Latest Tech News

Stay updated with the latest in technology, AI, cybersecurity, and more

Filtered by: security Clear Filter

Two critical Android 16 security features you're not using (but absolutely should)

JEFF PACHOUD/Getty Images Although Google's earlier-than-expected release of Android 16 was missing a few important features, the updated OS does deliver improved security that every Android user would be well-advised to enable. I'll explain these two key security features and how to find and enable them. Also: How to clear your Android phone cache (and why it greatly improves performance) 1. Identity Check This feature was added in 2024, but it didn't receive much attention until the relea

App Store safety again called into question by Tea app

Apple has frequently argued that it is reasonable for it to have monopolistic control over the sale of iPhone apps because it vets them for safety and security. This has been called into question over scam apps accepted into the App Store, and the same questions are being asked regarding the Tea app. The so-called dating advice app has been revealed to have major security vulnerabilities, which have exposed private chats and personal data of tens of thousands of women … Egregious security flaw

China summons Nvidia over potential security concerns in H20 chips

What just happened? Nvidia's relief at being allowed to resume export of its China-specific H20 chips may be short-lived. The country's cyberspace regulator says that it met with Nvidia to discuss national security concerns related to the H20, including potential tracking and backdoors. The Cyberspace Administration of China (CAC) said that Nvidia was asked to "clarify and submit relevant supporting documentation regarding security risks, including potential vulnerabilities and backdoors, assoc

Apple security bounties pay up to $2M, but it only paid $1k for a critical bug

Apple encourages security researchers to seek out and report vulnerabilities in its devices and apps, in return for which it pays bug bounties of up to $2M. However, one security researcher who reported a Safari vulnerability Apple graded as Critical, and gave a severity score of 9.8 out of 10, says they were paid only $1,000 … Apple upgraded its security bounty program back in 2022, and stated then that its average payout was $40,000 and that it had on twenty occasions paid a six-figure sum f

Critical vulnerability in AI coding platform Base44 allowing unauthorized access

One of the most profoundly transformed domains in the wake of the LLM revolution has been code generation, especially the rise of vibe coding, where natural language prompts replace traditional programming. This shift has empowered millions of users with little to no technical background to build fully functional applications with ease. Platforms like Loveable, Bolt, and Base44 are on the front of this movement - they have enabled the creation of millions of applications spanning from persona

Shadow AI adds $670K to breach costs while 97% of enterprises skip basic access controls, IBM reports

Want smarter insights in your inbox? Sign up for our weekly newsletters to get only what matters to enterprise AI, data, and security leaders. Subscribe Now Shadow AI is the $670,000 problem most organizations don’t even know they have. IBM’s 2025 Cost of a Data Breach Report, released today in partnership with the Ponemon Institute, reveals that breaches involving employees’ unauthorized use of AI tools cost organizations an average of $4.63 million. That’s nearly 16% more than the global ave

Security Bite: iPhone users are more reckless online, new study finds

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Appl

Palo Alto Networks agrees to buy CyberArk for $25 billion

In Brief Cybersecurity giant Palo Alto Networks announced on Wednesday its intent to acquire identity management and security company CyberArk for $25 billion. The deal, a mix of cash and stock, marks Palo Alto’s entrance into the identity security space, according to a company press release. Palo Alto has been on a shopping spree since Nikesh Arora took over as CEO and chairman of the company in 2018, according to the Financial Times, which estimated the company has spent more than $7 billion

Critical Vulnerability in AI Vibe Coding platform Base44

One of the most profoundly transformed domains in the wake of the LLM revolution has been code generation, especially the rise of vibe coding, where natural language prompts replace traditional programming. This shift has empowered millions of users with little to no technical background to build fully functional applications with ease. Platforms like Loveable, Bolt, and Base44 are on the front of this movement - they have enabled the creation of millions of applications spanning from persona

Critical Vulnerability Discovered 11 Days After Wix Buys Base44

One of the most profoundly transformed domains in the wake of the LLM revolution has been code generation, especially the rise of vibe coding, where natural language prompts replace traditional programming. This shift has empowered millions of users with little to no technical background to build fully functional applications with ease. Platforms like Loveable, Bolt, and Base44 are on the front of this movement - they have enabled the creation of millions of applications spanning from persona

Palo Alto Networks stock falls after announcing $25 billion Cyberark deal

Palo Alto Networks will take over Israeli identity security provider CyberArk in a deal valued at roughly $25 billion. The California-based cybersecurity company will pay shareholders $45 apiece for 2.2005 shares of CyberArk, representing a 26% premium to its share price Friday. The deal is expected to close during Palo Alto Networks' fiscal year 2026. Shares of Palo Alto fell 5% Wednesday, building on a 5% loss from Tuesday. CyberArk's stock whipsawed. Palo Alto CEO and chairman Nikesh Arora

Palo Alto Networks stock falls 7% after announcing $25 billion Cyberark deal

Palo Alto Networks will take over Israeli identity security provider CyberArk in a deal valued at roughly $25 billion. The California-based cybersecurity company will pay shareholders $45 apiece for 2.2005 shares of CyberArk, representing a 26% premium to its share price Friday. The deal is expected to close during Palo Alto Networks' fiscal year 2026. Shares of Palo Alto fell 7% Wednesday, building on a 5% loss from Tuesday. CyberArk's stock dipped about 1%. Palo Alto CEO and chairman Nikesh

Palo Alto Networks stock falls 8% after announcing $25 billion Cyberark deal

Palo Alto Networks will take over Israeli identity security provider CyberArk in a deal valued at roughly $25 billion. The California-based cybersecurity company will pay shareholders $45 apiece for 2.2005 shares of CyberArk, representing a 26% premium to its share price Friday. The deal is expected to close during Palo Alto Networks' fiscal year 2026. Shares of Palo Alto fell more than 8% Wednesday, building on a 5% loss from Tuesday. CyberArk's stock dipped about 2%. Palo Alto CEO and chair

Nightfall launches ‘Nyx,’ an AI that automates data loss prevention at enterprise scale

Want smarter insights in your inbox? Sign up for our weekly newsletters to get only what matters to enterprise AI, data, and security leaders. Subscribe Now Nightfall AI launched the industry’s first autonomous data loss prevention platform Wednesday, introducing an AI agent that automatically investigates security incidents and tunes policies without human intervention — a breakthrough that could reshape how enterprises protect sensitive information in an era of expanding cyber threats. The S

AI vs. AI: Prophet Security raises $30M to replace human analysts with autonomous defenders

Want smarter insights in your inbox? Sign up for our weekly newsletters to get only what matters to enterprise AI, data, and security leaders. Subscribe Now Prophet Security, a startup developing autonomous artificial intelligence systems for cybersecurity defense, announced Tuesday it has raised $30 million in Series A funding to accelerate what its founders describe as a fundamental shift from human-versus-human to “agent-versus-agent” warfare in cybersecurity. The Menlo Park-based company’s

The Tea App Data Breach: What Happened, and What Was Exposed

Tea, a women's safety dating app that surged to the top of the free iOS App Store listings, suffered a major security breach last week. The company confirmed Friday that it "identified authorized access to one of our systems" that exposed thousands of user images. And now we know that DMs were accessed during the breach, too. Tea's preliminary findings from the end of last week showed the data breach exposed approximately 72,000 images: 13,000 images of selfies and photo identification that peo

Trump caving on Nvidia H20 export curbs may disrupt his bigger trade war

The next front in Donald Trump's trade war will be chip tariffs—which could come by next month—but national security experts are warning that the president may have already made a huge misstep that threatens to disrupt both US trade and national security. In a letter Monday to Department of Commerce Secretary Howard Lutnick, 20 policymakers and professionals with a background in national security policy urged Trump to reverse course and block exports of Nvidia's H20 chips to China. In April, t

Trump’s cybersecurity cuts putting nation at risk, warns New York cyber chief

During the first few months of the new Trump administration, the White House slashed cybersecurity budgets, staff, and initiatives. And some, including cybersecurity experts and legislators, are not happy about it. One of them is Colin Ahern, the chief cyber officer for the state of New York. In a recent interview with TechCrunch, Ahern said that both he and New York Governor Kathy Hochul are worried that the Trump administration’s cuts to cybersecurity are putting the country at risk. “We wor

Here are the eight Apple security layers protecting your data

9to5Mac is brought to you by Incogni: Protect your personal info from prying eyes. With Incogni, you can scrub your deeply sensitive information from data brokers across the web, including people search sites. Incogni limits your phone number, address, email, SSN, and more from circulating. Fight back against unwanted data brokers with a 30-day money back guarantee. Apple has a reputation for prioritizing the privacy of its customers, and that commitment begins right at the chip design level.

Microsoft Is Giving Windows 10 Users Free Security Updates for a Year, but There's a Catch

As Microsoft gets ready to sunset Windows 10, security support is scheduled to end in October. You can get a one-year extended security update for $30. But if you want to stick with Windows 10 for another year, you might be better off with Microsoft's free option -- you'll just need to use cloud backup and connect it with your OneDrive account. The ability to get free updates on Windows 10 is a pretty big deal because it is still the most widely used Windows OS, accounting for just over 53% of

Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data

Attackers could use a recently patched macOS vulnerability to bypass Transparency, Consent, and Control (TCC) security checks and steal sensitive user information, including Apple Intelligence cached data. TCC is a security technology and a privacy framework that blocks apps from accessing private user data by providing macOS control over how their data is accessed and used by applications across Apple devices. Apple has fixed the security flaw tracked as CVE-2025-31199 (reported by Microsoft'

New York state cyber chief calls out Trump for cybersecurity cuts

During the first few months of the new Trump administration, the White House slashed cybersecurity budgets, staff, and initiatives. And some, including cybersecurity experts and legislators, are not happy about it. One of them is Colin Ahern, the chief cyber officer for the state of New York. In a recent interview with TechCrunch, Ahern said that both he and New York Governor Kathy Hochul are worried that the Trump administration’s cuts to cybersecurity are putting the country at risk. “We wor

Amazon's AI coding assistant exposed nearly 1 million users to potential system wipe

A hot potato: Earlier this month, a hacker compromised Amazon's generative AI coding assistant, Amazon Q, which is widely used through its Visual Studio Code extension. The breach wasn't just a technical slip, rather it exposed critical flaws in how AI tools are integrated into software development pipelines. It's a moment of reckoning for the developer community, and one Amazon can't afford to ignore. The attacker was able to inject unauthorized code into the assistant's open-source GitHub rep

I Asked Crime Experts When Home Break-Ins Usually Happen and the Answers Stunned Me

Modern home security cameras and smart systems are well-equipped to watch over our homes -- I should know, I've spent years testing more models than I can count. The biggest advantage is that they can watch your home when you're not there, like on a summer vacation or asleep at night. But when is your home the most vulnerable? I took a look. It turns out that burglars tend to break into houses or look for vulnerabilities at a few specific times. Knowing when can help you stay safer and pick the

Amazon AI coding agent hacked to inject data wiping commands

A hacker planted data wiping code in a version of Amazon's generative AI-powered assistant, the Q Developer Extension for Visual Studio Code. Amazon Q is a free extension that uses generative AI to help developers code, debug, create documentation, and set up custom configurations. It is available on Microsoft’s Visual Code Studio (VCS) marketplace, where it counts nearly one million installs. As reported by 404 Media, on July 13, a hacker using the alias ‘lkmanka58’ added unapproved code on

Tea App Breach Exposes 72,000 Selfies, ID Photos and Other User Images

Tea, a women's safety dating app that surged to the top of the free iOS App Store listings this week, has been the subject of a major security breach. The company confirmed Friday that it has "identified authorized access to one of our systems" that exposed thousands of user images. According to Tea's preliminary findings, the breach allowed access to approximately 72,000 images, broken down into two groups: 13,000 images of selfies and photo identification that people had submitted during acco

Tea App Users' Faces and IDs Reportedly Posted to 4chan in Security Breach

Tea, a women's safety dating app that surged to the top of the free iOS App Store listings this week, has been the subject of a major security breach. The company confirmed Friday that it has "identified authorized access to one of our systems" that exposed thousands of user images. According to Tea's preliminary findings, the breach allowed access to approximately 72,000 images, broken down into two groups: 13,000 images of selfies and photo identification that people had submitted during acco

Tea App Users' Faces and IDs Reportedly Posted to 4chan in Security Breach

Tea, a women's safety dating app that surged to the top of the free iOS App Store listings this week, has been the subject of a major security breach. The company confirmed Friday that it has "identified authorized access to one of our systems" that exposed thousands of user images. According to Tea's preliminary findings, the breach allowed access to approximately 72,000 images, broken down into two groups: 13,000 images of selfies and photo identification that people had submitted during acco

Microsoft: SharePoint flaws exploited in Warlock ransomware attacks

A China-based hacking group is deploying Warlock ransomware on Microsoft SharePoint servers vulnerable to widespread attacks targeting the recently patched ToolShell zero-day exploit chain. Non-profit security organization Shadowserver is currently tracking over 420 SharePoint servers that are exposed online and remain vulnerable to these ongoing attacks. "Although Microsoft has observed this threat actor deploying Warlock and Lockbit ransomware in the past, Microsoft is currently unable to co

OpenAI prepares to launch GPT-5 in August

is a senior editor and author of Notepad , who has been covering all things Microsoft, PC, and tech for over 20 years. Earlier this year, I heard that Microsoft engineers were preparing server capacity for OpenAI’s next-generation GPT-5 model, arriving as soon as late May. After some additional testing and delays, sources familiar with OpenAI’s plans tell me that GPT-5 is now expected to launch as early as next month. OpenAI CEO Sam Altman recently revealed on X that “we are releasing GPT-5 so