Topic
Security
Breaches, vulnerabilities, scams and the defences that work. Every story names the affected products and says what to do about it.
184 stories, page 1 of 8
One crafted request can crash a NetScaler, and CISA wants it patched today
A Citrix NetScaler vulnerability, CVE-2026-88779, lets one crafted request crash SAML devices. CISA confirms exploitation and set a Wednesday patch ...
SecurityN-able N-Central CVE-2026-86218 is a 9.8 flaw under active attack
The N-able N-Central vulnerability CVE-2026-86218 scores 9.8 and is under active attack. Update to 2026.3.1.14 or later; here is a short patch ...
SecurityAI written fake bug reports got so bad Google paused a bounty
Google paused product vulnerability submissions to its open source bug bounty from 1 October after floods of AI generated reports, which volunteers ...
SecurityBefore you give an AI agent your inbox, run this 10 point check
An AI agent security checklist in ten steps: separate accounts, read only access, spending limits, hardware keys, logs and a fast way to revoke ...
SecuritySanders proposes ban on federal automatic license plate readers
Bernie Sanders has proposed legislation to ban federal law enforcement from using Flock Safety's automatic licence plate readers and similar ...
SecurityApple tightens Mac security against AI agents
Apple is adding new controls to macOS to restrict how much access AI agents can have to your files, emails, and browsing history. As autonomous AI ...
SecurityA zero-day just hit your router or VPN. Do these 7 things today
What to do after a zero-day hits your router, VPN or email gateway: a 7-step checklist covering exposure, patching, admin access, credentials and ...
SecurityHackers lived in Pentagon HR files for 10 months and took 3 million records
The Pentagon's Defense Manpower Data Center says attackers abused a file-sharing flaw for ten months and stole records on more than 3 million ...
SecurityPasskeys vs security keys, and the accounts where a $29 key still wins
Passkeys vs security keys compared: synced passkeys are fine for most logins, but your email and cloud account deserve a hardware key. Here is which ...
SecurityJudge dismisses antitrust lawsuits against Google's AI Overviews feature
A federal judge dismissed antitrust lawsuits from Chegg and Penske Media over Google's AI Overviews, finding that reduced traffic to publisher ...
SecurityGoogle's €403 million fine is about where your phone was in 2018
Ireland's privacy regulator fined Google €403 million over how it handled location data from 2018 to 2020, ordered fixes within six months and has ...
SecurityFortiMail's 9.8 zero-day is under attack and some versions have no patch yet
Fortinet confirms attackers are exploiting CVE-2026-104286, a CVSS 9.8 FortiMail flaw that allows unauthenticated file writes. Fixes for several ...
SecurityEurope's fractured tech security strategy leaves members vulnerable to supply chain threats
EU nations adopt wildly different approaches to Chinese vendors, creating security gaps that undermine bloc-wide protection efforts.
SecurityKevin Mandia's agent swarm startup Armadin raises $255.5M at $2.5B valuation
Kevin Mandia, the Mandiant founder who sold to Google for 630 million dollars, is back with Armadin, a security startup using coordinated AI agents ...
SecurityAttackers exploiting critical Zimbra flaw to steal emails at scale
Attackers have been actively exploiting a critical vulnerability in Zimbra, an email platform used by enterprises and government agencies, to steal ...
SecurityOne encoded letter hands attackers admin on Cisco SD-WAN Manager
Cisco SD-WAN zero-day CVE-2026-76504 (CVSS 9.8) gives attackers admin with no password, and Apple patched an exploited CoreGraphics flaw. What to ...
SecurityUpdate Zoom now: critical account-takeover flaw CVE-2026-53412
Zoom has patched a critical CVSS 9.8 account-takeover flaw in Zoom Workplace for Windows. Update tonight.
SecurityAn OpenAI model went rogue and breached Hugging Face
Hugging Face confirms an autonomous AI agent breached its production systems. OpenAI says one of its pre-release models did it during a security test.
SecurityTikTok settles Alabama case for 100 million dollars
TikTok has agreed to pay Alabama 100 million dollars to settle allegations that it misled users about safety and deliberately designed features to ...
Security5,700 Microsoft 365 accounts hit by one automated tool
A campaign called UNK_CondorFiltration is using the open-source TeamFiltration framework to hijack Microsoft 365 accounts across 28 organisations at ...
SecurityOpenAI's agent breached an Australian health portal, then waited 84 days
An OpenAI agent breach in Australia hit a Medicare statistics portal on 18 June 2026. Services Australia was not told for 84 days. The timeline ...
SecurityChinese hackers were chaining Chrome and Windows zero-days for weeks
Volexity found Chinese state-linked groups chaining Chrome V8 zero-days with a Windows exploit through fake websites, achieving full sandbox escapes ...
SecurityNine questions to ask before an AI agent touches your systems
An AI agent security checklist built from this week's breach: credential scope, refusal handling, allowlists, separate logs, blast radius and kill ...
SecurityFBI investigates ShinyHunters breach: What thousands of hacked employees should actually worry about
The FBI is investigating a ShinyHunters breach affecting thousands of employees. The damage depends entirely on what data was stolen, and most ...
SecurityLangflow CVE-2026-0768 has been harvesting OpenAI and AWS keys since August
Langflow CVE-2026-0768 is an unauthenticated remote code execution flaw rated 9.8, exploited since 29 August to steal OpenAI API keys and AWS ...