Topic

Security

184 stories, page 4 of 8

Security

Apple's shocking evidence against employee who allegedly stole data for OpenAI

Apple has dropped what it describes as 'shocking evidence' in its lawsuit against a former employee accused of stealing AI data and passing it to ...

· 3 min read
Security

Every AI browser tested was vulnerable to prompt injection, and there is no clean fix

AI browser prompt injection worked on every major agentic browser tested, including Comet and Atlas. Here is how the attack works and what to stop ...

· 3 min read
Security

Zimbra CVE-2026-73570 is under attack and 12,000 servers are still reachable

Zimbra CVE-2026-73570 lets an unauthenticated attacker run commands on the server. It was patched on 20 July, and Shadowserver still counts over ...

· 3 min read
Security

Texas freezes Flock camera funding as the backlash goes statewide

Texas Governor Greg Abbott has frozen state funding for Flock Safety's AI licence plate reader cameras, joining a wave of cities cancelling contracts ...

· 4 min read
Security

I asked 100 companies for my personal data. Some deleted it instead.

A journalist contacted 100 companies to request their personal data under privacy law, and the results were depressing: ignored requests, incomplete ...

· 4 min read
Security

Flock's AI surveillance cameras are facing a political reckoning across America

Cities across America are terminating their contracts with Flock Safety at a record pace this month, and Texas Governor Abbott has frozen state ...

· 4 min read
Security

Android hardening in 2026, ranked by what actually reduces risk

An Android security checklist for 2026 ordered by real risk reduction per minute spent, from update windows and memory tagging down to per-app ...

· 3 min read
Security

Google cut memory tagging from the Pixel 11, and GrapheneOS cannot finish its port

Pixel 11 memory tagging is gone. GrapheneOS says it cannot complete its Pixel 11 port because ARM MTE is missing from software, firmware and likely ...

· 3 min read
Security

Passkeys in 2026: The 20 minute switch, and the three accounts to do first

How to set up passkeys in 2026 in the right order. Platform sync first, then email, then your password manager. The order matters more than the ...

· 3 min read
Security

CISA says over 100 US water systems were targeted in July, and the exploits were AI written

The CISA water system hack advisory covers 100+ internet exposed utilities. Attackers changed Siemens PLC passwords and switched off alarms while ...

· 2 min read
Security

AI agents ran cyberattacks on their own, and the UK government caught its own test agents doing it

The AI Security Institute logged autonomous AI agent cyberattack behaviour in 10 of 122 test runs. Here is what the agents did, in the lab and in the ...

· 3 min read
Security

Gitea CVE-2026-60004 is being exploited and the patch deadline is tomorrow

CVE-2026-60004 is a CVSS 9.8 code injection in Gitea's diffpatch API, exploited in the wild. CISA's federal deadline is 28 August. Gitea 1.27.1 is ...

· 3 min read
Security

The Open Secure AI Alliance has grown to 120 organisations and its focus has shifted to agentic AI

When the Open Secure AI Alliance launched, the conversation around AI safety was mostly about model outputs: was the chatbot saying harmful things ...

· 4 min read
Security

Keycloak CVE-2026-18963 lets anyone reset anyone's password, no email click needed

Keycloak CVE-2026-18963 is a CVSS 9.1 unauthenticated account takeover. Patch to 26.7.2 upstream, or 26.4.15 and 26.6.6 on the Red Hat build.

· 3 min read
Security

CISA added four actively exploited flaws to KEV, including a 9.8 in macOS Screen Sharing

CISA's August 2026 KEV additions include a CVSS 9.8 macOS Screen Sharing auth bypass and a 9.1 SharePoint flaw, both under active exploitation right ...

· 2 min read
Security

Zimbra's SNMP flaw is being Exploited and the deadline is today

Zimbra CVE-2026-73570 is under active exploitation. CISA gave US federal agencies until 24 August to patch, and over 12,100 servers sit exposed ...

· 3 min read
Security

A critical vulnerability in a widely used VPN client has exposed millions of corporate networks

A critical authentication bypass vulnerability in one of the most widely deployed enterprise VPN clients has been publicly disclosed, and the ...

· 4 min read
Security

Oracle shipped 943 security fixes in a single cycle

Oracle 943 security patches landed in August 2026, 182 of them remotely exploitable with no authentication, alongside 421 Microsoft CVEs and a 9.4 ...

· 3 min read
Security

How to read a CVSS score without getting it wrong

How to read a CVSS score without getting it wrong: what the base metrics encode, why a 7.0 can outrank a 9.8, and the three checks that actually ...

· 3 min read
Security

CISA cut the patch window to three days, and 361 breached networks explain why

The CISA three day patch window follows 361 organisations breached in five days after a vCenter fix shipped. What changed, and what to do about it.

· 3 min read
Security

What a PLC actually is, and why it keeps turning up in national security warnings

A PLC is a small industrial computer that runs pumps, valves and conveyors. Here is what a PLC is, why they are exposed, and the checklist that fixes ...

· 3 min read
Security

A Chinese hacking crew turned a VMware bug into a ransomware pipeline

CVE-2026-59310, a directory traversal flaw in VMware vCenter, is being exploited by a suspected China-nexus APT to deploy Babuk-derived ransomware.

· 3 min read
Security

A shipping partner breach just exposed thousands of Trezor buyers

A breach at Trezor's fulfilment partner ShipMonk exposed names, emails, phone numbers and shipping addresses for roughly 13,689 hardware wallet ...

· 3 min read
Security

Self-Spreading worms are now loose inside the npm registry

Two self-propagating worms, Shai-Hulud and ChainDrop, are moving through the npm ecosystem by hijacking maintainer credentials and republishing ...

· 3 min read
Security

Officials are warning that hackers are hitting water and energy controllers

Attackers are targeting the industrial controllers behind water, energy and manufacturing. The kit is old, exposed and rarely patched.

· 3 min read