Fashion retailer Express left customers’ personal data and order details exposed on the internet

Fashion giant Express has patched its website to fix a security flaw that allowed anyone to view other people’s order details and personal information, TechCrunch has learned exclusively. At least a dozen Express customer orders were publicly visible in Web search engine results. The security flaw exposed the order confirmation page of Express’s online store, […]
This simulation startup wants to be the Cursor of physics AI

The promise of physical AI is that engineers will be able to program physical agents in the same way they program digital agents. We’re not there yet. Robotics is still hampered by the lack of data from physical space. To train machines, companies need to build mock-up warehouses to test them, while the entire industry […]
[Webinar] Find and eliminate isolated non-human identities in the environment

mohit kumarApril 16, 2026Artificial Intelligence/Enterprise Security In 2024, 68% of cloud breaches were due to compromised service accounts and forgotten API keys. It’s not phishing. It’s not a weak password. An unmanaged non-human identity that no one saw. Each employee in your organization has 40-50 automated credentials, such as service accounts, API tokens, AI agent […]
Cisco patches four critical identity services, Webex flaw that allows code execution

Ravi LakshmananApril 16, 2026Vulnerability/Network Security Cisco has announced patches that address four critical security flaws affecting Identity and Webex services. These flaws could allow an attacker to execute arbitrary code and impersonate any user within the service. The vulnerability details are below. CVE-2026-20184 (CVSS Score: 9.8) – Improper certificate validation in the Control Hub and […]
Hackers used AI to steal hundreds of millions of Mexican government and civilian records, one of the largest cybersecurity breaches ever

Nine Mexican government agencies were hacked in an artificial intelligence (AI)-driven cyberattack between December 2025 and mid-February 2026, which researchers said should serve as a wake-up call. According to researchers at cybersecurity firm Gambit Security, a small group of individuals used Anthropic’s Claude Code and OpenAI’s GPT-4.1 to infiltrate both federal and state government agencies […]
Hidden passenger? How to route Taboola logged in banking sessions to Temu?

hacker newsApril 16, 2026Data privacy/compliance Bank has approved Taboola pixel. This pixel silently redirected logged-in users to the Temu tracking endpoint. This happened without the bank’s knowledge, user consent, and without a single security control registering a breach. For technical details, please see our Security Intelligence Brief. Download now → Blind spot of “first hop […]
Abuse of Obsidian plugin leads to PHANTOMPULSE RAT in targeted financial and cryptocurrency attacks

Ravi LakshmananApril 16, 2026Application security/threat intelligence A “novel” social engineering campaign that leverages the cross-platform note-taking application Obsidian as an initial access vector to distribute a previously undocumented Windows remote access Trojan called PHANTOMPULSE has been observed in attacks targeting individuals in the financial and cryptocurrency sectors. The campaign, named REF6598 by Elastic Security Labs, […]
Stephen Hawking’s black hole information paradox could be solved if the universe is 7-dimensional

New theoretical research suggests that black holes may never completely evaporate, contradicting Stephen Hawking’s infamous theory that appears to violate the fundamental laws of quantum mechanics. Instead, black holes may leave behind small, stable remnants that store all the information they once consumed, the study suggests. But there’s a twist, literally. For this theory to […]
DeepL, known for text translation, wants to translate your audio

DeepL, a translation company best known for its text tools, today released a speech-to-speech translation suite that covers use cases such as meetings, mobile and web conversations, and frontline worker group conversations through custom apps. The company is also releasing an API that allows external developers and companies to build on DeepL’s technology for customized […]
UAC-0247 Data theft malware campaign targets clinics and government in Ukraine

Ravi LakshmananApril 16, 2026Malware/Threat Intelligence Ukraine’s Computer Emergency Response Team (CERT-UA) has revealed details of a new campaign targeting government and municipal healthcare institutions, primarily clinics and emergency hospitals, distributing malware that can steal sensitive data from Chromium-based web browsers and WhatsApp. This activity was observed between March and April 2026 and is believed to […]