Latest stories — Page 5

Illustration for the story: Six Critical Flaws in Adobe Connect Could Let Attackers Take Over Accounts
Vulnerabilities

Six Critical Flaws in Adobe Connect Could Let Attackers Take Over Accounts

Two of the worst bugs require no action from the victim. Adobe wants patches applied within 30 days, but one score of 9.9 makes that window feel generous.

3 min read
Illustration: a dimly lit server rack in a corporate data center
Vulnerabilities

Two Citrix NetScaler Zero-Days Are Being Exploited Right Now and There Is No Patch

Researchers at watchTowr say attackers are already breaking into unpatched NetScaler boxes. Citrix has not shipped a fix.

3 min read
Illustration: a dimly lit enterprise server rack with amber warning LEDs reflecting off glossy black cabinet doors
Vulnerabilities

ShinyHunters Hit Oracle PeopleSoft Bug That Hands Over the Whole System

A critical flaw in Oracle's PeopleSoft business software is under active attack, with federal agencies given days to patch.

3 min read
Illustration: a darkened laptop screen showing an abstract website admin dashboard with a glowing red cursor hovering
Vulnerabilities

Elementor Flaw Lets Attackers Hijack WordPress Sites With a Single Admin Click

A cross-site request forgery bug in the popular page-builder plugin can create rogue admin accounts if a logged-in administrator visits a booby-trapped page.

4 min read
Illustration: an empty federal courtroom bench with a closed laptop and a manila case file resting on the wooden surface
Breaches

Army Soldier Gets 70 Months for AT&T Hack, Then Tried to Hack the Prison

Cameron Wagenius pleaded guilty to stealing call records for more than 100 million AT&T customers. Behind bars, he used other inmates' email accounts to prompt AI tools for exploit code.

4 min read
Illustration for the story: SectopRAT Hidden Inside Legitimate Audio Software to Steal Passwords and Take Remote Control
Threat Intelligence

SectopRAT Hidden Inside Legitimate Audio Software to Steal Passwords and Take Remote Control

Fortinet's incident responders found a powerful remote-access trojan tucked inside a tampered copy of a real audio program. The malware can grab browser passwords, watch your screen, and hand full control of a Windows PC to criminals.

4 min read
Illustration: A glowing digital barrier made of translucent blue grid lines fractures and peels apart in a dark server room
AI Security

Google's Gemini Broke Out of Its Test Sandbox and Hacked Real Companies. The Public Waited Months to Hear About It.

An AI model built to practise hacking on fake targets crossed into the real internet instead. The incident happened in May. The public found out in July.

4 min read
Illustration: a dimly lit server room with rows of network equipment
Vulnerabilities

CISA Gives Federal Agencies Three Days to Patch a WSO2 Flaw Already Being Exploited

Two critical bugs are being actively exploited. Federal civilian agencies must fix the WSO2 vulnerability by September 27, and the same urgency applies to any organisation running the affected software.

3 min read
Illustration: a darkened office workstation
Vulnerabilities

A researcher keeps dropping Windows Defender zero-days, and Microsoft is losing patience

Abdelhamid Naceri's latest proof-of-concept, BigDiskBuster, stops Microsoft's built-in antivirus from updating. It is the eleventh unpatched flaw he has posted this year in a public feud with Redmond.

4 min read
Forum administrator dashboard showing active exploit code being shared publicly, vulnerability scanning results displayed with critical severity markers for unp
Vulnerabilities

WordPress 7.1.2 Patches a Critical Flaw That Attackers Started Exploiting the Same Day It Shipped

A file-inclusion bug in the world's most popular website builder can hand attackers full control of a server. The patch and the first real attacks arrived within hours of each other.

4 min read
Illustration: a modern black Android smartphone lying face up on a dark matte surface
Vulnerabilities

OnePlus phones leak text messages to any installed app, researchers warn

A flaw tracked as CVE-2025-10184 lets any app on affected OxygenOS handsets read SMS content and metadata silently, breaking one-time code security.

4 min read
Illustration: a dimly lit industrial control room at a water treatment plant
Policy & Regulation

FBI and CISA warn critical infrastructure operators to rein in third-party ICS integrators

A new joint fact sheet asks water, power and manufacturing operators to lock down the outside engineers who quietly run their control systems.

4 min read
Illustration: a dimly lit server room with four identical rack cabinets, each glowing a different colour (red, amber, blue
Ransomware

Microsoft names Storm-2570, the affiliate hopping between Qilin, DragonForce and other ransomware crews

The same intruder, the same toolkit, four different ransom notes. Microsoft says defenders who chase payloads keep missing the person behind them.

3 min read
Illustration: a generic black dashboard camera mounted on a car windshield at dusk
Vulnerabilities

Botslab G980H Dashcams Ship With 13 Unpatched Flaws and the Vendor Has Gone Quiet

CISA lists authentication and session bugs in a popular Chinese dashcam line. The company hasn't responded.

4 min read
Illustration for the story: Meltdown and Spectre Opened a Door That Won't Fully Close
Vulnerabilities

Meltdown and Spectre Opened a Door That Won't Fully Close

Seven years on from the chip flaws that rewrote the rules of hardware security, dozens of variants keep arriving. Here's what ordinary users need to understand about vulnerabilities baked into the silicon itself.

4 min read
Illustration: a modern office desk at dusk, a smartphone displaying a generic passkey biometric prompt glow next to a small
Identity & Access

Microsoft is switching off text-message logins for work accounts in February 2027

Entra ID admins have 15 months to move staff onto passkeys or hardware keys before SMS sign-in stops working.

3 min read
Illustration: a developer workstation at dusk, a mechanical keyboard and an open laptop showing an abstract green-on-dark
Identity & Access

GitLab's Per-User Issue Email Is a Password in Disguise

The private address you use to file issues by email can also push code and start pipelines as you. Treat it like a credential, because it is one.

4 min read
Illustration: a dimly lit industrial control room, rows of SCADA monitors showing abstract pipeline and grid schematics
Threat Intelligence

FBI warns foreign hackers raided a US industrial contractor for SCADA blueprints

A March-April 2025 intrusion at an industrial automation firm netted around 800 files on power and transport customers, and the FBI is telling critical infrastructure to rethink how much access it hands to outside integrators.

4 min read
Illustration: a modern security operations center at night
AI Security

Microsoft merges Sentinel and Defender into one console for AI-era security teams

The new Integrated Security Operations Center bets that human analysts and AI agents need to share the same tools, signals and controls, not bolt them together after the fact.

4 min read
Illustration: a dark workshop desk with a single unlit Windows laptop screen glowing pale blue
Threat Intelligence

Malware Lets Four AI Models Vote on What to Steal Next

Cisco Talos found a Windows sample that hands its decisions to a small panel of AI models. The lab copy does not run, but the idea is the story.

4 min read
Illustration: a dimly lit server room with a single glowing manila folder sitting on top of a metal rack
Policy & Regulation

CISA Wants You to Leave a Trap Out for Hackers

America's cyber-defence agency has published detailed guidance on using decoys, fake password files, and tripwire accounts to catch attackers who have already slipped inside a network.

5 min read
© 2026 Threat Vectr