Latest stories — Page 49

Two Clicks to Own a Developer's Machine: The Cursor AI Flaw You Should Know About
Researchers found they could smuggle a malicious installation command into the most popular AI code editor by hiding it inside what looked like a routine code-review link.

A Hidden Door in Windows: How Attackers Can Blind Security Software to Malware
Researchers at Bitdefender have shown how a little-known Windows feature called bind links can be twisted to make malicious files invisible to the tools companies rely on to catch intrusions.

Cloud Security Professionals Gather Virtually to Tackle Shared Threats
A summit for security teams wrestling with cloud and data protection brings together practitioners and vendors, here is why these conversations matter to anyone whose data lives online.

The 'Approval Gap' in Ad Tech: When Marketing Tags Smuggle in Unknown Code
A single approved script on your website can quietly pull in code from vendors your security team has never heard of. Here is why that matters.

Researcher Publishes Windows Privilege-Escalation Exploit Hours After Microsoft's Monthly Patch
A proof-of-concept called LegacyHive targets the Windows User Profile Service, raising fresh questions about coordinated disclosure timing.

White House Launches AI-Powered Clearinghouse to Fix Software Flaws Faster
A new federal program called Gold Eagle will use artificial intelligence to sort and prioritise software vulnerabilities across government agencies and critical industries. Whether it delivers depends almost entirely on execution.

The AI Blind Spot in Corporate Security: Why Old Traffic Inspection Is Falling Behind
Employees are pasting company secrets into ChatGPT and installing rogue browser add-ons. The security tools most firms rely on can't see any of it.

Cribl Buys CardinalOps to Close the Gap Between Collecting Security Data and Acting on It
The $3.5 billion data-pipeline company moves beyond simply gathering security information, adding AI-powered tools that tell defenders where their defences are actually failing.

Bugs in Claude's Chrome Extension Let Other Add-Ons Read Your Gmail and Docs
Security researchers say two unpatched flaws in Anthropic's browser assistant can be exploited to silently pull private data from Google services, and a simple one-line fix has gone unshipped for months.

US Charges Three Russians for Running 'Bulletproof' Hosting That Powered Ransomware and Phishing Attacks on 42 American Organisations
A grand jury indictment unsealed this week names Aleksandr Volosovik, Kirill Zatolokin, and Yulia Pankova as the operators behind two companies that rented out hidden, hard-to-shut-down internet infrastructure to criminals worldwide.

Cursor on Windows Runs Rogue git.exe From Any Opened Repo, No Warning
A flaw in the AI code editor lets a booby-trapped repository execute code on a developer's machine the moment the folder is opened.

Fortinet, Ivanti, and ServiceNow patch 15 flaws, including a critical no-login attack on ServiceNow's AI platform
A flaw rated 9.5 out of 10 in severity lets criminals run malicious code on ServiceNow systems without needing a password. Twelve Fortinet products and two Ivanti tools also received fixes on the same day.

White House Launches 'Gold Eagle' to Speed Up Vulnerability Fixes Across Critical Infrastructure
A new government programme pairs open-source software maintainers with power grids, hospitals, and other critical operators to find and patch security flaws faster, with AI doing much of the sorting work.

When 80,000 fans log on at once: the cybersecurity headache facing 2026 World Cup stadiums
Tens of thousands of personal phones on one network, payment terminals, body cameras on referees, and sensors inside match balls. Stadium IT teams face a security puzzle that has no clean solution.

Hijacked AsyncAPI npm Packages Slipped a Botnet Loader Into Developer Machines
Four packages under the popular @asyncapi namespace were tampered with to deliver a multi-stage malware loader, in the latest reminder that the open-source supply chain is a soft target.

CISA sounds alarm on SharePoint Server flaws being used to break in right now
The US cyber agency says attackers are chaining three unpatched holes in self-hosted SharePoint to bypass logins, run code and stay hidden. Nearly 10,000 servers sit exposed online.

Siemens, Schneider Electric, and Rockwell Fix Dozens of Flaws in Factory Control Systems
Three of the world's biggest industrial equipment makers patched a wave of security flaws in the software that runs power plants, factories, and water systems. Here is what that means in plain English.

Cybersecurity Spends Billions Spotting Attacks. It Should Be Stopping Them.
Detection tools now dominate the security market, but faster alerts have not cut breach rates. A growing chorus of security professionals says the industry has the balance badly wrong.

Microsoft Halts Windows 11 Update for Dell PCs After Shutdowns and Overheating
A clash between a new Windows USB-C component and an Intel power-management driver is bricking performance on some Dell laptops.

Nigeria's Fraud Losses Keep Climbing Even as Reported Incidents Fall
Fewer fraud cases are being recorded in Nigeria, but each one costs more. A new cybersecurity framework is coming, the question is whether enforcement will follow.

US charges three Russians behind 'bulletproof' hosting service used by LockBit and Play ransomware
Federal prosecutors say Media Land and ML.Cloud rented servers to ransomware crews that caused more than $62 million in damage across 21 US states.