Tag: security

Hundreds of free VPN apps are not fit for purpose – but sadly, we can’t tell you which are the naughty ones

Many free VPNs act like spyware, collecting sensitive user information Several apps misuse permissions, turning privacy tools into tracking systems VPN developers often justify excessive access with misleading security explanations The growing popularity of free VPN apps has provided mobile users with an easy path to privacy – however, new…

Read More

Worrying Figma MCP security flaw could let hackers execute code remotely – here’s how to stay safe

CVE-2025-53967 allows remote code execution via figma-developer-mpc command injection flaw Vulnerability stems from unvalidated input passed to shell commands using child_process.exec Users should upgrade to version 0.6.3 or switch to safer child_process.execFile API A vulnerability has been found on the bridge between Figma and AI agents which could be used…

Read More

‘Bring your own device is the norm’: BYOD has reached epidemic levels as more workers use their personal smartphone for work – and businesses scramble to catch up

BYOD is now widespread, with security teams struggling to manage, report claims Edge devices remain exposed as research shows 40% are unmanaged across firms Zero trust adoption lags as employees continue using personal devices despite company policies Bring your own device (BYOD) is becoming the rule rather than the exception…

Read More

Living on the AI-edge: 60% of IT and security pros are considering leaving their jobs because of rising cyber threats – with many feeling hopeless and overwhelmed

Complex recovery tools make already exhausted IT staff lose confidence fast, report finds Many experts now see AI tools as another layer of stress The fear of personal blame drives deep anxiety across cybersecurity teams The pressure on IT and cybersecurity professionals is intensifying as the scale and sophistication of…

Read More

DeepMind’s latest AI tool wants to detect and repair software vulnerabilities before they get attacked

CodeMender automatically generates AI-reviewed security patches for open source projects Google DeepMind says CodeMender reduces vulnerability workloads through code validation DeepMind plans wider developer release once CodeMender’s reliability is confirmed Google DeepMind has revealed CodeMender, an artificial intelligence agent it says can automatically detect and fix software vulnerabilities before they…

Read More

Hackers claim to have stolen over a billion Salesforce records – and are demanding nearly $1 billion not to leak them

Scattered Lapsus$ Hunters launch data leak site to pressure victims into ransom negotiations Attackers exploited Salesloft’s Drift app to access Salesforce customer data, not Salesforce itself Victims include Cloudflare, Zscaler, Tenable; Salesforce denies platform compromise or active vulnerabilities Scattered Lapsus$ Hunters, a team-up of infamous hacking groups Scattered Spider, Lapsus$,…

Read More