A government-linked Indian IT portal served a fake Cloudflare check that tried to get visitors to run a copied command.
A new AWS benchmark finds that AI models catch most real bugs but flag a huge share of safe code…
GOV.UK One Login is opening passkeys to more than 23 million users, letting them sign in without a password.
Canada's Telus says attackers used stolen credentials to reach customer records over more than a year.
A viewer add-on with tens of thousands of installs sent live Twitch session tokens to a commercial bot operator.
Firewall and proxy rules that allow the old addresses will need updating before early October.
A new Transportation Department rule lets carriers skip meal vouchers and hotels for cyberattack delays if they meet security rules.
Researchers blocked devices they never owned for under $4, exploiting six weaknesses in the lost and stolen phone system.
The commission withdrew a Biden-era statement that treated health and fitness apps as covered by federal breach notification rules.
The VPN provider says a misconfigured internal test server gave outsiders engineering material and build credentials.
Group-IB found the long-running banking trojan building a second app that shelters inside Android's employer workspace.
A forged request sent from inside a real government domain was enough to pull identity documents, selfies, and Bitcoin histories…
One cPanel account with mail rights could reach root on a shared server before this week's fix.
ConnectWise closed a ScreenConnect gap that let live sessions move and run files without consent.
Bitdefender says Google Play's Early Access program shelters thousands of deceptive apps.
Anthropic says blocked accounts in Houthi-held Yemen tried to use Claude for missile work.
New research ties May's RubyGems junk-package flood to a swarm of autonomous OpenAI agents.
Two GitLab flaws, one a perfect 10.0, drew automated probes within hours of the patch.
Okta found thousands of live AI session tokens in a stealer log, letting thieves replay their way into paid tools.
Oleksii Lytvynenko, a lawyer who coded for the Conti ransomware crew, will spend four years in a US prison.
Apple's new Watch can turn nearby speech into text and summaries, and bystanders never get a say.
Manufacturers selling software and connected products in the EU must report exploited flaws within 24 hours.
Gen Digital says a China-linked crew used a Sogou input method flaw to plant the GRAYRABBIT backdoor on Windows machines.
GreyNoise says a lone operator used hundreds of AI agents to break into 395 organizations through two PaperCut flaws.