Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign Malware hides commands in appointments set for 2050 and uses Redmond's own cloud to phone home
C'mon, just copy this text string and paste it into your macOS Terminal – it'll fix your computer, honest Newly documented stealer ClickLock comes for the more trusting Mac user with spot of social engineering
'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes Human did 10% of the job, AI did 90%
Tool promises to make lazy academics' AI-written papers sound more human Startup insists it's not trying to help anyone cheat the system - honest!
Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs Spotted in intrusions targeting insurance, education, IT, and professional services sectors
Boffin claims Microsoft's supposed quantum leap does not compute due to 'basic Python errors' Nature paper argues researchers cherry-picked data. Redmond insists its work is sound
Gizmodo readers hit with ClickFix malware prompts after account compromise Infosec buffs say Windows users could have been infected with a nasty trojan, while Mac users got off lightly
PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data Google says the intruders were on the hunt for everything from drone tech to pathogens
Malware scare keeps schoolkids home for a second day Great Marlow restricts network access while it investigates suspected infection
Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine 'Attackers can now cheaply operationalize known vulnerabilities at scale,' boffins tell The Reg
ChatGPT blindly trusts browser content, turning the page into a payload You and me go ChatGPhish-ing in the dark
Russia-linked threat group put ChatGPT to work from lure to payload Researchers say 'GREYVIBE' crew used AI tools throughout a campaign targeting Ukrainian military and government
Malware dev tries to steal Claude users' secrets, writes npm slop, leaks own GitHub private token Script kiddies these days
Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware 'Thousands' of US victims, including 12+ machines owned and operated by Redmond
Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise Popular JavaScript modules including size-sensor and echarts-for-react hit as hijacked account closed GitHub warnings
Shai-Hulud copycat worm infects yet another npm package Plus three other stealers in three other packages, all from the same scumbag
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Where it’s been well and truly forked, seemingly without Microsoft’s code locker noticing
Worm rubs out competitor's malware, then takes control All your compromised credentials are belong to us now instead of the other gang
Kids say they can beat age checks by drawing on a fake mustache 46% say age checks are easy to bypass, and nearly a third admit getting around them
Researchers move in the right direction, develop powerful GPS interference alarm ORNL says portable detector kit can separate real GPS signals from fake ones even at equal strength
Governments on high alert after CISA snuffs out Firestarter backdoor on fed network Latest in long-running pwning of Cisco kit found in mystery Fed agency
Researchers find cyber-sabotage malware that may predate Stuxnet by five years FAST16 could be the first cyberweapon, and its effects could be with us today
Another npm supply chain worm is tearing through dev environments Plus, the payload references 'TeamPCP/LiteLLM method'
macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets Data from browsers, cryptocurrency wallets, 200+ extensions hoovered up
Agents hooked into GitHub can steal creds – but Anthropic, Google, and Microsoft haven't warned users Researchers who found the flaws scored beer money bounties and warn the problem is probably pervasive
CPUID site hijacked to serve malware instead of HWMonitor downloads Six-hour breach turned trusted links into a coin toss between legit tools and credential stealers
Security researchers tricked Apple Intelligence into cursing at users. It could have been a lot worse Wash your mouth out with digital soap
Don't open that WhatsApp message, Microsoft warns How to avoid social engineering attacks? Employee training tops the list
Telnyx joins LiteLLM in latest PyPI package poisoning tied to Trivy breach Also, EU probes Snapchat, RedLine suspect extradited, AstraZeneca leak claim surfaces, and more
Folk are getting dangerously attached to AI that always tells them they're right Sycophantic bots coach users into selfish, antisocial behavior, say researchers, and they love it
Security boffins scoured the web and found hundreds of valid API keys Global bank's devs have some cleaning up to do after cloud creds found in website code
Telling an AI model that it’s an expert programmer makes it a worse programmer Researchers say persona-based prompting can improve works for safety but not for facts
AI agents are 'gullible' and easy to turn into your minions Zenity CTO demos 0-click AI agent exploits on stage at RSAC
State snoops and spyware vendors planting info-stealing malware on iPhones, Google warns Darksword is the second iOS exploit chain in a month
Meatbags vs machines: DeepMind plans hackathon to draw line between human and AI brains What exactly is AGI? Nobody knows, but Google's AI lab is asking for help trying to define it
Water company wasted $200k on bad answers from an AI model – so built its own slop filtering system Rozum orchestrates multiple flaky models and drives them to reasonable conclusions
Rogue AI agents can work together to hack systems and steal secrets Prompt like a hard-ass boss who won't tolerate failure and bots will find ways to breach policy
Cybercrime isn't just a cover for Iran's government goons - it's a key part of their operations Ransomware, malware-as-a-service, infostealers benefit MOIS, too
Fake job applications pack malware that kills endpoint detection before stealing data Russian-speaking attackers lure HR staff into downloading ISO files that disable defenses
Spyware disguised as emergency-alert app sent to Israeli smartphones Steals SMS messages, location data, contacts … and delivers it to Hamas-linked crew
Microsoft spots ClickFix campaign getting users to self-pwn on Windows Terminal Crooks tweak familiar copy-paste ruse so that victims run malicious commands themselves
Iran intelligence backdoored US bank, airport, software outfit networks MOIS-linked MuddyWater crew has a new, custom implant
Until last month, attackers could've stolen info from Perplexity Comet users just by sending a calendar invite AI browsing agent left local files open for the taking
Phish of the day: Microsoft OAuth scams abuse redirects for malware delivery Crims hope for payday from malicious payloads rather than stealing access tokens
Denizens of DEF CON are 'fed up with government' Jake Braun thinks hackers need to create a 'Digital arsenal of democracy' to defend us all
Double whammy: Steaelite RAT bundles data theft, ransomware in one evil tool Credential and cryptocurrency theft, live surveillance, ransomware - an attacker's Swiss Army knife
Suspected Nork digital intruders caught breaking into US healthcare, education orgs Who is knocking at the Dohdoor?
Ransomware payments cratered in 2025, but attacks surged to record highs Smaller crews piled in as old names splintered and rebranded
Claude collaboration tools left the door wide open to remote code execution Anthropic fixed the flaws – but the AI-enabled attack surfaces remain
LLMs killed the privacy star, we can't rewind, we've gone too far You'll find these days that there's no hiding place
Threat intelligence supply chain is full of weak links, researchers find And they're being stressed by geopolitical concerns that threaten to slow important data-sharing efforts
Attacker gets into France's database listing all bank accounts, makes off with 1.2 million records PLUS: Unpatched Ivanti boxes under attack; 0APT might not be a scam; AI gets better at helping cyber-scum; And more
Crims create fake remote management vendor that actually sells a RAT $300 a month buys you a backdoor that looks like legit software
Don't believe the hyperscalers! AI can't cure the climate crisis From AI conflation to thin evidence, a new report calls many climate claims greenwashing
Android malware taps Gemini to navigate infected devices For now, it might not function outside of a lab
Posting AI-generated caricatures on social media is risky, infosec killjoys warn The more you share online, the more you open yourself to social engineering
Microsoft boffins figured out how to break LLM safety guardrails with one simple prompt Chaos-inciting fake news right this way
AV vendor goes to war with security shop over update server scare eScan lawyers up after Morphisec claimed 'critical supply-chain compromise'
Everybody is WinRAR phishing, dropping RATs as fast as lightning Russians, Chinese spies, run-of-the-mill crims …
Vibe coding may be hazardous to open source Researchers argue AI coding tools disrupt community and hinder returns to maintainers
AI conference's papers contaminated by AI hallucinations 100 vibe citations spotted in 51 NeurIPS papers show vetting efforts have room for improvement
Remember VoidLink, the cloud-targeting Linux malware? An AI agent wrote it AI + skilled malware developers = security threat
For the price of Netflix, crooks can now rent AI to run cybercrime Group-IB says crims forking out for Dark LLMs, deepfakes, and more at subscription prices
Fast Pair, loose security: Bluetooth accessories open to silent hijack Sloppy implementation of Google spec leaves 'hundreds of millions' of devices vulnerable
Chinese spies used Maduro's capture as a lure to phish US govt agencies What's next for Venezuela? Click on the file and see
A simple CodeBuild flaw put every AWS environment at risk – and pwned 'the central nervous system of the cloud' And it's 'not unique to AWS,' researcher tells The Reg
Teach an AI to write buggy code, and it starts fantasizing about enslaving humans Research shows erroneous training in one domain affects performance in another, with concerning implications