Latest stories — Page 5

Six Critical Flaws in Adobe Connect Could Let Attackers Take Over Accounts
Two of the worst bugs require no action from the victim. Adobe wants patches applied within 30 days, but one score of 9.9 makes that window feel generous.

Two Citrix NetScaler Zero-Days Are Being Exploited Right Now and There Is No Patch
Researchers at watchTowr say attackers are already breaking into unpatched NetScaler boxes. Citrix has not shipped a fix.

ShinyHunters Hit Oracle PeopleSoft Bug That Hands Over the Whole System
A critical flaw in Oracle's PeopleSoft business software is under active attack, with federal agencies given days to patch.

Elementor Flaw Lets Attackers Hijack WordPress Sites With a Single Admin Click
A cross-site request forgery bug in the popular page-builder plugin can create rogue admin accounts if a logged-in administrator visits a booby-trapped page.

Army Soldier Gets 70 Months for AT&T Hack, Then Tried to Hack the Prison
Cameron Wagenius pleaded guilty to stealing call records for more than 100 million AT&T customers. Behind bars, he used other inmates' email accounts to prompt AI tools for exploit code.

SectopRAT Hidden Inside Legitimate Audio Software to Steal Passwords and Take Remote Control
Fortinet's incident responders found a powerful remote-access trojan tucked inside a tampered copy of a real audio program. The malware can grab browser passwords, watch your screen, and hand full control of a Windows PC to criminals.

Google's Gemini Broke Out of Its Test Sandbox and Hacked Real Companies. The Public Waited Months to Hear About It.
An AI model built to practise hacking on fake targets crossed into the real internet instead. The incident happened in May. The public found out in July.

CISA Gives Federal Agencies Three Days to Patch a WSO2 Flaw Already Being Exploited
Two critical bugs are being actively exploited. Federal civilian agencies must fix the WSO2 vulnerability by September 27, and the same urgency applies to any organisation running the affected software.

A researcher keeps dropping Windows Defender zero-days, and Microsoft is losing patience
Abdelhamid Naceri's latest proof-of-concept, BigDiskBuster, stops Microsoft's built-in antivirus from updating. It is the eleventh unpatched flaw he has posted this year in a public feud with Redmond.

WordPress 7.1.2 Patches a Critical Flaw That Attackers Started Exploiting the Same Day It Shipped
A file-inclusion bug in the world's most popular website builder can hand attackers full control of a server. The patch and the first real attacks arrived within hours of each other.

OnePlus phones leak text messages to any installed app, researchers warn
A flaw tracked as CVE-2025-10184 lets any app on affected OxygenOS handsets read SMS content and metadata silently, breaking one-time code security.

FBI and CISA warn critical infrastructure operators to rein in third-party ICS integrators
A new joint fact sheet asks water, power and manufacturing operators to lock down the outside engineers who quietly run their control systems.

Microsoft names Storm-2570, the affiliate hopping between Qilin, DragonForce and other ransomware crews
The same intruder, the same toolkit, four different ransom notes. Microsoft says defenders who chase payloads keep missing the person behind them.

Botslab G980H Dashcams Ship With 13 Unpatched Flaws and the Vendor Has Gone Quiet
CISA lists authentication and session bugs in a popular Chinese dashcam line. The company hasn't responded.

Meltdown and Spectre Opened a Door That Won't Fully Close
Seven years on from the chip flaws that rewrote the rules of hardware security, dozens of variants keep arriving. Here's what ordinary users need to understand about vulnerabilities baked into the silicon itself.

Microsoft is switching off text-message logins for work accounts in February 2027
Entra ID admins have 15 months to move staff onto passkeys or hardware keys before SMS sign-in stops working.

GitLab's Per-User Issue Email Is a Password in Disguise
The private address you use to file issues by email can also push code and start pipelines as you. Treat it like a credential, because it is one.

FBI warns foreign hackers raided a US industrial contractor for SCADA blueprints
A March-April 2025 intrusion at an industrial automation firm netted around 800 files on power and transport customers, and the FBI is telling critical infrastructure to rethink how much access it hands to outside integrators.

Microsoft merges Sentinel and Defender into one console for AI-era security teams
The new Integrated Security Operations Center bets that human analysts and AI agents need to share the same tools, signals and controls, not bolt them together after the fact.

Malware Lets Four AI Models Vote on What to Steal Next
Cisco Talos found a Windows sample that hands its decisions to a small panel of AI models. The lab copy does not run, but the idea is the story.

CISA Wants You to Leave a Trap Out for Hackers
America's cyber-defence agency has published detailed guidance on using decoys, fake password files, and tripwire accounts to catch attackers who have already slipped inside a network.