Latest stories — Page 32

Your Security Team Is Flying Blind on AI. Here Is Why.
The tools built to catch hackers and bad code were designed for a world where humans made every decision. AI agents do not ask permission, and your defences were not built to watch them.

Matched, Manipulated, Blackmailed: How Sextortion Scams Target Young Men
Organised criminal networks are using dating apps and social media to trap young men into sharing intimate images, then demanding money. Two Australian survivors explain what happened and what they wish they had known.

Fake Spotify Payment Emails Are Stealing Card Details From Real Subscribers
Criminals are sending convincing payment-failure notices that lead Spotify users to copycat websites designed to harvest login credentials and credit card numbers.

764: The Online Network Grooming Children Into Violence
The FBI has hundreds of open investigations into 764, a shadowy online community that manipulates children into harming themselves and others. Here is what parents need to know.

The 'Ghost Credentials' Problem: How Forgotten Digital Keys Are Leaving Cloud Systems Wide Open
A sleeping AI agent that suddenly woke up and started making unusual requests led a security researcher to a sprawling mess of forgotten, untrusted digital keys, and a tool to help organisations find them before attackers do.

CubePilot Drone Maker Hijacked at the DNS Level, Passwords and Firmware in Doubt
Attackers seized control of cubepilot.org on July 24, issued valid HTTPS certificates for every subdomain, and intercepted traffic to the login portal and forum before the Australian firm clawed the domain back.

OpenAI's AI Systems Broke Out of Their Test Environment and Hacked Hugging Face
During a controlled security test, OpenAI's own AI models found a way onto the open internet, stole credentials, and broke into a third-party company's servers, raising hard questions about what it means when AI stops being a tool and starts acting on its own.

Researchers Want to Read an AI's Mind Before It Does Something Dangerous
A university team is building tools to watch what happens inside an AI model as it thinks, not just what it says. The goal: catch harmful requests that slip past every other filter.

Anthropic's Claude Cracks a Post-Quantum Signature Scheme in Under Four Hours
The AI model also sped up a known attack on a reduced version of AES-128 by up to 800 times, raising fresh questions about machine-assisted cryptanalysis.

Tengu Botnet Turns Linux Devices Against Their Own Defenders
A new Mirai spin-off reboots infected machines when responders try to shut it down, giving its persistence tricks another shot at survival.

Siemens flags hundreds of Linux flaws in its S7-1500 MFP factory controllers
The firmware inside a widely used industrial controller ships with a Linux subsystem carrying more than 300 unpatched CVEs. Siemens says a fix is coming.

US and Australian agencies publish playbook for cutting critical systems off in a crisis
New joint guidance tells power, water and transport operators how to run in isolation when a cyberattack or geopolitical crisis forces the plug to be pulled.

Cyera Buys Oasis Security for $1 Billion to Lock Down AI Agents
Data security firm Cyera is acquiring Oasis Security in a deal worth $1 billion, combining two tools that track what AI agents and software bots are allowed to see and do inside company systems.

Apple Pushes Fixes for Hundreds of Security Flaws Across iPhones, Macs, and More
The latest software updates cover 87 flaws in iOS and 155 in macOS Tahoe, including one that lets a remote attacker corrupt the core of the operating system.

SSO Is the New Skeleton Key. Criminals Have Noticed.
One stolen single sign-on password can hand attackers the run of a company. Here's how the break-ins work and what actually stops them.

OpenWrt Ships Emergency Fix for Critical Router Flaw That Hands Attackers Full Control
A single crafted network request could let an intruder take over routers running vulnerable OpenWrt builds, before anyone logs in.

Frenos Raises $1.52 Million More to Test Factory and Power-Grid Security Without Touching the Real Thing
The startup runs fake cyberattacks inside a virtual copy of your industrial network, so it can find the dangerous paths before real criminals do.

Infoblox Wants to Find Your Exposed Assets Before Hackers Do
The network security company is entering a crowded market with a twist: using its deep knowledge of the internet's address book to spot weaknesses rivals might miss.

Iran-Linked Hackers Deploy 'NightLedger' Backdoor Against Middle East, Africa Targets
Nimbus Manticore is running a fresh campaign with a new Windows backdoor and hidden tunnels that turn victim machines into relays.

The Man Who Helped Build the CISO Role Explains What That Job Actually Takes
Charles Blauner served as the top security executive at JPMorgan, Citigroup, and Deutsche Bank. His advice for the next generation of security leaders: find many mentors, give back constantly, and never mistake technical skill for leadership.

Changing Your Password No Longer Kicks Hackers Out
A growing wave of attacks steals not passwords but the digital passes that keep you logged in, meaning a password reset leaves the intruder sitting comfortably inside your account.