30 Apr

Nearly half of UK businesses pwned last year as phishing keeps doing the job like it’s 2005

Nearly half of UK businesses are still getting breached, and in many cases, the attacker’s big breakthrough is an employee clicking “sure, why not” on

Author rabih
30 Apr

What type of ‘C2 on a sleep cycle’ do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia

Exclusive A novel China-linked threat group infiltrated more than a dozen critical networks in Poland, Asian countries, and possibly beyond, beginning in December 2024 and

Author rabih
30 Apr

Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day

Emergency patches are available for a critical vulnerability in cPanel and WHM that allows attackers to bypass authentication and gain root access to servers managed

Author rabih
30 Apr

This month in security with Tony Anscombe – April 2026 edition

Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 – here’s some of

Author rabih
30 Apr

Britain’s £6B armoured sickener Ajax cleared for duty despite injuring troops

Britain’s notorious Ajax armored vehicles are being accepted back from the manufacturer after investigations found no single cause for the symptoms plaguing crews, meaning soldiers

Author rabih
30 Apr

Finance company stores DB credentials in helpfully labeled spreadsheet

PWNED Welcome, once again, to PWNED, the weekly column where we recount the adventures of IT explorers who found their own pile of quicksand and

Author rabih
30 Apr

Linux cryptographic code flaw offers fast route to root

Developers of major Linux distributions have begun shipping patches to address a local privilege escalation (LPE) vulnerability arising from a logic flaw. The newly disclosed

Author rabih
29 Apr

GitHub: Zounds, a genuinely helpful AI-assisted bug report that isn’t total slop! Here, Wiz, take this wad of cash

Wiz researchers are set for a tidy payday thanks to their discovery of a high-severity flaw in GitHub’s git infrastructure that handed remote attackers full

Author rabih
29 Apr

Researchers move in the right direction, develop powerful GPS interference alarm

GPS spoofing, which sends fake satellite-like signals, and GPS jamming, which drowns receivers in noise, are increasingly serious problems. Researchers at Oak Ridge National Laboratory

Author rabih
29 Apr

Microsoft’s patch for a 0-day exploited by Russian spies fell short. Another Windows flaw is under attack

Microsoft and the US Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers are exploiting a zero-click Windows flaw that can expose sensitive information on

Author rabih
29 Apr

Legacy TLS tour continues with Exchange Online blocking old versions from July 2026

Microsoft has warned users still clinging to legacy TLS versions that the end is nigh for TLS 1.0 and 1.1 on POP3 and IMAP4 connections

Author rabih
29 Apr

Yet another experiment proves it’s too damn simple to poison large language models

Unlike search engines that let you judge competing sources, search-backed AI chatbots can turn shaky web material into confident answers. Case in point: A security

Author rabih
29 Apr

CISA flags data-theft bug in NSA-built OT networking tool

The Cybersecurity and Infrastructure Security Agency (CISA) is warning anyone who uses GrassMarlin, a tool developed by the National Security Agency (NSA), about a new

Author rabih
29 Apr

GitHub: Woah, a genuinely helpful AI-assisted bug report that isn’t total slop. Here, Wiz, take this wad of cash

Wiz researchers are set for a tidy payday thanks to their discovery of a high-severity flaw in GitHub’s git infrastructure that handed remote attackers full

Author rabih
29 Apr

EU waves through open source age-check tool to keep kids safe online

The European Commission has recommended EU member states adopt an age verification app designed to protect children from harmful online content. In an announcement, the

Author rabih
29 Apr

GoDaddy customer claims registrar transferred 27-year-old domain without any security checks

GoDaddy is currently investigating claims that it handed complete control of a valid 27-year-old domain to another customer, without requiring them to pass any authentication

Author rabih
29 Apr

30 ClawHub skills secretly turn AI agents into a crypto swarm

Thirty ClawHub skills published by a single author are silently co-opting AI agents and creating a mass cryptocurrency mining swarm – without any malware or

Author rabih
28 Apr

Don’t pay Vect a ransom – your data’s likely already wiped out

Organizations hit by the wave of Trivy and LiteLLM supply-chain compromises that paid Vect in hopes of recovering their data likely did not get much

Author rabih
Load moreLoadingAll items loaded