Android 16 Lock Screen Flaw Lets Gemini Send Messages Without PIN
A critical vulnerability in Android 16 allows Gemini to bypass lock screen PINs and send SMS and WhatsApp messages, with a fix rolling out this week.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,662 stories synthesized.
A critical vulnerability in Android 16 allows Gemini to bypass lock screen PINs and send SMS and WhatsApp messages, with a fix rolling out this week.
A new buyer's guide ranks the top 10 Identity Threat Detection and Response (ITDR) solutions for 2026, highlighting their critical role in combating credential theft and identity-based attacks.
TP-Link has released firmware updates to address two vulnerabilities in its Kasa smart cameras, one enabling Man-in-the-Middle attacks and another leaking geolocation data.
OpenAI is investigating reports that its GPT-5.6 Codex AI model has unintentionally deleted files from user home directories, prompting calls for stricter AI agent access controls.
CISA has issued an emergency directive requiring federal agencies to patch two critical Fortinet FortiSandbox vulnerabilities, CVE-2026-39808 and CVE-2026-25089, which are being actively exploited in the wild.
Researchers have identified 'Cross-Site Prompting' (XSP) as a new vulnerability class for autonomous web agents, analogous to XSS for traditional web applications.
New research indicates that the persuasive power of AI-driven voice phishing (vishing) attacks relies more on sophisticated social engineering scripts than the realism of the cloned voice.
Polygraf AI introduces Meeting Guard, an AI-powered solution designed to detect fraud and enhance security during enterprise virtual meetings by acting as a participant and providing real-time analysis.
Two young members of the notorious Scattered Spider cybercrime group have been sentenced to over five years in prison for a 2024 attack that crippled 148 Transport for London (TfL) systems, forcing 27,000 staff to reset passwords and costing the organization approximately £29 million.
A heap-based buffer overflow in 7-Zip, CVE-2026-14266, allows remote attackers to execute arbitrary code by tricking users into opening a crafted XZ archive or visiting a malicious webpage.
Palo Alto Networks' Unit 42 report indicates AI is accelerating cyberattacks by enhancing efficiency and lowering barriers to entry, but fundamental attack methods remain largely unchanged.
Ransomware victims are increasingly unwilling to pay ransoms, forcing cybercriminal groups to innovate with AI and new evasion tactics, while the US targets enablers of these attacks.
Decentralized finance platform Ostium has halted trading following a sophisticated exploit that drained approximately $18 million in USDC from one of its vaults.
Coca-Cola disclosed that a ransomware attack on its Fairlife dairy subsidiary has disrupted US production, temporarily suspending operations and raising concerns about food supply chain security.
Wordfence Intelligence disclosed 267 vulnerabilities in 222 WordPress plugins and 6 themes between July 6-12, 2026, with 136 researchers contributing to WordPress security.
A cybersecurity researcher has successfully demonstrated how to backdoor an open-weight AI model with a remote code execution vulnerability for less than $100, highlighting significant risks in the AI supply chain.
Over one million phishing emails have been discovered using 'text salting' to bypass AI-driven security, embedding hidden text to confuse detection systems.
Microsoft's July Patch Tuesday addresses an unprecedented 622 vulnerabilities, featuring 62 critical flaws and three zero-days, two of which are under active exploitation, signaling a new era of AI-accelerated vulnerability research.
The UK's national security risk register has been updated to include cyberattacks against critical infrastructure, particularly water systems and data infrastructure, citing lessons from the CrowdStrike outage and the growing threat of hybrid warfare.
CISA has issued a critical advisory for Rockwell Automation's 1756 communication modules, warning of a denial-of-service vulnerability that could disrupt industrial control systems.
CISA has issued a critical advisory detailing three buffer overflow vulnerabilities in Rockwell Automation's widely used CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix industrial controllers, which could lead to denial-of-service conditions.
CISA has issued an advisory for a Stored Cross-Site Scripting vulnerability in Rockwell Automation's FactoryTalk DataMosaix Private Cloud, potentially leading to account takeover and credential theft.
A NULL Pointer Dereference vulnerability in NASA's Core Flight System Health & Safety application could allow attackers to crash the system, impacting critical space missions.
CISA has issued an advisory detailing four critical memory corruption vulnerabilities in Rockwell Automation Arena software, versions prior to V17.00.01, which could allow attackers to execute arbitrary code.