Latest stories — Page 8

The 'CDN Tsunami' Attack Turns a Trickle of Traffic Into a Flood at the Origin
Researchers show how the way big content delivery networks translate modern HTTP/3 requests into older HTTP/1.1 can multiply a small attack stream by up to 350 times against the website behind them.

'Zombie Card' Attack Brings Expired Visa Contactless Cards Back to Life
UMass Amherst researchers show how to rewrite the expiry date a payment terminal sees, letting dead cards buy real goods.

Atlassian and Splunk Push Patches for More Than 250 Flaws, Including Critical Bugs
Two major software vendors dropped sweeping security updates this week. Here is what changed, what could go wrong without the fix, and what ordinary users should know.

Kriminal: The $12.99-a-Month Criminal AI Service That Piggybacks on Grok and Claude
A new service called Kriminal sells access to leading AI models with their safety restrictions stripped out, packaging hacking tools, fake-identity generation and financial tracing into subscription tiers that start cheaper than a streaming service.

Cisco Patches Four Maximum-Severity Flaws in Crosswork Network Software
Fifteen vulnerabilities fixed across Cisco products, with three scoring a perfect 10 out of 10 on the standard severity scale. None are known to be exploited yet.

Fake Firefox Wallet Extensions Drain Crypto From Unwary Users
Researchers at Socket found 40 Firefox add-ons impersonating OKX, Rabby, TronLink and other crypto wallet brands, part of a wider 77-extension operation they call Offside Wallet Theft Factory.

NASA Spacecraft Control Software Has a Critical Flaw Attackers Could Use Remotely
Researchers at Cycode found a chain of bugs in AIT-GUI, a NASA/JPL tool used to talk to spacecraft, that lets outsiders send commands with no login required.

ToxicPanda 2.0: Android Banking Malware Now Targets 140+ Apps and Steals PINs
A revamped version of the ToxicPanda Android malware carries 167 remote commands and a PIN-grabbing routine aimed at banking and cryptocurrency apps worldwide.

After Russian Hackers Knocked Out a Satellite Network, an AI Tool Is Now Stress-Testing Its Defences
Viasat's satellite network was crippled by a Russian cyberattack in 2022. Now an AI-assisted security tool from Atalanta is being used to check whether the rebuilt defences can hold.

AI Agents That Go Rogue Are Now an Insider Threat, Security Expert Warns
A breach involving AI systems at a major machine-learning platform has exposed a problem companies weren't expecting: the AI tools they deploy to protect themselves can turn against them.

OpenAI Tightens AI Model Security After Hugging Face Breach and Astra Findings
New sandboxing controls, 30-minute alert windows, and the ability to pause model training mark a significant shift in how OpenAI handles security risks inside its own systems.

Manic Android malware hops between infected phones to steal Ukrainian banking data
Researchers at ThreatFabric say the spyware, active since February, targets 169 apps and can relay stolen data through nearby infected devices over Wi-Fi Direct or Bluetooth when the internet is unavailable.

Poland's CERT warns of active attacks on critical Zimbra email flaw
CERT Polska says attackers are exploiting CVE-2026-73570 in Zimbra Collaboration Suite. Zimbra patched the bug in version 10.1.20 on July 20.

Citrix Patches Critical Login-Bypass Flaw in NetScaler, Attacks Expected Soon
A security hole rated 9.3 out of 10 lets criminals walk straight past the login screen on widely used corporate network gear. Patches are out now, and researchers say exploitation is a matter of when, not if.

Microsoft probes Windows 11 August update after gamers report crashes in ARC Raiders and The Finals
The KB5121003 patch is under investigation after players on 24H2 and 25H2 reported freezes, access-violation errors and sudden reboots.

Airlock Digital Passes Australia's Toughest Government Security Check
The Australian application control firm has cleared an independent IRAP assessment at PROTECTED level, giving government and critical-infrastructure buyers one more piece of evidence for their due-diligence files.

ChatGPT goes dark worldwide as OpenAI scrambles to fix login failures
A global outage starting late Wednesday locked users out of ChatGPT, Codex and a dozen OpenAI API endpoints.

Australian Supermarkets Are Testing Face-Scanning Technology on Shoppers
Coles and Woolworths have confirmed trials of facial recognition software in their stores. Privacy advocates say collecting biometric data from grocery shoppers crosses a line.

UK Prime Minister Andy Burnham Tricked Into Texting a Fake Trump Aide
Someone impersonating Susie Wiles, Donald Trump's chief of staff, exchanged messages with the British Prime Minister. It is the latest in a string of attacks targeting senior politicians through simple social deception.

Meet Kriminal: The AI Service With No Rules That Anyone Can Find on Google
A subscription AI platform called Kriminal markets itself as uncensored and unlimited. Researchers say it is stitched together from mainstream AI tools, and that makes it very hard to shut down.

Sakura Internet Says Breach May Have Exposed 1.36 Million Customer Accounts
The Japanese cloud provider, a chosen supplier for Japan's Government Cloud, found the wider intrusion while investigating a smaller hack of its rental server service.