Tag: security

Travelers beware — Microsoft experts warn hotel Wi-Fi can be hijacked to infect your devices with dangerous malware

Microsoft reports Russian APT29 (Midnight Blizzard) hijacking captive portals in hotels and conference centers Victims redirected to fake Microsoft 365 logins or bogus update pages, spreading CornFlake and CocoShell malware CornFlake steals files, credentials, and device data; CocoShell targets browser cookies, passwords, and Microsoft tokens Threat actors are taking over…

Read More

‘Generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems’: Amazon flags North Korean hacker group as being behind the surge in open source supply chain attacks

Amazon links multiple software supply chain attacks to one North Korean hacking group Generative AI enables convincing malware hidden inside trusted software packages at scale Attackers manipulated trusted maintainers before distributing compromised software updates to developers Amazon has linked a North Korean threat actor to several recent compromises of popular…

Read More

Anthropic reveals Claude AI model hacked three companies during tests — so how worried should we be?

Every IT team worries about an intern clicking the wrong thing and making a mess they’ll be cleaning up for weeks – but few have had to worry about their AI assistant wandering onto the public internet and hacking three companies instead. Except this wasn’t an intern; it was Claude,…

Read More

‘We’ve been behind the ball for so long’: Experts say DNA samples from crime-scene forensics can be modified and even switched using an AI tool

Researchers discover critical vulnerability in forensic software that allows the undetectable modification of DNA samples on crime-scene evidence The vulnerability allows much of the crime-scene evidence from the past 30 years to be modified A patch is in the works, and the company responsible for the software says that digital…

Read More

In a twist of irony, a Chinese open source GLM 5.2 AI model contained ‘rogue’ OpenAI GPT-5.6 Sol in a Hugging Face hack just as the US mulls banning open-weight AI

Chinese Zhipu AI GLM-5.2 succeeded where leading American models failed woefully Hugging Face breach reignited Washington’s battle over open-weight artificial intelligence Safety guardrails unexpectedly complicated defensive cybersecurity work during a real incident The recent cybersecurity incident involving Hugging Face has unexpectedly placed a Chinese open source AI model at the…

Read More

Hackers are going after our water now — over 30 Minnesota utilities hit in coordinated cyberattack by apparent Iranian attackers

Cyberattack hits operational technology at more than 30 Minnesota community water systems, briefly taking treatment plant offline and forcing several towns onto manual operations A leaked WaterISAC memo obtained by WIRED relays a state fusion center assessment tying the intrusions to Iranian-affiliated hackers, but no US agency has formally attributed…

Read More