45 articles covering the latest in cybersecurity
"The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporting out a number of files, and finally creating AD Report.html to measure the success of…
Each read gets pinned to the moment it happened: the time, your location, what you were doing, even how you were using your phone. Some versions in the filing would listen all day; others would check in only at set…
On the flight home, I picked up a book I had not touched in a few years. Daniel Kahneman's Thinking, Fast and Slow. Kahneman is one of the rare people who genuinely changed how we understand human decisionmaking. He…
Distributed via Telegram and costing $400 a month (or $3,800 per year), attack chains leverage phishing lures that make use of legitimate email delivery infrastructure, such as Amazon Simple Email Service (Amazon SES)…
When it works, the person reads an ordinarylooking reply and never learns their assistant was tampered with.
This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here.
"At Balochistan Police, the compromised assets included servers hosting web applications that manage police and citizen data, such as criminal and biometric records," Aleksandar Milenkoski, principal threat researcher at…
No old password. No backup card. Once it is reset, whoever did it controls the wallet and can move the coins out.
Four of the bugs can crash a device. The other two could let an attacker who slips a malicious image in front of the bootloader run their own code, before the device has confirmed that the software is genuine.
Ravie Lakshmanan Jul 10, 2026Software Supply Chain / Malware [ ](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTNxzPo9jxkW3GuuZLBgtPOrG3vZ3va6E710jDJu JF0jCpyQ1JTpymdVwdSH2VHL6-...
The company has temporarily disabled access to the affected accounts, a step it says it took "out of an abundance of caution" while it works with internal and external security experts.
Apple filed a lawsuit Friday against OpenAI over allegations of trade secret theft and breach of contract.The iPhone maker alleges t...
"They're like a fancy paper weight," one creator told Engadge...
Jensen Huang has a test for whether an engineer is worth keeping, and it comes with a token budget attached. Speaking on the All-In Podcast at the close of GTC 2026, the Nvidia chief executive said th...
The threat actor, tracked by Okta under the moniker O-UNC-066 , has deployed a panel-controlled phishing kit that's capable of targeting the passkey enrollment process. The activity has singled out food and beverage,…
The apps flagged with at least one problem have been installed more than 2.4 billion times.
FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. He says it needs no login and no malformed packets: about 260 bytes of ordinary QPACK traffic takes the server process down.
Chinese cybersecurity company QiAnXin said that while the threat cluster may appear like a low-sophistication, high-activity operation that propagates malware via counterfeit installers using SEO poisoning techniques, it…
A brief description of the high-severity vulnerabilities is as follows -
OpenAI unveiled its newest family of models on Thursday, introducing a set of heavyweight programs into an increasingly crowded field of AI offerings.GPT-5.6 comes in three variants: Sol (considered i...
In the brief history of AI security, the prompt injection has quickly become the top threat. Large language models are inherently unable to distinguish between legitimate instructions provided by users and malicious ones…
The Microsoft-owned subsidiary noted that the following npm install behaviors that used to run automatically before have been made opt-in -
Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper . What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can…
OpenAI is rolling out its latest advanced LLM, Sol, for wide public access. Sol is considered to be at least on par with Anthropic’s Fable, a model whose capabilities (or ownership) stressed out the W...
An AI companion sounds dystopian, but it has become a common thread in the wider conversation about the perils of generative AI. What it refers to is essentially a conversational agent built to sustai...
L’Oreal is using AI to shorten product development timelines and identify new uses for ingredients already present in its portfolio.
Insilico Medicine is advancing to Phase III human trials for testing a drug identified by AI targeting idiopathic pulmonary fibrosis (IPF). This progression supplies the compu...
A recent AWS GraphRAG deployment reduced drug research and development cycles in phar...
Zimperium's zLabs, which found the operation, says it looks like a new variant of Oblivion, a $300-a-month rent-a-malware tool documented earlier this year.
The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network access; ordinary threading calls from any…
The models they tested through Copilot, Claude from Anthropic, and Gemini from Google, refused almost every harmful request when asked directly. Reframed as steps in a normal coding task, they produced the harmful…
Everything a reviewer would check matches. The commit's hash does not. That matters because so many systems treat a verified commit hash as a permanent, unique name for its contents.
The activity cluster, tracked by Elastic Security Labs under the moniker REF6045 , involves infecting victims through fake CAPTCHA verification pages that deceive them into running a malicious command that installs a…
New research, which its authors call HalluSquatting , turns that habit into an attack: work out the fake names an AI reliably invents, register them first, and wait for the assistant to fetch your trap on a user's…
The agents are not malicious. They just do a lot of things that, to a behavioral engine, look exactly like an attack.
The activity dates back to at least August 2022, according to DNS threat intelligence firm Infoblox. Once such campaign, observed earlier this year, involved the actor luring victims with a trojanized 7-Zip installer…
The affected tools are Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. Wiz calls the pattern GhostApproval and published it on July 8.
That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls " Friendly Fire. " It works against Anthropic's Claude Code and OpenAI's Codex when either is running in an…
"You can also @-mention Instagram accounts in the Meta AI app to bring specific Instagram profiles right into your images," the social media giant said in a post.
The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection Engine ("mpengine.dll"), which provides scanning, detection, and cleaning capabilities…
That is the gap, and it is not your fault. The tools and runbooks most teams run on were built for attackers who work at human speed. AI-driven attacks do not, and they run at scale. Save your seat for the free webinar,…
This is today's edition of The Download , our weekday newsletter ...
SponsoredIn partnership withElasticWith the rapid progress of AI capabilities and the move to agentic systems, organizations are expanding their use cases as the technology ...
This is today's edition of The Download , our weekday newsletter ...
SpaceXAI has released its latest model, Grok 4.5 — the first since the company went public several weeks ago.In a blog post published Wednesday, SpaceXAI characterized it...