Latest stories — Page 4

Nearly a Million Australians' Data Stolen in Origin Energy Breach Traced to Manila Call Centre
A former employee at a Manila-based Accenture office allegedly took customer records belonging to roughly 900,000 Origin Energy customers and tried to extort the company for money to return them.

Fake Wi-Fi Network on Delta Flight Triggers Federal Investigation After DEF CON
Someone on a Las Vegas-to-Atlanta flight set up a rogue wireless network called 'Delta WiFi Fast' that led passengers to a fake login page. The FBI is now involved, and suspicion is falling on attendees of DEF CON, the annual hacker conference held days earlier.

Malware Rode Into a Texas Police Server Inside Body Camera Footage
A hidden virus hitched a ride on police body-cam video, then spread through the entire justice chain. Experts say the real epidemic is a shortage of cyber training in law enforcement.

A Local Housing Authority Lost $1 Million to Email Fraud. Here Is What It Did Next.
A cybersecurity consultant's account of how a small government agency rebuilt its defences after criminals silently rerouted a wire transfer offers a practical road map for the thousands of local bodies running on skeleton IT crews.

Weekly Roundup: Trusted Software Turned Against Defenders, Plus a Critical Gogs Flaw
From signed drivers hijacked to disable antivirus tools, to a code-execution bug in the Gogs source-code platform, this week's threats show how attackers keep lowering the bar.

Rust developers hit by supply-chain attack on arrayref crate
Attackers hijacked a maintainer account and slipped credential-stealing malware into three popular Rust libraries during a 1.5-hour window on August 20.

A Flaw in N-able's Passportal Handed Any Malicious Website the Keys to Every Password a Business Stored
A researcher found that Passportal's browser extension trusted every message it received without question, letting any webpage silently drain a company's entire vault of login credentials.

Researchers Show How a Booby-Trapped Web Page Can Steal Your Grok Chat Data
Adversa AI's 'Cryptographic Context Injection' technique tricks xAI's Grok into leaking user names, locations and prompts to attacker servers when asked to summarise a page.

Who Is Watching You Right Now, and What Are They Doing With It?
From supermarket cameras to workplace keystroke logs, surveillance of ordinary people has quietly become a growth industry. AI is making it faster, cheaper, and harder to spot.

Elementor Pro flaw let attackers plant executable files on WordPress sites
A bug in the paid version of the popular WordPress builder let strangers upload PHP files and run code on the server. A patch is out.

Pakistan's Transparent Tribe Is Spying on Afghan Telecom Workers With Fresh Malware
A Pakistani hacking group has been quietly breaking into government and telecom targets in Afghanistan using two newly documented tools. India was in their sights too, but appears to have held the line.

A popular JavaScript sandbox has a hole in it, and the fix is to stop using it
Researchers found a way out of isolated-vm, an open-source tool used to safely run untrusted code. The maintainer says the project is unmaintained and users should migrate.

AI-powered phishing is slipping past email filters. Here's how to catch it after the click.
Email gateways can't spot every AI-written lure. The catch now happens at the identity and endpoint layer.

Grandoreiro Banking Malware Is Back, Targeting Mexican Bank Customers
A banking virus first spotted in 2016 is still active, still stealing money, and now using a clever disguise to slip past security software on computers in Mexico.

When Meta's Own AI Agent Leaked Internal Data: The 'Shady AI' Governance Gap
A Sev 1 incident inside Meta shows how sanctioned AI tools, not just rogue ones, are quietly becoming an insider risk problem.

The 'CDN Tsunami' Attack Turns a Trickle of Traffic Into a Flood at the Origin
Researchers show how the way big content delivery networks translate modern HTTP/3 requests into older HTTP/1.1 can multiply a small attack stream by up to 350 times against the website behind them.

'Zombie Card' Attack Brings Expired Visa Contactless Cards Back to Life
UMass Amherst researchers show how to rewrite the expiry date a payment terminal sees, letting dead cards buy real goods.

Atlassian and Splunk Push Patches for More Than 250 Flaws, Including Critical Bugs
Two major software vendors dropped sweeping security updates this week. Here is what changed, what could go wrong without the fix, and what ordinary users should know.

Kriminal: The $12.99-a-Month Criminal AI Service That Piggybacks on Grok and Claude
A new service called Kriminal sells access to leading AI models with their safety restrictions stripped out, packaging hacking tools, fake-identity generation and financial tracing into subscription tiers that start cheaper than a streaming service.

Cisco Patches Four Maximum-Severity Flaws in Crosswork Network Software
Fifteen vulnerabilities fixed across Cisco products, with three scoring a perfect 10 out of 10 on the standard severity scale. None are known to be exploited yet.

Fake Firefox Wallet Extensions Drain Crypto From Unwary Users
Researchers at Socket found 40 Firefox add-ons impersonating OKX, Rabby, TronLink and other crypto wallet brands, part of a wider 77-extension operation they call Offside Wallet Theft Factory.