Latest stories — Page 42

Photoreal editorial image, 16:9, full-frame edge to edge
Threat Intelligence

Russian spies are hijacking Europe's security cameras to watch weapons move to Ukraine

Dutch intelligence says a Kremlin unit is quietly logging into internet-connected CCTV to track military convoys, aid shipments and troop positions.

3 min read
A digital lock symbol over a network diagram, representing cybersecurity
Vulnerabilities

A Flaw in WordPress's Core Code Lets Criminals Take Over Websites Without Logging In

A newly discovered vulnerability in WordPress versions 6.9 and 7.0 lets attackers run their own commands on any affected site with no password required. Patches are out now.

3 min read
Full-frame photoreal editorial image of a dimly lit server room with rack lights glowing amber and blue, one rack door slightly ajar, faint holographic swarm of
AI Security

An AI agent broke into Hugging Face and stole credentials from the inside

The company says attackers used an autonomous AI system to run thousands of automated actions across its data pipeline, stealing cloud keys before staff caught on.

4 min read
Full-frame photoreal editorial image of a dimly lit university physics laboratory at night, glowing computer monitors showing generic webmail interface reflecti
Threat Intelligence

Microsoft Warns of Two ACR Stealer Campaigns Stealing Credentials Through Fake Fixes

Between late April and mid-June 2026, two separate criminal campaigns used a trick called ClickFix to persuade workers to hand over browser passwords, session tokens, and business documents, with no software flaw required.

3 min read
Photoreal news-editorial style, 16:9
Policy & Regulation

A New Index Is Tracking Every Major Corporate Data Breach, and Deliberately Leaving the Dollar Totals Out

Richard Bird, a veteran cybersecurity executive, has built a public tool that logs every significant breach companies are required to report. Its unusual choice: no running loss tally.

3 min read
Photoreal news-editorial 16:9 image of a large Japanese urban data centre at dusk, exterior shot, rows of cooling units and server ventilation grilles lit by am
Breaches

Ernst & Young Client Data Stolen in Third-Party Platform Breach

Names, Social Security numbers, and card details belonging to Ernst & Young clients were taken after criminals broke into a third-party software platform the firm used to manage data.

3 min read
Full-frame edge-to-edge photoreal editorial shot of a dimly lit corporate server room, rows of rack-mounted servers with amber and red status LEDs glowing, one
Vulnerabilities

Microsoft admits Windows update server sync has been broken for over a week

WSUS synchronization failures have blocked enterprise Windows updates since July 13, 2026, with only new installations fully restored so far.

4 min read
An AI scanning software code for vulnerabilities
AI Security

Capital One Releases Free AI Security Tool That Hunts Down Code Flaws Automatically

VulnHunter scans software for exploitable weaknesses and suggests fixes. The bank is giving it away free, arguing no single company can solve this problem alone.

3 min read
A close-up grid of eight portrait photographs arranged in two rows against a neutral grey background, half subtly lit with warm natural light suggesting authent
AI Security

An AI Bot Broke Into Hugging Face. Hugging Face Used AI to Figure Out What It Did.

The machine learning platform says an automated attack ran tens of thousands of actions inside its systems before being caught. Here is what got in, what was taken, and what ordinary users need to know.

3 min read
Full-frame photoreal editorial image of a modern enterprise data centre corridor at night, glowing amber server indicator lights reflecting off a polished floor
Vulnerabilities

Hackers Start Breaking Into ServiceNow AI Platform Through Critical Flaw CVE-2026-6875

Attackers are exploiting a pre-authentication bug in ServiceNow's flagship platform just days after patches shipped, researchers confirm.

4 min read
Photoreal news-editorial overhead shot of a darkened security operations center desk, multiple monitors glowing blue with abstract vulnerability dashboards and
Vulnerabilities

Google Patches Seven Memory Safety Bugs in Chrome 150, Three Rated Critical

All seven flaws were found internally or by researchers, not by criminals. But history says patch fast anyway.

3 min read
A photoreal editorial image of a modern computer server room, with glowing monitors displaying complex data visualizations, representing AI involvement in cyber
AI Security

Claude Mythos: A New Frontier in AI Cybersecurity

Anthropic's Claude Mythos emerges as a powerful AI tool for cybersecurity, promising faster vulnerability discovery but raising concerns over potential misuse.

3 min read
Photoreal editorial image of a dimly lit server room with rows of glowing blue and amber indicator lights on rack-mounted machines, one open cabinet showing exp
AI Security

Hugging Face Says an Autonomous AI Agent Broke Into Its Production Systems

The AI hosting giant disclosed unauthorised access to internal datasets and staff credentials, in what it says was an attack driven by an automated AI agent rather than a human operator.

4 min read
Full-frame overhead photograph of a developer workstation at night, glowing terminal window on a matte black laptop screen showing generic package installation
Threat Intelligence

SleeperGem: Three Booby-Trapped Ruby Packages Slip Onto RubyGems

Researchers say the malicious gems sat quietly on the official Ruby package registry, waiting to pull down further attacker code onto developer laptops.

3 min read
Macro photograph of tangled fiber optic cables glowing in deep blue and green light against a dark server room background, sharp focus on the glass fiber tips w
Vulnerabilities

WP2Shell: Two WordPress Flaws Are Being Exploited Right Now, and Millions of Sites Are at Risk

A pair of newly patched security holes in WordPress are already being used in live attacks. No login required. No special setup needed. Just a vulnerable website.

3 min read
Photoreal news-editorial style, 16:9 framing
Policy & Regulation

Trump Declassifies Election Fraud Claims: What Was Actually Said

President Trump addressed the nation on election security, citing newly declassified material and pointing a finger at China. Here is what we know, and what remains unverified.

3 min read
AI analyzing network data
Policy & Regulation

New Zealand's Privacy Commissioner Warns of a Hidden Threat Inside Your Own Organisation

A quarter of all reported privacy breaches in New Zealand now involve staff snooping on people's personal records. Organised crime is making the problem worse.

3 min read
A dimly lit modern security operations centre viewed from behind an empty analyst chair, multiple large curved monitors glowing with abstract log data and netwo
Policy & Regulation

Trump Claims China Stole 220 Million Voters' Data. His Own Intelligence Community Disagrees.

A primetime White House address aired sweeping allegations about Chinese data theft, dead voters, and rigged machines. The declassified documents released alongside the speech told a quieter story.

3 min read
Full-frame photoreal editorial image of a dimly lit server rack in a data centre, one status light glowing red among rows of green, cool blue ambient lighting,
Vulnerabilities

Critical NGINX Flaw Lets Attackers Crash Web Servers From Afar

F5 has patched CVE-2026-42533, a memory bug in nginx that a remote attacker can trigger with a single crafted request.

3 min read
Photoreal editorial shot of a dimly lit server room in a Russian government building, rows of network equipment with faint green status lights, a single monitor
Threat Intelligence

Hackers hijack Russian security tool ViPNet to spy on government agencies

A campaign called HelloNet has been slipping malicious files into ViPNet updates since May, hitting Russian ministries, energy firms and transport operators.

3 min read
Photoreal news-editorial image, 16:9, full-frame edge to edge, close-up of a rack-mounted network security appliance in a dim server room, glowing blue and ambe
Vulnerabilities

SonicWall VPN Appliances Hit by Zero-Day Attacks Weeks Before Public Warning

A newly identified group, tracked as UTA0533, broke into SonicWall SMA 1000 devices using unknown flaws from late June 2026, gaining the highest level of access.

3 min read
© 2026 Threat Vectr