Items tagged with security

Microsoft has discovered a Russian malware campaign called CaptiveCrunch, which is designed to compromise users of public Wi-Fi with falsified prompts at the captive sign-in screen. This includes phishing pages that steal logins or even falsified Windows or Android system update/download... Read more...
Cybersecurity researchers at Palo Alto Networks' Unit 42 have uncovered three novel post-compromise attack vectors that allow local malware on Windows PCs to quietly hijack Google-synced passkeys, bypassing biometric checks and PIN... Read more...
Generative AI has drastically lowered the bar for finding software vulnerabilities, but it has simultaneously unleashed a flood of machine-generated noise that is overloading security teams and breaking bug bounty programs.  According... Read more...
Google has begun piloting a twice-weekly update cadence for its massively popular Chrome web browser, a decision it made in the wake of fast-moving, AI-powered attacks. And for major Chrome milestones, the company is aiming to deliver new... Read more...
Securing the tech supply chain has become one of Washington's biggest priorities, and the latest move takes direct aim at the machines meant to power the next industrial era. The Federal Communications Commission has banned the import and... Read more...
Microsoft wants to fight AI-powered cyberattacks with AI defenders of its own. The company has unveiled Project Perception, a new agentic security system designed to hunt down weaknesses, investigate threats, and strengthen defenses at... Read more...
A cyberattack on Georgia-based medical billing provider Medical Computer Business Services (MCBS) has exposed sensitive personal and health records of over 1.2 million individuals. MCBS, an Augusta-headquartered company, which provides... Read more...
A new remote access trojan (RAT) has been discovered by the cybersecurity research team at Cisco Talos, and experts are sounding the alarm since it enables the installation of ransomware on the victim's system. The attack is dubbed msaRAT... Read more...
Another new vulnerability for Microsoft SharePoint, tracked as CVE-2026-50522, is now being actively exploited in the wild, Microsoft warns. Security team watchTowr found evidence of exploits in use, and noted that attacks started the same... Read more...
The CERT Coordination Center warns that Wi-Fi routers built by Tenda may have a hidden, authentication backdoor in firmware. Researchers from CERT, the Computer Emergency Response Team for the Software Engineering Institute at Carnegie... Read more...
Microsoft's drive to improve Windows security with AI-driven vulnerability discovery has led to another record-breaking Patch Tuesday. This time around, there's a whopping 570 security fixes for Windows 11, which is more than double the... Read more...
As it turns out, the batch of expiring Secure Boot certificates isn't the only Secure Boot-related concern that Microsoft and the public need to worry about this year. ESET Researchers have uncovered 11 vulnerable UEFI shim bootloaders... Read more...
Cyber criminals are constantly looking for new ways to compromise systems and devices, and sometimes that means going back to the well with malware that’s been successful in the past. That’s exactly what the researchers at security firm... Read more...
The open source, enterprise email software Zimbra was recently updated to version 10.1.19, and parent company Synacor urged users to update as soon as possible. Specifically, the update addresses a vulnerability in the Classic Web Client... Read more...
There has never been a better time to be a bug hunter, whether the goal is patching Windows or breaking into it. With AI now capable of digging up software flaws faster than any human team could manage, Microsoft has announced a sweeping... Read more...
Removing the privacy light from Meta's AI glasses turned into a small business, with modders openly advertising the work on Meta's own marketplace. Meta is now slamming that door shut with a software update that kills the camera entirely... Read more...
Nefarious actors are becoming adept at deploying Large Language Models (LLMs) in their malware campaigns. Case in point, the threat research team at security firm Sysdig has discovered what looks to be the first instance of an attack using... Read more...
Fans of the Flipper Zero have spent the past few weeks wondering whether the beloved pocket multi-tool was quietly being put out to pasture. A stretch of perceived silence from Flipper Devices, which recently announced its Busy Bar smart... Read more...
Since the introduction of premium iCloud+ in 2021, Apple has offered a privacy-centric feature for its users dubbed Hide My Email. Conceptually, Hide My Email allows iCloud+ users to create anonymous burner email accounts that can't be... Read more...
A new form of AI prompt injection malware has been discovered, dubbed BioShocking by the LayerX security team. And that name is no coincidence: it's a direct reference to the 2007 survival horror FPS BioShock and its iconic hypnotic phrase... Read more...
Anyone who's rooted their Android phone or jailbroken their iPhone to squeeze out a little extra control over the device is about to hit a wall, at least when it comes to using it for work or school. Microsoft has quietly armed... Read more...
Mozilla's 0din security team has discovered widespread prompt injection AI malware plaguing the GitHub ecosystem. This exploit, dubbed "indirect prompt injection," isn't the first of its kind. Previously, we've seen prompt injection... Read more...
1 2 3 4 5 Next