News Archive
1920 stories · page 71 of 80Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

What Changes When Your Software Supply Chain Includes AI Writing Your Code?
The use of AI in software development introduces new challenges to supply chain security. Organizations must now consider the security implications of AI-generated code, in addition to traditional component analysis. This requires a reevaluation of existing security practices to adapt to AI's role in code creation.

Claude Code’s hidden tracker was an “experiment,” says Anthropic
A researcher discovered a hidden tracking mechanism within Anthropic's Claude Code client that encoded user traffic data based on system time zones. Anthropic has since removed the feature, stating it was an experimental measure to prevent account abuse and protect against model distillation, potentially linked to recent US government export controls.

Google Is Suing Chinese Scammers Who Are Using Gemini
Google has filed a lawsuit against a Chinese criminal organization known as Outsider Enterprise. The group is accused of providing "phishing-as-a-service" through Telegram and allegedly leveraging Google's Gemini platform for their fraudulent operations.

Threat landscape for industrial automation systems. Q1 2026
In the first quarter of 2026, the overall percentage of industrial control systems (ICS) computers experiencing malware infections continued its downward trend, reaching a three-year low. However, certain regions and industries, particularly biometric systems and manufacturing, saw increases in specific threat categories like spyware and internet-based threats. While ransomware and malicious documents saw significant decreases, malicious scripts, phishing pages, and denylisted internet resources remained prevalent.

UAT-7810 continues building ORB networks using new malware
The threat actor UAT-7810 is reportedly developing new custom malware. This malware is being utilized to establish ORB networks, indicating an evolution in their tools and ongoing malicious operations.

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems
A recently discovered 16-year-old vulnerability in the Linux kernel's KVM hypervisor, dubbed Januscape, allows attackers to break out of a virtual machine. This flaw affects both Intel and AMD systems and could enable unauthorized code execution on the underlying host system.

Microsoft to enable Windows settings backup by default for orgs
Microsoft is making its Windows settings backup and restore feature the default for business organizations. This update will automatically apply to devices managed by Microsoft Entra that are upgraded to Windows 11 version 26H2.

Scammers are using AI to sell impossible flowers
Scammers are leveraging AI image generation to create and market seeds for non-existent, fantastical plants. These listings, appearing on major e-commerce platforms like eBay, Amazon, and Etsy, depict flowers in impossible shapes and colors, enticing buyers with visually appealing AI-generated images. The scam aims to profit from the sale of these fake seeds, differing from previous brushing scams that used unsolicited seed packets to manipulate reviews.

Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security
Keyfactor, a provider of machine identity and cryptographic security solutions, has announced a funding round valued at over $1 billion. The investment will support the advancement of its platform, with a focus on addressing future security challenges from artificial intelligence and post-quantum cryptography.

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
Researchers have identified a new cyberattack campaign targeting academic institutions in North America. The attackers, believed to be linked to China, are exploiting vulnerabilities within the Roundcube webmail system used by physics and engineering departments.

Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities
A China-aligned espionage group has been observed targeting U.S. and Canadian universities, specifically in physics and engineering departments. The attackers exploited two vulnerabilities in the Roundcube email client (CVE-2024-42009 and CVE-2025-49113) to steal credentials and establish persistent access through webshells and backdoors. Proofpoint researchers identified the campaign, which appears to be ongoing, and noted that victims may not yet be aware of the compromise.

BeyondTrust warns of critical flaws in remote access software
BeyondTrust has alerted users to two critical vulnerabilities affecting its Remote Support and Privileged Remote Access software. These security weaknesses could potentially enable attackers to circumvent authentication mechanisms.

Microsoft testing new Cloud Rebuild Windows 11 recovery feature
Microsoft is piloting a new Cloud Rebuild feature for Windows 11 through its Insider Preview program. This functionality aims to simplify the recovery process for users by allowing them to rebuild their operating system from the cloud. The feature is currently available to testers in the Experimental channel.

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
CERT/CC has identified a hidden backdoor in multiple Tenda router firmware versions. This backdoor allows unauthorized administrative access to the devices' web interfaces.

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
BeyondTrust has issued patches for critical vulnerabilities in its Remote Support and Privileged Remote Access software. These flaws could permit unauthenticated attackers to gain unauthorized control over affected systems.

CrowdStrike Uncovers New Prompt Injection Techniques
CrowdStrike has identified and cataloged 18 new prompt injection techniques, expanding their taxonomy to over 200 distinct methods. These new techniques, including Trigger-Activated Rule Addition and Algorithmic Payload Decomposition, highlight the evolving sophistication of attacks against AI systems. The company emphasizes the need for enhanced AI threat modeling, red teaming, detection engineering, and runtime visibility to combat these emerging threats.

'BusySnake' Infostealer Slithers Into Critical Infrastructure Networks
A sophisticated information-stealing malware known as 'BusySnake' has been observed targeting critical infrastructure. Threat actors identified as 'Armored Likho' have successfully infiltrated government and electrical power organizations across Russia, Brazil, and Kazakhstan.

CitrixBleed-ing Again? NetScaler Vulnerability Under Attack
Attackers wasted little time targeting the latest memory disclosure flaw in Citrix's NetScaler products, after researchers published a proof-of-concept exploit (PoC).

Canadian spy agency reports hacking three criminal groups in 2025
Canada's Communications Security Establishment (CSE) conducted offensive cyber operations against three distinct criminal organizations in 2025. The targets included a ransomware-as-a-service operation, an extremist group with international ties, and drug trafficking networks.

Phishing poses as big-brand job interview to steal Google accounts
A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals. [...]

Fake IT support calls on Microsoft Teams push EtherRAT malware
Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. [...]

Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks
Securonix says the sophisticated framework abuses compromised websites, Blogspot, PowerShell, and fileless techniques to evade detection and deploy the PureLog information stealer. The post Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’

Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
An Iranian hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-control (C2) framework dubbed Cavern (aka Cav3rn) targeting Israeli organizations.

Vietnam arrests suspects behind HiAnime anime piracy service
Vietnamese authorities have arrested and are prosecuting seven suspects believed to have run HiAnime, the largest anime piracy streaming service before its shutdown in June. [...]