Small teams are the heaviest users of AI coding agents

The pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On GitHub that somebody is usually one developer sitting alone with th… Continue reading Small teams are the heaviest users of AI coding agents

Estée Lauder discloses data breach tied to Oracle EBS vulnerability

Cosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée Lauder is one of the largest beauty companies in the world, known for its pre… Continue reading Estée Lauder discloses data breach tied to Oracle EBS vulnerability

The Odyssey piracy scams surface hours after its theatrical debut

Christopher Nolan’s The Odyssey had barely reached theaters before scammers began targeting people searching for pirated copies, according to Malwarebytes. Within hours of the film’s release, researchers found two separate scams running on … Continue reading The Odyssey piracy scams surface hours after its theatrical debut

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel

Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from Group-IB discovered. Targeted campaign tied to Iranian espionage activity The … Continue reading HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel

Italy fines WINDTRE €1.7 million over security flaws behind two data breaches

Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE €1.7 million over “serious data security shortcomings” that let hackers breach its systems twice and exfiltrate personal data belonging… Continue reading Italy fines WINDTRE €1.7 million over security flaws behind two data breaches

A forensic tool for backdoored code completions in AI assistants

Developers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick glance. Those tools learn from large collections of code, and some of that code ca… Continue reading A forensic tool for backdoored code completions in AI assistants

Two new high severity WordPress vulnerabilities, patch immediately!

The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, … Continue reading Two new high severity WordPress vulnerabilities, patch immediately!