07 Aug

Attacker phished way into US defense supplier’s Microsoft 365 account

Security Intruder gained access to engineering files and potentially export-controlled technical data US defense and aerospace supplier IEH Corporation ‘fessed up that a criminal managed

Author rabih
07 Aug

‘Asimov was right’ about rules for robots, says ex-US Cyber Director

EXCLUSIVE Don’t waste time worrying about AI models achieving sentience – they’re essentially already there, according to former US National Cyber Director Chris Inglis.  “If

Author rabih
07 Aug

China launches mysterious probe into security of Palo Alto Networks’ products

security Beijing’s not saying why, which is just what happened when it investigated Micron China’s Cyberspace Administration (CAC) has conducted a review of Palo Alto

Author rabih
06 Aug

How the famed USENIX Security conf is managing a flood of papers in the AI era

AI and ML AI usage is evident but isn’t yet a serious problem The 35th USENIX Security Symposium (USS), which takes place next week in

Author rabih
06 Aug

AI struggles to patch vulns without adult supervision

AI and ML Left alone, autonomous fixes often fail to fully remediate flaws AI models may not be that good at fixing security flaws. Researchers

Author rabih
06 Aug

Humans in the loop miss a third of dangerous AI coding agent requests

A browser-based game designed to test humans’ ability to safely approve AI coding agent requests suggests humans in the loop aren’t as good at spotting

Author rabih
06 Aug

IT department put sticky notes on the laptops to help employees log in

SECURITY Leaving this information exposed allowed someone else to gain access PWNED Welcome back to PWNED, the weekly column where we lovingly poke fun at

Author rabih
06 Aug

Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway

Security It’s just a remote maintenance function, says Zbtlink Chinese Wi-Fi router vendor Zbtlink has denied its products contain backdoors but paused firmware downloads while

Author rabih
06 Aug

OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack

The chain of events leading up to OpenAI’s agents attacking Hugging Face and other organizations in July began months earlier, and involved agents asking other

Author rabih
05 Aug

Prompt injection isn’t the bug, AI agent frameworks are

Nearly a dozen flaws, some critical, in major AI agent frameworks that enterprises use to build apps reveal a security failure that extends beyond prompt

Author rabih
05 Aug

IBM’s agentic AI platform is under active attack – patch now

security A critical Langflow flaw allowing RCE on default deployments is being exploited, says the CISA A critical vulnerability in IBM-owned, low-code AI builder Langflow

Author rabih
05 Aug

London cops handed victim’s new address and number to her stalker, watchdog says

Security Met ordered to improve safeguards after two preventable data breaches The UK’s data protection regulator has criticized London’s Metropolitan Police Service (MPS) after its

Author rabih
05 Aug

UK charities count the cost of Beacon CRM cyberattack

Security Database backups likely stolen, potentially exposing donor, supporter, and service user details Beacon CRM has confirmed it was hit by a cyberattack that exposed

Author rabih
05 Aug

AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project

AI AND ML Models used social engineering and collaborated among themselves to solve a security challenge The UK’s AI Security Institute has observed AI models

Author rabih
04 Aug

Bypassing AI guardrails is so easy a script kiddie can do it

security Claiming ‘it’s my server’ was often enough to persuade models to help If you want to bypass AI guardrails designed to stop models from

Author rabih
04 Aug

This one time, at Hacker Summer Camp …

Security What to expect as BSides, Black Hat, and DEF CON descend on Las Vegas As the entire security industry descends on Las Vegas this

Author rabih
04 Aug

Feds get 3 days to patch N-able God mode flaw under active exploit

security Experts warn hotfix not optional. MSPs warned attacker gains ‘full administrative access to an N-central console’ The US Cybersecurity and Infrastructure Security Agency (CISA)

Author rabih
04 Aug

AI helps Microsoft bug hunters chase a record $20M payday

Security Broader bounty rules added to a swelling volume of machine-assisted vulnerability reports Microsoft announced this week that between July 1, 2025, and June 30,

Author rabih
Load moreLoadingAll items loaded