News Archive
1920 stories · page 75 of 80Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
Researchers have demonstrated a novel ransomware technique that operates entirely within a web browser, bypassing the need for native installations or exploits. By leveraging the File System Access API in Chrome, specifically on Android, malicious websites can trick users into granting access to sensitive photo directories. This method, inspired by AI-generated concepts, uses social engineering tactics like fake image-enhancement tools to prompt users for permissions, enabling the browser-based ransomware to potentially encrypt or modify files.

Martin Lee: Running through the Arctic (and the threat landscape)
Ever wonder how someone goes from studying human viruses to leading cybersecurity teams? In this Humans of Talos, we’re joined by Martin Lee, EMEA Lead, to talk about his journey into the industry.

The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign
Threat actors are distributing malicious installer archives that masquerade as popular freeware, such as OBS Studio and Bandicam. These installers contain a legitimate Microsoft binary alongside a rogue DLL that enables DLL sideloading. This process deploys the ScreenConnect remote access tool, which attackers use to maintain control over compromised systems and potentially execute further payloads like AsyncRAT.

ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoi

OpenClaw: risks for the users and how to mitigate them
OpenClaw, an AI agent ecosystem formerly known as Clawdbot and Moltbot, offers flexibility and task automation but introduces security risks to users and organizations. The system's 'skills' feature, which allows for natural language instructions and easy creation of extensions, can be exploited by attackers. The article aims to explore these security aspects, known vulnerabilities, and mitigation strategies.

Phishing Attack Targets MetaMask Users with Fake Credentials
This morning, an interesting phishing email hit my mailbox. It targets Metamask[1], a cryptocurrency wallet, available as a browser extension and a mobile app, that lets users store, send, and receive crypto money. It's pretty popular, so a

AI Hallucinations Create Phantom Domains for Supply Chain Attacks
Artificial intelligence models can generate domain names that do not actually exist, a phenomenon known as "phantom squatting." Attackers are leveraging this AI hallucination to create malicious domains that mimic legitimate ones, thereby posing a significant threat to software supply chains. This tactic allows them to potentially intercept or manipulate software development processes.

China-Linked Group Targets Southeast Asia Critical Systems
The group compromised at least 10 regional organizations, including two state-owned entities, and deployed a new backdoor.

Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool
A threat group linked to Iran, known as TAG-182, is actively distributing a surveillance tool called MarkiRAT. This malware is being spread through fake applications disguised as VPNs and download tools, primarily targeting Iranian citizens both within and outside the country. The operations appear to be conducted via social media platforms and are likely part of Iran's intensified cyber surveillance efforts.

Fake Bug Report Hijacks AI Coding Agents at Scale
"Agentjacking" is the latest demonstration of how easily attackers can exploit an AI agent's inability to differentiate between content and instructions.

Scammers race to cash in on Venezuelan earthquake disaster
Scammers wasted no time exploiting Venezuela's devastating earthquake, with researchers uncovering 212 newly-registered relief-themed domains in just five days. Read more in my article on the Hot for Security blog.

Attackers Seize Exposed AI Endpoints to Power Offensive Ops
Threat actors don't need any special authentication to reach a target endpoint — they just need to know where it is.

Why Identity Security Is Your Cyber Career Entry Point
In this "Heard it From a CISO" video, Silverfort CISO John Paul Cunningham explains that AI in cybersecurity workflows is creating opportunities rather than eliminating jobs — and there are more ways than ever to break into this essential f

Accelerating the quantum-safe timeline
Microsoft is accelerating its timeline for transitioning to post-quantum cryptography (PQC) due to advancements in quantum research and government guidance. The company aims to have its products and services ready for PQC by 2029, encouraging organizations to begin their transition sooner to mitigate risks and costs associated with this multi-year engineering effort.

Phishers Gain Persistence at EU, Asia Hospitality Orgs
Separate but similar campaigns described by Microsoft and Trend Micro use malicious zip files to spread malware via social engineering and obsfucation, including blockchain abuse.

What’s new in Microsoft Security: June 2026
Microsoft is enhancing its security offerings with a focus on AI and agent protection. New features include 'Codename MDASH,' an AI-powered system for discovering and remediating complex software vulnerabilities across environments. Additionally, Microsoft Defender now extends endpoint protection to local AI agents, detecting and blocking threats like prompt injection attempts targeting tools such as GitHub Copilot CLI and Claude Code.

Weekly Update 510: Live From Mallorca with Scott Helme
How's the view?! Back to business, it's now 8 years ago that Scott and I thought it would be a cool idea to build Why no HTTPS? We used the site to shame companies for not implementing their transport later security property, and to make it

AI-Generated Workflows Are a Silent Security Disaster
Teams are dealing with a truly dangerous problem — automation that works, but that no one understands.

The Realities of AI Video Surveillance
The Financial Times has a good article on how AI is changing the capabilities of video surveillance, with information from both Israel/Iran and Russia. I wrote about this sort of thing a few years ago, how AI enables mass spying in the way

USB drives carrying China-linked malware infected Japanese military networks for nearly a year
Read more in my article on the Hot for Security blog.

Apple Releases June Software Updates
Apple released updates for iOS/iPadOS, macOS, and Safari on Monday. There have been no updates for other Apple operating systems (visionOS, watchOS, tvOS). Usually, Apple updates all products at the same time.

NIST Enrichment Reductions Impact CVE Coverage, Accuracy
The National Institute of Standards and Technology (NIST) scaled back the number of CVEs it selects for in-depth analysis, but the move has produced mixed results, according to researchers.

'Djinn' Stealer Targets Cloud, AI Credentials
The infostealer was delivered via CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp, targeting credentials linking development and admin environments to wider enterprise systems.

Vulnerabilities Expose Private Data in Indian Government Systems
One critical vulnerability, among many discovered by a researcher, could have allowed anyone to walk in and take over a national government portal.