20 Aug

Grok chat duped into swallowing injected instructions

xAI’s Grok web chat agent is currently vulnerable to a novel form of prompt injection, according to security researchers with Adversa AI. The technique allows

Author rabih
20 Aug

French tax authority says break-in exposed data of 600K, including some private messages

Security Stolen details range from contact information to household finances and withholding rates France’s tax authority says attackers may have stolen the contents of messages

Author rabih
20 Aug

AI agent suggested installing a malware package. Engineer almost took its advice

SECURITY Fortunately, the company had a policy of checking source code on GitHub first PWNED Welcome back to PWNED, the column where we make fun

Author rabih
19 Aug

‘Not a theoretical risk,’ feds warn as attackers use AI-made code to hack critical infrastructure controllers

Attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities,

Author rabih
19 Aug

ICE boss to agents: Leave the Meta spy glasses at home

security ‘Personally owned body-worn cameras are prohibited,’ ICE tells The Reg. Because the last thing DHS needs is more proof of misconduct Some ICE employees

Author rabih
19 Aug

Flock surveillance backlash mounts as fiendish Halloween plans circulate

Security CEO apologizes for police misuse as activists call for vandal action against license plate cameras Surveillance tech company Flock has struggled with its public

Author rabih
19 Aug

Comcast gives its Wi-Fi motion detector a security makeover

Security Rebranded feature promises household alerts without video, but mind the small print Comcast has folded its Wi-Fi-based intruder detection feature into Xfinity Shield, a

Author rabih
19 Aug

NIST Releases Tips & Tactics for Building Automation & Control System Cybersecurity

Credit: Shutterstock Credit: Kristina Rigopoulos, NIST Recent cyberattacks highlight the growing threat to operational technology (OT) used in critical infrastructure. Whether you work for an

Author rabih
19 Aug

Australian hotel chain leaks guests’ PII after breach at third-party database operator

cyber-crime Unknown parties know where you stayed last summer, down under, across 120 Quest properties Australian aparthotel chain Quest has revealed it leaked customer data.

Author rabih
18 Aug

OpenAI’s overhead will rise 20 percent for some workloads as it hardens security

ai and ml Expanded multistage chain of thought monitoring makes frontier model work more expensive OpenAI on Tuesday said its decision to suspend model training

Author rabih
18 Aug

Expired credit cards revived by researchers to make unauthorized payments

security Gaps in expiry checks could let dead plastic make purchases again Researchers affiliated with the University of Massachusetts Amherst have found that you can

Author rabih
18 Aug

CISA gives feds 3 days to fix actively exploited Ray RCE bug

Security Phishing, malvertising attacks could target devs to gain access to private corporate networks CISA says attackers are exploiting a critical 2025 vulnerability in Ray,

Author rabih
18 Aug

Apple plugs image-processing hole ripe for spyware abuse

Security Patch batch spans current kit, older iGadgets, Macs, and Vision Pro Apple has released a batch of vulnerability fixes for iPhones, iPads, and Macs,

Author rabih
18 Aug

Copilot tricked into telling reseachers how to hack itself

Researchers manipulated Microsoft Copilot Personal into telling them how to hack the AI assistant – eventually tricking it into sending sensitive data to an external

Author rabih
17 Aug

An AI broke Snowflake’s code. Then another AI agent exploited it

Security Don’t worry, this one was via a bug bounty program An AI broke Snowflake’s code; then another AI, an attack agent, autonomously found the

Author rabih
17 Aug

Stronger Cybersecurity Programs Start with People: NIST Wants Your Input on the Path Forward for Human-Centered Cybersecurity

Credit: Shutterstock When was the last time a cybersecurity process at work made you want to scream? Maybe it was a password requirement so complicated

Author rabih
17 Aug

Crook hawks millions of records allegedly plundered from corporate Azure tenants

SECURITY McDonald’s, Vodafone, TCS, Kyndryl, and others named as researchers point to compromised credentials A cybercrook claims to have siphoned millions of employee records from

Author rabih
17 Aug

Code fixers have fired up the AI warp drive. Strange new worlds await

COLUMNISTS With more patches per month than at a pirate convention, the bug must be an endangered species. Well, about that It is the best

Author rabih
Load moreLoadingAll items loaded