A security flaw in “Claude in Chrome” enables any Chrome extension, including those without permissions, to execute privileged commands, steal data, and perform agentic actions.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Shadow AI is the new “known unknown,” and it lives inside every modern enterprise. Legacy cyber products won't secure AI; only AI built to govern AI can.
A Canvas hack has leaked nearly 280 million records from faculty, staff, and students across 8,809 colleges, online learning platforms, and school districts.
A critical vulnerability discovered by AI spans most of the history of NGINX, which was first made available in 2004. The web server is frequently used as a load balancer and cache for static content, and some recent estimates find that about 20 to 30% of the world's busiest websites make use of it.
A security breach at numerous Polish water treatment plants enabled state-sponsored threat actors to manipulate industrial control systems across five cities.
The U.K.’s Information Commissioner’s Office has fined a South Staffordshire water supplier $1.3 million, following a multi-year data breach that affected more than 630,000 people.
One of the world’s largest electronics manufacturers, Foxconn, has experienced a cyber attack on its North American operation by the Ransomware-as-a-Service Nitrogen cybercrime gang.
For the first time in its publication history of nearly 20 years, Verizon's annual Data Breach Investigations Report (DBIR) is tracking vulnerability exploitation as the leading initial access method for attackers. Stolen credentials had been the #1 method for the entirety of the report's history up to this year.
On May 19 GitHub confirmed the security breach across its social media channels, verifying that there was unauthorized access to internal repositories and stating that it was monitoring the situation for further activity. It also said that it had no evidence that information stored in customer repositories or internal information about customers was compromised.
American convenience store chain 7-Eleven has confirmed a data breach claimed by the notorious ransomware gang ShinyHunters, which leaked personal data and corporate information.










