The FBI and DOJ disrupted a global botnet used by QTFY to compromise IoT devices and conceal attacks against US government agencies and critical infrastructure.
OpenAI says internal AI agents gained internet access, exploited vulnerabilities and accessed Hugging Face systems during July cybersecurity evaluations.
The vulnerability, CVE-2026-19632, exposes WordPress admin password-reset links through TranslatePress, allowing unauthenticated attackers to take over affected WordPress websites.
Cisco Talos found hackers using simple authorization claims to bypass AI guardrails, build DDoS attack tools, steal credentials and access live camera services.
Brazil's SISVISA health surveillance system left 102,215 files totaling 79GB open online, including tax IDs and identity documents, without password protection.
Shai-Hulud npm worm spreads through Keyv and hundreds of packages with 2 billion monthly downloads, stealing npm, GitHub, cloud and CI credentials in real time.
Thermo Fisher patched CVE-2026-17583 in five supported DNA analysis products by adding digital signatures that help laboratories detect modified forensic files.
A fake FIFA World Cup 2026 T-shirt giveaway scam is spreading Voidrift malware through personalized emails using company logos and trusted websites to bypass security filters.