Latest stories — Page 34

Anyone Can Now Attack Unpatched vBulletin Forums Thanks to Public Exploit Code
Working exploit code for a critical vBulletin flaw is out in the open, and it lets a stranger run commands on the server without logging in.

ShinyHunters claims Ernst & Young breach, points to supply-chain attack
The extortion crew says stolen credentials from a third-party supplier gave them access to EY's Jira, GitHub and Azure. The accounting giant has not confirmed the group's role.

Weekly Threat Recap: A Rogue AI Agent, Old Bugs Back at Work, and Exposed Systems Nobody Fixed
OpenAI reports an AI agent that stepped outside its lane, while attackers keep finding shelter in tools defenders already trust.

The AI helpers your staff installed without telling IT
Autonomous AI agents are quietly attaching themselves to company accounts, often with wide permissions and no oversight. Here is what that means and how to get a grip on it.

n8n Patches Sandbox Escape That Let Editors Run Commands on the Server
A flaw in the popular automation platform let anyone with workflow-editing access break out of the safe zone and run system commands. n8n has issued a fix.

Fake Microsoft Teams Update Pushes Remote-Control Tools onto Victims' PCs
A phishing run tracked as Operation BlueDash uses a bogus 'secure document' lure and a counterfeit Microsoft Store page to install legitimate remote-access software on target machines.

Nvidia Leads 40-Company Coalition to Build Open Security Tools for AI Systems
The Open Secure AI Alliance wants shared, openly inspectable tools to become the standard defence against attacks on artificial intelligence systems, and it is warning regulators that locking down open AI could leave defenders blind.

Cruciferra: The Malware-Hiding Service Fuelling Attacks on Indian Taxpayers
A China-linked group is using a paid tool called Cruciferra to smuggle remote-access malware onto Windows machines, with tax-themed phishing emails as the way in.

OpenAI Skips the New Industry Alliance Trying to Fix the Problem Its Own AI Helped Create
After OpenAI's unrestricted AI models were used to attack Hugging Face, a coalition of 30-plus tech companies formed to build open, freely available cybersecurity AI. OpenAI is not among them.

Milan Startup Beelzebub Raises $3.4 Million to Build AI Traps for Hackers
The Italian cybersecurity firm's platform assumes criminals are already inside a company's network and uses artificial intelligence to lure them into decoy systems, catch them, and lock them out automatically.

What Is Really Inside Your Work Apps? Lookout's New Tool Aims to Tell You
A new scanning service from mobile security firm Lookout builds detailed ingredient lists for enterprise apps, exposing hidden vulnerable components before criminals can exploit them.

Hotel and Conference Wi-Fi Networks Hijacked to Steal Corporate Login Details
Criminals are quietly rewriting the internet directions on public Wi-Fi routers at hotels and conference centres, then catching employees' Microsoft 365 passwords mid-air. Researchers say the campaign has been running since at least June 2026.

Your ransomware playbook is probably putting the wrong person in charge at 4 a.m.
A growing body of evidence shows that the real damage in ransomware incidents often comes not from the attack itself, but from who gets to decide whether to pull the plug on a business-critical system.

Anthropic's Opus 5 Can Find Software Bugs Almost as Well as Its Most Powerful AI, But Can't Turn Them Into Weapons
The company's new mid-tier model gets close to its top system on spotting security flaws. Exploit-writing is another story.

DentaQuest Data Breach: Up to 23 Million People's Dental and Health Records Exposed
A three-day network intrusion at one of America's largest dental benefits administrators may have handed criminals the Social Security numbers, treatment records, and government IDs of tens of millions of people.

The Hackers Got Hacked: Inside the Klue Breach and What It Means for Every Business Using Cloud Software
A forgotten service account let criminals walk into a competitive-intelligence platform. Then a second criminal group stole the stolen data. The whole chain is a masterclass in how cloud software trust goes wrong.

China-Linked Hackers Hit Middle East Governments With New Malware That Hides in Telegram
Zscaler researchers say a group tied to East Asia is running fresh spy operations against government networks, using three never-before-seen tools.

CISOs Are Now Running Business Resilience. Most Companies Haven't Noticed.
Security chiefs are quietly absorbing responsibility for keeping companies alive after a disaster, not just preventing one. Three experienced practitioners explain what that shift actually demands.

Gold Coast teacher charged after using AI to generate explicit images of students and staff
A 73-year-old former teacher at a Queensland private school faces four criminal charges after police found AI-generated child exploitation material on his school-issued laptop, following a nine-month investigation.

GitHub and PyPI Add Waiting Periods to Slow Down Supply-Chain Attacks
Dependabot now waits three days before pulling in new package versions, and PyPI blocks file uploads to releases older than 14 days.

Adelaide Man Charged After Police Find AI-Generated Child Exploitation Material on His Devices
A 26-year-old from South Australia's northern suburbs is believed to be one of the first people in the country charged specifically with producing child abuse material created by artificial intelligence tools.