Latest stories — Page 36

Photoreal news-editorial 16:9 image of a server operations center at night, rows of humming rack servers casting cold blue and amber light across the floor, a s
AI Security

AI Agents Need More Than a Watchful Eye. They Need a Leash.

Watching what AI agents do inside your systems is useful. Stopping them doing the wrong thing is the harder job, and the one security teams keep tripping over.

4 min read
Full-frame edge-to-edge photoreal close-up of a smartphone on a dark wooden desk displaying an abstract blue messaging app settings screen, a small printed pape
Threat Intelligence

Illinois man gets 76 months for phishing 750 women's Snapchat accounts

Kyle Svara, 26, tricked victims into handing over login codes by posing as Snap staff, then stole nude photos and traded them online.

4 min read
Macro view of a tangled knot of glowing fiber optic cables pulsing with light, set against a dark server room background, with some cables dimming and flickerin
AI Security

AI Assistant Turned Loose on Thai Finance Ministry Network

An attacker disabled safety prompts on an AI coding agent and let it run reconnaissance and privilege-escalation checks against Thailand's treasury systems on its own.

4 min read
A depiction of a digital shark attacking a cloud of GitHub repositories
Threat Intelligence

Golden Chickens Malware Crew Returns With Four New Tools

The criminal group behind a long-running 'malware-as-a-service' operation has rolled out fresh code, including a stripped-down loader and a browser password stealer.

3 min read
Photoreal news-editorial 16:9 image of a glowing computer monitor in a dimly lit office showing dense lines of green and white code, with a physical padlock sit
AI Security

Five Major AI Coding Tools Keep Inventing the Same Fake Software Packages

A researcher found 127 made-up package names shared across ChatGPT, Claude, Gemini, and DeepSeek, and 53 of those names are still free for criminals to register today.

3 min read
Full-frame edge-to-edge overhead photoreal shot of a dimly lit desk with an open laptop showing a generic email inbox interface, scattered printed invoices, a c
Threat Intelligence

After Tycoon2FA Was Shut Down, Phishing Criminals Went Looking for New Tricks

Microsoft's Q2 2026 email threat report shows that busting a major phishing-for-hire service slashed attack volume by 92%, but criminals quickly pivoted to Microsoft Teams chats and automated email campaigns that hit tens of thousands of organisations in hours.

4 min read
Full-frame photoreal editorial image of a modern enterprise data centre corridor at night, glowing amber server indicator lights reflecting off a polished floor
Vulnerabilities

Redis Patches Four Code-Execution Bugs After AI Agent Finds Zero-Days

Seven security releases went out on July 23 after researchers used Moonshot AI's Kimi K3 agents to uncover authenticated remote code execution chains in stock Redis builds.

3 min read
Photoreal news-editorial shot of a stack of rack-mounted network appliances in a dim server room, faint amber status LEDs reflecting off polished floor tiles, s
Vulnerabilities

AI Scanner Finds Eight Serious Bugs in NodeBB Forum Software

Aikido Security's automated code review turned up admin takeover and private-message flaws in six hours. All eight are patched in version 4.14.2.

3 min read
A visual representation of a digital storm hitting a Drupal logo, symbolizing a security vulnerability
Vulnerabilities

CISA orders three-day fix as Clop hits PTC Windchill flaw

A critical bug in PTC's product design software, CVE-2026-12569, is being used by the Clop extortion crew to steal corporate data. Regulators in the US and Germany moved fast.

4 min read
Photoreal news-editorial overhead shot of an open laptop on a dark desk, screen glowing with abstract terminal output and a faint contact-card icon, scattered p
AI Security

When AI Speaks Your Language But Its Security Doesn't

AI safety filters were built mostly in English. For companies operating across Europe's dozens of languages, that gap is already being used against them.

4 min read
Aerial 16:9 view of a busy Australian high street at dusk, warm amber shopfront lights glowing against a deep blue evening sky, a mix of small independent shops
Policy & Regulation

Australian Regulator Fines TAB $2.7 Million for Spam and Telemarketing Breaches

Tabcorp's gambling brand ignored Do Not Call registrations and ignored unsubscribe requests at scale. Now it has paid more than $2.7 million in penalties, and the regulator says the failures point to deep problems inside the company's compliance systems.

3 min read
Full-frame overhead view of a modern silver laptop on a dark wooden desk, screen showing a blurred generic system password dialog with a red warning glow, apps
Threat Intelligence

Dolphin X: The New Malware That Uses AI to Pick Which Victims to Rob First

A remote access trojan sold on a cybercrime forum claims to score infected computers by their value, helping criminals go after the richest targets first.

4 min read
Full-frame photoreal editorial shot of a dimly lit server room with a single rack unit highlighted by a red status LED, blurred network cables in the foreground
Vulnerabilities

Check Point's Admin Console Has a Critical Flaw That Hands Attackers the Keys to Everything

A security hole in Check Point's management software lets criminals walk in without a password and rewrite the rules of an entire network. Ten organisations have already been hit.

4 min read
Photoreal editorial photograph of a large empty industrial tractor assembly hall at dusk, warm overhead lights on green paint bays, no visible logos or text, wi
Breaches

Origin Energy confirms data breach; hacker claims 2 million customer records held for extortion

Australia's largest energy retailer says names, addresses, birth dates and partial bank details were exposed. An unidentified hacker calling themselves 'John Doe' has threatened to leak the data within two weeks.

4 min read
Full-frame edge-to-edge photoreal overhead shot of a tangle of consumer networking gear — a stacked home router, an IP camera, and a small Android set-top box —
Threat Intelligence

Fake Claude installer promoted by Bing ads hits 29 organisations with SectopRAT

Attackers hid a phishing page on Anthropic's own domain, then bought Bing ads to send people to a booby-trapped 'Claude Desktop' download.

4 min read
Close-up top-down view of a glowing digital web of interconnected nodes on a dark surface, with one node subtly emitting a hidden pulse of light in a different
AI Security

AI Is Writing the New Cybercrime Playbook. Here Is How Defenders Are Answering

Automated attacks can now break through company defences in seconds. A new generation of AI-powered security tools aims to fight back at the same speed, before human analysts even see an alert.

4 min read
Extreme close-up of a glowing computer motherboard at night, thousands of tiny amber and red lights pulsing across circuit traces, shallow depth of field, dark
Identity & Access

Microsoft's New Passkey System Has Flaws That Let Old Hacking Tricks Work Again

A security researcher found three near-exploitable bugs in Windows 11 and Microsoft's cloud login service, just as the company prepares to make passkeys the default for hundreds of millions of users.

4 min read
Aerial 16:9 photograph of a small rural town at dusk, with a single brightly lit modern hospital building contrasting against rows of dimly lit older structures
AI Security

AI Agents Are Breaking the Security Promises of Confidential Computing

A technology built to keep sensitive data locked away is running into a problem it was never designed for: AI assistants that cannot forget what they have read.

4 min read
A darkened computer server room with ominous lighting, showcasing advanced digital security tools in action, emphasizing cybersecurity themes
Ransomware

Ransomware Hit a Japanese Frozen-Food Giant and KFC Felt It

A cyberattack on Nichirei, one of Japan's biggest cold-chain logistics companies, froze shipments across the country, left KFC franchises warning of shortages, and put a spotlight on how fragile food supply chains really are.

4 min read
A developer workstation surrounded by digital threats, symbolizing malware infiltration
Threat Intelligence

The Week Malware Wore a Friendly Face: Fake Extensions, Poisoned Packages and an Image That Talked to an AI

A roundup week where the payload wasn't the story. The disguise was.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a darkened smartphone screen displaying a generic green messenger app with a QR code prompt, faint Cyr
Threat Intelligence

Ukraine warns of hackers hiding malware inside a fake Notepad++ plugin

CERT-UA links the campaign to UAC-0099, a group previously tied to Russia's Sandworm, which is using a genuine copy of Notepad++ to smuggle in a loader called LunchPoke.

4 min read
© 2026 Threat Vectr