Latest stories — Page 43

Before Anyone Reaches the Gate: Why Event Security Starts in the Digital World
A major concert, a championship, a political gathering: the real threats often take shape online, days or weeks before the first fan walks through the door.

How to actually test an AI SOC before you buy one
A new buyer's guide argues that vendor demos hide more than they reveal, and lays out how to stress-test AI security tools against your own data.

SonicWall Security Devices Were Hacked for Weeks Before a Fix Existed
Criminals planted hidden malware inside SonicWall remote-access appliances at least three weeks before the manufacturer knew the attack routes existed. Two fresh vulnerabilities, now patched, gave intruders near-total control of the devices.

A Week When Small Inputs Caused Big Damage
WordPress code execution, SonicWall zero-days, attacks on AI services, and a fresh SharePoint flaw defined a punishing seven days for defenders.

The Real Mythos Problem Isn't New Bugs. It's How Long Yours Stay Open.
Anthropic's AI-driven vulnerability finder has flooded the pipeline since April. But the harder question for defenders is how many days a known flaw sits unpatched on their own network.

Russian spies are hijacking Europe's security cameras to watch weapons move to Ukraine
Dutch intelligence says a Kremlin unit is quietly logging into internet-connected CCTV to track military convoys, aid shipments and troop positions.

A Flaw in WordPress's Core Code Lets Criminals Take Over Websites Without Logging In
A newly discovered vulnerability in WordPress versions 6.9 and 7.0 lets attackers run their own commands on any affected site with no password required. Patches are out now.

An AI agent broke into Hugging Face and stole credentials from the inside
The company says attackers used an autonomous AI system to run thousands of automated actions across its data pipeline, stealing cloud keys before staff caught on.

Microsoft Warns of Two ACR Stealer Campaigns Stealing Credentials Through Fake Fixes
Between late April and mid-June 2026, two separate criminal campaigns used a trick called ClickFix to persuade workers to hand over browser passwords, session tokens, and business documents, with no software flaw required.

A New Index Is Tracking Every Major Corporate Data Breach, and Deliberately Leaving the Dollar Totals Out
Richard Bird, a veteran cybersecurity executive, has built a public tool that logs every significant breach companies are required to report. Its unusual choice: no running loss tally.

Ernst & Young Client Data Stolen in Third-Party Platform Breach
Names, Social Security numbers, and card details belonging to Ernst & Young clients were taken after criminals broke into a third-party software platform the firm used to manage data.

Microsoft admits Windows update server sync has been broken for over a week
WSUS synchronization failures have blocked enterprise Windows updates since July 13, 2026, with only new installations fully restored so far.

Capital One Releases Free AI Security Tool That Hunts Down Code Flaws Automatically
VulnHunter scans software for exploitable weaknesses and suggests fixes. The bank is giving it away free, arguing no single company can solve this problem alone.

An AI Bot Broke Into Hugging Face. Hugging Face Used AI to Figure Out What It Did.
The machine learning platform says an automated attack ran tens of thousands of actions inside its systems before being caught. Here is what got in, what was taken, and what ordinary users need to know.

Hackers Start Breaking Into ServiceNow AI Platform Through Critical Flaw CVE-2026-6875
Attackers are exploiting a pre-authentication bug in ServiceNow's flagship platform just days after patches shipped, researchers confirm.

Google Patches Seven Memory Safety Bugs in Chrome 150, Three Rated Critical
All seven flaws were found internally or by researchers, not by criminals. But history says patch fast anyway.

Claude Mythos: A New Frontier in AI Cybersecurity
Anthropic's Claude Mythos emerges as a powerful AI tool for cybersecurity, promising faster vulnerability discovery but raising concerns over potential misuse.

Hugging Face Says an Autonomous AI Agent Broke Into Its Production Systems
The AI hosting giant disclosed unauthorised access to internal datasets and staff credentials, in what it says was an attack driven by an automated AI agent rather than a human operator.

SleeperGem: Three Booby-Trapped Ruby Packages Slip Onto RubyGems
Researchers say the malicious gems sat quietly on the official Ruby package registry, waiting to pull down further attacker code onto developer laptops.

WP2Shell: Two WordPress Flaws Are Being Exploited Right Now, and Millions of Sites Are at Risk
A pair of newly patched security holes in WordPress are already being used in live attacks. No login required. No special setup needed. Just a vulnerable website.

Trump Declassifies Election Fraud Claims: What Was Actually Said
President Trump addressed the nation on election security, citing newly declassified material and pointing a finger at China. Here is what we know, and what remains unverified.