Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator After all that hype, AI scanner found one low-severity cURL flaw
BWH Hotels guests warned after reservation data checks out with cybercrooks Customers urged to keep an eye out for phisherfolk
Google says criminals used AI-built zero-day in planned mass hack spree GTIG says AI-powered hacking has moved well beyond phishing emails and chatbot tricks
Water company's leaky security earns near-£1M fine Utility provider failed to detect Cl0p ransomware attack for nearly two years
Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged Cybercrooks ruin engineers' weekends with Saturday attack
Taiwan's train cyber-trauma reveals a global system that’s coming off the tracks That’s not a radio. THIS is a radio
Worm rubs out competitor's malware, then takes control All your compromised credentials are belong to us now instead of the other gang
Disgraced US gov software contractor found guilty of database destruction Twin brother still faces trial over broader cybercrime allegations
'Dirty Frag' Linux flaw one-ups CopyFail with no patches and public root exploit Broken disclosure embargo left admins facing a fresh root-level flaw with no CVE
Meta U-turns on encryption push for Instagram as DMs go plaintext After years of insisting end-to-end encryption was the future of online comms, Zuckcorp has handed itself full visibility into user chats once again
Hackers ate my homework: Educational SaaS Canvas down after cyberattack ShinyHunters takes the credit and gives developer an F for security
Meta fights Ofcom over how many billions count as billions Social media biz says watchdog's fine formula is 'disproportionate' and should stop counting global revenue
Mozilla boasts Mythos boosted Firefox bug cull Yet it remains unclear if Anthropic's uber model was effective, or if better model middleware is what makes the difference
Fake IT workers rented laptops to Nork scammers, got prison time Matthew Isaac Knoot and Erick Ntekereze Prince will each do 18 months for hosting laptops used by North Korean IT workers to remotely infiltrate US companies
Anthropic response to 1-click pwn: Shouldn't have clicked 'ok' Security biz Adversa AI argues users of AI tools need clearer warnings
60% of MD5 password hashes are crackable in under an hour Happy World Password Day! Maybe it's finally time to kill this holiday in favor of World No-More-Passwords Day?
$250M crypto-robbing gang’s dirty work guy sentenced to 6.5 years behind bars The then-teen was told to break in and steal what the keyboard warriors couldn’t
State-backed hackers hammer Palo Alto firewall zero-day before patch lands Internet-facing PAN-OS firewalls are once again doing impressions of initial access brokers
Hungarian cops cuff suspected swatter after two-year FBI probe 20-year-old fessed up after investigators found video of crime in progress
The network password was a key plot point in one of the most famous movies of all time Fortunately, it was a legit contractor who guessed it
Arctic Wolf kicks 250 employees out of the pack to save money for AI Cuts appear to hit sales, product, and marketing, accounting for under 10% of staff
1 in 8 employees totally cool with selling work credentials 13% say they’ve sold logins or know someone who has, survey suggests
Iran cybersnoops still LARPing as ransomware crooks in espionage ops MOIS-linked cyber outfit puts on a ransomware show to disguise the wide-open backdoor behind the scenes
UK age-gating plans risk breaking the internet, privacy groups warn Activists say ministers are targeting access rather than Big Tech's data-hungry business models
Taiwan cops say student's radio kit brought bullet trains to a standstill Investigators spent weeks unravelling enthusiast's bedroom project
India orders infosec red alert in case Mythos sparks crime spree Securities regulator urges market players to develop new strategies and nail cyber-basics before AI models fuel mass attacks
ServiceNow clears agents for landing with new AI control tower ServiceNow acquisitions Veza and Traceloop join to monitor agents and AI workflows
Attackers are cashing in on fresh 'CopyFail' Linux flaw Researchers dropped a reliable root exploit and it didn’t sit idle for long
Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knocking Cushman & Wakefield activated incident response protocols after serial extortionists issued separate threats
ShinyHunters claims dump puts 119K Vimeo emails in the wild Vimeo points finger at analytics supplier Anodot, says no logins or card data were touched
Romance scammers turn sweet talk into £102M payday Victims losing £280K a day to fake profiles and sob stories
Singapore boffins get diverse SIEMs singing in harmony with agentic rule translation Vendors all use different formats. This tech translates them all so you can smooth your SOC
Kids say they can beat age checks by drawing on a fake mustache 46% say age checks are easy to bypass, and nearly a third admit getting around them
Shadow IT has given way to shadow AI. Enter AI-BOMs 'If you don't have visibility, you can't understand what to protect'
If the vote you rocked, your personal info can be grokked Even limited voter rolls can be linked to identify people, research shows
Five Eyes spook shops warn rapid rollouts of agentic AI are too risky Prioritize resilience over productivity, say CISA, NCSC and their friends from Oz, NZ, Canada
Brace for the patch tsunami: AI is unearthing decades of buried code debt Britain's cyber agency says the bill for years of technical shortcuts is coming due, and it's arriving all at once
First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed Exploitation was underway before patches landed, at least one victim reports ransomware demand
OpenAI locks GPT-5.5-Cyber behind velvet rope despite slamming Anthropic for doing exactly that Altman's crew now doing the same gatekeeping it recently mocked
Pro-Iran crew turns DDoS into shakedown as Ubuntu.com stays down 313 Team tells Canonical: pay up or the packets keep coming
Passport to £££: Home Office adds £216M to travel doc contract before a single bid's been placed Start date pushed back a year, annual cost up a third, and UK's now handing out eight million passports a year
The never-ending supply chain attacks worm into SAP npm packages, other dev tools Mini Shai-Hulud caught spreading credential-stealing malware
Bot her emails: most modern phishing campaigns are AI-enabled KnowBe4 says 86% of phishing it tracked used AI, and inboxes are only the start
FBI cyber boss: China's hacker-for-hire ecosystem 'out of control' One alleged cyber contractor was extradited to the US over the weekend
Google's fix for critical Gemini CLI bug might break your CI/CD pipelines This CVSS 10.0 RCE vuln has been patched, automatically for some, so better check those workflows
French prosecutors link 15-year-old to mega-breach at state’s secure document agency Two computer crime allegations follow up to 18M lines of data surfacing online
Nearly half of UK businesses pwned last year as phishing keeps doing the job like it's 2005 Turns out the real problem is not AI but staff still clicking on dodgy emails from 'IT support'
What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Just in time for the Trump-Xi summit
Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day Emergency patches out now for those managing the millions of domains assumed to be affected
Finance company stores DB credentials in helpfully labeled spreadsheet Great idea, guys. Let's keep all of the data in an Excel file with weak password protection
Linux cryptographic code flaw offers fast route to root Patches land for authencesn flaw enabling local privilege escalation
Researchers move in the right direction, develop powerful GPS interference alarm ORNL says portable detector kit can separate real GPS signals from fake ones even at equal strength
Microsoft's patch for a 0-day exploited by Russian spies fell short. Another Windows flaw is under attack Second try's a charm?
Legacy TLS tour continues with Exchange Online blocking old versions from July 2026 Microsoft readies the axe once again for yesterday's security
Yet another experiment proves it's too damn simple to poison large language models There is no 6 Nimmt! champion, but a $12 domain registration and one Wikipedia edit convinced several bots there was
CISA flags data-theft bug in NSA-built OT networking tool GrassMarlin leaks sensitive information, provided your targeting phishing skills are sharp enough
GitHub: Zounds, a genuinely helpful AI-assisted bug report that isn't total slop! Here, Wiz, take this wad of cash Claude ploughs through months of work in rapid time, helps Wiz researchers nab lucrative award
30 ClawHub skills secretly turn AI agents into a crypto swarm Yet another reason not to feast on OpenClaw
Don't pay Vect a ransom - your data's likely already wiped out 'Full recovery is impossible for anyone, including the attacker'
Have I Been Pwned claims Pitney Bowes hit by 8.2M email address leak Names, phone numbers, physical addresses also included in Shiny Hunters alleged data dump
Ongoing supply-chain attack 'explicitly targeting' security, dev tools Vendor confirms repo data exposure after Lapsus$ claims source code, secrets dump
Cursor-Opus agent snuffs out startup’s production database Relax, the data's been recovered. Continue with your vibe coding
Medical and utility tech companies admit digital breakins Itron, Medtronic disclose breaches in Friday filings
Cybersec is a thankless job: expanding workload and shrinking pay packet Global recruitment giant says 71% of human firewalls saw wages stagnate last year as threats and responsibilities grew
Burglar alarm biz burgled: ADT confirms cyber intrusion after ShinyHunters extortion attempt Security giant says attackers grabbed 'limited set' of data. Crooks claim 10 million records
Anthropic's magic code-sniffer: More Swiss cheese than cheddar, for now AI vuln-hunter finds what humans taught it to find. Funny that
AI's not going to kill open source code security Cal.com considers AGPL a license to drill, but not everyone feels that way
Crime crew impersonates help desk, abuses Microsoft Teams to steal your data Coming in cold with custom Snow malware
ShinyHunters claim they have cruise giant Carnival's booty as 7.5M emails surface Leak-site bragging meets breach hunters as Have I Been Pwned flags millions of records
Governments on high alert after CISA snuffs out Firestarter backdoor on fed network Latest in long-running pwning of Cisco kit found in mystery Fed agency