Hackers are mass-exploiting two WordPress flaws, and AI found the way in
Hackers are mass-exploiting two WordPress flaws, and AI found the way in

If you run a WordPress site, the advice this week is blunt: update it now. Two flaws in the software are under active exploitation across the internet. WordPress powers more than half of every website online, so the blast radius is huge. Security firms…

Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs

Hackers are chaining together two newly discovered flaws to achieve remote code execution.

Top AI coding agents can be easy victims to sandbox escapes, showing they aren’t as secure as they claim to be

What if a host component outside the sandbox reads AI coding agents’ output? And what if that output is manipulated?

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars.

Safety guardrails blocked Hugging Face’s defenders, not the attacker, when an AI agent breached its systems

Hugging Face’s incident response team first turned to frontier AI models to analyze a breach of the company’s production infrastructure, and the models refused to help. Commercial safety guardrails built to stop attackers blocked every forensic query b…

ShinyHunters hit medial giant Abbott, disrupting cancer drug research and more

Abbott suffers two attacks in the same week, and at least one is demanding a ransom payment.

Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk

Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.

Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies

Edinburgh-based tech firm Craneware said customer data was stolen during a cyberattack. The company makes software that thousands of U.S. hospitals, pharmacies, and clinics rely on for billing patients, potentially exposing health data.

OneDrive will block screenshots of sensitive documents, but only in Microsoft’s own browser.
OneDrive will block screenshots of sensitive documents, but only in Microsoft’s own browser.

Starting next month, OneDrive and SharePoint will block screen captures when enterprise users open certain sensitivity-labelled PDFs in Microsoft Edge. The restriction applies to documents carrying a Purview Information Protection label without the Cop…