A security flaw in “Claude in Chrome” enables any Chrome extension, including those without permissions, to execute privileged commands, steal data, and perform agentic actions.
A Canvas hack has leaked nearly 280 million records from faculty, staff, and students across 8,809 colleges, online learning platforms, and school districts.
A critical vulnerability discovered by AI spans most of the history of NGINX, which was first made available in 2004. The web server is frequently used as a load balancer and cache for static content, and some recent estimates find that about 20 to 30% of the world's busiest websites make use of it.
A security breach at numerous Polish water treatment plants enabled state-sponsored threat actors to manipulate industrial control systems across five cities.
The U.K.’s Information Commissioner’s Office has fined a South Staffordshire water supplier $1.3 million, following a multi-year data breach that affected more than 630,000 people.
The rise of AI has had a seismic impact on the digital threat landscape—but its implications for data storage and retention are often overlooked.
One of the world’s largest electronics manufacturers, Foxconn, has experienced a cyber attack on its North American operation by the Ransomware-as-a-Service Nitrogen cybercrime gang.
For the first time in its publication history of nearly 20 years, Verizon's annual Data Breach Investigations Report (DBIR) is tracking vulnerability exploitation as the leading initial access method for attackers. Stolen credentials had been the #1 method for the entirety of the report's history up to this year.
On May 19 GitHub confirmed the security breach across its social media channels, verifying that there was unauthorized access to internal repositories and stating that it was monitoring the situation for further activity. It also said that it had no evidence that information stored in customer repositories or internal information about customers was compromised.
American convenience store chain 7-Eleven has confirmed a data breach claimed by the notorious ransomware gang ShinyHunters, which leaked personal data and corporate information.










