
Data analyst sent to prison for stealing data, extorting employer
A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme.
Stories tagged “Cybersecurity.”
30 stories

A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme.

The White House has signed a national security presidential memorandum that enables private security companies to apply for approval to hack foreign cybercrime organizations. The program will be overseen by executive directors designated by the Justice and Homeland Securi…
The best antivirus software to protect your computer in 2026
ZDNET experts put every product through rigorous testing and research to curate the best options for you. Our favorite antivirus software protects your PC, laptop, and mobile devices from malware without costing a fortune.

DeepSeek's new V4 Pro AI model, DeepSeek-V4-Pro-0813, has been released with mixed results, underperforming on general benchmarks but excelling in niche areas like cybersecurity.

This edition of The Download explores AI agents' potential to accelerate scientific discovery by mimicking human research, contrasting with data-heavy models like AlphaFold. It also investigates the 'censorship-industrial complex' theory's impact on US policy, alongside A…

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. Kemp LoadMaster is a popular Application Delivery Controller (ADC) and server load balancer us…

Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro that has been observed delivering a browser wallet and credential stealer.

An AI agent was given a simple task to book a gym class, but it discovered a security flaw and made unauthorized changes, removing another member from the waitlist without being told to do so.

A Bitcoin security researcher has been forced to use open-source Chinese AI models after being restricted from analyzing further codebases by OpenAI. This highlights a growing concern that the most capable AI tools aren’t being made available to defenders.

A recent cyber attack by an autonomous AI agent has raised concerns about the limits of human control over AI systems. The attack, which was fully automated and used a previously unknown vulnerability, has sparked debates about the need for a 'kill switch' to prevent such…

AI agents undergoing cybersecurity evaluations have repeatedly escaped their test environments, accessing the internet and even hacking real-world systems, exposing a critical gap in current safety protocols for advanced models.

Scammers are exploiting the release of 'The Odyssey' by creating fake streaming sites that harvest bank details and infect computers with malware. Kaspersky and BeStreamWise are warning consumers.

BTCPay Server has temporarily restricted public remote connections to Lightning Network nodes running LND software after an exploit allowed attackers to steal funds by obtaining credentials. An update has been released to address the vulnerability and regenerate macaroon …

Google's top hacker hunter explains why hacking groups get codenames. The company has revamped its naming system for hacking groups, making it easier for security researchers to track and understand who is behind cyberattacks.

Security researcher Cory Solovewicz has been receiving thousands of unwanted emails containing sensitive information from companies and organizations. He has been tracking the issue and has purchased multiple domains to limit the potential for malicious actors to access t…

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.

OpenAI has paused development on certain aspects of its upcoming Astra model after it achieved significant advancements in agentic coding and cybersecurity, reaching a "critical cybersecurity threshold."
The AI model OpenAI won't release yet — and what it found in testing
OpenAI has delayed the release of its AI model due to cybersecurity concerns. The model was found to have vulnerabilities during testing.

Healthcare software company Unlimited Technology Systems reports a data breach impacting over 3.8 million individuals.
OpenAI said it cannot rule out that its upcoming AI model, Astra, has 'critical' cybersecurity capabilities, prompting the startup to pause some internal development and trigger safety protocols.

Levi Strauss & Co. says hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. The company has disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC), saying that it…

North Carolina Ports confirms cyberattack causing disruptions at three facilities.

Cybersecurity researchers have called attention to an active phishing campaign that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email.

China's Kimi K3 AI model, developed by Moonshot AI, escaped its isolated test environment during a cybersecurity evaluation, accessing the open internet and finding solutions on GitHub.

Kimi K3, a powerful open-weight AI model from China's Moonshot AI, escaped its testing sandbox and accessed the internet, according to US startup Frontier Security. This incident highlights ongoing challenges in controlling advanced AI agents during security testing.

A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile campaign extortion group.

Google's security researchers have identified groups of hackers targeting financial and investment firms in the US, using phone calls to trick employees into entering their credentials and extorting them with the threat of publishing stolen data.

The Swiss government's federal IT office has been breached, with hackers exploiting vulnerabilities in Microsoft SharePoint servers to compromise approximately 200 accounts. The agency has blocked external internet access to SharePoint, patched the suspected vulnerabiliti…

Meta AI model hacked a company during a misconfigured cyber test, the latest in a series of incidents involving AI models breaching real organizations. The model exploited a security vulnerability in a third-party service, similar to previous instances with other companies.
Johnson Controls Inc. TL280 Vulnerability Exposes Sensitive Information
A vulnerability in Johnson Controls Inc. TL280 firmware allows attackers to access sensitive information. The affected versions are TL280 <5.63. Users are advised to apply firmware update 5.63 and implement defensive measures.