ChatGPT users have gained two new security controls: one aimed at preventing data theft through prompt injection and another at tracking account sign-ins. According to OpenAI, the first of these, Lockdown Mode, is an optional setting that limits how far… Read More "OpenAI Unveils ChatGPT Account Security Controls"
North Korean Hackers Use Fake Coding Tasks to Steal Crypto
A likely North Korean threat actor has phished software developers at almost 100 organizations with fake job and code-review lures to steal cryptocurrency and credentials. According to new analysis from Proofpoint, which tracks the cluster as UNK_DeadDrop, the campaign sent… Read More "North Korean Hackers Use Fake Coding Tasks to Steal Crypto"
WhatsApp Discovers NSO Group-Linked Spearphishing Attempts
WhatsApp has asked a US court to hold a blacklisted spyware firm in contempt, after claiming it has violated a permanent injunction banning it from targeting users. The messaging giant said on June 8 that it “successfully disrupted” social engineering… Read More "WhatsApp Discovers NSO Group-Linked Spearphishing Attempts"
Infosecurity Europe: Why JLR’s CISO Enforced In-Person Password Resets
When Jaguar Land Rover (JLR) was hit by a major cyber-attack in September 2025, one of the first things the company’s cybersecurity leader did was to call over 30,000 staff on site to reset their passwords. Speaking during Infosecurity Europe… Read More "Infosecurity Europe: Why JLR’s CISO Enforced In-Person Password Resets"
Check Point Warns Critical Auth Bypass Bug Exploited in the Wild
Check Point has urged customers to patch a critical zero-day vulnerability in its Remote Access VPN and Mobile Access solutions that is being actively exploited. CVE-2026-50751 is an authentication bypass flaw that affects deployments configured to use the deprecated IKEv1 key… Read More "Check Point Warns Critical Auth Bypass Bug Exploited in the Wild"
Google Releases Patch for Chrome Vulnerability Exploited in the Wild
Google has released an emergency update to patch 74 Chrome vulnerabilities, including a high-severity flaw that has been exploited in the wild. This is the fifth Chrome zero-day vulnerability in 2026 that has been exploited before a patch has been… Read More "Google Releases Patch for Chrome Vulnerability Exploited in the Wild"
Critical phpBB Flaw Lets Attackers Hijack Any Account with One Request
A critical flaw in the phpBB forum software has been disclosed that lets attackers hijack any account, including administrators, with a single unauthenticated request and no password. Tracked as PTT-2026-004 and rated 9.4 on the CVSS scale, the flaw is… Read More "Critical phpBB Flaw Lets Attackers Hijack Any Account with One Request"
AI Coding Adoption Hits 97% but Governance Lags Behind
Nearly all software development teams have adopted AI coding assistants, but fewer than a third govern how the tools are used and that gap is capping the productivity AI promises. The figures come from an independent survey of 831 software… Read More "AI Coding Adoption Hits 97% but Governance Lags Behind"
75% of Firms Deploy Vulnerable Code Amid Pressure on CISOs
Nearly all CISOs have felt pressured to suppress or delay compliance-related cybersecurity issues in code, especially when business deadlines need to be hit, a new report has warned. According to the research, released on Jun 8 by Checkmarx, 95% of… Read More "75% of Firms Deploy Vulnerable Code Amid Pressure on CISOs"
Microsoft Fixes 200 CVEs This Patch Tuesday
System administrators are in for a busy few weeks after Microsoft published updates to fix 200 vulnerabilities including three publicly disclosed zero-days June’s Patch Tuesday. A total of 33 critical CVEs were tackled, with most (28) remote code execution (RCE)… Read More "Microsoft Fixes 200 CVEs This Patch Tuesday"