News Archive
1920 stories · page 14 of 80Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

Chrome 152 Patches Over 300 Vulnerabilities
Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities. The post Chrome 152 Patches Over 300 Vulnerabilities appeared first on SecurityWeek.

Linux Foundation Introduces TRACE Standard for AI Runtime Evidence
This new open standard offers hardware-attested runtime and compliance evidence for AI agents

Interpol's Jackal IV Disrupts West African Crime Infrastructure
The international law enforcement operation focused on disrupting crime-as-a-service networks and supporting infrastructure behind groups like Black Axe.

WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion
WhatsApp says 1 billion users now use passkeys, while stronger two-step verification and caller context add new layers of account protection. WhatsApp has reached a significant security milestone: more than one billion people now use passkeys to protect access to their accounts. At the same time, Meta is adding stronger two-step verification and more information […]

Nigeria Looks to Sovereign Cloud for Cyber, National Security
The West African nation launched financing, procurement, and infrastructure policies to boost its sovereign cloud initiative and increase domestic technical knowledge.

Beware of fake Indeed interview apps used to install spyware
Scammers are posing as employers on Indeed to trick job seekers into installing fake Android interview apps that deliver malware.

Meta adds three new features to keep WhatsApp accounts secure
Meta has added new security enhancements to WhatsApp, this time in the form of stronger two-step verification, additional information about calls from unknown numbers, and the ability to add multiple passkeys to the same account. New account security features (Source: Meta) “On WhatsApp, your conversations belong only to you and the people you’re talking to. It’s why we built end-to-end encryption

Sensitive Information Exposed in Nutex Health Data Breach
Nutex Health has informed the SEC that it recently detected unauthorized access and data exfiltration. The post Sensitive Information Exposed in Nutex Health Data Breach appeared first on SecurityWeek.

Linux Foundation takes on TRACE, a hardware-backed runtime evidence specification for AI agents
The Linux Foundation has adopted TRACE, a new hardware-backed specification for generating runtime evidence for AI agents and confidential workloads. Developed by major tech companies, TRACE aims to provide a standardized, cryptographically verifiable record of an AI agent's execution environment, policies, and data handling. This initiative seeks to build trust and enable independent verification of AI operations across different cloud and computing infrastructures.

Production data in testing is still common, and Tricentis’ CISO wants it gone
In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught a prompt injection gap in red-teaming and held a release for a week until it was fixed. Dean describes what gets an AI vendor rejected, mostly vague answers about where data lives a

CISA Warns of Exploited Gitea Vulnerability
CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1. The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek.

AI vulnerability discovery scores the highest impact of 20 emerging risks
Risk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber vulnerabilities came back first, according to Gartner. Three months earlier the same quarterly survey put information integrity risk at the top and left AI vulnerability discovery out of the top five. The exploit step stopped being hard Two things chan

Hottest cybersecurity open-source tools of the month: August 2026
Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. SkillSpector: NVIDIA’s open-source security scanner for AI agent skills SkillSpector is an open-source scanner from NVIDIA that reads an agent skill and tells you whether to install it. Point it at a directory, a

LACMA data breach last year exposed social security and medical data
The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]

A Cautionary Tale About Data Breach Claims, Verification and Carhartt
You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here: 🚨Cyber

Hackers abuse npm mirrors to host phishing redirect pages
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]

Hidden Prompts Trick AI Into False Email Summaries
With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.

The GTA VI leaks are breaking the internet. Security researchers have seen this before.
A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience. The post The GTA VI leaks are breaking the internet. Security researchers have seen this before. appeared first on CyberScoop.

58 arrested in international cybercrime crackdown
Interpol officials said it uncovered a crime-as-a-service network in Argentina run by 196 people that provided website domains and money laundering support to West African organized crime groups like Black Axe.

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]

Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw
Attackers can exploit a security bug in NVIDIA's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.

Employee benefits platform Paylogix says hackers stole financial and health data
Employee benefits platform Paylogix has confirmed a cyberattack that occurred in the fall, during which hackers accessed its systems and stole sensitive personal and financial data. The breach, which impacted tens of thousands of individuals across multiple states, involved the theft of Social Security numbers, financial account information, health data, and more. The Akira ransomware gang has claimed responsibility for the attack, and federal law enforcement has been notified.

Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice
Joshua Culver, aka “Maverick Young,” is accused of imitating the head of the NSA’s Tailored Access Operations unit during a time it wasn’t called that. The post Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice appeared first on CyberScoop.

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
The U.S. Department of the Treasury has imposed sanctions on nearly 60 Iran-linked entities and individuals, including a malicious cyber group affiliated with Iran's Ministry of Intelligence and Security (MOIS). This group is accused of extensive breaches of U.S. critical infrastructure and financially motivated cyber theft. The sanctions are part of a broader economic campaign aimed at severing financial lifelines supporting the Iranian regime and the Islamic Revolutionary Guard Corps (IRGC).