most drivers genuinely can't remember every parking session they've paid for.