Latest stories — Page 56

Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

U.S. Government Gives Agencies Two Weeks to Patch Four Actively Exploited Flaws

Critical security holes in Adobe ColdFusion, Langflow, and Joomla extensions are already being used by attackers. Federal agencies have until July 10 to fix them.

3 min read
Photoreal news-editorial 16:9 image
AI Security

Researchers Show How a Fake GitHub Comment Can Trick AI Tools Into Leaking Secret Code

A crafted public comment on GitHub can manipulate AI-powered automation into handing over data from private repositories, no password required.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a darkened server rack in a data centre, blue and amber status lights glowing, one drawer pulled sligh
Vulnerabilities

US cyber agency gives federal staff four days to patch Langflow AI tool being actively hacked

CISA added an authorisation bypass in the popular AI-agent builder Langflow to its must-patch list after Sysdig spotted attackers stealing cloud keys and hijacking servers.

4 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Policy & Regulation

Estonia Plans to Give AI Assistants Their Own Government ID Numbers

The Baltic nation wants AI agents to act inside government systems as semi-independent registered entities. Security experts say a registration number alone will not make that safe.

3 min read
A close-up, sharply lit photograph of two printed pages lying side by side on a dark desk, one page covered in dense text and tables with several entries circle
Threat Intelligence

Your Threat Feed Said One Thing. The Malware Said Another.

A former incident responder spent two years learning that intelligence reports, federal advisories, and foreign government bulletins all share the same quiet flaw: the copy most people read is rarely the full story.

4 min read
A wide 16:9 editorial photograph of a neat wooden desk under warm office lighting, with an open study notebook filled with handwritten notes, a laptop displayin
Policy & Regulation

The 13 security certifications paying the biggest salary premiums right now

New data from Foote Partners ranks the credentials that translate most directly into a bigger pay cheque, from a $165 Microsoft exam to a portfolio qualification that can cost tens of thousands of dollars.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit server room with rows of dark rack-mounted servers, blue and amber status LEDs reflecting
Vulnerabilities

CISA Flags Four Live-Exploited Bugs in Adobe, Joomla and Langflow

The US cyber agency gave federal agencies until early December to patch a critical Adobe ColdFusion flaw and three others already being abused in the wild.

3 min read
Full-frame close-up of a dark server room aisle, rows of black rack-mounted machines with faint green and amber status LEDs, one open server tray showing a bare
Vulnerabilities

GhostLock: A 15-Year-Old Linux Bug Hands Any User Root Access

Researchers say CVE-2026-43499 has sat in the Linux kernel since 2011 and needs nothing more than a normal login to seize full control.

3 min read
A polished oak courtroom interior shot from a low angle looking toward an empty defendant's table, morning light cutting through tall windows and casting long s
Identity & Access

Former College Basketball Player Charged With $2.2 Million Fraud Scheme Involving Fake Identities

Kerr Kriisa, who played at Arizona, West Virginia, Kentucky, and Cincinnati, faces five counts of wire fraud after allegedly posing as his own mother and a made-up person to extract money from two victims over four years.

3 min read
A smartphone resting on a car dashboard at night, its screen glowing with an incoming call notification, rain-blurred streetlights visible through the windscree
Threat Intelligence

Fake DoorDash Calls Are Draining Delivery Drivers' Wallets

Criminals are posing as DoorDash support staff, tricking gig workers into handing over account details, then quietly emptying their earnings. One driver lost $21,000.

3 min read
Photoreal news-editorial 16:9 image of a modern smartphone lying flat on a wooden desk, its screen glowing with a generic notification message, surrounded by so
Policy & Regulation

The Qantas Settlement Text That Looks Like a Scam But Isn't

More than one million Qantas customers are receiving texts and emails about a $105 million class-action settlement over COVID-19 flight credits. The messages are real, and ignoring them could mean missing a payment.

3 min read
Photoreal editorial shot of a modern glass office tower at dusk with cold blue interior lighting on empty open-plan floors, a faint reflection of code-like patt
Breaches

Accenture confirms break-in as hacker offers 35GB of stolen code for sale

The consulting giant says the incident is contained, but a forum seller known as 888 claims to be holding source code, Azure access keys and SSH keys taken in July 2026.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a stack of small office routers with blinking status lights on a dark server-room shelf, faint blue an
Threat Intelligence

Chinese hackers hijack unpatched routers to build a stealth relay network

A group Cisco Talos calls UAT-7810 is breaking into Ruckus and ASUS routers to hide the tracks of other China-linked spying crews.

3 min read
Full-frame overhead photograph of an unbranded Android-style smartphone lying on a dark desk, screen glowing red with abstract geometric login form shapes, fain
Threat Intelligence

RedWing: The Rent-a-Fraud Kit Turning Android Phones Into Bank Robberies

A new Android malware sold on Telegram lets almost anyone hijack a victim's phone, steal banking logins and grab the codes meant to keep accounts safe.

3 min read
Photoreal editorial image, 16:9, full frame edge to edge
Cloud Security

Google Chatbot Flaw Let Attackers Hijack Other Bots and Read User Chats

A bug in Google Dialogflow CX, patched after a Varonis report, could have let one rogue chatbot spy on and puppet others sharing the same cloud project.

3 min read
Full-frame photoreal editorial shot of an open industrial control cabinet inside a substation, showing a ruggedised ethernet switch with blue and green status L
Vulnerabilities

Siemens tells industrial customers to patch RUGGEDCOM switches now, cites dozens of flaws in SINEC OS

The German engineering giant has shipped version 4.0 of its ruggedised network operating system to close a long list of bugs, including one rated 9.8 out of 10.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
AI Security

A Hidden Command in a GitHub Issue Can Silently Steal a Company's Private Code

Researchers found a flaw in GitHub's AI automation tool that lets an outsider read an organisation's private repositories by hiding plain-English instructions inside a public bug report.

3 min read
Full frame, photoreal news-editorial image of a laptop screen showing a generic corporate sign-in code entry page in a dimly lit office, with a smartphone besid
Identity & Access

Fake Teams Invites Are Tricking Microsoft 365 Users Into Handing Over Their Accounts

A phishing crew is skipping the fake login page and walking victims straight through Microsoft's own device sign-in flow.

4 min read
Photoreal news-editorial image, 16:9, full frame edge to edge
Threat Intelligence

Spanish police arrest suspected helper of pro-Russian hacking crews

The man in Palencia allegedly helped a Ukrainian hacker flee toward Russia and supported groups linked to attacks on U.S. water and energy sites.

3 min read
Full-frame edge-to-edge photoreal editorial shot of a modern glass office corridor at dusk, with two adjacent identical meeting rooms separated by a cracked gla
AI Security

Writer AI Patches Critical Cross-Tenant Flaw That Exposed Customer Sessions

A one-click bug dubbed WriteOut let outsiders hop between customer accounts on the enterprise AI platform before it was quietly fixed.

3 min read
Full-frame edge-to-edge photoreal editorial image of a darkened luxury jewelry display case at night, glass reflecting faint blue digital patterns suggesting ne
Threat Intelligence

A Windows Device ID Helped Trace an Alleged Scattered Spider Hacker to a Jewelry Heist

Federal prosecutors say a single hardware identifier tied a May 2025 intrusion at a luxury retailer to the online accounts of a 19-year-old.

4 min read
© 2026 Threat Vectr