FIFA World Cup 2026 fraud is live before kickoff. Researchers found 270,000 stolen fan credentials and 3,800 dormant fake domains primed to activate on June 11.
Oxford suffered two vendor data breaches in under five weeks. Group GTI's CareerConnect was hit on May 28, exposing alumni emails and encrypted passwords.
Anthropic deployed engineers inside the NSA to run Mythos, its restricted cybersecurity AI, while fighting the Pentagon's supply-chain ban in two federal courts.
A Magecart skimmer hid in Stripe's customer database since December 2025, routing stolen cards through api.stripe.com to evade CSP on Magento checkout pages.
CVE Lite CLI, now an OWASP Incubator Project, scans JavaScript lockfiles locally and returns copy-and-run fix commands instead of CVE ID lists. Free, MIT-licensed, no data...
ChatGPT's Lockdown Mode reached all personal accounts in June, blocking the outbound connections that prompt injection attacks use to steal session data.
Toronto researchers' AI worm breached 73.8% of a simulated enterprise network in 7 days by stealing victim GPU compute to run a free open-weight LLM, setting...
Ireland's HSE lost email and system access for hours on June 4 after a third-party vendor was hit by ransomware, the third such incident since 2021.
LAX B1/B2 visa denial claims now point to CBP custody rules, visitor visa work limits, phone searches and the paperwork that follows refusal.
Hackers tricked Meta's AI support chatbot into swapping account emails and resetting passwords to hijack Instagram profiles. Here is how the attack worked.