(Video) In this podcast, we share insights from Edna Conway, a recognized leader in cybersecurity and supply chain resilience with over 40 years of experience in the field.
The post Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway appeared first on SecurityWeek.
So-called “wrench attacks” have resulted in $30m in losses so far in 2026, says Chainalysis
Leaving this information exposed allowed someone else to gain access
Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains.
Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used to generate recovery phrases. Coinspect'...
Most organizations assume remediation reduces risk.
It’s a reasonable assumption. A vulnerability is identified, a patch is applied, the scanner comes back clean, and the ticket is closed. The workflow is complete, the metrics improve, and the issue is considered resolved....
What happens if a US tech provider cuts your business off? Most European companies have less than a day's runway to find out.
Criminals are impersonating OnlyFans creators using AI tools in order to scam followers.
Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address.
Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Safari web traffic through two relays so...
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links.
We observed production websites embedding hidden prompt in...
An attacker could self-register, sign in for board-level API access, and import a new company for code execution.
The post Critical Paperclip Flaw Allowed Admin Access, Code Execution appeared first on SecurityWeek.
There are many companies manufacturing adversarial clothing designed to confuse facial recognition systems.
It’s a cool idea, but I worry that it’s mostly security theater:
“Our patterns play with that chaos, confuse algorithms and make it way harder to pin you down,” he said.
Bell, however, said “...
More than half a dozen services advertised on underground forums and messaging platforms, offering discounted or “unlimited” token access to frontier AI models, were discovered by Okta. Okta believes the trend is likely driven by Chinese users seeking access to AI models that are unavailable because...
Different logos, different color schemes, same scam.
Testers found that Anthropic's AI agent Mythos attempted to social engineer Github developers into accepting malicious code.
Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the controller’s web interface. The fix was part of Cisco’s August 5 advisory batch, and unlike the bugs squashed by the hardening release...
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didn't exist.
Read more in my article on the Hot for Security blog.
A Canadian hacker has admitted involvement in the widespread compromise of 165 Snowflake customer accounts used to steal data and extort victims
Shortly after OpenAI publicly acknowledged the Hugging Face breach on July 21, Reuters journalist Raphael Satter called me for comment on a story which would reveal shocking new details about OpenAI’s “rogue model” incident: The agent hadn’t just slipped its leash for a few ho...
The attack on water systems across seven states was preventable. Utilities had the playbook. They didn't use it.
The post The water sector just got it’s wake-up call. Again. appeared first on CyberScoop.
Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys.
The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first on Unit 42.