04 May

Five Eyes spook shops warn agentic is too wonky for rapid rollout

Information security agencies from the nations of the Five Eyes security alliance have co-authored guidance on the use of agentic AI that warns the technology

Author rabih
02 May

Brace for the patch tsunami: AI is unearthing decades of buried code debt

Britain’s cyber agency is warning that AI-fuelled bug hunting is about to flush out years of buried flaws, leaving defenders scrambling to keep up. In

Author rabih
01 May

First reports come in of victims of critical cPanel vuln as ‘millions’ of sites potentially exposed

CISA has added a critical cPanel bug to its known-exploited list, confirming that attackers are already poking holes in one of the internet’s most widely

Author rabih
01 May

OpenAI locks GPT-5.5-Cyber behind velvet rope despite slamming Anthropic for doing exactly that

OpenAI is lining up a limited release of its new GPT-5.5-Cyber model to a handpicked circle of “cyber defenders,” just weeks after taking a swipe

Author rabih
01 May

Pro-Iran crew turns DDoS into shakedown as Ubuntu.com stays down

Canonical says its web infrastructure is under attack after a pro-Iran hacktivist group instructed its members to target the open source giant. “I can confirm

Author rabih
01 May

Passport to £££: Home Office adds £216M to travel doc contract before a single bid’s been placed

The Home Office has increased the annual value and overall duration of its new passport production contract, increasing it to a total of £576 million

Author rabih
30 Apr

The never-ending supply chain attacks worm into SAP npm packages, other dev tools

The wave of supply chain attacks aimed at security and developer tools has washed up more victims, namely SAP and Intercom npm packages, plus the

Author rabih
30 Apr

Bot her emails: most modern phishing campaigns are AI-enabled

Give a man a phishing kit and he might get lucky a couple of times; teach an AI to phish and it’ll change the landscape,

Author rabih
30 Apr

FBI cyber boss: China’s hacker-for-hire ecosystem ‘out of control’

China’s “hacker-for-hire ecosystem has gotten out of control,” according to Brett Leatherman, assistant director of the FBI’s cyber division. This ecosystem includes private technology companies

Author rabih
30 Apr

Google’s fix for critical Gemini CLI bug might break your CI/CD pipelines

If you use Gemini CLI, watch out: Google has patched a CVSS 10.0 vulnerability in its command-line AI tool and is warning anyone running it

Author rabih
30 Apr

French prosecutors link 15-year-old to mega-breach at state’s secure document agency

French prosecutors say police detained a 15-year-old on April 25 over the alleged theft of millions of records from France Titres (ANTS), the agency handling

Author rabih
30 Apr

Nearly half of UK businesses pwned last year as phishing keeps doing the job like it’s 2005

Nearly half of UK businesses are still getting breached, and in many cases, the attacker’s big breakthrough is an employee clicking “sure, why not” on

Author rabih
30 Apr

What type of ‘C2 on a sleep cycle’ do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia

Exclusive A novel China-linked threat group infiltrated more than a dozen critical networks in Poland, Asian countries, and possibly beyond, beginning in December 2024 and

Author rabih
30 Apr

Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day

Emergency patches are available for a critical vulnerability in cPanel and WHM that allows attackers to bypass authentication and gain root access to servers managed

Author rabih
30 Apr

This month in security with Tony Anscombe – April 2026 edition

Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 – here’s some of

Author rabih
30 Apr

Britain’s £6B armoured sickener Ajax cleared for duty despite injuring troops

Britain’s notorious Ajax armored vehicles are being accepted back from the manufacturer after investigations found no single cause for the symptoms plaguing crews, meaning soldiers

Author rabih
30 Apr

Finance company stores DB credentials in helpfully labeled spreadsheet

PWNED Welcome, once again, to PWNED, the weekly column where we recount the adventures of IT explorers who found their own pile of quicksand and

Author rabih
30 Apr

Linux cryptographic code flaw offers fast route to root

Developers of major Linux distributions have begun shipping patches to address a local privilege escalation (LPE) vulnerability arising from a logic flaw. The newly disclosed

Author rabih
Load moreLoadingAll items loaded