Recent articles
September 2, 2026
BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
What can we learn from a BGP hijacking that poisoned production software? Plenty.
arstechnica.com
August 31, 2026
Think twice before installing this device promising free movies
In exchange for free stuff, devices make home connections part of a proxy network.
arstechnica.com
August 28, 2026
Authorities arrest 2 alleged members of prolific hacking group TeamPCP
The group infected more than 1,000 organizations in a relentless supply-chain attack campaign.
arstechnica.com
August 27, 2026
Claude, Codex, and Hermes installed unowned code inside corporate networks
227 install commands were found in corporate docs pointing at code nobody owns.
arstechnica.com
August 27, 2026
How OpenAI let a mob of LLM agents game a test and ransack Hugging Face
Without authorization, 1,200 OpenAI agents conspired among themselves to game a test.
arstechnica.com
August 24, 2026
Inaudible sounds used to fingerprint browsers catch AliExpress red-handed
Is the technique outdated? Yes. Is it still creepy? Also yes.
arstechnica.com
August 20, 2026
Grok exfiltrates user data when malicious instructions are encrypted
Cryptographic Context Injection is only the latest way to break an LLM safety guardrail.
arstechnica.com
August 18, 2026
Microsoft Copilot reveals secret input that allowed it to be hacked
Secret parameter allowed hackers to steal passwords when a target clicked on a link.
arstechnica.com
August 14, 2026
Vulnerability giving attackers full control of Macs is under active exploitation
Screen-sharing bug lets remote hackers log in without a password.
arstechnica.com
August 13, 2026
Private security firms will soon be allowed to hack overseas cybercriminals
Trump memo is first time gov't has authorized private sector to perform cyber attacks.
arstechnica.com
August 12, 2026
Terabytes of credentials leaked in massive supply-chain attack
The data was scraped and exfiltrated from 2,500 users of a compromised AI package.
arstechnica.com
August 11, 2026
Chrome adopts what may be the best protection yet against account takeovers
Device-bound session credentials thwart an increasingly common form of account takeover.
arstechnica.com
August 11, 2026
New Pass-ta-key attack reveals all the things we didn't know about passkeys
Why passkey apps treat Windows differently than other operating systems.
arstechnica.com
August 5, 2026
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Baseboard management controllers from the world's biggest manufacturers are a security mess.
arstechnica.com
July 31, 2026
Likely illegally, Claude gained access to 3 networks. Will Anthropic be held to account?
Had the hacks used conventional methods, someone would likely go to prison.
arstechnica.com
July 30, 2026
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Exploits can give persistent server access that survives credential rotation and disk re-imaging.
arstechnica.com
July 29, 2026
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
HAWK withstood years of testing that had yet to uncover a fatal weakness found through Mythos.
arstechnica.com
July 28, 2026
We now have a better understanding how OpenAI hacked into Hugging Face
10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch.
arstechnica.com
July 27, 2026
Microsoft unveils AI security tools it says outperform competing platforms
Microsoft says tools cost less than competing ones and outperform them, too.
arstechnica.com
July 18, 2026
Prompt Injection Attacks Are Thwarting AI Hacking Agents
“Context bombing” tricks malicious AI agents into shutting down before they can do harm.
www.wired.com
July 16, 2026
Now, even Russia's most elite hackers are using Clickfix to infect devices
The social-engineering technique has primarily been a tool of financially motivated criminals.
arstechnica.com
July 15, 2026
Windows 0-day drops the same day Microsoft releases record number of patches
HiveLegacy is a "powerful primitive" that's likely capable of other nefarious actions.
arstechnica.com
July 14, 2026
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
Old and forgotten "shims" Microsoft failed to revoke have made Secure Boot bypasses simple.
arstechnica.com
July 13, 2026
The US government warns that Russia state hackers are coming after your router
With residential proxies all the rage, CISA urges router users to be vigilant.
arstechnica.com
July 13, 2026
Now, defenders are embracing the prompt injection, too
"Context bombing" tricks hacking agents into shutting down before they can do harm.
arstechnica.com
July 9, 2026
Patch for Windows Defender 0-day could allow attackers to fill hard disk
The feud between NightmareEclipse and Microsoft shows no signs of resolving soon.
arstechnica.com
July 8, 2026
Google pays $250K for Linux vulnerability allowing guest VM escapes
Both vulnerabilities allow untrusted users to gain root privileges.
arstechnica.com
July 8, 2026
Hackers can use 9 of the most popular AI tools to assemble massive botnets
"HalluSquatting" weaponizes LLMs' inability to say "I don't know."
arstechnica.com
July 2, 2026
Newly discovered PamStealer isn't your typical macOS malware
The discovery underscores the increased effort being poured into Mac infostealers.
arstechnica.com
June 30, 2026
New attack provides one more reason why AI browsers are a bad idea
Telling an LLM that 2 + 2 = 5 is enough to make it follow forbidden instructions.
arstechnica.com