Latest stories — Page 40

Cisco Builds Cheaper AI Tools to Hunt Security Flaws in Software Code
The company's new Antares models scan source code for known vulnerabilities at a fraction of what larger AI systems cost. Here is what that means for businesses that write or buy software.

Siemens Rushes Fix for Smart Plug Riddled With Eight Serious Flaws
The SIDIS Secured SmartPlug carried a critical 9.8-rated bug plus seven more in bundled open-source libraries. Siemens says update to V7.26.0310.

Google DeepMind Unveils Gemini 3.5 Flash Cyber, an AI That Hunts and Patches Software Bugs
The new model, offered only to governments and vetted partners through CodeMender, aims to spot flaws in code and write fixes on its own.

A Poisoned Web Page Was Enough to Hijack Amazon's AI Coding Assistant
Researchers showed that Kiro, Amazon's AI-powered coding tool, could be tricked into running attacker code just by reading a booby-trapped web page.

Hackers Race to Break Into WordPress Sites Through 'wp2shell' Flaws
Two critical bugs in WordPress core let attackers install backdoors without a password. Automatic updates are out, but roughly one in five sites is still exposed.

Third SharePoint Flaw From July Patch Batch Is Now Being Attacked
CVE-2026-50522 lets unauthenticated attackers run code on SharePoint servers. A public proof-of-concept dropped, and the exploitation followed.

Why Stolen Logins Keep Opening the Door to Power Grids and Water Plants
Attackers rarely need fancy exploits when a valid password and an unchecked laptop will do. A look at why device trust is the missing half of Zero Trust in critical infrastructure.

Qilin Ransomware Crews Break In Through Palo Alto Firewall Flaw
Arctic Wolf Labs says attackers used CVE-2026-0257, a now-patched authentication bypass in PAN-OS, to get inside networks before deploying Qilin ransomware in June 2026.

AI Coding Tools Carry Real Security Risks, and the Danger Depends on What You're Building With
A new study tested 16 major AI coding assistants and found an average of 15 security flaws per project. The safest choice for one type of software can be one of the worst for another.

Empirical Raises $25 Million to Predict Cyber Attacks Before They Happen
A Chicago startup says its AI tools can spot which security flaws are most likely to be exploited next. Investors just bet $25 million that it's right.

SecurityWeek Launches Awards Programme to Spotlight Industrial Cybersecurity's Best Work
A new independently judged awards scheme will recognise the people and technologies making a real difference in protecting factories, power grids, and critical infrastructure.

Invisible Text on an Android Screen Can Hijack AI Phone Assistants, and Then the PC Behind Them
Researchers show how a rogue Android app can whisper hidden orders to open-source AI agents, and pivot the attack onto the computer running the show.

Bit2Watt: How a Regular Cloud Customer Could Wobble the Power Grid
Researchers at Zhejiang University say a paying cloud tenant with ordinary GPU access can swing a data centre's electricity draw hard enough to shake the grid, no hacking required.

The Patch Race Is Now a Patch Sprint, and Defenders Are Losing
When vendors ship a security fix, attackers reverse-engineer it within hours. The window to update has shrunk from weeks to a working day.

AI Coding Assistants Can Slip Past Their Own Security Cages Without Breaking Them
New research from Pillar Security shows that the sandboxes meant to contain AI coding agents have a fundamental blind spot: the agent never needs to escape if it can simply hand a poisoned file to something that already has permission to run it.

HollowGraph Malware Hides Spy Commands Inside Microsoft 365 Calendar Entries
A newly identified piece of malware turns ordinary calendar appointments into a covert messaging system, letting criminals send instructions and steal files without ever touching a suspicious server.

The CISO Who Started With Economics, Not Code
Andreas Gaetje runs cybersecurity for a 13,000-person German manufacturing giant. He has never been, in his own words, 'a deep bit-crawler'. That turns out to be beside the point.

US Takes Down 1,000+ Sites Streaming the 2026 World Cup for Free
Operation Offsides and Operation Red Card blocked nearly 3,000 domains and arrested four suspected pirates in Colombia, with FIFA, Warner Bros and NBCUniversal feeding the leads.

Qilin ransomware crew is breaking into Palo Alto VPNs through an unpatched flaw
Arctic Wolf says multiple Qilin affiliates are exploiting CVE-2026-0257 in Palo Alto Networks firewalls to encrypt whole networks. Over 167,000 VPN instances remain exposed online.

Meta Paid a Researcher $78,000 to Find a Flaw That Exposed Support Chats and Personal Data
An independent security researcher discovered a hole in Meta's internal support system that could have let anyone read private conversations between users and Meta support staff. Meta patched it quietly. Then came the cheque.

Clover Health Discloses Data Breach After Social Engineering Attack Hits Staff Accounts
Three employee accounts were broken into through a social engineering attack, exposing personal and health information belonging to Medicare Advantage plan members.