Latest stories — Page 30

The Man Who Meets You at Your Worst: Inside Melbourne Airport's Only Chaplain
Martyn Scrimshaw has spent nine years walking the terminals of Melbourne Airport, helping the homeless, the scammed, the grieving, and the fleeing. Now a film starring Hugo Weaving is bringing his work to a wider audience.

ChatGPT Broke Out of Its Test Cage and Hacked Hugging Face. Now Everyone Has Questions.
OpenAI's AI hacking agents escaped a controlled test environment and attacked a major AI platform on their own. Was it a safety failure, a marketing stunt, or both?

Arista rushes fix for VeloCloud flaw already being used in attacks
A perfect-10 command injection bug in on-premises VeloCloud Orchestrator lets anyone on the network take over the box. Attackers found it first.

Two Cloud Giants, Two Flaws, Zero Bug Bounties: The 'Confused Deputy' Problem That Won't Go Away
A security researcher found ways to silently hijack administrator control over both Microsoft Azure and Google Cloud infrastructure. Neither company paid a reward. One quietly fixed its flaw without saying so.

How the FBI Took Down LockBit by Destroying the One Thing Criminals Can't Easily Replace: Trust
Operation Cronos didn't just seize servers. It turned LockBit's own website against its partners, shattered the group's reputation, and cut ransom attacks in the US by nearly 80 percent.

The Cheapest Way to Beat an AI Security System Is to Read Its Rulebook
Confidence in autonomous hacking tools has collapsed. A researcher says the real problem runs deeper: the governance rules we write to keep AI security systems safe can become a weapon in an attacker's hands.

Dysphoria Botnet Rebuilds on Blockchain After March Takedown
Researchers at CNCERT and XLab say the IoT botnet now hides its control servers behind blockchain domains and routes traffic through infected devices, making shutdowns harder.

Apple sued after fake Sparrow Wallet app on App Store drains $1.8M in Bitcoin
Three users say a counterfeit crypto wallet, promoted in App Store collections, tricked them into handing over the secret recovery phrases that guard their coins.

Anyone Can Now Attack Unpatched vBulletin Forums Thanks to Public Exploit Code
Working exploit code for a critical vBulletin flaw is out in the open, and it lets a stranger run commands on the server without logging in.

ShinyHunters claims Ernst & Young breach, points to supply-chain attack
The extortion crew says stolen credentials from a third-party supplier gave them access to EY's Jira, GitHub and Azure. The accounting giant has not confirmed the group's role.

Weekly Threat Recap: A Rogue AI Agent, Old Bugs Back at Work, and Exposed Systems Nobody Fixed
OpenAI reports an AI agent that stepped outside its lane, while attackers keep finding shelter in tools defenders already trust.

The AI helpers your staff installed without telling IT
Autonomous AI agents are quietly attaching themselves to company accounts, often with wide permissions and no oversight. Here is what that means and how to get a grip on it.

n8n Patches Sandbox Escape That Let Editors Run Commands on the Server
A flaw in the popular automation platform let anyone with workflow-editing access break out of the safe zone and run system commands. n8n has issued a fix.

Fake Microsoft Teams Update Pushes Remote-Control Tools onto Victims' PCs
A phishing run tracked as Operation BlueDash uses a bogus 'secure document' lure and a counterfeit Microsoft Store page to install legitimate remote-access software on target machines.

Nvidia Leads 40-Company Coalition to Build Open Security Tools for AI Systems
The Open Secure AI Alliance wants shared, openly inspectable tools to become the standard defence against attacks on artificial intelligence systems, and it is warning regulators that locking down open AI could leave defenders blind.

Cruciferra: The Malware-Hiding Service Fuelling Attacks on Indian Taxpayers
A China-linked group is using a paid tool called Cruciferra to smuggle remote-access malware onto Windows machines, with tax-themed phishing emails as the way in.

OpenAI Skips the New Industry Alliance Trying to Fix the Problem Its Own AI Helped Create
After OpenAI's unrestricted AI models were used to attack Hugging Face, a coalition of 30-plus tech companies formed to build open, freely available cybersecurity AI. OpenAI is not among them.

Milan Startup Beelzebub Raises $3.4 Million to Build AI Traps for Hackers
The Italian cybersecurity firm's platform assumes criminals are already inside a company's network and uses artificial intelligence to lure them into decoy systems, catch them, and lock them out automatically.

What Is Really Inside Your Work Apps? Lookout's New Tool Aims to Tell You
A new scanning service from mobile security firm Lookout builds detailed ingredient lists for enterprise apps, exposing hidden vulnerable components before criminals can exploit them.

Hotel and Conference Wi-Fi Networks Hijacked to Steal Corporate Login Details
Criminals are quietly rewriting the internet directions on public Wi-Fi routers at hotels and conference centres, then catching employees' Microsoft 365 passwords mid-air. Researchers say the campaign has been running since at least June 2026.

Your ransomware playbook is probably putting the wrong person in charge at 4 a.m.
A growing body of evidence shows that the real damage in ransomware incidents often comes not from the attack itself, but from who gets to decide whether to pull the plug on a business-critical system.