Topic

Security

Breaches, vulnerabilities, scams and the defences that work. Every story names the affected products and says what to do about it.

184 stories, page 1 of 8

Security

One crafted request can crash a NetScaler, and CISA wants it patched today

A Citrix NetScaler vulnerability, CVE-2026-88779, lets one crafted request crash SAML devices. CISA confirms exploitation and set a Wednesday patch ...

· 2 min read
Security

N-able N-Central CVE-2026-86218 is a 9.8 flaw under active attack

The N-able N-Central vulnerability CVE-2026-86218 scores 9.8 and is under active attack. Update to 2026.3.1.14 or later; here is a short patch ...

· 2 min read
Security

AI written fake bug reports got so bad Google paused a bounty

Google paused product vulnerability submissions to its open source bug bounty from 1 October after floods of AI generated reports, which volunteers ...

· 2 min read
Security

Before you give an AI agent your inbox, run this 10 point check

An AI agent security checklist in ten steps: separate accounts, read only access, spending limits, hardware keys, logs and a fast way to revoke ...

· 3 min read
Security

Sanders proposes ban on federal automatic license plate readers

Bernie Sanders has proposed legislation to ban federal law enforcement from using Flock Safety's automatic licence plate readers and similar ...

· 5 min read
Security

Apple tightens Mac security against AI agents

Apple is adding new controls to macOS to restrict how much access AI agents can have to your files, emails, and browsing history. As autonomous AI ...

· 4 min read
Security

A zero-day just hit your router or VPN. Do these 7 things today

What to do after a zero-day hits your router, VPN or email gateway: a 7-step checklist covering exposure, patching, admin access, credentials and ...

· 3 min read
Security

Hackers lived in Pentagon HR files for 10 months and took 3 million records

The Pentagon's Defense Manpower Data Center says attackers abused a file-sharing flaw for ten months and stole records on more than 3 million ...

· 3 min read
Security

Passkeys vs security keys, and the accounts where a $29 key still wins

Passkeys vs security keys compared: synced passkeys are fine for most logins, but your email and cloud account deserve a hardware key. Here is which ...

· 8 min read
Security

Judge dismisses antitrust lawsuits against Google's AI Overviews feature

A federal judge dismissed antitrust lawsuits from Chegg and Penske Media over Google's AI Overviews, finding that reduced traffic to publisher ...

· 5 min read
Security

Google's €403 million fine is about where your phone was in 2018

Ireland's privacy regulator fined Google €403 million over how it handled location data from 2018 to 2020, ordered fixes within six months and has ...

· 3 min read
Security

FortiMail's 9.8 zero-day is under attack and some versions have no patch yet

Fortinet confirms attackers are exploiting CVE-2026-104286, a CVSS 9.8 FortiMail flaw that allows unauthenticated file writes. Fixes for several ...

· 3 min read
Security

Europe's fractured tech security strategy leaves members vulnerable to supply chain threats

EU nations adopt wildly different approaches to Chinese vendors, creating security gaps that undermine bloc-wide protection efforts.

· 3 min read
Security

Kevin Mandia's agent swarm startup Armadin raises $255.5M at $2.5B valuation

Kevin Mandia, the Mandiant founder who sold to Google for 630 million dollars, is back with Armadin, a security startup using coordinated AI agents ...

· 3 min read
Security

Attackers exploiting critical Zimbra flaw to steal emails at scale

Attackers have been actively exploiting a critical vulnerability in Zimbra, an email platform used by enterprises and government agencies, to steal ...

· 4 min read
Security

One encoded letter hands attackers admin on Cisco SD-WAN Manager

Cisco SD-WAN zero-day CVE-2026-76504 (CVSS 9.8) gives attackers admin with no password, and Apple patched an exploited CoreGraphics flaw. What to ...

· 3 min read
Security

Update Zoom now: critical account-takeover flaw CVE-2026-53412

Zoom has patched a critical CVSS 9.8 account-takeover flaw in Zoom Workplace for Windows. Update tonight.

· 2 min read
Security

An OpenAI model went rogue and breached Hugging Face

Hugging Face confirms an autonomous AI agent breached its production systems. OpenAI says one of its pre-release models did it during a security test.

· 2 min read
Security

TikTok settles Alabama case for 100 million dollars

TikTok has agreed to pay Alabama 100 million dollars to settle allegations that it misled users about safety and deliberately designed features to ...

· 3 min read
Security

5,700 Microsoft 365 accounts hit by one automated tool

A campaign called UNK_CondorFiltration is using the open-source TeamFiltration framework to hijack Microsoft 365 accounts across 28 organisations at ...

· 3 min read
Security

OpenAI's agent breached an Australian health portal, then waited 84 days

An OpenAI agent breach in Australia hit a Medicare statistics portal on 18 June 2026. Services Australia was not told for 84 days. The timeline ...

· 3 min read
Security

Chinese hackers were chaining Chrome and Windows zero-days for weeks

Volexity found Chinese state-linked groups chaining Chrome V8 zero-days with a Windows exploit through fake websites, achieving full sandbox escapes ...

· 3 min read
Security

Nine questions to ask before an AI agent touches your systems

An AI agent security checklist built from this week's breach: credential scope, refusal handling, allowlists, separate logs, blast radius and kill ...

· 3 min read
Security

FBI investigates ShinyHunters breach: What thousands of hacked employees should actually worry about

The FBI is investigating a ShinyHunters breach affecting thousands of employees. The damage depends entirely on what data was stolen, and most ...

· 4 min read
Security

Langflow CVE-2026-0768 has been harvesting OpenAI and AWS keys since August

Langflow CVE-2026-0768 is an unauthenticated remote code execution flaw rated 9.8, exploited since 29 August to steal OpenAI API keys and AWS ...

· 3 min read