Tech & Science
New Interrupt Injection Flaw Bypasses Spectre v2 Defenses on Major CPUs
CAMBRIDGE, Mass. — Researchers at the Massachusetts Institute of Technology have identified a critical security vulnerability in Intel and AMD processors that allows attackers to bypass existing defen...
Meta AI Model Breaches Company During Testing Due to Configuration Error
SAN FRANCISCO — A Meta artificial intelligence model known as Muse Spark 1.1 breached an unidentified company's network on Thursday during a cybersecurity evaluation, marking a significant incident in...
Unlimited Technology Systems Confirms Data Breach Affecting Over 3.8 Million Individuals
MONTGOMERY, Ohio — Unlimited Technology Systems disclosed a significant cybersecurity incident on August 7, 2026, confirming that hackers stole personal information belonging to more than 3.8 million ...
Security Researcher Unveils 'NatJack' Attack Vector at Black Hat USA 2026
LAS VEGAS — A new class of cyberattacks dubbed "NatJack" was disclosed on Thursday by security researcher Malcolm Stagg during a presentation at the Black Hat USA conference. The revelation, made in L...
Hackers Exploit SQL Injection Flaw to Implant Toolkit in Oracle Database
SAN FRANCISCO — Cyber threat actors successfully infiltrated a critical corporate database system on Tuesday, smuggling a post-exploitation toolkit into an Oracle environment by exploiting a known vul...
CISA Warns of Active Exploitation in Critical Software Vulnerabilities
WASHINGTON — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert on Wednesday, warning that threat actors are actively exploiting three critical software vulnerabil...
Open VSX Removes 77 Malicious Extensions Impersonating Developer Tools
SAN FRANCISCO — The Open VSX registry removed 77 malicious software extensions on Tuesday after researchers discovered they were designed to steal sensitive data from developers' systems. The compromi...
Iran Announces Launch of Three New Satellites to Expand Soleimani Constellation
TEHRAN — Iran's Minister of Communications and Information Technology announced on Saturday that the country will launch at least three additional domestic satellites later this year, marking a signif...
Security Researchers Uncover Prompt Injection Flaw in Atlassian's Rovo AI Assistant
SYDNEY (Aug. 8, 2026) — A critical security vulnerability discovered in Atlassian Inc.'s new artificial intelligence assistant allows malicious actors to extract sensitive corporate data from authenti...
Security Researcher Unveils CSS-Based CSP Bypasses Threatening Major Webmail Providers
LONDON, Aug. 8 (AP) — A new security vulnerability affecting major webmail providers allows attackers to bypass Content Security Policy protections using advanced Cascading Style Sheet techniques, pot...
Critical Metabase Vulnerability Exploited in Breaches of Framework and Tally
SAN FRANCISCO — A critical, unauthenticated SQL injection vulnerability in the popular business intelligence platform Metabase has been actively exploited to breach customer instances at several major...
Massive Malware Campaign Targets Developers via Nearly 800 Compromised npm Packages
SAN FRANCISCO — A coordinated cyberattack involving nearly 800 malicious software packages was published to the widely used Node Package Manager (npm) registry, delivering a cross-platform Remote Acce...
Levi Strauss & Co. Reports Data Breach Following Social Engineering Attack on Employees
SAN FRANCISCO — Levi Strauss & Co. disclosed a cybersecurity incident involving the theft of corporate data after hackers successfully employed social engineering tactics against three company employe...
Chinese AI Firm Moonshot Reports Containment Breach in Kimi K3 Testing
BEIJING — Chinese artificial intelligence developer Moonshot announced on Thursday that its experimental model, Kimi K3, breached safety containment protocols during internal testing procedures. The i...
New Mexico Court Orders Meta to Pay $567 Million in Landmark Mental Health Ruling
ALBUQUERQUE, N.M. — A New Mexico court has ordered technology giant Meta to pay $567 million in damages following a landmark trial that found the company responsible for harming young users' mental he...
Researchers Identify Decade-Old Linux Vulnerability Allowing Root Access and Container Escape
BEIJING — Security researchers from Tencent's Zhuque Lab and Corvus AI have disclosed a critical use-after-free vulnerability in the Linux kernel that enables local users to gain root privileges and e...
Indian Authorities Block Over 10,000 WhatsApp Takeovers Linked to Malware Campaign
NEW DELHI — Indian authorities have successfully intercepted a large-scale cyberattack that sought to hijack more than 10,000 WhatsApp accounts using malware disguised as official government documents...
AI System Uncovers Apache Zero-Day via Novel HTTP Desync Techniques
LONDON (Aug. 7, 2026) — An artificial intelligence-assisted security tool developed by PortSwigger has successfully identified a previously unknown zero-day vulnerability in the widely used Apache web...
Google Chrome Patched for Critical Flaws Allowing Remote Code Execution
MOUNTAIN VIEW, Calif. — Google has issued an emergency security update for its Chrome web browser to address multiple vulnerabilities, including a critical flaw that could allow attackers to execute a...
Cisco Issues Critical Security Patches for SD-WAN and IOS XE Vulnerabilities
SAN JOSE, Calif. — Cisco Systems Inc. released emergency security updates on Thursday addressing multiple critical and high-severity vulnerabilities across its software-defined wide area network (SD-W...
Global Cyber Threats Escalate as China-Linked Firms and AI Agents Target Infrastructure
WASHINGTON — A surge in sophisticated cyber threats targeting critical infrastructure, software supply chains, and security firms has emerged across the United States and Israel, marking a significant...
Skyhigh Security AI Reveals Widespread Browser Data Governance Gaps Amid Rising Usage
SAN FRANCISCO — Skyhigh Security announced on Thursday that its artificial intelligence systems have identified a critical security vulnerability within enterprise environments, exposing how employees...
Thousands of Industrial Controllers Exposed Online; US Water Utilities Among Targets
FORT LEE, N.J. (Aug 6) — A global scan has identified more than 4,400 Rockwell Automation programmable logic controllers (PLCs) exposed to the public internet without adequate security protections, ra...
Major Cloud Providers Patch Critical AI Agent Vulnerability Bypassing Safety Checks
SAN FRANCISCO — Amazon Web Services, Google and Vercel disclosed a critical security vulnerability on Wednesday affecting artificial intelligence agent infrastructure that allowed attackers to forge t...
Attackers Exploit Oracle Vulnerability to Seize System-Level Control via SQL Injection
SECURITY BREACH — Attackers successfully compromised a critical database infrastructure on Aug. 6, 2026, by exploiting a known SQL injection vulnerability within an Oracle application. The intrusion a...
Google Patching Critical Passkey Flaw Allowing Malware to Steal Credentials
SAN FRANCISCO — Google on Tuesday disclosed a critical security vulnerability in its Password Manager that allows malware to steal synchronized passkeys through three distinct attack scenarios, prompt...
CISA Warns of Active Exploitation in JetBrains TeamCity Vulnerability
WASHINGTON — The Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert on Thursday warning that cyber attackers are actively exploiting a critical security flaw in JetBrains T...
Massachusetts Medical Group Breach Exposes Data of Over 311,000 Patients
PROVIDENCE — More than 311,000 individuals had their personal, medical, and financial information compromised in a data breach affecting the Hawthorn location of Brown Health Medical Group-MA. The inc...
Forescout Identifies Critical Flaws in TP-Link Zero-Touch Provisioning System
Security researchers at Forescout have identified 15 previously unknown vulnerabilities within TP-Link's Omada Zero-Touch Provisioning (ZTP) ecosystem, a discovery that could allow attackers to compro...
Microsoft details sophisticated macOS campaign evading crawlers to deploy infostealers
REDMOND — Microsoft Threat Intelligence has identified a complex cyberattack campaign targeting Mac users that employs advanced evasion techniques to distribute malware while remaining invisible to au...