Topic
Security
184 stories, page 3 of 8
Microsoft just patched two Windows flaws attackers were already using
September's Patch Tuesday fixed 973 vulnerabilities, including two Windows zero-days already exploited in the wild, with a CISA deadline of 22 ...
SecurityMedusa ransomware has now hit 500 critical infrastructure targets
The Medusa ransomware operation has now breached roughly 500 organisations across US critical infrastructure sectors, according to fresh threat ...
SecurityAnthropic says Chinese AI labs have been systematically stealing its model's brain
Anthropic has directly named Alibaba, Moonshot AI, and DeepSeek in a new report alleging they ran coordinated distillation campaigns to extract ...
SecurityWhat a CVSS 10.0 actually means, and the four questions to ask next
A CVSS 10.0 means remotely reachable, no credentials, total impact. Here is what the score really covers and the four questions that decide your ...
SecurityBlueMoon turned a 27 day Chrome patch gap into four espionage campaigns
Proofpoint found four state-aligned groups running the same Chrome and Windows exploit chain within days. The V8 fix sat in public Chromium source ...
SecurityMicrosoft patched 974 flaws in one day. Only two were being exploited.
Microsoft's September 2026 Patch Tuesday closed a record 974 CVEs, more than double August's 421. Two are under active attack. Why the count is ...
SecurityYour LG smart TV has been scanning your home network, and that is a problem
Researchers have found that LG smart TVs are actively scanning home networks to identify third-party devices like phones and laptops, and the ...
SecurityHackers are draining Claude subscribers' AI credits and Anthropic is finally talking about it
Hackers are getting into Claude accounts and burning through subscribers' AI token allowances, with at least one user noticing his credits draining ...
SecurityLiquid lost 95 percent of its Bitcoin to self-declared white hats
Around 4,000 BTC left the federation wallet backing Blockstream's Liquid Network. The people who took it want to be called researchers, and nobody ...
SecurityTen exploited flaws hit the CISA KEV catalogue in seven days
CISA KEV September 2026: ten actively exploited flaws were added in seven days, led by a 10.0 SonicWall SMA 1000 flaw that needs no authentication at ...
SecurityHome network security settings for 2026: Nine router changes worth twenty minutes
Nine home network security settings for 2026, in order: WPA3, a real admin password, firmware updates, WPS off, remote management off, and an ...
SecurityCISA KEV, September 2026: Seven exploited flaws, and attackers are hunting AI servers
CISA KEV September 2026: seven exploited vulnerabilities added in a week, including a CVSS 10.0 SonicWall flaw, plus attackers stealing LLM keys from ...
SecurityTen actively exploited CVEs land before September's Patch Tuesday
Ten actively exploited CVEs in September 2026, led by a SharePoint auth bypass and RCE chain, plus two CVSS 10 flaws in HPE Fabric Composer.
SecurityA ransomware crook used frontier AI to do a two week job in ten hours
Unit 42 researchers documented a human attacker using frontier AI models to plan and execute a network intrusion that would normally take a skilled ...
SecurityShinyHunters claims 5.2 million records from American Tower Corporation
The extortion group ShinyHunters says it pulled over 5.2 million records from telecoms infrastructure giant American Tower on 3 September, the latest ...
SecurityPaperCuts print server has a pre-auth RCE chain, and attackers found it first
Two chained flaws in PaperCut NG and MF let an unauthenticated attacker take over the application server. Active exploitation is already underway.
SecurityOpenAI commits 1 billion dollars to cyber defence with Daybreak programme
OpenAI has announced a 1 billion dollar programme called Daybreak for Frontline Defenders, aimed at getting frontier AI tools into the hands of ...
SecurityHow to check what ports are exposed to the internet
How to check what ports are exposed to the internet, in five steps, from finding your real public IP range to closing management interfaces nobody ...
SecurityCrowdStrike SafeMind: Two AI models built to attack and defend each other
CrowdStrike SafeMind pairs a 27 billion parameter attacker model with a 128 billion parameter defender, run against a digital twin of your own ...
SecurityA CVSS 10.0 SonicWall flaw is being exploited right now
A maximum severity SonicWall vulnerability has been added to the CISA Known Exploited Vulnerabilities catalogue alongside five other actively ...
SecuritySonicWall CVE-2026-83548 is scored 10.0 and under active exploitation
CVE-2026-83548 is a pre-auth flaw in SonicWall SMA1000 appliances scored 10.0 and already exploited. What it does and what to patch today.
SecurityPalo Alto Networks paid 500 million dollars for IT automation startup Console
Palo Alto Networks has acquired IT automation startup Console for 500 million dollars, adding AI-powered IT service management to its expanding ...
Security150 million driver's licence photos May have been stolen from an ID verification service
A major identity verification service appears to have been hacked, with over 150 million driver's licence photos reportedly now for sale on a dark ...
SecurityHow to check the CISA KEV Catalog and find out what is being exploited today
The CISA KEV catalogue is a free public list of vulnerabilities criminals are provably using right now. Here is how to check your own software ...
SecurityFTC sues Amazon over secret ad surcharge scheme involving 22 states
The FTC, joined by 22 state attorneys general, is accusing Amazon of secretly inflating ad prices and passing the cost on to both sellers and ...