Latest stories — Page 58

Meta's New AI Tool Can Put Real People Into Fake Photos Without Asking First
Meta's Muse Image feature lets anyone generate pictures using other people's public Instagram photos. Critics say the opt-out system puts the burden in the wrong place.

A City Council Candidate Made Fake CNN News Stories on His Phone. It Probably Won't Be the Last Time.
A New York race showed how easy it is to generate convincing fake political news with AI. Experts say the tools are only getting cheaper and faster.

Farage's £5m Crypto Gift Was Flagged to the UK's National Crime Agency Over Money-Laundering Fears
Bankers who processed the payment raised a formal suspicion report. Now the Reform UK leader faces scrutiny from two directions at once.

Seven Arrested Over Alleged Council Fraud in Shepparton as Police Probe Four-Year Scheme
Greater Shepparton City Council referred its own employees to police after internal checks flagged suspicious financial activity stretching back to 2022.

Criminals Are Using GitHub's Own Public Tools to Map Your Company Before They Strike
Researchers at Datadog tracked months of quiet, automated snooping across GitHub that blends perfectly into normal traffic, and most organisations never notice it happening.

Mexico's World Cup Moment: A New Cyber Plan Meets Its First Big Test
The FIFA World Cup 2026 is stress-testing Mexico's seven-month-old National Cybersecurity Plan before the country even has a proper cybersecurity law.

Calgary university loses student and staff files to hackers who wiped the originals
Mount Royal University says a June 17 break-in ended with stolen data on shared drives and a ransom demand of 30 bitcoin from a group calling itself CMD Organization.

One Person, 72 Hours, One Wrecked AWS Account: How AI Handed a Lone Criminal the Keys to a Global Enterprise
Security firm Sygnia says a single attacker used artificial intelligence to tear through a major cloud environment at a pace that would normally require a full criminal crew. The unnamed victim was extorted.

Fake Paysafe and Skrill SDKs on npm and PyPI Went After Developers' Secrets
A single attacker uploaded 17 lookalike payment packages that quietly stole API keys, cloud credentials and GitHub tokens from anyone who installed them.

China-linked hackers hit university email servers to spy on physics and defence researchers
A group tracked as UNK_MassTraction is exploiting two Roundcube flaws at U.S. and Canadian universities to steal logins and plant backdoors, Proofpoint says.

Fake Pirated Software Ads Are Draining Passwords and Hijacking Computers to Mine Crypto
A campaign uncovered by Palo Alto Networks researchers is tricking people into downloading malware disguised as cracked software, stealing saved passwords while quietly running up victims' electricity bills.

When your AI coder looks exactly like a hacker to the security software
Sophos found that popular AI coding assistants keep tripping the same alarms designed to spot break-ins, and the false alerts are piling up.

Fake 'security upgrade' phone calls trick Microsoft 365 users into handing over their accounts
A criminal crew called Pink is calling staff, walking them through a fake Microsoft passkey setup, and quietly registering a login key of its own.

HalluSquatting: When AI Coding Helpers Invent Fake Software, Criminals Register It First
Researchers show how attackers can predict the fake package names AI assistants make up, then publish real malware under those names, waiting for developers to install the trap.

Accenture Confirms Data Breach After Hacker Claims Source Code Was Stolen
The consulting giant says the incident is contained and caused no disruption, but a hacker has publicly claimed to have taken internal source code.

Chinese Hacking Group Adds Three New Backdoors to Its Router Attack Kit
The group behind a long-running campaign targeting small office routers has quietly expanded its toolbox, giving it more ways to hide inside a victim's network.

Ubiquiti Rushes Fixes for a 10-out-of-10 Flaw Across UniFi Gear
The networking vendor patched serious holes in UniFi Connect, Talk, Access, Protect and the underlying UniFi OS. One bug scores a perfect 10 on the severity scale.

When the Help Desk Becomes the Front Door: AI-Assisted Social Engineering Hits Onboarding
IBM says 16% of breaches in 2025 involved attackers using AI. A lot of those calls land at the service desk, and new-hire onboarding is the softest spot.

'Ghost Phishing' Campaign Slips Past Email Filters by Hiding Until It Reaches the Victim
The EvilTokens operation is hitting companies across the US and Europe with pages that stay encrypted in transit and only unlock inside the target's browser.

Fake CAPTCHA Pages Are Stealing From Mexican Bank Customers
Elastic Security Labs is tracking a fraud campaign, dubbed REF6045, that tricks people into pasting a malicious command from a bogus 'prove you're human' page.

Blocking Phishing Emails Is Not Enough. Here Is Why the Attack Carries On Anyway.
Filtering a malicious email out of your inbox stops one message, not the criminal behind it. A live webinar on 8 July 2026 sets out what disrupting a phishing campaign at its source actually requires.