Law enforcement in Wapello County, Iowa is operating under a usage policy that explicitly directs officers not to disclose their use of Flock automated license plate reader cameras to vehicle occupants or in official reports unless absolutely necessary. This practice of concealing surveillance technology deployment mirrors historical patterns seen with IMSI-catchers like Stingray devices, which police similarly went to great lengths to keep hidden from the public and legal proceedings.
A campaign tracked as Offside Wallet Theft Factory has distributed 40 malicious Firefox extensions impersonating legitimate Web3 wallet applications including OKX, Rabby Wallet, and TronLink to steal cryptocurrency credentials. The Socket Threat Research team identified the malicious add-ons as part of a larger infrastructure of 77 browser extensions sharing common code and infrastructure, indicating a coordinated theft operation.
Oz Hair and Beauty confirmed a data breach affecting customer information accessed through its online platform before August 2026, exposing names, email addresses, phone numbers, and purchase history, though credit card details and banking information were not compromised. The company has launched a forensic investigation with external specialists, notified affected customers, and is implementing enhanced cybersecurity measures, while warning customers to remain vigilant against phishing attempts and unsolicited requests for personal information.
A critical vulnerability in Elementor Pro's Forms module allows unauthenticated attackers to upload PHP files and execute arbitrary code on affected WordPress installations. Tracked as CVE-2026-32475 with a CVSS score of 9.0, this unrestricted file upload flaw poses severe risk to sites running the vulnerable plugin. Researchers have publicly disclosed technical details of the vulnerability, increasing the likelihood of active exploitation.
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9 (Critical). Affects TrueConf Server.
TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.8 (Critical). Affects TrueConf Server.
At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold statuettes of Mozart have vanished from the streets. This has happened to the same artist before. Organised crime, or a publicity stunt? Jenny has thoughts - and some parallels for the world of cybersecurity. All this and more in episode 481 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Jenny Radcliffe.
A new AI platform called Kriminal is being offered without content filters or safety guardrails, despite official policies against illicit use, enabling bad actors to access tools for social engineering, offensive cybercrime operations, and reconnaissance scanning. The service's accessibility via cryptocurrency payments raises concerns about its potential abuse for coordinated cyberattacks and other malicious activities in the threat landscape.
Enterprises face a new insider threat vector as agentic AI systems gain adoption, requiring organizations to implement monitoring strategies for autonomous agents operating within their infrastructure. The concern has been heightened following recent security incidents, prompting security leaders to reassess how AI agents with system access could be exploited or compromised to facilitate attacks from within.
CISA and the FBI have warned of an ongoing AI-backed campaign targeting vulnerable Siemens S7 industrial control devices across multiple critical sectors including energy and water utilities. Threat actors are employing disguised scripts that appear to be legitimate software to compromise these systems, leveraging artificial intelligence in their attack methodology.
Researchers have disclosed a remote Spectre attack against Cloudflare Workers that successfully extracted a JSON Web Token from a co-located Worker in production, achieving data exfiltration rates of up to 12 bits per second. The attack represents a significant improvement over previous demonstrations, running 360 times faster than a similar attack shown in 2021, and was conducted using an attacker-controlled Worker alongside a victim Worker in a controlled end-to-end experiment.
U.S. agencies are warning that AI-fueled attacks represent an active threat to water utilities and other critical sectors. Hackers are reportedly targeting Siemens S7 Series programmable logic controllers in attacks that agencies characterize as potentially unprecedented in their use of AI techniques.
OpenAI has temporarily halted reinforcement learning training for its latest models to strengthen its internal safety defenses and expand monitoring capabilities, citing growing risks as AI systems become more advanced. The two-week pause follows concerns about preventing incidents similar to a previous Hugging Face-related event. The company emphasized that developing and testing increasingly capable models carries escalating risks that necessitate enhanced protective measures.