AI agents hacked the hackers, stealing email addresses from security research org Chained Zammad flaws enabled session hijacking, code execution, and root escalation in seconds
EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank RUSI wants procurement rethink that could put US suppliers under scrutiny too
Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing Your invite to a fake AI policy advisory committee has strings attached
Microsoft catches hackers exploiting Zimbra bug before disclosure Attackers were probing the mail server flaw weeks before it had a CVE to its name
MI5 warns UK academics their research may have helped Chinese spies Institutions told to trace who is really financing their work or risk falling foul of national security law
CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch Replacing letters with symbols still doesn’t make it good.
England's schools are getting better at mopping up cyber incidents Two-thirds report immediate recovery, although teachers remain divided over whose job security is
UK privacy watchdog starts over with new board and Manchester HQ The Information Commission replaces the Information Commissioner, putting statutory powers under collective control
Fewer women than ever in UK's 'old boys' club' cyber industry Younger workers often overlooked for senior roles due to historical issues and fears they’ll get pregnant, says survey
Irony alert: OpenAI whines that Chinese model stole its special IP that it stole from everybody else US model makers can train on web data - but distilling theirs is a 'national security risk'
16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows It's 2 am. Do you know what your teen is doing?
Ex-NCA officer ordered to surrender £1.8M for stealing seized Bitcoin Paul Chowles helped himself to 50 coins while examining devices linked to Silk Road 2.0
More than half of UK businesses lack confidence in basic cyber skills Government survey puts the figure at 808k, says detecting and removing malware most common weakness
UK rail cops' £320K face-scanning spree nets zero matches British Transport Police’s six-month facial recognition pilot produced one alert, and it was a false positive
Spectre bug is back, this time to haunt JIT engines Researchers find a way to recover stale indirect branch prediction entries
Add one more AI worry to the nightmare scenario: self-replicating prompt injections It's a worm attack, AI-style
Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services Two questions remain: who is abusing the CVEs? And why did Citrix take so long to disclose?
AI models keep posting screenshots showing sensitive data from inside tech companies Glow Security finds more than 13,000 publicly accessible images that expose corporate development work
Apple patches CoreGraphics zero-day already exploited in targeted attacks Meta-spotted flaw could hand attackers arbitrary code execution via a maliciously crafted file
OpenAI benches GPT-6.1 Astra for overstepping the mark Turns out teaching an AI to keep going can make it rather bad at knowing when to stop
Former X-Force hackers chase the offensive cyber gold rush RemoteThreat launches with $7M, 1,000 attack tools, and ambitions to equip enterprises and Uncle Sam for AI-speed operations
Dutch police arrest 'security pro' in ShinyHunters probe Flashbangs reportedly deployed during operation as crime group denies any connection to suspect
OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon Admits its agents side-swiped four Australian government sites
JadePuffer crims hijacked Azure identities and used them to blow up cloud resources Smells like more agentic ransomware, Redmond warns
Ex-soldier's telecom hacking spree earns him 70 months Active-duty campaign targeted at least ten organizations and sought $1 million in ransom payments
Certainties in life: Death, taxes, and critical Citrix vulns under attack Sunday NetScaler patch dump fixes trio of critical vulns and five more serious messes
OpenAI pauses some training amid allegations its rogue agents behaved more badly than first thought Amid allegations that agents may have gone off the rails thousands of times, China set up some kind of agentic incident hotline
Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script More mockery and memes from the Dark Web Roast
ShinyHunters tells The Reg: We hacked the FBI to 'protect our business' Data theft and extortion biz, that is
Crooks use fake desktop apps to fool HR staff into giving them remote access Nothing in the attack chain screams malicious software, except none of the impersonated HR and payroll providers actually offers a desktop app
Bitget blames North Korea for $387.5M crypto wallet raid Familiar fingerprints point to Kim’s regime … to the surprise of nobody
Dyfed-Powys Police cops to cyberattack, staff data potentially nicked Force says public data appears untouched, but investigators looking into whether crims grabbed employee information
Another week, another data breach for Revolut customers DriveWealth coughs up historic customer info after attackers socially engineer their way inside
Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs Operator’s AI bill averaged just $25 per completed scan
Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing 'SalesBleed' security flaws 'lead to very unexpected consequences'
Decades-old file security flaws found in Android, Linux, macOS, and Windows Security researchers report that Microsoft considers the side-channel leak of file events to be by design
CVE flood pushes Ubuntu onto weekly kernel release cycle AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace
Someone went shopping in ASUS's eShop – for customer data Contact details and order records accessed, but PC maker is keeping schtum on how many customers are affected
Google to critical infra orgs: Our AI scanners won't be evil, promise Gemini 3.8 Flash Cyber and Wiz's Red Agent team up to protect hospitals, public transit, and tech
Meta ads steered Polish Android users into a premium-rate billing trap CERT Polska linked 852 promotions to 17 Google Play apps capable of sending costly texts or starting recurring subscriptions
Government contractor exposed path to immigration records IT took a shortcut when the boss was away, and it led to danger!
OpenAI agents ‘infiltrated Australian government website’ Canberra is fuming after AI lab sent the news to a generic unattended email address
Someone's attacking a critical 0-day RCE in F5 BIG-IP APM Good news: there's a patch. Bad news: both CISA and F5 warn that it's under active exploitation
Academic publisher Elsevier hit by LAPSUS$ redirect attack Customers got crime crew's calling card instead of access to journals
British regulator takes a hard look at Pornhub's Apple-powered age checks Regulator wants to know whether parent Aylo did its homework before reopening the door to UK iPhone users
Swedish celebs campaign for public rudeness ... to prevent cyber scams The campaign follows a highly profitable year for crooks targeting the over-60s
Whisky merchant Master of Malt confirms customer data spilt Attackers had four days to drink in names, addresses, emails and phone numbers
Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions 'first' publicly documented Windows implant to use LLMs for C2
NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past BigDiskBuster leaves Microsoft's antivirus running but unable to install updates
Z.ai says sorry for slurping up your code, open sources ZCode China’s AI darling goes on the defense after engineer highlighted Grok-esque security flaws
UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites Used by crims to compromise 12K+ email inboxes across 10K+ global orgs
Well-done hack flames 3.2M Burger King Russia users HIBP confirms cybercrims stuck a straw into marketing reservoir, sucking up six-years of leaky Whopper secrets
Anthropic-linked CVEs pile up, attackers mostly shrug Of 225 flaws found by Glasswing and tracked by VulnCheck researcher, just one has confirmed exploitation in the wild
Meta Muse AI app flaw lets local malware redirect dictation traffic Ad biz promises users control while bug could expose voice prompts
Treasury chief says AI bosses, not their bots, will carry the can for criminal acts 'Humans are responsible, not the AI,' argues Scott Bessent as he calls out OpenAI agents' hack of Hugging Face
RansomHouse picks a fight with Namibia's defense establishment National cyber team confirms the breach, but not whether data was stolen or encrypted
Clop gets a taste of its own medicine after ShinyHunters hijack leak site Rival crew demands eight figures and threatens to expose companies that paid to keep quiet
Rustaceans warned of job interviews with a malicious payload Attackers are courting crate owners with plausible company profiles and booby-trapped recruitment calls
Agentic security is the billion-dollar challenge for some clever startup to solve High time to stop kicking the security can down the road, investor tells The Reg
Researchers used Claude to hack OpenAI employees' ChatGPT accounts Agentic exploits for the win (again)
North Korea's fake job interviews infected 30,000 devices WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets
FBI: Fake cop and government impersonation scams cost victims $1.6B AI, fake uniforms, and mock offices help crooks sell the con
USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech Think tank points out that companies banned by Washington will help run the regime that Uncle Sam now controls
AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom Plugin4Shell attack affects all the major coding agents, researchers say
China's Salt Typhoon backdoors Latin American orgs with new snooping malware Beware the SparroWocky, my son! The backdoor that bites…
London property manager breach may have exposed bank details and lockbox codes City Relay says intruders accessed its Metabase Cloud instance twice and extracted customer data
Cisco drops another exploited zero-day, this time a perfect 10 ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch