Security
Apple urges updates as hackers target iPhones
Apple is urging billions of iPhone users to update immediately after confirming that hackers are already exploiting newly patched flaws in iOS 26.2.
Read more about Apple urges updates as hackers target iPhones
Hackers turn ChatGPT, Grok chat links into malware traps on search engines
Cybercriminals are flooding search results with manipulated ChatGPT or Grok answers. Users trying to clean their Macs or free up space end up installing powerful infostealer malware.
Read more about Hackers turn ChatGPT, Grok chat links into malware traps on search engines
LastPass fined £1.2M by ICO for comprehensive data breach
The Information Commissioner’s Office (ICO) has imposed a fine of £1.2 million on LastPass UK following a data breach that affected 1.6 million people.
Read more about LastPass fined £1.2M by ICO for comprehensive data breach
Your questions, answered by Cybernews: Can your vape be hacked?
Screening Windows, playing Doom, hosting a website, or orchestrating a cyberattack. What else can be done with your vape? Each week, our team selects one pressing and common reader issue and deconstructs it to help you stay safe online.
Read more about Your questions, answered by Cybernews: Can your vape be hacked?
Stanford University pits cybersecurity researchers versus AI: should humans worry?
Ten cyber pros were given $2,000 to beat the autonomous AI agents in hacking a live enterprise environment. One of them actually succeeded, but the victory comes at a steeper cost.
Read more about Stanford University pits cybersecurity researchers versus AI: should humans worry?
EU can’t attract and retain cyber talent: why?
Both public and private organizations in critical sectors across the European Union are finding it difficult to attract and retain cybersecurity professionals, ENISA (the European Union Agency for Cybersecurity) says.
Read more about EU can’t attract and retain cyber talent: why?
Chinese state hackers attended Cisco cybersec training, researcher claims
Two Chinese hackers accused of running one of Beijing’s biggest cyber-espionage campaigns may have first learned their craft in a beginner-level Cisco training program.
Read more about Chinese state hackers attended Cisco cybersec training, researcher claims
Feds charge former Accenture employee for misleading them on cloud security
A former product manager at Accenture repeatedly lied to the company’s government customers about the compliance of its cloud product with security regulations. Now, she’s been charged by the Justice Department.
Read more about Feds charge former Accenture employee for misleading them on cloud security
React, Next.js disclose follow-up vulnerabilities, again urge users to patch immediately
Web server admins must scramble to update their backend servers again after React and Next.js disclosed two additional follow-up vulnerabilities related to last week’s discovery of a critical bug.
Read more about React, Next.js disclose follow-up vulnerabilities, again urge users to patch immediately
Google rushes Chrome updates after new vulnerability found exploited in wild
Chrome users are racing against active attackers after Google confirmed a newly patched vulnerability is already being exploited in the wild. Clues lead to Google’s WebGL engine.
Read more about Google rushes Chrome updates after new vulnerability found exploited in wild
Microsoft urges users to change passwords, as the Dune-inspired worm hits again
A resurrected and more vicious Shai-Hulud worm is silently tearing through the software supply chain, compromising developers and cloud pipelines at scale.
Read more about Microsoft urges users to change passwords, as the Dune-inspired worm hits again
Google launches Android emergency live video to stream 911 calls in real time
Google’s Android Emergency Live Video lets users stream live footage to 911 dispatchers, giving first responders vital real-time context to save lives faster.
Read more about Google launches Android emergency live video to stream 911 calls in real time
Newly identified ransomware can execute total takeover of compromised devices
Droidlock, a new type of malware more accurately classified as ransomware, has the ability to lock device screens with a ransomware-like overlay and illegally acquire app lock credentials. This then leads to a total takeover of the compromised device.
Read more about Newly identified ransomware can execute total takeover of compromised devices
Bitdefender launches free phone number lookup tool to combat scammers
Bitdefender, a cybersecurity company, has launched a free and unlimited “Reverse Phone Lookup” tool that assesses whether unknown numbers are linked to spam or scams.
Read more about Bitdefender launches free phone number lookup tool to combat scammers
Free spy tool can track 3 billion WhatsApp users, drain batteries and data limits
A tool for tracking over three billion WhatsApp and Signal users has been publicly released. Just by knowing the phone number, attackers can determine when users come home, when they are actively using the phone, when they go to sleep, or when they are offline. They can also drain batteries and data limits without the users noticing anything.
Read more about Free spy tool can track 3 billion WhatsApp users, drain batteries and data limits
Fortinet, Ivanti, SAP release urgent patches for critical security vulnerabilities
Cybersecurity and software companies Fortinet, Ivanti, and SAP have all dropped patches to address critical security flaws in their products that could result in an authentication bypass and code execution if successfully exploited.
Read more about Fortinet, Ivanti, SAP release urgent patches for critical security vulnerabilities
Google fixes GeminiJack zero-click exposing corporate Gmail, Calendar invites, shared Docs
A newly uncovered AI injection prompt vulnerability in the Google Gemini enterprise AI ecosystem – allowing attackers to steal sensitive Gmail, Docs, and Calendar data – has been fixed, but experts say it is just the beginning of AI vulnerabilities to come.
Read more about Google fixes GeminiJack zero-click exposing corporate Gmail, Calendar invites, shared Docs
Aeroflot hack explained: report says infrastructure was nearly destroyed
The Bell, an independent Russian news outlet, has published a deep dive into this July’s major hack of Russia’s national airline Aeroflot. It turns out the company’s entire infrastructure was close to collapsing.
Read more about Aeroflot hack explained: report says infrastructure was nearly destroyed
Attackers exploit React2Shell vulnerability to target home CCTV, smart plugs, and TVs
A critical new flaw in React Server Components has unleashed a global wave of automated attacks hammering thousands of smart devices.
Read more about Attackers exploit React2Shell vulnerability to target home CCTV, smart plugs, and TVs
Sudan’s war-shaken aviation sector receives one more blow: hackers claim to be selling internal documents
A hacker claims to have compromised one of Sudan’s few surviving airlines, dumping its internal manuals and security data onto a cybercrime marketplace.
Read more about Sudan’s war-shaken aviation sector receives one more blow: hackers claim to be selling internal documents