:

[SECURITY]

STORIES FROM THE SECURITY DESK ■ LAST 14 DAYS ■ RSS

SECURITY

100 STORIES

Google is rolling out Encrypted Client Hello (ECH) support in Android 17 to prevent network monitoring of user browsing activity. The privacy feature strengthens connection security across cellular and home networks.

4H AGOIndustry Desk

A new survey shows more Americans oppose police use of license plate readers than support them. The finding reflects growing concerns about surveillance overreach.

4H AGOIndustry Desk

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a "major incident" involving a compromised system following claims by the Qilin ransomware group.

11H AGOAI Desk

Claude, Codex, and Hermes generated 227 install commands referencing code with no identifiable owners, according to analysis of corporate documentation. The discovery raises security concerns about AI-generated dependencies.

11H AGOAI Desk

Manchester Airports Group disclosed a breach affecting Manchester, Stansted, and East Midlands airports. Hackers accessed data from approximately 8.7 million customers.

18H AGOAI Desk

A lawsuit alleges that Elon Musk's xAI trained its Grok language models using child sexual abuse material, including both real and AI-generated imagery.

18H AGOAI Desk

The ShinyHunters extortion group has published sensitive data from nearly 13 million Carhartt customer accounts stolen earlier this month, according to data breach notification service Have I Been Pwned.

YESTERDAYSecurity Desk

A Russian-speaking ransomware gang called Aur0ra exploited SpaceX's Cursor AI coding assistant to breach at least seven companies between mid-April and late May, according to security firm Gambit Security.

YESTERDAYAI Desk

Americans are systematically targeting and disabling Flock Safety cameras across the country in a decentralized protest movement. The surveillance devices face everything from vandalism to theft as public opposition intensifies.

YESTERDAYIndustry Desk

The US Justice Department has dismantled online infrastructure used by Chinese state-sponsored hackers targeting NASA, the Federal Reserve, and the Senate. The action represents a coordinated effort to disrupt cyber operations against American government agencies and critical infrastructure.

YESTERDAYSecurity Desk

The U.S. Cybersecurity and Infrastructure Security Agency has issued a mandate requiring all federal agencies to patch an actively exploited remote code execution vulnerability in Citrix NetScaler appliances by Saturday.

AUG 27Security Desk

A new Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service attacks and root-level privilege escalation.

AUG 27Industry Desk

The FBI has dismantled proxy tools used by Chinese hackers in a widespread campaign against NASA, the Federal Reserve, the US Senate, and the Justice Department. The operation marks a significant coordinated response to months of intrusions into critical US infrastructure.

AUG 26Security Desk

Snowflake is phasing out password authentication for legacy service accounts, requiring organizations to adopt passwordless methods. The real challenge: identifying which accounts exist, who manages them, and what access they hold.

AUG 26Industry Desk

Medical technology company Boston Scientific disclosed a cyberattack that disrupted IT systems and operations worldwide. The company is working to restore normal services.

AUG 26Security Desk

The FBI has disrupted infrastructure used by Chinese state-sponsored actors to conduct cyber espionage operations. The takedown targeted a technical quartermaster operation that provided reconnaissance, proxy management, and operational routing capabilities.

AUG 26Security Desk

The Cybersecurity and Infrastructure Security Agency confirmed that hackers targeted over 100 U.S. water systems in July. The attacks are suspected to be backed by Iran.

AUG 26Security Desk

PeopleFinders has launched Stud or Dud, a new website that allows users to run background checks on potential romantic partners. The service uses the same public data as PeopleFinders.com.

AUG 26Industry Desk

Pro-Kremlin channels are distributing AI-generated videos of Ukrainian lawmakers calling for peace talks. The fabricated clips accumulated 130,000 views in two weeks, undermining public trust regardless of fact-checking efforts.

AUG 26AI Desk

Amazon-owned Ring is deploying TAKE encryption across all cameras by default, a method designed to limit police requests for video footage while maintaining AI features like person and package detection.

AUG 26Security Desk

Find My is a critical iPhone security feature that Apple recommends keeping enabled at all times. Disabling it significantly reduces your ability to locate and recover a lost or stolen device.

AUG 26Industry Desk

Hackers are actively exploiting a critical vulnerability in Gitea, a self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The flaw enables code injection attacks against affected systems.

AUG 26Security Desk

Hospital operator Nutex Health disclosed that unauthorized attackers stole data from company servers in a cyberattack. The healthcare provider is currently investigating the incident.

AUG 26Security Desk

The Coalition for Content Provenance and Authenticity's camera authentication system is encountering fundamental technical obstacles that prevent it from functioning as designed in practical deployments.

AUG 26Industry Desk

Illinois county prosecutors secretly provided personal information about criminal defendants to federal immigration agents without warrants, public disclosure, or legislative approval.

AUG 26Industry Desk

Law enforcement from 22 countries arrested 58 individuals and identified 263 suspects in a coordinated crackdown on cybercrime networks run by African crime groups.

AUG 26Security Desk

The Los Angeles County Museum of Art disclosed a data breach from last year that compromised customer and employee information, including social security numbers and medical records.

AUG 25Security Desk

A phishing-as-a-service platform called AnonyMousKIT uses voice AI agents to extract passcodes from stolen Apple devices and bypass Activation Lock security features.

AUG 25AI Desk

Following recent hacks of AI models, companies are debating whether to move cybersecurity testing online. Proponents argue that internet-connected tests provide more accurate threat assessments.

AUG 25AI Desk

France's tax administration fell victim to a significant security breach, exposing vulnerabilities in one of the country's most critical government systems. Details remain limited as authorities investigate the incident.

AUG 25Security Desk

A large distributed denial-of-service attack has disrupted Norway's shared government digital infrastructure since Monday, affecting public sector services accessible to citizens.

AUG 25Industry Desk

Security researchers have released a new bootloader that exploits a privilege escalation vulnerability in the original Meta Quest headset, granting users full control and independence from Meta's servers and applications.

AUG 25Industry Desk

WhatsApp is upgrading its two-factor authentication system, replacing six-digit codes with password-based verification. The change aims to provide users with stronger security protection.

AUG 25Industry Desk

WhatsApp is rolling out enhanced account security features including support for multiple passkeys and upgraded two-step verification. The changes replace the previous six-digit PIN system with stronger alphanumeric passwords.

AUG 25Industry Desk

Threat actors have compromised over 270 Zimbra Collaboration Suite instances through remote code execution attacks exploiting a high-severity vulnerability. The ongoing campaign targets organizations worldwide.

AUG 25Security Desk

Top Chinese military strategists have published analyses detailing artificial intelligence's role in accelerating command decision-making. The writings offer insight into Beijing's military modernization efforts.

AUG 25AI Desk

Chinese state-backed hacking groups have more than doubled their cyberattacks since adopting AI models to generate exploit code and scan networks, according to Taiwanese cybersecurity firm TeamT5.

AUG 25AI Desk

AliExpress deployed an outdated browser fingerprinting technique using ultrasonic frequencies to identify and track users. Security researchers discovered the e-commerce platform embedding inaudible sounds in web pages to create unique device signatures.

AUG 25Industry Desk

An unpatched vulnerability in Calix GS7 XGS residential routers allows remote attackers to bypass network protections and expose devices on private networks to the internet. The flaw affects routers deployed by multiple U.S. broadband providers.

AUG 24Security Desk

Cody Wilson, creator of the first 3D-printed gun, says he's developed software to bypass government-mandated blocks on 3D printers making firearms. The claim marks the start of an escalating regulatory battle over ghost guns.

AUG 24Industry Desk

Hackers are exploiting critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The flaws allow attackers to forge SAML responses and gain administrator access.

AUG 24Security Desk

Microsoft's Paint and Photos applications automatically embed invisible GUIDs into locally generated images, according to reverse engineering analysis. The watermarks persist even when files are created entirely offline.

AUG 24AI Desk

Chinese threat actors are integrating DeepSeek and other open-source AI models into cyberattacks, researchers report. The shift demonstrates how readily available AI tools can amplify hacking capabilities against international targets.

AUG 24Security Desk

Cybersecurity firm ReliaQuest confirmed it repelled a data-theft attack after hackers impersonated a security team member to target an employee. The incident follows the ShinyHunters breach.

AUG 24AI Desk

A government-backed South Korean startup platform suffered a data breach after developers exposed an encryption key through an API. The incident highlights critical security management lapses in protecting sensitive data.

AUG 24AI Desk

ToxicPanda Android malware has evolved to target 349 applications and support 167 remote commands. The malware exploits VPN permissions to block Google Play access on infected devices.

AUG 24Security Desk

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that U.S. government agencies patch an actively exploited vulnerability in Zimbra Collaboration Suite within three days.

AUG 24Security Desk

The UAE is building a homegrown AI security industry to defend against escalating cyberattacks on its banks, aviation, and energy sectors since tensions with Iran intensified.

AUG 24AI Desk

Visa is enabling expired payment cards to continue processing contactless transactions through a new feature. The move allows cardholders to keep using their old cards for tap-to-pay purchases even after expiration.

AUG 23Industry Desk

A Texas-based student discovered and reported an unauthorized AI system being used for cyberattacks. The disclosure prompted immediate investigation and security responses from affected organizations.

AUG 23AI Desk

A supply-chain attack is exploiting legitimate device-update apps to infect Android-based car head units with malware. The compromised devices are being enlisted into proxy botnets or used for ad fraud schemes.

AUG 22Security Desk

Apollo Global Management disclosed a data breach in July resulting from a social engineering attack that exposed personal information. The incident joins a recent wave of cyberattacks targeting major hedge funds.

AUG 22Security Desk

Researchers at the UK AI Security Institute have exposed critical weaknesses in how language models are evaluated for safety, showing that current benchmarks don't measure consistent traits and can be artificially inflated.

AUG 22AI Desk

Felony Bench, a new platform, aggregates criminal case information and court records in a searchable database. The launch has generated significant interest in tech communities discussing digital access to legal proceedings.

AUG 22Industry Desk

The US Department of Energy is examining whether Chinese-made lidar sensors pose a security threat if adopted widely in American vehicles. The investigation addresses concerns about potential vulnerabilities in autonomous vehicle technology.

AUG 21Security Desk

A US citizen faces felony charges after deleting data from their phone during a border inspection. The case raises questions about digital privacy rights and government authority at ports of entry.

AUG 21Industry Desk

A previously unknown malware family called SynkLoader is being distributed through Microsoft Teams phishing campaigns. The malware steals credentials by displaying a fake lock screen.

AUG 21AI Desk

A security researcher discovered they had inadvertently captured phone call logs to military installations through a misconfigured system. The incident highlights infrastructure vulnerabilities in telecommunications routing.

AUG 21Industry Desk

Idaho National Laboratory is conducting a security review of Chinese lidar technology, with funding from companies in the electric and autonomous vehicle sectors. The investigation aims to identify potential vulnerabilities in the sensor systems.

AUG 21Security Desk

Over 9,300 Amazon Web Services access keys have been publicly exposed since August 2022, with the majority still active and granting full account control. Security researchers warn that attackers could exploit these credentials to compromise corporate infrastructure.

AUG 21Industry Desk

Senator Ron Wyden has requested a comprehensive review of how federal agencies deploy hacking tools and spyware against Americans. The inquiry targets the FBI, DEA, ICE's Homeland Security Investigations, and the Secret Service.

AUG 21Security Desk

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies immediately patch two actively exploited vulnerabilities in TrueConf Server, a self-hosted communications platform.

AUG 21Security Desk

AI-driven phishing attacks are increasingly bypassing traditional email filters with personalized, convincing messages. Managed service providers must monitor identity, email, and endpoint activity to detect threats that slip through inbox defenses.

AUG 21AI Desk

Comcast introduced Xfinity Shield this week, a platform that allows customers to opt into turning their routers into motion sensors. The announcement sparked immediate privacy concerns among users.

AUG 21Industry Desk

Toronto's Hospital for Sick Children disclosed a cybersecurity incident that compromised personal information belonging to current and former employees and job applicants. The breach stemmed from a vulnerability in third-party software.

AUG 21Security Desk

A billing bug in Codex on AWS Bedrock is charging users approximately 10 times the expected rate. The issue was reported on GitHub and has generated significant discussion among developers.

AUG 21Industry Desk

A federal judge has overturned part of the conviction of former Google software engineer Linwei Ding, who was earlier found guilty of stealing AI trade secrets for two Chinese companies.

AUG 21AI Desk

Security researchers demonstrate how seemingly innocent interview questions can be weaponized to extract sensitive system information and compromise infrastructure. The technique exploits social engineering during technical assessments.

AUG 20Industry Desk

A threat actor impersonated a major cryptocurrency news outlet to target cybersecurity professionals. The attackers used Google Docs to distribute malware.

AUG 20Security Desk

Security researchers warn that Chinese hackers have embedded malicious code in critical civilian infrastructure systems. A recent war game simulation demonstrated vulnerabilities in US defenses against such attacks.

AUG 20Industry Desk

A compromised Rust crate named Arrayref executed malicious code at build time, exploiting the package's procedural macro functionality. The discovery highlights supply chain vulnerabilities in the Rust ecosystem.

AUG 20Dev Desk

Researchers have identified a large-scale campaign targeting Dahua IP cameras, with attackers compromising over 14,500 devices across a 35-day period. The attack, dubbed CameraSwarm, primarily affected devices in Ukraine and Russia.

AUG 20AI Desk

A critical vulnerability in Elementor Pro allows attackers to upload executable files and execute arbitrary code on WordPress servers. The flaw affects thousands of sites using the popular page builder plugin.

AUG 20Industry Desk

Alation, a major data search and AI platform, disclosed unauthorized access to its systems following a breach discovered Tuesday. The company is actively investigating the incident.

AUG 20AI Desk

Researchers discovered that xAI's Grok language model can be tricked into exfiltrating user data when malicious instructions are hidden through encryption. The vulnerability, termed Cryptographic Context Injection, represents a new method to bypass the AI system's safety guardrails.

AUG 20Industry Desk

US officials report that hackers are targeting internet-connected Siemens controllers used in water facilities across the country, with AI tools enhancing their attack capabilities.

AUG 20AI Desk

AliExpress deploys silent WebAudio fingerprinting on its website that interferes with Bluetooth multipoint functionality on user devices. The script runs without explicit user consent.

AUG 20Industry Desk

Citrix has issued an urgent warning for administrators to patch two vulnerabilities affecting NetScaler Gateway and NetScaler ADC appliances. The flaws pose immediate security risks to remote access and networking infrastructure.

AUG 20Industry Desk

The Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies that threat actors are actively exploiting a critical vulnerability in MLflow, an open-source AI engineering platform.

AUG 20Security Desk

A new Android malware called Manic is targeting users across multiple European countries and uses a novel data exfiltration method through nearby infected devices.

AUG 20Security Desk

Security defenses effectively block known attack methods but often fail against behavioral variants that achieve the same objectives through different techniques, according to Picus Security's Blue Report 2026.

AUG 20Industry Desk

A suspected ransomware affiliate is impersonating a recovery service called "Ransom Busters" to extract payments from victims. The scammer contacts targets before attacks go public, falsely claiming to offer decryption keys and data deletion.

AUG 19Security Desk

Japanese cloud and data center provider Sakura Internet disclosed a security breach affecting up to 1.36 million customer accounts. Hackers accessed the company's sales management system containing contract and membership data.

AUG 19Security Desk

The NSA, CISA, and FBI warn that attackers are using AI to build exploit scripts for Siemens S7 controllers, significantly lowering the barriers to compromising critical industrial infrastructure.

AUG 19AI Desk

U.S. cybersecurity agencies have issued a warning about threat actors deploying AI-generated scripts to exploit Siemens S7 Series programmable logic controllers in critical infrastructure systems across the country.

AUG 19AI Desk

T-Mobile successfully expelled Chinese-backed hackers from its network by identifying and severing their access point early in the intrusion. The swift action prevented a large-scale breach of the carrier's systems.

AUG 19Security Desk

Flock is testing new artificial intelligence that can track and identify individuals based on driving patterns rather than license plates alone. The technology represents a significant expansion of vehicle surveillance capabilities.

AUG 19AI Desk

A casual domain registration escalated into international tension when a developer's lighthearted purchase became entangled in balloon tracking infrastructure and cross-border disputes.

AUG 19AI Desk

Roblox has agreed to implement privacy changes after Australia's eSafety commissioner discovered adults could contact children without parental consent on the gaming platform. The regulator said verifiable safety measures are critical to the service's viability.

AUG 19Security Desk

Security firm Huntress detected a 155-fold increase in password spraying attacks during the first half of 2026, with one campaign generating over 81 million login attempts in just two weeks.

AUG 19Security Desk

Healthcare software company CareCloud confirmed a cyberattack compromised medical records for 3.7 million patients, marking one of the largest healthcare data breaches in the U.S. this year.

AUG 19Security Desk

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has alerted organizations to a critical remote code execution vulnerability in Windows Internet Key Exchange (IKE) Service Extensions that hackers are actively exploiting.

AUG 19Security Desk

ClarityCheck, a people-search tool marketing itself as private and secure, left an unprotected database containing over 9 million image files accessible to the public.

AUG 19Industry Desk

The FBI reported that the Medusa ransomware gang has breached over 500 critical infrastructure organizations in the United States since June 2021. The campaign represents a significant threat to national security infrastructure.

AUG 19Security Desk

The Clop ransomware gang created a specialized Java web shell targeting PTC Windchill and FlexPLM servers. The malware includes built-in capabilities to decrypt credentials, enumerate repositories, and exfiltrate files.

AUG 18Industry Desk

France's tax authority plans to use artificial intelligence tools to identify vulnerabilities in its systems following a cyberattack that compromised personal data of hundreds of thousands of taxpayers.

AUG 18AI Desk

Passkeys offer stronger protection than passwords, even when paired with password managers. The shift addresses fundamental vulnerabilities in traditional authentication.

AUG 18Industry Desk

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware groups are actively exploiting a high-severity Windows Task Host vulnerability. The flaw was previously flagged as under active exploitation in April.

AUG 18Security Desk

Microsoft has begun removing the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11, citing widespread abuse by cybercriminals. The tool is being eliminated from Windows 11 versions 24H2 and 25H2.

AUG 18Security Desk

Israel has established a fabricated think tank apparently designed to influence AI chatbot outputs and shape how these systems respond to queries about Israeli policy. The scheme highlights vulnerabilities in how large language models source and validate information.

AUG 18AI Desk