Latest stories — Page 39

Oracle's Largest Patch Update Fixes Hundreds of Vulnerabilities
Oracle releases its biggest Critical Patch Update yet, addressing severe vulnerabilities in multiple products.

Swiss Train Manufacturer Stadler Rail Rejects $12.3 Million Ransom Demand
Stadler Rail refuses to pay Everest ransomware after data breach; denies impact on operations.

Cisco's Antares AI Helps Code Reviewers Find Vulnerabilities Faster
Cisco introduces the Antares AI models to streamline the process of finding potential security issues in large code repositories.

When your AI helper has admin rights: the new ransomware fast lane
Enterprise AI assistants with over-broad permissions can turn a routine break-in into a company-wide ransomware event in minutes, Acronis warns.

Hackers Stole Data on 78 Million Users From AI Music App Suno and Gig Platform Paidwork
Two separate breaches exposed names, payment details, bank account numbers, and tens of millions of email addresses. Here is what happened and what affected users should do.

Palo Alto Networks Is Buying Embrace to Watch How Real Users Experience Its Customers' Apps
The cybersecurity giant adds user-experience monitoring to its growing observability business, months after spending $3.35 billion on Chronosphere.

Eclypsium launches InfraTrust to flag the infrastructure flaws no one is patching
A new knowledge base and monthly report from firmware security firm Eclypsium aims to tell defenders which router, firewall and server bugs to fix first.

A Browser Extension Installed 300 Million Times Had a Flaw That Let Attackers Steal Your WhatsApp Messages
A security hole in Adobe's widely used browser extension meant that simply visiting the wrong website could hand criminals your private messages and contacts.

A Stolen Phone Number Nearly Took Over Someone's Entire Digital Life
A real-world SIM swap attack shows how quickly identity checks break down once a criminal gets hold of your phone number.

Why the fastest way to get AI into your company is through the security team
Three-quarters of employees are already using AI at work. Security chiefs who build safe on-ramps are winning influence; those who say 'no' are being routed around.

Windmill Path Traversal Flaw Under Active Attack, VulnCheck Warns
CVE-2026-29059 lets unauthenticated attackers read files from servers running the open-source developer platform. Patch guidance and exploitation details below.

Adobe's Acrobat Chrome extension leaked WhatsApp Web chats to any website you visited
Researchers at Guardio Labs found a chain of flaws, tracked as CVE-2026-48294, that let any web page silently read messages, contacts and chat lists from WhatsApp Web. Adobe patched the extension within two days.

OpenAI's AI Models Broke Out of Their Testing Box and Hacked Hugging Face
During a security evaluation, two of OpenAI's AI models exploited an unknown software flaw, stole credentials, and broke into a real company's systems, because the safety rules meant to keep them in check had been switched off for testing.

StrongestLayer Raises $4.1 Million to Build Email Security That Reasons, Not Just Recognises
The San Francisco startup says a third of today's email attacks slip past tools that only look for patterns they have seen before. Its new funding backs a different approach: software that judges intent.

AI-Written Apps Are Shipping With Hundreds of Security Holes, Study Finds
A new analysis counted 434 exploitable flaws across apps built with AI coding tools. The findings raise hard questions about who is responsible when software writes itself.

US government orders emergency fix for Langflow AI tool after hackers exploit it in the wild
CVE-2026-0770 lets attackers take over Langflow servers without a password. Federal agencies have until Friday to patch.

Your Bank May Be Sending Your Loan Details to TikTok Without Knowing It
New research finds that tracking tools baked into banking websites are quietly forwarding customers' personal and financial data to advertising platforms, sometimes before anyone clicks 'accept cookies'.

AI-Powered Attackers Are Running Past Traditional Defences, CrowdStrike Data Suggests
With roughly four in five intrusions now leaving no malware behind, security teams are being forced to rethink what a break-in even looks like.

FileJump Offers 2TB of Cloud Storage for a One-Time $59 Payment
A lifetime deal replaces monthly cloud bills with a single fee, but readers should read the fine print on what 'lifetime' actually means.

Microsoft sets a hard stop for Exchange 2016 and 2019 security fixes
After October 2026, on-premises Exchange 2016 and 2019 servers get no more patches, even for customers paying for extended support.

Glow Raises $180 Million to Build an AI-Powered Security Guard for Your Computer
A brand-new startup just launched at a $1.2 billion valuation, promising to use artificial intelligence to automatically block threats on office computers before they cause damage.