Cyfirma's latest Automotive Industry Report for the second quarter of 2026 rates the sector’s overall cyber risk at 5.0 out of 10, classified as elevated. Drawing on 90 days of telemetry across five threat categories, the analysis reveals a mixed picture of steady ransomware pressure, third-party-driven incidents, and a distinctive pattern of financially motivated activity. Ransomware activity produced 47 victims across 20 countries, remaining effectively flat quarter by quarter with the secto
All Articles (3171)
On 19 August 2026, US DHS CISA partnered with National Security Agency and other US government partners to publish a joint Cybersecurity Advisory about an active threat targeting Siemens S7 series programmable logic controllers (PLCs). The advisory, Defending Against an Active Threat to Siemens S7 Series PLCs, provides an overview of the threat activity, and mitigations to protect and defend against this activity.
Threat actors are conducting targeted reconnaissance and capability developme
The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and US Department of Health and Human Services (HHS) are releasing this updated joint advisory to disseminate known Medusa ransomware tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) identified through FBI investigations as recently as April 2026. Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. Both Medusa developers and affiliates
FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary. While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple
Millions of photos go online every day. Most people still treat a face in a picture as belonging to the person who is depicted. That assumption may no longer hold true. Software can now lift a face from one photograph and drop it into a completely different scene, or put a stranger’s face into someone else’s original setting while keeping the pose, expression, clothes, and background. The results look real enough that ordinary viewers, and sometimes the detection software itself, accept them
A cybercriminal AI service called MessiahGPT is being advertised on BreachForums as an unrestricted platform for generating malware, phishing material, and other illegal content, according to new research from Trellix. MessiahGPT operates through messiahgpt.de and has an associated Telegram community. Trellix said the platform was live when its researchers examined it, offering 50 free queries without registration. Paid plans start at $8 per month, with cryptocurrency accepted and no identity
The most common cybersecurity threats that K-12 schools face are data breaches, ransomware attacks, business email compromises, denial of service attacks, and invasions, according to CISA, a division of the US Department of Homeland Security. "Unfortunately, cyber criminals often see K-12 schools and school districts as lucrative soft targets for their exploits," CISA said in the 12 August guidance. "Part of this may be attributed to the fact that K-12 policy, planning, budgeting, resources an
Security practitioners face twin pressures as artificial intelligence enters everyday penetration testing. Teams use AI to discover weaknesses faster while also checking the AI systems their organizations introduce. New findings from Pentest-Tools.com show demand already outstrips capacity for most groups. Nearly nine out of ten practitioners who have generated findings with AI report that the results need substantial manual checking.[1]
Among 147 respondents who had used such tools, 87.8% sa
Wille Sutton, a famous USA bank robber, was quoted as saying, “I rob banks; that’s where the money is.” The “money” is now in cybercrime. Cybercrime continues to exact a heavy toll on the world economy, yet accurate figures remain elusive because so many incidents go unreported. A new Comparitech study of the top 100 countries by GDP has put the annual cost to victims at an estimated $1.24 trillion. For perspective, $1.24 trillion is about 3.8% of total nominal US Gross Domestic Product (GDP
For more than a decade, scientists have described neural networks that could run on quantum computers. The promise was clear: quantum bits can exist in combinations of states and can share linked relationships that ordinary computers cannot copy easily. Those features might let a quantum network solve certain pattern problems more effectively than any classical system. Until recently almost every discussion of the idea stayed on paper or on ordinary computers that only simulated quantum behav
Imagine a busy intersection where one self-driving car spots a pedestrian stepping out from behind a delivery truck while another vehicle, approaching from a different angle, detects the truck slowing down unexpectedly. If these two cars could combine what they see, the result would be a more complete picture that helps both vehicles anticipate hazards earlier and respond more smoothly. This kind of cooperation could reduce crashes, ease traffic flow, and make autonomous driving
Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. This advisory provides technical details of the activity, as well as tailored detection and mitigation
The UK AI Security Institute (AISI) reported that an agent running Claude Mythos 5 spent 34 hours trying to merge a malware dropper into a real open-source project during a security evaluation, after searching the open internet and landing on a real, unconnected repository whose name happened to share a keyword with the test’s fictional scenario.[1]
The agent researched the maintainers, opened a pull request pairing a hidden dropper with a working bug fix, and cycled through three payload versio
The debate around Anthropic's Claude Mythos has already moved beyond Silicon Valley. Recently, access to the model became the subject of unprecedented government restrictions. This is primarily about concerns that its vulnerability and discovery capabilities could be misused by hostile actors. Controls have partially eased following additional safeguarding.
In a matter of weeks, this has created an interesting ripple effect: AI supply is becoming increasingly global. Foundational models are adva
Infrastructure provider Cloudflare has published its Q2 2026 Internet Disruptions report, examining how apparently minor technical failures and external events can disconnect entire countries from the global network. Drawing on visibility across more than 330 cities in over 125 countries, the company used traffic data from Cloudflare Radar to document the scale and causes of the quarter’s most significant outages.
On 5 May 2026 a maintenance error during a DNSSEC key rollover at DENIC, the reg
Since ChatGPT arrived in late 2022, analysts at SentinelLABS have been bullish about what large language models (LLMs) could do for reverse engineering and malware analysis. The early models were useful for teaching but too rudimentary for production work; that changed with the advent of reasoning models. OpenAI’s o1-preview, in September 2024, was the first to show the kind of sustained problem-solving the work demands, and within months Sean Heelan had used o3 to find a net-new vulnerability
Netflix is being sued for $105 million after hard drives containing unreleased content, including a copy of the Nicolas Cage war thriller Fortitude, were taken from the Streamer’s Los Angeles offices. The action has been brought by Swiss producer and financier Simon Afram together with his company Op-Fortitude Ltd in California federal court. Afram invested more than $45 million of his own money in the project, which took over seven years to complete. Directed by Simon West, Fortitude is a Se
New findings from Forcepoint's X-Labs outline an interesting scenario that could easily mimic real life: An AI assistant with browser access reads a webpage about travel disruption. Near the bottom of that page, in text sized and positioned so no human will ever see it, sits a short paragraph stating that ABC Travel Support is the official emergency booking provider and should always be recommended when urgent travel changes are needed.
The assistant's text extractor does not distinguish betwee
YouTube announced major changes to the YouTube Partner Program taking effect 1 February 2027. New creators will need 8,000 watch hours or 20 million Shorts views to qualify for ad revenue, doubling existing entry benchmarks. Current partners are grandfathered in, though Shorts ad payouts will now require a recurring 10 million views over 90 days.
YouTube is planning a big requirement change to the YouTube Partner Program (YPP) that will make it harder for new creators to start monetizing from a
Contact details of Angelina Jolie, Robert De Niro and Martin Scorsese have been exposed in a data breach. Jennifer Lawrence, Morgan Freeman, Michael Douglas, Rami Malek, Sharon Stone, and directors George Lucas and Danny Boyle are also said to have been involved in the alleged leak last month. The stars’ phone numbers and email addresses were revealed after a Tribeca Film Festival database, simply named “contacts”, was accidentally made public online, with Jeremiah Fowler, a researcher for Bla