A now-patched Microsoft Copilot vulnerability let attackers steal emails, MFA codes and files with one click. The fix is in, but the underlying dynamic: AI tools with sweeping access inside …
News
-
-
A CDN-level supply chain attack backdoored over 1.2 million WordPress sites via OptinMonster, TrustPulse and PushEngage. Here is exactly what to check and how to clean up.
-
MIT’s Fractal OS found three previously unknown security behaviours in the Apple M1, including the first confirmed Phantom speculation on Apple Silicon. The findings say less about how dangerous the …
-
The Gentlemen ransomware group has claimed 478 victims — including a UK business used to breach a client — by exploiting unpatched VPN appliances and spending weeks inside networks before …
-
ShinyHunters exploited CVE-2026-35273 for nearly two weeks before Oracle published any advisory. The flaw is serious — but the disclosure gap is the structural failure that put 100 organisations at …
-
Velvet Ant’s decade inside a target network reveals a gap that affects most security programmes: the tools used to report security health are not designed to detect a Linux PAM …
-
CVE-2026-50751’s root cause — a gateway that let clients disable their own certificate verification — reflects a wider design failure. Here’s what it means for how organisations should think about …