News Archive
1920 stories · page 67 of 80Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

Chrome 150 Update Fixes 27 Security Flaws
Google has released an update for its Chrome browser, version 150, addressing a total of 27 vulnerabilities. The patch includes fixes for 13 use-after-free bugs, two of which were identified as critical severity.

8Layers Secures $2.9 Million for Identity Security Platform
Spanish startup 8Layers has successfully raised $2.9 million in an extended pre-seed funding round. This capital infusion comes just two months after the company launched its digital identity protection platform, signaling strong investor confidence in its market potential.

AI Coding Agents Can Be Tricked Into Executing Malicious Code
Researchers have demonstrated a vulnerability in AI coding agents, such as Anthropic's Claude Code and OpenAI's Codex, where they can be manipulated into executing malicious code instead of identifying security flaws. This 'Friendly Fire' attack exploits the autonomous mode of these agents, potentially leading them to run harmful code on the user's system.

Tenda Firmware Vulnerability Allows Unauthenticated Admin Access
A critical backdoor vulnerability has been discovered in Tenda device firmware, identified as CVE-2026-11405. This flaw enables unauthenticated attackers to gain administrative control over affected devices by accessing their web management interface. The vulnerability remains unpatched, posing a significant risk to users.

Fake 7-Zip Installers Hijack Devices for Proxy Network
A threat group known as Lurking Lizard has established a large-scale residential proxy network using over 230 fake domains. This operation, active since at least August 2022, leverages compromised devices, including those infected via fake 7-Zip installers, to route traffic for malicious purposes.

Honeypot Researcher Finds Bot's Plea for Help
A honeypot researcher discovered a peculiar scanning bot that uses a URL path as a plea for help, seemingly from someone in Belarus. The bot, which scans for open ports and sends basic HTTP requests, appears to be intentionally limited and not malicious. The author claims the bot's purpose is to draw attention to their situation.

When AI-Accelerated Discovery Outruns Patching, Exploitability Proof Decides What Gets Fixed First
The increasing speed at which AI models discover software vulnerabilities, particularly in open-source components, is outpacing the ability of organizations to patch them. This necessitates a shift in risk prioritization, focusing on exploitability rather than just severity scores. An industry coalition called Athena aims to accelerate the defense of open-source software, while tools like those from Qualys help organizations identify which discovered vulnerabilities are actively being exploited and require immediate attention.

Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation
Ubiquiti has released security updates to address seven vulnerabilities in its UniFi OS, including several critical flaws. One critical vulnerability, CVE-2026-50746, allows for command injection in the UniFi Connect Application, impacting systems that manage building infrastructure like smart lighting and EV chargers. Other patched issues include SQL injection, improper input validation, and SSRF vulnerabilities across various UniFi applications, potentially leading to privilege escalation.

Greek victims sue Intellexa over Predator spyware
Victims in Greece have filed a lawsuit against Intellexa, the company behind the Predator spyware. The spyware's use was revealed in 2022, with evidence found on numerous phones. This revelation previously resulted in the resignations of the head of Greece's intelligence service and the prime minister's chief of staff.

Cash App Owner to Pay $45 Million Over Lax Security Claims
Block, Inc., the owner of Cash App, has agreed to pay $45 million to settle allegations that it misrepresented the security protections offered to its users. State attorneys general stated that the company incorrectly claimed Cash App provided the same level of security as traditional banks.

Accenture Confirms Security Incident After Hacker Claims 35GB Source-Code Theft
Accenture has acknowledged a security incident after a threat actor advertised what they claim is stolen internal data. The attacker, using the alias "888", says they took more than 35GB of source code and cloud credentials from the consulting giant and are offering it for sale. Accenture says it has addressed the source of the issue and that its operations were not disrupted.

FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices
A widespread issue dubbed FortiBleed has been reported, involving the large-scale exposure and abuse of credentials targeting internet-facing FortiGate devices. This problem stems from credential reuse and brute-force attacks, rather than a new vulnerability. The risk is particularly high for devices lacking multi-factor authentication or those with previously compromised credentials.

AI Coding Tools Trigger Endpoint Security Rules
Researchers have observed that AI coding assistants are inadvertently triggering endpoint security software designed to detect malicious activity. These tools, including Cursor, Claude Code, and OpenAI Codex, are setting off behavioral detection rules due to actions like credential harvesting and system reconnaissance, which mimic attacker behavior. The AI agents themselves are not malicious, but their operations resemble those of human intruders.

Protecting Microsoft at AI speed: How SFI proactively hardens our cloud
Microsoft has developed an internal AI system to proactively evaluate and strengthen its cloud infrastructure. This system operates at AI speed to match the scale and complexity of Microsoft's hyper-scale environments, ensuring security controls are robust and effective. While not a customer-facing product, the insights gained will inform future product improvements.

Accenture Confirms Data Breach Following Source Code Theft Claim
Accenture has confirmed a data breach occurred, which involved the alleged theft of source code. The company stated that the incident has been contained and remediated, with no impact on its operations or service delivery.

China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors
A China-linked advanced persistent threat (APT) group, identified as LapDogs, has reportedly enhanced its malicious toolkit. Security researchers have observed the deployment of three new backdoors: LongLeash, DogLeash, and JarLeash, which are designed to compromise small office/home office (SOHO) routers.

RedWing Android Spyware Sold as a Service on Telegram
A new Android spyware called RedWing is being offered as a service on Telegram, allowing less sophisticated attackers to compromise phones and steal banking information. Researchers have identified it as a polished malware-as-a-service operation with extensive documentation and a subscription model, potentially linked to Russian threat actors. RedWing employs fake login overlays, SMS interception, call forwarding, and even screen control to harvest credentials and conduct further malicious activities.

HalluSquatting Attack Exploits AI Coding Assistants to Deliver Malware
A new attack technique called HalluSquatting leverages the tendency of AI coding assistants to invent non-existent project names. Attackers can register these fabricated names and trick the AI into recommending them, thereby leading users to unknowingly install malicious software like botnet malware.

Operationalizing Day Minus Seven: The Cloud-Native ROC
The article introduces the concept of a Risk Operations Center (ROC) as a necessary evolution for cybersecurity teams facing AI-driven threats. It argues that traditional risk management models are insufficient due to the speed at which AI can discover and exploit vulnerabilities, especially in cloud environments. A ROC, powered by platforms like Qualys Enterprise TruRisk Management (ETM), aims to unify disparate security findings, hyper-prioritize risks based on exploitability and business impact, and enable autonomous remediation to keep pace with attackers.

China-Linked APT Expands Proxy Network With New Malware
A China-linked advanced persistent threat group, identified as UAT-7810, is reportedly expanding its network of proxy servers. This expansion is being facilitated by the deployment of new malware, according to research from Cisco Talos.

Armored Likho Hits Government, Energy Sectors With BusySnake Stealer
Cybersecurity researchers have identified a new threat actor, dubbed Armored Likho, targeting government and energy sectors in Russia, Kazakhstan, and Brazil with a sophisticated phishing campaign. The operation utilizes a custom-built Python infostealer named BusySnake, designed to steal credentials, sensitive documents, and other high-value data. The attackers employ AI-generated payloads to obscure their activities and maintain persistence through various methods, including reverse SSH tunneling.

Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)
CISA has issued a warning regarding a critical vulnerability (CVE-2026-55255) in the Langflow AI framework, which is being actively exploited by attackers. The flaw allows authenticated users to execute arbitrary flows belonging to other users, potentially leading to the theft of sensitive credentials and data exposure, especially in multi-tenant environments. US federal agencies have been mandated to patch this vulnerability by July 10th.

3 Ways AI Powers Service Desk Attacks and How to Prevent Them
Artificial intelligence is increasingly being used by attackers to enhance service desk attacks, particularly during employee onboarding. AI tools can create more convincing impersonations, accelerate reconnaissance for personalized attacks, and scale malicious campaigns. To counter these threats, organizations need to implement stronger identity verification methods, such as secure password delivery, biometric liveness detection, and multi-factor authentication before sensitive actions are approved.

Bug in top AI coding agents shows that Unix-era security headaches never really die
A vulnerability dubbed "GhostApproval" has been discovered in at least six popular AI coding assistants, allowing them to access files outside their designated workspaces and potentially execute remote code. The flaw exploits symbolic links, a long-standing security issue, to trick agents into writing malicious content, such as SSH keys, to sensitive system files. While some vendors have patched the issue and assigned CVEs, others have downplayed the risk or are yet to release fixes.