Latest stories — Page 54

US Cyber Agency Flags Two Joomla Add-On Flaws Already Being Exploited
CISA says attackers are actively abusing critical bugs in the iCagenda and Balbooa extensions, both scored a perfect 10 on the severity scale.

OpenAI Lifts the Five-Hour Cap on ChatGPT and Codex After a Weekend of Overloaded Demand
Plus, Pro and Business subscribers get a usage reset and a temporary reprieve from the rolling limit, as OpenAI tunes GPT-5.6 Sol to burn through allowances more slowly.

Nine in Ten Top Adult Sites Now Check Ages in Australia, But VPN Workarounds Are Next on the Regulator's List
Australia's online safety watchdog says most major adult platforms have put age gates in place since March. Now it wants to know whether a simple privacy tool is letting users walk straight around them.

Meta Kills AI Image Tool Days After Launch Over Privacy Backlash
A new feature that let users generate pictures by pulling content from public Instagram accounts lasted less than a week before Meta pulled it following an outcry from users and a Hollywood union.

You Probably Can't Spot an AI Fake Face. Researchers Think They Can Teach You
A team of scientists from Australia, Canada and the UK are testing whether ordinary people can be trained to tell real human faces from AI-generated impostors. The early results are cautiously encouraging.

Anthropic gives paying Claude users another week of Fable 5 access
The company pushed the deadline from July 12 to July 19, blaming compute constraints for the on-again, off-again availability of its top model.

RedHook Android Malware Turns Phones Into Their Own Debugging Tool
A new build of the RedHook trojan tricks Android users into switching on Wireless Debugging, then quietly promotes itself to a privilege level normal apps can never reach.

Argentina's Football Association Says Its Email Account May Have Been Hacked After World Cup Win
Someone sent journalists messages from the AFA's official inbox claiming Argentina's victory over Egypt was fixed. The association says it didn't send them.

Ofcom Wants Big Tech to Stop Scam Ads. Here's What That Means for You.
The UK's communications regulator has told the country's largest social platforms to clean up fraudulent advertising or face fines of up to 10% of their global revenue.

MSG's Secret Celebrity Database Tagged Nearly 40,000 People by Sexuality, Race, and 'Risk' Level
A data breach at Madison Square Garden exposed an internal tracking list that sorted celebrities, public figures, and ordinary visitors using labels including 'LGBTQIA,' 'DO NOT HOST,' and a personal 'risk' score.

Bank of England Gets Power to Regulate Amazon, Google and Other Cloud Giants Serving UK Banks
New rules taking effect this week mean two regulators can now inspect and direct the tech companies that keep Britain's financial system running, a first for the UK.

Suspected Chinese and Indian Spies Both Targeted Pakistani Police, Researchers Say
A two-year campaign hit Balochistan Police and other law enforcement bodies, with servers holding criminal records among the compromised assets.

Booby-trapped jscrambler npm release runs infostealer the moment you install it
Version 8.14.0 of a popular JavaScript protection package shipped with a hidden payload that fires during install, no code changes required from the developer.

Dormant GitHub Accounts Quietly Mapped Thousands of Organisations for Months
Criminals used more than 50 sleeping accounts to probe GitHub's public data systems in what security researchers call a sustained reconnaissance campaign.

Australia sounds the alarm: hackers are hijacking small business websites at scale
The Australian Cyber Security Centre says a worldwide campaign is planting hidden backdoors on sites running WordPress, Joomla, Craft CMS and more, with small businesses bearing the brunt.

'Ghostcommit' smuggles hacker instructions inside images to trick AI coding assistants
Researchers hid secret commands in an ordinary PNG file, walked past two popular AI code reviewers, and got a coding assistant to leak a project's passwords.

Zimbra Patches Critical Webmail Flaw That Lets Booby-Trapped Emails Run Code
A stored cross-site scripting bug in Zimbra's Classic Web Client can hijack a user's session the moment a rigged email is opened.

Meta's New AI Tool Can Generate Photos of Instagram Users Without Telling Them
Meta Muse Image AI lets anyone tag a public Instagram account and produce AI-generated images using that person's face. Affected users get no notification at all.

A US Senator Wants Laws to Rein In AI Before the Damage Gets Worse
Senator Ed Markey has introduced a package of bills targeting AI's biggest real-world harms: water-hungry data centres, biased hiring algorithms, and workers being overruled by software they never saw.

Meta's New AI Tool Lets Anyone Remix Your Instagram Photos Without Asking
Muse can turn public profile pictures into AI-generated images. Experts warn ordinary users may not realise they have already opted in.

Six bugs in U-Boot bootloader open the door to hidden firmware attacks
Researchers found flaws in the open-source code that starts up millions of embedded devices, from routers to industrial kit. Fixes are out.