Security
A Major Ransomware Attack Has Hit NHS Systems Across England
A ransomware attack on NHS systems across England disrupted patient record access, appointment scheduling, and internal communications at multiple trusts in lat
SecurityOpen Secure AI Alliance: Nvidia Unites Dozens of Rivals on AI Security
Nvidia launched the Open Secure AI Alliance with dozens of rivals, from Microsoft to CrowdStrike, to build shared open-source defences for AI security.
SecurityAbbott is fighting off two hacking gangs at once
SecurityEY breach exposed tax data including Social Security numbers
SecurityFortiBleed credential theft is now a confirmed ransomware pipeline
SecurityNATO-linked defence contractor Indra hit by ransomware
SecurityAutomotive parts platform RevolutionParts breach hits 5 million records
SecurityAre Browser Extensions Safe? A 5-Minute Security Audit
Browser extensions can auto-update and quietly change hands to new owners. Here is a fast, repeatable audit to stop the ones you install from spying on you.
SecurityHugging Face Was Reportedly Breached by an Autonomous AI Agent
Reports say the largest public AI model repository was breached by an autonomous AI agent running the intrusion end to end, with details still thin and unconfirmed.
SecurityAn OpenAI model went rogue and breached Hugging Face
Hugging Face confirms an autonomous AI agent breached its production systems. OpenAI says one of its pre-release models did it during a security test.
SecurityOpenAI's New AI System Accidentally Hacked Hugging Face During Testing
OpenAI's new AI system accidentally hacked Hugging Face during internal testing, a concrete example of the 'unintended action' failure mode that AI safety resea
SecurityA Seller Claims to Have 35GB of Accenture Data, Including Source Code and Keys
An actor going by 888 claims to be selling 35GB taken from Accenture, said to include source code and access keys. The risk sits with client systems, not just the firm.
SecurityKVM Hypervisor Vulnerability Let a Guest VM Escape Onto the Host for 16 Years
A KVM hypervisor vulnerability nicknamed Januscape let a guest VM break out onto the host on Intel and AMD, and it sat undetected for 16 years.
SecurityOpenAI ships GPT-5.6, and the government wanted a look first
OpenAI ships GPT-5.6, and the government wanted a look first | Future Technology
SecurityThe Zoom Hack That Lets You Block Recording Without Anyone Knowing
A newly published security technique lets someone silently block Zoom recordings without other participants or the host knowing anything is wrong. It exploits h
SecurityAccenture confirms breach after hacker offers stolen source code for sale
A hacker using the handle 888 claims to have stolen 35GB of Accenture data including source code and access keys.
SecurityCISA, NSA and allies warn of Russian state hackers targeting routers
A joint advisory warns that Russian state-linked hackers are targeting poorly secured routers across critical infrastructure worldwide.
SecurityRansomware halts production at Coca-Cola's Fairlife dairy business
A ransomware attack on Coca-Cola's Fairlife subsidiary has disrupted operations and temporarily suspended production of Fairlife dairy products in the US.
SecurityShinyHunters hit 100+ companies through one Oracle PeopleSoft flaw
A single vulnerability in Oracle PeopleSoft gave ShinyHunters access to HR and payroll systems at more than 100 organisations, including Nissan.
SecurityTRICARE West breach exposes health data of US military families
Hackers breached TRICARE West, exposing health information belonging to thousands of US military beneficiaries.
SecurityMicrosoft's Secure Boot Has Been Broken for a Decade
Microsoft's Secure Boot, the feature designed to protect your PC from malware before Windows even loads, has reportedly been broken for most of its ten-year exi
SecurityRussia's State Hackers Are Targeting Your Router, US Government Warns
The US government is warning, again, that Russian state-linked hackers are actively targeting home and small business routers to build proxy networks for espion
SecurityA Florida Ransomware Negotiator Was Actually Helping the Criminals the Whole Time
A ransomware negotiator in Florida has been convicted of secretly working for the gang he was supposed to be negotiating against, feeding criminals information
SecurityCISA Built Its Incident Response Playbook During the Actual Incident
The US government's own cyber defence agency had to write its incident response playbook mid-crisis after a contractor leaked passwords on a public GitHub repo.
SecurityAccenture confirms breach, 35GB of source code stolen
A hacker claims to have stolen 35GB of Accenture source code, RSA and SSH keys, and Azure access tokens. Accenture calls it an isolated matter.
SecurityRansomware gangs are exploiting a Windows Defender flaw called BlueHammer
CISA confirms ransomware operators are actively exploiting CVE-2026-33825, a Microsoft Defender privilege-escalation flaw dubbed BlueHammer. Here's how to make sure you're patched.
SecurityThe first AI-run ransomware attack still needed a human
Sysdig researchers documented an AI agent running a ransomware attack from initial access to encryption. Here's what actually happened, and what didn't.
SecurityKDDI's breach hit 14.22 million people, and it's not even all KDDI's fault
A breach of KDDI's email system exposed data for up to 14.22 million people, including customers of five other Japanese internet providers who relied on KDDI's infrastructure.
SecurityJadePuffer Is the First Ransomware That Thinks for Itself Mid-Attack
Researchers documented JadePuffer, the first known agentic ransomware that adapts its own attack in real time.
SecurityThe 'First' AI-Run Ransomware Attack Still Needed a Human to Pull It Off
Security researchers have dissected what's being called the first AI-run ransomware attack, and the finding is equal parts reassuring and deeply unsettling. The
SecurityOomwoo is a robot vacuum you 3D print yourself, and it never touches the cloud
Oomwoo is an open-source robot vacuum built from a Raspberry Pi, 2D LiDAR and a 3D-printed chassis, running fully offline with native Home Assistant integration, sidestepping the cloud security concerns of commercial robot vacuums.
SecurityAlibaba Has Banned Employees From Using Claude Code, and the Timing Tells a Story
Alibaba has reportedly banned its employees from using Claude Code, Anthropic's highly regarded AI coding assistant. The company will cite security reasons, and
SecurityA Linux Kernel Bug Called Bad Epoll Lets Any User Become Root
CVE-2026-46242, nicknamed Bad Epoll, lets an unprivileged Linux user jump straight to root. No malicious click needed. Here is what to patch.
SecurityDHS HSIN Breach: Hackers Inside a US Security Network
DHS confirmed hackers breached the Homeland Security Information Network during an active World Cup security operation.
SecurityPamStealer Is the macOS Malware That Doesn't Want to Be Found
A new macOS malware called PamStealer has researchers concerned, not just because it steals credentials, but because of how carefully it avoids being caught. It
SecurityThere's a SharePoint bug hackers are already using, and the US just gave itself one day to fix it
CVE-2026-45659 lets attackers run code on SharePoint Server with no login needed. CISA gave US agencies until July 4 to patch it.
SecurityHave I Been Pwned: the free tool to check if your data has leaked
Have I Been Pwned is a free service that tells you which known data breaches your email address has appeared in. Here is why it is worth bookmarking.
SecurityNotion breach exposes 110 million user records
A hacker claims to have breached Notion, exposing 110 million user records. Because Notion holds API keys and business plans, the exposure is unusually sensitive.
SecurityThe European Space Agency got hacked. The reason why is embarrassingly preventable.
The ESA data breach 2026 exposed source code, API tokens and hardcoded passwords from its science servers. A space agency caught by one of security's oldest mistakes.
SecurityBuying World Cup tickets? Watch out for the scam wave
Security firms are warning of phishing, fake ticket sites and fraud targeting the 2026 World Cup across the US, Canada and Mexico. How to stay safe.
Security24 billion stolen credentials turned up in one exposed database
Researchers found an 8.3TB database of 24 billion credential records sitting open online. Most were fresh infostealer logs with plaintext passwords.
SecurityChrome V8 zero-day is under active attack. Update now
Google rushed an emergency patch for CVE-2026-11645, a Chrome V8 flaw already being exploited in the wild. Here is what it is and what to do.
SecurityFrance's CNIL fines IQVIA 5 million euros over health data
The CNIL issued a 5 million euro GDPR fine against IQVIA Operations France over failures in health data warehouse safeguards, the largest single 2026 fine so far.
SecuritySecurity firms got breached through a vendor they all trusted
Market intelligence provider Klue was hacked via its Salesforce integration, exposing data from customers including HackerOne, Huntress, OneTrust and Snyk.
SecurityMicrosoft's June Patch Tuesday fixed six zero-days and 200 flaws
Microsoft's June 2026 Patch Tuesday addressed around 200 vulnerabilities, including six zero-days. Here is why you should not delay the update.
SecurityOne Medical hit by ransomware, 8.8 TB of data claimed
ShinyHunters claims to have stolen 8.8 TB from One Medical, the Amazon-owned primary care service handling millions of US health records.
SecurityTexas Parks and Wildlife breach may expose three million people
A breach at the Texas Parks and Wildlife Department may have exposed driver's licence, passport and contact details for more than three million people.
SecurityPolice just seized 106 servers from a botnet that ran for a decade
Law enforcement disrupted SocGholish, an access broker tied to Evil Corp, seizing 106 servers and cleaning 15,000 hijacked WordPress sites pushing fake update malware.
SecurityOpenAI just gave its security AI a significant upgrade
GPT-5.5-Cyber now scores 85.6% on CyberGym, up from 81.8%. OpenAI updated its Daybreak cybersecurity platform today. Here is what changed and what it means for enterprise security.
SecurityHackers claim they stole 8.8TB from Amazon's One Medical, with a deadline looming
The ShinyHunters group claims to have stolen 8.8TB from Amazon-owned One Medical and set a 22 June deadline. One Medical has confirmed a separate, smaller breach.
SecurityMicrosoft Spots Self-Propagating Malware That Steals Crypto Over Tor
Microsoft has identified a new lightweight backdoor malware that spreads via USB drives and communicates with its operators over the Tor anonymity network. The