08 Jan

Yes, criminals are using AI to vibe-code malware

Interview With everyone from would-be developers to six-year-old kids jumping on the vibe coding bandwagon, it shouldn’t be surprising that criminals like automated coding tools

Author rabih
08 Jan

Ransomware attacks kept climbing in 2025 as gangs refused to stay dead

If 2025 was meant to be the year ransomware started dying, nobody appears to have told the attackers. In its 2025 State of Ransomware in

Author rabih
08 Jan

CISA flags actively exploited Office relic alongside fresh HPE flaw

CISA has added a pair of security holes to its actively exploited list, warning that attackers are now abusing a maximum-severity bug in HPE’s OneView

Author rabih
08 Jan

UK regulators swarm X after Grok generated nudes from photos

Elon Musk’s X platform is under fire as UK regulators close in on mounting reports that the platform’s AI chatbot, Grok, is generating sexual imagery

Author rabih
08 Jan

Maximum-severity n8n flaw lets randos run your automation server

A maximum-severity bug in the popular automation platform n8n has left an estimated 100,000 servers wide open to complete takeover, courtesy of a flaw so

Author rabih
08 Jan

OpenAI putting bandaids on bandaids as prompt injection problems keep festering

Security researchers at Radware say they’ve identified several vulnerabilities in OpenAI’s ChatGPT service that allow the exfiltration of personal information. The flaws, identified in a

Author rabih
08 Jan

Are criminals vibe coding malware? All signs point to yes

Interview With everyone from would-be developers to six-year-old kids jumping on the vibe coding bandwagon, it shouldn’t be surprising that criminals like automated coding tools

Author rabih
08 Jan

Credential stuffing: What it is and how to protect yourself

Digital Security Reusing passwords may feel like a harmless shortcut – until a single breach opens the door to multiple accounts Christian Ali Bravo 08

Author rabih
08 Jan

Logitech macOS mouse mayhem traced to expired dev certificate

Logitech says an expired developer certificate is to blame after swaths of customers were left infuriated when their mice malfunctioned. Various users took to social

Author rabih
08 Jan

Cloudflare pours cold water on ‘BGP weirdness preceded US attack on Venezuela’ theory

Cloudflare has poured cold water on a theory that the USA’s incursion into Venezuela coincided with a cyberattack on telecoms infrastructure. The theory came from

Author rabih
07 Jan

IBM’s AI agent Bob easily duped to run malware, researchers show

IBM describes its coding agent thus: “Bob is your AI software development partner that understands your intent, repo, and security standards.” Unfortunately, Bob doesn’t always

Author rabih
07 Jan

ESA calls cops as crims lift off 500 GB of files, say security black hole still open

exclusive The European Space Agency on Wednesday confirmed yet another massive security breach, and told The Register that the data thieves responsible will be subject

Author rabih
07 Jan

Stalkerware slinger pleads guilty for selling snooper software to suspicious spouses

The US government has secured a guilty plea from a stalkerware maker in federal court, marking just the second time in more than a decade

Author rabih
07 Jan

Microsoft scraps Exchange Online spam clamp after customers cry foul

Microsoft has backed away from planned changes to Exchange Online after customers objected to limits designed to curb outbound email abuse. In its cancellation announcement,

Author rabih
07 Jan

Ministry of Justice splurged £50M on security – still missed Legal Aid Agency cyberattack

The UK’s Ministry of Justice spent £50 million ($67 million) on cybersecurity improvements at the Legal Aid Agency (LAA) before the high-profile cyberattack it disclosed

Author rabih
07 Jan

Jaguar Land Rover wholesale volumes plummet 43% in cyberattack aftermath

Brit luxury automaker Jaguar Land Rover has reported devastating preliminary Q3 results that lay bare the cascading consequences of a crippling cyberattack, revealing wholesale volumes

Author rabih
07 Jan

HSBC app takes a dim view of sideloaded Bitwarden installations

Some HSBC mobile banking customers in the UK report being locked out of the bank’s app after installing the Bitwarden password manager via an open

Author rabih
07 Jan

HackerOne ‘ghosted’ me for months over $8,500 bug bounty, says researcher

Last fall, Jakub Ciolek reported two denial-of-service bugs in Argo CD, a popular Kubernetes controller, via HackerOne’s Internet Bug Bounty (IBB) program. Both were assigned

Author rabih
Load moreLoadingAll items loaded