For you Ai Security Dev Cloud Hardware Startups Releases General

Security · Top stories

1 source 1 report 1d ago

Taiwan indicts ex-TSMC manager over alleged leakage of chip secrets to China

Taiwanese prosecutors indicted a former TSMC deputy manager for allegedly stealing 21 confidential chip technology documents to share with a Chinese firm. This case, the first under Taiwan's National Security Act related to core semiconductor technologies, highlights continuing concerns about industrial espionage amid heightened geopolitical tensions.

security taiwan semiconductors espionage national security
3 sources 3 reports 1d ago Updated 1d ago

OpenSSL HollowByte Flaw Exposes Servers to Memory Exhaustion with Minimal Payload

A vulnerability in OpenSSL, known as HollowByte, allows attackers to trigger a denial-of-service condition by sending an 11-byte payload. The flaw causes vulnerable servers to pre-allocate memory for incomplete TLS handshake messages. Fixed versions without official CVEs or advisories include OpenSSL 4.0.1 and others released on June 9. Upgrading is crucial to prevent potential server freezes.

security openssl vulnerability dos
8 sources 9 reports 5d ago

Teens sentenced to 5.5 years for £29M Transport for London cyber attack

Owen Flowers and Thalha Jubair were sentenced to 5.5 years for a 2024 cyberattack on TfL that caused £29 million in damages. The attack severely disrupted services and breached data of millions. Authorities cite this case as a major enforcement action against young cybercriminals.

security cybercrime hacking TfL law enforcement
1 source 1 report 7h ago

SecurityWeek Introduces Critical Impact Awards for Industrial Cybersecurity

SecurityWeek has launched the Critical Impact Awards to recognize achievements in industrial cybersecurity. This awards program aims to honor organizations and individuals based on merit rather than sponsorship, enhancing credibility in the cybersecurity field.

security cybersecurity awards ics industrial
1 source 1 report 7h ago

Kenya investigates hack of president's website demanding bitcoin ransom

Kenya is investigating a cyberattack that defaced President William Ruto's official website with a ransom demand of five bitcoins. The attackers claimed this was their third warning to the president, though no sensitive data has been compromised according to government officials.

security cybersecurity kenya bitcoin hack
1 source 4 reports 7h ago Updated 6h ago

Researchers Reveal Security Flaws in AI Coding Agents and Open-Source Mobile Frameworks

Researchers from Hong Kong University have highlighted vulnerabilities in AI coding agents, notably OpenAI Codex and Claude Code, which can be bypassed using techniques like SKILLCLOAK. These techniques allow malicious AI add-ons and agents to evade current security scanners. These findings underscore the need for improved security measures in AI agent marketplaces and software, as current defenses are inadequate.

security malware ai research dev
1 source 1 report 7h ago

CISO Andreas Gaetje Discusses Career Path at Körber AG

Andreas Gaetje, CISO at Körber AG, reflects on his unconventional career journey from economics to cybersecurity. He emphasizes the significance of adapting to the evolving role of IT security, which has grown from compliance to a critical business threat.

security cybersecurity ciso korber career
1 source 1 report 7h ago

Meta Awards $78,000 Bug Bounty for Critical Customer Support Data Vulnerability

Meta has awarded a $78,000 bounty to researcher Rony K Roy for discovering a vulnerability in its support data system that could have led to the exposure of sensitive customer information. The issue, initially thought minor, was found to allow unauthorized access to support cases and user communications, demonstrating significant flaws in Meta's security framework.

security meta bug bounty vulnerability
1 source 1 report 7h ago

Clover Health Investments Reports Data Breach Affecting Customer Information

Clover Health Investments disclosed a data breach affecting customers' personal and health information due to a social engineering attack that compromised three employee accounts. The company initiated its response plan and engaged cybersecurity experts to handle the situation, though the full impact of the breach is still being investigated.

security data breach cybersecurity healthcare Clover Health
2 sources 2 reports 1d ago Updated 1d ago

AI Technology Reduces Vulnerability Exploitation Time, Increasing Security Concerns

The rapid increase in newly reported vulnerabilities, and the use of AI in exploit development, has significantly reduced the time it takes for cyber threats to be operationalised. This has created a larger 'exposure window' between vulnerability discovery and remediation, placing pressure on security teams. With CVEs published at an unprecedented rate, prompt response times are becoming crucial to mitigate potential breaches.

security vulnerabilities CVE pentesting exploitation
1 source 1 report 1d ago

South Korea's diplomat training system breached by hackers for 9 months

Hackers compromised South Korea's diplomatic academy's e-learning platform for nine months, exposing employee data. This breach raises serious cybersecurity concerns, especially given the country's past experiences with North Korean cyberattacks.

security cybersecurity data breach south korea diplomacy
1 source 1 report 1d ago

Ransomware Payments Increase Under Regulatory Scrutiny

A recent report reveals that nearly half of ransomware victims pay ransoms, with the median amount demanded rising. In response, some jurisdictions, including the UK, are moving to ban ransom payments for public sector entities amid a surge in ransomware attacks driven by AI tools and advanced targeting methods.

security ransomware cybersecurity regulation ai
7 sources 7 reports 7d ago

Cybersecurity Expert Sentenced for Role in BlackCat Ransomware Scams

Angelo Martino, a former ransomware negotiator, has been sentenced to 70 months for aiding the BlackCat ransomware gang. Collaborating with accomplices, he shared confidential negotiation details, causing victims to lose over $75 million. This highlights vulnerabilities within cybersecurity industries.

security ransomware cybersecurity law criminal justice
1 source 1 report 1d ago

Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic Computers

A Russian-speaking hacker named 'bandcampro' leveraged Google's open-source Gemini CLI to control a botnet consisting of eight PCs at a dental clinic. This incident highlights the evolving use of AI in cybercrime, enabling sophisticated operations that can rapidly adapt and proliferate.

security ai botnet cybercrime
6 sources 9 reports 4d ago

PamStealer Malware Targets macOS for Credential Theft Using Apple's PAM

Researchers have discovered PamStealer, a macOS malware that uses Apple's PAM interface to steal user credentials. This sophisticated malware employs a two-stage delivery system, disguising as the clipboard manager Maccy and utilising stealthy JavaScript for Automation. It highlights emerging threats in macOS security exploiting native Apple frameworks for credential theft.

security macos malware credential-theft threats
6 sources 7 reports 6d ago

HalluSquatting Attack Exploits AI Hallucinations to Form Botnets

The "HalluSquatting" attack exploits AI hallucinations to inject malicious commands into coding assistants, potentially creating botnets. Researchers from Tel Aviv University and other institutions demonstrated that attackers can pre-register fictitious software names generated by AI. AI models' tendency to hallucinate and act on fake package names can expose systems to widespread malware deployment.

security ai halluSquatting malware cybersecurity
6 sources 6 reports 12d ago

CERT/CC Reports Hidden Backdoor in Tenda Router Firmware Allowing Admin Access

A vulnerability in various Tenda router firmware versions, CVE-2026-11405, allows unauthorized administrative access via an undocumented backdoor. This flaw poses significant security risks for users as attackers can bypass authentication to control devices remotely. Despite warnings, Tenda has not addressed the issue, leaving affected devices unpatched.

security tenda router vulnerability firmware
1 source 1 report 1d ago

SleeperGem Malicious RubyGems Target Dev Machines in Supply Chain Attack

A new cyber attack, codenamed SleeperGem, has been identified, affecting the Ruby ecosystem through three malicious RubyGems. This attack poses a significant risk to developers by potentially compromising their machines and extending to other packages.

security ruby malware
2 sources 2 reports 1d ago Updated 1d ago

Craneware Reports Data Breach Affecting US Hospitals and Pharmacies

Craneware, a UK-based software provider for over 2,000 US hospitals, reported a data breach involving employee and customer information. The breach resulted in the theft of significant data, impacting hospitals' billing and patient management services. The incident has been contained, with investigations ongoing.

security data breach healthcare cybersecurity Craneware
2 sources 2 reports 1d ago

Hacker Attack Disrupts Romania's Land Registry Operations

Romania's land registry agency suffered a cyberattack, resulting in the wiping of its database and a halt in real estate transactions. The agency is migrating its systems to the government cloud to restore operations while ensuring data integrity.

security hacking data breach romania real estate
2 sources 2 reports 1d ago Updated 1d ago

Russian Hackers Use Security Cameras to Monitor NATO and Ukrainian Military Movements

Russian intelligence services are using internet-connected security cameras across Ukraine and NATO states to gather military intelligence. This operation involves exploiting cameras with default settings or security flaws, collecting data on military logistics and weapon shipments, and targeting Ukrainian troops. The breaches pose serious security risks across Europe and Ukraine.

security cybersecurity espionage NATO Ukraine
5 sources 5 reports 4d ago

Ransomware Attack Halts Fairlife Dairy's U.S. Production Temporarily

Coca-Cola's Fairlife dairy subsidiary has halted U.S. operations following a ransomware attack that affected production systems. The July 16 incident led to the activation of crisis protocols, though product quality was not impacted. Fairlife's U.S. facilities are paused, but Canadian operations remain unaffected.

security coca-cola fairlife ransomware food industry
2 sources 2 reports 20d ago

FBI and CISA Warn of Russian Phishing Attacks on Signal and WhatsApp Accounts

The FBI and CISA have issued an updated warning about Russian intelligence phishing campaigns targeting Signal and WhatsApp accounts. Attackers are using Signal Backup Recovery Keys to hijack accounts, and the U.S. is offering a $10 million reward for information on the group responsible. The campaign has compromised thousands of accounts of high-profile targets, including government officials and journalists.

security russia phishing signal hacking
1 source 1 report 14h ago

Cloudflare moves to post-quantum cryptography with ML-KEM and ML-DSA

Cloudflare is transitioning its encryption methods to ML-KEM and ML-DSA to address quantum computing threats. The U.S. NIST standardized these algorithms in 2024, and Cloudflare aims for full post-quantum security by 2029.

security post-quantum cryptography quantum computing
1 source 1 report 14h ago

Cloudflare joins UK's Cyber Resilience Pledge to enhance cybersecurity governance

The UK government launched the Cyber Resilience Pledge, aimed at enhancing cybersecurity governance. Cloudflare joined as a founding signatory, emphasizing collective defense principles against increasing cyber threats.

security cloudflare cybersecurity uk government
1 source 1 report 14h ago

Cisco Talos Deploys SnortML for Machine Learning Intrusion Detection

Cisco Talos launched SnortML, a machine learning detection engine integrated into Snort 3, to address gaps in traditional IDS. It allows for faster responses to novel exploits by processing data locally and issuing verdicts in under a millisecond.

security intrusion detection machine learning snort
1 source 1 report 14h ago

Kubernetes to Correct CVE Records for Unfixed Vulnerabilities in 2026

The Kubernetes project will correct inaccuracies in CVE records for older unfixed vulnerabilities on June 1, 2026. This change aims to improve transparency and ensure that vulnerability scanners can better identify risks that currently go undetected due to erroneous fixed version tags.

security kubernetes cve vulnerabilities
2 sources 2 reports 1d ago Updated 1d ago

7-Zip Version 26.02 Fixes High-Severity RCE Flaw in XZ Archive Processing

7-Zip released version 26.02 to address a remote code execution (RCE) vulnerability linked to XZ-compressed data. Discovered by Lunbun researcher Landon Peng, the flaw could be exploited if a user opened a specially crafted archive. This highlights the need for manual updates due to 7-Zip's lack of an automatic update feature, emphasizing user awareness and action.

security 7-zip vulnerability rce xz-archive
5 sources 5 reports 6d ago

Microsoft Issues Record 570 Security Patches, Including Three Zero-Days

Microsoft's July 2026 Patch Tuesday included a record 570 security patches, with three zero-day vulnerabilities addressed. The increase is partly due to AI-assisted discovery, highlighting a trend in vulnerability identification and remediation.

security microsoft patches vulnerabilities patch-tuesday
5 sources 5 reports 12d ago

Critical KVM/x86 Vulnerability Allows VM Escape to Host on Intel and AMD

Januscape, a 16-year-old use-after-free vulnerability (CVE-2026-53359) in Linux's KVM hypervisor, allows guest VMs to execute arbitrary code on host systems, compromising host security in multi-tenant environments. Discovered by Hyunwoo Kim, this first-known architecture-independent exploit has been demonstrated in Google's kvmCTF. Cloud providers like Google Cloud and AWS may be particularly vulnerable, posing risks of data breaches.

security kvm vulnerabilities cloud linux
5 sources 6 reports 14d ago

19-Year-Old Extradited to U.S. for Role in Scattered Spider Hacks

Peter Stokes, a dual U.S. and Estonian citizen, was extradited from Finland to the U.S. to face charges related to hacking activities with Scattered Spider. Notable incidents include a 2025 cyberattack on a luxury jewelry retailer demanding an $8 million cryptocurrency ransom. The extradition underscores efforts to combat global cybercrime.

security cybercrime hacking law enforcement scattered spider
5 sources 5 reports 15d ago

Opera Rolls Out 'Paste Protect' to Counter ClickFix Cyber Attacks

Opera has introduced 'Paste Protect', a new feature to block malicious clipboard commands copied from websites, aimed at mitigating ClickFix-style attacks. These attacks leverage social engineering tactics to mislead users into pasting harmful code into terminals. The new feature marks the first native defense against this rising cyber threat in a major web browser.

security browser malware opera cybersecurity
1 source 1 report 1d ago

F5 Releases Patches for Critical NGINX Vulnerability Allowing Remote Code Execution

F5 has released security patches for a critical vulnerability in NGINX (CVE-2026-42533) that allows remote attackers to trigger a heap buffer overflow, potentially leading to remote code execution and denial of service. This vulnerability affects numerous NGINX versions and some configurations, which could expose many installations unless updated.

security nginx vulnerability patches
1 source 1 report 16h ago

New Proposal for Interoperable Passkey Records and Go API Announced

A new specification for interoperable passkey records, inspired by Password Hashing Competition Strings, aims to simplify the integration of passkeys in applications. This proposal allows developers to handle passkey records as opaque strings, making implementation more efficient and reducing complexity in database interactions.

security webauthn authentication passkeys
2 sources 4 reports 1d ago Updated 1d ago

Chrome 150 Update Addresses 27 Vulnerabilities, Enhances Security

Google released Chrome 150, patching 27 security vulnerabilities, including two critical use-after-free flaws in Ozone and Views. This update is part of a broader effort to improve browser security, with most flaws discovered internally by Google. Regular updates are essential due to frequent exploitation of memory safety vulnerabilities in browsers like Chrome.

security chrome vulnerabilities google browser
1 source 1 report 2d ago

Texas Police Acquire FalcoNet Surveillance System for $4.5 Million

Texas State Police purchased four FalcoNet-equipped Chevrolet Tahoes for $4.5 million to enhance surveillance capabilities. This technology, capable of intercepting mobile phone communications, raises significant concerns over privacy and data collection on civilians.

security surveillance privacy law enforcement technology
4 sources 4 reports 3d ago

San Francisco Orders Apple and Google to Remove Nudify Apps for Legal Violations

San Francisco City Attorney David Chiu ordered Apple and Google to remove 13 nudification apps from their app stores, citing violations of California laws against deepfake pornography. The apps are accused of creating non-consensual explicit images, which impact women and minors. The city claims the companies have profited from these apps and warns of potential civil penalties if they do not comply within 28 days.

security nudification deepfake apple google
1 source 1 report 2d ago

Hackers Target Russian Government Agencies via ViPNet Software Abuse

A threat actor is exploiting ViPNet's update mechanism to deploy malware against Russian organizations, including government agencies. The campaign, named HelloNet, impacts multiple sectors and reflects ongoing vulnerabilities in widely used security products.

security malware russia cybersecurity APT
4 sources 5 reports 4d ago

xAI Sues South Carolina Man Over Grok-Generated Sexual Images

xAI has initiated a lawsuit against Terry Wayne Harwood, alleging misuse of its Grok AI to generate child sexual abuse material (CSAM). This legal action, driven by Harwood's alleged bypassing of Grok's safeguards, underscores the challenges AI companies face in preventing abuse of their technology.

security grok csam lawsuit xai
4 sources 4 reports 5d ago

Ofcom Probes TikTok's Child Safety Due to Age Verification Concerns

UK regulator Ofcom is investigating TikTok's age verification methods under the Online Safety Act 2023. Concerns revolve around TikTok's use of 'age inference' technology, which might not adequately identify minors and expose them to harmful content. TikTok claims compliance with safety obligations, while Ofcom's findings could result in significant penalties if failures are confirmed.

security tiktok ofcom children safety
More stories →