Cybersecurity News
Filters
NASA's ground control software has a worrying security flaw which could let hackers contact spacecraft
Researchers have discovered a security vulnerability in NASA's open-source ground control software, which handles communications with spacecraft and instruments. The flaw could potentially allow hackers to intercept or send unauthorized commands to space missions. NASA has been informed of the vulnerability, highlighting ongoing cybersecurity concerns around critical space infrastructure.
Android users beware — if you own one of these budget smartphones, your device could be hacked with a simple video call
Researchers have discovered a security vulnerability affecting budget Android smartphones using Unisoc chips. The exploit can be triggered simply by initiating a video call, potentially granting attackers root-level access to the device. Unisoc chips are commonly found in affordable handsets across developing markets. Users are advised to apply any available security updates and remain cautious until patches are widely distributed.
Hackers are using “evolved” capabilities in AI-generated malware to hit US critical infrastructure at an unprecedented scale — “active threat” currently hitting energy, water and agricultural industries
Hackers are using AI-generated malware to attack US critical infrastructure at an unprecedented scale, targeting energy, water, and agricultural sectors. The ongoing campaign exploits internet-facing Siemens S7 Series programmable logic controllers to identify targets. Officials describe it as an active threat, with attackers demonstrating evolved capabilities attributed to AI-assisted tools.
Scammers pose as ransomware recovery agents, but just go on to steal more from victims
Cybercriminals are posing as ransomware recovery specialists to defraud victims twice. Groups like "Ransom Busters" pose as legitimate recovery firms, approach ransomware victims, and pocket fees without delivering results. In reality, they are ransomware affiliates exploiting desperate victims. Experts warn organizations to thoroughly vet any recovery service before paying, as the fake recovery industry is growing alongside ransomware itself.
Moving AI from pilot to production
Many enterprises struggle to move AI beyond pilot projects. Success requires reliable infrastructure, clean data pipelines, and robust security. Equally important is building organizational trust through transparency and explainability. Leadership must champion AI initiatives, align them with business goals, and foster cross-functional collaboration. Without these foundations, AI projects stall despite promising early results.
Healthtech firm CareCloud reveals March 2026 data breach impacted 3.7 million patients
Matched: health
Healthcare technology company CareCloud has disclosed a data breach that occurred in March 2026, affecting approximately 3.7 million patients. The company is notifying those impacted, though it has not revealed what specific types of patient information were compromised in the incident.
BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
Researchers found Microsoft Defender's signed remediation driver can be repurposed as a kernel-level attack primitive without exploits or memory corruption. By instructing the trusted driver to execute arbitrary file and registry operations from Ring 0, attackers gain powerful kernel access. The technique requires no vulnerabilities, leveraging a legitimate Microsoft component against itself.
NCSC Urges Stronger Controls for Agentic AI Systems
The UK's National Cyber Security Centre has warned that agentic AI systems — which can plan and execute tasks autonomously — introduce significant security risks. The NCSC recommends organisations apply strict access controls, sandbox AI agents to limit their reach, maintain human oversight, and carefully vet the tools and data agents can access, to reduce risks from errors, manipulation or misuse.
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
Matched: cryptocurrency
Manic is Android malware targeting Ukrainian and European banks, government services, cryptocurrency platforms, and military communications. It blends banking malware with spyware capabilities and can exfiltrate data from offline phones by routing it through nearby infected devices. The malware targets financial credentials, identity data, and messaging apps, representing an unusually sophisticated cross-sector mobile threat.
Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service
A facial recognition database belonging to ClarityCheck, a reverse image search and identity verification service, was left exposed, leaking over 9 million images. The breach was discovered by security researchers who notified the company, which subsequently secured the database. The incident raises serious privacy concerns given the sensitive biometric nature of the exposed data.
How AI is transforming the role of test engineers
AI is reshaping the test engineer role, shifting focus from writing test cases manually to overseeing AI-generated automation. Engineers increasingly act as "quality orchestrators," validating AI outputs, interpreting results, and making strategic decisions. While AI handles repetitive tasks faster and at scale, human judgment remains essential for contextual understanding, edge cases, and ensuring systems align with real-world user expectations.
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Matched: cryptocurrency
ToxicPanda malware has been updated with 167 remote commands and expanded global targeting, according to Zimperium zLabs. The Android banking trojan now includes PIN harvesting capabilities targeting over 140 banking and cryptocurrency apps. Researchers also noted connections to the GoldDigger malware family, with both conducting on-device fraud to bypass traditional security measures.
Before approving the next AI budget, check the network
UK boards are being urged to evaluate their network infrastructure before increasing AI spending. Experts warn that connectivity, resilience, and visibility are prerequisites for effective AI deployment. Without assessing these foundations, organisations risk wasting investment on AI tools that underperform due to inadequate underlying infrastructure. Boards are advised to treat network readiness as a governance priority alongside AI strategy.
15 Malicious Firefox Extensions Abuse Cloudflare Workers to Exfiltrate Crypto Wallet Secrets
Matched: cryptocurrency
Fifteen malicious Firefox extensions posing as crypto wallets, themes, and browser tools have been stealing recovery phrases, private keys, login credentials, and clipboard data since at least March 2026. The campaign uses Cloudflare Workers to exfiltrate stolen information and spans 77 extensions total, putting users' digital assets and online accounts at serious risk.
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
Matched: cryptocurrency
Researchers found 40 malicious Firefox extensions disguised as Web3 products like OKX and Rabby Wallet that steal cryptocurrency wallet credentials. Dubbed "Offside Wallet Theft Factory" by Socket Threat Research, the extensions are part of a broader group of 77 add-ons sharing code and infrastructure. Users are advised to verify extensions carefully before installing.
AI vendor dependency is becoming a resilience risk
Enterprises increasingly rely on a small number of AI vendors, creating significant resilience risks if those services fail, change pricing, or shut down. Experts warn that organizations must build governance frameworks and contingency strategies into AI planning from the start, rather than treating vendor dependency as an afterthought, to ensure long-term stability and operational continuity.
Op-Ed: Australian AI agents need expiration dates, not just permissions
Matched: Australia
Australia's AI governance debate is shifting from whether to deploy AI agents to how to govern them once active. Experts argue current permission-based frameworks are insufficient, proposing AI agents be given expiration dates — automatic deactivation after set periods — rather than relying solely on access controls. This would limit risk from forgotten or compromised agents operating indefinitely within sensitive systems.
Airlock Digital Completes Independent IRAP Assessment at the PROTECTED Level
Matched: Australia
Airlock Digital has completed an independent IRAP assessment at the PROTECTED level, providing Australian government, defence, and critical infrastructure organisations with additional assurance when evaluating the company's application control and allowlisting solutions for use in sensitive environments.
Exclusive: Ransomware newcomers list South Australia’s Ramsey Bros as hacking victim
Matched: Australia
Ransomware group Storm claims to have hacked Ramsey Bros, a South Australian farm machinery supplier. The group says it has published stolen data as proof, including alleged customer information and vehicle inspection records. Ramsey Bros has not yet publicly commented. Storm is considered a newcomer among ransomware groups, which typically steal and threaten to leak data to pressure victims into paying.
High Alert! Aussie cyber agency warns of active exploitation of N-able N-central vulnerability
Matched: Australia
Australia's cyber security agency has warned of active exploitation of a high-severity vulnerability in N-able's N-central remote monitoring and management software. The ACSC is urging Australian organisations using the platform to apply patches immediately. The flaw could allow attackers to gain unauthorised access to systems managed through the software.
