Top stories
Google and Microsoft Remove ModHeader Extension After Hidden Data Collector Found
Google and Microsoft have removed the ModHeader extension, with 1.6 million installs, after a dormant browsing-history collector was discovered within it. Although the collector was inactive, the potential for future data gathering raised significant privacy concerns.
2026 Public Sector M-Trends Report Highlights Alarming Cybersecurity Trends
The 2026 Public Sector Threat Landscape report reveals significant vulnerabilities in cybersecurity for the public sector, including a 22-second median hand-off to ransomware operators. These findings underscore an urgent need for rapid, machine-speed defenses amidst evolving attack methods that exploit trust boundaries.
MemGhost Attack Alters AI Agents' Memories with One Email
Researchers unveiled a new attack method, MemGhost, that allows attackers to implant false memories in AI assistants using a single email. This stealth memory injection alters how the AI responds in future sessions, raising significant concerns about the security of AI systems that retain user information.
UK charges five in connection with Russian Coms spoofing platform
UK authorities have charged five individuals linked to the Russian Coms caller ID spoofing platform, which facilitated over 1.8 million scam calls. This platform, operational since 2020, enabled criminals to impersonate financial institutions and law enforcement, leading to significant financial losses for victims worldwide.
Centers Laboratory Data Breach Impacts Over 540,000 Individuals
Centers Laboratory reported a data breach affecting 542,377 individuals, revealing personal and health information. The breach occurred due to limited access by cybercriminals from the WorldLeaks group, which highlights ongoing threats to healthcare data security.
Ireland's data centers used 23% of electricity in 2025, nearing total home consumption
Data centers in Ireland consumed 23% of the country's electricity in 2025, a significant rise from previous years. This growth raises concerns over electricity demand and its impact on residents, competing closely with residential electricity use.
RedHook Android malware exploits Wireless ADB for elevated privileges
The RedHook Android malware now leverages Wireless ADB to gain shell access without USB connections. This enhancement increases its capability, allowing for sophisticated attacks including credential theft and remote control of devices.
Motorola MR2600 Router Vulnerable to Unauthenticated RCE Attack
A remote code execution vulnerability has been discovered in Motorola’s MR2600 router, allowing attackers to upload malicious firmware without authentication. This flaw poses significant risks to users, as it can lead to unauthorized access and control of the device.
Brazilian woman rescued after 55 years of domestic servitude
A woman in Brazil, referred to as Maria, was rescued after 55 years in slave-like conditions. Employed by three generations of one family since the age of seven, she received no pay and had no personal freedom.
Landmark lawsuit holds Meta and Google accountable for social media addiction
Mark Lanier led a landmark case against Meta and Google, arguing their platforms deliberately foster addiction, affecting children’s mental health. The trial, described as a 'big tobacco moment for big tech,' challenges the design of social media platforms rather than their content, setting a precedent for future cases.
Fraudsters Use Faked News Stories to Scam Investment Site Victims
Fraudsters are creating fake articles that mimic reputable news sites, including The Guardian, to lure victims to scam investment platforms. These fraudulent stories often feature manipulated content about well-known individuals like Jim Ratcliffe and David Attenborough, aiming to trick unsuspecting readers into providing personal information and funds.
Quantum-Mesh-QEC v2 Introduces Fault-Tolerant Quantum Control System
Quantum-Mesh-QEC v2 launches a real-time, fault-tolerant infrastructure for quantum error correction, overcoming traditional decoding limitations. By implementing a 3-Tier Hardware-Fused Control Loop, it enables low-latency control without classical decoding interference, significantly enhancing quantum computing reliability.
Australia warns of global CMS-targeting campaign exploiting vulnerabilities
The Australian Cyber Security Centre alerted about a global exploitation campaign affecting vulnerable CMS platforms, including WordPress and Joomla. Affected sites have had webshells deployed, allowing attackers persistent access to steal data and compromise services, highlighting the urgent need for security updates.
Amazon layoffs affected 16,000 employees, reshaping job market dynamics
Amazon laid off approximately 16,000 employees in January, marking its largest cut in history. This wave of layoffs reflects a broader trend in the tech industry, where around 140,000 employees have been let go in the U.S., influenced significantly by automation and AI developments.
CISA lacked prepared incident response plan during May cybersecurity exposure incident
CISA officials revealed they had to create an incident response playbook during a cybersecurity incident in May, when sensitive keys were exposed. This situation underscores the importance of having pre-established response plans to effectively address security breaches without delay.
New research shows Einstein's relativity affects chemical bonding in heavy elements
Brown University researchers have found that Einstein's relativity alters the behavior of triple bonds in heavy elements. Their study provides direct evidence that as atomic nuclei become heavier, traditional chemical bond classifications, specifically sigma and pi bonds, become indistinct due to relativistic effects.
Study analyzes health impact of RFK Jr.'s vaccine policy change for toddlers
A study published in JAMA Network Open analyzes the detrimental effects of a recent policy change regarding the MMRV vaccine. The panel, selected by Health Secretary Robert F. Kennedy Jr., voted to strip federal recommendations for the vaccine without a comprehensive review, which will affect children’s access amid rising health risks.
ICE Faces Criticism Over Deportation Threats to Witnesses of Fatal Shooting
After the fatal shooting of Lorenzo Salgado Araujo by ICE officers, advocates are demanding the release of bodycam footage. DHS claims the agents were not wearing body cameras due to funding issues, while witnesses in ICE detention contradict the agency's self-defense narrative, raising concerns about accountability.
GPT-5.6 Sol Ultra proves Cycle Double Cover Conjecture
The latest version of GPT, named GPT-5.6 Sol Ultra, has produced a proof for the Cycle Double Cover Conjecture. This achievement represents a significant advancement in the application of AI to complex mathematical problems, potentially impacting future research in mathematics and AI.
Astronomers achieve most precise measurement of Earth's Lense-Thirring effect
A team led by Ignazio Ciufolini has reported the most accurate measurement of Earth's Lense-Thirring effect, reducing uncertainty from a few percentage points to 0.2%. This measurement was achieved using the LARES-2 satellite, which is designed to minimize the impact of external forces.
SpaceX applies to launch 100k new Starlink satellites for increased bandwidth
SpaceX has applied to the FCC to launch 100,000 Gen3 Starlink satellites to enhance broadband capacity. Once deployed, the network is projected to deliver multi-gigabit symmetrical speeds, positioning SpaceX to dominate the satellite internet market and meet future demand from AI devices.
Steam revenue reaches $11.1 billion in H1 2026, driven by Chinese market growth
Valve's Steam platform generated an estimated $11.1 billion in revenue in the first half of 2026, marking a 14.5% increase from H1 2025. Key factors include a rise in Chinese players, higher game prices, and increased emphasis on legacy game catalogues, highlighting a significant shift towards digital sales in the gaming industry.
Oratomic raises $300M to develop utility-scale quantum computer with fewer qubits
Oratomic has secured $300 million in a Series A funding round to develop a utility-scale quantum computer, aiming to complete it by the end of the decade. The company plans to use an innovative approach that requires only 10,000 to 20,000 qubits for effective error correction, significantly fewer than other competitors. This development could accelerate the commercialization of quantum computing technologies across various fields.
Tencent seeks to acquire AI startup Manus from Meta after Beijing intervention
Tencent is reportedly negotiating to acquire Manus from Meta for $2 billion following a government order to unwind the deal. This move reflects China's aim to maintain control over its AI assets amid rising competition with the U.S.
Laser Attack Allows Password Reset on Tangem Wallets Without Old Password
Researchers demonstrated that a laser attack can reset Tangem wallet passwords, allowing complete control over the wallet. Since the flaw cannot be fixed through software updates, all existing cards remain vulnerable, posing a significant risk for owners of lost or stolen cards.
Bank of England to Regulate Key Tech Firms Like Amazon and Google
The Bank of England will regulate major tech firms, starting next week, due to concerns over financial stability. Companies like Amazon, Google, Oracle, and Microsoft must ensure resilience against cyber threats and service disruptions.
WhatsApp-to-Host Attack Chain Exploits Three Vulnerabilities in OpenClaw
Three patched vulnerabilities in OpenClaw could enable attacks via WhatsApp, leading to credential theft and arbitrary code execution. Security researcher Chinmohan Nayak detailed these vulnerabilities, which don't require prior access for exploitation, raising concerns about configuration and security practices.
Nanya Technology to Quadruple 2027 Capital Spending to $6.2 Billion Amid Dramatic Revenue Surge
Nanya Technology plans to increase its capital spending to $6.2 billion in 2027, up from $1.55 billion in 2023, as second-quarter revenue skyrockets by 684% to T$82.55 billion. The surge is primarily driven by a more than 70% increase in average selling prices for DRAM, pushing gross margins to 79.5%.
Silver Fox Group Unveils MODBEACON RAT with gRPC Streaming C2
The Silver Fox cybercrime group has introduced MODBEACON, a Rust-based remote access trojan utilizing gRPC for encrypted command-and-control traffic. This advanced malware signifies a shift in technique, focusing on long-term access and stealth in compromised systems across Asia.
Unpatched XQUIC Flaw Allows Remote Clients to Crash HTTP/3 Servers
A flaw in Alibaba's XQUIC library allows remote clients to crash HTTP/3 servers using valid traffic. The vulnerability, disclosed by researcher Sébastien Féry, affects all versions up to v1.9.4 and poses a risk to any server using XQUIC with default QPACK settings.
Hacker Server Leak Exposes WP-SHELLSTORM's Backdoor Operations on WordPress Sites
A cybercrime group operating under the name WP-SHELLSTORM left a server open, revealing over 1.4 million targeted websites and operational details of their mass hacking approach. This exposure highlights significant vulnerabilities in outdated WordPress plugins, particularly affecting users of the Breeze caching plugin and Joomla's JCE editor.
EU Commission finds Instagram and Facebook breach Digital Services Act
The European Commission has determined that Instagram and Facebook employ addictive design practices, violating the Digital Services Act (DSA). This finding could lead to significant regulatory repercussions for Meta and reshape design practices in social media across the EU.
Polestar ceases US sales, leaving owners and dealers uncertain about future
Polestar announced it will stop selling vehicles in the US beginning with the 2027 model year after being denied authorization for Chinese-made software. Current owners and dealers are expressing concerns about vehicle value, servicing, and warranties following this decision.
Research Finds Major Security Flaws in 281 Free Android VPN Apps
A study of 281 free Android VPN apps revealed significant security flaws, including traffic leaks and unencrypted data transmission. With over 2.4 billion installs, these weaknesses compromise user privacy and could allow malicious actors to redirect traffic.
Facial recognition in UK shops to alert police in real-time, sparking privacy concerns
Facewatch will launch a feature in UK shops that alerts police to serious offenders via facial recognition. Civil liberties groups raise concerns over surveillance risks and the technology's potential for false positives.
Ofcom proposes regulations for big tech to combat scam ads
Ofcom has proposed new measures requiring platforms like YouTube and Instagram to tackle fraudulent advertisements. If enacted, companies could face fines of up to £18 million or 10% of global turnover for non-compliance, significantly impacting how tech firms manage advertising content.
Vulnerability 'Ill Bloom' Leads to $3.1 Million Loss in Cryptocurrency Wallets
The 'Ill Bloom' vulnerability discovered by Coinspect allows attackers to exploit weakly generated recovery phrases in cryptocurrency wallets. This flaw has already resulted in the theft of approximately $3.1 million from 431 wallets, highlighting significant risks for users of older or lesser-known wallet software.
Lyzr Uses AI Agent to Successfully Raise $100 Million in Series B Funding
Lyzr, a startup specializing in AI agents, utilized its own AI agent, SivaClaw, to secure a $100 million Series B funding round. This approach demonstrated the effectiveness of their product, attracting $400 million in investor interest without traditional fundraising efforts.
Research reveals 69% of enterprises expose AI agents through shared API keys
VentureBeat's research indicates that 69% of enterprises utilize shared API keys across multiple AI agents, increasing security risks. This finding has contributed to significant acquisitions in the security sector, with over $22 billion invested to counteract these vulnerabilities.
New Helix vishing group targets SharePoint for data theft
A new cybercriminal group named Helix is using vishing and MFA abuse to steal data from SharePoint environments. The group impersonates employees to trick victims into giving up sensitive information, leading to data extortion practices similar to those of previous groups like ShinyHunters and BlackFile.