Latest stories — Page 44

New Zealand's Privacy Commissioner Warns of a Hidden Threat Inside Your Own Organisation
A quarter of all reported privacy breaches in New Zealand now involve staff snooping on people's personal records. Organised crime is making the problem worse.

Trump Claims China Stole 220 Million Voters' Data. His Own Intelligence Community Disagrees.
A primetime White House address aired sweeping allegations about Chinese data theft, dead voters, and rigged machines. The declassified documents released alongside the speech told a quieter story.

Critical NGINX Flaw Lets Attackers Crash Web Servers From Afar
F5 has patched CVE-2026-42533, a memory bug in nginx that a remote attacker can trigger with a single crafted request.

Hackers hijack Russian security tool ViPNet to spy on government agencies
A campaign called HelloNet has been slipping malicious files into ViPNet updates since May, hitting Russian ministries, energy firms and transport operators.

SonicWall VPN Appliances Hit by Zero-Day Attacks Weeks Before Public Warning
A newly identified group, tracked as UTA0533, broke into SonicWall SMA 1000 devices using unknown flaws from late June 2026, gaining the highest level of access.

Russian Military Hackers Trick Ukrainians Into Infecting Their Own PCs
Ukraine's cyber emergency team says a Sandworm sub-group is using fake CAPTCHA prompts to plant data-stealing malware.

Australian Health Clinics Waited 22 Days to Warn Patients After Hackers Stole Medical Records
Partnered Health, which operates more than 60 clinics across Australia, sat on a serious data theft for three weeks before telling anyone. Experts say that gap is long enough to cause real harm.

Hackers Hit 21 Australian Health Clinics, Putting Medicare Numbers and Test Results at Risk
Partnered Health confirmed a data breach on 23 June that reached patient files across Sydney, Melbourne and Canberra. Experts warn the stolen records could surface for sale on hidden online marketplaces.

Moroccan Intelligence Insider Blows Whistle on Years of Pegasus Spyware Targeting
A former spy describes how Morocco reportedly used phone-hacking software since 2017 to surveil journalists, human rights workers, and foreign politicians, including cabinet ministers in Spain and officials in France.

Two Scattered Spider Hackers Jailed for Attacking Transport for London
Owen Flowers, 18, and Thalha Jubair, 20, each received five-and-a-half years after pleading guilty to a 2024 attack that stole data on up to 10 million customers and cost TfL £29 million to recover from.

7-Zip Ships Emergency Fix for Flaw That Lets Booby-Trapped Archives Run Code
Version 26.02 patches a heap buffer overflow in XZ decompression. There is no auto-update, so users have to grab it themselves.

Microsoft sees spike in ACR Stealer attacks lifting passwords and session tokens from browsers
The info-stealer is arriving through fake 'fix this error' prompts and hidden inside JPEG images, and it walks off with the browser cookies that keep users signed in.

On-Device Age Checks: The Quiet Fix to a Loud Privacy Problem
New age verification laws are forcing websites to check how old you are. A newer approach keeps your face on your phone instead of shipping it to a server.

Locksmith Scams Up 147 Percent: How Criminals Are Gaming Google Search to Trap People in Crisis
Fake locksmiths are buying their way to the top of search results, then charging thousands for simple jobs. A new regulatory gap is letting them operate freely.

Timor-Leste Police Arrest 314 People in Raids on Scam Call Centre Compounds
A country just 700 kilometres from Darwin has become the latest staging ground for international phone fraud, as police crack down on fortified compounds packed with laptops, SIM cards, and satellite internet equipment.

A WordPress Bug Lets Strangers Run Code on Your Site. No Login Required.
Every WordPress 6.9 and 7.0 site was exposed until a Friday emergency patch. The fix is being force-installed.

Abbott Digs Into Two Cyber Incidents at Its Cancer Diagnostics Arm
The medical giant is investigating a break-in at old Exact Sciences systems and a separate extortion claim tied to a research portal.

Ransomware Gang Exploited Two SonicWall Security Flaws Before a Fix Existed
A group tied to Inc ransomware broke into enterprise networks through a pair of critical holes in SonicWall remote-access devices, stealing credentials and preparing to lock down files.

Seven booby-trapped npm packages hit Vite developers with blockchain-controlled malware
Researchers at Checkmarx say the ViteVenom campaign hides its command server across four different cryptocurrency networks, making it unusually hard to shut down.

How a String of Morse Code Tricked an AI Into Wiring Real Money
A crypto heist nobody heard much about previews a dangerous new kind of attack, one that needs no stolen passwords, no malware, and no hacked firewall.

An 11-byte message can knock OpenSSL servers offline, researchers warn
A newly disclosed flaw nicknamed HollowByte lets attackers exhaust memory on servers running vulnerable versions of OpenSSL, the software that secures most of the web.