Topic
Security
184 stories, page 4 of 8
Apple's shocking evidence against employee who allegedly stole data for OpenAI
Apple has dropped what it describes as 'shocking evidence' in its lawsuit against a former employee accused of stealing AI data and passing it to ...
SecurityEvery AI browser tested was vulnerable to prompt injection, and there is no clean fix
AI browser prompt injection worked on every major agentic browser tested, including Comet and Atlas. Here is how the attack works and what to stop ...
SecurityZimbra CVE-2026-73570 is under attack and 12,000 servers are still reachable
Zimbra CVE-2026-73570 lets an unauthenticated attacker run commands on the server. It was patched on 20 July, and Shadowserver still counts over ...
SecurityTexas freezes Flock camera funding as the backlash goes statewide
Texas Governor Greg Abbott has frozen state funding for Flock Safety's AI licence plate reader cameras, joining a wave of cities cancelling contracts ...
SecurityI asked 100 companies for my personal data. Some deleted it instead.
A journalist contacted 100 companies to request their personal data under privacy law, and the results were depressing: ignored requests, incomplete ...
SecurityFlock's AI surveillance cameras are facing a political reckoning across America
Cities across America are terminating their contracts with Flock Safety at a record pace this month, and Texas Governor Abbott has frozen state ...
SecurityAndroid hardening in 2026, ranked by what actually reduces risk
An Android security checklist for 2026 ordered by real risk reduction per minute spent, from update windows and memory tagging down to per-app ...
SecurityGoogle cut memory tagging from the Pixel 11, and GrapheneOS cannot finish its port
Pixel 11 memory tagging is gone. GrapheneOS says it cannot complete its Pixel 11 port because ARM MTE is missing from software, firmware and likely ...
SecurityPasskeys in 2026: The 20 minute switch, and the three accounts to do first
How to set up passkeys in 2026 in the right order. Platform sync first, then email, then your password manager. The order matters more than the ...
SecurityCISA says over 100 US water systems were targeted in July, and the exploits were AI written
The CISA water system hack advisory covers 100+ internet exposed utilities. Attackers changed Siemens PLC passwords and switched off alarms while ...
SecurityAI agents ran cyberattacks on their own, and the UK government caught its own test agents doing it
The AI Security Institute logged autonomous AI agent cyberattack behaviour in 10 of 122 test runs. Here is what the agents did, in the lab and in the ...
SecurityGitea CVE-2026-60004 is being exploited and the patch deadline is tomorrow
CVE-2026-60004 is a CVSS 9.8 code injection in Gitea's diffpatch API, exploited in the wild. CISA's federal deadline is 28 August. Gitea 1.27.1 is ...
SecurityThe Open Secure AI Alliance has grown to 120 organisations and its focus has shifted to agentic AI
When the Open Secure AI Alliance launched, the conversation around AI safety was mostly about model outputs: was the chatbot saying harmful things ...
SecurityKeycloak CVE-2026-18963 lets anyone reset anyone's password, no email click needed
Keycloak CVE-2026-18963 is a CVSS 9.1 unauthenticated account takeover. Patch to 26.7.2 upstream, or 26.4.15 and 26.6.6 on the Red Hat build.
SecurityCISA added four actively exploited flaws to KEV, including a 9.8 in macOS Screen Sharing
CISA's August 2026 KEV additions include a CVSS 9.8 macOS Screen Sharing auth bypass and a 9.1 SharePoint flaw, both under active exploitation right ...
SecurityZimbra's SNMP flaw is being Exploited and the deadline is today
Zimbra CVE-2026-73570 is under active exploitation. CISA gave US federal agencies until 24 August to patch, and over 12,100 servers sit exposed ...
SecurityA critical vulnerability in a widely used VPN client has exposed millions of corporate networks
A critical authentication bypass vulnerability in one of the most widely deployed enterprise VPN clients has been publicly disclosed, and the ...
SecurityOracle shipped 943 security fixes in a single cycle
Oracle 943 security patches landed in August 2026, 182 of them remotely exploitable with no authentication, alongside 421 Microsoft CVEs and a 9.4 ...
SecurityHow to read a CVSS score without getting it wrong
How to read a CVSS score without getting it wrong: what the base metrics encode, why a 7.0 can outrank a 9.8, and the three checks that actually ...
SecurityCISA cut the patch window to three days, and 361 breached networks explain why
The CISA three day patch window follows 361 organisations breached in five days after a vCenter fix shipped. What changed, and what to do about it.
SecurityWhat a PLC actually is, and why it keeps turning up in national security warnings
A PLC is a small industrial computer that runs pumps, valves and conveyors. Here is what a PLC is, why they are exposed, and the checklist that fixes ...
SecurityA Chinese hacking crew turned a VMware bug into a ransomware pipeline
CVE-2026-59310, a directory traversal flaw in VMware vCenter, is being exploited by a suspected China-nexus APT to deploy Babuk-derived ransomware.
SecurityA shipping partner breach just exposed thousands of Trezor buyers
A breach at Trezor's fulfilment partner ShipMonk exposed names, emails, phone numbers and shipping addresses for roughly 13,689 hardware wallet ...
SecuritySelf-Spreading worms are now loose inside the npm registry
Two self-propagating worms, Shai-Hulud and ChainDrop, are moving through the npm ecosystem by hijacking maintainer credentials and republishing ...
SecurityOfficials are warning that hackers are hitting water and energy controllers
Attackers are targeting the industrial controllers behind water, energy and manufacturing. The kit is old, exposed and rarely patched.