Goto

Collaborating Authors

 attacker


DMV breach confirmed as hackers claim 200,000 records stolen

FOX News

This material may not be published, broadcast, rewritten, or redistributed. Quotes displayed in real-time or delayed by at least 15 minutes. Market data provided by Factset . Powered and implemented by FactSet Digital Solutions . Mutual Fund and ETF data provided by LSEG . Asked Siri to call your bank?


Thousands of hacked sites trick you into installing malware

FOX News

Fake CAPTCHA scams have compromised over 5,400 websites, tricking users into pasting malware commands into Windows Run. WordPress and PrestaShop sites are among those affected.


Microsoft's September updates fix a record 973 security flaws

PCWorld

PCWorld reports that Microsoft's September update patches a record 973 security vulnerabilities, doubling the previous month's total, with 113 classified as critical. Two zero-day exploits are already being actively used by attackers, and flaws in Windows, Excel, SharePoint, and Windows Hello could allow remote code execution or privilege escalation. Users are strongly urged to update their Microsoft software immediately to protect against these serious risks. Yesterday was September Patch Tuesday, which means Microsoft released security updates addressing 973 new security vulnerabilities.


Anthropic automatically signs out Claude users to protect them from hackers

Engadget

Stolen Claude logins have serious resale value at scale. Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told Axios in August that a trade has grown up around hijacked AI accounts, with criminals trafficking credentials for Claude, ChatGPT and Gemini. Meanwhile, findings by Palo Alto Networks' Unit 42 have traced hijacked accounts to proxy services known as transfer stations. These pool stolen credentials and resell access to AI services at a much lower cost than retail. Anthropic doesn't publish exact figures for its Claude usage limits, but every prompt has a compute cost, which the company absorbs when a stolen session is doing the prompting.


19 Chrome extensions were secretly stealing data. Uninstall these now

PCWorld

PCWorld warns that 19 Chrome and Edge extensions were found secretly stealing user data, including login details and crypto tokens, through hidden malware. The malicious campaign reportedly evaded detection for around two years, with attackers injecting harmful code into already popular extensions after they gained user trust. Google and Microsoft have removed these add-ons from their stores, but affected users must manually uninstall them to fully protect their devices. Security experts at Socket are warning about browser extensions for Google Chrome and Microsoft Edge that contain malware. The accompanying report mentions a total of 19 add-ons that were deliberately infected with malicious code in order to intercept user data and steal access details to digital wallets.


Chinese hackers target NASA and key US agencies, DOJ alleges

FOX News

This material may not be published, broadcast, rewritten, or redistributed. Quotes displayed in real-time or delayed by at least 15 minutes. Market data provided by Factset . Powered and implemented by FactSet Digital Solutions . Mutual Fund and ETF data provided by LSEG . Survivor's Christian Hubicki marvels at China's robotics games records: 'Willing to break the robots to do it' Chinese humanoid robot breaks Usain Bolt's 100m dash record at 9.39 seconds'CHUMP CHANGE': How a $17B settlement is a landmark for social, still good for Meta Kurt'CyberGuy' Knutsson recalls being stuck in New Orleans during Hurricane Katrina Cybercrime a global problem, thieves go for'targets of opportunity,' expert says Steve Doocy explores the US Air Force Academy's elite military training Supporting data centers is'perilous' politically: Brian Kilmeade Fox News Flash top headlines are here. Check out what's clicking on FoxNews.com.


That April Windows update you skipped? Hackers are exploiting it now

PCWorld

PCWorld reports that CISA has flagged four actively exploited security vulnerabilities affecting Windows, VMware vCenter, Microsoft SharePoint, and Apple macOS systems. Critical flaws carry severity scores as high as 9.8 out of 10, with attackers using them to deploy ransomware, install Monero mining malware, and bypass authentication entirely. Users and administrators are urged to apply available patches immediately, including recent Windows, SharePoint, VMware, and macOS updates, to avoid becoming targets. The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about four security vulnerabilities that are being exploited by attackers in the wild. CISA has added the vulnerabilities to its catalog of Known Exploited Vulnerabilities (KEV) . Microsoft Windows and SharePoint, VMware vCenter, and Apple macOS are affected. Inclusion in the KEV catalog sends an important signal: CISA doesn't simply list every known vulnerability out there, but only those for which there is concrete evidence of active exploitation by attackers. The agency points out that such vulnerabilities are among the most commonly used attack vectors and pose a significant risk.


Microsoft fixes 421 bugs and a Windows zero-day in August Patch Tuesday - update ASAP

ZDNet

I wore the world's first HDR10 smart glasses TCL's new E Ink tablet beats the Remarkable and Kindle Anker's new charger is one of the most unique I've ever seen I wore the world's first HDR10 smart glasses TCL's new E Ink tablet beats the Remarkable and Kindle Anker's new charger is one of the most unique I've ever seen The exploited zero-day flaw could allow an attacker to gain system privileges on a Windows PC. One vulnerability has already been exploited in the wild. Microsoft continues its onslaught against security vulnerabilities, fixing a whopping 421 bugs in August's Patch Tuesday update. But looking beyond the sheer number, Windows users should install this month's update, as it patches a zero-day flaw that's already been exploited by attackers. Aimed at Windows 11 25H2/24H2, Windows 11 23H2, and Windows 10, the 421 vulnerabilities encompass a range of Microsoft products, including Office, Exchange, Azure, and SharePoint.


Russian hackers can steal emails without a click

FOX News

This material may not be published, broadcast, rewritten, or redistributed. Quotes displayed in real-time or delayed by at least 15 minutes. Market data provided by Factset . Powered and implemented by FactSet Digital Solutions . Mutual Fund and ETF data provided by LSEG . Don't let fake election websites fool you before 2026 midterms Martha Reeves' 'BRUTAL' National Anthem performance goes viral'Mind-boggling' suspect at Trump golf course would approach federal agents: Ex-FBI agent Market analyst hails Chevron-Microsoft deal as a'tremendous breakthrough' AI agents spark concerns over'going rogue,' hacking companies Fox News Flash top headlines are here. Check out what's clicking on FoxNews.com.


A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims' Blind Spots

WIRED

A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims' Blind Spots A new type of malware can worm deep into AI coding systems to steal data and logins--and can flip a "death switch" to destroy files and keep out real users. As AI tools proliferate and become deeply ingrained in software development around the world, new research from the cybersecurity firm Crowdstrike shows how attackers are actively targeting the AI toolchain to steal access credentials, gain deeper access to a target environment, exfiltrate sensitive data, and even destroy target files and systems--all while finding new ways to cover their tracks. Researchers discovered a worm in the wild while investigating AI software supply chain attacks. Adam Meyers, CrowdStrike's senior vice president of counter adversary work, says that the company has not yet attributed the activity to a specific actor, but that it fits into larger evolutions in how attackers like TeamPCP (which Crowdstrike tracks as "Altered Spider") and North Korean groups are targeting the AI software supply chain. "This is one of the campaigns that we've seen showing that this is an emerging attack class," Meyers tells WIRED.