Security · Top stories
Taiwan indicts ex-TSMC manager over alleged leakage of chip secrets to China
Taiwanese prosecutors indicted a former TSMC deputy manager for allegedly stealing 21 confidential chip technology documents to share with a Chinese firm. This case, the first under Taiwan's National Security Act related to core semiconductor technologies, highlights continuing concerns about industrial espionage amid heightened geopolitical tensions.
OpenSSL HollowByte Flaw Exposes Servers to Memory Exhaustion with Minimal Payload
A vulnerability in OpenSSL, known as HollowByte, allows attackers to trigger a denial-of-service condition by sending an 11-byte payload. The flaw causes vulnerable servers to pre-allocate memory for incomplete TLS handshake messages. Fixed versions without official CVEs or advisories include OpenSSL 4.0.1 and others released on June 9. Upgrading is crucial to prevent potential server freezes.
Teens sentenced to 5.5 years for £29M Transport for London cyber attack
Owen Flowers and Thalha Jubair were sentenced to 5.5 years for a 2024 cyberattack on TfL that caused £29 million in damages. The attack severely disrupted services and breached data of millions. Authorities cite this case as a major enforcement action against young cybercriminals.
SecurityWeek Introduces Critical Impact Awards for Industrial Cybersecurity
SecurityWeek has launched the Critical Impact Awards to recognize achievements in industrial cybersecurity. This awards program aims to honor organizations and individuals based on merit rather than sponsorship, enhancing credibility in the cybersecurity field.
Kenya investigates hack of president's website demanding bitcoin ransom
Kenya is investigating a cyberattack that defaced President William Ruto's official website with a ransom demand of five bitcoins. The attackers claimed this was their third warning to the president, though no sensitive data has been compromised according to government officials.
Researchers Reveal Security Flaws in AI Coding Agents and Open-Source Mobile Frameworks
Researchers from Hong Kong University have highlighted vulnerabilities in AI coding agents, notably OpenAI Codex and Claude Code, which can be bypassed using techniques like SKILLCLOAK. These techniques allow malicious AI add-ons and agents to evade current security scanners. These findings underscore the need for improved security measures in AI agent marketplaces and software, as current defenses are inadequate.
CISO Andreas Gaetje Discusses Career Path at Körber AG
Andreas Gaetje, CISO at Körber AG, reflects on his unconventional career journey from economics to cybersecurity. He emphasizes the significance of adapting to the evolving role of IT security, which has grown from compliance to a critical business threat.
Meta Awards $78,000 Bug Bounty for Critical Customer Support Data Vulnerability
Meta has awarded a $78,000 bounty to researcher Rony K Roy for discovering a vulnerability in its support data system that could have led to the exposure of sensitive customer information. The issue, initially thought minor, was found to allow unauthorized access to support cases and user communications, demonstrating significant flaws in Meta's security framework.
Clover Health Investments Reports Data Breach Affecting Customer Information
Clover Health Investments disclosed a data breach affecting customers' personal and health information due to a social engineering attack that compromised three employee accounts. The company initiated its response plan and engaged cybersecurity experts to handle the situation, though the full impact of the breach is still being investigated.
AI Technology Reduces Vulnerability Exploitation Time, Increasing Security Concerns
The rapid increase in newly reported vulnerabilities, and the use of AI in exploit development, has significantly reduced the time it takes for cyber threats to be operationalised. This has created a larger 'exposure window' between vulnerability discovery and remediation, placing pressure on security teams. With CVEs published at an unprecedented rate, prompt response times are becoming crucial to mitigate potential breaches.
South Korea's diplomat training system breached by hackers for 9 months
Hackers compromised South Korea's diplomatic academy's e-learning platform for nine months, exposing employee data. This breach raises serious cybersecurity concerns, especially given the country's past experiences with North Korean cyberattacks.
Ransomware Payments Increase Under Regulatory Scrutiny
A recent report reveals that nearly half of ransomware victims pay ransoms, with the median amount demanded rising. In response, some jurisdictions, including the UK, are moving to ban ransom payments for public sector entities amid a surge in ransomware attacks driven by AI tools and advanced targeting methods.
Cybersecurity Expert Sentenced for Role in BlackCat Ransomware Scams
Angelo Martino, a former ransomware negotiator, has been sentenced to 70 months for aiding the BlackCat ransomware gang. Collaborating with accomplices, he shared confidential negotiation details, causing victims to lose over $75 million. This highlights vulnerabilities within cybersecurity industries.
Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic Computers
A Russian-speaking hacker named 'bandcampro' leveraged Google's open-source Gemini CLI to control a botnet consisting of eight PCs at a dental clinic. This incident highlights the evolving use of AI in cybercrime, enabling sophisticated operations that can rapidly adapt and proliferate.
PamStealer Malware Targets macOS for Credential Theft Using Apple's PAM
Researchers have discovered PamStealer, a macOS malware that uses Apple's PAM interface to steal user credentials. This sophisticated malware employs a two-stage delivery system, disguising as the clipboard manager Maccy and utilising stealthy JavaScript for Automation. It highlights emerging threats in macOS security exploiting native Apple frameworks for credential theft.
HalluSquatting Attack Exploits AI Hallucinations to Form Botnets
The "HalluSquatting" attack exploits AI hallucinations to inject malicious commands into coding assistants, potentially creating botnets. Researchers from Tel Aviv University and other institutions demonstrated that attackers can pre-register fictitious software names generated by AI. AI models' tendency to hallucinate and act on fake package names can expose systems to widespread malware deployment.
CERT/CC Reports Hidden Backdoor in Tenda Router Firmware Allowing Admin Access
A vulnerability in various Tenda router firmware versions, CVE-2026-11405, allows unauthorized administrative access via an undocumented backdoor. This flaw poses significant security risks for users as attackers can bypass authentication to control devices remotely. Despite warnings, Tenda has not addressed the issue, leaving affected devices unpatched.
SleeperGem Malicious RubyGems Target Dev Machines in Supply Chain Attack
A new cyber attack, codenamed SleeperGem, has been identified, affecting the Ruby ecosystem through three malicious RubyGems. This attack poses a significant risk to developers by potentially compromising their machines and extending to other packages.
Craneware Reports Data Breach Affecting US Hospitals and Pharmacies
Craneware, a UK-based software provider for over 2,000 US hospitals, reported a data breach involving employee and customer information. The breach resulted in the theft of significant data, impacting hospitals' billing and patient management services. The incident has been contained, with investigations ongoing.
Hacker Attack Disrupts Romania's Land Registry Operations
Romania's land registry agency suffered a cyberattack, resulting in the wiping of its database and a halt in real estate transactions. The agency is migrating its systems to the government cloud to restore operations while ensuring data integrity.
Russian Hackers Use Security Cameras to Monitor NATO and Ukrainian Military Movements
Russian intelligence services are using internet-connected security cameras across Ukraine and NATO states to gather military intelligence. This operation involves exploiting cameras with default settings or security flaws, collecting data on military logistics and weapon shipments, and targeting Ukrainian troops. The breaches pose serious security risks across Europe and Ukraine.
Ransomware Attack Halts Fairlife Dairy's U.S. Production Temporarily
Coca-Cola's Fairlife dairy subsidiary has halted U.S. operations following a ransomware attack that affected production systems. The July 16 incident led to the activation of crisis protocols, though product quality was not impacted. Fairlife's U.S. facilities are paused, but Canadian operations remain unaffected.
FBI and CISA Warn of Russian Phishing Attacks on Signal and WhatsApp Accounts
The FBI and CISA have issued an updated warning about Russian intelligence phishing campaigns targeting Signal and WhatsApp accounts. Attackers are using Signal Backup Recovery Keys to hijack accounts, and the U.S. is offering a $10 million reward for information on the group responsible. The campaign has compromised thousands of accounts of high-profile targets, including government officials and journalists.
Cloudflare moves to post-quantum cryptography with ML-KEM and ML-DSA
Cloudflare is transitioning its encryption methods to ML-KEM and ML-DSA to address quantum computing threats. The U.S. NIST standardized these algorithms in 2024, and Cloudflare aims for full post-quantum security by 2029.
Cloudflare joins UK's Cyber Resilience Pledge to enhance cybersecurity governance
The UK government launched the Cyber Resilience Pledge, aimed at enhancing cybersecurity governance. Cloudflare joined as a founding signatory, emphasizing collective defense principles against increasing cyber threats.
Cisco Talos Deploys SnortML for Machine Learning Intrusion Detection
Cisco Talos launched SnortML, a machine learning detection engine integrated into Snort 3, to address gaps in traditional IDS. It allows for faster responses to novel exploits by processing data locally and issuing verdicts in under a millisecond.
Kubernetes to Correct CVE Records for Unfixed Vulnerabilities in 2026
The Kubernetes project will correct inaccuracies in CVE records for older unfixed vulnerabilities on June 1, 2026. This change aims to improve transparency and ensure that vulnerability scanners can better identify risks that currently go undetected due to erroneous fixed version tags.
7-Zip Version 26.02 Fixes High-Severity RCE Flaw in XZ Archive Processing
7-Zip released version 26.02 to address a remote code execution (RCE) vulnerability linked to XZ-compressed data. Discovered by Lunbun researcher Landon Peng, the flaw could be exploited if a user opened a specially crafted archive. This highlights the need for manual updates due to 7-Zip's lack of an automatic update feature, emphasizing user awareness and action.
Microsoft Issues Record 570 Security Patches, Including Three Zero-Days
Microsoft's July 2026 Patch Tuesday included a record 570 security patches, with three zero-day vulnerabilities addressed. The increase is partly due to AI-assisted discovery, highlighting a trend in vulnerability identification and remediation.
Critical KVM/x86 Vulnerability Allows VM Escape to Host on Intel and AMD
Januscape, a 16-year-old use-after-free vulnerability (CVE-2026-53359) in Linux's KVM hypervisor, allows guest VMs to execute arbitrary code on host systems, compromising host security in multi-tenant environments. Discovered by Hyunwoo Kim, this first-known architecture-independent exploit has been demonstrated in Google's kvmCTF. Cloud providers like Google Cloud and AWS may be particularly vulnerable, posing risks of data breaches.
19-Year-Old Extradited to U.S. for Role in Scattered Spider Hacks
Peter Stokes, a dual U.S. and Estonian citizen, was extradited from Finland to the U.S. to face charges related to hacking activities with Scattered Spider. Notable incidents include a 2025 cyberattack on a luxury jewelry retailer demanding an $8 million cryptocurrency ransom. The extradition underscores efforts to combat global cybercrime.
Opera Rolls Out 'Paste Protect' to Counter ClickFix Cyber Attacks
Opera has introduced 'Paste Protect', a new feature to block malicious clipboard commands copied from websites, aimed at mitigating ClickFix-style attacks. These attacks leverage social engineering tactics to mislead users into pasting harmful code into terminals. The new feature marks the first native defense against this rising cyber threat in a major web browser.
F5 Releases Patches for Critical NGINX Vulnerability Allowing Remote Code Execution
F5 has released security patches for a critical vulnerability in NGINX (CVE-2026-42533) that allows remote attackers to trigger a heap buffer overflow, potentially leading to remote code execution and denial of service. This vulnerability affects numerous NGINX versions and some configurations, which could expose many installations unless updated.
New Proposal for Interoperable Passkey Records and Go API Announced
A new specification for interoperable passkey records, inspired by Password Hashing Competition Strings, aims to simplify the integration of passkeys in applications. This proposal allows developers to handle passkey records as opaque strings, making implementation more efficient and reducing complexity in database interactions.
Chrome 150 Update Addresses 27 Vulnerabilities, Enhances Security
Google released Chrome 150, patching 27 security vulnerabilities, including two critical use-after-free flaws in Ozone and Views. This update is part of a broader effort to improve browser security, with most flaws discovered internally by Google. Regular updates are essential due to frequent exploitation of memory safety vulnerabilities in browsers like Chrome.
Texas Police Acquire FalcoNet Surveillance System for $4.5 Million
Texas State Police purchased four FalcoNet-equipped Chevrolet Tahoes for $4.5 million to enhance surveillance capabilities. This technology, capable of intercepting mobile phone communications, raises significant concerns over privacy and data collection on civilians.
San Francisco Orders Apple and Google to Remove Nudify Apps for Legal Violations
San Francisco City Attorney David Chiu ordered Apple and Google to remove 13 nudification apps from their app stores, citing violations of California laws against deepfake pornography. The apps are accused of creating non-consensual explicit images, which impact women and minors. The city claims the companies have profited from these apps and warns of potential civil penalties if they do not comply within 28 days.
Hackers Target Russian Government Agencies via ViPNet Software Abuse
A threat actor is exploiting ViPNet's update mechanism to deploy malware against Russian organizations, including government agencies. The campaign, named HelloNet, impacts multiple sectors and reflects ongoing vulnerabilities in widely used security products.
xAI Sues South Carolina Man Over Grok-Generated Sexual Images
xAI has initiated a lawsuit against Terry Wayne Harwood, alleging misuse of its Grok AI to generate child sexual abuse material (CSAM). This legal action, driven by Harwood's alleged bypassing of Grok's safeguards, underscores the challenges AI companies face in preventing abuse of their technology.
Ofcom Probes TikTok's Child Safety Due to Age Verification Concerns
UK regulator Ofcom is investigating TikTok's age verification methods under the Online Safety Act 2023. Concerns revolve around TikTok's use of 'age inference' technology, which might not adequately identify minors and expose them to harmful content. TikTok claims compliance with safety obligations, while Ofcom's findings could result in significant penalties if failures are confirmed.