Latest stories — Page 48

Pentagon Hits Pause on Contractor Cybersecurity Checks, Citing Too Few Auditors and Too Much Red Tape
The Defense Department is suspending the second phase of its main cybersecurity certification programme for a 60-day review, leaving smaller defence suppliers in a holding pattern.

Fake Guardian Articles Are Tricking People Into Scam Investment Sites
Criminals are building convincing copies of trusted news websites, complete with fake celebrity stories, to push victims toward fraudulent trading platforms.

Scammers Are Calling Telstra Customers and Pretending to Help After Last Week's Outage
Criminals are cold-calling Australians and posing as Telstra staff in the days after a national network failure. Here is what happened, what data could be at risk, and what you should do if your phone rings.

The Engineers Building Both Sides of the AI Security War
A new breed of security team is quietly writing the rules for how artificial intelligence gets used in cyberattacks and defenses. Most companies have never heard of them.

Russian Spies Are Breaking Into the World's Routers. The Password Is Often Still 'Admin'.
A joint advisory from the US, UK, and a dozen allied nations warns that Russian FSB hackers have spent years walking into critical infrastructure networks through the digital equivalent of an unlocked front door.

Japan's biggest taxi firm Nihon Kotsu hit by malware, dispatch system still down
The Tokyo-based operator pulled systems offline over the weekend after detecting unauthorized access. Bookings, phone dispatch and a service for expectant mothers remain suspended.

Malicious Jscrambler npm package stole developer secrets for two hours before takedown
A poisoned release of the Jscrambler npm package was downloaded almost 1,500 times, scooping up cloud keys, wallet seed phrases and browser credentials before the company pulled it.

CrashStealer: the new Mac malware that slips past Apple's own safety checks
Researchers at Jamf Threat Labs say the C++-based stealer used an Apple-notarised installer to bypass Gatekeeper and grab passwords, browser data and crypto wallets from macOS users.

Chrome and Edge Yank ModHeader Extension After Hidden History Collector Found
The browser add-on had 1.6 million users. A dormant tracker sat inside its official store version, though no evidence suggests it ever ran.

Russia's FSB Is Quietly Hijacking Old Routers Across Critical Infrastructure, Allies Warn
A rare joint advisory from thirteen agencies details how FSB Center 16 hackers, tracked as Berserk Bear and Static Tundra, have spent over a decade pulling configs from misconfigured network gear.

GigaWiper: The Malware That Destroys on Demand
A newly uncovered piece of malicious software lets criminals break into a system, wait quietly, then choose exactly how they want to erase everything. Microsoft researchers say it is unlike anything they have tracked before.

Your AI risk register is a list, not a plan. Here is what organisations are missing.
Documenting AI risks is the easy part. Knowing who can actually shut the system down when something goes wrong is where most programmes fall apart.

CISA flags active attacks on two Joomla add-ons that let hackers take over websites
Old flaws in the iCagenda and Balbooa Forms extensions are being used to plant malicious files on Joomla sites, and the U.S. cyber agency has given federal bodies three weeks to patch.

One Poisoned Email Can Rewrite What Your AI Assistant 'Remembers' About You
Researchers show how a single message can plant a false memory in an AI agent's long-term store, quietly steering its answers in every future chat.

The Week Trusted Software Turned Hostile: ShareFile, Citrix Bleed 2, and AI Coding Attacks
Automated bug-hunting is cutting both ways, and old flaws are still landing hits because patches sat in a queue.

CISA Left AWS GovCloud Keys on GitHub for Six Months, Ignored Nine Alerts
The US cyber agency's own postmortem admits it missed automated warnings, muddled its reporting channels, and took two days to rotate leaked admin credentials.

ScamBuster Turns Phishing Emails Into Intelligence by Pretending to Be the Victim
A French engineer built an AI system that replies to scam emails, plays along long enough to extract bank details and phone numbers, then hands the data to investigators.

From Prison to Cybersecurity Advocate: The Jesse McGraw Story
Once known online as GhostExodus, Jesse McGraw hacked hospital systems as a teenager, went to federal prison, and came out the other side trying to help defenders. His story is a rare look at what radicalises young hackers and what, sometimes, pulls them back.

Lidl Customers in Three Countries Warned After Supplier Breach Exposes Personal Data
The German discount chain says a file at an outside IT provider was raided, spilling names, phone numbers and dates of birth for online shoppers in Germany, Belgium and the Netherlands.

Varonis Launches Free Entra ID Training Game to Teach Cloud Identity Attacks
Breach at the Beach is a browser-based challenge that walks defenders through the kind of Microsoft Entra ID attacks Varonis researchers say they see in real customer environments.

Forg365: A $400-a-Month Kit That Hijacks Microsoft 365 Logins
A new subscription phishing service uses device codes, session theft and AI-written lures to break into corporate email accounts.