Tag: emerging threats
4863 articles

Florida Sues OpenAI, Altman Over Alleged Safety Neglect
Florida's top lawman, Attorney General James Uthmeier, is taking a stand against OpenAI and its CEO Sam Altman, alleging the company prioritized profits over safety, putting users at risk. He's filed a civil suit seeking penalties and holding Altman personally accountable for the harm caused to Floridians.

CISA Warns of Active Exploits Targeting Android, Linux Flaws
A high-severity Android flaw, CVE-2025-48595, is being actively exploited in targeted attacks, allowing hackers to gain increased privileges without needing any user interaction. This critical vulnerability affects Android 14-16 and has prompted CISA to add it to its list of Known Exploited Vulnerabilities.

Bug Hunter Exposes Microsoft VS Code Flaw in Protest of Disclosure Handling
A bug hunter's frustrating experience with Microsoft's disclosure process sparked a protest, as Ammar Askar publicly exposed a VS Code flaw that could allow attackers to steal OAuth tokens and access GitHub repositories. Askar's proof-of-concept exploit highlights the vulnerability, which was previously mishandled by Microsoft's security response team.

Antarctic Treaty System Frays Amid Global Geopolitical Tensions
The Antarctic Treaty, meant to keep the continent out of global conflicts, is showing signs of fraying as geopolitical tensions rise, with recent talks in Hiroshima failing to yield consensus on crucial issues like protecting emperor penguins and regulating tourism. Despite a gathering of over 400 international delegates, key measures were left unadopted, leaving the treaty's future uncertain.

Banks' Annual Testing Model Leaves 345 Days of Unvalidated Exposure
Imagine having 345 days of potential vulnerability, with hackers free to exploit your defenses while you wait for your annual security test. That's the harsh reality of the traditional annual testing model, which leaves your business exposed for nearly 11 months of the year.

Trump's AI Order Falls Short on Safety, Security Oversight
As President Trump recently issued an executive order calling on AI companies to voluntarily share their most powerful models with the US government, concerns linger about the lack of concrete safety and security oversight. It's now up to Congress to step in and address the potential risks without stifling innovation or compromising free expression.

Konvu Wins Top Honors in Infosecurity Europe Cyber Startup Award
Konvu took top spot in the Infosecurity Europe Cyber Startup Award, impressing judges with its innovative solution and beating out four other contenders. CEO Lucas Masson was thrilled, saying it was a huge honor for their solution to resonate with the judges.

Malware Hidden in Hentai Games Exposes Users to Full System Compromise
Beware of hentai games that seem too good to be true - a new malware campaign has been discovered that hides in these games and can fully compromise your system. Hundreds of users, mainly in Russia, Brazil, Germany, and Vietnam, have already fallen victim to this threat, dubbed Argamal.

China Mounts High-Energy Laser on Tactical Vehicle
China just took its high-energy laser game to the next level by mounting a 20 kW laser turret on a Dongfeng Mengshi-like 4×4 tactical vehicle - a surprisingly roadworthy ride that looks like it could blend in with civilian traffic. This unusual combo raises eyebrows about its potential uses, beyond just military might.

Cyber Force Plan Unveils $10 Billion Budget Requirement
The Commission on US Cyber Force Generation is proposing a bold new vision: a separate Cyber Force military service that could require a whopping $10 billion to get off the ground. This game-changing plan outlines what it would take to create a distinct military branch focused on cyber operations.

GitHub Dev Attack Exploits OAuth Tokens
A single click can be all it takes for an attacker to swipe a GitHub token, giving them free rein to read and write to your private repos. Security researcher Ammar Askar warns that a clever exploit in GitHub.dev's web-based editor can turn a harmless link into a token-stealing threat.

Identity Visibility Platforms Shrink IAM Attack Surface
Nearly half of all identity activity in enterprises remains invisible to centralized identity and access management, creating a hidden risk that can leave organizations vulnerable to attacks. This "Identity Dark Matter" emerges as identities multiply across apps, teams, and systems, outpacing the ability of security teams to keep control.

Acer Rushes to Patch Zero-Days in Wave 7 Routers
Acer is urgently patching a critical vulnerability in its Wave 7 routers that allowed hackers to easily access sensitive login credentials, putting your entire network at risk. This flaw let attackers remotely tap into plaintext passwords stored in log archives, no authentication required.

UK Banks Gain Access to OpenAI's GPT-5.5 Cyber Model
UK banks are now part of an exclusive group gaining early access to OpenAI's cutting-edge GPT-5.5 Cyber model, a powerful AI tool designed to bolster their defenses against sophisticated cyber threats. This move comes as Anthropic's rival program, Project Glasswing, expands to 200 partners, leaving some UK banks to tap into OpenAI's innovative solution instead.

US Invites AI Developers to Voluntary Cybersecurity Review
The US government is taking a collaborative approach to AI cybersecurity, inviting developers to voluntarily review their most powerful models and give the government a 30-day heads-up before releasing them to trusted partners. This move aims to create accountability and ensure responsible AI development, with experts agreeing that real accountability is key to making voluntary security programs effective.

Unpatched Windows Search Flaw Exposes User Hashes
A newly discovered vulnerability in Windows' search feature can be exploited to steal user passwords, allowing hackers to gain access to sensitive information. By simply clicking on a malicious link, a user's login credentials can be exposed to attackers.

Law Enforcement Disrupts Nine Illegal Streaming Crime Groups
In a major crackdown on illegal streaming crime, authorities have dismantled nine organized crime groups and made 29 arrests in a seven-month operation that targeted the entire criminal ecosystem. The coordinated effort, involving 13 countries, identified 86 suspects and referred 59 cases to judicial authorities.

HTTP/2 Bomb Vulnerability Targets Major Web Servers with Remote DoS Exploit
A newly discovered HTTP/2 Bomb vulnerability can be exploited to launch a remote Denial of Service (DoS) attack on major web servers, taking advantage of a weakness in the default HTTP/2 configuration. This flaw cleverly combines a compression bomb and a Slowloris-style hold to target HPACK, HTTP/2's header-compression scheme.

Anthropic Widens AI Vulnerability Detection to 200 Organizations
Anthropic's Project Glasswing just got a major boost, expanding its AI-powered vulnerability detection to 200 organizations across 15 countries, helping to safeguard critical software in power, water, healthcare, and more. This significant growth builds on the program's success, with its advanced AI model, Claude Mythos Preview, already uncovering over 10,000 high-priority vulnerabilities.

CISOs Warned to Treat Cyber Threats as Geopolitical Statecraft
Don't make the rookie mistake of thinking cyber threats are just an IT issue - the truth is, they're a matter of statecraft that requires a much broader perspective. Bharat Thakrar warns that ignoring this reality is like being a turkey blissfully unaware of the farmer's plans.

AI-Driven Patching Pressures Redefine Vulnerability Response
The window between patch release and exploitation has dramatically shrunk to just six hours and 40 minutes, leaving organizations scrambling to keep up with increasingly rapid vulnerability response. This alarming trend is fueled by the growing power of large language models that can autonomously discover and even fix vulnerabilities.

Google Bolsters Android Defenses Against AI-Powered Scam Calls
Google's new fake call detection feature sends a silent signal to verify the caller, instantly warning you if a scammer tries to impersonate someone you know. If the signal is missing, your device double-checks with the caller's actual phone to keep you safe.

AI-Powered Cybercrime Tools Flood Dark Web Marketplaces
The dark web has seen a staggering 3,810% surge in AI-powered cybercrime tools, with posts skyrocketing from 38 in December to 1,486 in February, signaling a new wave of threats. This alarming trend has experts like Cynthia Kaiser, SVP of the Ransomware Research Center at Halcyon, warning that cyber threats have become the "national security challenge of our lifetime."

Malware Campaigns Target Gamers, 86K Infected by CountLoader
A shocking 86,000 gamers have fallen victim to CountLoader, a sneaky malware campaign that's been targeting players since January 2026, and the masterminds behind it are making it easy for others to join the malicious party with their free, user-friendly malware service.