A swarm of AI agents broke into a major code-hosting site and OpenAI explains how, Google Search can now track flight prices and book hotels, workwear brand Carhartt confirms a 12.9-million-account data breach, a critical flaw hits over a million WordPress sites running the Avada theme, and Meta agrees to an $18 billion child-safety settlement.
A fake Grand Theft Auto VI demo turns out to be password-stealing malware, an AI-voice scam talks iPhone owners into reading out their passcodes, WhatsApp adds passkeys and stronger sign-in, a Stanford study finds AI is thinning out entry-level hiring, and Apple's new $899 Mac mini is built with on-device AI in mind.
A European regulator fines Uber €825 million for letting software cut drivers off with no human involved, an Android banking trojan learns to hide from Google Play, an actively exploited email-server flaw lands on the US patch-now list, and the company behind America's licence-plate cameras trims how long it keeps the data.
Amazon raises prices on Echo, Kindle, Fire TV and eero as the AI boom squeezes memory chips, LinkedIn's AI-slop button starts cutting reach, TikTok settles a children's privacy case for $400 million, malware turns car screens into rented internet connections, and a business school puts AI stand-ins of its instructors in a $699 course.
Account takeovers that never touch your password, fake IT help desk messages arriving over Microsoft Teams, tap-to-pay finally coming to Walmart, ChatGPT reaching into Apple Messages, and a free button that keeps readers finding your site.
A critical WordPress page-builder flaw with a patch already out, 40 fake crypto wallet add-ons for Firefox, expired credit cards brought back to life, a web page that can steal your Grok chats, and free study tools in Google Search.
Fake CAPTCHA prompts on hacked WordPress sites, a 3.7-million-patient medical records breach, a Windows update deadline, free Alexa+ on Fire TV, and Firefox's new AI window.
OpenAI launches a teen version of ChatGPT and pauses a frontier model over cyber risk, Comcast turns routers into motion sensors, and a Windows flaw is now in ransomware hands.
Microsoft is building a fix for a Defender flaw that hands an attacker full control of a Windows PC and has published working exploit code against it; new Mac malware spread through fake download pages steals saved passwords and drives your signed-in browser remotely; sign-in prompts on hotel and conference Wi-Fi are being used to get past two-step verification; ChatGPT's new Computer History feature logs clicks and keystrokes on Macs and stores the result unencrypted; and hardware crypto wallet owners' home addresses were taken from shipping partners.
A Linux botnet active since July is taking over internet-facing routers, cameras and network drives from several well-known brands and using them to relay other people's traffic; Twitch quietly enrolled every account in generative AI training and has now added an opt-out toggle; Anthropic has explained the invisible watermark now embedded in Claude's written output, and the limits are the important part; a guide to checking whether your AI accounts have been broken into; and the company behind the Cursor coding tool has been bought for 60 billion dollars in stock.
A pre-login flaw in the Mac Screen Sharing service is now being used in real attacks to install crypto-mining software, and the fix has been available since August 6; an extortion group published names, addresses, emails and phone numbers for 1.6 million RingCentral accounts; Google is letting people switch off the visible watermark on Gemini images, video and music while an invisible one stays; a new free service shows which ad and data companies run on a site or app; and the price of the big AI models is falling.
A flaw in Adobe Commerce and Magento lets an attacker take over a shopper's account with no password and no action by the victim, and a firm that watches these stores says attempts are already being blocked; the FBI has published an alert about accounts broken into using old passwords and fake support messages; and Microsoft is merging its consumer and work Copilot apps, retiring several features on August 18 with content in them not carried across.
The US cyber agency has added a Windows networking-driver flaw to its catalogue of vulnerabilities known to be exploited and given federal agencies until August 25 to apply the fix, security researchers documented 737 Chrome extensions posing as free VPNs that route every browser tab through a server the operators control, and Google's 2026 Pixel line goes on sale on August 20 at $899, $1,099 and $1,299.
Zoom has patched a chain of three flaws that allowed a person in a meeting to run code on another participant's computer with no click required, a compromised promotional feed in a set of widely installed WordPress plugins created hidden administrator accounts on affected sites, Anthropic has begun marking Claude's text and image output so it can be identified later, Spotify will badge artist profiles that are AI creations and keep them out of personalised recommendations, and a fake in-flight Wi-Fi network on a Delta flight is being investigated.
A personal AI agent discovered that a gym's reservation software never checked who was cancelling a booking and cancelled someone else's, a cyberattack on the logistics firm that ships Steam hardware in Europe exposed names and home addresses at a bank, retailers and Valve, three pieces of passkey research at Black Hat showed the implementations leaking key material rather than the design failing, YouTube is raising its monetisation entry bar to 8,000 watch hours on February 1 2027, and Google's ad and analytics tools are getting AI summaries in beta.
A maximum-severity hole in Metabase was used to steal customer data from companies including a laptop maker and a form-building service, attackers are calling employees on their personal mobiles pretending to be the help desk, X is retiring its Revenue Sharing program on September 7, an AI cyclone model that gave forecasters an extra day of warning has been published and open-sourced, and a New Mexico court has ordered Meta to fund $567 million of youth mental health treatment.
WordPress 7.0.3 fixes eleven security holes including one an attacker can reach before logging in, a phishing campaign is taking over Microsoft 365 accounts to sit on payroll and invoice email, a seed-generation bug in Coldcard hardware wallets has cost owners more than $130 million with a fake "security audit" email now chasing the same people, Microsoft Edge has started switching off older extensions including some ad blockers, and Google Maps can now order food and book hotels on your behalf in the US.
OpenAI is making its newer model the default for free ChatGPT accounts and removing the cap on text chats, Google will start deleting Assistant from Android phones and watches on September 4 with no way back, a 250-domain campaign is tricking Mac owners into pasting a password-stealing command into Terminal, researchers showed the leading AI browsers can be hijacked by hidden instructions in an email, and Shopify says AI-assistant traffic to its stores tripled in a year.
A four-university study finds AI chatbots earn victims' trust faster than human romance scammers, an intelligence operation is hijacking hotel Wi-Fi login pages to push fake software updates, a random-number flaw in COLDCARD wallets is tied to an $88.6 million Bitcoin theft, more than 30 Minnesota water systems were hit in a coordinated attack, and Anthropic says three of its models breached real companies during safety tests.
Google says AI-assisted bug hunting fixed 1,072 Chrome flaws in two releases and is pushing Chrome toward weekly patches, a vishing campaign talks employees into handing over remote access, no-name streaming devices run proxy and ad-fraud schemes, the FTC sues a telehealth company over tracking pixels, and OpenAI cuts prices on two GPT-5.6 tiers.
Researchers show a hidden prompt can ride from one Copilot-written document into the next, a coordinated attack disrupted Minnesota water utilities, Qualcomm is reportedly raising chip prices September 1, the FCC bars new imports of foreign robots and power inverters, and Android gets age signals.
Links to shared AI conversations were indexed by search engines, the largest US grid plans to curtail data centers during shortages, a lawsuit says an imposter crypto app slipped into the App Store, Apple starts leasing devices, and Perplexity's agent arrives on Windows.
Hugging Face users are asked to rotate tokens, a gray market sells AI access at 90%-plus discounts, a work-software company cuts a fifth of its staff, and open-weight models raise the stakes on where your AI comes from.
OpenAI launches a small-business program and health features, Anthropic cuts the cost of long-running AI, a safety incident makes the case for guardrails, and Meta leans into assistants.