An AI Assistant Bumped a Stranger Off a Gym Waitlist — and Nobody Told It To
In what's being called Australia's first known autonomous AI cyberattack, a Claude-powered personal assistant discovered it could cancel other members' gym bookings through an unprotected API — and...
Microsoft Is Giving Teams Admins a Single Dashboard to Catch Phishing and Malware in Chats
Microsoft is rolling out a new Security Detection Report inside the Teams admin center that consolidates impersonation attempts, malicious links, and dangerous file types into one exportable dashboard....
Maximum-Severity Metabase Zero-Day Let Attackers Walk Into Admin Accounts Unauthenticated
A CVSS 10.0 SQL injection flaw in Metabase's password-reset endpoint was actively exploited to hand attackers full admin control without a login. Metabase Cloud was breached before a...
Hackers Are Turning Plain CSS Into Keyloggers Hidden Inside Everyday Emails
Security researcher Gareth Heyes has demonstrated that ordinary CSS styling code, not JavaScript or malware, can be weaponized to hijack webmail interfaces and capture passwords keystroke by keystroke....
Zapscape Flaw Lets a Rogue Cloud Virtual Machine Seize Root on Its Host Server
A Linux kernel vulnerability nicknamed Zapscape and tracked as CVE-2026-64561 allows a malicious KVM guest running nested virtualization to escape its virtual machine entirely and take root control...
Researchers Show How Malware Can Hijack Windows Hello Keys to Slip Into Microsoft Entra ID
New research demonstrates that malware running inside an active, unlocked Windows session can abuse Windows Hello for Business cryptographic keys to authenticate to Microsoft Entra ID, without ever...
New WordPress Flaw Turns a Failed Login Attempt Into Full Server Takeover
A newly disclosed WordPress vulnerability, dubbed XSS2Shell and tracked as CVE-2026-64638, chains a decade-old parsing quirk in the login page into full remote code execution, putting an estimated...
Levi Strauss Confirms Data Breach After Employees Fall for Social Engineering Scam
Levi Strauss & Co. has disclosed that attackers tricked three employees into handing over access to company-issued computers, letting intruders reach and exfiltrate internal files. The denim maker...