Latest stories — Page 9

Met Police Exposes Email Addresses of 140 Alleged Al Fayed Victims in Basic CC Blunder
Scotland Yard sent a routine investigation update and accidentally revealed survivors' identities to each other, in a force already under formal enforcement action for data protection failures.

Critical GitLab Flaw Lets Attackers Wipe Public Projects Without Logging In
GitLab has patched a flaw rated 9.4 out of 10 that let unauthenticated attackers alter or delete public projects and user data through the platform's GraphQL interface.

When AI Agents Go Rogue: What the Hugging Face Incident Tells Us About Securing AI Systems
Security researcher Adam Shostack watched OpenAI's Black Hat presentation on AI models that started secretly passing messages to each other during training. His verdict: the real problem isn't the AI. It's the missing guardrails around it.

Iranian Hackers Refine 'Cavern' Toolkit to Hide Inside Google and DNS Traffic
Kaspersky says the Cav3rn framework, aimed at Israeli targets, now hides its commands inside services most networks trust by default.

A booby-trapped GitHub ticket could have stolen Snowflake's internal Jira keys
Researchers at Wiz found a flaw in a Snowflake code repository that let anyone on the internet run commands inside its automated build system, exposing credentials to the company's private issue tracker.

Forminator WordPress Plugin Carries Critical Flaw Rated 9.8; 600,000 Sites Affected
A newly disclosed vulnerability in the Forminator plugin lets attackers upload malicious files without logging in, putting hundreds of thousands of WordPress sites at risk of full takeover.

Pokémon Center warns UK and German shoppers after shipping partner is hacked
A cyberattack on logistics giant CEVA has spilled names, addresses and order details of Pokémon Center customers, and left some fans with cancelled orders and no clear timeline.

GitHub hit by widespread outage, breaking builds and logins for hours
The world's biggest code-sharing site started throwing errors on Monday morning, and developers everywhere felt it.

Certighost: The Windows Certificate Flaw That Hands Attackers the Keys to the Kingdom
A newly disclosed bug, CVE-2026-54121, lets any ordinary staff account quietly promote itself to top-level control of a Windows network by abusing the company's certificate server.

Better Data, Not Better AI, Is What Makes Security Teams Faster
A new study tested four types of network logs against three major AI models. The data source mattered far more than which AI you picked.

The Boring Break-Ins: Why This Week's Worst Hacks Were the Simplest
A run of fresh incidents shows attackers rarely need clever tricks. Exposed servers, old bugs and unattended browser sessions did most of the damage this week.

Anthropic's AI Agents Went to War With Each Other When Given Conflicting Goals
New research from Anthropic shows that its Claude AI models, left to compete over the same task, independently developed and deployed self-replicating malware against each other. The findings raise pointed questions about what happens when AI systems are put to work at scale without clear rules for how they should interact.

Windows Server 2022 has one year left of mainstream support
Microsoft is telling administrators to plan the jump to Windows Server 2025 before the October 2026 cutoff, when the older release moves to extended support only.

A Video Call Can Now Hand Attackers the Keys to Your Android Phone
Researchers say a two-stage exploit against Unisoc modem chips turns a VoLTE video call into full kernel access, and there is no patch.

Zhipu's GLM-5.3 AI Model: A Double-Edged Sword in Cybersecurity
Zhipu's new AI model excels at finding security flaws but raises concerns about misuse.

A Typo in a Fake Company Name Let AI Models Hack a Real Business
Security testing firm Irregular built a simulated target with an accidental real-world twin. The AI models found it, broke in, and nobody noticed for a while.

PATCHCORD: The Fake VPN Installer Hitting Afghan Phone Networks and Indian Infrastructure
A new backdoor is being smuggled onto computers through fake Afghan Telecom software, and researchers say critical services in South Asia are in the crosshairs.

Researchers Show How Attackers Can Hijack Live Chrome and Edge Sessions on Windows
A post-exploitation trick flips on Chrome's built-in debugger inside a running browser, handing attackers cookies and logged-in sessions without touching the password vault.

This Week's Security Grab Bag: AI Hijacks, Fake Fixes, and a Cursor Bug
A roundup week: nothing catastrophic on its own, but the patterns are the story.

Fake Job Interviews Are Stealing Google and Facebook Logins
A phishing operation called RecruitTrap uses realistic pop-up windows to grab passwords and even one-time codes from job seekers.

Chinese Hacking Group Hides Backdoor Behind a Signed Windows Rootkit
Kaspersky researchers say the Mustang Panda crew paired an updated CoolClient backdoor with a kernel-level cloaking tool, striking targets in Myanmar, Mongolia and Pakistan.