Latest stories — Page 59

Fake Tax Emails Are Planting Two Separate Spying Tools on Indian Taxpayers' Computers
A campaign timed to India's tax filing season tricks people into downloading what looks like an official government utility. Inside: two hidden programs that give criminals full remote control of the victim's machine.

U.S. Government Gives Agencies Two Weeks to Patch Four Actively Exploited Flaws
Critical security holes in Adobe ColdFusion, Langflow, and Joomla extensions are already being used by attackers. Federal agencies have until July 10 to fix them.

Researchers Show How a Fake GitHub Comment Can Trick AI Tools Into Leaking Secret Code
A crafted public comment on GitHub can manipulate AI-powered automation into handing over data from private repositories, no password required.

US cyber agency gives federal staff four days to patch Langflow AI tool being actively hacked
CISA added an authorisation bypass in the popular AI-agent builder Langflow to its must-patch list after Sysdig spotted attackers stealing cloud keys and hijacking servers.

Estonia Plans to Give AI Assistants Their Own Government ID Numbers
The Baltic nation wants AI agents to act inside government systems as semi-independent registered entities. Security experts say a registration number alone will not make that safe.

Your Threat Feed Said One Thing. The Malware Said Another.
A former incident responder spent two years learning that intelligence reports, federal advisories, and foreign government bulletins all share the same quiet flaw: the copy most people read is rarely the full story.

The 13 security certifications paying the biggest salary premiums right now
New data from Foote Partners ranks the credentials that translate most directly into a bigger pay cheque, from a $165 Microsoft exam to a portfolio qualification that can cost tens of thousands of dollars.

CISA Flags Four Live-Exploited Bugs in Adobe, Joomla and Langflow
The US cyber agency gave federal agencies until early December to patch a critical Adobe ColdFusion flaw and three others already being abused in the wild.

GhostLock: A 15-Year-Old Linux Bug Hands Any User Root Access
Researchers say CVE-2026-43499 has sat in the Linux kernel since 2011 and needs nothing more than a normal login to seize full control.

Former College Basketball Player Charged With $2.2 Million Fraud Scheme Involving Fake Identities
Kerr Kriisa, who played at Arizona, West Virginia, Kentucky, and Cincinnati, faces five counts of wire fraud after allegedly posing as his own mother and a made-up person to extract money from two victims over four years.

Fake DoorDash Calls Are Draining Delivery Drivers' Wallets
Criminals are posing as DoorDash support staff, tricking gig workers into handing over account details, then quietly emptying their earnings. One driver lost $21,000.

The Qantas Settlement Text That Looks Like a Scam But Isn't
More than one million Qantas customers are receiving texts and emails about a $105 million class-action settlement over COVID-19 flight credits. The messages are real, and ignoring them could mean missing a payment.

Accenture confirms break-in as hacker offers 35GB of stolen code for sale
The consulting giant says the incident is contained, but a forum seller known as 888 claims to be holding source code, Azure access keys and SSH keys taken in July 2026.

Chinese hackers hijack unpatched routers to build a stealth relay network
A group Cisco Talos calls UAT-7810 is breaking into Ruckus and ASUS routers to hide the tracks of other China-linked spying crews.

RedWing: The Rent-a-Fraud Kit Turning Android Phones Into Bank Robberies
A new Android malware sold on Telegram lets almost anyone hijack a victim's phone, steal banking logins and grab the codes meant to keep accounts safe.

Google Chatbot Flaw Let Attackers Hijack Other Bots and Read User Chats
A bug in Google Dialogflow CX, patched after a Varonis report, could have let one rogue chatbot spy on and puppet others sharing the same cloud project.

Siemens tells industrial customers to patch RUGGEDCOM switches now, cites dozens of flaws in SINEC OS
The German engineering giant has shipped version 4.0 of its ruggedised network operating system to close a long list of bugs, including one rated 9.8 out of 10.

A Hidden Command in a GitHub Issue Can Silently Steal a Company's Private Code
Researchers found a flaw in GitHub's AI automation tool that lets an outsider read an organisation's private repositories by hiding plain-English instructions inside a public bug report.

Fake Teams Invites Are Tricking Microsoft 365 Users Into Handing Over Their Accounts
A phishing crew is skipping the fake login page and walking victims straight through Microsoft's own device sign-in flow.

Spanish police arrest suspected helper of pro-Russian hacking crews
The man in Palencia allegedly helped a Ukrainian hacker flee toward Russia and supported groups linked to attacks on U.S. water and energy sites.

Writer AI Patches Critical Cross-Tenant Flaw That Exposed Customer Sessions
A one-click bug dubbed WriteOut let outsiders hop between customer accounts on the enterprise AI platform before it was quietly fixed.