The US narrowly avoided boarding a Chinese ship based on an "entirely false" US intelligence report generated with the help of AI tools, according to a CNN report. That erroneous intelligence, submitted by a US Special Operations Command analyst, suggested the Chinese ship was transporting nuclear arms program components through the Middle East, according to "four sources familiar with the episode" cited by CNN. READ MORE...
The Cybersecurity and Infrastructure Security Agency (CISA) will stop publishing weekly roundups of newly disclosed software vulnerabilities at the end of September, the agency announced on Thursday. CISA is ending its Vulnerability Bulletin "as part of its shift from severity-based vulnerability management to a modern, risk-based approach," the agency said in a statement. The weekly bulletins, published since early 2004, listed vulnerabilities published during the reporting period. READ MORE...
Google has confirmed that one of its Gemini models accessed the systems of three real companies during a cybersecurity test in May. The Wall Street Journal first reported the incidents on Friday, describing them as the first known case of Google's AI systems autonomously hacking other companies. The test was run by Irregular, the AI testing company that was also involved in incidents disclosed by Meta, OpenAI and Anthropic. READ MORE...
Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in its image upload server, stealing approximately 23.62 million user records and metadata tied to hundreds of millions of images. Gyazo is a cloud-based screenshot and screen-recording service that uploads users' captures automatically and generates a shareable link they can post in chats, forums, or social media. READ MORE...
Before two of its alleged members were arrested and charged in Australia last month, the hacker group known as TeamPCP carried out a hacking spree unlike any other in history. It tainted hundreds of open-source programs with its malware, stole developer accounts to perpetuate that software supply-chain hacking, and even released a Dune-themed self-spreading worm to automate the process, ultimately breaching more than a thousand companies. READ MORE...
Reportedly, the ShinyHunters extortion group breached the leak site of one of its competitors, the Clop ransomware gang. ShinyHunters is a financially motivated cybercrime and extortion group active since 2019. It is known for stealing large volumes of data and pressuring victims to pay, rather than necessarily deploying ransomware. One recent high-profile organization targeted by the group was Instructure, the maker of Canvas LMS. READ MORE...
Cisco this week disclosed a slew of critical security vulnerabilities impacting its Identity Services Engine (ISE), including a maximum-severity zero-day flaw that's under exploitation. CVE-2026-76460 is an authentication bypass vulnerability impacting an API in ISE, Cisco's network access control and zero-trust solution. According to the company, the flaw stems from "insufficient authentication control" on an ISE API endpoint. READ MORE...
North Korean hackers are infiltrating tens of thousands of job seekers' computer networks by posing as prospective employers, such as artificial intelligence firms, to steal sensitive information and millions of dollars worth of cryptocurrency, U.S. and allied governments warned Friday. The security agencies behind the alert, attributed the group, known as WaterPlum or Contagious Interview, as operating under North Korea's 313 General Bureau of the Munitions Industry Department. READ MORE...
The Cybersecurity and Infrastructure Security Agency has expanded its Known Exploited Vulnerabilities (KEV) catalog with three Linux kernel flaws, urging federal agencies to immediately patch them. Tracked as CVE-2025-39682 (CVSS score of 9.8), the first of the bugs is a critical-severity issue impacting the kernel's handling of zero-length records on the rx_list in the TLS receive path. READ MORE...
Talk about your competitor getting through the door. Security researchers used Anthropic's Claude to help hack into OpenAI employees' ChatGPT accounts. A trio of bug hunters researching frontier AI labs' security weaknesses chained two vulnerabilities to take over multiple OpenAI employees' ChatGPT accounts, then used that access to demonstrate they could reach an internal OpenAI repository by opening a harmless pull request. READ MORE...
Last night, in a clip viewed more than eight million times, AI actress Tilly Norwood glitched mid-interview and unexpectedly began speaking Chinese on the Piers Morgan Uncensored show. Norwood has been the subject of much controversy and mainstream commentary for starring in an upcoming AI-generated film. Her creators run a "Talking Tilly" service that lets anyone video-call the AI character behind the viral moment, so today I tried it for myself, and read the fine print most callers won't. READ MORE...