TechEU Cyber Rules Hit Smart Home AI Firms With Tight Deadlines
Latest

Human choices, not rogue AI, caused the Hugging Face breach
The recent security incident involving OpenAI and Hugging Face was driven by deliberate corporate decisions to disable safety controls, not by autonomous machine rebellion.

Trezor breach exposes 347,000 users to phishing risks
A security lapse at an email provider has left hundreds of thousands of Trezor customers vulnerable to targeted scams, with thousands already falling for fake alerts.

Google patches 90 Android flaws to block remote attacks
Google has released a major security update closing over 90 vulnerabilities, including 26 critical flaws that allow remote code execution on Android 14 through 17.

Cisco firewall flaws enable ransomware and state attacks
Two critical bugs in Cisco firewall management software are being actively exploited by state-sponsored hackers and ransomware groups to steal credentials and seize control of networks.

PaperCut Replaces Emergency Patches With Comprehensive Security Fixes
PaperCut has issued new maintenance releases that supersede previous emergency patches, addressing two flaws currently under active exploitation by state-linked actors.

Sogou Input Method Flaw Lets Hackers Install Backdoors
A China-linked group used a design flaw in a popular Chinese typing tool to seize control of Windows computers, according to new security research.

JFrog Artifactory Flaws Enable Rapid Admin Takeover
Attackers exploited a chain of two vulnerabilities in JFrog Artifactory to seize control of self-hosted servers and install persistent backdoors. The attacks targeted outdated systems, but a third flaw poses a broader risk to unpatched instances.

Conti ransomware member sentenced to four years in prison
A Ukrainian national has been sentenced to four years in prison for his role in the Conti ransomware operation, which extorted over $150 million from victims globally.

AI shifts focus for Salesforce security governance
Traditional security checks on user logins are no longer enough as AI agents join the workflow. A new framework argues that organizations must now map and govern the trust relationships between these automated systems and enterprise data.

Android malware Mantax Otax combines ransomware and spying
A new malware strain called Mantax Otax targets Android users by encrypting files and stealing sensitive data, while also harassing victims to force payment.

Pentagon admits long-term network neglect creates critical risks
The US military acknowledges that years of delayed maintenance have left its digital infrastructure vulnerable to new AI-driven threats.

GitHub Adds API Control for AI Security Scans
Developers can now use standard code commands to activate AI security checks, removing the need for manual clicks.
More

Illustration: Tradingbird Hackers integrate AI into attack workflows
Adversaries are using AI to speed up attacks and steal model logic, forcing defenders to rethink their security strategies.

Illustration: Tradingbird IDScan offers free monitoring after data breach
A major identity protection firm is providing complimentary security services following a significant data leak involving sensitive government documents.

Illustration: Tradingbird The Data Burden of Autonomous AI Agents
A new industry report highlights a critical gap: while most tech leaders are deploying autonomous AI agents, a significant minority lacks the governance structures needed to manage the resulting data explosion.

Illustration: Tradingbird Google Play Early Access Apps Exploited for Deceptive Scams
Threat actors are abusing a feedback feature on Android's app store to distribute thousands of misleading applications that promise unrealistic rewards.

Illustration: Tradingbird Callers Impersonating IT Staff Compromise Corporate Cloud Access
Criminals are bypassing corporate security by targeting employees' personal mobile devices. By posing as internal IT support, they trick staff into approving fraudulent authentication requests, granting attackers long-term access to sensitive company data.

Illustration: Tradingbird Gigabud Trojans Hide in Android Work Profiles
A new tactic used by the Gigabud banking trojan is evading security checks by isolating malware within Android's work profile feature.

Illustration: Tradingbird AI Agents Drive Mass PaperCut Breaches
A suspected Russian-speaking threat actor used automated AI agents to exploit security flaws in PaperCut software, compromising over 440 instances across 48 countries in a matter of hours.

Illustration: Tradingbird Check Point patches critical VPN certificate flaws
Check Point has released urgent fixes for two high-severity vulnerabilities in its firewall and management software that could allow remote attackers to execute code without authentication.

Illustration: Tradingbird Default AI Gateway Keys Left Millions of Servers Exposed
A security scan revealed that nearly one in ten public AI gateways accepted a placeholder key, granting attackers full administrative control over critical infrastructure.

Illustration: Tradingbird Wallet Makers Warn Users of Phishing Wave
Attackers exploited a shared email vendor to send fake security alerts to crypto users, prompting urgent warnings from major hardware wallet brands.

Illustration: Tradingbird Fake security alerts target hardware wallet users
Trezor and BitBox are warning users to disregard fraudulent security alerts, with Trezor now confirming the emails stem from a compromised third-party email service. The incident follows a recent data breach at logistics partner ShipMonk that exposed customer details and triggered extortion demands from the ShinyHunters group.

Illustration: Tradingbird QNu Labs Secures Funding for National Quantum Network
QNu Labs has raised $21 million to build a 2,000-kilometer quantum-secure network in India, aiming to protect critical infrastructure from future hacking risks.

Illustration: Tradingbird US Freezes $52.8 Million in Crypto From Scam Marketplace
A coordinated federal effort has dismantled a major online hub for fraud services, seizing digital assets and targeting physical compounds in Madagascar.

Illustration: Tradingbird AI Progress Threatens Digital Security Foundations
Recent breakthroughs in mathematical problem-solving by artificial intelligence models signal a potential shift in how we secure digital communications, challenging long-held assumptions about encryption stability.

Illustration: Tradingbird LG Smart TV Privacy Investigation Reveals Network Scanning
New findings suggest LG televisions may monitor viewing habits and network activity without clear user consent, raising concerns about home surveillance.

Illustration: Tradingbird Stolen AI Tokens Bypass Security Checks
Cybercriminals are exploiting leaked AI service tokens to bypass multi-factor authentication, according to a new security report.

Illustration: Tradingbird FBI warns AI accelerates cyber threats, urging focus on basic hygiene
Federal investigators state that artificial intelligence is making attacks faster and more capable, but emphasize that traditional defensive measures remain the most effective countermeasure.

Illustration: Tradingbird Microsoft Defender Zero-Day Bypasses Latest Security Patches
A newly disclosed flaw allows attackers to bypass recent security updates, granting elevated access to Windows systems despite Microsoft's latest fixes.

Illustration: Tradingbird LG Disputes Mass TV Surveillance Allegations
LG rejects claims that 216 million smart TVs are actively spying on users, stating that audio recording only occurs with explicit user consent.

Illustration: Tradingbird Default credentials on self-hosted servers face rapid compromise
Keeping factory settings on home servers creates an immediate security risk. Automated scanners find and exploit these weak entry points within hours, turning a hobby into a liability.

Illustration: Tradingbird Mac security threats and conference updates
Recent reports highlight a shift in how malware targets macOS, while the major Apple security conference prepares for its next edition.

Illustration: Tradingbird Exposed Bitcoin Wallets Face Critical Security Risk
A critical flaw in Alby Hub allowed attackers to steal funds from wallets exposed to the internet, affecting users who ran older versions.

Illustration: Tradingbird DeepSeek Harness Flaw Allowed Agents to Disable Security Controls
A critical security flaw let AI coding agents escape their restricted environments, exposing developer systems to unauthorized access and data theft.
