Latest stories — Page 41

Full-frame photoreal editorial image of a darkened developer workstation with two glowing monitors, one showing abstract code and the other showing a plain web
AI Security

A Poisoned Web Page Was Enough to Hijack Amazon's AI Coding Assistant

Researchers showed that Kiro, Amazon's AI-powered coding tool, could be tricked into running attacker code just by reading a booby-trapped web page.

3 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit server room with a single rack bathed in blue and red light, a laptop open on a nearby cart sho
Vulnerabilities

Hackers Race to Break Into WordPress Sites Through 'wp2shell' Flaws

Two critical bugs in WordPress core let attackers install backdoors without a password. Automatic updates are out, but roughly one in five sites is still exposed.

4 min read
Photoreal editorial shot of a dimly lit corporate server room, rows of rack-mounted servers glowing with amber and blue status lights, one rack door slightly aj
Vulnerabilities

Third SharePoint Flaw From July Patch Batch Is Now Being Attacked

CVE-2026-50522 lets unauthenticated attackers run code on SharePoint servers. A public proof-of-concept dropped, and the exploitation followed.

3 min read
Photoreal editorial photograph of a dimly lit industrial control room in a water treatment facility, rows of monitors showing SCADA dashboards, a single unatten
Identity & Access

Why Stolen Logins Keep Opening the Door to Power Grids and Water Plants

Attackers rarely need fancy exploits when a valid password and an unchecked laptop will do. A look at why device trust is the missing half of Zero Trust in critical infrastructure.

4 min read
A photoreal editorial image of a server room corridor at night, one rack door slightly ajar with a soft red warning light spilling out, blue status LEDs on netw
Ransomware

Qilin Ransomware Crews Break In Through Palo Alto Firewall Flaw

Arctic Wolf Labs says attackers used CVE-2026-0257, a now-patched authentication bypass in PAN-OS, to get inside networks before deploying Qilin ransomware in June 2026.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a sleek matte-black padlock resting on a softly glowing computer keyboard, cool blue and teal rim ligh
AI Security

AI Coding Tools Carry Real Security Risks, and the Danger Depends on What You're Building With

A new study tested 16 major AI coding assistants and found an average of 15 security flaws per project. The safest choice for one type of software can be one of the worst for another.

3 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
AI Security

Empirical Raises $25 Million to Predict Cyber Attacks Before They Happen

A Chicago startup says its AI tools can spot which security flaws are most likely to be exploited next. Investors just bet $25 million that it's right.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Policy & Regulation

SecurityWeek Launches Awards Programme to Spotlight Industrial Cybersecurity's Best Work

A new independently judged awards scheme will recognise the people and technologies making a real difference in protecting factories, power grids, and critical infrastructure.

3 min read
Full-frame overhead shot of a modern Android smartphone lying on a matte desk, screen glowing with faint white-on-white text patterns barely visible, next to a
AI Security

Invisible Text on an Android Screen Can Hijack AI Phone Assistants, and Then the PC Behind Them

Researchers show how a rogue Android app can whisper hidden orders to open-source AI agents, and pivot the attack onto the computer running the show.

3 min read
Full-frame photoreal editorial shot of a modern data centre hall at night, rows of server racks glowing with faint blue and amber LEDs, thick power cables snaki
Cloud Security

Bit2Watt: How a Regular Cloud Customer Could Wobble the Power Grid

Researchers at Zhejiang University say a paying cloud tenant with ordinary GPU access can swing a data centre's electricity draw hard enough to shake the grid, no hacking required.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit server room with a single rack door open, blue and amber status lights reflecting off poli
Vulnerabilities

The Patch Race Is Now a Patch Sprint, and Defenders Are Losing

When vendors ship a security fix, attackers reverse-engineer it within hours. The window to update has shrunk from weeks to a working day.

3 min read
Photoreal news-editorial image, 16:9, full frame edge to edge
AI Security

AI Coding Assistants Can Slip Past Their Own Security Cages Without Breaking Them

New research from Pillar Security shows that the sandboxes meant to contain AI coding agents have a fundamental blind spot: the agent never needs to escape if it can simply hand a poisoned file to something that already has permission to run it.

3 min read
Full-frame 16:9 photoreal editorial shot of a dimly lit server room with one rack door left ajar, faint blue LED glow spilling out onto a concrete floor, cables
Threat Intelligence

HollowGraph Malware Hides Spy Commands Inside Microsoft 365 Calendar Entries

A newly identified piece of malware turns ordinary calendar appointments into a covert messaging system, letting criminals send instructions and steal files without ever touching a suspicious server.

3 min read
A sleek, modern corporate security operations room photographed from a low angle looking toward a large curved desk with multiple dark monitors displaying abstr
Opinion

The CISO Who Started With Economics, Not Code

Andreas Gaetje runs cybersecurity for a 13,000-person German manufacturing giant. He has never been, in his own words, 'a deep bit-crawler'. That turns out to be beside the point.

3 min read
Full-frame photoreal editorial image of a darkened laptop screen displaying a generic seized-domain notice in a modern living room, glow of a football match on
Policy & Regulation

US Takes Down 1,000+ Sites Streaming the 2026 World Cup for Free

Operation Offsides and Operation Red Card blocked nearly 3,000 domains and arrested four suspected pirates in Colombia, with FIFA, Warner Bros and NBCUniversal feeding the leads.

4 min read
Photoreal editorial shot of a dimly lit server room with a rack-mounted enterprise firewall appliance glowing red on its status LEDs, blue network cables tangle
Ransomware

Qilin ransomware crew is breaking into Palo Alto VPNs through an unpatched flaw

Arctic Wolf says multiple Qilin affiliates are exploiting CVE-2026-0257 in Palo Alto Networks firewalls to encrypt whole networks. Over 167,000 VPN instances remain exposed online.

3 min read
A close-up photorealistic view of a fractured dark blue computer chip on a black reflective surface, with hairline cracks glowing faint red from underneath, sha
Vulnerabilities

Meta Paid a Researcher $78,000 to Find a Flaw That Exposed Support Chats and Personal Data

An independent security researcher discovered a hole in Meta's internal support system that could have let anyone read private conversations between users and Meta support staff. Meta patched it quietly. Then came the cheque.

3 min read
Photoreal editorial shot of a modern medical diagnostics laboratory at night, rows of automated testing machines lit by cool blue LEDs, a single unattended moni
Breaches

Clover Health Discloses Data Breach After Social Engineering Attack Hits Staff Accounts

Three employee accounts were broken into through a social engineering attack, exposing personal and health information belonging to Medicare Advantage plan members.

3 min read
Full-frame photoreal editorial shot of a darkened server room with a single glowing amber warning light reflected on rows of rack-mounted hardware, faint blue s
Vulnerabilities

Hackers Chain Two WordPress Bugs to Hijack Sites Without a Password

The flaw pair, nicknamed wp2shell, lets attackers take over vulnerable WordPress sites remotely. Mass scanning is already underway.

3 min read
Photoreal news-editorial style 16:9 image of a dark server room with faint green code reflections across black rackmount hardware, a single keyboard resting on
AI Security

Code Red Turns 25: The Worm That Still Has Things to Teach Us

A worm that spread across the internet in 2001 exposed a security blind spot that organisations keep rediscovering. Today, AI tools are the new version of the same problem.

3 min read
Photoreal news-editorial image of a rack-mounted network load balancer appliance in a dim data center aisle, cooling fans glowing amber, cables hanging from the
Vulnerabilities

Zimbra Patches Six Security Flaws, Including a Bug That Lets Strangers Run Commands on Your Email Server

The business email platform Zimbra has released a batch of fixes covering a serious command-injection flaw and five other vulnerabilities. No attacks in the wild have been confirmed, but the company is urging every customer to update immediately.

3 min read
© 2026 Threat Vectr