Latest stories — Page 57

Keyfactor Raises Over $1 Billion to Tackle AI and Post-Quantum Security
The investment backs technology that manages digital certificates and cryptographic keys, as companies race to prepare for a generation of threats that today's encryption may not survive.

The Gentlemen Ransomware Gang Turns Your Own IT Tools Against You
A fast-spreading criminal group is using the software your IT team trusts every day to take over company networks. The real test is not whether they got in. It is what happens next.

Suspected Chinese Hackers Target University Webmail in Credential-Stealing Campaign
A hacking group tied to China is breaking into Roundcube webmail systems at physics and engineering faculties across US and Canadian universities to steal login details.

Windows will start backing up work laptops by default in 2026
Microsoft is flipping its enterprise settings backup tool from opt-in to opt-out for Windows 11 26H2, and IT teams have until later this year to decide if they want it on.

BeyondTrust patches two critical bugs that let attackers walk past the login screen
The remote-access vendor rushed out fixes for four flaws in its Remote Support and Privileged Remote Access products, two of which allow unauthenticated attackers to reach powerful admin accounts under certain configurations.

Hidden Admin Backdoor Found in Tenda Router Firmware, CERT/CC Warns
A flaw tracked as CVE-2026-11405 lets anyone skip the password check and take over affected Tenda routers through the web interface.

Microsoft Begins Testing Cloud Rebuild, a Remote Reinstall Tool for Broken Windows 11 PCs
The feature, part of Microsoft's Windows Resiliency Initiative, downloads a fresh copy of Windows and drivers from the cloud even when the machine won't boot. It is available now to Insiders on the Experimental channel.

BeyondTrust Rushes Fixes for Two Critical Flaws That Let Attackers Walk Into Remote Support Tools
The company's Remote Support and Privileged Remote Access products carry pre-authentication bugs rated 9.2 on the severity scale, meaning attackers need no password to break in.

The Software Safety Label Problem: Why What Companies Ship Often Doesn't Match What They Report
A growing body of regulation now requires software makers to list every component inside their products. A Toronto-based firm says most of those lists are wrong before the ink dries, and regulators are starting to agree.

AI Agents Can Be Tricked Into Sending Money. Zscaler Has the Data.
A new study shows that some expensive, enterprise-grade AI assistants fall for hidden instructions that most humans would ignore, and experts warn the real danger is far bigger than a fake three-dollar fee.

UK Watchdog Warns AI Is Outpacing the Rules Meant to Protect Your Money
A government-ordered review says Britain's financial regulator needs stronger powers before AI reshapes banking, insurance, and lending for millions of ordinary people.

The FTC Is Warning About Fake Party Invitation Scams Arriving by Email and Text
Criminals are sending convincing fake event invitations to steal personal information. Here is what the scam looks like and how to avoid it.

German Court Case Exposes Telegram Network That Drugged and Filmed Women in Secret
A phone call from police told a Chinese student in Germany that her ex-boyfriend had taken nude photos of her while she slept. She was one of many victims of an organised online group.

Meet BusySnake: The Stealthy Malware Quietly Raiding Government Networks
A newly discovered hacking group is hitting government offices and critical services in three countries with a cunning piece of spy software. Here is what it does and who is at risk.

A New Citrix NetScaler Flaw Is Already Being Exploited, And It Looks Familiar
A security hole in widely used Citrix network equipment is leaking corporate secrets from memory. Attackers moved within 24 hours of the patch dropping.

Fake IT Helpdesk Calls on Microsoft Teams Are Planting EtherRAT on Company PCs
Attackers pose as internal support staff over Teams voice calls, then walk employees through installing remote-access tools that drop a Node.js trojan.

Fake job interviews from 'Adidas', 'Netflix' and 'OpenAI' recruiters are stealing Google logins
A phishing crew is impersonating more than 30 major brands, hiding behind real business software from PeopleForce and Salesforce to trick marketing staff into handing over their Gmail passwords.

Iranian Spies Target Israeli IT Firms With a New Custom Toolkit Called Cavern
A hacking crew tied to Iran's intelligence ministry is running a previously unseen command-and-control framework against Israeli government bodies and their IT suppliers.

A 16-Year-Old Flaw in Linux's Virtual Machine Engine Lets Guests Break Into Their Host
Januscape (CVE-2026-53359) sits in shared code used on both Intel and AMD servers, and a public demo already crashes the host machine.

Vietnam charges seven over HiAnime, the piracy site that briefly out-streamed Disney+
Police say the operators earned nearly $13 million from ads across 100+ sites hosting 26,000 pirated anime titles.

Hackers Race to Exploit Gitea Flaw That Lets Anyone Log In as Admin
A missing check in Gitea's Docker images let attackers claim any username by adding a single header. Sysdig says probing began within days of the patch.