Top stories
Firefox 148 Launches Sanitizer API for Enhanced XSS Protection
Firefox 148 introduces the Sanitizer API, allowing developers to sanitize untrusted HTML with the setHTML() method, improving security against XSS attacks. This API provides a standardized way to prevent vulnerabilities that have historically plagued the web, positioning Firefox as a leader in web safety enhancements.
Firefox Implements CRLite for Secure Certificate Revocation Checking
Firefox has introduced CRLite, allowing private and efficient certificate revocation checking, marking it the first browser to do so. This change enhances security by ensuring that revoked certificates, which pose security risks, are identified accurately without revealing user browsing activity.
U.S. Directive Bans Differential Privacy for Economic Data Releases
The U.S. Secretary of Commerce issued DAO 216-26, banning differential privacy techniques for data protection. This directive reverses decades of advancements in privacy measures and may weaken the usefulness of census and economic statistics.
Apple's iOS 27 introduces Trust Insights to combat real-time scams
Apple has unveiled the Trust Insights framework in iOS 27, designed to help apps detect social engineering scams in real-time. By analyzing user behavior during interactions, it can flag potential scams and notify users through apps, addressing the growing prevalence of such scams, particularly with the rise of AI deepfakes.
U.S. Labor Force Participation Falls to Lowest Level in 50 Years
The U.S. labor force participation rate fell to 61.5%, the lowest since March 2021, attributed to a significant drop in job seekers. This decline indicates a concerning trend in the labor market, with many workers, possibly retirees or discouraged job seekers, exiting the workforce.
Anubis Ransomware Group Exploits Citrix Bleed 2 Vulnerability for Attacks
The Anubis ransomware operation has been identified exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to gain access to targeted environments. This trend, utilizing legitimate remote access tools for lateral movement, highlights the evolving tactics of ransomware groups and the urgent need for organizations to address vulnerabilities.
Supreme Court ruling jeopardizes EU-US data transfer framework
A Supreme Court ruling allowing the president to dismiss independent agency heads jeopardizes the EU-U.S. Data Privacy Framework. Max Schrems plans to sue to invalidate the framework, which governs data transfers crucial for €1.7 trillion in transatlantic trade.
SK hynix announces $712.5 billion investment in South Korean semiconductor operations
SK hynix revealed plans to invest KRW 1.1 trillion ($712.5 billion) in its South Korean operations, primarily for semiconductor production. This includes KRW 100 trillion ($64 billion) for its Cheongju campus for NAND and HBM production, and KRW 400 trillion ($259.5 billion) for a new Southwestern semiconductor cluster.
Linux 6.9 LUKS Suspend Fails to Clear Disk-Encryption Keys from Memory
In Linux kernel version 6.9, the LUKS suspend functionality ceased to wipe disk-encryption keys from memory, potentially exposing sensitive information. This change raises significant security concerns, particularly for systems requiring strong data protection measures.
Spain Blacklists Palantir from Public and State-Controlled Companies
The Spanish government has blacklisted Palantir Technologies from public and private state-controlled companies due to concerns regarding national security information misuse. This decision disrupts existing contracts and procurement pipelines, reflecting a broader trend of regulatory pushback against the company in Europe.
Japan's top court rules AI cannot be listed as inventor in patents
The Supreme Court of Japan determined that artificial intelligence cannot be designated as an inventor on patent applications. This ruling impacts how inventions generated by AI can be legally protected, emphasizing that only human beings can hold such rights under existing patent laws.
Umbrij Malware Exploits OAuth to Access Gmail Through Google API
The ToddyCat threat actor has released a new malware named Umbrij, which gains unauthorized access to Gmail accounts via the Google API using OAuth tokens. This technique could significantly impact corporate email security, as it leverages existing Gmail sessions for access.
UN report highlights risk of AI worsening global inequality
The UN warns that AI development could exacerbate global inequality without shared governance. A report outlines the risks and provides a framework for responsible AI development to ensure equitable access and control.
Inscribe Uses Amazon Bedrock for Rapid Document Fraud Detection
Inscribe utilizes Amazon Bedrock to enhance its document fraud detection, reducing verification time to under 90 seconds. This advancement addresses the surge in AI-generated fraud and the pressing need for financial institutions to maintain accuracy amidst increasing application volumes.
Visa, Mastercard, and Coinbase Announce New Global Stablecoin Open USD
Visa, Mastercard, and Coinbase launched a stablecoin called Open USD, tied to the US dollar. The initiative aims to enhance global stablecoin usage and creates a consortium of over 140 businesses to support this effort.
Schrödinger accelerates molecular discovery by 4x using AlphaEvolve
Schrödinger partnered with Google Cloud to implement AlphaEvolve, enhancing their MLFF process by 4x. This advancement resolves the trade-off between speed and precision in molecular simulations, significantly impacting drug discovery and materials design.
UK CMA targets Apple and Google’s app store duopoly with new regulations
The UK’s Competition and Markets Authority is proposing regulations to dismantle the duopoly of Apple and Google over mobile app stores, allowing developers to direct users to external payment methods. This change aims to enhance competition by lifting existing restrictions and could significantly impact the revenue model of both tech giants.
Firefly Aerospace Operates NVIDIA Jetson in Lunar Orbit for the First Time
Firefly Aerospace's Blue Ghost Mission 2 will use NVIDIA Jetson for AI processing in lunar orbit, enabling real-time data insights. This marks a significant advancement in space technology, reducing the delay of data transmission and processing from space.
AI Develops Innovative Radio Chips to Accelerate Wireless Technologies
Princeton researchers utilized AI to design radio-frequency integrated circuits (RFICs), overcoming traditional design limitations. This AI-driven methodology can significantly enhance the performance and reduce the design time for RFICs, which are critical for advancing 5G, autonomous vehicles, and satellite technologies.
5G Fixed Wireless Access Emerges as Key Broadband Solution
Fixed Wireless Access (FWA) has become the leading application for 5G, serving over 14 million U.S. customers. This shift allows carriers to repurpose existing 5G infrastructure for home internet, providing a cost-effective alternative to traditional cable services.
NVIDIA and AWS Enhance AI Production with New EC2 G7 Instances
NVIDIA and AWS have launched EC2 G7 instances powered by NVIDIA RTX PRO 4500 GPUs, enhancing AI production capabilities. These instances offer substantial performance improvements, enabling enterprises to deploy AI and data analytics workloads at scale with lower operational complexity.
NVIDIA Powers Over 400 of the World's 500 Fastest Supercomputers
NVIDIA technology powers 81% of the TOP500 supercomputers, with significant growth in new deployments. The adoption of NVIDIA CPUs and GPUs indicates a strong focus on AI and high-performance computing across various systems.
JUPITER, Europe’s first exascale supercomputer, showcases advanced projects at ISC
JUPITER, Europe's first exascale supercomputer, is demonstrating its capabilities at ISC in Hamburg with projects mapping the human brain, simulating climate, and building AI systems. This development marks a significant shift in computational power, enabling complex scientific problems previously deemed unreachable.
Google DeepMind announces $10M funding for multi-agent AI safety research
Google DeepMind has announced a new funding initiative of up to $10 million for research on multi-agent AI safety. This funding aims to understand and manage the risks associated with interactions among AI agents as they become more widespread, which is critical for ensuring safety and predictability in AI systems.
Google Gemini 3.5 Live Translate Offers Real-Time Voice Translation
Google has launched Gemini 3.5 Live Translate, enhancing speech-to-speech translation for over 70 languages. The model allows for continuous translation without pauses, significantly improving real-time multilingual communication.
Microsoft announces Azure Cobalt 200 VMs with 50% performance improvement for AI
Microsoft's Azure Cobalt 200 Arm-based VMs provide a 50% performance boost over the Cobalt 100, tailored for agentic AI workloads. This launch signals a shift in cloud architecture due to increased customer demand for compute in AI applications.
New Android malware silently infects billions of devices via Google
A new Trojan horse malware disguised as 'Android Developer Verifier' has infected around 4 billion Android devices running version 8 or higher. It operates in the background with root privileges, preventing users from removing it and blocking access to software from unregistered developers.
Serious Flaw in Argo CD Repo-Server Allows Remote Code Execution
An unpatched flaw in Argo CD's repo-server allows unauthenticated attackers to execute code, potentially taking over Kubernetes clusters. Synacktiv, which discovered the issue, reports that the vulnerability remains unaddressed nearly 18 months after it was reported.
Google Announces AI Updates Including Gemma 4 12B and Android 17
In June 2026, Google unveiled significant AI advancements including the Gemma 4 12B model and Android 17. These developments aim to create a more integrated AI environment that enhances productivity across various fields by allowing AI assistance to function seamlessly on personal devices.
Critical Vulnerability in Progress Kemp LoadMaster Enables Root Command Execution
A critical vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster permits unauthenticated root command execution via API requests. Patches are released to mitigate the CVSS 9.8 flaw. Reports indicate active exploitation attempts, causing security concerns among users.
AI-Generated Ransomware Discovered Exploiting Chromium API on Windows and Android
A new ransomware artifact created by the AI model DeepSeek combines theoretical attacks with real browser functionality, enabling browser-based ransomware on Windows and Android. This marks the first identified practical attack chain of its kind, indicating a significant shift in the cybersecurity threat landscape.
Realta Fusion generates electricity from fusion reaction, marking industry milestone
Realta Fusion conducted an experiment demonstrating electricity generation directly from its fusion device, WHAM, which successfully powered a lightbulb. This marks the first time a private company has publicly achieved this, potentially advancing the profitability of fusion power through higher energy efficiency.
GuardFall Exploits Decades-Old Shell Injection Risks in AI Coding Agents
New research from Adversa AI reveals that the GuardFall vulnerability allows bypassing safety checks in AI coding agents. This poses risks of executing malicious shell commands with full account access across multiple popular open-source agents.
Critical Flaw CVE-2026-46817 in Oracle E-Business Suite Exploited
A critical vulnerability in Oracle E-Business Suite, CVE-2026-46817, is now being actively exploited. Impacting versions 12.2.3 to 12.2.15, the flaw allows unauthenticated attackers to take control of Oracle Payments, necessitating immediate patching for affected instances.
Supreme Court Rules Government Requires Warrant for Geofence Warrants
The Supreme Court ruled that government access to a user’s location history requires a warrant. This ruling underscores the Fourth Amendment's protections for digital privacy, limiting law enforcement's ability to utilize geofence warrants without substantial proof of necessity.
Mustang Panda Exploits Zoho WorkDrive in Campaign Against Indian Government
The Mustang Panda group has launched campaigns targeting the Indian government, utilizing Zoho WorkDrive to transmit commands and steal data. This approach leverages legitimate service traffic to mask malicious activities and is part of broader espionage efforts aimed at India's hydropower initiatives and defense relations with Taiwan.
Microsoft Removes 119 Malicious Edge Extensions Involved in Malware Operation
Microsoft has removed 119 Edge extensions from its Add-ons store that concealed malware within images and fonts, compromising user credentials and facilitating ad fraud. The extensions, installed by up to 2.6 million users, utilized steganography to hide malicious code, operating undetected for years.
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
A public proof-of-concept has been released for CVE-2026-55200, a critical flaw in libssh2 that may allow memory corruption and code execution for connected clients. This vulnerability affects all versions up to 1.11.1, posing significant risks as libssh2 is widely used in various applications and systems.
Hijacked npm and Go Packages Deploy Python Infostealer via VS Code Tasks
Cybersecurity researchers have identified hijacked npm and Go packages that deploy a Python-based infostealer on compromised systems. This method utilizes a concealed VS Code task to execute malware upon opening a project folder, facilitating data theft and persistent access.
China's LineShine crowned world's fastest supercomputer, surpassing El Capitan
China's supercomputer LineShine has become the fastest globally, reclaiming the title for the first time since 2018. This development is significant in light of ongoing US trade restrictions on high-powered computing components, highlighting China's ability to innovate despite challenges.