Latest stories — Page 27

Thermo Fisher patches DNA analysis flaw that could let evidence files be quietly altered
A vulnerability in Applied Biosystems human identification software could allow near-invisible edits to forensic DNA files before analysts ever see them.

AI Isn't Bringing New Attack Tricks. It's Making the Old Ones Much Faster
Security experts say the lesson from AI-assisted hacking isn't panic about sci-fi threats. It's that the basics your organisation has been ignoring for years just got a lot more dangerous to skip.

Three flaws in Hugging Face's Diffusers library let booby-trapped AI models run code on your machine
Researchers found ways to bypass the safety switch meant to stop untrusted AI models from executing hidden instructions when loaded.

N-able confirms hackers seized N-central servers through a login-bypass flaw
The remote-management platform's first patch didn't hold. A second fix, in build 2026.3.1.7, closes CVE-2026-18577.

Cybersecurity Then and Now: What Actually Changed (and What Didn't)
A look at how the threats facing ordinary people and the businesses they deal with have shifted over the decades, and why some of the oldest tricks still work best.

Iranian hackers suspected in attack on 30 US water systems
A wave of cyberattacks hit Minnesota water infrastructure on Sunday and Monday, briefly cutting supply to one town. Investigators say the methods match a known Iranian-linked group, though formal attribution has not yet been made.

OpenAI's unreleased 'Astra' model reportedly cracked 10 maths problems that stumped humans for decades
The lab says an internal version of its next big model produced fresh results in geometry, cryptography and group theory, at a compute cost of around $2,000 per problem.

Chrome Moves to Block Malware That Hijacks Your New Tab Page
Google is testing a defence that stops malicious software from posing as an IT administrator to lock unwanted extensions into consumer Chrome installs on Windows and macOS.

Victorian Parliamentary Committee Exposes Cult Survivors' Email Addresses in Mass Mailing Blunder
A parliamentary committee sent its final report on cult harm to 330 visible recipients, accidentally revealing the contact details of abuse survivors to the very groups they had fled.

Trump Weighs AI Controls After OpenAI's Tools Broke Into Other Companies' Systems
OpenAI has admitted its AI tools acted outside their intended limits at least twice in a week. Now the White House is asking how much control the government should take over artificial intelligence, and what that means for the race against China.

OpenAI's AI Agent Broke Into Hugging Face, Then Went Looking for More Targets
An artificial intelligence agent built by OpenAI tried to hack several companies on its own initiative, raising hard questions about who is responsible when a machine decides to start attacking things.

A Coldcard Firmware Bug From 2021 May Have Cost Bitcoin Holders $70 Million
Researchers say a four-year-old flaw in a popular hardware wallet let one attacker sweep nearly 1,200 addresses in under an hour.

A Security Startup Just Raised $19 Million to Help Companies Spend Smarter on Cybersecurity
Balance Theory wants to give security leaders a single system for deciding where to put their money. Its platform already tracks more than $1 billion in security spending.

Adobe Patches Perfect-10 Flaw in Campaign Classic That Lets Attackers Run Code Remotely
A permission check gone wrong in Adobe's marketing automation platform could hand attackers full control, with no user interaction needed.

Cyber-attack on England's Department for Education exposes 607,000 records
Contact details for individuals and organisations were taken in a breach affecting two government education portals. No bank details were stolen, but the incident lands as UK school and college cyber-attacks hit record frequency.

Amgen Says Attackers Stole Patient Data From Third-Party Cloud Systems
The biotech giant disclosed the breach in an SEC filing after detecting unauthorized activity in July, but has not named the cloud providers involved or how many patients are affected.

Arch Linux freezes package adoptions after wave of malware sneaks into user repository
A stealer that harvests browser logins, crypto wallets and SSH keys has spread through more than 200 community-maintained Arch packages, forcing the project to hit pause.

Adform ad platform hijacked to swap crypto wallet addresses on visitor clipboards
A tampered script served through the Danish ad-tech firm's network quietly replaced Bitcoin and Ethereum addresses with attacker-controlled ones, redirecting payments from anyone who copied a wallet on an affected site.

Chinese-Speaking Hackers Hit Central Asian Governments With Two New Malware Families
Researchers link a spying campaign against Afghanistan, Kyrgyzstan and neighbours to a Chinese-speaking crew using tools tracked as OctLurk and SilkLurk.

CISA Rewrites the Rules for Software Ingredients Lists. Critics Say It's Not Enough.
A 17-nation coalition has updated the global standard for tracking what goes into software. The framework is broader than its 2021 predecessor, but security experts argue it sidesteps the hardest questions.

OpenAI cuts GPT-5.6 API prices by up to 80%, adds a faster paid tier
Luna drops to $0.20 per million input tokens, Terra falls 20%, and a new Sol Fast mode runs 2.5 times quicker for double the price.