Latest stories — Page 78

Anthropic Pulls Claude Fable 5 and Mythos 5 After Federal Suspension Order
A late-Friday directive citing national security forced Anthropic to cut off its top-tier models — for everyone, not just foreign nationals.

GreatXML's BitLocker Bypass Claim Falls Short — For Now
A pseudonymous researcher dropped an alleged WinRE-based BitLocker exploit days after Patch Tuesday. A respected vulnerability analyst couldn't replicate it. The researcher is already hunting a fix.

AUR Supply-Chain Hit: 400+ Arch Packages Backdoored With Rust Stealer, Optional eBPF Rootkit
Build scripts in hijacked Arch User Repository packages dropped a credential harvester — and an eBPF rootkit when root was available.

Velvet Ant Lived Inside PAM and OpenSSH for Nearly Ten Years
A China-nexus crew skipped the endpoints defenders actually watch and backdoored the Linux login stack itself, where IR runbooks rarely reach.

Over 400 AUR Packages Backdoored With Rust-Based Credential Stealer
Attackers rewrote build scripts in Arch's community repo to drop a secret-harvesting binary — with an eBPF rootkit waiting if it gets root.

Google Takes Lighthouse PhaaS Operators to Court Over Gemini-Powered Smishing
Civil complaint targets a China-linked network behind the 'Outsider' phishing kit, alleging misuse of Gemini to scale text-message fraud against U.S. consumers.

Week in Brief: Google Security Cuts, AudiA6 Forum Axed, Coupang's $400M Fine
ICS exposure holds flat while the attack surface grows, IBM and AT&T face hack cover-up allegations, and Microsoft quietly drops an AI incident-response playbook.

US Surveillance Capabilities Temporarily Halted by Congressional Inaction
Congressional impasse leaves Section 702 in limbo, halting some warrantless surveillance.

Tchap Account Takeover Exposes 73,000 French Government Users
France's sovereign messaging platform wasn't broken — a user was. Social engineering got an attacker inside, and unencrypted public rooms did the rest.

Agentjacking: Poisoned Sentry Error Reports Hijack AI Coding Assistants
Researchers describe a prompt-injection class that turns developer error-tracking pipelines into a remote code execution path against AI coding agents.

AI Web Agents Have No Reliable Prompt Injection Defenses, Benchmark Finds
Researchers ran 3,168 adversarial tests against GPT-5 and Gemini-powered agents. The 'Robust Behavior' outcome — agent completes task, attacker gets nothing — never appeared.

MDR's AI Reckoning: When the Old Service Model Stops Keeping Up
Managed detection and response solved a staffing problem. It is not, by itself, an answer to adversaries who automate reconnaissance and intrusion at machine speed.

LangGraph Patches Three Bugs, Including an SQLi-to-RCE Chain in Self-Hosted Agents
The framework underpinning a wave of multi-agent AI deployments shipped fixes for a flaw chain that let attackers pivot from SQL injection to code execution on self-hosted nodes.

Sniper Dz Phishing-as-a-Service Goes Dark After INTERPOL Sweep Nets 201 Arrests
Operation Ramz dismantled a decade-old PhaaS storefront and pulled in its alleged operator, 'Guedz', across 13 MENA jurisdictions.

Cybersecurity Never Built a Health Model. AI Just Made That Inexcusable.
Thirty years of reactive security looked fine when threats moved at human speed. They don't anymore.

ShinyHunters Rode a PeopleSoft Zero-Day Into University Networks
A CVSS 9.8 RCE flaw in Oracle PeopleSoft gave UNC6240 a two-week head start before Oracle even confirmed the bug existed.

CISA Gives Agencies 72 Hours on Ivanti Sentry Bug Under New Emergency Directive
BOD 26-04 sets a sharper clock for actively exploited flaws. First target: an Ivanti Sentry vulnerability already in attackers' hands.

AudiA6 Crypto Laundromat Pulled Offline After Washing €336M for Ransomware Crews
Europol says the takedown severs a major cash-out pipeline tied to ransomware payouts and underground markets.

Harvest Now, Decrypt Later: Most Organizations Still Aren't Ready for the Quantum Cryptography Shift
NIST published its first three post-quantum standards in 2024. A year later, only 5% of security teams have a defined strategy. The clock is running whether they know it or not.

ShinyHunters Hit Universities Through PeopleSoft Zero-Day Before Oracle Patch
Mandiant ties a two-week extortion spree against Oracle PeopleSoft deployments to UNC6240, the cluster better known as ShinyHunters.

Langflow Path Traversal Flaw CVE-2026-5027 Hits CISA's Exploited List
An unauthenticated write-anywhere bug in the open-source AI builder is being abused in the wild, per VulnCheck telemetry, raising fresh questions for federal users bound by BOD 22-01 patch deadlines.