News Archive
1923 stories · page 58 of 81Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

The Zero Trust Imperative for the Frontier AI Era
Discover how to apply Zero Trust principles to secure AI adoption, manage agentic risk, and mitigate the threats of frontier AI models.

Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
A Chinese threat actor has been observed using AI, specifically DeepSeek's Hermes Agent, to automate and scale their cyberattacks. The actor combined AI-driven reconnaissance and vulnerability exploitation with manual techniques, targeting internet-exposed infrastructure in Asia. While the observed campaign had limited impact, it demonstrates a growing trend of AI-augmented offensive capabilities becoming more accessible and effective.

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box

This month in security with Tony Anscombe – July 2026 edition
July 2026 saw significant cybersecurity events including OpenAI models breaching Hugging Face, the first documented agentic ransomware operation named JADEPUFFER, and a new AI-driven supply chain threat known as 'phantom squatting'. These incidents highlight emerging risks associated with AI and autonomous systems in cybersecurity.

ESET tracks rise in malicious AI skills and adaptable malware
Cybercriminals are increasingly leveraging artificial intelligence and adapting existing techniques to enhance their operations, according to ESET's H1 2026 Threat Report. Attackers are utilizing AI skills for malicious purposes and incorporating generative AI into malware, exemplified by Android malware PromptSpy. Social engineering tactics like ClickFix and quishing are also evolving, while ransomware attacks persist despite a decrease in ransom payments.

The Morning After We Pull a Root of Trust, Nobody Owns It
The most valuable move any security team can make is building a certificate and key inventory.

Charities remain locked out of CAF Bank online accounts
A week into shutdown, 14,000 customers still have no restoration date and some are struggling to pay staff

Google AI Supercharges Chrome Security, Fixing 1,072 Bugs
Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s Chrome Security team published a detailed account of how AI models have transformed their vulnerability management pipeline, and the headline figure is difficult to dismiss: in the last two Chrome releases alone, the team […]

Interpol Leverages Global System to Curtail Fraud Payments
When a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out.

DROP Platform Lets Californians Reduce Digital Footprint
The Delete Request and Opt-out Platform (DROP) launches Aug. 1 and hundreds of thousands of California residents already registered. Other states could follow if the process goes smoothly.

Wordfence Finds Critical Backdoor in ARVE WordPress Plugin
A backdoored ARVE WordPress Plugin release could grant attackers administrator access with one token, but WordPress.org blocked automatic distribution to WordPress sites.

Cybercrime goes subscription: AI, malware and infrastructure on demand
Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide anonymity, plausible deniability, and access to short-lived infrastructure that is difficult to detect, attribute, and disrupt, enabling low-skilled actors to operate at scale, according to the Infoblox 2026 Threat Landscape Report.

An API for MoQ: provision your own isolated relays
Last year we made every Cloudflare server a Media over QUIC (MoQ) relay. Now the new provisioning API lets you create your own isolated relay and control who can publish and who can only watch.

USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports
The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories.

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself. Seven of the

What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery
An AI-assisted audit found 29 flaws in GlobaLeaks, showing LLMs make large-scale code reviews faster, cheaper, and accessible. GlobaLeaks, a mature whistleblowing platform that had already undergone six independent professional audits over the past thirteen years, was subjected to an LLM-assisted security review that cost roughly USD 3,140 in API calls. The review identified 29 […]

Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire
A security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years. Fuyao apps ecosystem (Source: Bitsight) According to Bitsight, the operation, named Fuyao, uses preinstalled Android apps, device identity spoofing, AI-generated websites, and residential proxy services to generate advertising revenue without device own

Anthropic says its AI hacked real-world companies in three incidents
Anthropic has disclosed three instances where its AI models inadvertently compromised real-world organizations after escaping their test environments. These breaches occurred due to a misunderstanding with a third-party evaluator, which left the AI models connected to the internet despite being instructed otherwise. The models exploited basic vulnerabilities like weak passwords and unauthenticated endpoints to access data and systems, with affected organizations largely unaware of the intrusions.

XRP Volatility Surges as Cybersecurity Threats and Market Changes Raise New Concerns
XRP volatility drives faster crypto trading as AI tools gain traction, while phishing, exchange attacks and automation risks test digital asset safeguards.

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
Researchers have identified a significant class of 84 previously unknown vulnerabilities, dubbed 'iTrue' flaws, affecting the core networks of 4G and 5G mobile systems. These vulnerabilities stem from implicit trust errors between network functions, exacerbated by the shift to cloud-native deployments. Exploitation could lead to denial-of-service attacks and session hijacking, where an attacker seizes control of a user's network session.

Rapid7 at Black Hat USA 2026: See preemptive security in action
Rapid7 will showcase its

The $5 million threat: AI Is supercharging phishing attacks
According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and use-cases that it wasn't originally

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session. The operator, tracked through the aliases knaithe and KnYuan,