Latest stories — Page 52

Russia's FSB Is Quietly Hijacking Old Routers Across Critical Infrastructure, Allies Warn
A rare joint advisory from thirteen agencies details how FSB Center 16 hackers, tracked as Berserk Bear and Static Tundra, have spent over a decade pulling configs from misconfigured network gear.

GigaWiper: The Malware That Destroys on Demand
A newly uncovered piece of malicious software lets criminals break into a system, wait quietly, then choose exactly how they want to erase everything. Microsoft researchers say it is unlike anything they have tracked before.

Your AI risk register is a list, not a plan. Here is what organisations are missing.
Documenting AI risks is the easy part. Knowing who can actually shut the system down when something goes wrong is where most programmes fall apart.

CISA flags active attacks on two Joomla add-ons that let hackers take over websites
Old flaws in the iCagenda and Balbooa Forms extensions are being used to plant malicious files on Joomla sites, and the U.S. cyber agency has given federal bodies three weeks to patch.

One Poisoned Email Can Rewrite What Your AI Assistant 'Remembers' About You
Researchers show how a single message can plant a false memory in an AI agent's long-term store, quietly steering its answers in every future chat.

The Week Trusted Software Turned Hostile: ShareFile, Citrix Bleed 2, and AI Coding Attacks
Automated bug-hunting is cutting both ways, and old flaws are still landing hits because patches sat in a queue.

CISA Left AWS GovCloud Keys on GitHub for Six Months, Ignored Nine Alerts
The US cyber agency's own postmortem admits it missed automated warnings, muddled its reporting channels, and took two days to rotate leaked admin credentials.

ScamBuster Turns Phishing Emails Into Intelligence by Pretending to Be the Victim
A French engineer built an AI system that replies to scam emails, plays along long enough to extract bank details and phone numbers, then hands the data to investigators.

From Prison to Cybersecurity Advocate: The Jesse McGraw Story
Once known online as GhostExodus, Jesse McGraw hacked hospital systems as a teenager, went to federal prison, and came out the other side trying to help defenders. His story is a rare look at what radicalises young hackers and what, sometimes, pulls them back.

Lidl Customers in Three Countries Warned After Supplier Breach Exposes Personal Data
The German discount chain says a file at an outside IT provider was raided, spilling names, phone numbers and dates of birth for online shoppers in Germany, Belgium and the Netherlands.

Varonis Launches Free Entra ID Training Game to Teach Cloud Identity Attacks
Breach at the Beach is a browser-based challenge that walks defenders through the kind of Microsoft Entra ID attacks Varonis researchers say they see in real customer environments.

Forg365: A $400-a-Month Kit That Hijacks Microsoft 365 Logins
A new subscription phishing service uses device codes, session theft and AI-written lures to break into corporate email accounts.

Five Londoners Charged Over Russian Coms, the Scam-Call Platform Behind 1.8 Million Fake Calls
The UK's National Crime Agency says the platform helped criminals impersonate banks and police, costing an estimated 170,000 victims tens of millions of pounds.

37 Cybersecurity Deals in One Month: What June 2026's M&A Surge Tells Us
From a $4 billion Accenture mega-deal to a $70 million automated-patching pickup, June was a busy month for security industry consolidation. Here is what moved and why it matters.

Attacker Uses AI-Written PowerShell Script to Map a Company's Network
Researchers say an unknown intruder ran a script that looks machine-generated to catalogue users, computers and domain controllers inside a Windows network.

The Two-Speed SOC: Why Autonomous AI and Analyst Copilots Need Different Guardrails
A design question inside a Fortune 50 security team points to a bigger governance gap for AI in the security operations centre.

Meta's Patent Bid: An AI That Listens All Day and Guesses Your Mood
A newly filed Meta patent describes software that would listen to a user's voice, infer their emotional state, and log it against time, location, and phone activity.

A Hidden Door in RabbitMQ Left Company Systems Wide Open for Two Years
A flaw in the popular messaging software handed anyone on the network a master key to company data. Patches are out. Use them now.

Two Security Flaws in RabbitMQ Could Let Attackers Steal Login Secrets and Take Over Corporate Messaging Systems
A widely used software tool that moves data between business applications has patched two vulnerabilities, one of which could hand criminals full control over the system without a password.

EU and UK Hit Russian Spy Hackers With Joint Sanctions
Brussels and London name GRU and FSB officers behind years of cyberattacks on European power grids, government networks and elections.

Ransomware group claims attack on Els for Autism Foundation
A criminal group called cmdorganization has listed the Florida-based autism charity on a dark-web extortion site. The foundation has not confirmed any incident, and the claim could not be independently verified.