Latest stories — Page 97

Three npm Packages Squat PostCSS Names to Drop a Windows RAT
Typosquatted utilities pulled roughly a thousand combined downloads before researchers flagged them. The payload targets Windows developer machines, which is exactly where the credentials live.

White House Sets Hard Clock on Post-Quantum Migration for Federal Systems
An executive order mandates that high-value federal assets shift to post-quantum cryptography by 2030-2031. For identity infrastructure, that deadline is closer than it looks.

From Prevention to Resilience: Cybersecurity’s New Paradigm
Breaches are no longer a matter of if. The question is whether your organisation can keep functioning when one lands.

WhatsApp DMs Push VBScript Loaders That Deploy Legitimate RMM Tools
An active campaign abuses WhatsApp Desktop and Web to distribute scripted droppers that install commercial remote-management software across at least nine jurisdictions.

OpenAI Hands GPT-5.5-Cyber to 'Trusted Defenders' Under Daybreak
The model is pitched at deep codebase analysis and vuln patching. The interesting part is who gets access, and what shows up in the post-mortem when they don't.

Five Eyes to CSOs: AI Has Already Changed Your Threat Model — Act Now
A joint advisory from CISA and four allied agencies demands strategic action on AI-amplified threats. Experts say the advice is late, vague, and misses the real risk sitting inside your own network.

GitHub Tightens Security to Counter Pwn Request Attacks
actions/checkout v7 automatically blocks workflows that pull unreviewed fork code inside pull_request_target events, with backports arriving July 16.

PixelSmash Bug in FFmpeg Decoder Opens RCE Path on Jellyfin
A newly disclosed flaw in FFmpeg's PixletVideo decoder enables remote code execution against Jellyfin media servers under specific conditions, with denial-of-service exposure for Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio.

ShapedPlugin's Update Channel Hijacked, Pro Plugins Shipped with Backdoor
Attackers slipped malicious code into licensed Pro releases by compromising the vendor's own build pipeline, a clean supply-chain hit on WordPress installs.

AutoJack: A Drive-By to RCE Hiding in AutoGen Studio's Dev UI
A prototyping tool nobody treated as production becomes a one-click code execution chain. The fix is out. The pattern is not.

DifyTap: Four Unauthenticated Bugs in Dify Expose Cross-Tenant AI Conversations
Researchers at Zafran say a chain of flaws in the popular agentic workflow platform let attackers read other tenants' chats without logging in.

AWS Continuum Wants to Close the Gap Between AI-Generated Code and AI-Fixed Vulnerabilities
Amazon's new agentic security service promises continuous discovery, triage, and remediation. In practice, it's a bet that the same AI acceleration creating your backlog can also drain it.

Squidbleed: A 1997 FTP Parsing Bug Is Still Leaking Cleartext HTTP in Squid Proxies
A heap over-read disclosed by Calif.io exposes other users' requests, credentials and session tokens included, to anyone permitted to send traffic through the same proxy.

The 'Search-as-a-Service' Economy Built on Stolen Credentials
Underground brokers now sell targeted lookups against stolen credential corpora, lowering the bar for access brokers and intrusion crews alike.

OXLOADER Drops CastleStealer via Poisoned Google Ads, Researchers Say
Elastic Security Labs links the malvertising chain to a likely Russian-speaking, financially motivated operator.

Android's Identity Wall Goes Up Sept. 30, 2026 — Starting With Four Countries
Brazil, Indonesia, Singapore and Thailand are the first markets where unverified developers lose the right to install apps on certified Android devices, sideload or not.

Weekly Threat Roundup: EDR Killers, Browser Bugs, and an Android Trojan With Too Many Hands
Abused integrations, poisoned WordPress, and ransomware crews still gunning for endpoint sensors, familiar tradecraft, better packaged.

When Legacy Infrastructure Becomes the Soft Underbelly of Your AI Agent Stack
Governance frameworks like NIST AI RMF and the EU AI Act assume the pipes under the model are secure. They often aren't.

ShinyHunters Doesn't Need Malware. That's the Point.
The group's latest breaches are a reminder that stolen credentials and patience beat zero-days most days of the week.

Usbliter8: The iPhone Boot Exploit That Can't Be Patched
A proof-of-concept is now public for a hardware-level vulnerability that bypasses Apple's boot defenses on millions of iPhones, and there's no software fix coming.

CSIS Got a Warrant to Reach Into Canadian Routers and Kill Two Botnets
A Federal Court ruling unsealed June 15 is the first public use of CSIS threat-reduction warrant powers against infected infrastructure on Canadian soil.