NextRecap What's next in tech
HOME / TOPICS / SECURITY

Security

Novel attacks, exploits, worms and demonstrated weaknesses in systems people actually use. Named intrusions with a timeline and a result — not routine CVE round-ups or breach filings.

156 stories in the last month Other topics: AI · Robots · Hardware · Design · Science · Space · Dev

Latest SECURITY

New Pass-ta-key attack reveals all the things we didn't know about passkeys Passkey apps handle Windows authentication differently than other platforms, creating security inconsistencies Ars Technica · 9h
There’s a major security hole in CDJs, Rekordbox; here’s what’s affected AlphaTheta announced critical security vulnerabilities affecting many CDJ/XDJ models and all versions of Rekordbox across macOS, Windows, An CDM · 1d
Now we have a timeline of the OpenAI accidental attack against Hugging Face OpenAI presented details at Black Hat about a security incident involving Hugging Face. Simon Willison · 4d
‘Zoomsday’ hack uncovered using fewer than 20 AI prompts

Researchers at A Security found a critical Zoom vulnerability allowing device hijacking during calls using fewer than 20 AI prompts; Zoom ha

A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

AI tool found a Zoom screen-sharing vulnerability (now patched) that let call participants hijack each other's devices

Active in security ALL ENTITIES →

Every security story, by month

AUGUST 2026
The Register Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure The Register Deepfake hiccup unmasks suspected digital certificate fraudster The Register Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub The Register Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G The Register Japan kind-of completes its sovereign satnav constellation The Register Anthropic pledges to embed watermarks to help discern AI slop in sop to EU The Register DEF CON hackers add new muscle to water utility protection The Register Zuck rekindles open weights Llama drama with Muse Glimmer The Register North Korean spies are running local LLMs to cause AI mischief Engadget An OpenClaw agent reportedly hacked a gym's booking system and kicked someone off a waiting list The Register Cyber vulnerability sweep picks up Royal Navy drones sending data to China Tom's Hardware GeForce NOW exploit lets you access the full Windows desktop through a simple file swap — Modder runs local AI models on Ultimate tier with 48GB of VRAM and no restrictions Tom's Hardware Steam hardware distributor hit by cyberattack, 'expect fake messages,' Valve warns — Europe vendor has personal information and hardware purchase details stolen The Register Smart glasses are only smart if we train them to be good. Then they'll be fantastic The Register Linus Torvalds says AI has made 'huge' Linux kernel updates the new normal The Register Advertisers are trying to influence AI bots with secret ads The Register NEC tests parking tech that only starts charging once you exit your car The Register Ransomware gangs skip the CEO, head straight for the 40-something IT manager Simon Willison Now we have a timeline of the OpenAI accidental attack against Hugging Face The Register Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default simonwillison.net Timeline of the OpenAI accidental attack against Hugging Face The Register South Korean satellite spots SpaceX lunar impact github.com Hardware backdoors in some x86 CPUs The Register OpenAI pledges to add Astra security as Anthropic loosens Fable's leash TechCrunch OpenAI says it slowed Astra model development over security concerns Hackaday Hacking a $6000 Cotton Candy Machine to Fully Control It The Register Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks The Register AI titans to tidy agent frontier with plugin prescription Engadget Framework customer information was accessed as part of a data breach The Register Ransomware attacks spike as world distracted by AI The Register Brit boffins boast of beating barriers to building fusion power TechCrunch Computer maker Framework notifies ‘all customers’ of a data breach The Register N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands The Register ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they've dumped 10.9M email addresses The Register MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs Hackaday This Week in Security: Claude Gets Hacking, Hotel WiFi, and NPM Compromised Again The Register Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder The Register Microsoft tosses Teams Live chat into its feature graveyard The Register Attacker phished way into US defense supplier's Microsoft 365 account The Register Intrusion at US healthcare software provider puts 3.8M people's data at risk The Register 'Asimov was right' about rules for robots, says ex-US Cyber Director The Register Cop who used police system to snoop for info on crook pals sentenced for Computer Misuse Act offenses The Register Sysadmin summoned to explain italics – to a user with at least two degrees The Register China launches mysterious probe into security of Palo Alto Networks' products The Register ‘Humans will be a rounding error on the internet’ says Cloudflare exec The Register How the famed USENIX Security conf is managing a flood of papers in the AI era Wired Hackers Stalked Me by Hijacking a Smartwatch for Kids The Register AI struggles to patch vulns without adult supervision The Register Latest GitHub outage squeezes Actions, Pages to death The Register Uncle Sam aims to help nuclear energy find its sea legs GitHub Blog How we took malware advisories beyond npm The Register Humans in the loop miss a third of dangerous AI coding agent requests github.com schrodingers-toctou: The binary you run is not the program you wrote The Register Next step for LINK spacecraft – a software update that won't make things worse. Are you listening, Microsoft? The Register Platform Engineering 2.0: your platform was built for a different era. AI just exposed it The Register Microsoft excludes Domain Exclusion from MS 365 Copilot – days after rolling it out The Register Snowflake extortionist admits 165-victim cloud crime spree – and squeezing one target twice The Register Blue Origin blames New Glenn fireball on engine oxygen valve The Register European firms afraid of US tech kill switch but haven't made an escape plan The Register IT department put sticky notes on the laptops to help employees log in The Register Meta latest to tell world its AI agent wandered out of test pen The Register Azure CTO pastes Doom into Paint one frame at a time Hackaday Hacking a Tenda AC1200 Wi-Fi Router with a CVE Combo The Register Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway The Register OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack The Register Meta wants to get inside your terminal with its new coding agent Simon Willison An AI model from Meta also hacked another company during testing Wired OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree Wired A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide Ars Technica Thousands of servers can be backdoored by exploiting buggy motherboard controllers The Register Time Magazine has a separate version of its website with ads only AI can see Ars Technica Anthropic’s AI used fake identities, malware in rogue attack on GitHub project The Register IBM's agentic AI platform is under active attack - patch now The Register Samsung and Mousterian move ahead with floating datacenter for Texas The Verge Rogue AI agents created fake online identities in another hacking attempt The Register Voyager 2 cheats the power budget for another year The Register Keeping yesterday's computers ticking takes more than nostalgia Engadget OpenAI and Anthropic models went on a hacking spree when tested by the UK's AI research institute The Register AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project The Register AMD's results spotlight risks of putting all your AI eggs in too few baskets The Register Dev proves LLMs will run on anything – even a $10 microcontroller The Register Bypassing AI guardrails is so easy a script kiddie can do it Hackaday BornHack Radio 102.8 FM, Playing Radio At A Hacker Camp The Register Feds get 3 days to patch N-able God mode flaw under active exploit The Register AI helps Microsoft bug hunters chase a record $20M payday The Register NASA puts astronauts’ lives in the hands of Tesla’s flaky Cybertruck The Register Cloudflare has mostly ditched third party security tools, suggests not trying that at home The Register China turns up the heat with open model blitz as US model makers panic The Register Google dev kit spurs first-ever agent-on-agent violence Hackaday Circuit Bending, But Make It MIDI The Register AI slop pollutes the CVE pipeline with fake vulns The Register Russian spies turn public Wi-Fi into malware delivery systems The Register Google Earth's AI makeover survives one trip around the Sun The Register Google Earth's AI makeover survives for just one planetary rotation MIT Tech Review Here’s why AI agents lie and cheat to reach their goals The Register Claude Code is revolutionizing digital archaeology. Enterprise better dig it The Register AI is 'both the weapon and the target' in latest wave of cyberattacks The Register Microsoft says 8 GB of RAM should be enough for anyone running Windows 11 Tom's Hardware Iran suspected of conducting cyberattacks on US water suppliers in 45 municipalities — small towns mostly targeted, with utilities switching to manual control New Atlas Sub-$300 diagnostics tablet jailbreaks modern vehicle software locks warez.sl0p.foo Apple Screen Sharing Pre-Auth RCE darknavy.org Patch In, Exploit Out: How deepsec Reconstructed the Pwn2Own Microsoft Edge Sandbox Escape Tom's Hardware Anthropic's Claude hacked three real-life companies during security capabilities test — test environment with internet access and unwitting targets' lax cybersecurity practices led to bots running rampant Wired 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran Ars Technica Defcon's new badge is a security key you can see inside The Register A deep dive into Nvidia's Vera CPU and the Olympus cores that power it
JULY 2026
Ars Technica Claude published malicious code to the Internet and attacked 3 real companies The Register Dev who gave HashiCorp its name returns with a faster terminal multiplexer tailscale.com Tailscale didn't stop the Hugging Face intrusion The Register The most famous brand in physical security got pwned by ShinyHunters The Register US bank places trust in ransomware crew that promised to delete its data Hackaday Hacking a Commercial Colorimeter to add RAL Color Code Support The Register Anthropic and OpenAI are competing to see whose agents can go rogue harder The Register Update Teams mobile app by October or lose your calendar The Register NASA's Swift rescue slips to late August as LINK battles its spin New Atlas I let another AI attack SwitchBot's AI Hub and it won (review) The Register Scotland's university procurement center confirms cybercrooks broke in The Register Anthropic’s Claude escaped test sandbox to attack three organizations TechCrunch Anthropic says its own AI models breached three companies during security tests OpenAI Disrupting a Criminal Scam Operation TechCrunch Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI The Register GPUs could explode to multiple TB with new storage-inspired memory tech The Register Open source project fools AI scrapers with poisoned font The Register Jailed Flock vandal wipes out three cameras, racks up thousands in damages TechCrunch In the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppable ethiack.com KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) The Register Amazon links four poisoned npm packages to one North Korean crew lwn.net GCC steering committee announces AI policy The Register Hims & Hers accused of sharing health secrets and hiding the cancel button The Register MariaDB again faces questions over Galera's open source future The Register Russian spies take their half-click email attack from Zimbra to Outlook MIT Tech Review A fundamental flaw leaves LLMs strikingly vulnerable to attack The Register Brighton gig screen goes One Step Beyond with an update pop-up The Register Curiosity rover spots field of giant honeycomb on Mars – but no giant space bees Hackaday Keyboard Lights As An Airgap Attack Vector Hackaday Using Video Glasses As a Camera Viewfinder Is Harder Than It Looks Ars Technica Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission The Register NOAA ditches weather-predicting supercomputers for Google Cloud The Register Big vacuum is watching as robo-cleaners put humans behind the wheel TechCrunch The Hugging Face break-in explained The Register Uncle Sam sees the light, offers GlobalFoundries $300M to pursue silicon photonics while taking 1% stake Simon Willison AI Worming through Word Wired It’s Frighteningly Easy to Jailbreak Some Frontier AI Models The Register Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems The Register AI digs through 3,700 accounts of dreams and waking life, finds method in the madness Simon Willison Discovering cryptographic weaknesses with Claude Simon Willison Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident MIT Tech Review OpenAI called the Hugging Face attack unprecedented. But we’ve been here before. Import AI Import AI 466: The bitter lesson for robotics, AIs complete week-long programming tasks; and OpenAI's accidental AI hacker Hugging Face Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident