For you Ai Security Dev Cloud Hardware Startups Releases General

From The Hacker News · 40 stories

8 sources 8 reports 28d ago

Google releases Gemini 3.8 Flash AI model with improved benchmarks

Google has released Gemini 3.8 Flash, the third Flash update in three months, which shows improved performance in benchmarks compared to its predecessor. This model is designed for software engineering, autonomous agents, and complex enterprise workflows, and is available with an introductory pricing offer.

ai llm cybersecurity software development google
8 sources 8 reports 70d ago

Google Introduces Selfie Video for Account Sign-in and Recovery

Google has launched a new selfie video option for account sign-in and recovery, allowing users to regain access by recording a short video of their face. This feature provides an alternative verification method, particularly useful when traditional authentication methods are unavailable, by comparing a live video to a securely stored reference video.

security google authentication biometrics account recovery
8 sources 9 reports 77d ago

Teens sentenced to 5.5 years for £29M Transport for London cyber attack

Owen Flowers and Thalha Jubair were sentenced to 5.5 years for a 2024 cyberattack on TfL that caused £29 million in damages. The attack severely disrupted services and breached data of millions. Authorities cite this case as a major enforcement action against young cybercriminals.

security cybercrime hacking TfL law enforcement
7 sources 7 reports 10d ago

Google fined over €400m by Irish DPC for manipulating location data consent

Google received a fine exceeding €400 million from Ireland's Data Protection Commission (DPC) for manipulating users into agreeing to location data tracking. The DPC's six-year inquiry found Google lacked a valid legal basis for processing location data, which could reveal sensitive personal information.

security privacy regulation location-data google
7 sources 7 reports 37d ago

WhatsApp Enhances Account Security with Stronger 2FA and Multiple Passkeys

WhatsApp has updated its account security features, allowing users to set alphanumeric passwords with special characters for two-step verification, replacing the previous six-digit PINs. The platform also introduced support for adding multiple passkeys to a single account, useful for users across iOS and Android devices, and added more context for calls from unknown numbers on Android.

security whatsapp passkeys verification 2fa
7 sources 7 reports 38d ago

TikTok settles DOJ children's privacy lawsuit for $400 million

TikTok and its parent company, ByteDance, have agreed to pay $400 million to settle a lawsuit filed by the U.S. Department of Justice (DOJ) in 2024. The lawsuit alleged violations of the Children's Online Privacy Protection Act (COPPA) by collecting personal information from underage users without parental consent. The settlement includes new age-related controls and parental oversight measures.

security tiktok privacy settlement doj
7 sources 10 reports 40d ago

Model Context Protocol (MCP) 2026-07-28 Specification Released, Adopting Stateless Core

The Model Context Protocol (MCP) has released its 2026-07-28 specification, transitioning from a bidirectional stateful protocol to a request/response stateless core. This update, the largest revision since its launch, aims to improve reliability and scalability for MCP servers, addressing a highly requested developer feature. Major SDKs, including TypeScript, Python, and C#, have been updated to support the new specification.

ai protocol api sdk stateless
7 sources 9 reports 55d ago

Dependabot introduces default three-day cooldown for version updates

Dependabot now includes a default three-day cooldown before opening version update pull requests. This change aims to reduce the risk of merging compromised versions immediately after their release, enhancing supply chain security for developers.

dev dependabot github software security
7 sources 7 reports 80d ago

Cybersecurity Expert Sentenced for Role in BlackCat Ransomware Scams

Angelo Martino, a former ransomware negotiator, has been sentenced to 70 months for aiding the BlackCat ransomware gang. Collaborating with accomplices, he shared confidential negotiation details, causing victims to lose over $75 million. This highlights vulnerabilities within cybersecurity industries.

security ransomware cybersecurity law criminal justice
6 sources 10 reports 46d ago

New "Pass-ta-key" Attacks Bypass Passkey Protections in Google Password Manager

Researchers from Palo Alto Networks' Unit 42 have identified three "Pass-ta-key" attack methods that allow malware on compromised Windows machines to bypass passkey protections in Chrome's Google Password Manager. These attacks exploit how Chrome stores device keys and re-enrolls devices, enabling silent authentication, installation of attacker-controlled keys, or extraction of synced passkey private keys, demonstrating vulnerabilities in passkey implementations when an endpoint is already compromised.

security passkeys malware chrome google
6 sources 6 reports 50d ago

Zoom Patches Critical Vulnerability Allowing Device Takeover During Screen Sharing

Zoom has patched critical vulnerabilities in its video conferencing platform that allowed attackers to remotely execute code and take over devices during screen-sharing sessions. Discovered by A Security using fewer than 20 AI prompts, the flaw affected all supported operating systems and required no victim interaction, highlighting the increasing accessibility of advanced exploit development.

security zoom vulnerability ai patch
6 sources 7 reports 52d ago

WebKit Flaws Expose Real IP Addresses for iCloud Private Relay and Proxy Browser Users

Security researchers Talal Haj Bakry and Tommy Mysk discovered three WebKit features that bypass proxy configurations, leading to IP and DNS leaks. These vulnerabilities affect Apple's iCloud Private Relay and other proxy browsers on iOS and macOS, potentially exposing users' real IP addresses and DNS servers. A class action lawsuit has been filed against Apple regarding the iCloud Private Relay flaw.

security webkit privacy ios apple
6 sources 9 reports 57d ago

HalluSquatting Attack Exploits AI Hallucinations to Form Botnets

The "HalluSquatting" attack exploits AI hallucinations to inject malicious commands into coding assistants, potentially creating botnets. Researchers from Tel Aviv University and other institutions demonstrated that attackers can pre-register fictitious software names generated by AI. AI models' tendency to hallucinate and act on fake package names can expose systems to widespread malware deployment.

security ai halluSquatting malware cybersecurity
6 sources 6 reports 66d ago

Microsoft Launches MAI-Cyber-1-Flash and Perception for AI Cybersecurity

Microsoft introduced MAI-Cyber-1-Flash, its first AI model specialized in cybersecurity, and Project Perception, an agentic security platform. These tools are designed to identify and remediate software vulnerabilities, with MAI-Cyber-1-Flash integrated into Microsoft's MDASH harness. The company claims the new offerings outperform competitor models on benchmarks and reduce operational costs.

security cybersecurity ai microsoft vulnerability
6 sources 9 reports 72d ago

Apple Fixes iCloud+ 'Hide My Email' Vulnerability After Public Scrutiny

Apple has patched a vulnerability in its Hide My Email feature that exposed real email addresses, following public and legal pressure. The issue persisted for over a year despite early warnings from security researcher Tyler Murphy. The flaw raised significant privacy concerns for users.

security apple privacy email lawsuit
6 sources 9 reports 72d ago

WordPress wp2shell Vulnerability Exploited; Urgent Patches Released

Two critical WordPress vulnerabilities, dubbed 'wp2shell' (CVE-2026-60137 and CVE-2026-63030), allow unauthenticated attackers to execute code. Affecting versions 6.9.0-6.9.4 and 7.0.0-7.0.1, fixes were released in versions 6.9.5 and 7.0.2. The vulnerabilities, actively exploited, prompted immediate patching, affecting over 500 million sites. WordPress initiated forced automatic updates, while Cloudflare deployed protective measures.

security wordpress vulnerability rce cloudflare
6 sources 9 reports 77d ago

PamStealer Malware Targets macOS for Credential Theft Using Apple's PAM

Researchers have discovered PamStealer, a macOS malware that uses Apple's PAM interface to steal user credentials. This sophisticated malware employs a two-stage delivery system, disguising as the clipboard manager Maccy and utilising stealthy JavaScript for Automation. It highlights emerging threats in macOS security exploiting native Apple frameworks for credential theft.

security macos malware credential-theft threats
6 sources 6 reports 84d ago

CERT/CC Reports Hidden Backdoor in Tenda Router Firmware Allowing Admin Access

A vulnerability in various Tenda router firmware versions, CVE-2026-11405, allows unauthorized administrative access via an undocumented backdoor. This flaw poses significant security risks for users as attackers can bypass authentication to control devices remotely. Despite warnings, Tenda has not addressed the issue, leaving affected devices unpatched.

security tenda router vulnerability firmware
2 sources 2 reports 1d ago Updated 1d ago

MetaMask Addresses Security Incident, Exits Affected Ethereum Validators

MetaMask is responding to an ongoing security incident affecting its infrastructure and has begun exiting affected validators in its non-custodial staking operations. This measure is precautionary, with no immediate threat identified to MetaMask wallets, but will incur foregone rewards and potential downtime penalties for the exited validators.

security metamask ethereum staking cryptocurrency
5 sources 9 reports 3d ago

Anthropic Accuses Chinese AI Labs of Illegally Distilling Claude Models

Anthropic's head of threat intelligence, Jacob Klein, stated that foreign adversaries, particularly Chinese AI labs, are illegally accessing and distilling its Claude models to train competing AI technology and sell cheaper copycat versions. This practice, which Anthropic considers theft of intellectual property, is intensifying as the company approaches a potential IPO and has prompted concerns from the U.S. government regarding undermined American research.

ai intellectual property china security model-distillation
2 sources 2 reports 57d ago

Critical Vulnerabilities in Paperclip AI Platform Allow Remote Code Execution

Two critical security flaws in Paperclip, an open-source control plane for AI agents, could allow attackers to execute commands on network servers or developer computers. The most severe vulnerability, CVE-2026-41679, has a CVSS score of 10.0 and allows remote code execution without prior authentication, while another flaw (GHSA-x8hx-rhr2-9rf7) enables execution on developer machines. A third flaw exposed sensitive data through unauthenticated API routes.

security ai vulnerability open-source cve
2 sources 2 reports 71d ago

RefluXFS Linux Kernel Flaw Allows Local Root Access on XFS Filesystems

A nine-year-old Linux kernel flaw, dubbed RefluXFS (CVE-2026-64600), allows unprivileged local users to overwrite root-owned files on XFS filesystems and gain persistent root access. This race condition vulnerability affects systems running Linux kernel v4.11 or later with XFS filesystems created with `reflink=1`, including default installations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux.

security linux vulnerability xfs
2 sources 2 reports 93d ago

FBI and CISA Warn of Russian Phishing Attacks on Signal and WhatsApp Accounts

The FBI and CISA have issued an updated warning about Russian intelligence phishing campaigns targeting Signal and WhatsApp accounts. Attackers are using Signal Backup Recovery Keys to hijack accounts, and the U.S. is offering a $10 million reward for information on the group responsible. The campaign has compromised thousands of accounts of high-profile targets, including government officials and journalists.

security russia phishing signal hacking
3 sources 18 reports 2d ago

Chrome 150 Update Addresses 27 Vulnerabilities, Enhances Security

Google released Chrome 150, patching 27 security vulnerabilities, including two critical use-after-free flaws in Ozone and Views. This update is part of a broader effort to improve browser security, with most flaws discovered internally by Google. Regular updates are essential due to frequent exploitation of memory safety vulnerabilities in browsers like Chrome.

security chrome vulnerabilities google browser
5 sources 5 reports 23d ago

Liquid Network loses $320 million in Bitcoin to purported white-hat hackers

The Liquid Network, a Bitcoin sidechain, had approximately $320 million (4,000 BTC) drained from its federation wallet by individuals claiming to be white-hat hackers. These individuals state they will return the funds once a vulnerability is fixed, prompting Liquid to suspend transactions and engage with them.

security bitcoin blockchain cryptocurrency blockstream
5 sources 5 reports 31d ago

Android 17 Integrates Encrypted Client Hello for Enhanced Web Privacy

Android 17 introduces platform-wide support for Encrypted Client Hello (ECH), a new internet standard that encrypts website destination information. This prevents internet service providers (ISPs) and Wi-Fi operators from seeing specific domain names, thereby limiting user profiling and targeted advertising. This makes Android the first major mobile operating system to implement ECH at a platform level.

security android privacy encryption networking
5 sources 6 reports 32d ago

US Seizes Domains Linked to Chinese Hacking Group QTFY Targeting Government Agencies

The U.S. Department of Justice and FBI seized domains associated with the Chinese state-sponsored hacking group QTFY, disrupting its operations. This group allegedly used QTRouter and QScan malware to compromise U.S. critical infrastructure and government entities, including NASA, the Federal Reserve, and the U.S. Senate, since 2018.

security cybersecurity china government malware
5 sources 5 reports 38d ago

New Android Car Head Unit Malware Uses Built-In Updaters for Ad Fraud and Botnets

A new malware family targeting Android-based vehicle head units from DoFun has been discovered, spreading through the devices' built-in update mechanisms. This malware aims to facilitate ad fraud and create a proxy botnet, marking the first documented case of malware on car head units with a device-specific infection chain.

security android malware automotive botnet
5 sources 7 reports 38d ago

Polish Energy Plant Cyberattack Used Novel Private APN Vector, Shutting Down Turbine

A previously undisclosed cyberattack in December 2025 targeted a small Polish combined heat and power (CHP) plant, causing a temporary shutdown of its steam turbine and water treatment system. The attack, which threatened heat supply to 50,000 residents, utilized a private Access Point Name (APN) as an attack vector, marking the first documented real-world use of this method to access industrial control systems.

security critical infrastructure cyberattack poland cybersecurity
5 sources 5 reports 42d ago

Malicious `proc-macro1` crate leads to supply chain attack on `arrayref` and other Rust crates

The Rust Security Response Team identified and removed several malicious crates, including `proc-macro1`, which was used in a supply chain attack to compromise popular crates like `arrayref`, `internment`, and `append-only-vec`. This incident highlights the vulnerability of software supply chains to malicious package injections and necessitates developers to verify their dependencies.

security rust supply chain attack crate supply chain
5 sources 12 reports 62d ago

Zimbra Releases Critical Security Patches for Classic Web Client

Zimbra has released version 10.1.19 to patch a critical stored XSS vulnerability in its Classic Web Client, which could allow attackers to execute malicious code via crafted emails. Additionally, Zimbra version 10.1.20 addresses multiple vulnerabilities, including command injection and mail forwarding bypass. The updates are crucial to maintain security for users of the Zimbra Collaboration Suite.

security zimbra xss vulnerability patches
5 sources 5 reports 72d ago

Google Launches Gemini 3.5 Flash Cyber for Efficient Vulnerability Management

Google DeepMind has launched Gemini 3.5 Flash Cyber, a cybersecurity AI model to detect and patch vulnerabilities efficiently. Initially available to governments and trusted partners via CodeMender, this model provides a cost-effective alternative to larger AI security models like Anthropic's Mythos. Its introduction is part of a broader release including Gemini 3.6 Flash and 3.5 Flash-Lite, demonstrating Google's continued commitment to cybersecurity innovation.

ai google cybersecurity vulnerabilities security
5 sources 6 reports 76d ago

WhatsApp Launches Username Feature for Enhanced User Privacy

WhatsApp has initiated a rollout of a username feature, allowing users to interact via usernames instead of phone numbers. This move is targeted at enhancing privacy for the platform's three billion users. However, there are concerns about potential impersonation risks, especially in large user markets like India.

releases whatsapp privacy usernames messaging
5 sources 5 reports 77d ago

EU Mandates Google to Provide AI Rivals Access to Android and Search Data

The European Union requires Google to provide rival AI applications access to Android functionalities and to share anonymized search data under the Digital Markets Act. This aims to prevent Google from leveraging its OS dominance to limit competition. Google cited potential privacy and security concerns with these changes.

ai google eu android privacy
5 sources 5 reports 85d ago

Critical KVM/x86 Vulnerability Allows VM Escape to Host on Intel and AMD

Januscape, a 16-year-old use-after-free vulnerability (CVE-2026-53359) in Linux's KVM hypervisor, allows guest VMs to execute arbitrary code on host systems, compromising host security in multi-tenant environments. Discovered by Hyunwoo Kim, this first-known architecture-independent exploit has been demonstrated in Google's kvmCTF. Cloud providers like Google Cloud and AWS may be particularly vulnerable, posing risks of data breaches.

security kvm vulnerabilities cloud linux
5 sources 6 reports 86d ago

19-Year-Old Extradited to U.S. for Role in Scattered Spider Hacks

Peter Stokes, a dual U.S. and Estonian citizen, was extradited from Finland to the U.S. to face charges related to hacking activities with Scattered Spider. Notable incidents include a 2025 cyberattack on a luxury jewelry retailer demanding an $8 million cryptocurrency ransom. The extradition underscores efforts to combat global cybercrime.

security cybercrime hacking law enforcement scattered spider
5 sources 5 reports 88d ago

Opera Rolls Out 'Paste Protect' to Counter ClickFix Cyber Attacks

Opera has introduced 'Paste Protect', a new feature to block malicious clipboard commands copied from websites, aimed at mitigating ClickFix-style attacks. These attacks leverage social engineering tactics to mislead users into pasting harmful code into terminals. The new feature marks the first native defense against this rising cyber threat in a major web browser.

security browser malware opera cybersecurity
1 source 1 report 18h ago Updated 18h ago

OFAC Sanctions Tren de Aragua for ATM Jackpotting; Threat Actors Use Blockchains for Malware

The U.S. Treasury's OFAC sanctioned 10 individuals involved in a Tren de Aragua ATM jackpotting scheme that stole over $40 million from U.S. financial institutions, with proceeds laundered via cryptocurrency. Separately, cyber threat actors are using public blockchains, a technique called EtherHiding or Blockchain Dead Drops, to conceal malware instructions, making takedowns difficult.

security cybersecurity financial crime blockchain malware
4 sources 19 reports 6d ago

Critical RCE Flaw in Forminator WordPress Plugin Affects 600,000+ Sites

A critical security vulnerability (CVE-2026-15748) in the Forminator Forms WordPress plugin allows unauthenticated attackers to upload malicious PHP files, leading to remote code execution and site compromise. The flaw, rated 9.8 on CVSS, affects over 600,000 active installations and requires specific form configurations for exploitation, but has been patched in version 1.56.2.

security wordpress vulnerability rce elementor
3 sources 3 reports 2d ago

New Spectre v2 Variant (BTR) Affects Intel, AMD, Arm CPUs, Leaks Sensitive Data

Researchers from VUSec and Scuola Superiore Sant'Anna have discovered a new Spectre v2 variant, named Branch Target Reuse (BTR), impacting Intel, AMD, and Arm CPUs. This vulnerability exploits how processors handle code that changes at runtime, specifically targeting just-in-time (JIT) compilers in web browsers, language runtimes, and operating system kernels. BTR can lead to sensitive data leaks, such as root password hashes from Intel Linux systems, and fixes for CVE-2026-64507 and CVE-2026-64508 have been merged into the Linux kernel.

security spectre cpu vulnerability linux
More stories →