News Archive
1920 stories · page 70 of 80Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
A now-patched flaw in Google Dialogflow CX could have allowed chatbot hijacking. An attacker with edit rights on a single Code Block agent could compromise other agents in the same Google Cloud project and read live conversations.

Supreme Court allows Texas app law requiring age verification to take effect
The Supreme Court has permitted a Texas law requiring app age verification to take effect. Advocacy and technology trade groups had sought an emergency stay of the Texas App Store Accountability Act.

Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers
A sophisticated threat group, believed to be operating from China, is actively exploiting security weaknesses in Roundcube webmail servers. Their objective is to gain unauthorized access to university networks across the United States and Canada, with the ultimate goal of stealing user login information.

Britain plans to build autonomous AI 'Cyber Shield' to defend nation
Britain is developing an autonomous AI-powered Cyber Shield to strengthen national defense against cyber threats. The National Cyber Security Centre says such a system is needed as attackers could operate at machine speed and scale.

'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows
A vulnerability dubbed GitLost leaks private data from GitHub Agentic Workflows. An unauthenticated attacker can craft a public GitHub Issue to silently exfiltrate data from private repositories.

Spain arrests suspected member of pro-Russian hacktivist groups
Spanish authorities have arrested an individual suspected of active membership in pro-Russian hacktivist groups, reportedly including CyberArmy of Russia Reborn and Z-Pentest.

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC. "The campaign did no

Qualys Joins Cisco Cloud Control Studio as a Launch Partner to Bring Risk Intelligence to Agentic Operations
Qualys has partnered with Cisco to integrate its risk intelligence capabilities into Cisco's new Cloud Control Studio platform. This collaboration aims to provide joint customers with unified asset inventory, prioritized vulnerability findings, and automated remediation workflows directly within Cisco's AI-driven operational environment. The integration is designed to help security teams manage expanding attack surfaces and overwhelming alert volumes by providing context and enabling faster, more efficient responses.

Major Japanese telco says cyberattack exposed 12 million emails
A major Japanese telecommunications company reported a cyberattack that exposed 12 million email accounts. The breach hit an email system managing accounts, webmail, and storage across five internet service providers.

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
Noma Security demonstrated that a public GitHub Issue can trick GitHub Agentic Workflows into leaking private repository data. A seemingly innocuous issue on a public repo can be crafted to exfiltrate private contents.

The GitHub Actions Attack Pattern Your CI Security Scanners Miss
ActiveState detailed a GitHub Actions attack pattern that often bypasses traditional CI security scanners. The analysis explains how these attack chains evade detection and how to better govern CI/CD pipelines.

Fake Netflix, Coca-Cola, and FIFA job scams target marketers
Scammers are impersonating well-known brands like Netflix, Coca-Cola, and FIFA to target marketing professionals with fake job offers. The fraudulent websites use sophisticated techniques, including mimicking Google sign-in pop-ups and routing victims through legitimate services, to appear credible. This campaign has been active for at least five months, exploiting the competitive job market and the increasing use of AI in recruitment.

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
A court filing revealed that a persistent Windows device ID helped the FBI trace an alleged Scattered Spider hacker. The identifier linked the suspect to a break-in at a luxury jewelry retailer.

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
A now-patched critical session isolation flaw was found in the enterprise generative-AI platform Writer. It could have let agent previews leak session tokens, enabling cross-tenant compromise.

CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws
CISA is reportedly using Anthropic Mythos AI to scan government software for vulnerabilities. The audits are said to be led by the agency Attack Surface Evaluation team to strengthen federal security reviews.

UK cyber pledge draws only a handful of top firms despite ministerial appeal
A UK government cyber pledge attracted only a handful of major companies despite a ministerial appeal. Notable signatories include Aviva, the London Stock Exchange Group, and Marks & Spencer.

Cloudflare proudly joins the UK government's Cyber Resilience Pledge
The UK government has introduced a voluntary Cyber Resilience Pledge, encouraging organizations to adopt strong cybersecurity governance and supply chain security. Cloudflare is among the first to sign, aligning with the pledge's principles of democratizing security, leadership accountability, and transparency. This initiative comes as the UK faces increasing cyber threats, including a rise in DDoS attacks and the growing influence of AI in cybercrime.

Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud
Two individuals were arrested over a phishing operation that harvested credit card details. The arrests come as the Netherlands is named the worst country in Europe for payment fraud.

Critical Adobe ColdFusion Vulnerability Exploited in Attacks
A critical Adobe ColdFusion vulnerability, CVE-2026-48282 with a maximum CVSS score of 10, is being actively exploited in attacks. The flaw poses a severe risk to affected systems.

Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks
An Iran-linked threat actor is using an adaptable modular command-and-control framework in cyberattacks. It compromised IT service providers to reach high-value targets primarily in Israel.

Webinar tomorrow: Why modern email attacks require a new approach to defense
A webinar examines why modern email attacks require new defenses. It highlights behavioral AI for detecting phishing, business email compromise, and account takeover while reducing alert fatigue.

New Januscape Linux flaw allows VM escape on Intel, AMD devices
A newly identified Linux kernel vulnerability, dubbed Januscape, allows virtual machine escape on Intel and AMD systems. The 16-year-old flaw lets attackers break out of a VM and run code on the host.

Cyber Shield: The path to an agentic AI future for cyber defence
The UK's GCHQ has unveiled 'Cyber Shield,' a blueprint for a national cyber defence capability integrating agentic AI. This initiative aims to counter escalating cyber threats by enabling machine-speed identification, reduction, and resolution of national cyber risks. Cyber Shield will foster collaboration across sectors to develop and deploy AI-powered defensive agents, enhancing the UK's resilience against both current and future sophisticated attacks.

CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker
A profile interview features Tarah Wheeler, Chief Information Security Officer of TPO Group, discussing her career and perspectives on cybersecurity leadership.