Data Security News
The Hacker News
- Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logsby info@thehackernews.com (The Hacker News)
Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively […]
- AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Codeby info@thehackernews.com (The Hacker News)
Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a […]
- Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilitiesby info@thehackernews.com (The Hacker News)
Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash […]
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoCby info@thehackernews.com (The Hacker News)
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per […]
- Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Accessby info@thehackernews.com (The Hacker News)
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin […]
- Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilitiesby info@thehackernews.com (The Hacker News)
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management […]
- Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCsby info@thehackernews.com (The Hacker News)
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no […]
- N-day is Becoming N-Hour. Patching Faster Won't Save You.by info@thehackernews.com (The Hacker News)
Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly […]
Graham Cluley Blog
- Ukraine warns fake CAPTCHAs are being used to make you hack yourselfby Graham Cluley
Ukraine's computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on […]
- Google’s Gemini lets strangers send messages from your locked Android phoneby Graham Cluley
Gemini, Google's AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for […]
- Anubis ransomware: what you need to knowby Graham Cluley
The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more […]
- Smashing Security podcast #476: Remote-control rickshaws and rogue book marketersby Graham Cluley
An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions […]
- The ransomware negotiator who was working for the other sideby Graham Cluley
When a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help. Specialist ransomware negotiation firms […]
- Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at riskby Graham Cluley
Have you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role? Well, before you start brushing […]
- Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itselfby Graham Cluley
A 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers […]
- Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraudby Graham Cluley
Two young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit card details of […]
Infosecurity Magazine
- Russian Hacker Turns Jailbroken Claude Into Pentest Platform
Russian-speaking actor Trim built a commercial offensive AI pentest tool on jailbroken Claude models
- A New Ransomware Threat Actor Emerges Every Week, Warns Report
Analysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmented
- FBI Warns of Deepfake Videos Impersonating IC3 Leadership
FBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sites
- US Hospital Finance Software Provider Craneware Reports Data Theft
Craneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data […]
- Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros
In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS […]
- Cruciferra Crypter Uses Process Ghosting to Evade Detection
Cruciferra crypter used process ghosting and 90 custom ciphers to hide payloads for multiple actors
- JadePuffer Returns With Ransomware Designed to Wipe AI Models
JadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifacts
- Researchers Build WordPress Exploit Using OpenAI's GPT
A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain
Dark Reading News
- Ransomware Is Accelerating, But It's Not Because of AIby Jai Vijayan
Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended […]
- Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Taskby Robert Lemos
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec […]
- Hacker Turns AI Jailbreaks Into Offensive Attack Platformby Elizabeth Montalbano
A Russian-speaking actor, "Trim," dismantled publicly available frontier models and integrated them with offensive security tools.
- Choose Wisely: AI-Generated Coding Risk Varies, a Lotby Alexander Culafi
AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used.
- 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeoverby Jai Vijayan
Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of […]
- Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Pushby Rob Wright
Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages, but cost and human-in-the-loop viability remain […]
- 25 Years After Code Red: What the Worm Era Can Teach Us About AI Securityby Marc Maiffret, James Maude, Dennis Fisher
Marc Maiffret reflects on Code Red's legacy and the security lessons helping organizations navigate AI risk today.
- CISOs Feel the Heat Over AI Riskby Robert Lemos
Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position.

