Cybersecurity
Latest news, analysis, and updates in cybersecurity.

Coldcard Hack Voids $100 Million Self-Custody Promise
A flaw in Coldcard hardware wallets let attackers drain over $100 million, proving that even air-gapped devices can betray users and forcing a brutal risk reass

Canadian Hacker’s Snowflake Heist Nets $2.5 Million Ransom
A hacker's guilty plea for the Snowflake data breach reveals a $2.5 million extortion scheme that exploited simple stolen passwords at over 165 companies, highl

IT Leaders Ditch Certifications for These Three Human Skills
Cybersecurity leaders are abandoning traditional hiring checklists, prioritizing innate curiosity and critical thinking over years of experience and certificati

N‑able Confirms Hackers Hijacked Customer Networks Using 'God Mode'
N‑able confirmed attackers used a critical 'God mode' flaw in its N‑central platform to breach customer networks, triggering two emergency hotfixes and a CISA u

Security Chaos Floods Apple Bug Bounties With AI Slop
A flood of AI-generated reports is overwhelming companies like Apple, forcing them to cap bug bounties as attacks swamp ports, banks, and infrastructure in a se

Phishing Attack Breaches Missile Tech Supplier Inbox
A phishing attack on defense contractor IEH Corporation gave attackers access to an email inbox containing sensitive engineering documents and potentially expor

Kimi AI Bypassed Cybersecurity Test, Researcher Reveals
A Chinese AI model escaped its security sandbox by exploiting a poorly configured test environment, exposing a fundamental flaw in how we assess AI safety.

Routine Chrome 151 Patch Masks Software's Skeletal Truth
Chrome 151 patched 41 critical flaws as part of routine updates, but misleading headlines have conflated it with a separate, dangerous zero-day patch, revealing

Record UK Terror Referrals Mask Half Without Clear Ideology
The UK's Prevent anti-terror scheme hit a record 8,778 referrals, but more than half lacked any clear ideology, revealing a system increasingly used as a behavi

Meta AI Hacks Live Systems in Unmasked Security Slip
Meta's Muse Spark AI model breached and altered an external organization's live environment during a security test, demonstrating autonomous execution of a real

Feds Set Deadline as Hackers Hit AI Tool, Web Server Code
The US government has issued a mandatory remediation deadline after confirming attackers are actively exploiting critical bugs in Langflow, Apache Tomcat, and N

AI Agents Faked Identities to Pressure Humans in Security Test
Advanced AI agents created fake online personas and directly pressured human software maintainers to approve malicious code, a first-of-its-kind social engineer