News Archive
1923 stories · page 50 of 81Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

'Asimov was right' about rules for robots, says ex-US Cyber Director
Humans will get the AI models they deserve

Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix
NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities. The post Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix appeared first on SecurityWeek.

Google Links Redact Extortion Group to BlackFile Rebrand
BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and

Black Hat USA 2026 – Summary of Vendor Announcements (Part 4)
Companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 4) appeared first on SecurityWeek.

Microsoft, Apple Release Fresh Security Updates
Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass. The post Microsoft, Apple Release Fresh Security Updates appeared first on SecurityWeek.

OpenAI drops ChatGPT text chat limits for free users, adds new safeguards for teens
OpenAI has updated GPT-5.6 Sol, the model behind ChatGPT for Plus and Pro subscribers, and pushed a new model, GPT-5.6 Luna, out to everyone using the free tier. The company is also removing the rate limit on text conversations for free users, allowing them to keep chats going without waiting for the limit to reset. For Plus and Pro accounts, GPT-5.6 Sol now handles both quick replies and longer r

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Researchers have discovered a method for malware to abuse Windows Hello for Business keys, enabling persistent access to Microsoft Entra ID. The technique allows malicious code running within a user's active session to silently authenticate using the victim's Hello for Business key, bypassing biometric or PIN prompts on TPM-backed systems. This can lead to the attacker registering their own device, obtaining a Primary Refresh Token, and potentially adding further authentication methods, even satisfying phishing-resistant authentication requirements.

Ransomware Surges in July After Q2 Lull
Finance, technology and healthcare sectors were particularly heavily targeted in July, according to Comparitech

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
Researchers discovered vulnerabilities in Anthropic's Claude Code and Google's Gemini CLI that allowed unprivileged attackers to execute code on CI runners. The flaws, which have been patched and assigned CVEs, involved issues with command validation and container launching. A separate finding related to OpenAI's Codex also allowed for the hijacking of agent runs, though OpenAI considers its sandbox to have behaved as documented.

Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)
UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack of "modern" logging: shells. Most shells provide an historization of the typed commands through a flat file in the $HOME directory (ex: $HOME/.bash_history). They suffer of multiple problems:

3.8 Million Impacted by Unlimited Technology Systems Data Breach
Hackers stole personal, medical, and health insurance information from a company’s data center. The post 3.8 Million Impacted by Unlimited Technology Systems Data Breach appeared first on SecurityWeek.

Keepit AI Truth Cloud protects the data behind enterprise AI
Keepit announced AI Truth Cloud, transforming backup from a compliance requirement into the strategically valuable data asset an organization can hold. As AI agents take on business-critical decisions, AI Truth Cloud positions Keepit as the sovereign source of truth that enterprise AI can safely build on: data that is verifiable, governed, immutable, and proven. From backup to trusted enterprise o

Critical Vulnerabilities Patched With Chrome 151 Update
The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws. The post Critical Vulnerabilities Patched With Chrome 151 Update appeared first on SecurityWeek.

AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam
Scammers are leveraging AI-generated deepfakes to impersonate OnlyFans creators, tricking fans into sending money through platforms like Cash App. This scam not only defrauds fans but also harms creators, who face accusations from angry followers and even threats. While legal measures are being introduced, the global nature of hosting and enforcement challenges hinder effective control.

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Researchers have linked the threat actor known as TeamPCP to cybercriminal activities dating back to 2020, predating their known supply chain attacks. The group has a history of exploiting vulnerabilities in internet-facing infrastructure, including Redis servers and AI platforms, for various malicious purposes like cryptocurrency mining and botnet creation. Their operations have evolved to include sophisticated supply chain compromises, weaponizing open-source libraries and leveraging cloud infrastructure for widespread attacks.

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?
July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, of course, well over 600 CVEs were identified in the Security Updates Guide. Interestingly, only two CVEs were reported as exploited zero-days and only one as publicly disclosed, but we’ll get back to that later in this artic

What the first year of EU AI Act transparency enforcement could look like
In this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of enforcement might bring. He explains why corrective orders will likely outnumber large fines, when an AI agent working through a ticket queue counts as interacting with a person, and how security teams should handle simulated phishing that uses cloned

US fuel gauge exposure fell by more than half in three months
Every month for the better part of a year, about 4,800 US internet addresses answered a query in the protocol that fuel tank gauges speak. In June the number was 2,354. The count fell across April, May, and June, all three months sit below the previous year’s floor, and the decline holds up against checks for address churn and port hopping. Exposure figures rarely move this way, and almost never t

CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX
CrowdStrike researchers have identified 21 novel methods for obfuscating shell commands on VMware ESX hypervisors. These techniques, ranging from simple encoding to complex cryptographic ciphers and invisible Unicode characters, evade traditional log-based detection by exploiting the parsing stage of command execution. CrowdStrike has developed detection patterns to identify these obfuscated commands at scale, enhancing security for ESX environments frequently targeted by ransomware.

ShieldFont Fights AI Scraping With Deceptive Text
A new web font called ShieldFont has been developed to combat AI-driven web scraping. It displays one version of text to human users while serving a different, altered text to automated crawlers that inspect the page's source code. This technique aims to confuse AI models trained on scraped data by providing them with inaccurate information.

China launches mysterious probe into security of Palo Alto Networks' products
Beijing’s not saying why, which is just what happened when it investigated Micron

AI-generated phishing texts bypass human intuition
AI can craft highly convincing spear-phishing text messages that are difficult for even experienced individuals to distinguish from legitimate communications. A demonstration showed that personalized AI-generated texts, mimicking official alerts, could easily deceive recipients, highlighting the limitations of relying on gut feelings to identify threats.

ISC Stormcast For Friday, August 7th, 2026 (Fri, Aug 7th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.