Latest stories — Page 6

Phishing Has a New Problem: The Attacker Isn't Human Anymore
Email defences built for bad links and bad attachments are struggling as AI agents start writing, sending, and even reading the mail on both sides.

Researchers Say 14,500 Dahua Cameras Fell to a Six-Week Hijack Campaign
Hunt.io traced Operation CameraSwarm through an exposed 407 MB working directory, revealing password guessing, two authentication-bypass flaws, and a peer-to-peer relay trick.

CodeSecCon Brings Developers and Security Teams Together to Fix a Growing Blind Spot
A virtual conference focused on building safer software is drawing both coders and cybersecurity professionals to the same table, a pairing that rarely happens and badly needs to.

SilkParasite: New Espionage Group Hits Central Asian Governments With Five Unseen Hacking Tools
Researchers have named a fresh spying operation running seven remote-access tools against government offices across the region, five of them never seen before.

Prevalent AI Banks $22 Million to Stitch Together Scattered Business Data
A London firm built by ex-GCHQ and Darktrace veterans just landed its first outside funding. Here is what it does and why the security world is watching.

US Charges 17 Iranians With Hacking Hundreds of Universities and Government Agencies
A federal indictment names 17 people linked to a Tehran company that stole more than 31 terabytes of academic research on behalf of Iran's Revolutionary Guard. Five defendants now carry $10 million bounties.

Four Critical Security Flaws Exploited in Apple, Microsoft, and VMware Products
CISA warns of active exploitation of severe vulnerabilities in popular software, affecting millions globally.

Windows Defender Crashed Mid-Scan After Buggy Update, Microsoft Ships Fix
A faulty signature update knocked out Microsoft's built-in antivirus on Windows 10 and 11 machines this week, leaving scans failing and some users reinstalling their operating system before a patch arrived.

Nearly 2,000 Hacked WordPress Sites Turned Into a Criminal Toolkit
A sprawling operation dubbed StopAndProtect is quietly using compromised WordPress sites as a delivery network for malware, stolen files and screenshots.

CISA Orders Urgent Fixes for Four Actively Exploited Flaws in Windows, VMware, and macOS
Four security holes, all being actively abused by real attackers right now, need patches immediately. Two hit Microsoft, one VMware, one Apple.

Microsoft Ties 30+ Rotating Domains to MacSync, a New Mac Data-Stealing Malware
Defender Experts traced the macOS stealer across shifting web infrastructure by matching endpoint and network behaviour, not just domain names.

Oracle Pushes 943 Security Fixes in August 2026 Patch Update
Oracle's latest monthly security release covers more than 1,000 flaws across two dozen products, including nearly 90 critical bugs that score almost perfectly on the industry's severity scale.

AI is already in your attacker's toolkit. Is it in your defences?
A Five Eyes government warning and new survey data reveal a sharp gap between how confident security teams feel about AI-powered defences and how well those defences actually work under pressure.

A 15-Minute Framework for Spotting What AI Systems Can Do Wrong
Security expert Adam Shostack built PHANTOM-B to help organisations find the risks hiding inside AI-powered software before those risks find them.

Firefox and Chrome Rush Out Patches for Dozens of Security Flaws
Mozilla fixed 58 vulnerabilities in Firefox 154, while Google addressed 15 in Chrome 151, including two critical bugs that could let attackers run malicious code on your device.

Medusa ransomware has hit 500 critical infrastructure targets, US agencies warn
A fresh CISA advisory says the gang's victim count has jumped from 300 to over 500 since March 2025, with hospitals, defence suppliers and banks all in the firing line.

Fake celebrity interviews and AI-generated 'news' are fuelling an investment scam surge in Australia
Australia's corporate regulator removed nearly 20,000 scam websites last year, as criminals use AI-generated deepfakes of politicians and financial commentators to make phoney investment schemes look real.

Researchers Tricked Microsoft Copilot Into Revealing Its Own Weaknesses, Then Used That Knowledge to Steal Data
A research team at Varonis discovered that simply chatting with Microsoft's AI assistant could expose enough internal detail to build a working attack. Microsoft has patched the flaws, but the technique raises questions that go well beyond one product.

Comcast Turns Home Wi-Fi Into a Motion Sensor With New Xfinity Shield
The cable giant is pitching your router as a way to spot movement around the house, no cameras required. Privacy questions come with it.

The Security Chiefs Who Finally Get to Tell Their Stories
A new documentary series lets cybersecurity leaders speak openly about hacks, burnout, and the human cost of keeping organisations safe. One episode alone involves $2 million stolen in a single phone call.

The Ransomware Scavengers: 'Ransom Busters' Emails Victims Demanding Up to $60,000
A new outfit is contacting companies already hit by ransomware and offering, for a fee, to wipe their stolen files from the attackers' servers.