Latest stories — Page 31

A weathered combination padlock resting on a cracked concrete surface, surrounded by a tangled web of thin copper wires spreading outward in all directions, pho
Identity & Access

AI agents with too many keys: why permissions are the new identity problem

As companies rush to deploy AI assistants that act on their behalf, security researchers warn the real danger is not the AI itself but the sweeping access rights it inherits.

4 min read
A close-up, photoreal, news-editorial image of tangled fiber optic cables glowing with intense orange and red light against a dark server room background, with
Vulnerabilities

Windows 11 gets a 42-fix preview update with quieter alerts and better voice control

Microsoft's optional KB5101684 preview for Windows 11 24H2 and 25H2 clears up File History backup errors, a DFS drive quirk that scared File Explorer, and a compliance bug that locked new work laptops out of company resources.

4 min read
Photoreal news-editorial 16:9 image of a vast server room at night, rows of glowing rack-mounted hardware receding into darkness, cool blue and amber indicator
AI Security

Mate Security Pulls In $35 Million to Build an AI-Powered Cyber Defence System That Learns on the Job

The Tel Aviv startup wants to replace traditional security operations centres with an AI platform that studies each company's own network and gets smarter after every attack it handles.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Policy & Regulation

Nearly Three in Four Companies Admit They Aren't Ready for a Serious Cyberattack

A survey of 600 senior IT security leaders finds most have the tools but lack the coordination, visibility and boardroom alignment to survive a real incident.

4 min read
A network diagram showing a supply chain attack with compromised npm packages affecting developer systems
Vulnerabilities

One Click on a Bad Web Page Was Enough to Break Firefox and Tor

Researchers at Nebula Security say a now-patched Firefox flaw let attackers run code just by loading a page, and it worked against Tor Browser too.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Cloud Security

ThreatLocker Raises $190 Million to Expand Its Block-Everything-First Security Model

The Florida firm now counts more than 70,000 business customers and is opening a UK office on the back of its latest funding haul.

3 min read
Full-frame edge-to-edge photoreal editorial image of an empty modern server room with a single illuminated robotic arm reaching toward a glowing network port, c
Opinion

AI Is Shrinking the Time Between Bug and Break-In. Playbooks Haven't Caught Up.

Vendors are pitching AI-driven vulnerability tools like Mythos as the answer. The harder question is what defenders have been doing wrong for years.

4 min read
Photoreal news-editorial overhead shot of a darkened server room aisle, blue and amber rack indicator LEDs glowing along both walls, faint condensation haze nea
Vulnerabilities

Broadcom Patches Critical 'VM Escape' Flaw in VMware ESXi, Plus Four More Vulnerabilities

Five security flaws, three rated critical, have been fixed across VMware's most widely-used virtualisation products. One lets an attacker break out of a contained virtual machine and reach the underlying server it runs on.

3 min read
A sleek, modern corporate security operations room photographed from a low angle looking toward a large curved desk with multiple dark monitors displaying abstr
Opinion

Refurbished ASUS Chromebook CM30 drops to $145, and shoppers should read the fine print

A grade-A refurb at a steep discount looks tempting, but second-hand laptops carry their own security homework.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a generic silver smartphone lying face down on a steel evidence tray, connected via a thick gray data
Policy & Regulation

Russia Charges Telegram's Pavel Durov With Aiding Terrorism

The FSB says Telegram refused to take down channels it flagged. Durov, living abroad, calls the case political theatre.

4 min read
A cracked smartphone screen lying face-up on a cold concrete floor, its display showing a faint padlock icon surrounded by a shattered web of glass fractures, h
Policy & Regulation

US and Australia Publish Joint Playbook for Cutting Critical Infrastructure Off From Cyber Attack

New guidance tells power plants, water utilities, and other essential services how to keep running even when their networks are under attack or must be disconnected entirely.

3 min read
Photoreal news-editorial aerial view of a vast network of illuminated fiber-optic cables converging on a central node that has gone dark, surrounding nodes stil
Threat Intelligence

Criminals Are Hijacking Cargo Trucks With Laptops, Not Crowbars

Cargo theft powered by hacking has surged more than 1,500 percent since 2021. The freight industry's patchwork of old systems and thin security budgets has made it an easy mark, and the criminals running these operations are sophisticated enough to move stolen truckloads across borders.

4 min read
Macro photograph of tangled fiber optic cables glowing in deep blue and green light against a dark server room background, sharp focus on the glass fiber tips w
Vulnerabilities

Gitea Patches Critical Flaw That Lets Repo Users Run Shell Commands

CVE-2026-60004 carries a 9.8 CVSS score and is fixed in Gitea 1.27.1. Anyone running an older self-hosted instance should update now.

3 min read
a government building with digital security overlay, emphasizing cybersecurity
Policy & Regulation

The US Government Just Changed How Agencies Must Fix Security Flaws. It Is Not Enough.

A new federal directive finally ties patch deadlines to real-world risk. Then AI rewrote the problem.

5 min read
Full-frame edge-to-edge photoreal editorial image of a modern flat-screen smart television glowing in a dim living room at night, faint blue light spilling onto
Threat Intelligence

Spur Intelligence Raises $200 Million to Unmask Hidden Internet Traffic

The IP intelligence firm has operated without outside funding since 2017. Now it has the backing to scale tools that help companies see who is really behind anonymised web traffic.

3 min read
Close-up top-down view of a smartphone lying on a wooden table, its screen displaying a generic colourful digital invitation card with balloons and confetti gra
Identity & Access

The Four Ways Criminals Beat Multi-Factor Authentication (And What You Can Do About It)

Multi-factor authentication was supposed to be the lock that hackers couldn't pick. It turns out there are at least four reliable ways through it, and most organisations are leaving at least one door wide open.

4 min read
Full-frame edge-to-edge overhead photoreal shot of a generic black smartphone on a dark slate surface, screen glowing faint blue with abstract geometric lock-pa
Threat Intelligence

Flying Eagle Android Spyware Kit Leaks Onto Telegram, Traced to 170 Servers

Researchers link the free-to-copy surveillance toolkit to a fake Chinese police services app aimed at Android phone users.

3 min read
A high-voltage electricity substation at dusk, transformers and steel pylons silhouetted against a deep blue sky, faint control-room glow visible through a dist
Threat Intelligence

More Than 30 Minnesota Water Utilities Hit in Coordinated Cyberattack

Attackers knocked out automated controls at water and wastewater plants across the state on July 26 and 27. Drinking water stayed safe, but one city briefly shut its plant down entirely.

4 min read
Full-frame edge-to-edge photoreal editorial shot of a darkened server room corridor with a single rack door ajar, cool blue emergency lighting spilling across p
Ransomware

Ransomware gangs are going after VPNs, and an AI just ran its own attack

Ransomware attacks rose for the fourth month in a row in June, with criminals targeting the devices companies use to connect remote workers. A new AI-driven attack completed an entire break-in with no human at the keyboard.

3 min read
A digital representation of software supply chain attack with code streams and lock graphics
Threat Intelligence

Booby-trapped @joyfill npm packages hide a remote-control trojan

Two beta versions of the popular Joyfill JavaScript packages were tampered with to plant malware that runs the moment a developer imports them.

4 min read
Aerial top-down view of a large modular data center campus at dusk, cooling units and server hall rooftops visible, warm amber security lighting contrasting wit
Cloud Security

Fortinet unveils FortiGate 1200G firewall with built-in SASE enforcement for on-premises sites

The new midrange appliance pushes cloud-style security policy into company-controlled buildings and data centres, running at up to 397 Gbps. Availability is set for Q3 2026.

3 min read
© 2026 Threat Vectr