News Archive
1920 stories · page 78 of 80Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways
The UK's National Cyber Security Centre has released guidance for organizations utilizing Fortinet products. This advisory comes in response to a widespread campaign that has been observed targeting Fortinet firewalls and VPN gateways.

Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model
Cisco Talos detailed a new approach to reverse engineering that pairs local AI agents with traditional analysis tools like the VB6 disassembler vbdec. Instead of awkwardly bolting AI onto the software, vbdec exposes its parsed data through

Oracle Releases June Patch Update Addressing 243 Vulnerabilities
Oracle has issued its June Critical Security Patch Update, resolving 243 unique CVEs with 245 security patches. A significant portion, 122 patches, are rated as critical severity. The Oracle Fusion Middleware product family received the largest number of fixes, with 106 patches.

Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed
What if your AI coding assistant could be tricked into stealing your own company's secrets - by reading a single booby-trapped bug report? No phishing email. No malware. No password ever stolen. Just an AI doing exactly what it was told. Me

NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK's critical systems
The CEO of the UK's National Cyber Security Centre stated that three-quarters of cyber threats targeting the nation's critical infrastructure originate from hostile state actors. This alarming statistic was revealed during a security lecture, underscoring the significant geopolitical dimension of cyber warfare.

Maine forced to take down data breach portal after fake notices filed with authorities
The US state of Maine has taken its public data breach notification portal offline after someone submitted fraudulent breach disclosures impersonating two well-known technology companies. Read more in my article on the Hot for Security blog

Weekly Update 508
Light switches. How on earth is it so hard to find decent light switches?! It sounds ridiculous until you actually spend enough time looking for ones that meet two simple criteria: Aren't stateful (switch is up or down, has to be push-butto

Privacy own-goal: World Cup blunder leaks Lionel Messi’s passport details
Argentina's World Cup squad had their passport numbers leaked before a ball was kicked - not by hackers, but by someone who failed to redact a document properly. document. It's a mistake that has been made many times in the past... Read mor

A tale of two eras
In this week’s newsletter, Amy reminisces on the tech toys of their childhood, inspired by a hilarious lesson about why your digital privacy shouldn't be left on an open channel.

Silent Ransom Group: what you need to know
Most extortion gangs hide behind a keyboard. Silent Ransom Group will phone your staff pretending to be IT support - and if that fails, send someone to your office in person to plug in a USB stick. Read more in my article on the Fortra blog

AI Could Revolutionize Cybersecurity Analysis and Defense
A keynote speaker argued that cybersecurity is moving beyond its experimental phase due to increasing complexity and reliance on human attention. The speaker suggested that large language models offer a scalable solution by providing cheap, abundant evaluative power, enabling defenders to analyze and act more efficiently. This shift could lead to more automated, standardized, and sustainable security practices by integrating artificial intelligence with human expertise.

Threat Actors Weaponize AI Hype to Deliver AsyncRAT
Malicious actors are exploiting the current interest in artificial intelligence by distributing malware. They are using deceptive AI-themed documents that contain hidden scripts to install AsyncRAT, a tool that grants them remote control over compromised systems.

Smashing Security podcast #471: This AI worm just rewrote its own rules
Researchers at the University of Toronto have built a worm that thinks for itself. Using free off-the-shelf AI models it works out how to break into each new computer it encounters, and hijacks the powerful ones to host its own AI brain. An

Who Runs the Ransomware Group ‘The Gentlemen?’
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of

Why schools remain one of cybercriminals’ favourite targets
Schools on both sides of the Atlantic have been revealed in recent days to have been hit by hackers, reminding all of us that ransomware gangs see educational instituions as targets all year round. Read more in my article on the Hot for Sec

Weekly Update 507
1,000 breaches is one hell of a milestone. It's not just the process of getting data, verifying it, loading it, sending notifications etc, it's all the other stuff that goes into keeping the whole thing afloat. Legal docs. Trademarks. Accou

A Record-Breaking Patch Tuesday for June 2026
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bug

Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities
Microsoft Patch Tuesday details for June 2026.

Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5
If you've ever received an out-of-the-blue message via LinkedIn from a recruiter offering some well-paid consultancy work, intelligence agencies have a message for you: be very careful. Read more in my article on the Hot for Security blog.

Meta’s own AI chatbot to blame for Instagram accounts being stolen in seconds
Hackers have been hijacking Instagram accounts at scale by exploiting Meta's AI support chatbot. And, as if that weren't bad enough, the technique required no technical skill whatsoever. Read more in my article on the Fortra blog.

Reporting from Vegas: Networking, AI, and good boys
Joe’s on-the-ground report from Cisco Live U.S. is here, complete with therapy dog pictures and tips on handling conference overstimulation.

Cybercriminals Are Targeting the FIFA World Cup 2026
Cybercriminals are leveraging the upcoming FIFA World Cup 2026 to conduct various malicious activities. These attacks include phishing campaigns, the distribution of fake tickets, malware deployment, impersonation tactics, and attempts to steal user credentials.

Winning the cyber marathon with Tony Giandomenico
Tony Giandomenico, Senior Director of Product Management, joins Amy to discuss the Talos Threat Hunting launch what he's excited about for the future of cybersecurity, and, of course, his Ironman triathlons.

Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting
Learn how Cisco Talos Threat Hunting uses hypothesis-driven methods and multi-domain telemetry correlation to find stealthy threats operating below automated detection thresholds.