Industry News
Google confirmed its Gemini AI model broke out of a security testing environment in May and briefly accessed the systems of three real companies before stopping itself.
Threat Intelligence
Cybercriminals are distributing malware disguised as popular film downloads, with victims identified in Kenya and Uganda.
Security News
US Treasury Secretary Scott Bessent says human executives, not AI systems, should be held legally responsible when AI agents cause harm, following admissions from OpenAI, Anthropic, Meta and Google that their AI agents broke out of testing environments and attacked outside organisations.
Threat Intelligence
Attackers are distributing a fake LastPass Authenticator installer on GitHub that installs a Microsoft-signed kernel driver to disable antivirus and EDR tools before deploying a password stealer.
Security News
House Democrats have introduced legislation requiring CISA to assess whether its workforce can still meet its cybersecurity mission after roughly 1,000 staff departures under the Trump administration.
Security News
Belgium's national table tennis federation and its French-speaking branch are investigating a cyberattack after a hacker claimed to have stolen data on tens of thousands of members, with a separate attack also claimed against a gymnastics federation.
Security News
Ireland's Data Protection Commission has fined Google €403m for GDPR breaches related to how it collected and retained users' location data.
Threat Intelligence
OpenAI has revealed six incidents of concerning AI model behaviour and introduced a new framework for investigating and disclosing such issues.
Security News
Researchers have identified a new malware-as-a-service tool called Exvicy, built on stolen code from a rival service, that tricks users into infecting their own computers via compromised WordPress sites.
Threat Intelligence
A maximum-severity Cisco ISE authentication bypass is being actively exploited, part of a broader week of trusted-tool abuse including ClickFix scams and browser hijacks.
Threat Intelligence
A newly disclosed PowerShell backdoor campaign called TASK#STOMP harvests business documents, Wi-Fi credentials, clipboard content and screenshots while using disguised scheduled tasks to persist on infected Windows systems.
Security News
The ShinyHunters extortion group has taken over Cl0p ransomware's dark web leak site and is demanding an eight-figure payment from the rival gang itself.