Latest stories — Page 51

Progress ShareFile zero-day forced emergency server shutdowns; patch is out
A path traversal flaw in Storage Zone Controllers let admin users read and write files they shouldn't. Progress says no customer breach has been found.

ClickFix: The Fake Error Pop-Up That Tricks You Into Hacking Yourself
A scam that launched in 2024 has grown into a thriving criminal marketplace. Researchers say standard antivirus tools are missing it almost entirely, and they have built a new detection method to fill the gap.

Three States Write the Rules on Powerful AI Before Washington Does
Illinois, New York, and California have passed disclosure laws covering the most advanced AI systems. The patchwork that results will cost companies money and leave ordinary users with unanswered questions.

Fake LastPass and Bitwarden emails send users to bogus DocuSign pages
Criminals are impersonating two of the biggest password managers with polished 'policy update' emails that push a malicious file download.

RabbitMQ Bugs Could Have Handed Attackers the Keys to Corporate Messaging
Two access control flaws in the widely used RabbitMQ broker exposed OAuth secrets and let one tenant peek at another's data.

You Don't Need to Fire the Exploit to Know You're Exposed
A quieter way to test whether a vulnerability actually threatens your network: check the steps an attacker would need, not the payload itself.

Seven Security Flaws Fixed in VMware Avi Load Balancer, One Rated Critical
Broadcom has patched a critical flaw that lets attackers break into a core networking component without a password, plus six more serious bugs found by two outside researchers.

Popular AI Coding Tool Cursor Runs Malicious Files Automatically, Researcher Warns
A security firm reported the flaw seven months ago. Cursor has yet to patch it.

Pentera Pitches Validation as the Missing Layer in AI Security Workflows
The vendor argues AI security agents making real decisions need proof, not just risk scores, before they act.

Hackers Are Faking OAuth App IDs to Quietly Test Stolen Microsoft Logins
A new trick lets attackers check stolen Microsoft Entra ID passwords without triggering a single sign-in alert.

Eleven Old Microsoft-Signed Boot Files Could Let Hackers Slip Past Secure Boot
Researchers say the signed UEFI applications, still trusted by most PCs, can be used to load malicious code before Windows even starts.

KU Leuven Researchers Find 85 Browser Crypto Wallets Leak User Data
Academic study says the way popular wallet extensions talk to websites lets outsiders link separate crypto addresses to the same person.

A Bug in the Claude for Chrome Extension Has Survived Eight Fixes and Still Leaks Your Gmail
A flaw nicknamed 'ClaudeBleed' lets other browser extensions quietly read your email and calendar. After eight attempted patches, it apparently still works.

Microsoft is killing SMS logins for business accounts. Passkeys take over in September 2026.
Entra ID, the sign-in system used by millions of companies, will switch to passkeys by default. Text-message codes get shut off in February 2027.

SAP Patches Critical Flaws in NetWeaver, Approuter, and Commerce Cloud
Three SAP products used by thousands of businesses worldwide carried serious security holes. Patches are now available, and anyone running the affected software should move fast.

Microsoft trials an ad-free Windows Search for Insiders
The refreshed search bar prioritises your files and apps over Store promos and web suggestions, and adds a toggle to switch them off entirely.

Forg365 Sells Ready-Made Microsoft 365 Hijacking Kits on Telegram for $400 a Month
A new phishing service hands criminals automated tools to break into Microsoft 365 accounts and stay there, even after a victim changes their password.

Valarian Raises $50 Million to Lock Down AI Workloads in Sensitive Organisations
The UK startup wants to give governments and regulated industries a way to run AI systems they actually control, not one rented from a cloud provider.

US sanctions a VPN, a malware disguiser, and the people behind them for helping ransomware gangs
Treasury targets 1VPNS and a Belarusian 'crypter' seller who together helped ransomware crews hit hospitals, banks and local governments.

Your Incident Response Playbook Almost Certainly Does Not Cover AI Failures. That Is a Problem.
Seven in ten organisations have AI plugged into their core systems, yet most security teams are trying to handle AI breakdowns with tools built for a completely different kind of threat.

Grok's Coding Assistant Was Quietly Shipping Whole Git Repos to xAI
A researcher caught version 0.2.93 of Grok Build uploading entire repositories, private history included, to a Google Cloud bucket run by xAI.