Carly Page
Verified
(She/Her)
As seen in:
MSN,
MSN UK,
Yahoo Entertainment,
Yahoo Life,
Forbes,
The Independent (UK),
The Telegraph,
Yahoo Canada,
Yahoo News,
Yahoo News Australia
and
Freelance tech journalist and copywriter, formerly senior cybersecurity reporter at TechCrunch.
☎️ Signal: carly.44
✉️ carlypagewrites@gmail.com
Articles by Carly Page
Crooks push Mac malware through fake OpenAI Codex ads
Cybercrims are using fake OpenAI Codex download pages to trick Mac developers into running malware disguised as installation commands. Researchers at Cato Networks uncovered the campaign after spotting sponsored Google search results targeting people looking to download Codex for macOS. The ads direct would-be users to a convincing-looking download page hosted on Google Sites, complete with the familiar OpenAI branding. There is, however, no Codex waiting at the other end.
ShinyHunters and ReliaQuest trade blows over claimed breach
ShinyHunters and ReliaQuest trade blows over claimed breach Attackers took a look at an employee's identity dashboard, but security firm says that's as far as they got ShinyHunters has claimed another cybersecurity scalp, but ReliaQuest says the crew's social engineering attack only got as far as one employee identity before its defenses slammed the door. The ransomware baddies listed US-based infosec biz ReliaQuest on its leak site on August 23, claiming the corporation as its latest victim.
$1T investment giant Apollo breached after social engineering attack
$1T investment giant Apollo breached after social engineering attack Hackers spent four days inside the org's cloud platforms after apparently talking their way in Apollo Global Management has admitted that attackers talked their way into its cloud systems and got their hands on Social Security numbers and other personal information. Apollo isn't saying which cloud platforms were compromised, how the attackers got in, or how many people are affected by the breach.
Oshen raises $5M to scale autonomous ocean robots for defence missions
Plymouth-based robotics company Oshen has raised $5 million to ramp up production of its autonomous ocean robots as demand grows from defence and weather agencies. The round was led by Lunar Ventures, with backing from AlbionVC, Twin Track and Concept Ventures. Oshen said the money will fund manufacturing expansion and build capabilities in passive acoustics, subsea infrastructure protection, and anti-submarine warfare.
Why is AI going on a hacking spree?
5 hours ago Some things are just better on a big screen. There are lots of ways to get content on the big screen, like using a connected streaming device or accessing a built-in smart TV OS. But you can also do so wirelessly by using technology like Chromecast and Apple AirPlay, both of which "cast" (wirelessly …
Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it Original
CISA has ordered US federal agencies to patch two exploited flaws in TrueConf, a Russian-built video conferencing platform, after compromised servers were caught handing malware to unsuspecting meeting participants. The US cybersecurity agency on Thursday added CVE-2026-72529 and CVE-2026-72530 to its Known Exploited Vulnerabilities catalog, saying both have been used in real-world attacks. What CISA doesn't say is who is being attacked, or where.
Hackers poison popular Rust crates to steal developers' credentials
Hackers slipped malware into several popular Rust packages this week, turning routine software builds into a route onto developers' machines. The attack extended beyond a single dodgy crate. Someone had published a new version of arrayref, a legitimate and widely used Rust package, with proc-macro1 added as a dependency. The attacker had also yanked recent legitimate releases of arrayref, helping steer users toward the poisoned release.
Microsoft sounds alarm as perfect-10 Entra ID flaw comes under attack
Microsoft sounds alarm as perfect-10 Entra ID flaw comes under attack Redmond says the cloud identity bug is already fixed, but isn't saying who exploited it or how widely Microsoft has fixed a maximum-severity vulnerability in Entra ID that attackers were already exploiting in the wild. Tracked as CVE-2026-69836, the vulnerability carries the maximum CVSS score of 10.0 and could allow an unauthenticated attacker to execute code remotely in Microsoft's cloud identity service.
Slack Code taps into collective vibe, puts AI agents into the group chat
Slack has decided that AI coding agents have spent quite enough time alone with developers and would be better off doing their work where everyone can watch: on Slack. The Salesforce-owned chat factory has introduced Slack Code, which gives coding agents their own project channels where they can work alongside the humans supposedly keeping an eye on them. Slack calls this "multiplayer AI," which is another way of saying the coding bot is leaving the developer's terminal and joining the group chat.
Ransomware crook poses as recovery firm to steal payments from fellow extortionists
Ransomware crook poses as recovery firm to steal payments from fellow extortionists Because apparently even ransomware gangs can't trust the people they do business with A ransomware affiliate appears to have found a new way to squeeze victims for cash: pose as the good guy and undercut the criminals it was working with.
OpenAI glitch locks out vetted cyber researchers – and some can't get back in
OpenAI glitch locks out vetted cyber researchers – and some can't get back in Affected users say support cannot restore their previous approval or override the new decision OpenAI says a technical stuff-up booted some vetted security researchers out of its Trusted Access for Cyber (TAC) program, only for its recovery process to decide some of them aren't welcome back. The problem surfaced this week when participants reported that their previously approved status had vanished without warning.
GALLOS Technologies raises £35M to expand defence tech portfolio
UK defence and security investor GALLOS Technologies has raised £35 million to build and back more companies working across national security and resilience. The $50 million (£35 million) balance sheet investment round was co-led by Ventura Capital and Aberdeen Investments, the company confirmed in a LinkedIn post, with existing investor Lansdowne Partners also taking part.
UK puts Google AI on the flight path to fewer contrails
UK puts Google AI on the flight path to fewer contrails Trial will test whether small route and altitude tweaks can reduce aviation's warming impact Britain is putting Google AI in the flight-planning loop to see whether airliners can dodge the patches of sky where their vapor trails are most likely to stick around and warm the planet.
LITILIT secures €8m to develop high-power modular laser system
Lithuanian laser specialist LITILIT has secured €8 million in financing to develop a high-power modular femtosecond laser system, technology that could ultimately find applications across advanced manufacturing, aerospace and defence supply chains. Lithuania’s national development bank, ILTE, will cover most of the € 10 million bill with an €8 million loan. LITILIT will put in the remaining €2 million as it works towards a FEMODA system capable of reaching 1,000W of average optical power.
UK's tech talent pipeline shrinks as overseas worker visa applications fall 7%
UK's tech talent pipeline shrinks as overseas worker visa applications fall 7% Third consecutive annual decline adds to concerns about shortages of specialist skills Fewer skilled overseas workers are applying for UK tech visas, with numbers down for the third year running even as ministers talk up Britain's chances in the global technology race.
Crook hawks millions of records allegedly plundered from corporate Azure tenants
A cybercrook claims to have siphoned millions of employee records from the Microsoft Azure environments of major companies including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services. The alleged haul spans nine organizations and is being advertised for sale by a threat actor using the name "TheHatman," according to research published by Hudson Rock. McDonald's accounts for the largest alleged dataset on TheHatman's shopping list, with 1.7 million records purportedly up for grabs.
Scottish prosecutors cast eye over leaky supplier after staff data exposed
Scottish prosecutors cast eye over leaky supplier after staff data exposed Unnamed third party spotted suspicious activity, with names, roles, and email addresses potentially affected Scotland's public prosecution service has warned 300 staff that their personal information may have been caught up in a cyberattack on one of its suppliers.
Australia puts speed ahead of perfection in new defence technology strategy
Australia has unveiled a 10-year plan to overhaul how it develops and buys military technology, with AI, autonomous systems and undersea warfare among six capabilities earmarked for accelerated investment.
Mystery attacker spent a year raiding Salesforce and ServiceNow portals
Someone has spent more than a year rifling through Salesforce and ServiceNow portals around the world, harvesting data that organizations accidentally left open to anyone who came looking. Researchers at Reco have named the operation "City-Forum" after a domain connected to its infrastructure. The domain has pointed to the attacker's server since March 2025, although exactly when the campaign began is unclear. Reco says the activity is continuing and increasing in volume.
Twitch feeds your streams to Amazon's AI unless you tell it to stop
Twitch feeds your streams to Amazon's AI unless you tell it to stop Bot training switch is on by default, because apparently asking first wasn't going to work Twitch has given streamers a switch to stop their channel content being fed into Amazon's generative AI machinery, but naturally it is turned on by default. If it was opt-in, nobody would opt in. That's honestly the answer.
Chinese tech in Royal Navy drones exposes UK defence supply chain dilemma
Britain’s push for cheaper, faster military technology comes with a catch: somewhere inside that shiny new British-built drone, there may still be technology sourced from China. That problem came into sharp focus this week after it was reported that cameras fitted to the Royal Navy’s K3 Scout drones, supplied by British defence company Kraken Technology Group, sent “heartbeat” data to an IP address in China.
Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure
Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure Newly minted RaaS crew breaks in through using internet-facing kit via known Fortinet flaws, then steals and scrambles data US cyber agencies are warning critical infrastructure operators to patch their internet-facing kit after Gunra ransomware affiliates were spotted exploiting known vulnerabilities to break into networks. Gunra first surfaced in 2025 and has wasted little time expanding.
Cyberattack on logistics giant CEVA delivers customer data into the wrong hands
A cyberattack on logistics giant CEVA has disrupted warehouses across Europe and exposed customer data belonging to a growing list of big-name clients, including Valve and Ajax. The France-headquartered shipping outfit, which operates more than 1,000 warehouses worldwide and generated $18.3 billion in revenue last year, was attacked between July 29 and August 1, according to a notification Valve sent to customers.
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub Original
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub Audit logs found no unexpected visitors, but release verification still needs an update Mozilla has revoked a cryptographic key used to sign Firefox and Thunderbird releases after discovering someone had accidentally committed an unencrypted copy of the private key to a GitHub repository.
Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G
Researchers have found that a malicious SIM card can tell some phones and cellular-connected devices to leak data, drop to 2G, shut themselves down, or even execute code, all thanks to functionality that's supposed to be there. The research [PDF], presented at the USENIX WOOT conference in Baltimore this week, examines proactive SIM functionality, which allows a SIM to issue commands to the device hosting it.
Attackers pick Levi's pockets in social engineering attack
Attackers pick Levi's pockets in social engineering attack Crims talked their way onto three employee PCs before trousering corporate data Levi Strauss is investigating a data breach after attackers used social engineering to access three employees' work computers.
Framework loses customer data in Metabase zero-day attack
Modular laptop maker Framework has warned customers that an attacker exploited a zero-day at analytics provider Metabase to access names, email addresses, phone numbers, physical addresses, and login IP addresses, according to an email shared on Reddit. For business customers, the exposed information may also include company names, phone numbers, VAT or Employer Identification Numbers (EINs), and billing email addresses. Framework said order and payment details were not affected.
Ransomware gangs skip the CEO, head straight for the 40-something IT manager
Ransomware gangs skip the CEO, head straight for the 40-something IT manager Gen Xers who feel triggered by this should remember to unplug the network cable and call the cops Turns out the fastest way to get a company to consider paying a ransom isn't calling the CEO – it's targeting the 46-year-old IT manager. That's according to Zscaler, whose ThreatLabz researchers tracked 351 victims across 334 organizations caught up in a single ransomware campaign over the course of a month.
N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands Original
N-able has confirmed attackers exploiting an N-central zero-day made it into customer networks, as the vendor pushes out a second mandatory hotfix just days after the first. According to N-able, attackers exploited vulnerable N-central servers remotely, then used the platform's Take Control feature to connect to systems inside the environments being managed through them.
ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they've dumped 10.9M email addresses
ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they've dumped 10.9M email addresses Cancer diagnostics breach spills personal and health info as extortion crew says healthcare giant ‘should’ve paid the ransom’ Hackers have dumped data stolen from Abbott’s cancer diagnostics business after the healthcare giant apparently declined to pay up, with the leak containing 10.9 million unique email addresses alongside personal and health information.
Intrusion at US healthcare software provider puts 3.8M people's data at risk
Intrusion at US healthcare software provider puts 3.8M people's data at risk Unlimited Technology Systems says names, Social Security numbers, diagnoses, and insurance details may have been swiped A US healthcare software provider has admitted that hackers may have made off with sensitive data belonging to 3.8 million people, making it the largest healthcare breach reported to regulators so far this year.
Shai-Hulud shows engineering teams have a new AI security problem
You have 1 article left to read this month before you need to register a free LeadDev.com account. Estimated reading time: 5 minutes Key takeaways: 81% of teams give AI-coding agents write access; only 7% keep it read-only. That’s what Shai-Hulud exploited. Nearly a quarter reuse human credentials for agents, only 7% manage agent identity properly. AI security policies are rising, but core controls (rotation, monitoring, revocation) remain rare.
Snowflake extortionist admits 165-victim cloud crime spree – and squeezing one target twice
Snowflake extortionist admits 165-victim cloud crime spree – and squeezing one target twice Connor Moucka pleads guilty over sprawling 2024 campaign that looted billions of records A Canadian who helped orchestrate the sprawling Snowflake-linked data theft campaign has pleaded guilty in the US, admitting that he and his co-conspirators returned to squeeze at least one victim a second time.
Meta latest to tell world its AI agent wandered out of test pen
If AI companies are collecting badges for "our model escaped the test environment," Meta just earned one. The Facebook parent company has confirmed that one of its AI models exploited a vulnerability in another organization's systems during a security evaluation, making it the third major AI developer in less than two weeks to disclose an agent wandering beyond its intended sandbox. The incident happened during testing carried out by AI security firm Irregular.
AI agents can create database sprawl issues. YugabyteDB’s solution is more agents!
The next database scaling problem may not be how big a database gets, but how many databases an enterprise suddenly has to run. That’s the inspiration behind YugabyteDB AMP, or Agentic Multitenant Postgres, a new serverless PostgreSQL tier designed for a world in which companies could be running hundreds or thousands of AI agents, each generating its own data layer demands. For Yugabyte, that means rethinking what scale looks like.
Ore Energy raises $43m to scale iron-air batteries for Europe’s AI boom
Amsterdam-based Ore Energy has raised $43 million (£32 million) in Series A funding to commercialise its iron-air battery technology, betting that Europe’s growing appetite for AI, manufacturing and renewable energy will drive demand for long-duration electricity storage. The round was led by Plural and HV, with participation from Positron Ventures, bringing the company’s total funding to $61 million.
UK mulls making employers ask before installing bossware
UK mulls making employers ask before installing bossware Proposals span AI productivity scores, keystroke logging, biometrics, and other ways to watch workers The UK government is considering forcing employers in Great Britain to consult workers before rolling out "bossware," opening the door to new rules covering everything from AI-powered productivity scoring to keystroke logging and biometric surveillance.
Police National Legal Database confirms data theft after dark web leak
cyber-crime Police National Legal Database confirms data theft after dark web leak ExfilSquad claims 135,000 contact records weeks after hitting the Department for Education The Police National Legal Database (PNLD) is the latest UK public sector outfit to admit that cybercriminals made off with its data, including the names and work email addresses of police officers, justice staff, government partners, and customers.
UK government investment arm cops to 40-hour leak of officials' contact details Original
UK government investment arm cops to 40-hour leak of officials' contact details Employee failed to follow security policy, leaving internal management file open to the public The UK government's corporate finance adviser has admitted that an employee left an internal file containing the names and work email addresses of dozens of officials publicly accessible for around 40 hours.
Americans give all-day school phone bans a ringing endorsement
Americans give all-day school phone bans a ringing endorsement Polling suggests patience with handsets in the classroom is running shorter than a teenager's battery life Americans are warming to the idea that schools should be for learning rather than doomscrolling, with support for all-day smartphone bans now outweighing opposition for the first time.
Amazon links four poisoned npm packages to one North Korean crew Original
Amazon links four poisoned npm packages to one North Korean crew Researchers say Sapphire Sleet socially engineered maintainers before publishing malicious updates through trusted accounts Amazon has linked the compromises of four npm packages over the past 18 months, saying they were all the work of the same North Korean crew.
Russian spies take their half-click email attack from Zimbra to Outlook
Russian spies take their half-click email attack from Zimbra to Outlook Opening a booby-trapped message unleashes a browser implant that can survive password changes and device rebuilds The Russian espionage crew that turned simply reading an email into a security risk has expanded beyond Zimbra, with Proofpoint saying it's now pulling the same half-click trick against Microsoft Outlook Web Access.
AI digs through 3,700 accounts of dreams and waking life, finds method in the madness
AI digs through 3,700 accounts of dreams and waking life, finds method in the madness Researchers uncover patterns in how sleeping minds recombine memories, people, and places Your brain apparently spends the night remixing reality rather than simply replaying it, according to researchers armed with AI and more than 3,700 accounts of dreams and waking life.
AI-found bugs aren't proving any easier to exploit despite the hype
AI-found bugs aren't proving any easier to exploit despite the hype VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage Anthropic's Project Glasswing may have uncovered tens of thousands of potential security flaws, but new research suggests AI-assisted vulnerability discovery has yet to produce the wave of real-world attacks many expected.
Mate Security bets a context-first AI architecture can reinvent the SOC as it lands $35M Series A
Every major security vendor now has an AI copilot, but Mate Security thinks they’re solving the wrong problem. The Tel Aviv-based startup announced on Tuesday it has raised a $35 million Series A led by Canaan Partners, with participation from Insight Partners, Team8 and M12, Microsoft’s venture fund, just eight months after closing a $15.5 million seed round.
Ex-Helsing maritime chief Amelia Gould joins Kraken as CTO
Kraken has appointed Amelia Gould as chief technology officer, bringing in the former Helsing maritime chief to lead the development of its autonomous vessels and associated technologies. Gould will oversee Kraken’s technology strategy and the development of its advanced maritime platforms as the British-founded defence company expands its product portfolio and international manufacturing operations.
When vendor-supplied support matters: How AI is changing the open source security equation
Every enterprise runs on open source, but keeping it secure has become significantly harder. Frontier AI models are uncovering vulnerabilities faster than maintainers can comfortably process them, while giving attackers many of the same capabilities. The result is a growing backlog of fixes that organizations are expected to evaluate and deploy ever more quickly. That shift is forcing enterprises to look beyond the software itself.
Hyperscale, hypersensitive: US teacher cuffed for applauding datacenter critics
Hyperscale, hypersensitive: US teacher cuffed for applauding datacenter critics Public meeting over proposed AI bit barn ended with zoning approval, a physics teacher arrested, and fresh questions over whether clapping now counts as disorderly conduct A Kansas physics teacher discovered that in at least one corner of America's AI buildout, applause can apparently earn you a trip to jail.
Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock Unauthenticated command injection scores perfect 10 and may expose managed Edge devices A critical flaw in Arista's VeloCloud Orchestrator has gone from zero to KEV in short order, with the networking giant confirming attackers are already exploiting it.
BAE spin-out Nuclear Turbines raises £15M for compact reactor push
Manchester-based startup Nuclear Turbines has emerged from stealth with £15 million in funding to develop compact reactors it claims could bring the cost of nuclear power below fossil fuels. The company, spun out of BAE Systems through its Launchpad initiative, is taking a different approach to the small modular reactor (SMR) market by ditching much of the steam infrastructure used in conventional nuclear plants.
Show More
loading
Actions
Get in touch with Carly
Contact Carly, search articles and posts on X, monitor coverage, and track replies from one place.
Learn more about Muck Rack