Latest stories — Page 45

Fake QR code stickers on Christchurch parking meters are stealing payments
Scammers placed fraudulent stickers over real payment instructions to redirect drivers to copycat websites. The Christchurch City Council is urging residents not to scan any QR code found on a parking machine.

AI Agents Can Go Rogue. Your Security Model Was Never Built to Stop Them.
A cybersecurity expert warns that AI agents, software programs that make decisions and take actions on their own, break every assumption that four decades of security thinking was built on. The fix is not a new tool. It is a new way of thinking.

ClickLock: the Mac malware that locks up your screen until you type your password
A new macOS stealer, tracked by Group-IB, freezes everything on the screen except a password box. It has already hit around 100 machines in 33 countries.

Two Scattered Spider hackers get 5.5 years each for crippling London's transport network
Thalha Jubair and Owen Flowers pleaded guilty to the August 2024 attack on Transport for London, which cost the agency £29 million and briefly threatened chaos for 8.4 million passengers.

Ransomware Attack Halts Fairlife Milk Production Across the US
Coca-Cola told the SEC that hackers broke into its Fairlife dairy subsidiary, forcing the company to stop making protein shakes and ultra-filtered milk at its American plants.

Over a Million Phishing Emails Used Hidden Text to Fool AI Security Filters
Researchers found that criminals are hiding innocent words inside malicious emails to confuse both traditional and AI-powered spam filters, and the technique is working.

A Flaw in Claude's Chrome Extension Let Rogue Add-ons Hijack the AI Assistant
Anthropic patched a bug that let malicious browser extensions puppet Claude into touching a user's Gmail, Google Docs, and Salesforce accounts.

CISA Flags Three Actively Exploited Bugs in Fortinet and SharePoint
Two Fortinet FortiSandbox flaws and a Microsoft SharePoint deserialization bug are being used in real attacks, the US cyber agency warns.

Zoom patches a flaw that could hand strangers full control of your account
A critical bug in Zoom's Windows software let attackers take over accounts without a password, a click, or any help from the victim. Zoom found it first and patched it. Here is what you need to know.

This Week's Cyber Mess: Fake Repos, Chrome Sync Stalking and a Ransomware Crew That Moves in a Day
A roundup of the week's smaller stories that share one uncomfortable theme: attacks that succeed because something looked close enough to trust.

Siemens Patches Four Flaws in SICAM 8 Grid Kit, Including a Firmware Signing Bypass
The German industrial giant is pushing V26.20 firmware for gear that sits inside power stations. One bug lets an insider install their own firmware.

A malformed packet can knock Rockwell's Flex 5000 Adapter offline until someone power-cycles it
Rockwell Automation has patched a denial-of-service flaw in a widely deployed factory-floor module. The fix ships as firmware 6.012.

The Machines That Run the World Are Running Decades-Old Software
Industrial control systems keep factories, water plants, and power grids alive. They also run code written before Wi-Fi existed. Fixing that is harder than it sounds.

n8n Login Bug Let a Valid Token From One Provider Log You In as Someone Else
The workflow automation platform matched users on a single ID field and ignored who issued the token. On Enterprise setups with more than one login provider, that was enough to walk in as another person.

AI Agents Are Making Security Playbooks Obsolete. Identity Is the Fix.
Security teams built their rules for humans clicking buttons. AI agents click a thousand buttons a second, and the old playbook cannot keep up.

23andMe to pay $18 million after 43 states found 'flimsy' security let hackers steal 6.9 million profiles
A coalition of state attorneys general says the DNA testing firm lacked basic protections like multifactor authentication before the 2023 breach that exposed genetic data on nearly seven million customers.

ClickLock: The Mac Stealer That Won't Let You Work Until You Hand Over Your Password
A new macOS malware kills your apps in a loop every 210 milliseconds, holding your machine hostage until you type in your login password.

TELEPUZ: The New Malware Hiding Behind Fake 'Fix This' Website Pop-ups
A modular info-stealer is spreading through booby-trapped websites that trick visitors into pasting malicious commands into their own computers.

Two Scattered Spider Members Jailed in UK's Largest Ever Cybercrime Prosecution
Thalha Jubair and Owen Flowers each received five and a half years in prison for a 2024 attack on Transport for London that cost the city £29 million.

AI Data Centres Are Being Built at Speed. Security Is Not Keeping Up.
A new report finds that the same assumptions baked into traditional data centres are being carried straight into AI facilities, where the stakes are much higher and the blast radius is far wider.

ClickLock Stealer Tricks Mac Users Into Handing Over Their Own Passwords
A newly discovered piece of Mac malware skips the usual hacking tricks and simply persuades victims to run it themselves, then locks the screen until they surrender their passwords.