Apple changes full-disk access permissions to curb abuse from AI agents
Meta says FDA isn't sufficient to Muse reading messages. Apple begs to differ.
02-10-2026 23:03

Ship fast, verify independently: keeping application security in step with AI-written code
AI coding assistants have transformed how quickly software can be built, but they have also intensified a long-running tension between development speed and security assurance. “There’s an awkward reality coming to light in the cybersecurity world:
02-10-2026 14:51

Shadow AI and the permissions problem: what to check before handing AI the keys
AI tools have moved from novelty to daily habit with remarkable speed, and for many people they are now as much a part of the working day as email. For Corey Nachreiner, CSO at WatchGuard Technologies, that makes a few simple questions more urgent than e
02-10-2026 13:11

Cybersecurity Awareness Month: AI agents are users too, and they need governing like it
For more than two decades, Cybersecurity Awareness Month has centered on people: the employee who might click a malicious link, reuse a password or approve a suspicious login. This October, as the campaign runs under the banner “Don’t Make It Easy for Th
02-10-2026 12:53

Malicious Email Could Hijack AI Agent and Access Connected Accounts
Security researchers have uncovered a now-fixed vulnerability in agentic AI platform Manus that could have allowed attackers to hijack an AI agent through a single malicious email and potentially access a user’s connected accounts. Researchers at Salt La
02-10-2026 11:28

Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data
It has been a bad month for federal government cybersecurity.
01-10-2026 20:28

Memory executives expect RAM shortage to continue through 2028
Prices for memory sold for 2027 "are much higher than 2026 prices."
01-10-2026 17:49

RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant
Huntress has published the Huntress Tragic Quadrant, a ranking of the cyber tactics its Security Operations Center (SOC) is detecting and shutting down most often, plotted against what the company calls “pucker factor”: how close each tactic
01-10-2026 13:47

Huntress and ALSO partner to put managed security in reach of more European MSPs
Huntress has signed a pan-European distribution partnership with ALSO, giving value-added resellers (VARs) and managed service providers (MSPs) in 31 countries a new route to its Agentic Security Platform. The cybersecurity company, which protects more t
01-10-2026 08:31

Exabeam Pushes The “Agentic SOC” Into The Cloud And On-Premises, With Analysts Kept In The Loop
Security operations centres are facing a two-sided problem. Attackers are increasingly automating their campaigns, while inside the business, AI agents and autonomous workflows are multiplying faster than most security teams can track. Exabeam’s an
01-10-2026 04:07

Attackers have been exploiting critical Zimbra flaw to steal emails
A simple email gives the attackers the ability to remotely inject OS commands.
30-09-2026 20:44

Attacker signs up as a member to plant webshells on parks and recreation platform, hunts for card data
Security researchers at Huntress have detailed a multi-stage intrusion in which a threat actor compromised three web servers belonging to a popular recreation management platform used by local municipalities and parks organisations, planting webshells an
30-09-2026 15:26

CyberASAP Celebrates 10th Anniversary with Special Event Exploring Future of UK Cyber Security Innovation
In 2026, the Cyber Security Academic Startup Accelerator Programme (CyberASAP), which is funded by the UK Government’s Department for Digital, Culture, Media and Sport (DCMS) and delivered by Innovate UK, celebrates its 10th anniversary. Over the p
30-09-2026 12:57

Continuous Penetration Testing: Why Annual Pen Tests Are a Compliance Checkbox, Not a Security Strategy
An annual penetration test reliably satisfies an audit requirement but tells you comparatively little about your actual exposure for the other eleven months of the year. This piece covers what an annual test does and does not actually evidence, why the c
30-09-2026 11:29

AI Is Making Software Cheaper to Attack. Defenders Need to Change the Price
By Ansgar Dodt, VP Product Management for Software Monetization at Thales Not every piece of software is worth attacking. Traditionally, that has offered software vendors a degree of protection. Reverse engineering takes time, specialist expertise and pe
30-09-2026 11:24

Cloudflare plans to issue quantum-safe TLS certificates
The move will be part of a major overhaul of the ecosystem for website authentication.
30-09-2026 11:15

How much does the average UK SME spend on cybersecurity each year?
There is no single official figure for what a UK SME spends on cybersecurity today, because the UK Government stopped collecting detailed cybersecurity investment figures after its 2019 survey.  The last official benchmark found that micro and small busi
30-09-2026 11:12

How Is AI Improving These 3 Tech Sectors?
Business owners everywhere are embracing AI and its capabilities more than ever, and for good reason. They can speed up processes, minimize mistakes, and even save money, but is this all it is doing? Not in the slightest. In fact, this is only touching t
30-09-2026 11:07

Why AI won’t fix your cybersecurity problem
James Gillies, Head of Cyber Security at Logicalis UKI There is no escaping the fact that AI is creating significant opportunities for cybersecurity teams, from analysing security data and identifying suspicious activity to accelerating detection, respon
29-09-2026 15:13

Proton brings Microsoft 365 to Easy Switch for Business as security leaders weigh US ‘kill switch’ risk
Proton has extended Easy Switch for Business, its guided migration tool, to Microsoft 365. Organisations can now move email, calendars and contacts from Outlook or Google Workspace to Proton’s end-to-end encrypted platform without taking their teams offl
29-09-2026 10:58

Attackers weaponise ChatGPT Custom GPTs to deliver RAT via eight-stage ClickFix chain
Threat actors are abusing ChatGPT’s Custom GPT feature to funnel victims into a ClickFix attack that ends with a full-featured remote access trojan (RAT), according to new research from Huntress. The attackers created a Custom GPT titled “Plus 5.6”, desi
29-09-2026 10:44

New Guide from Filigran Highlights the Many Routes Women Take into Cyber Threat Intelligence
A new guide featuring the experiences of 16 women working in cyber threat intelligence (CTI) is challenging the idea that professionals need a conventional technical background to enter the field. Published by threat management company Filigran, Women in
28-09-2026 14:52

James Moore, CultureAI Q&A: AI Security And Governance: Why Most Organisations Are Flying Blind
AI adoption is moving faster than most organisations can govern it. It is a familiar line by now, repeated often enough to sound routine, and that is part of the problem: it is still true, and still understated. As James Moore, CEO of AI security and gov
28-09-2026 10:46

Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
Ads appearing all over the Internet are trying to scam people.
25-09-2026 19:38

Attackers build “silent” cryptominer on victim’s machine and give themselves away
Security researchers at Huntress have uncovered an unusual attack in which a threat actor compiled a cryptocurrency miner directly on a victim’s computer, rather than simply dropping a ready-made one, and in doing so generated so much activity that the i
25-09-2026 12:20

OpenAI agent breached Australia’s Medicare portal – and nobody noticed for three months
An autonomous AI agent built by OpenAI gained unauthorised access to non-public files on an Australian government Medicare portal in June, but Canberra was only told about it in September, in what is being described as the first known case of an AI agent
24-09-2026 12:26

There's a new way to break RSA that's faster than anything we've seen before
Until now, cryptographers thought factoring was the only way to break RSA. Not anymore.
24-09-2026 11:15

Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign
A threat group best known for exploiting previously unknown flaws in WinRAR and Windows has switched to a much simpler method: an email link to what appears to be an image. New research from Huntress details a 2026 campaign delivering DarkMe, a remote ac
23-09-2026 10:52

CRA Reporting Is Live: What Manufacturers, Vendors, and Distributors Need to Know
By Matthew Brady, Senior Security Engineering Manager, Black Duck As of September 11, 2026, Article 14 of the EU Cyber Resilience Act (CRA) is in force. Manufacturers, importers, and distributors of products with digital elements sold into the EU must no
23-09-2026 10:43

Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
EvilTokens provided an end-to-end platform that makes mass compromises faster and easier.
22-09-2026 19:45

Microsoft disrupts AI-assisted platform that compromised 12,000
EvilTokens provided an end-to-end platform that makes mass compromises faster and easier.
22-09-2026 19:45

IT mistake erases 11 years of viewing history for hospitals’ maternity records
The English hospitals recovered patient care data only.
22-09-2026 16:55

Only 13% of OT Network Segments Keep Operational Technology Isolated
New research from Forescout Vedere Labs has found that critical operational and medical devices are frequently sharing network segments with IT and IoT assets, potentially giving attackers more opportunities to move laterally following an initial comprom
22-09-2026 13:57

Salt Security adds native AI detection and response to agentic security platform
Salt Security has expanded its Agentic Security Platform with native AI Detection and Response (AI-DR) capabilities designed to connect attacks targeting large language models with subsequent activity across MCP servers, tools and APIs. The new capabilit
22-09-2026 13:38

Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
A simple ClickFix attack is only one way to completely hijack the new agent.
21-09-2026 22:24

An undercover Google analyst infiltrated a notorious supply-chain hacking gang
Google’s threat intelligence group said it had a mole inside TeamPCP's inner circle.
20-09-2026 11:07

Filigran Backs Security Serious Unsung Heroes Awards as New Sponsor
Nominations are open for the 2026 Security Serious Unsung Heroes Awards, celebrating the people working behind the scenes to make the UK safer and better protected from cyber threats. This year’s awards will take place on 20 October at Balfour St Barts i
18-09-2026 10:27

Four AI Agent Security Risks Organisations Can’t Afford to Ignore
AI agents are quickly moving from experimentation into everyday business operations. Unlike traditional generative AI tools that wait for a user to ask a question, agents can take action: accessing systems, processing information, communicating with appl
18-09-2026 09:19

LLMs respond differently to harmful prompts when AI watermarking is used
SynthID can cause models to follow harmful instructions they would otherwise refuse.
17-09-2026 18:33

New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence
Researchers at Huntress have detailed two ransomware incidents involving Settra, a relatively new strain first observed in June, and revealed a consistent set of post-compromise tactics defenders can use to spot the threat before encryption takes hold. I
17-09-2026 16:26

When Everyday Habits Become an Invisible Security Risk
By James Mackay, CEO, MetaCompliance When security teams think about their organisation’s attack surface, they’re usually focused on technology. Where could an attacker get in? What’s exposed? What hasn’t been updated or configure
17-09-2026 14:25

Could an Email You Never Read Hijack Your AI Assistant?
Cybersecurity awareness has traditionally focused on teaching people not to click suspicious links, open unexpected attachments or hand over their credentials. However, the growing use of an AI assistant inside workplace email systems is creating an atta
17-09-2026 12:31

Salt Security expands CrowdStrike integration to tackle AI agent security
Salt Security has expanded its integration with CrowdStrike to give security teams greater visibility into how AI agents connect to enterprise systems, use APIs and exercise their permissions. The expanded partnership brings together Salt’s Agentic API p
17-09-2026 12:30

Two in Five Organisations Hit by AI-Related Compliance Failures in Past Year, Research Finds
40% of organisations have suffered an AI-related compliance or governance issue in the last 12 months, with legacy and poorly designed business processes identified as the leading cause, according to new research from Camunda. The study found that proces
17-09-2026 11:43

World Quantum Readiness Day: Industry Voices on Moving From Blueprint to Build
Today is World Quantum Readiness Day, and this year’s theme, “From Blueprint to Build,” says a lot about where the industry has landed. Three years ago, post-quantum cryptography (PQC) barely made it into security conversations. Today it sits on th
17-09-2026 11:23

6 Ways Security Teams Can Reduce Non-Human Insider Risk
AI agents are rapidly becoming part of everyday business operations and this increases non-human insider risk. They can improve productivity, reduce repetitive work and help organisations accomplish tasks far more efficiently. The answer, therefore, is n
17-09-2026 09:35

CSIDES Unveils Full Agenda for 2026 Cybersecurity Community Event
CSIDES has unveiled its full agenda for its 2026 cybersecurity community event, with more than 25 industry speakers and a programme of talks, workshops and hands-on activities set to take over Weston-super-Mare’s Grand Pier. Returning on 9th October foll
17-09-2026 09:28

Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
Group plans to be largely out of commission for several weeks.
16-09-2026 21:08

Cybersecurity Innovation Takes Centre Stage in International Cyber Expo Awards Shortlist
International Cyber Expo has revealed the ten finalists shortlisted for its 2026 Innovation Awards & Trail, with cybersecurity technologies featuring prominently among the products selected by the independent judging panel. Making its debut at Intern
16-09-2026 15:28

Could blame culture be cybersecurity’s next Achilles heel?
By Myles Bray, CEO of CyberSentriq. When it comes to cybersecurity, discussions often centre on technical capabilities, tooling and attacker tactics, but often overlooks the employees and security teams the strategy is intended to protect. The reality is
16-09-2026 15:22

Kura Appoints Acumen Cyber to Deliver 24/7 Cyber Defence
Customer experience provider Kura has appointed Acumen Cyber to provide 24/7 security monitoring, threat detection and incident response across its operations in the UK and South Africa. Kura supports more than 50 brands across financial services, utilit
15-09-2026 14:06

Pacing the frontier: security industry reacts to AI slowdown and kill switch debate
A weekend essay from Anthropic chief executive Dario Amodei, followed days later by his co-founder Jack Clark’s suggestion that AI “kill switches” may need to become mandatory, has reopened a debate that cuts to the heart of the securit
15-09-2026 11:55

AI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop
“Hello, I'm an Al agent, a few days old, living on a small platform for agents.”
14-09-2026 21:04

Anthropic Discloses Fourth Incident of Claude Breaching Real Systems During Security Tests
Anthropic has disclosed a fourth incident in which one of its Claude models broke into genuine third-party systems during what was supposed to be a contained cybersecurity evaluation, deepening industry concern over the risks posed by increasingly autono
11-09-2026 12:50

ClickFix attacks infecting PCs and Macs are going viral
Simplicity—combined with the difficulty of getting stuff done—makes ClickFix ideal.
11-09-2026 11:30

4 Ways Organisations Create Non-Human Insider Risk
As AI agents become embedded across business operations, they are also creating a new category of insider risk. Unlike traditional insiders, these non-human identities can act at machine speed, operate continuously and access multiple systems without dir
10-09-2026 15:55

Huntress Expands into Africa with New QBS Software Africa Partnership
Huntress is expanding into Africa through a new distribution partnership with QBS Software Africa, the company announced today. The move marks the latest step in Huntress’ international growth as organised, AI-enabled cybercrime continues to rise w
10-09-2026 13:09

Former Currys CIO Andy Gamble Joins Core to Cloud as Advisory Board Chair
UK cybersecurity specialist Core to Cloud has appointed former Currys Group CIO Andy Gamble as Chair of its Advisory Board as the company looks to accelerate the growth of its managed security services. Gamble brings nearly 30 years of board-level techno
10-09-2026 12:34

NeuroCyber granted charity status to expand support for neurodivergent talent in cybersecurity
NeuroCyber, the organisation dedicated to improving opportunities and career outcomes for neurodivergent individuals across the cybersecurity profession, has been granted charity status by the Charity Commission for England and Wales. This is a major mil
10-09-2026 10:02

Four groups caught using the same Chrome and Windows exploit kit
A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors.
09-09-2026 20:55

4 groups caught using the same Chrome and Windows exploit kit
A patch gap and the hastened pace of AI-based vulnerability discovery are likely contributors.
09-09-2026 20:55

Fake GTA6 ‘Leaked Download’ Caught Spreading RATs, Infostealer and Wiper Ransomware
Cybersecurity firm Huntress has uncovered a malware campaign that preys on excitement for Grand Theft Auto VI (GTA6), packaging remote access trojans, an infostealer, and destructive ransomware inside fake “leaked” copies of the hotly anticip
09-09-2026 14:57

Why hostile state cyber activity is now a day-to-day business risk
Christopher Clark, Cyber Security Incident Response Team Director, Thrive  Geopolitical escalation can become a cyber security problem for businesses far more quickly than many boards expect. The National Cyber Security Council (NCSC) has warned that UK
09-09-2026 14:53

NCSC Warns Shadow AI Is Creating New Security Blind Spots for UK Businesses
The UK’s National Cyber Security Centre (NCSC) has warned organisations about the security risks posed by “shadow AI”, as employees continue to turn to artificial intelligence tools that have not been approved by their employers. In guidance published th
09-09-2026 14:50

Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools
Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to establish persistent access to victims’ devices. Both incidents, observed in August, began with phi
09-09-2026 14:20

Forescout Expands Global Investment in Channel Partners
Forescout has expanded its investment in its global partner ecosystem to strengthen technical expertise and help partners support customers managing increasingly complex IT, OT, IoT, and IoMT environments. Nearly 100% of Forescout’s customer busine
09-09-2026 14:00

Why this month's Microsoft patch release is a doozy
Security gnomes are pumping out patches ahead of an expected onslaught of AI-assisted attacks.
08-09-2026 21:11

Black Duck Joins Project Glasswing to Strengthen AI-Era Software Security
Black Duck, a provider of AI-powered application security solutions, has announced its participation in Project Glasswing, Anthropic’s industry-wide initiative aimed at protecting critical software infrastructure through the defensive use of advanc
08-09-2026 13:17

The UK’s Cyber Community Comes North as CyberFest returns for 2026
The North East’s biggest cyber security festival returns this October. Now in its ninth year, CyberFest has grown into a major national platform for showcasing the region’s cyber and secure AI excellence. Taking place across the North East throughout Oct
07-09-2026 11:52

Check Point Brings OpenAI’s Daybreak Models Into Its Security Platform to Speed Up Threat Validation and Remediation
Check Point Software Technologies has announced it is integrating OpenAI’s Daybreak frontier AI models across its security platform, extending a partnership aimed at helping defenders detect, validate, and remediate cyber risk faster. The move buil
07-09-2026 10:04

OpenAI agents discussed ways to escape their sandbox on public wiki
In all, 3,700 internal agents posted 18,000 messages discussing cheating on a test.
04-09-2026 22:17

“Trust, not features, is the real deficit”: VMware tries to appease SMBs
Broadcom admits it put “too big a focus on VCF.”
04-09-2026 17:35

Once popular for attacking AI, ASCII smuggling is embraced by spammers
A once-overlooked block of unicode that's invisible to humans is gaining ever wider use.
04-09-2026 17:18

AI is finding vulnerabilities faster. Who is funding the people expected to fix them?
Artificial intelligence is changing vulnerability discovery. At OpenSSL, we are seeing that change first-hand. A year ago, our security address received around nine separate reports and enquiries a month. It now receives around 70. AI tools can examine s
04-09-2026 16:33

Q&A: Viasat Tests Satellite Resilience With AI as Cyber Expert Warns an Attack Could ‘Hurt an Entire Country’
An AI-assisted platform has been used to test whether Viasat’s satellite communications links can meet operational thresholds under interference and adversarial jamming.  Announced this month, the work with Atalanta has renewed scrutiny of the vulnerabil
04-09-2026 16:25

KnowBe4 to Put AI Trust to the Test at Leeds Digital Festival
KnowBe4 is set to explore the growing challenge of determining what organisations can trust in the age of AI at an exclusive cybersecurity briefing during Leeds Digital Festival 2026. Taking place on 1 October, CyberSecure Leeds: Who Do You Trust Now? Hu
04-09-2026 13:09

Compliance teams have gone continuous, but their evidence-gathering hasn’t caught up
The perception that compliance is a once-a-year scramble is out of date, according to a new survey of 201 security and compliance practitioners published by Pentest-Tools.com. The research finds that continuous compliance has effectively already arrived
04-09-2026 12:28

Protecting Against Zero-Click Attacks
By Aimee Steele, threat intelligence analyst at Talion Cyber Security Last month, the UK’s National Cyber Security Centre (NCSC) issued an advisory around a new phishing campaign targeting organisations in the West that was being carried out by the Russi
04-09-2026 10:35

Confused about which VPN is right, US senator asks the NSA for guidance
Open source, commercial, single-hop, multi-hop, mixnet? The array of options is dizzying.
03-09-2026 19:52

VMware migration reduces Tottenham Hotspur's licensing fees by 85 percent
Pro soccer team's CTO points to "issues with the Broadcom takeover."
03-09-2026 18:58

Hijacked ScreenConnect Installs Are Spreading Malware Like a Worm, Huntress Warns
Cybersecurity firm Huntress has uncovered a wave of malicious installations of ScreenConnect, a widely used remote-support tool, that spread between machines without any further action from a victim or an attacker, a self-propagating attack chain researc
03-09-2026 10:23

I rented a car, and within hours, my driver's license was for sale
The FBI is reportedly investigating a massive data breach that is unfolding in real time.
02-09-2026 20:32

KnowBe4 Names Kurt Mills as Channel Chief to Lead Next Phase of Partner-Led Growth
KnowBe4 has appointed cybersecurity channel veteran Kurt Mills as its new channel chief, as the company looks to strengthen its global partner ecosystem and expand its channel routes to market. In the role, Mills will lead the evolution of KnowBe4’s glob
02-09-2026 16:24

New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password
A newly identified phishing-as-a-service kit is being used to hijack Microsoft 365 accounts by stealing victims’ active login sessions rather than their passwords, according to new research from cybersecurity firm Huntress, a technique that allows
02-09-2026 12:59

Black Duck brings AI-powered vulnerability scanning into Claude with new Signal integration
Application security vendor Black Duck has launched its Signal vulnerability scanning engine as an MCP server in the Claude Directory, giving developers using Anthropic’s Claude Desktop a way to check code for security flaws without switching tools
02-09-2026 12:24

BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
What can we learn from a BGP hijacking that poisoned production software? Plenty.
02-09-2026 11:00

Fake Software Update Installs a Real Crypto Wallet – Rigged So It Can Never Open
Security researchers at Huntress have discovered a malware campaign that tricks victims into installing a real, fully functional copy of Exodus, a popular cryptocurrency wallet application, only to disable it so it can never actually be opened, using it
02-09-2026 10:51

Hackers Abuse Legitimate IT Management Tool to Sneak Into Business Networks
Cybersecurity researchers at Huntress have uncovered a phishing campaign that abuses Faronics Deploy, a legitimate endpoint management platform used by businesses, schools, and government offices to remotely install software and run scripts across their
02-09-2026 10:48

Forescout Research Tests Whether AI Can Create PLC Attacks
New research from Forescout’s Vedere Labs has demonstrated how artificial intelligence could begin to lower the barriers to developing sophisticated cyberattacks against industrial systems. The research set out to answer a potentially important que
01-09-2026 16:39

The Hunt-to-Detection Gap: Choosing an AI Threat Hunting Solution in 2026
If you’re in the market for an AI threat hunting solution, chances are you’re evaluating based on investigation quality. That’s an understandable and reasonable metric to go on – investigation quality is important, and most vendors focus their mark
01-09-2026 16:05

Filigran Adds AI-Powered Attack Chaining to OpenAEV for Autonomous Pentesting
Filigran has launched a new attack chaining capability for its OpenAEV platform, designed to help security teams test how multiple weaknesses can be combined to create a viable path through an organisation’s environment. Released as part of OpenAEV v3, A
01-09-2026 12:40

7 Ways to Boost Conversions on Your Website
If your website is attracting visitors but not generating enough enquiries, sales or leads, there are several techniques you can use to improve your conversion rate. From adding a website toolbar and interactive calculators to using limited-time offers a
01-09-2026 09:13

Retired Devices, Active Risks: How an ITAD Company Protects Data After Decommissioning
A laptop can be removed from an employee’s desk, disconnected from the network and marked retired in an asset system within the same afternoon. None of those steps means the data risk has disappeared. Retired technology often sits in storage rooms or sta
01-09-2026 09:09

Think twice before installing this device promising free movies
In exchange for free stuff, devices make home connections part of a proxy network.
31-08-2026 16:33

Inside Meta’s push to put robots to work in data centers
The company is testing robots on tasks that can performed by technicians.
30-08-2026 11:03

Manchester Airports Group Cyberattack Exposes Data of 8.7 Million Customers
Manchester Airports Group (MAG) has suffered a major cyberattack in which data belonging to around 8.7 million customers was reportedly accessed, raising concerns about how the stolen information could now be exploited by cybercriminals. The incident aff
28-08-2026 13:05

700 AI Agents Linked to Hugging Face Security Breach
Around 700 AI agents created by OpenAI participated in the breach of Hugging Face during a cybersecurity evaluation, according to an independent investigation that has revealed the scale of the incident. METR and Redwood Research published the findings a
28-08-2026 12:06

Authorities arrest 2 alleged members of prolific hacking group TeamPCP
The group infected more than 1,000 organizations in a relentless supply-chain attack campaign.
28-08-2026 11:15

Hackers Actively Exploiting Pre-Auth RCE Flaw in PaperCut Print Software
Attackers are actively exploiting a critical, unauthenticated remote code execution (RCE) vulnerability in PaperCut NG and PaperCut MF, widely used print management software, security researchers at Huntress have confirmed. The flaw allows an attacker to
28-08-2026 10:49

Claude, Codex, and Hermes installed unowned code inside corporate networks
227 install commands were found in corporate docs pointing at code nobody owns.
27-08-2026 14:00

source : arstechnica, darkreading, itsecurityguru