LIVE · cybersecurity feed
Live wire

News Archive

555 stories · page 21 of 24

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

azurehigh

Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

Microsoft has made Azure AD Graph Activity Logs available for ingestion into Elastic, enabling threat detection within SIEM/XDR solutions. Previously, this critical telemetry was largely inaccessible to customers, leaving a significant visibility gap for defenders. This development allows for the monitoring of adversary activities that leverage the legacy graph.windows.net surface, which remained unlogged until recently.

security

Close Encounters of the Human Kind

In the latest Threat Source, Hazel channels her inner Spielberg to explore why humans are delightfully irrational, reminding us that while security best practices are simple in theory, they’re a lot harder to pull off when you’re busy deali

malware

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers

fortinethigh

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways

The UK's National Cyber Security Centre has released guidance for organizations utilizing Fortinet products. This advisory comes in response to a widespread campaign that has been observed targeting Fortinet firewalls and VPN gateways.

ai

Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model

Cisco Talos detailed a new approach to reverse engineering that pairs local AI agents with traditional analysis tools like the VB6 disassembler vbdec. Instead of awkwardly bolting AI onto the software, vbdec exposes its parsed data through

CVE-2026-35273critical

Oracle Releases June Patch Update Addressing 243 Vulnerabilities

Oracle has issued its June Critical Security Patch Update, resolving 243 unique CVEs with 245 security patches. A significant portion, 122 patches, are rated as critical severity. The Oracle Fusion Middleware product family received the largest number of fixes, with 106 patches.

phishing

Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed

What if your AI coding assistant could be tricked into stealing your own company's secrets - by reading a single booby-trapped bug report? No phishing email. No malware. No password ever stolen. Just an AI doing exactly what it was told. Me

cybersecurityhigh

NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK's critical systems

The CEO of the UK's National Cyber Security Centre stated that three-quarters of cyber threats targeting the nation's critical infrastructure originate from hostile state actors. This alarming statistic was revealed during a security lecture, underscoring the significant geopolitical dimension of cyber warfare.

breach

Maine forced to take down data breach portal after fake notices filed with authorities

The US state of Maine has taken its public data breach notification portal offline after someone submitted fraudulent breach disclosures impersonating two well-known technology companies. Read more in my article on the Hot for Security blog

patch

Weekly Update 508

Light switches. How on earth is it so hard to find decent light switches?! It sounds ridiculous until you actually spend enough time looking for ones that meet two simple criteria: Aren't stateful (switch is up or down, has to be push-butto

breach

Privacy own-goal: World Cup blunder leaks Lionel Messi’s passport details

Argentina's World Cup squad had their passport numbers leaked before a ball was kicked - not by hackers, but by someone who failed to redact a document properly. document. It's a mistake that has been made many times in the past... Read mor

security

A tale of two eras

In this week’s newsletter, Amy reminisces on the tech toys of their childhood, inspired by a hilarious lesson about why your digital privacy shouldn't be left on an open channel.

security

Silent Ransom Group: what you need to know

Most extortion gangs hide behind a keyboard. Silent Ransom Group will phone your staff pretending to be IT support - and if that fails, send someone to your office in person to plug in a USB stick. Read more in my article on the Fortra blog

ai

AI Could Revolutionize Cybersecurity Analysis and Defense

A keynote speaker argued that cybersecurity is moving beyond its experimental phase due to increasing complexity and reliance on human attention. The speaker suggested that large language models offer a scalable solution by providing cheap, abundant evaluative power, enabling defenders to analyze and act more efficiently. This shift could lead to more automated, standardized, and sustainable security practices by integrating artificial intelligence with human expertise.

malwarehigh

Threat Actors Weaponize AI Hype to Deliver AsyncRAT

Malicious actors are exploiting the current interest in artificial intelligence by distributing malware. They are using deceptive AI-themed documents that contain hidden scripts to install AsyncRAT, a tool that grants them remote control over compromised systems.

ai

Smashing Security podcast #471: This AI worm just rewrote its own rules

Researchers at the University of Toronto have built a worm that thinks for itself. Using free off-the-shelf AI models it works out how to break into each new computer it encounters, and hijacks the powerful ones to host its own AI brain. An

ransomware

Who Runs the Ransomware Group ‘The Gentlemen?’

A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of

ransomware

Why schools remain one of cybercriminals’ favourite targets

Schools on both sides of the Atlantic have been revealed in recent days to have been hit by hackers, reminding all of us that ransomware gangs see educational instituions as targets all year round. Read more in my article on the Hot for Sec

breach

Weekly Update 507

1,000 breaches is one hell of a milestone. It's not just the process of getting data, verifying it, loading it, sending notifications etc, it's all the other stuff that goes into keeping the whole thing afloat. Legal docs. Trademarks. Accou

patchcritical

A Record-Breaking Patch Tuesday for June 2026

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bug

vulnerability

Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities

Microsoft Patch Tuesday details for June 2026.

security

Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5

If you've ever received an out-of-the-blue message via LinkedIn from a recruiter offering some well-paid consultancy work, intelligence agencies have a message for you: be very careful. Read more in my article on the Hot for Security blog.

ai

Meta’s own AI chatbot to blame for Instagram accounts being stolen in seconds

Hackers have been hijacking Instagram accounts at scale by exploiting Meta's AI support chatbot. And, as if that weren't bad enough, the technique required no technical skill whatsoever. Read more in my article on the Fortra blog.

ai

Reporting from Vegas: Networking, AI, and good boys

Joe’s on-the-ground report from Cisco Live U.S. is here, complete with therapy dog pictures and tips on handling conference overstimulation.