Security · Top stories
LastPass and Bitwarden users face phishing attacks with fake security alerts
LastPass has warned users of a phishing campaign using fake security alerts to redirect users to malicious websites. Similarly, Bitwarden users have also been targeted with similar phishing tactics, raising concerns over user security.
Singapore Charges Two in AI GPU Smuggling Case; Nvidia Tightens Measures
Singapore has charged two individuals, Lim Jenny and Woon Guo Jie Aaron, with money laundering in an AI GPU smuggling case. The authorities seized a $42 million mansion and froze over $772,000 linked to the alleged activities. In response to U.S. pressure, Nvidia has drastically cut its list of authorized customers in Asia to curb smuggling into China.
Nihon Kotsu shuts down systems following cyberattack
Nihon Kotsu, Japan's largest taxi operator, experienced a cyberattack that compromised its systems, including the taxi dispatch service. The disruption affects multiple operations, including booking and internal systems, prompting the company to engage cybersecurity experts for an investigation.
Lionshead Implements Automated Security Checks in Pull Requests
Lionshead has integrated a set of automated security checks into its pull request process to prevent vulnerabilities from reaching production. This approach is critical for smaller teams, which lack the resources to manage security incidents effectively.
TFTP Honey Pot Captures Traffic from Infosec Companies
A TFTP honeypot running on a VPS and a home server collected 20-50 packets daily, revealing mostly scheduled scans from infosec firms. The results highlight the interest and activity from companies like Shodan and Censys in TFTP traffic, indicating ongoing reconnaissance efforts in network environments.
QR Code Phishing (Quishing) Threats on the Rise, Bypassing MFA
QR code phishing, or 'quishing,' is increasingly used to bypass multi-factor authentication and steal data. With a reported 25% year-over-year increase, these scams often disguise malicious links in QR codes found in emails, attachments, or physical settings, raising concerns about security.
Apple Sues OpenAI Over Alleged Trade Secret Theft by Former Employees
Apple is suing OpenAI, claiming trade secret theft by ex-Apple employees now at OpenAI, including former VP of product design, Tang Tan. The lawsuit notes concern over more than 400 former Apple employees at OpenAI, escalating tensions about proprietary knowledge in tech.
Progress Urges ShareFile Customers to Shut Down Storage Zone Controllers Due to Threat
Progress has advised ShareFile customers to disable Storage Zone Controllers due to a credible security threat. Although access to affected accounts has been temporarily disabled, the nature of the threat remains unclear, with no evidence of unauthorized access reported.
Cloudflare launches Precursor for enhanced bot detection and user verification
Cloudflare has launched Precursor, a client-side verification system that collects behavioral signals to distinguish between human and automated traffic. This system bolsters existing bot protection by providing deeper insights into user interactions across applications, enhancing overall detection accuracy.
Varonis Launches Entra ID Training Experience 'Breach at the Beach'
Varonis Threat Labs introduced 'Breach at the Beach', a Capture The Flag (CTF) training on Entra ID. This training helps security practitioners understand data exfiltration threats linked to non-human identities amid evolving AI technology.
AI-Generated PowerShell Script Used in Active Directory Attack
Researchers identified a cyber attack employing a PowerShell script likely generated by AI for Active Directory enumeration. The script executed a sophisticated attack chain, highlighting a trend of using AI-assisted tools in cyber intrusions.
Prismata Introduced to Combat Cross-Site Prompt Injection in Web Agents
Prismata is a new defense mechanism designed to enhance security for autonomous web agents by enforcing contextual least privilege. It limits the visibility and capabilities of web agents when encountering user-generated content, significantly reducing the success rate of prompt injection attacks while maintaining their operational utility.
Bulgarian man charged with stealing seized cryptocurrency from prison
Rossen G. Iossifov faces charges for allegedly stealing $290,000 in seized cryptocurrency while incarcerated. This case underscores ongoing issues in tracking and curbing cryptocurrency-related fraud and the challenges of the enforcement in maintaining control over seized assets.
Lumen Technologies Expands Asset Inventory from 17,000 to 1.1 Million
Lumen Technologies utilized the Axonius asset intelligence platform to consolidate data from over 40 systems, uncovering 1.1 million devices, significantly increasing its asset visibility. This comprehensive view enhances Lumen's ability to manage vulnerabilities and streamline incident response procedures.
QIZ Security Secures $17 Million for Cryptographic Governance Platform
QIZ Security has raised $17 million in seed funding to enhance its post-quantum cryptography management platform. The platform aims to enable organizations to govern encryption across various environments and prepare for quantum computing risks.
LVM continues recovery efforts after ransomware attack disrupted services
Latvia's state forestry company, LVM, is still restoring IT systems weeks after a June ransomware attack. Customer services, including mapping and hunting applications, remain affected, with two-thirds of customers lacking access.
Summer IT Staffing Gaps Create Increased Cybersecurity Risks
Organizations face heightened cybersecurity risks during summer due to reduced IT staffing levels. Cybercriminals capitalize on slower response times, leading to increased vulnerabilities and potential for successful attacks.
Palo Alto Networks Addresses 13 Security Vulnerabilities in Recent Patch
Palo Alto Networks has patched 13 vulnerabilities across its products, including a severe buffer overflow in PAN-OS that could allow DoS attacks and remote code execution. Organizations are advised to apply these updates to mitigate risks, particularly given the vulnerabilities' potential for exploitation despite currently low attack activity.
NSA Rebrands Hacking Division as 'Tailored Access Operations'
The NSA has reinstated the name 'Tailored Access Operations' for its hacking division, reversing a prior reorganization decision. This change aims to enhance its responses to evolving cyber threats from nations like China and Russia.
Security Focus on System Prompt Leakage in Generative AI Applications
System prompts, essential for LLMs, face leakage issues due to prompt injection risks. This risk highlights the need for robust security measures in generative AI designs.
AI Coding Agents Trigger Security Alarms for Normal Operations
Sophos detected that AI coding agents like Claude Code and Codex are triggering endpoint security alarms by performing activities that mimic cyberattacks. This is significant as it highlights the challenges of distinguishing legitimate developer tools from potential threats in security systems.
Google selects 33 startups for inaugural Gemini Startup Forum in cybersecurity
Google has announced the first cohort of 33 cybersecurity startups for its Gemini Startup Forum, which emphasizes the integration of AI in addressing key industry challenges. These startups will collaborate with experts from Google DeepMind and Google Cloud to enhance cybersecurity solutions across various focus areas such as autonomous agent protection and post-quantum cryptography.
Google integrates Threat Intelligence with Wiz ASM for proactive security
Google Threat Intelligence is integrating with Wiz Attack Surface Management to enhance proactive security measures. This integration aims to connect real-time threat intelligence with exploitable risks, helping organizations prioritize defenses against actual adversary activity.
Django Releases Security Updates 6.0.7 and 5.2.16 to Address Vulnerabilities
Django has released updates 6.0.7 and 5.2.16 to fix several low-severity security issues. The updated versions address vulnerabilities involving cookie signing, email transmission, caching behavior, and a heap buffer over-read in GDALRaster. Users are advised to upgrade promptly to maintain security and mitigate potential risks.
CISA Uses Anthropic's Mythos AI to Audit Federal Software for Vulnerabilities
CISA is deploying Anthropic’s Mythos AI model to scan federal government software for vulnerabilities. The initiative aims to identify and rectify potential security flaws that could be exploited before they are discovered by adversaries.
UK National Cyber Action Plan Delayed Amid Political Upheaval
The UK's National Cyber Action Plan launch has been postponed due to political instability following Prime Minister Keir Starmer's resignation. The Cyber Resilience Pledge, part of the plan, saw limited participation, with less than 15 FTSE 350 companies signing up despite government efforts. The delay and low participation raise concerns about the UK's commitment to cybersecurity amid leadership transitions.
U.S. Army websites hacked, defaced with political messages against Trump
The U.S. Army has repaired two websites after they were defaced with messages criticising President Trump and promoting Kurdish independence. These incidents highlight ongoing security vulnerabilities in government-operated systems amid increased hacktivist activities.
Tarah Wheeler Shares Insights on Her Career in Cybersecurity Leadership
Tarah Wheeler, CISO at TPO Group, discusses her unexpected journey into cybersecurity and her social science perspective on the field. Her insights highlight the importance of understanding human behavior in shaping effective security policies and leadership roles in cybersecurity.
Kremlin-linked drones suspected in European airspace incursions from shadow fleet
The International Institute for Strategic Studies reports drone flights over Europe may be coordinated by the Kremlin using Russian-linked commercial ships. These incidents, impacting NATO member countries, highlight vulnerabilities in European air defenses against low-cost drone incursions.
Japanese teen arrested for cyberattack on anime streaming service Bandai Channel
A 15-year-old boy was arrested in Japan for exploiting a flaw in Bandai Channel's servers to fraudulently cancel over 46,000 subscriptions. The incident led to a temporary suspension of the service and underscores vulnerabilities in streaming platforms.
New OSINT Tool Monitors Exposed Files on Domains Using Certificate Transparency Logs
A new OSINT tool has been launched that monitors certificate transparency logs to identify exposed files on newly-seen domains. This tool allows penetration testers and bug bounty hunters to search for sensitive data like configuration files and database dumps easily.
BareMetal RAM Dumper Tool Developed for Cold Boot Attack Testing
A new x86 bare-metal tool allows users to dump system RAM directly to a USB drive during Cold Boot Attack experiments. By cooling the RAM to -60°C, sensitive information can be extracted before data decay occurs, highlighting vulnerabilities in memory security.
YouTube Studio AI vulnerable to prompt injection via comments
A flaw in YouTube Studio's AI assistant, Ask Studio, allows attackers to manipulate responses by editing comments. This could mislead creators into trusting malicious instructions disguised as official communications from YouTube.
Spike in vulnerabilities linked to Claude Mythos Preview release
Following the announcement of Anthropic's Claude Mythos Preview in April 2026, high- and critical-severity vulnerabilities surged over 3.5 times by June. This increase highlights the dual-use risks of advanced AI models in cybersecurity.
Canadian Hacker Jailed for Cyberattack; KDDI Data Breach Impacts 14 Million
Aubrey Cottle, a Canadian hacker linked to Anonymous, was sentenced to 18 months in prison for a 2021 cyberattack on the Texas GOP. Meanwhile, KDDI announced a data breach affecting over 14 million users, exposing email addresses and passwords.
Django Software Foundation Receives CNA Status for Security Management
The Django Software Foundation (DSF) has achieved CNA status, enabling it to assign CVE IDs internally for vulnerabilities in Django and select community projects. This move streamlines the advisory process and enhances independence in managing security incidents.
Node.js Releases Multiple LTS and Current Versions with Security Updates
Node.js released versions 20.20.2, 22.22.2, 24.14.1, 25.8.2, 22.23.0, 24.17.0, and 26.3.1, focusing on improving security. Fixes cover vulnerabilities in cryptographic functions, permissions, and TLS handling.
Node.js Releases Security Updates Addressing Multiple Vulnerabilities
Node.js has issued security updates for versions 20.x, 22.x, 24.x, 25.x, and 26.x to address various vulnerabilities that could lead to process crashes and security issues. The updates resolve problems in TLS error handling, HTTP request processing, WebCrypto implementation, and proxy credential exposure. These vulnerabilities, if exploited, could impact application stability and security.
Rust Security Team Addresses Cargo Vulnerabilities (CVE-2026-5222 & CVE-2026-5223)
The Rust Security Response Team has identified two vulnerabilities in Cargo, impacting third-party registries. CVE-2026-5222 is a low-severity issue allowing potential credential exposure, while CVE-2026-5223 is a medium-severity issue that could allow malicious code to overwrite other crates. Rust 1.96.0, releasing May 28, 2026, will address these issues.
Mozilla Reports Improved Bug Detection in Firefox Using AI Models
Mozilla has utilized Claude Mythos Preview and AI models to identify and rectify a high volume of latent security bugs in Firefox. This enhancement of AI capabilities has drastically reduced false positives and bolstered the browser's defenses against attacks.