Latest stories — Page 36

AI Agents Need More Than a Watchful Eye. They Need a Leash.
Watching what AI agents do inside your systems is useful. Stopping them doing the wrong thing is the harder job, and the one security teams keep tripping over.

Illinois man gets 76 months for phishing 750 women's Snapchat accounts
Kyle Svara, 26, tricked victims into handing over login codes by posing as Snap staff, then stole nude photos and traded them online.

AI Assistant Turned Loose on Thai Finance Ministry Network
An attacker disabled safety prompts on an AI coding agent and let it run reconnaissance and privilege-escalation checks against Thailand's treasury systems on its own.

Golden Chickens Malware Crew Returns With Four New Tools
The criminal group behind a long-running 'malware-as-a-service' operation has rolled out fresh code, including a stripped-down loader and a browser password stealer.

Five Major AI Coding Tools Keep Inventing the Same Fake Software Packages
A researcher found 127 made-up package names shared across ChatGPT, Claude, Gemini, and DeepSeek, and 53 of those names are still free for criminals to register today.

After Tycoon2FA Was Shut Down, Phishing Criminals Went Looking for New Tricks
Microsoft's Q2 2026 email threat report shows that busting a major phishing-for-hire service slashed attack volume by 92%, but criminals quickly pivoted to Microsoft Teams chats and automated email campaigns that hit tens of thousands of organisations in hours.

Redis Patches Four Code-Execution Bugs After AI Agent Finds Zero-Days
Seven security releases went out on July 23 after researchers used Moonshot AI's Kimi K3 agents to uncover authenticated remote code execution chains in stock Redis builds.

AI Scanner Finds Eight Serious Bugs in NodeBB Forum Software
Aikido Security's automated code review turned up admin takeover and private-message flaws in six hours. All eight are patched in version 4.14.2.

CISA orders three-day fix as Clop hits PTC Windchill flaw
A critical bug in PTC's product design software, CVE-2026-12569, is being used by the Clop extortion crew to steal corporate data. Regulators in the US and Germany moved fast.

When AI Speaks Your Language But Its Security Doesn't
AI safety filters were built mostly in English. For companies operating across Europe's dozens of languages, that gap is already being used against them.

Australian Regulator Fines TAB $2.7 Million for Spam and Telemarketing Breaches
Tabcorp's gambling brand ignored Do Not Call registrations and ignored unsubscribe requests at scale. Now it has paid more than $2.7 million in penalties, and the regulator says the failures point to deep problems inside the company's compliance systems.

Dolphin X: The New Malware That Uses AI to Pick Which Victims to Rob First
A remote access trojan sold on a cybercrime forum claims to score infected computers by their value, helping criminals go after the richest targets first.

Check Point's Admin Console Has a Critical Flaw That Hands Attackers the Keys to Everything
A security hole in Check Point's management software lets criminals walk in without a password and rewrite the rules of an entire network. Ten organisations have already been hit.

Origin Energy confirms data breach; hacker claims 2 million customer records held for extortion
Australia's largest energy retailer says names, addresses, birth dates and partial bank details were exposed. An unidentified hacker calling themselves 'John Doe' has threatened to leak the data within two weeks.

Fake Claude installer promoted by Bing ads hits 29 organisations with SectopRAT
Attackers hid a phishing page on Anthropic's own domain, then bought Bing ads to send people to a booby-trapped 'Claude Desktop' download.

AI Is Writing the New Cybercrime Playbook. Here Is How Defenders Are Answering
Automated attacks can now break through company defences in seconds. A new generation of AI-powered security tools aims to fight back at the same speed, before human analysts even see an alert.

Microsoft's New Passkey System Has Flaws That Let Old Hacking Tricks Work Again
A security researcher found three near-exploitable bugs in Windows 11 and Microsoft's cloud login service, just as the company prepares to make passkeys the default for hundreds of millions of users.

AI Agents Are Breaking the Security Promises of Confidential Computing
A technology built to keep sensitive data locked away is running into a problem it was never designed for: AI assistants that cannot forget what they have read.

Ransomware Hit a Japanese Frozen-Food Giant and KFC Felt It
A cyberattack on Nichirei, one of Japan's biggest cold-chain logistics companies, froze shipments across the country, left KFC franchises warning of shortages, and put a spotlight on how fragile food supply chains really are.

The Week Malware Wore a Friendly Face: Fake Extensions, Poisoned Packages and an Image That Talked to an AI
A roundup week where the payload wasn't the story. The disguise was.

Ukraine warns of hackers hiding malware inside a fake Notepad++ plugin
CERT-UA links the campaign to UAC-0099, a group previously tied to Russia's Sandworm, which is using a genuine copy of Notepad++ to smuggle in a loader called LunchPoke.