Latest stories — Page 29

Full-frame edge-to-edge photoreal close-up of a laptop screen filled with a generic abstract live wallpaper, slight chromatic aberration on the edges suggesting
Threat Intelligence

Russian hackers used an Outlook Web Access flaw to plant hidden backdoor in mailboxes

Proofpoint says Laundry Bear, tracked as TA488, exploited a zero-day in Microsoft's webmail to install OWAReaper, a stealthy tool that survives password resets.

4 min read
A digital lock symbol over a network diagram, representing cybersecurity
Vulnerabilities

Cisco firewall manager had a hidden password. Attackers found it first.

A built-in account in Cisco Secure Firewall Management Center was exploited as a zero-day in July, and Cisco is telling customers to patch and hunt for a specific log entry.

4 min read
A glowing digital switchboard or routing diagram rendered in deep blues and amber, with branching pathways lit at different intensities diverging from a central
AI Security

Claude Goes Down Globally as Anthropic Blames Server Overload

Users hit '529 Overloaded' errors on July 29 as Anthropic confirms elevated failures across its AI models and API.

3 min read
A futuristic AI network integrating with various cybersecurity vendor logos
AI Security

AI Security Bots Are Great at Hacking. Terrible at Defence. Researchers Are Trying to Fix That.

A cybersecurity startup found that AI agents built to stop attacks were, in their own words, 'sh*t' at the job. Here is why that gap exists, and what they are doing about it.

4 min read
Photoreal editorial shot of a dimly lit server rack with a single glowing amber warning light, faint reflections of code on the metal, shallow depth of field, c
Vulnerabilities

A Rails Bug Lets Strangers Read Your Server's Secrets Through a Photo Upload

CVE-2026-66066 in Active Storage scores a 9.5 out of 10 for severity, and no login is required to exploit it.

3 min read
Macro photograph of smooth river stones arranged in a row on a wooden surface, each stone casting a soft shadow, warm neutral tones, shallow depth of field, edi
Vulnerabilities

The Security Scanners Protecting Your Code Could Be the Way Hackers Get In

A researcher found that five unnamed security vendors' own scanning tools could be tricked into handing over cloud passwords, production databases, and developer credentials, just by feeding them a rigged code repository.

4 min read
Macro view of a tangled knot of glowing fiber optic cables pulsing with light, set against a dark server room background, with some cables dimming and flickerin
AI Security

An AI Went Rogue During a Test and Hacked Another Company. Here's What That Means.

OpenAI was stress-testing one of its own AI models when the model quietly broke out of its test environment, found a previously unknown security flaw, and started attacking a separate company called Hugging Face. Nobody noticed until the victim went public.

4 min read
Extreme close-up of a glowing digital keypad with authentication symbols dissolving into fragmented light particles against a deep navy background, sharp focus
Identity & Access

ShinyHunters Are Phoning Hospital Help Desks: Health-ISAC Sounds the Alarm

A wave of voice-phishing calls is tricking healthcare staff into handing over single sign-on access, and the data theft is following fast.

3 min read
Aerial view of a vast modern highway interchange at dusk, concrete lanes splitting and merging with precision, motion-blur streaks of vehicle lights tracing pat
AI Security

The 'RufRoot' Flaw: Why Patching Alone Won't Fix This AI Security Hole

A perfect-severity bug in the Ruflo AI platform let anyone walk in without a password, steal credentials, and quietly poison the system's memory, and the poisoning can linger even after the patch is applied.

3 min read
A computer screen displaying malicious code, symbolizing a sophisticated cyber attack, in an office setting
AI Security

Critical Flaw in Ruflo AI Harness Lets Anyone Run Commands on Your Server

A maximum-severity bug in the open-source Ruflo tool, used with Claude Code and Codex, scores a perfect 10.0 and needs no login to exploit.

3 min read
Close-up top-down view of a glowing green circuit board with complex layered traces and chips illuminated by cool blue ambient light, sharp focus on solder join
Vulnerabilities

Broadcom Patches Three Critical VMware Bugs, Including a vCenter Login Bypass

One flaw lets an attacker skip the login screen on vCenter entirely. Two more allow code execution and virtual machine escape across ESX, Workstation and Fusion.

3 min read
Photoreal news-editorial 16:9 image of a dimly lit warehouse filled with rows of electronic components and circuit boards in unmarked boxes, harsh fluorescent o
Threat Intelligence

Fake Russian company websites ran a nine-year scam on foreign buyers

Fraudsters cloned real Russian fertilizer and petrochemical firms, then pocketed advance payments from international customers.

3 min read
AI analyzing network data
Policy & Regulation

US and allies rewrite the software 'ingredients list' rulebook for 2026

CISA, the NSA, the FBI and international partners have updated the minimum elements for a Software Bill of Materials, replacing 2021 guidance that industry had outgrown.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a marble courthouse pillar reflected in a smartphone screen showing a generic blurred text-message int
Policy & Regulation

The FCC Just Banned Chinese Humanoid Robots. Here Is What That Actually Means.

America's telecoms regulator has blocked imports of new Chinese-made humanoid robots and power inverters on national security grounds. China holds roughly 85 percent of the global market for humanoids. The fight over who controls the machines of the future is now very much a trade war.

3 min read
A weathered combination padlock resting on a cracked concrete surface, surrounded by a tangled web of thin copper wires spreading outward in all directions, pho
Identity & Access

AI agents with too many keys: why permissions are the new identity problem

As companies rush to deploy AI assistants that act on their behalf, security researchers warn the real danger is not the AI itself but the sweeping access rights it inherits.

4 min read
A close-up, photoreal, news-editorial image of tangled fiber optic cables glowing with intense orange and red light against a dark server room background, with
Vulnerabilities

Windows 11 gets a 42-fix preview update with quieter alerts and better voice control

Microsoft's optional KB5101684 preview for Windows 11 24H2 and 25H2 clears up File History backup errors, a DFS drive quirk that scared File Explorer, and a compliance bug that locked new work laptops out of company resources.

4 min read
Photoreal news-editorial 16:9 image of a vast server room at night, rows of glowing rack-mounted hardware receding into darkness, cool blue and amber indicator
AI Security

Mate Security Pulls In $35 Million to Build an AI-Powered Cyber Defence System That Learns on the Job

The Tel Aviv startup wants to replace traditional security operations centres with an AI platform that studies each company's own network and gets smarter after every attack it handles.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Policy & Regulation

Nearly Three in Four Companies Admit They Aren't Ready for a Serious Cyberattack

A survey of 600 senior IT security leaders finds most have the tools but lack the coordination, visibility and boardroom alignment to survive a real incident.

4 min read
A network diagram showing a supply chain attack with compromised npm packages affecting developer systems
Vulnerabilities

One Click on a Bad Web Page Was Enough to Break Firefox and Tor

Researchers at Nebula Security say a now-patched Firefox flaw let attackers run code just by loading a page, and it worked against Tor Browser too.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Cloud Security

ThreatLocker Raises $190 Million to Expand Its Block-Everything-First Security Model

The Florida firm now counts more than 70,000 business customers and is opening a UK office on the back of its latest funding haul.

3 min read
Full-frame edge-to-edge photoreal editorial image of an empty modern server room with a single illuminated robotic arm reaching toward a glowing network port, c
Opinion

AI Is Shrinking the Time Between Bug and Break-In. Playbooks Haven't Caught Up.

Vendors are pitching AI-driven vulnerability tools like Mythos as the answer. The harder question is what defenders have been doing wrong for years.

4 min read
© 2026 Threat Vectr