20 Aug

Amazon quietly fixed Q Developer flaws that made AI agent vulnerable to prompt injection, RCE

Amazon has quietly fixed a couple of security issues in its coding agent: Amazon Q Developer VS Code extension. Attackers could use these vulns to

Author rabih
20 Aug

FBI: Russian spies exploiting a 7-year-old Cisco bug to slurp configs from critical infrastructure

The FBI and security researchers today warned that Russian government spies exploited a seven-year-old bug in end-of-life Cisco networking devices to snoop around in American

Author rabih
20 Aug

Commvault releases patches for two nasty bug chains after exploits proven

Researchers at watchTowr just published working proof-of-concept exploits for two unauthenticated remote code execution bug chains in backup giant Commvault. They reported the four vulnerabilities

Author rabih
20 Aug

‘Limited’ data leak at Aussie telco turns out to be 280K customer details

Aussie telco giant TPG Telecom has opened an investigation after confirming a cyberattack at subsidiary iiNet. It said the “cyber incident” was contained on August

Author rabih
20 Aug

McDonald’s not lovin’ it when hacker exposes nuggets of rotten security

A white-hat hacker has discovered a series of critical flaws in McDonald’s staff and partner portals that allowed anyone to order free food online, get

Author rabih
19 Aug

Don’t want drive-by Ollama attackers snooping on your local chats? Patch now

A now-patched flaw in popular AI model runner Ollama allows drive-by attacks in which a miscreant uses a malicious website to remotely target people’s personal

Author rabih
19 Aug

Like burglars closing a door, Apache ActiveMQ attackers patch critical vuln after breaking in

Criminals exploiting a critical vulnerability in open source Apache ActiveMQ middleware are fixing the flaw that allowed them access, after establishing persistence on Linux servers.

Author rabih
19 Aug

Casino tech outfit Bragg cops to intrusion but says data jackpot untouched

Canadian casino software slinger Bragg Gaming Group has disclosed a “cybersecurity incident,” though it’s adamant the intruders never got their hands on customer data. MGM

Author rabih
19 Aug

US spy chief claims UK backed down over Apple backdoor demand

The UK government has reportedly abandoned its attempt to strong-arm Apple into weakening iPhone encryption after the White House forced Blighty into a quiet climb-down.

Author rabih
19 Aug

The need for speed: Why organizations are turning to rapid, trustworthy MDR

Business Security How top-tier managed detection and response (MDR) can help organizations stay ahead of increasingly agile and determined adversaries Phil Muncaster 19 Aug 2025

Author rabih
19 Aug

More customers asking for Google’s Data Boundary, says Cloud Experience boss

Interview Google’s President of Customer Experience, Hayete Gallot, offered some words of comfort to developers who are looking nervously at the rise of AI assistants

Author rabih
19 Aug

Browser wars are back, predicts Palo Alto, thanks to AI

Brace for a new round of browser wars, according to Palo Alto Networks CEO Nikesh Arora. Speaking on the company’s Q4 FY2025 earnings call, Arora

Author rabih
18 Aug

Facial recognition works better in the lab than on the street, researchers show

Facial recognition technology has been deployed publicly on the basis of benchmark tests that reflect performance in laboratory settings, but some academics are saying that

Author rabih
18 Aug

Pot calls kettle black as China dubs US ‘surveillance empire’ over chip tracking

Comment Chinese state media called the US an aspiring “surveillance empire” over its proposed use of asset tracking tags to crack down on black-market GPU

Author rabih
18 Aug

Microsoft’s Nuance coughs up $8.5M to rid itself of MOVEit breach suit

Microsoft-owned talk-to-text outfit Nuance has agreed to cough up $8.5 million to settle a class action lawsuit over the sprawling MOVEit Transfer mega-breach – although

Author rabih
18 Aug

Workday warns of CRM breach after social engineers make off with business contact details

Workday has admitted that attackers gained access to one of its third-party CRM platforms, but insists its core systems and customer tenants are untouched. Oh,

Author rabih
18 Aug

Boffins say tool can sniff 5G traffic, launch ‘attacks’ without using rogue base stations

Security boffins have released an open source tool for poking holes in 5G mobile networks, claiming it can do up- and downlink sniffing and a

Author rabih
18 Aug

Every question you ask, every comment you make, I’ll be recording you

Opinion Recently, OpenAI ChatGPT users were shocked – shocked, I tell you! – to discover that their searches were appearing in Google search. You morons!

Author rabih
Load moreLoadingAll items loaded