Security

164 articles · page 3 of 4

Security

Two Nigerian Men Extradited to US on Sextortion Charges Linked to Deaths of Two Teens

Two Nigerian nationals have been extradited to the United States and charged in connection with sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina. The men, Adebola Festus Adekunle, 26, and Mudasiru Afeez Olawale, 24, were arrested in Nigeria in August 2023 as part of "Operation Artemis," a joint international law enforcement effort targeting sextortion rings operating from Nigeria that prey on minors worldwide.

31 Aug·2 min
Security

Critical GiveWP Donation Plugin Flaw Puts 100,000+ WordPress Sites at Risk of Remote Code Execution

A maximum-severity vulnerability in the GiveWP WordPress donation plugin, tracked as CVE-2026-82222, enables unauthenticated attackers to execute arbitrary commands on affected hosting servers, putting over 100,000 websites at risk. The flaw, reported by researcher Udin Chan via Patchstack, affects GiveWP through version 4.16.7.1 and was patched in version 4.16.7.2 released on August 27.

29 Aug·2 min
Security

Former DIA insider threat specialist pleads guilty to leaking state secrets

Nathan Vilas Laatsch, a former Defense Intelligence Agency IT specialist assigned to the Insider Threat Division, has pleaded guilty to attempting to pass top-secret information to a foreign government, the Justice Department announced. Laatsch, 29, was arrested in May 2025 after an FBI undercover operation caught him placing a thumb drive containing classified documents in an Arlington, Virginia park, believing he was delivering them to a foreign spy.

29 Aug·2 min
Security

X uncovers 200,000-strong Chinese bot farm amplifying anti-AI data center narratives

X has identified a bot farm of approximately 200,000 accounts, including 200 that actively posted about AI data centers driving up electricity prices and straining the grid, which the platform's Global Government Affairs team says was an attempt to manipulate public debate on American AI and energy policy. The accounts are suspected to have been created by Chinese operators and used fake American personas to amplify negative claims about data center impacts.

28 Aug·2 min
Security

FBI and AFP arrest alleged TeamPCP masterminds in Perth over supply chain attacks

The Australian Federal Police, with assistance from the FBI, have arrested two men in Perth believed to be the masterminds behind TeamPCP, a cybercrime syndicate responsible for supply chain attacks that compromised more than 1,000 organisations, stole over 500,000 credentials, and exfiltrated at least 300 gigabytes of data. The arrests, made on Wednesday, follow investigations that began in April 2026 after multiple cyber threat assessment companies alerted authorities to malicious code inserted into open-source repositories.

28 Aug·2 min
Security

AI companion review site Intimeros exposed internal data on unsecured test server for three weeks

Intimeros, a website that rates and reviews AI companions including chatbots designed as boyfriends and girlfriends, inadvertently exposed unpublished reviews, pricing, and editorial notes to the public for three weeks after a colleague disabled password protection on a test version of the site. The staging site was indexed by Google, making sensitive editorial strategy visible to competitors and anyone who stumbled upon it.

28 Aug·2 min
Security

AI coding agents tricked into installing malicious packages via website text files

Security researchers have discovered that AI coding agents including Anthropic's Claude, OpenAI's Codex, and Nous Research's Hermes automatically install unowned code referenced in llms.txt files on corporate websites, creating a dangerous new attack vector. Within an hour of registering a handful of unclaimed package names, researchers received callbacks from a Fortune 500 company, and over time dozens more – including from other Fortune 500 firms and startups – responded. One misconfigured site was found to be directing visitors to live malware.

28 Aug·3 min
Security

AI-Agent Swarm Hits 395 Organizations via PaperCut Flaws as Zero-Day Attacks Surge Across Chrome, SonicWall

In a dramatic escalation of automated cyberattacks, a threat actor using hundreds of AI agents exploited PaperCut NG/MF vulnerabilities to compromise 395 organizations across 48 countries, while Google and SonicWall separately warned of new zero-day flaws being actively exploited in the wild. The coordinated warnings underscore a rapid shift toward AI-driven and chained exploit tactics targeting enterprise and government networks.

28 Aug·3 min·5 sources
Security

Australia Arrests Two Alleged TeamPCP Hackers Behind Developer Supply Chain Attacks

Australian federal police have arrested and charged two young men believed to be members of TeamPCP, a hacking group that has launched a series of sophisticated supply chain attacks targeting software developers worldwide. The arrests, announced on August 27, 2026, mark a significant escalation in law enforcement efforts against attackers who have compromised thousands of downstream users by poisoning popular open source packages.

28 Aug·3 min
Security

Manchester Airports Group data breach exposes 8.7 million customer records

Manchester Airports Group (MAG), the operator of three major UK airports, has disclosed a cyberattack that compromised the personal data of approximately 8.7 million customers, including email addresses, phone numbers, vehicle registration numbers, and postcodes. The breach affected data collected for car parking, lounge bookings, and public Wi-Fi services, though the company stated that no payment or passport information was stored on the compromised systems. MAG said it immediately contained the risk and has notified relevant authorities, while warning customers to remain vigilant against potential phishing attempts.

28 Aug·3 min·2 sources
Security

Brevard County ‘Deputy of the Year’ Resigns After Using Flock Surveillance System to Stalk Ex-Girlfriend

Brevard County deputy sheriff Michael Fultz, named Deputy of the Year in 2025, resigned after an internal investigation revealed he used the Flock automated license plate reader system to stalk his ex-girlfriend, alongside multiple incidents of sexual misconduct, racist behavior, and abuse of authority. The case underscores growing concerns about police misuse of surveillance technologies for personal purposes.

28 Aug·2 min
Security

Cyber-Attack on Three UK Airports Exposes Data of Nearly 9 Million Customers

Manchester Airports Group (MAG) has confirmed a cyber-attack on its systems that compromised the personal data of approximately 8.7 million customers across Manchester, London Stansted, and East Midlands airports. Hackers accessed email addresses, phone numbers, vehicle registration numbers, and postcodes from bookings for car parks, lounges, fast-track services, and in-airport WiFi sign-ups. The operator has assured the public that passenger safety and flight operations remain unaffected.

27 Aug·2 min·2 sources
Security

CISA Orders Federal Agencies to Patch Actively Exploited Citrix NetScaler Flaw by Saturday

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive requiring all federal civilian agencies to patch a critical remote code execution vulnerability in Citrix NetScaler appliances by Saturday, citing active exploitation in the wild. The directive, which falls under CISA's Binding Operational Directive (BOD) 22-01, gives agencies until the end of the week to apply the fix or take alternative mitigating measures to protect against ongoing attacks.

27 Aug·2 min
Security

Carhartt data breach exposes 12.9 million accounts, ShinyHunters group claims

The ShinyHunters extortion group has publicly released sensitive data belonging to nearly 12.9 million Carhartt customer accounts, according to data breach notification service Have I Been Pwned. The breach, which occurred earlier this month, exposes names, email addresses, and potentially other personal information, raising concerns about credential theft and targeted phishing attacks against the popular clothing retailer's customers.

27 Aug·2 min
Security

Perth Men Charged as Key Players in Global Cybercrime Syndicate, FBI Alleges

Two young men from Perth, Western Australia, have been charged for their alleged role in a sophisticated global cybercrime syndicate that used malicious open-source software to steal from thousands of businesses, according to the FBI. The men appeared in court this week, facing serious charges as part of an international investigation into a cybercrime network that exploited open-source code to infiltrate and rob companies around the world.

27 Aug·3 min
Security

US Discloses Over 100 Water Systems Hit in July Cyberattack Blitz

The U.S. government has disclosed that malicious cyber activity struck more than 100 internet-exposed water and wastewater systems in July 2026, marking the first time federal officials have quantified the scope of a campaign widely attributed to Iranian-backed hackers. The Cybersecurity and Infrastructure Security Agency (CISA) linked the intrusions to programmable logic controllers (PLCs) connected directly to the internet, a configuration that creates significant security risks.

27 Aug·3 min
Security

US Designates Italian Tech Collective Autistici/Inventati as Global Terrorist Entity

The United States State Department has officially designated Autistici/Inventati, an Italian collective that provides secure email and web hosting services to activists and nonprofit organizations, as a Specially Designated Global Terrorist (SDGT), a move that has alarmed free speech and digital rights advocates who argue the group is being punished for its pro-privacy stance rather than for any terrorist activities.

27 Aug·2 min
Security

Boston Scientific hit by cyberattack disrupting global operations

Boston Scientific disclosed on Wednesday that a cyberattack has caused a global disruption to its operations, affecting its ability to process and ship customer orders. The medical device maker reported the incident in a filing with the Securities and Exchange Commission, stating that the breach began on Tuesday and is ongoing, with the company working with third-party cybersecurity experts to contain the threat. The company's shares fell more than 4% on Wednesday morning as investors reacted to the uncertainty.

27 Aug·2 min·3 sources
Security

US seizes domains used by Chinese state-sponsored hackers who infiltrated NASA, Senate, and Federal Reserve

The U.S. Department of Justice and FBI have seized three domains linked to a Chinese state-sponsored hacking group known as QTFY, which they say compromised systems at NASA, the Senate, the Federal Reserve, and multiple other federal agencies, marking a significant escalation in efforts to disrupt persistent cyber espionage operations originating from the People's Republic of China.

27 Aug·2 min·3 sources
Security

Hackers Exploit Critical Gitea Vulnerability in Code Injection Attacks, CISA Warns

A critical-severity vulnerability in Gitea, the self-hosted Git service, is being actively exploited by attackers in code injection attacks, according to a warning from the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The flaw allows remote threat actors to inject malicious code into repositories, potentially compromising source code, CI/CD pipelines, and developer credentials. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, signaling an urgent need for organizations to apply patches.

26 Aug·2 min