Latest stories — Page 3

SynkLoader: The Fake IT Help Desk Trick Hiding Behind a Phony Windows Lock Screen
Attackers posing as internal IT are pushing a new modular malware through Microsoft Teams, complete with a convincing fake login prompt built to steal Windows passwords.

New Android malware slips into cars through the dashboard's own update system
Kaspersky says the DoFun head unit malware turns infected vehicles into ad-fraud engines and proxy relays for cybercrime.

Microsoft's Own Antivirus Driver Can Be Turned Into a Weapon at Boot
Check Point researchers show how BTR.sys, the trusted cleanup tool inside Microsoft Defender, can be steered to wipe files and registry keys before Windows even finishes starting.

Former NSA Director Paul Nakasone Opens Private Security Advisory Firm
The retired four-star general who ran America's signals intelligence agency for six years is now taking his expertise to paying clients in government, business, and beyond.

9,300 leaked AWS keys still work, and 768 hand over full control of a company's cloud
Truffle Security tracked exposed Amazon cloud keys for four years. Most were never rotated, and 88% still logged in on the day of testing.

Zombie Cards, Cut Cables, and a Botnet: The Week's Cybercrime Stories You May Have Missed
A DDoS attack on encrypted messaging app Threema, a new Linux botnet called Evooo1Bot, and T-Mobile physically severing a cable to stop an intrusion all made news this week. Here is what happened.

Researchers Find Way to Hide Malicious Instructions Inside Encrypted AI Prompts
A new technique called 'Cryptographic Context Injection' slips harmful commands past the safety filters built into Grok and Gemini by wrapping them in encryption that only the AI unwraps.

New Phishing Toolkit Registers Attacker Passkeys to Survive Password Resets
A tool called iAuthFlow V2 lets criminals plant a login credential they control inside your account, so changing your password does nothing to lock them out.

Can you actually stay private online? The case for separate digital identities
Reusing the same email, phone number and card everywhere hands data brokers and criminals a ready-made profile. Compartmentalising your identity blunts that.

Microsoft brings back a Classic Outlook look for people stuck on the new app
A new toggle inside Outlook on the web and the New Outlook for Windows lets users switch to a theme that mimics the old client, easing a migration many staff have resisted.

OpenAI's AI Models Broke Into a Real Website. The Safety Fixes Came After.
An OpenAI test model wandered off its leash, broke into an outside website, and exposed the kind of basic containment gaps that experts say should have been closed before any high-risk testing began.

CISA gives federal agencies two weeks to fix TrueConf video server flaws already being abused
Two critical bugs in the self-hosted conferencing platform let attackers run code without a password. Hacktivists have been using them since July.

Wazuh Adds AI Assistants to Speed Up Security Teams Drowning in Alerts
The open-source security platform is bolting large language models onto its dashboards, aiming to cut the hours analysts spend triaging attacks.

Hackers Hide Malware Instructions in FTP Server Greetings
A quiet trick spotted by SOCRadar uses FTP welcome messages to smuggle commands onto Windows machines, dropping two new remote-control tools called E4del and PINHOLE.

SickKids Says Third-Party Software Flaw Exposed Employee and Applicant Data
Toronto's largest paediatric hospital confirms a breach affecting HR records. Patient files were not touched.

OpenAI Wants to Catch Misuse Without Reading Your Chats
A new system called Private Safety Processing looks for patterns of harmful behaviour across multiple conversations, but never shows OpenAI staff the actual messages. Here is what that means, and why it matters.

AI Arms Race: Why Smart CISOs Are Choosing Their Battles, Not Fighting All of Them
Attackers are using artificial intelligence to move faster, employees are leaking sensitive data into consumer AI tools without realising it, and the window to fix vulnerabilities before criminals exploit them is shrinking. Here is what security leaders should actually prioritise.

Defence Contractors Say They Feel Ready for the Pentagon's New Security Rules, But Can't Actually Prove It
Two new surveys find that American defence suppliers are more confident than ever about meeting the Pentagon's cybersecurity standard, while their ability to demonstrate that confidence on paper is getting worse, not better.

Microsoft Pushes 22 Security Fixes, Six Rated Maximum Severity
A batch of patches covers Microsoft's cloud and identity products, with six flaws scoring a perfect 10 out of 10 on the severity scale. Most fixes apply automatically, but one Defender vulnerability is still waiting for a patch.

Microsoft Confirms Critical Entra ID Flaw Was Exploited, Says No Customer Action Needed
Redmond patched a perfect-10 remote code execution bug in its cloud identity service and says the fix was applied on its side.

Thirty US States Take Meta to Trial Over Child Safety, Seeking Up to $1 Trillion
A federal jury trial launched this week could force Facebook and Instagram to strip out some of their most addictive features, and cost Meta more money than most countries earn in a year.