Uber allegedly uses AI systems to predict lowest fares drivers will accept, manipulates their behaviour using slot machine-like tactics This article has been indexed from Silicon UK Read the original article: Drivers Sue Uber Over AI Manipulation
FaceTime Scammers Combine Credential Theft, Remote-Access Apps, and iOS Exploits for Device Takeover.
Apple-focused scam operations are increasingly using FaceTime as a high-trust social-engineering channel to steal credentials and, in higher-risk cases, prepare victims for device compromise. Apple said threat actors may approach targets via phone calls, FaceTime, SMS, email, and other communications,…
Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
Public exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed. The post Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the…
CMMC Phase II suspended, tracking troops in Iran, defenders turn to context bombing
Pentagon suspends CMMC Phase II requirements US troop location data under attack in Iran “Context Bombing” flips the script on prompt injections Get the show notes here: https://cisoseries.com/cybersecurity-news-cmmc-phase-ii-suspended-tracking-troops-in-iran-defenders-turn-to-context-bombing/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked…
11 Old Signed UEFI Shims Just Broke Secure Boot on Millions of PCs
ESET found 11 Microsoft-signed UEFI shims, some over a decade old, that let attackers bypass Secure Boot without a single new exploit. 11 Old Signed UEFI Shims Just Broke Secure Boot on Millions of PCs on Latest Hacking News |…
Two Joomla Extensions Hit by Zero-Day File Upload Attacks Before Patches Landed
CISA added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities catalog after automated attackers exploited file upload flaws in iCagenda and Balbooa Forms weeks before either bug had a CVE number. Two Joomla Extensions Hit by Zero-Day File Upload Attacks…
Staff Sue Meta Over Alleged Use Of AI To Conduct Layoffs
AI systems disproportionately targeted people with medical conditions, pregnancies in mass layoff of thousands, lawsuit claims This article has been indexed from Silicon UK Read the original article: Staff Sue Meta Over Alleged Use Of AI To Conduct Layoffs
Google Chrome 150 Update Fixes 15 Security Vulnerabilities, Including 2 Critical Use-After-Free Flaws
Google Chrome version 150 addresses vulnerabilities in several core browser components, including Ozone, Skia, V8, GPU, Media, UI, Navigation, libyuv, and Linux Toolkit Theming. Among the updates, two critical vulnerabilities, designated as CVE-2026-15764 and CVE-2026-15765, involve use-after-free issues in Ozone,…
Hackers Abuse OAuth Device Codes and Entra ID Enrollment for Persistent SaaS Access
AI-enabled phishing-as-a-service operations are driving a sharp increase in identity attacks in 202620262026, with threat actors increasingly abusing OAuth device authorization flows and Microsoft Entra ID device enrollment to obtain durable access to SaaS environments. Jalisco is a device code…
Critical SonicWall SMA 1000 SSRF and Remote Code Execution Flaws Actively Exploited in the Wild
SonicWall has issued a security advisory regarding two vulnerabilities affecting the SMA1000 Series appliances. Among these, a critical server-side request forgery (SSRF) flaw has been identified, which carries a maximum CVSS score of 10.0. The company has confirmed that threat…
Microsoft Fixes Multiple Windows RDP Flaws Exposing Sensitive Data Over the Network
Microsoft has addressed multiple information-disclosure vulnerabilities in the Windows Remote Desktop Protocol (RDP). This widely used service enables remote administration and access to Windows systems. The five flaws could permit attackers to retrieve information from vulnerable hosts, potentially exposing data…
IT Security News Hourly Summary 2026-07-15 09h : 6 posts
6 posts were published in the last hour 6:35 : EU Sets Out Plans For Social Media Restrictions 6:35 : Fortinet Patches 7 Security Flaws Affecting FortiOS, FortiProxy, FortiPAM, FortiSASE, and FortiSandbox 6:34 : China-Linked Hackers Weaponize Claude Code and…
EU Sets Out Plans For Social Media Restrictions
European Commission to propose phased approach to allowing children access to social media, amid pressure from member states on safety This article has been indexed from Silicon UK Read the original article: EU Sets Out Plans For Social Media Restrictions
Fortinet Patches 7 Security Flaws Affecting FortiOS, FortiProxy, FortiPAM, FortiSASE, and FortiSandbox
Fortinet has released security updates for seven vulnerabilities affecting FortiOS, FortiProxy, FortiPAM, FortiSASE, and FortiSandbox, including a high-severity flaw that could expose Virtual Network Computing (VNC) access across all network interfaces. The advisories, published by the Fortinet Product Security Incident…
China-Linked Hackers Weaponize Claude Code and DeepSeek in Government Intrusion Campaign
A suspected China-linked threat actor has integrated Anthropic’s Claude Code and DeepSeek-v4-pro into an active intrusion campaign targeting government entities, Taiwanese industry, and financial-services organizations. TencShell was first documented by Cato CTRL in May and assessed as linked to suspected…
Critical Claude for Chrome Flaw Lets Malicious Extensions Read Gmail, Google Docs, and Calendar
Two vulnerabilities in Anthropic’s Claude for Chrome extension could allow a malicious browser extension to trigger AI-driven actions affecting a victim’s Gmail, Google Docs, and Google Calendar data. These issues are still reproducible in Claude for Chrome version 1.0.801.0, released…
Americans are ignoring scam calls, but phishing emails still fool many
Americans are becoming more effective at avoiding spam calls and texts, but new research suggests that the strategy comes with an unexpected cost. A new survey of 1,000 Americans from privacy company Cloaked, revealed that two-thirds of respondents have missed…
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed below – CVE-2026-15409 (CVSS score: 10.0) –…
Russian Hackers Hijack Routers To Target Critical Infrastructure
Threat group attributed to Russia’s FSB security service actively seeking out poorly configured routers around world, researchers say This article has been indexed from Silicon UK Read the original article: Russian Hackers Hijack Routers To Target Critical Infrastructure
Notepad++ v8.9.7 Security Update Fixes 5 Vulnerabilities, Including Stack Buffer Overflow and Zip Slip Flaws
Notepad++ has released version 8.9.7, codenamed “Slava Ukraini.” This update addresses five security vulnerabilities related to session-file handling, environment-variable expansion, ZIP extraction, macro validation, and the Windows installation process. The release date was July 14, 2026, and includes three CVE-tracked…
Goose Creek – 6,574,121 breached accounts
In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company’s customers, claiming the company had a security vulnerability and suffered a data breach. The data was…
Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection Attacks
Notepad++ v8.9.7 has been released with critical security fixes addressing multiple vulnerabilities, including a high-risk PowerShell command injection flaw that could enable arbitrary code execution during installation. The update resolves five distinct issues spanning path traversal, buffer overflow, and authentication…
Microsoft Active Directory Services 0-Day Vulnerability Actively Exploited in the Wild
Microsoft has released security updates for CVE-2026-56155, an actively exploited elevation-of-privilege vulnerability in Active Directory Federation Services (AD FS). This flaw allows an authenticated local attacker with low privileges to gain administrator-level access on affected systems. CVE-2026-56155 stems from insufficient…
SingGuard-NSFA: Open-source guardrails for agentic AI
SingGuard-NSFA is an open-source guardrail framework aimed at operational threats in agent workflows. Four models ship at 0.8B, 2B, 4B, and 9B parameters, all built on Qwen3.5 base backbones. Risk taxonomy The NSFA risk taxonomy organizes threats along the CIA…