From The Hacker News · 40 stories
Google releases Gemini 3.8 Flash AI model with improved benchmarks
Google has released Gemini 3.8 Flash, the third Flash update in three months, which shows improved performance in benchmarks compared to its predecessor. This model is designed for software engineering, autonomous agents, and complex enterprise workflows, and is available with an introductory pricing offer.
Google Introduces Selfie Video for Account Sign-in and Recovery
Google has launched a new selfie video option for account sign-in and recovery, allowing users to regain access by recording a short video of their face. This feature provides an alternative verification method, particularly useful when traditional authentication methods are unavailable, by comparing a live video to a securely stored reference video.
Teens sentenced to 5.5 years for £29M Transport for London cyber attack
Owen Flowers and Thalha Jubair were sentenced to 5.5 years for a 2024 cyberattack on TfL that caused £29 million in damages. The attack severely disrupted services and breached data of millions. Authorities cite this case as a major enforcement action against young cybercriminals.
Google fined over €400m by Irish DPC for manipulating location data consent
Google received a fine exceeding €400 million from Ireland's Data Protection Commission (DPC) for manipulating users into agreeing to location data tracking. The DPC's six-year inquiry found Google lacked a valid legal basis for processing location data, which could reveal sensitive personal information.
WhatsApp Enhances Account Security with Stronger 2FA and Multiple Passkeys
WhatsApp has updated its account security features, allowing users to set alphanumeric passwords with special characters for two-step verification, replacing the previous six-digit PINs. The platform also introduced support for adding multiple passkeys to a single account, useful for users across iOS and Android devices, and added more context for calls from unknown numbers on Android.
TikTok settles DOJ children's privacy lawsuit for $400 million
TikTok and its parent company, ByteDance, have agreed to pay $400 million to settle a lawsuit filed by the U.S. Department of Justice (DOJ) in 2024. The lawsuit alleged violations of the Children's Online Privacy Protection Act (COPPA) by collecting personal information from underage users without parental consent. The settlement includes new age-related controls and parental oversight measures.
Model Context Protocol (MCP) 2026-07-28 Specification Released, Adopting Stateless Core
The Model Context Protocol (MCP) has released its 2026-07-28 specification, transitioning from a bidirectional stateful protocol to a request/response stateless core. This update, the largest revision since its launch, aims to improve reliability and scalability for MCP servers, addressing a highly requested developer feature. Major SDKs, including TypeScript, Python, and C#, have been updated to support the new specification.
Dependabot introduces default three-day cooldown for version updates
Dependabot now includes a default three-day cooldown before opening version update pull requests. This change aims to reduce the risk of merging compromised versions immediately after their release, enhancing supply chain security for developers.
Cybersecurity Expert Sentenced for Role in BlackCat Ransomware Scams
Angelo Martino, a former ransomware negotiator, has been sentenced to 70 months for aiding the BlackCat ransomware gang. Collaborating with accomplices, he shared confidential negotiation details, causing victims to lose over $75 million. This highlights vulnerabilities within cybersecurity industries.
New "Pass-ta-key" Attacks Bypass Passkey Protections in Google Password Manager
Researchers from Palo Alto Networks' Unit 42 have identified three "Pass-ta-key" attack methods that allow malware on compromised Windows machines to bypass passkey protections in Chrome's Google Password Manager. These attacks exploit how Chrome stores device keys and re-enrolls devices, enabling silent authentication, installation of attacker-controlled keys, or extraction of synced passkey private keys, demonstrating vulnerabilities in passkey implementations when an endpoint is already compromised.
Zoom Patches Critical Vulnerability Allowing Device Takeover During Screen Sharing
Zoom has patched critical vulnerabilities in its video conferencing platform that allowed attackers to remotely execute code and take over devices during screen-sharing sessions. Discovered by A Security using fewer than 20 AI prompts, the flaw affected all supported operating systems and required no victim interaction, highlighting the increasing accessibility of advanced exploit development.
WebKit Flaws Expose Real IP Addresses for iCloud Private Relay and Proxy Browser Users
Security researchers Talal Haj Bakry and Tommy Mysk discovered three WebKit features that bypass proxy configurations, leading to IP and DNS leaks. These vulnerabilities affect Apple's iCloud Private Relay and other proxy browsers on iOS and macOS, potentially exposing users' real IP addresses and DNS servers. A class action lawsuit has been filed against Apple regarding the iCloud Private Relay flaw.
HalluSquatting Attack Exploits AI Hallucinations to Form Botnets
The "HalluSquatting" attack exploits AI hallucinations to inject malicious commands into coding assistants, potentially creating botnets. Researchers from Tel Aviv University and other institutions demonstrated that attackers can pre-register fictitious software names generated by AI. AI models' tendency to hallucinate and act on fake package names can expose systems to widespread malware deployment.
Microsoft Launches MAI-Cyber-1-Flash and Perception for AI Cybersecurity
Microsoft introduced MAI-Cyber-1-Flash, its first AI model specialized in cybersecurity, and Project Perception, an agentic security platform. These tools are designed to identify and remediate software vulnerabilities, with MAI-Cyber-1-Flash integrated into Microsoft's MDASH harness. The company claims the new offerings outperform competitor models on benchmarks and reduce operational costs.
Apple Fixes iCloud+ 'Hide My Email' Vulnerability After Public Scrutiny
Apple has patched a vulnerability in its Hide My Email feature that exposed real email addresses, following public and legal pressure. The issue persisted for over a year despite early warnings from security researcher Tyler Murphy. The flaw raised significant privacy concerns for users.
WordPress wp2shell Vulnerability Exploited; Urgent Patches Released
Two critical WordPress vulnerabilities, dubbed 'wp2shell' (CVE-2026-60137 and CVE-2026-63030), allow unauthenticated attackers to execute code. Affecting versions 6.9.0-6.9.4 and 7.0.0-7.0.1, fixes were released in versions 6.9.5 and 7.0.2. The vulnerabilities, actively exploited, prompted immediate patching, affecting over 500 million sites. WordPress initiated forced automatic updates, while Cloudflare deployed protective measures.
PamStealer Malware Targets macOS for Credential Theft Using Apple's PAM
Researchers have discovered PamStealer, a macOS malware that uses Apple's PAM interface to steal user credentials. This sophisticated malware employs a two-stage delivery system, disguising as the clipboard manager Maccy and utilising stealthy JavaScript for Automation. It highlights emerging threats in macOS security exploiting native Apple frameworks for credential theft.
CERT/CC Reports Hidden Backdoor in Tenda Router Firmware Allowing Admin Access
A vulnerability in various Tenda router firmware versions, CVE-2026-11405, allows unauthorized administrative access via an undocumented backdoor. This flaw poses significant security risks for users as attackers can bypass authentication to control devices remotely. Despite warnings, Tenda has not addressed the issue, leaving affected devices unpatched.
MetaMask Addresses Security Incident, Exits Affected Ethereum Validators
MetaMask is responding to an ongoing security incident affecting its infrastructure and has begun exiting affected validators in its non-custodial staking operations. This measure is precautionary, with no immediate threat identified to MetaMask wallets, but will incur foregone rewards and potential downtime penalties for the exited validators.
Anthropic Accuses Chinese AI Labs of Illegally Distilling Claude Models
Anthropic's head of threat intelligence, Jacob Klein, stated that foreign adversaries, particularly Chinese AI labs, are illegally accessing and distilling its Claude models to train competing AI technology and sell cheaper copycat versions. This practice, which Anthropic considers theft of intellectual property, is intensifying as the company approaches a potential IPO and has prompted concerns from the U.S. government regarding undermined American research.
Critical Vulnerabilities in Paperclip AI Platform Allow Remote Code Execution
Two critical security flaws in Paperclip, an open-source control plane for AI agents, could allow attackers to execute commands on network servers or developer computers. The most severe vulnerability, CVE-2026-41679, has a CVSS score of 10.0 and allows remote code execution without prior authentication, while another flaw (GHSA-x8hx-rhr2-9rf7) enables execution on developer machines. A third flaw exposed sensitive data through unauthenticated API routes.
RefluXFS Linux Kernel Flaw Allows Local Root Access on XFS Filesystems
A nine-year-old Linux kernel flaw, dubbed RefluXFS (CVE-2026-64600), allows unprivileged local users to overwrite root-owned files on XFS filesystems and gain persistent root access. This race condition vulnerability affects systems running Linux kernel v4.11 or later with XFS filesystems created with `reflink=1`, including default installations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux.
FBI and CISA Warn of Russian Phishing Attacks on Signal and WhatsApp Accounts
The FBI and CISA have issued an updated warning about Russian intelligence phishing campaigns targeting Signal and WhatsApp accounts. Attackers are using Signal Backup Recovery Keys to hijack accounts, and the U.S. is offering a $10 million reward for information on the group responsible. The campaign has compromised thousands of accounts of high-profile targets, including government officials and journalists.
Chrome 150 Update Addresses 27 Vulnerabilities, Enhances Security
Google released Chrome 150, patching 27 security vulnerabilities, including two critical use-after-free flaws in Ozone and Views. This update is part of a broader effort to improve browser security, with most flaws discovered internally by Google. Regular updates are essential due to frequent exploitation of memory safety vulnerabilities in browsers like Chrome.
Liquid Network loses $320 million in Bitcoin to purported white-hat hackers
The Liquid Network, a Bitcoin sidechain, had approximately $320 million (4,000 BTC) drained from its federation wallet by individuals claiming to be white-hat hackers. These individuals state they will return the funds once a vulnerability is fixed, prompting Liquid to suspend transactions and engage with them.
Android 17 Integrates Encrypted Client Hello for Enhanced Web Privacy
Android 17 introduces platform-wide support for Encrypted Client Hello (ECH), a new internet standard that encrypts website destination information. This prevents internet service providers (ISPs) and Wi-Fi operators from seeing specific domain names, thereby limiting user profiling and targeted advertising. This makes Android the first major mobile operating system to implement ECH at a platform level.
US Seizes Domains Linked to Chinese Hacking Group QTFY Targeting Government Agencies
The U.S. Department of Justice and FBI seized domains associated with the Chinese state-sponsored hacking group QTFY, disrupting its operations. This group allegedly used QTRouter and QScan malware to compromise U.S. critical infrastructure and government entities, including NASA, the Federal Reserve, and the U.S. Senate, since 2018.
New Android Car Head Unit Malware Uses Built-In Updaters for Ad Fraud and Botnets
A new malware family targeting Android-based vehicle head units from DoFun has been discovered, spreading through the devices' built-in update mechanisms. This malware aims to facilitate ad fraud and create a proxy botnet, marking the first documented case of malware on car head units with a device-specific infection chain.
Polish Energy Plant Cyberattack Used Novel Private APN Vector, Shutting Down Turbine
A previously undisclosed cyberattack in December 2025 targeted a small Polish combined heat and power (CHP) plant, causing a temporary shutdown of its steam turbine and water treatment system. The attack, which threatened heat supply to 50,000 residents, utilized a private Access Point Name (APN) as an attack vector, marking the first documented real-world use of this method to access industrial control systems.
Malicious `proc-macro1` crate leads to supply chain attack on `arrayref` and other Rust crates
The Rust Security Response Team identified and removed several malicious crates, including `proc-macro1`, which was used in a supply chain attack to compromise popular crates like `arrayref`, `internment`, and `append-only-vec`. This incident highlights the vulnerability of software supply chains to malicious package injections and necessitates developers to verify their dependencies.
Zimbra Releases Critical Security Patches for Classic Web Client
Zimbra has released version 10.1.19 to patch a critical stored XSS vulnerability in its Classic Web Client, which could allow attackers to execute malicious code via crafted emails. Additionally, Zimbra version 10.1.20 addresses multiple vulnerabilities, including command injection and mail forwarding bypass. The updates are crucial to maintain security for users of the Zimbra Collaboration Suite.
Google Launches Gemini 3.5 Flash Cyber for Efficient Vulnerability Management
Google DeepMind has launched Gemini 3.5 Flash Cyber, a cybersecurity AI model to detect and patch vulnerabilities efficiently. Initially available to governments and trusted partners via CodeMender, this model provides a cost-effective alternative to larger AI security models like Anthropic's Mythos. Its introduction is part of a broader release including Gemini 3.6 Flash and 3.5 Flash-Lite, demonstrating Google's continued commitment to cybersecurity innovation.
WhatsApp Launches Username Feature for Enhanced User Privacy
WhatsApp has initiated a rollout of a username feature, allowing users to interact via usernames instead of phone numbers. This move is targeted at enhancing privacy for the platform's three billion users. However, there are concerns about potential impersonation risks, especially in large user markets like India.
EU Mandates Google to Provide AI Rivals Access to Android and Search Data
The European Union requires Google to provide rival AI applications access to Android functionalities and to share anonymized search data under the Digital Markets Act. This aims to prevent Google from leveraging its OS dominance to limit competition. Google cited potential privacy and security concerns with these changes.
Critical KVM/x86 Vulnerability Allows VM Escape to Host on Intel and AMD
Januscape, a 16-year-old use-after-free vulnerability (CVE-2026-53359) in Linux's KVM hypervisor, allows guest VMs to execute arbitrary code on host systems, compromising host security in multi-tenant environments. Discovered by Hyunwoo Kim, this first-known architecture-independent exploit has been demonstrated in Google's kvmCTF. Cloud providers like Google Cloud and AWS may be particularly vulnerable, posing risks of data breaches.
19-Year-Old Extradited to U.S. for Role in Scattered Spider Hacks
Peter Stokes, a dual U.S. and Estonian citizen, was extradited from Finland to the U.S. to face charges related to hacking activities with Scattered Spider. Notable incidents include a 2025 cyberattack on a luxury jewelry retailer demanding an $8 million cryptocurrency ransom. The extradition underscores efforts to combat global cybercrime.
Opera Rolls Out 'Paste Protect' to Counter ClickFix Cyber Attacks
Opera has introduced 'Paste Protect', a new feature to block malicious clipboard commands copied from websites, aimed at mitigating ClickFix-style attacks. These attacks leverage social engineering tactics to mislead users into pasting harmful code into terminals. The new feature marks the first native defense against this rising cyber threat in a major web browser.
OFAC Sanctions Tren de Aragua for ATM Jackpotting; Threat Actors Use Blockchains for Malware
The U.S. Treasury's OFAC sanctioned 10 individuals involved in a Tren de Aragua ATM jackpotting scheme that stole over $40 million from U.S. financial institutions, with proceeds laundered via cryptocurrency. Separately, cyber threat actors are using public blockchains, a technique called EtherHiding or Blockchain Dead Drops, to conceal malware instructions, making takedowns difficult.
Critical RCE Flaw in Forminator WordPress Plugin Affects 600,000+ Sites
A critical security vulnerability (CVE-2026-15748) in the Forminator Forms WordPress plugin allows unauthenticated attackers to upload malicious PHP files, leading to remote code execution and site compromise. The flaw, rated 9.8 on CVSS, affects over 600,000 active installations and requires specific form configurations for exploitation, but has been patched in version 1.56.2.
New Spectre v2 Variant (BTR) Affects Intel, AMD, Arm CPUs, Leaks Sensitive Data
Researchers from VUSec and Scuola Superiore Sant'Anna have discovered a new Spectre v2 variant, named Branch Target Reuse (BTR), impacting Intel, AMD, and Arm CPUs. This vulnerability exploits how processors handle code that changes at runtime, specifically targeting just-in-time (JIT) compilers in web browsers, language runtimes, and operating system kernels. BTR can lead to sensitive data leaks, such as root password hashes from Intel Linux systems, and fixes for CVE-2026-64507 and CVE-2026-64508 have been merged into the Linux kernel.