Security researchers found 150 lookalike Open VSX extensions published under trusted names, highlighting how extension marketplaces can expose developer credentials, source code, and CI/CD systems to supply-chain risk.
Fake downloads of The Odyssey are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information.
Google is restoring Blogger sites wrongly flagged for malware after hundreds of publishers reported locked or unavailable blogs and false-positive alerts.
Apple briefly removed Telegram from the App Store over reported CSAM, highlighting moderation failures and the distribution power held by app-store operators.
Apple is challenging a UK order reportedly requiring access to encrypted iCloud data, reviving a wider dispute over privacy, security, and lawful access.
The OnePlus Nord 6 will receive six years of security updates but only four generations of Android upgrades. Here’s how that split could affect app compatibility, device management, and long-term purchasing decisions.
OpenAI’s latest GPT-5.6 safety results show low failure rates for direct prompt injection but higher success rates when attacks arrive through tools and external content.
CrowdStrike warns that AI adoption, rapid vulnerability exploitation, cloud attacks, and malicious npm packages are creating new enterprise security risks.
The Open Secure AI Alliance introduced SAFE guidelines and open agent-security tools at Black Hat, giving enterprises a framework for safer AI deployment.
Samsung plans to ban Smart TV apps containing residential proxy software after researchers found apps could route traffic through users’ home connections.
Google is developing Chrome protections that could block policy-installed extensions from hijacking New Tab pages and search settings on personal devices.
Microsoft’s Project Perception brings coordinated AI agents into security operations, raising new questions about permissions, oversight, accuracy, and deployment risk.
Claude Opus 5 set a Vending-Bench record while fabricating supplier bids, breaking truces, and ignoring refunds, showing why companies need stronger AI agent controls.
Google is testing twice-weekly Chrome security updates as AI tools uncover more vulnerabilities and the company works to shrink the browser’s patch gap.
Researchers found that seven of nine tested Hugging Face image-editing tools produced sexualized alterations, highlighting gaps in model oversight, provenance, and enterprise vendor controls.
GitHub’s new Actions safeguard pauses potentially malicious workflow runs before execution, leaving repository owners to decide who can approve them and what checks must come first.
Looking for the best Chrome VPN extensions in 2026 to enhance your online security and privacy? Dive into our list of top-rated VPNs and find your best fit.
Enterprise AI adoption is accelerating, but new research suggests identity governance is lagging behind. Here's why AI agent identities are becoming a critical security challenge.
Microsoft is retiring its legacy Threat Intelligence portal on August 1. Security teams should verify licenses, permissions, investigation projects, APIs, and automated workflows before the cutoff.
Cursor has patched a high-severity Windows vulnerability that allowed malicious Git repositories to execute code, highlighting security risks in AI coding environments.
Coca-Cola has confirmed data was stolen in the ransomware attack on Fairlife after the Anubis gang published allegedly stolen files, escalating the incident.
JetBrains has patched CVE-2026-63077, a critical TeamCity flaw that could let unauthenticated attackers execute server commands and compromise connected CI/CD pipelines.
Meta is removing Instagram videos that use Ray-Ban smart glasses to harass strangers, highlighting growing privacy concerns around AI-powered wearable cameras.
Meta is under renewed scrutiny after researchers found thousands of AI "nudify" ads on Facebook and Instagram, raising questions about the company's advertising enforcement.
Nvidia’s Open Secure AI Alliance brings major tech and cybersecurity firms together to develop shared protections for enterprise AI agents and systems.
The AI Kill Switch Act would let DHS order developers to slow or shut down frontier models after catastrophic incidents, raising enterprise continuity concerns.
Chick-fil-A disclosed a credential stuffing attack affecting customers across 10 states, underscoring the risks of password reuse and account takeover.