Data and security

Auto Added by WPeMatico

The researcher Microsoft threatened just dropped a seventh Windows zero-day hours after Patch Tuesday

Chaotic Eclipse, the security researcher Microsoft threatened with criminal prosecution, has published a seventh Windows zero-day exploit. Called RoguePlanet, it grants attackers SYSTEM privileges on fully patched Windows 10 and 11 machines. The researcher released the proof-of-concept hours after Microsoft shipped its June Patch Tuesday update, which fixed a record 200 vulnerabilities. RoguePlanet exploits a […]

This story continues at The Next Web

The researcher Microsoft threatened just dropped a seventh Windows zero-day hours after Patch Tuesday Read More »

Researchers tricked an OpenClaw AI agent into leaking AWS keys and customer data with a phishing email

Security researchers at Varonis built an OpenClaw email agent, connected it to a Gmail inbox with fake company data, and then phished it. The agent, dubbed Pinchy, handed over AWS credentials, database connection strings, and a customer export without verifying who was asking. It took a single impersonation email. The experiment tested whether AI agents […]

This story continues at The Next Web

Researchers tricked an OpenClaw AI agent into leaking AWS keys and customer data with a phishing email Read More »

A Chinese state-linked botnet has grown to 1,500 hacked routers and is mapping vulnerable targets within hours of disclosure

A covert botnet linked to Chinese state-sponsored hackers has more than doubled in size and is now scanning for newly disclosed vulnerabilities within hours of publication. The JDY botnet comprises over 1,500 compromised small office and home office routers, firewalls, and IoT devices, according to new research from Lumen’s Black Lotus Labs. Most of the […]

This story continues at The Next Web

A Chinese state-linked botnet has grown to 1,500 hacked routers and is mapping vulnerable targets within hours of disclosure Read More »

KPMG secretly and repeatedly accessed a whistleblower’s computer, then shared the files with its CEO

KPMG secretly and repeatedly accessed a whistleblower’s work computer to extract documents detailing their allegations of data misuse, then shared the material with senior partners and the firm’s former chief executive, the Australian Financial Review has reported. The global accounting firm had the legal right to access an employee’s work laptop. What makes it striking […]

This story continues at The Next Web

KPMG secretly and repeatedly accessed a whistleblower’s computer, then shared the files with its CEO Read More »

Aryon Security raises $29M to stop cloud breaches before they happen

Aryon Security, an Israeli cloud-security startup, has raised $29M in a Series A round to push a prevention-first approach to securing the cloud. The round, which the company says brings its total funding to $38M, was led by US-based Brightmind Partners. The investor list is the headline. Shlomo Kramer’s Skinos Ventures, Datadog, Blumberg Capital, and […]

This story continues at The Next Web

Aryon Security raises $29M to stop cloud breaches before they happen Read More »

Your face is the ticket: Google’s Gemini and biometric gates are the World Cup’s quieter tech story

The 2026 World Cup is rolling out two layers of technology that most of its 10 million visitors will actually touch: a consumer-AI layer led by Google, and a biometric-identity layer that turns a fan’s face into a ticket. This is the quieter half of the tournament’s tech, the half aimed at fans rather than […]

This story continues at The Next Web

Your face is the ticket: Google’s Gemini and biometric gates are the World Cup’s quieter tech story Read More »

Two Russian APT groups are exploiting a WinRAR flaw patched nearly a year ago to hit Ukraine

Two Russian state-linked hacking groups are actively exploiting a path traversal vulnerability in WinRAR that was patched nearly a year ago, using it to deploy credential-stealing malware against Ukrainian government and military targets, according to research published by Trend Micro. The flaw, tracked as CVE-2025-8088 and rated 8.4 on the CVSS scale, allows attackers to […]

This story continues at The Next Web

Two Russian APT groups are exploiting a WinRAR flaw patched nearly a year ago to hit Ukraine Read More »

Meta pulled facial recognition code from its smart glasses app one day after WIRED found it, then denied the timing was related

Meta removed nearly all traces of an unreleased facial recognition system from its smart glasses companion app on Friday, one day after WIRED reported that the software had been quietly embedded in an app installed on more than 50 million phones. The feature, which Meta internally called NameTag, was designed to convert faces captured by […]

This story continues at The Next Web

Meta pulled facial recognition code from its smart glasses app one day after WIRED found it, then denied the timing was related Read More »

Anthropic releases Claude Fable 5, a Mythos-class model the public can finally use, days before a potential record IPO

Anthropic on Tuesday released Claude Fable 5, a model built on the same architecture as its restricted Mythos system, making Mythos-class intelligence publicly available for the first time. Fable 5 is available to enterprise customers and paid subscribers, but it comes with new safeguards that block responses in cybersecurity, biology, chemistry, and what Anthropic calls […]

This story continues at The Next Web

Anthropic releases Claude Fable 5, a Mythos-class model the public can finally use, days before a potential record IPO Read More »

The UK is reviewing its £330M NHS deal with Palantir, and may pull the plug in 2027

The British government has put its most contentious health-tech contract on notice. It is now formally reviewing the NHS’s £330mn deal with Palantir, and weighing whether to walk away in 2027. Technology minister Liz Kendall confirmed the review this week, telling Times Radio that “the current health secretary is reviewing every single aspect of that […]

This story continues at The Next Web

The UK is reviewing its £330M NHS deal with Palantir, and may pull the plug in 2027 Read More »

Shopping Cart