Latest stories — Page 46

China-Linked 'Daxin' Rootkit Returns After Four Years, Found Inside Taiwan Factory
The stealthy kernel malware, last documented in 2022, showed up alongside a new backdoor called Stupig on a manufacturer's network.

A single fake review can trick an AI agent into buying the wrong product
Researchers describe a new class of attack where planted content on trusted pages steers AI assistants into harmful actions without ever hijacking the task itself.

Brazilian Government Sites Turned Into Malware Traps in PhantomEnigma Campaign
Attackers quietly took over more than 20 official .gov.br domains and used them to push a stealthy backdoor, according to new analysis from ANY.RUN.

Windows 11 24H2 Home and Pro users have three months before security updates stop
Microsoft has set 13 October 2026 as the cut-off for monthly patches on Windows 11 24H2 Home and Pro, and on Windows 10 Enterprise LTSB 2016.

Oak Raises $60 Million to Replace Fragmented Identity Security Tools With a Single Platform
A new Israeli-American startup wants to give companies one place to see and control every username, AI agent, and automated system that can touch their data.

AI Finds Bugs Fast. Proving They're Real Still Takes a Human.
AI tools can scan code and spit out vulnerabilities at speed, but a finding is worthless until someone shows it actually works. Here's why that gap matters for anyone worried about software security.

One Hacked Shark Robot Vacuum Can Hand an Attacker the Keys to Every Shark Vacuum in the Region
A researcher pulled a security key off a $500 robot vacuum and used it to run commands on other people's Shark vacuums, including reading their Wi-Fi passwords in plaintext.

Splunk and Zoom Fix Security Flaws That Could Let Hackers Take Over Accounts
Both companies pushed out patches this week. One Zoom flaw scores a near-perfect danger rating and could let a criminal break into accounts without knowing a password.

US government orders emergency patch for critical Oracle finance software flaw
CISA gave federal agencies until Saturday to fix CVE-2026-46817, an Oracle E-Business Suite bug already under attack.

Five Government Agencies Tell Software Makers: Open a Front Door for Bug Reporters
CISA and four allied agencies have published a joint guide urging tech companies to set up formal programmes so security researchers can safely report flaws before criminals find them first.

AI Can Build a Dossier on Your CEO in Ten Minutes. Most Companies Have No Answer for That.
Artificial intelligence tools have turned the slow, skilled work of researching a target executive into a task anyone with a browser can do. Security teams have not caught up.

Russian Crew Hides Starland Backdoor Inside Fake Zoom and WebEx Installers
UAT-11795 is spiking popular software downloads with a credential-and-crypto stealer, and US users are the main target.

Spirals ransomware crew locked down an IT firm's network in under a day
A new group broke in through an exposed web server, disabled defences and encrypted files inside 24 hours, Symantec says.

Give an AI a Body and You Give It an Attack Surface
Warehouses and factories are buying humanoid robots before security teams have a single audit standard to work from. Here is what that means for the people on the floor.

F5 Fixes Serious Security Flaws in NGINX and BIG-IP
Multiple vulnerabilities in two widely used pieces of networking software could have let attackers take control of systems, crash services, or steal data. Patches are now available.

China's Military Is Quietly Banning Its Own Cybersecurity Companies
Chinese armed forces are shutting some of the country's biggest cybersecurity firms out of military contracts, and the reason has nothing to do with bad software.

How a Spanish Cybercrime Gang Stole €140 Million and Almost Got Away With It
Spanish police, working with partners across Europe and beyond, dismantled a fraud network that used fake boss emails, phony investment sites, and nearly a thousand bank accounts to steal the equivalent of $161 million from ordinary people and businesses.

AI Is Finding Software Flaws Faster Than Companies Can Fix Them. Something Has to Change.
Security experts are calling time on the old 'scan once a month, patch when you can' model. Artificial intelligence now finds vulnerabilities faster than human teams can close them.

Nightmare Eclipse Releases 'LegacyHive' Windows Zero-Day on Patch Tuesday
A prolific anonymous researcher drops yet another unpatched Windows flaw, this time one that lets ordinary users quietly take control of administrator accounts.

Four Security Firms Patch Serious Flaws in Their Own Products
Tenable, ESET, Tanium, and Trend Micro have all pushed out fixes this month for high- and critical-severity vulnerabilities in tools that businesses rely on to stay secure.

Australian Actress Falls Victim to $10,500 Insurance Scam
Christine Whelan Browne, a well-known Australian theatre actress, warns others about an insurance scam after losing her car.