Latest stories — Page 33

A 20-year-old flaw is leaking passwords from 24,000 servers online
Researchers found tens of thousands of remote server management chips exposed to the internet, many still using the sticker password from the factory.

Every AI Browser on the Market Can Be Hacked, Researchers Warn
Security firm Zenity says agentic browsers have stripped out decades-old web protections to work across multiple sites, and every one tested could be taken over by a malicious social-media post or newsletter link.

Act Security Aims to Tackle Cloud Vulnerability Challenges with $60 Million in Funding
Act Security emerges from stealth to address cloud security issues caused by AI-discovered vulnerabilities, armed with substantial funding and a novel approach.

From Breaking In to Shutting Hackers Out: The Two Lives of Tal Kollander
Tal Kollander spent years on the offensive side of hacking before switching to defence. His story is a window into how the two worlds actually think about each other.

Hush Security Raises $30 Million to Put AI Agents Under Proper Control
A Tel Aviv startup wants every autonomous AI program inside a company to carry a verifiable identity and leave a full paper trail. Investors just backed that idea to the tune of $30 million.

Researcher Publishes Linux Kernel Root Exploit Built With AI Help
CVE-2026-53264, a use-after-free flaw in the kernel's traffic-control code, lets an ordinary Linux user gain full system control on CentOS Stream 9.

JetBrains Patches Critical TeamCity Flaw That Let Attackers Run Commands Without Logging In
CVE-2026-63077 carries a 9.8 severity score and affects every on-premises version of the build server. Cloud customers were fixed automatically.

Your AI Safety Certificate Is Worthless the Moment the Agent Goes Live
Compliance badges on AI products look reassuring. They don't protect you once an autonomous agent starts reading your files, calling your internal systems, and making decisions faster than any human can watch.

PEAR ransomware crew claims 1.26 million-record breach at Georgia billing firm MCBS
Medical Computer Business Services says attackers roamed its network for four days in September 2025. A ransomware group now claims it stole 3.3 terabytes of patient and business data.

Google Gives Hackers New Names, Here Is Why That Matters
Google's threat-intelligence team is replacing its old numbering system with memorable two-word labels for every hacking group it tracks, making it easier for researchers and companies to talk about the same criminals.

Microsoft Debuts Its First Cybersecurity-Only AI Model Inside MDASH
The company says pairing MAI-Cyber-1-Flash with GPT-5.4 scored 95.95% on CyberGym at half the cost of its previous best setup.

AI Smart Glasses Are Walking Into Your Office. Nobody Knows How to Stop Them.
Samsung's entry into AI-powered glasses has forced security leaders to face an uncomfortable truth: the recording device problem is already everywhere, and a ban probably makes things worse.

Microsoft's New AI Security Service Can Find Bugs, Simulate Attacks and Write Patches, All in Minutes
Project Perception strings together a team of specialised AI agents to do what used to take a room full of security experts. But the real story is how Microsoft built it to work without the biggest, most expensive AI models.

The Man Who Meets You at Your Worst: Inside Melbourne Airport's Only Chaplain
Martyn Scrimshaw has spent nine years walking the terminals of Melbourne Airport, helping the homeless, the scammed, the grieving, and the fleeing. Now a film starring Hugo Weaving is bringing his work to a wider audience.

ChatGPT Broke Out of Its Test Cage and Hacked Hugging Face. Now Everyone Has Questions.
OpenAI's AI hacking agents escaped a controlled test environment and attacked a major AI platform on their own. Was it a safety failure, a marketing stunt, or both?

Arista rushes fix for VeloCloud flaw already being used in attacks
A perfect-10 command injection bug in on-premises VeloCloud Orchestrator lets anyone on the network take over the box. Attackers found it first.

Two Cloud Giants, Two Flaws, Zero Bug Bounties: The 'Confused Deputy' Problem That Won't Go Away
A security researcher found ways to silently hijack administrator control over both Microsoft Azure and Google Cloud infrastructure. Neither company paid a reward. One quietly fixed its flaw without saying so.

How the FBI Took Down LockBit by Destroying the One Thing Criminals Can't Easily Replace: Trust
Operation Cronos didn't just seize servers. It turned LockBit's own website against its partners, shattered the group's reputation, and cut ransom attacks in the US by nearly 80 percent.

The Cheapest Way to Beat an AI Security System Is to Read Its Rulebook
Confidence in autonomous hacking tools has collapsed. A researcher says the real problem runs deeper: the governance rules we write to keep AI security systems safe can become a weapon in an attacker's hands.

Dysphoria Botnet Rebuilds on Blockchain After March Takedown
Researchers at CNCERT and XLab say the IoT botnet now hides its control servers behind blockchain domains and routes traffic through infected devices, making shutdowns harder.

Apple sued after fake Sparrow Wallet app on App Store drains $1.8M in Bitcoin
Three users say a counterfeit crypto wallet, promoted in App Store collections, tricked them into handing over the secret recovery phrases that guard their coins.