Security · Top stories
Chrome 150 Update Addresses 27 Vulnerabilities, Enhances Security
Google released Chrome 150, patching 27 security vulnerabilities, including two critical use-after-free flaws in Ozone and Views. This update is part of a broader effort to improve browser security, with most flaws discovered internally by Google. Regular updates are essential due to frequent exploitation of memory safety vulnerabilities in browsers like Chrome.
Cybersecurity Threats: Spyware from Game Cheats and Fake Installer RATs Target Users
Cybersecurity researchers identified malicious NuGet packages disguised as game utilities that install spyware. Additionally, a financially motivated group is using trojanized software installers to deploy a sophisticated remote access tool aimed at U.S. and European users.
Over 20 Brazilian Government Websites Hijacked for Malware Delivery
More than 20 Brazilian government websites were hijacked as part of an active PhantomEnigma campaign, presenting significant risks to banks and public agencies. The attacks utilized spoofed emails and compromised government domains, allowing malware to be delivered under the guise of trusted infrastructure.
Daxin Malware Reemerges in Taiwan; New Stupig Backdoor Found
The Daxin malware has been discovered in a Taiwan manufacturing firm after being dormant for over four years, alongside a new backdoor called Stupig. This development highlights ongoing threats to critical infrastructure and the sophistication of malware that can evade detection for years.
Spirals ransomware encrypts networks within 24 hours after initial compromise
A new ransomware group, Spirals, compromised an IT services firm in South Asia and completed data theft and encryption in under 24 hours. The rapid expansion of ransomware capabilities poses significant threats to corporate network security.
Moroccan insider exposes use of Pegasus spyware on dissidents and officials
A former intelligence official revealed that Morocco utilized Pegasus spyware to target journalists and politicians from 2017 to 2021. This raises concerns about surveillance practices and human rights violations in the country.
FBI Reports Over $893 Million Lost to AI Voice Fraud in 2025
The FBI's 2025 report reveals over 22,000 complaints linked to AI voice fraud, resulting in losses exceeding $893 million. This new category highlights the increasing sophistication of voice manipulation scams, particularly affecting vulnerable populations.
Claude AI Mismanagement Leads to Data Leakage Risk
An exploit demonstrated that AI assistants like Claude can unintentionally leak sensitive user data without notification. This raises serious concerns about the security of personal information stored in AI memory systems.
Tailscale vulnerabilities allowed DoS and unauthorized root access
Tailscale issued a security advisory for two vulnerabilities, one allowing denial of service through malformed HTTP requests and another permitting unauthorized root access via specially crafted SSH usernames. Affected users are advised to upgrade to Tailscale version 1.98.9 or newer to resolve these issues.
Global Surge in Malicious Traffic Linked to Smart Appliances
Anubis' reputation database reveals that 80-90% of malicious traffic hits originate from IPs not in threat monitoring lists, suggesting a widespread issue with compromised smart appliances. This indicates a significant increase in the vulnerability of IoT devices to threats and the need for global action.
Spanish Police Dismantle €140 Million Cyber Fraud Network, Four Arrested
Spanish Police have dismantled a cybercrime organization involved in €140 million of investment fraud and business email compromise (BEC), arresting four individuals. This operation highlights a sophisticated scheme utilizing over 800 bank accounts and numerous accomplices to launder significant amounts of illicit funds.
Finland issues wanted notice for hacker behind Vastaamo psychotherapy data breach
Finnish police have issued a wanted notice for Aleksanteri Kivimäki after his appeal was denied. Kivimäki was convicted for hacking psychotherapy provider Vastaamo and extorting patients, with implications for cybercrime accountability.
LabubaRAT Trojan Disguised as NVIDIA Software Targets Windows Systems
Researchers discovered LabubaRAT, a new Rust-based remote access trojan masquerading as NVIDIA software. Its ability to blend into target environments and perform extensive monitoring and control functions poses significant risks for affected systems and organizations.
Researcher Identifies Security Flaws in Major LLMs Allowing Dangerous Exploits
Researcher Dave Kuszmar found vulnerabilities in large language models (LLMs) that allow circumvention of safety measures, enabling the generation of harmful instructions. This revelation indicates an industry-wide security issue, prompting calls for a halt to LLM deployment until safety measures are improved.
Iran exploited telecom vulnerabilities to track U.S. military in the Middle East
The Iranian government exploited vulnerabilities in telecom infrastructure, specifically SS7, to locate U.S. military personnel during the Iran War. This espionage resulted in targeted attacks on U.S. forces, leading to injuries.
OpenAI requires hardware-backed passkeys for TAC members starting September 1
OpenAI announced that all individual members of its Trusted Access for Cyber must use hardware-backed passkeys for account security starting September 1. This mandate is intended to enhance protection against phishing and social engineering attacks, ensuring that access to critical AI capabilities is limited to trusted users.
VMware Avi Load Balancer Patches 7 Critical Vulnerabilities
Broadcom announced patches for seven vulnerabilities in VMware Avi Load Balancer, including critical authentication bypass and remote code execution issues. Organizations are advised to update promptly to prevent potential exploitation, especially as VMware flaws have been targeted in past attacks.
Microsoft Entra ID adopts passkeys as default authentication by September 2026
Starting September 2026, Microsoft Entra ID will replace SMS and voice authentication with passkeys as the default method. This transition aims to enhance security against credential theft and phishing attacks, as SMS and voice authentication will be retired in February 2027.
Research Reveals Privacy Flaws in 85 Crypto Wallet Extensions
A study by KU Leuven on 85 popular crypto wallet extensions identified significant privacy vulnerabilities, including user address leaks and tracking risks. These weaknesses could potentially enable tracking of users across different websites, undermining the anonymity intended by these wallets.
AI chatbots produce predictable passwords, research reveals security risks
Research indicates that passwords generated by AI chatbots like Claude and ChatGPT display predictable patterns, undermining their security. The findings suggest that using trusted password generators is a safer alternative for creating secure passwords.
148 npm Packages Created DDoS Botnet Using Student Proxy Disguise
A research report details how 148 npm packages disguised as student proxies turned browsers into a DDoS botnet for two weeks in May. This operation exploited students' need to bypass web filters, transforming their devices into attack traffic sources that operated without users' knowledge.
Microsoft Identifies Salesforce Breach Tactics Linked to ShinyHunters
Microsoft's research reveals that ShinyHunters exploited Salesforce environments using OAuth trust relationships, without exploiting flaws in the platform. This activity highlights vulnerabilities tied to common third-party vendor connections and employee consent, leading to unauthorized data access.
Google and Microsoft Remove ModHeader Extension After Hidden Data Collector Found
Google and Microsoft have removed the ModHeader extension, with 1.6 million installs, after a dormant browsing-history collector was discovered within it. Although the collector was inactive, the potential for future data gathering raised significant privacy concerns.
2026 Public Sector M-Trends Report Highlights Alarming Cybersecurity Trends
The 2026 Public Sector Threat Landscape report reveals significant vulnerabilities in cybersecurity for the public sector, including a 22-second median hand-off to ransomware operators. These findings underscore an urgent need for rapid, machine-speed defenses amidst evolving attack methods that exploit trust boundaries.
UK charges five in connection with Russian Coms spoofing platform
UK authorities have charged five individuals linked to the Russian Coms caller ID spoofing platform, which facilitated over 1.8 million scam calls. This platform, operational since 2020, enabled criminals to impersonate financial institutions and law enforcement, leading to significant financial losses for victims worldwide.
Centers Laboratory Data Breach Impacts Over 540,000 Individuals
Centers Laboratory reported a data breach affecting 542,377 individuals, revealing personal and health information. The breach occurred due to limited access by cybercriminals from the WorldLeaks group, which highlights ongoing threats to healthcare data security.
RedHook Android malware exploits Wireless ADB for elevated privileges
The RedHook Android malware now leverages Wireless ADB to gain shell access without USB connections. This enhancement increases its capability, allowing for sophisticated attacks including credential theft and remote control of devices.
Motorola MR2600 Router Vulnerable to Unauthenticated RCE Attack
A remote code execution vulnerability has been discovered in Motorola’s MR2600 router, allowing attackers to upload malicious firmware without authentication. This flaw poses significant risks to users, as it can lead to unauthorized access and control of the device.
Fraudsters Use Faked News Stories to Scam Investment Site Victims
Fraudsters are creating fake articles that mimic reputable news sites, including The Guardian, to lure victims to scam investment platforms. These fraudulent stories often feature manipulated content about well-known individuals like Jim Ratcliffe and David Attenborough, aiming to trick unsuspecting readers into providing personal information and funds.
Australia warns of global CMS-targeting campaign exploiting vulnerabilities
The Australian Cyber Security Centre alerted about a global exploitation campaign affecting vulnerable CMS platforms, including WordPress and Joomla. Affected sites have had webshells deployed, allowing attackers persistent access to steal data and compromise services, highlighting the urgent need for security updates.
CISA lacked prepared incident response plan during May cybersecurity exposure incident
CISA officials revealed they had to create an incident response playbook during a cybersecurity incident in May, when sensitive keys were exposed. This situation underscores the importance of having pre-established response plans to effectively address security breaches without delay.
Laser Attack Allows Password Reset on Tangem Wallets Without Old Password
Researchers demonstrated that a laser attack can reset Tangem wallet passwords, allowing complete control over the wallet. Since the flaw cannot be fixed through software updates, all existing cards remain vulnerable, posing a significant risk for owners of lost or stolen cards.
WhatsApp-to-Host Attack Chain Exploits Three Vulnerabilities in OpenClaw
Three patched vulnerabilities in OpenClaw could enable attacks via WhatsApp, leading to credential theft and arbitrary code execution. Security researcher Chinmohan Nayak detailed these vulnerabilities, which don't require prior access for exploitation, raising concerns about configuration and security practices.
Silver Fox Group Unveils MODBEACON RAT with gRPC Streaming C2
The Silver Fox cybercrime group has introduced MODBEACON, a Rust-based remote access trojan utilizing gRPC for encrypted command-and-control traffic. This advanced malware signifies a shift in technique, focusing on long-term access and stealth in compromised systems across Asia.
Unpatched XQUIC Flaw Allows Remote Clients to Crash HTTP/3 Servers
A flaw in Alibaba's XQUIC library allows remote clients to crash HTTP/3 servers using valid traffic. The vulnerability, disclosed by researcher Sébastien Féry, affects all versions up to v1.9.4 and poses a risk to any server using XQUIC with default QPACK settings.
Hacker Server Leak Exposes WP-SHELLSTORM's Backdoor Operations on WordPress Sites
A cybercrime group operating under the name WP-SHELLSTORM left a server open, revealing over 1.4 million targeted websites and operational details of their mass hacking approach. This exposure highlights significant vulnerabilities in outdated WordPress plugins, particularly affecting users of the Breeze caching plugin and Joomla's JCE editor.
Research Finds Major Security Flaws in 281 Free Android VPN Apps
A study of 281 free Android VPN apps revealed significant security flaws, including traffic leaks and unencrypted data transmission. With over 2.4 billion installs, these weaknesses compromise user privacy and could allow malicious actors to redirect traffic.
Facial recognition in UK shops to alert police in real-time, sparking privacy concerns
Facewatch will launch a feature in UK shops that alerts police to serious offenders via facial recognition. Civil liberties groups raise concerns over surveillance risks and the technology's potential for false positives.
Vulnerability 'Ill Bloom' Leads to $3.1 Million Loss in Cryptocurrency Wallets
The 'Ill Bloom' vulnerability discovered by Coinspect allows attackers to exploit weakly generated recovery phrases in cryptocurrency wallets. This flaw has already resulted in the theft of approximately $3.1 million from 431 wallets, highlighting significant risks for users of older or lesser-known wallet software.
Research reveals 69% of enterprises expose AI agents through shared API keys
VentureBeat's research indicates that 69% of enterprises utilize shared API keys across multiple AI agents, increasing security risks. This finding has contributed to significant acquisitions in the security sector, with over $22 billion invested to counteract these vulnerabilities.