DEF CON hackers add new muscle to water utility protection
Franklin project adds new security providers, employs digital twins and AI
Franklin project adds new security providers, employs digital twins and AI
Kimsuky's phishing attacks get an AI boost
What wouldst thou ask of the monkey's paw?
Crims talked their way onto three employee PCs before trousering corporate data
Pub chain says turn off the cameras, reminds punters not to blare sound from phone vids either
No, no nasties to see here, guv...
Repairable hardware is little comfort when personal details escape
Walk away and hope the classifier catches anything irreversible or destructive
PLUS: Hiveminds are emerging to hack the planet, and open-weight models are the new new red scare
Gen Xers who feel triggered by this should remember to unplug the network cable and call the cops
Researchers scour social media to measure developer concerns about AI coding tools
Or how I learned to stop worrying and love dangerous AI
Calling all defenders
What, you didn't think the top gangs were busy watching agents escape their sandboxes too, did you?
Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again
Timer interrupts reopen branch predictor poisoning window, with a working Zen 2 exploit to prove it
Investigation into whether staff improperly accessed Minnie Merriman’s file after she was named for the first time this week
Intruder gained access to engineering files and potentially export-controlled technical data
Humans will get the AI models they deserve
Beijing’s not saying why, which is just what happened when it investigated Micron
AI usage is evident but isn't yet a serious problem
Left alone, autonomous fixes often fail to fully remediate flaws
You wouldn't let Claude Code cat your AWS credentials or Kubernetes config on request, would you?
Leaving this information exposed allowed someone else to gain access
It’s just a remote maintenance function, says Zbtlink
It started with an 'impossible task' and led to AI deciding it needed to act as a collective intelligence
Check Point researchers tried to break the frameworks enterprises use to build AI apps. Now they're telling Black Hat attendees what they found
A critical Langflow flaw allowing RCE on default deployments is being exploited, says the CISA
Met ordered to improve safeguards after two preventable data breaches
Database backups likely stolen, potentially exposing donor, supporter, and service user details
Models used social engineering and collaborated among themselves to solve a security challenge
Claiming 'it's my server' was often enough to persuade models to help
What to expect as BSides, Black Hat, and DEF CON descend on Las Vegas
Experts warn hotfix not optional. MSPs warned attacker gains 'full administrative access to an N-central console'
Broader bounty rules added to a swelling volume of machine-assisted vulnerability reports
Cops arrest budding politician for allegedly dealing with Flock's expansion the American way
Customers told traffic may be limited at certain times following more than ten days offline
Automates bug bounty triage with Sonnet for $58 a month, CSO says Mythos would cost $200k
Poisoned pull requests contain prompt injection that allows one to control another
With NIST still buried under its backlog, expect AI-generated bogus reports to continue
Keyloggers, audio-visual surveillance, and token theft on CaptivePortal's agenda as hospitality sector put on alert
Trump rejects Tehran theory, blames 'grossly incompetent' governor of Minnesota instead
Employee failed to follow security policy, leaving internal management file open to the public
CrowdStrike tracks 89% surge in machine-assisted activity as patch windows shrink to 48 hours
Hopefully the company secures houses better than it locks down SaaS systems
Whoever wins, we lose
A week into shutdown, 14,000 customers still have no restoration date and some are struggling to pay staff
Wrote and published malware during tests, which is apparently OK because leaky test environments were the real problem
A lesson for aspiring vandals: Take out all the cameras, not just the ones that flout your ideals
Opening a booby-trapped message unleashes a browser implant that can survive password changes and device rebuilds