Latest stories — Page 47

ClickLock: The Mac Stealer That Won't Let You Work Until You Hand Over Your Password
A new macOS malware kills your apps in a loop every 210 milliseconds, holding your machine hostage until you type in your login password.

TELEPUZ: The New Malware Hiding Behind Fake 'Fix This' Website Pop-ups
A modular info-stealer is spreading through booby-trapped websites that trick visitors into pasting malicious commands into their own computers.

Two Scattered Spider Members Jailed in UK's Largest Ever Cybercrime Prosecution
Thalha Jubair and Owen Flowers each received five and a half years in prison for a 2024 attack on Transport for London that cost the city £29 million.

AI Data Centres Are Being Built at Speed. Security Is Not Keeping Up.
A new report finds that the same assumptions baked into traditional data centres are being carried straight into AI facilities, where the stakes are much higher and the blast radius is far wider.

ClickLock Stealer Tricks Mac Users Into Handing Over Their Own Passwords
A newly discovered piece of Mac malware skips the usual hacking tricks and simply persuades victims to run it themselves, then locks the screen until they surrender their passwords.

China-Linked 'Daxin' Rootkit Returns After Four Years, Found Inside Taiwan Factory
The stealthy kernel malware, last documented in 2022, showed up alongside a new backdoor called Stupig on a manufacturer's network.

A single fake review can trick an AI agent into buying the wrong product
Researchers describe a new class of attack where planted content on trusted pages steers AI assistants into harmful actions without ever hijacking the task itself.

Brazilian Government Sites Turned Into Malware Traps in PhantomEnigma Campaign
Attackers quietly took over more than 20 official .gov.br domains and used them to push a stealthy backdoor, according to new analysis from ANY.RUN.

Windows 11 24H2 Home and Pro users have three months before security updates stop
Microsoft has set 13 October 2026 as the cut-off for monthly patches on Windows 11 24H2 Home and Pro, and on Windows 10 Enterprise LTSB 2016.

Oak Raises $60 Million to Replace Fragmented Identity Security Tools With a Single Platform
A new Israeli-American startup wants to give companies one place to see and control every username, AI agent, and automated system that can touch their data.

AI Finds Bugs Fast. Proving They're Real Still Takes a Human.
AI tools can scan code and spit out vulnerabilities at speed, but a finding is worthless until someone shows it actually works. Here's why that gap matters for anyone worried about software security.

One Hacked Shark Robot Vacuum Can Hand an Attacker the Keys to Every Shark Vacuum in the Region
A researcher pulled a security key off a $500 robot vacuum and used it to run commands on other people's Shark vacuums, including reading their Wi-Fi passwords in plaintext.

Splunk and Zoom Fix Security Flaws That Could Let Hackers Take Over Accounts
Both companies pushed out patches this week. One Zoom flaw scores a near-perfect danger rating and could let a criminal break into accounts without knowing a password.

US government orders emergency patch for critical Oracle finance software flaw
CISA gave federal agencies until Saturday to fix CVE-2026-46817, an Oracle E-Business Suite bug already under attack.

Five Government Agencies Tell Software Makers: Open a Front Door for Bug Reporters
CISA and four allied agencies have published a joint guide urging tech companies to set up formal programmes so security researchers can safely report flaws before criminals find them first.

AI Can Build a Dossier on Your CEO in Ten Minutes. Most Companies Have No Answer for That.
Artificial intelligence tools have turned the slow, skilled work of researching a target executive into a task anyone with a browser can do. Security teams have not caught up.

Russian Crew Hides Starland Backdoor Inside Fake Zoom and WebEx Installers
UAT-11795 is spiking popular software downloads with a credential-and-crypto stealer, and US users are the main target.

Spirals ransomware crew locked down an IT firm's network in under a day
A new group broke in through an exposed web server, disabled defences and encrypted files inside 24 hours, Symantec says.

Give an AI a Body and You Give It an Attack Surface
Warehouses and factories are buying humanoid robots before security teams have a single audit standard to work from. Here is what that means for the people on the floor.

F5 Fixes Serious Security Flaws in NGINX and BIG-IP
Multiple vulnerabilities in two widely used pieces of networking software could have let attackers take control of systems, crash services, or steal data. Patches are now available.

China's Military Is Quietly Banning Its Own Cybersecurity Companies
Chinese armed forces are shutting some of the country's biggest cybersecurity firms out of military contracts, and the reason has nothing to do with bad software.