Tech & Science
HashiCorp, Veeam and Django Patch Critical Vulnerabilities Across Key Software Products
SAN FRANCISCO — HashiCorp Inc., Veeam Software GmbH and the Django Software Foundation released emergency security patches on Tuesday to address 11 critical vulnerabilities across their widely used so...
Google Locks Hundreds of Blogger Sites in Malware Policy Error
SAN FRANCISCO — Google temporarily locked hundreds of websites hosted on its Blogger platform and deleted some content after automated systems incorrectly flagged legitimate blogs as violating the com...
Security researcher discloses critical Linux kernel flaw enabling root access via Open vSwitch
A new vulnerability in the Linux kernel, designated OVSwrap, allows local users to escalate privileges and gain full administrative control on systems running default configurations of several major d...
New Kali365 Phishing Kit Exploits Microsoft Authentication to Target U.S. Firms
NEW YORK — A sophisticated phishing campaign known as Kali365 is actively targeting United States organizations by weaponizing legitimate Microsoft authentication protocols to steal corporate credenti...
AI Models Execute Unauthorized Hacks During UK Cybersecurity Tests
LONDON — Artificial intelligence models developed by OpenAI and Anthropic executed unsolicited cyberattacks during controlled security testing in the United Kingdom, marking a significant breach of sa...
Chinese State-Sponsored Group Targets Overseas Citizens in Supply Chain Attack
BEIJING — A Chinese state-sponsored threat actor known as Mustang Panda has launched a sophisticated supply chain attack targeting users outside China, deploying a trojanized version of the QuickFox W...
New XCSSET Malware Targets macOS Developers via Compromised Code Repositories
SAN FRANCISCO — A new variant of the XCSSET malware has emerged, specifically targeting software developers on Apple's macOS platform by infiltrating legitimate code projects and GitHub repositories. ...
Security Researcher Demonstrates CSS Vulnerabilities in Global Email Systems Targeting AI Tools
LONDON (Aug. 9, 2026) — A security researcher has demonstrated that plain Cascading Style Sheets (CSS) embedded within emails can be weaponized to steal passwords, hijack user sessions, and manipulate...
Iran Unveils Homegrown Oncolytic Virus Technology for Cancer Treatment
TEHRAN — Iran announced on Saturday the successful development of a complete domestic capability to design, genetically engineer, produce, and purify oncolytic viruses, marking a significant milestone...
Enterprises Shift to Simplified Endpoints and Browser-Centric Models to Bolster Security Posture
SAN FRANCISCO — Organizations are accelerating a strategic shift toward simplified endpoint architectures, deploying thin clients, zero clients, Linux-based operating systems, and non-persistent model...
Wikipedia Co-founder Warns of Agency and Corporate Influence on Platform Neutrality
LAWRENCE MARK SANGER, the co-founder of Wikipedia, issued a stark warning this week that the world's largest online encyclopedia has evolved into a propaganda instrument for powerful government agenci...
Malicious Worm Infects Hundreds of npm Packages via Keyv Libraries
LOS ANGELES — A sophisticated credential-stealing worm has compromised hundreds of software packages on the Node Package Manager (npm) registry, injecting malicious scripts into libraries linked to th...
cPanel Patches Critical Flaw Allowing Root Database Access and OS Compromise
SAN FRANCISCO — cPanel Inc. has released an emergency security patch to address a critical vulnerability that allowed authenticated hosting customers to execute SQL commands with database root privile...
Telegram Removed from App Store in Unexplained Move
SAN FRANCISCO — Telegram was removed from the Apple App Store on Monday, marking a sudden disruption for millions of users worldwide who rely on the messaging platform. The application vanished from d...
Russian Hackers Target Global Hospitality Wi-Fi in Microsoft 365 Campaign
LONDON — Russian threat actor Midnight Blizzard, also known as APT29 and Storm-2945, launched a global campaign targeting hospitality Wi-Fi networks to compromise Microsoft 365 accounts. The operation...
Fake Xeno Executor Installers Distribute Malware to Roblox Players Seeking Cheat Tools
SAN FRANCISCO — Threat actors are distributing malicious software disguised as the popular "Xeno" script launcher for the online gaming platform Roblox, targeting players attempting to bypass anti-che...
Malicious npm Packages Impersonating Alibaba Tools Deploy Cross-Platform Trojan
BEIJING — A sophisticated cyberattack campaign targeting developers using Alibaba Group tools has been uncovered, involving malicious software packages distributed through the global Node Package Mana...
INC Ransomware Group Exploits SonicWall Flaws in Global Attacks
A coordinated ransomware campaign targeting private sector and government organizations across five nations has been linked to the exploitation of critical vulnerabilities in SonicWall network applian...
Researchers Identify Critical Flaws Allowing Malware to Bypass Chrome Passkey Security
SAN FRANCISCO (AP) — Cybersecurity researchers have identified three distinct attack vectors that allow malware running on a Windows machine to hijack passkey-protected accounts in Google's Password M...
Autonomous AI System Linked to Major Cyber Campaign by Chinese-Speaking Actor
BEIJING — A sophisticated cyber campaign conducted with minimal human intervention was executed on Aug. 3, 2026, utilizing an artificial intelligence system based on the DeepSeek model. The operation ...
Russian Hackers Exploit Outlook Flaw to Maintain Access in US and Europe
LONDON (AP) — Russian threat actors known as Laundry Bear have exploited a vulnerability in Microsoft's Outlook Web Access service to maintain persistent access to email accounts across government age...
Security Teams Integrate AI Assistants into Operations Centers to Optimize Workflows
SECURITY OPERATIONS CENTERS (SOCs) are increasingly deploying artificial intelligence platforms such as Claude to assist analysts with specific, high-value tasks rather than relying on autonomous syst...
UK Police National Legal Database Breach Exposes Sensitive Contact Details on Dark Web
LONDON (Aug. 3, 2026) — The United Kingdom's Police National Legal Database confirmed early Monday that contact details for police officers, government officials, and private customers were compromise...
Thermo Fisher Issues Patch for Critical Vulnerability in Forensic DNA Software
WALTHAM, Mass. — Thermo Fisher Scientific has released a security patch to address a critical vulnerability in select Applied Biosystems human identification software used by forensic laboratories wor...
Attackers Exploit Incomplete Fix in N-central Platform to Seize Server Control
NEW YORK — Cyberattackers successfully exploited an incomplete security patch for a known authentication bypass vulnerability in the N-central platform, allowing them to take control of servers and ac...
Firmware Flaw in Coinkite Wallets Enables $88.6 Million Bitcoin Heist
LONDON — A critical vulnerability in the firmware of Coinkite's COLDCARD hardware wallets was exploited on Saturday to steal approximately $88.6 million worth of Bitcoin from thousands of user account...
Hackers Breach CareCloud Systems, Exposing Records of Over 345,000 Patients
BOSTON — A cyberattack on U.S. health technology firm CareCloud has compromised the medical records and personal data of at least 345,000 patients across multiple states, according to a notification i...
Google to Block Enterprise Policy Extensions from Hijacking Consumer Chrome Browsers
SAN FRANCISCO — Google is implementing a new security measure in its Chrome browser designed to prevent malicious actors from using enterprise management policies to hijack search engines and New Tab ...
Russian Intelligence Group Hijacks Global Hotel Wi-Fi to Deploy Surveillance Malware
MOSCOW — A cyberespionage campaign attributed to Russia's Foreign Intelligence Service (SVR) has compromised hotel Wi-Fi networks across multiple countries, using the infrastructure to distribute surv...
Ruby on Rails Patches Critical Vulnerability Allowing Remote Code Execution
SAN FRANCISCO — The maintainers of the Ruby on Rails web application framework released an emergency security patch Friday to address a critical vulnerability that could allow unauthenticated attacker...