Latest stories — Page 42

Russian spies are hijacking Europe's security cameras to watch weapons move to Ukraine
Dutch intelligence says a Kremlin unit is quietly logging into internet-connected CCTV to track military convoys, aid shipments and troop positions.

A Flaw in WordPress's Core Code Lets Criminals Take Over Websites Without Logging In
A newly discovered vulnerability in WordPress versions 6.9 and 7.0 lets attackers run their own commands on any affected site with no password required. Patches are out now.

An AI agent broke into Hugging Face and stole credentials from the inside
The company says attackers used an autonomous AI system to run thousands of automated actions across its data pipeline, stealing cloud keys before staff caught on.

Microsoft Warns of Two ACR Stealer Campaigns Stealing Credentials Through Fake Fixes
Between late April and mid-June 2026, two separate criminal campaigns used a trick called ClickFix to persuade workers to hand over browser passwords, session tokens, and business documents, with no software flaw required.

A New Index Is Tracking Every Major Corporate Data Breach, and Deliberately Leaving the Dollar Totals Out
Richard Bird, a veteran cybersecurity executive, has built a public tool that logs every significant breach companies are required to report. Its unusual choice: no running loss tally.

Ernst & Young Client Data Stolen in Third-Party Platform Breach
Names, Social Security numbers, and card details belonging to Ernst & Young clients were taken after criminals broke into a third-party software platform the firm used to manage data.

Microsoft admits Windows update server sync has been broken for over a week
WSUS synchronization failures have blocked enterprise Windows updates since July 13, 2026, with only new installations fully restored so far.

Capital One Releases Free AI Security Tool That Hunts Down Code Flaws Automatically
VulnHunter scans software for exploitable weaknesses and suggests fixes. The bank is giving it away free, arguing no single company can solve this problem alone.

An AI Bot Broke Into Hugging Face. Hugging Face Used AI to Figure Out What It Did.
The machine learning platform says an automated attack ran tens of thousands of actions inside its systems before being caught. Here is what got in, what was taken, and what ordinary users need to know.

Hackers Start Breaking Into ServiceNow AI Platform Through Critical Flaw CVE-2026-6875
Attackers are exploiting a pre-authentication bug in ServiceNow's flagship platform just days after patches shipped, researchers confirm.

Google Patches Seven Memory Safety Bugs in Chrome 150, Three Rated Critical
All seven flaws were found internally or by researchers, not by criminals. But history says patch fast anyway.

Claude Mythos: A New Frontier in AI Cybersecurity
Anthropic's Claude Mythos emerges as a powerful AI tool for cybersecurity, promising faster vulnerability discovery but raising concerns over potential misuse.

Hugging Face Says an Autonomous AI Agent Broke Into Its Production Systems
The AI hosting giant disclosed unauthorised access to internal datasets and staff credentials, in what it says was an attack driven by an automated AI agent rather than a human operator.

SleeperGem: Three Booby-Trapped Ruby Packages Slip Onto RubyGems
Researchers say the malicious gems sat quietly on the official Ruby package registry, waiting to pull down further attacker code onto developer laptops.

WP2Shell: Two WordPress Flaws Are Being Exploited Right Now, and Millions of Sites Are at Risk
A pair of newly patched security holes in WordPress are already being used in live attacks. No login required. No special setup needed. Just a vulnerable website.

Trump Declassifies Election Fraud Claims: What Was Actually Said
President Trump addressed the nation on election security, citing newly declassified material and pointing a finger at China. Here is what we know, and what remains unverified.

New Zealand's Privacy Commissioner Warns of a Hidden Threat Inside Your Own Organisation
A quarter of all reported privacy breaches in New Zealand now involve staff snooping on people's personal records. Organised crime is making the problem worse.

Trump Claims China Stole 220 Million Voters' Data. His Own Intelligence Community Disagrees.
A primetime White House address aired sweeping allegations about Chinese data theft, dead voters, and rigged machines. The declassified documents released alongside the speech told a quieter story.

Critical NGINX Flaw Lets Attackers Crash Web Servers From Afar
F5 has patched CVE-2026-42533, a memory bug in nginx that a remote attacker can trigger with a single crafted request.

Hackers hijack Russian security tool ViPNet to spy on government agencies
A campaign called HelloNet has been slipping malicious files into ViPNet updates since May, hitting Russian ministries, energy firms and transport operators.

SonicWall VPN Appliances Hit by Zero-Day Attacks Weeks Before Public Warning
A newly identified group, tracked as UTA0533, broke into SonicWall SMA 1000 devices using unknown flaws from late June 2026, gaining the highest level of access.