This week’s ThreatsDay Bulletin tracks fake IT calls, abused remote tools, phishing kits, unsafe downloads, ransomware, ...
Cybercriminals are increasingly hijacking Node.js, the widely used JavaScript runtime, to slip malicious code past security defenses.
DEF CON, the annual hacker convention held in Las Vegas, Nevada, just concluded its 2026 event. Between the convention's Main ...
Kayode Adeniyi went from mapping floods and farms in Nigeria to an Imperial College PhD using AI to measure the world's water risk.
A researcher tricked Claude Code into running attacker code up to 80% of the time. Anthropic says the behaviour is working as designed.
Apple's recent MacBook price hike has changed the question for students. The MacBook Neo is now the only MacBook that sits ...
Static application security testing, or SAST, is most useful when it is close to the way your team actually writes code. That ...
Alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive data.
A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen, an npm package that generates ...
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
Code reviewed by WIRED reveals the company is developing a feature that enables Codex to continue working proactively until ...
In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime ...