Cybersecurity
Breaches, vulnerabilities, security companies
OpenAI pledges $1 billion for AI cyber defense program
OpenAI has pledged $1 billion in credits to help organizations defending critical U.S. infrastructure—including water utilities, electric grids, local governments, banks, and nonprofits—access its AI-powered cybersecurity tools, training, and support. The "Daybreak for Frontline Defenders" initiative aims to help these sectors strengthen their defenses as AI-driven cyberattacks become more advanced. OpenAI says it will expand the program to partner countries in the coming weeks.
More in Cybersecurity
SonicWall SMA1000 flaws exploited before disclosure
SonicWall has confirmed two critical vulnerabilities in its SMA1000 remote access appliances, identified as CVE-2026-83548 and CVE-2026-83549, are being exploited in the wild. These flaws can be chained to let attackers run code on affected systems without authentication. Patches are now available, and security agencies have flagged the issues as known exploited vulnerabilities. There is no information about the number of affected customers.
FBI Investigates Dark Web Sale of 153 Million Licenses
The FBI's New Orleans office has opened an investigation into a dark web service selling over 153 million U.S. and Canadian drivers license scans. Interviews and forum posts suggest these records, including those of senior U.S. officials, may stem from a breach at a Louisiana-based identity verification company. The service claims to have accumulated data for more than a year, exposing identities of millions across North America.
Breeze Comet targets Brazilian financial firms with fraud
A group known as Breeze Comet has targeted Brazilian banks, retailers, and e-commerce companies through sophisticated attacks since early 2024, according to Google Cloud and Mandiant. The organization uses malware and voice phishing to access internal payment systems and carry out fraudulent transfers. Google states that Breeze Comet is also using generative AI to develop new malware and may expand operations to parts of Latin America and Africa.
Google fixes Chrome zero-day exploited in the wild
Google released an update to Chrome addressing a critical security flaw, CVE-2026-85046, that has been actively exploited. The vulnerability, found in the V8 JavaScript engine, could let attackers run code by luring users to malicious web pages. The bug was reported by Salvatore Gulizia, who received a $1,000 bounty. Updates are available for Windows, macOS, and Linux. U.S. agencies are required to patch by September 18.
Phishing Campaign Poses as IT Staff on Microsoft Teams
A coordinated phishing operation dubbed 'Spring Ring' targeted more than 150 employees at at least 10 companies between January and April 2026, according to Palo Alto Networks' Unit 42. Attackers used external Microsoft Teams accounts to impersonate IT support, aiming to trick victims into installing remote monitoring or malicious software. Some attacks escalated to attempted NTLM relay attacks against company domain controllers. No successful compromises or losses were reported in the source.
Serbian activists hit by largest known spyware attack
Researchers have identified at least 14 Serbian civil society members, including student activists, as victims of advanced spyware earlier this year. Forensic analysis confirmed Pegasus spyware was used on at least one target, with a NoviSpy variant also detected. This is the largest documented wave of spyware attacks in Serbia, occurring around the March local elections. There is no evidence on who conducted the attacks, and the Serbian government has denied involvement.
Researcher Publishes CrowdStrike Falcon Privilege Escalation PoC
A security researcher identified as Chaotic Eclipse has released a proof-of-concept exploit for a previously unknown privilege escalation vulnerability in CrowdStrike's Falcon security software. The exploit, called FalconFlank, targets the product's handling of Microsoft Office macro remediation on current Windows 11 and Windows Server 2025 systems. CrowdStrike says it is investigating the claim and is advising customers to adjust certain policy settings while the review is ongoing.
Microsoft detects mass phishing using hidden Unicode tags
Microsoft identified a large phishing campaign that uses hidden Unicode tag characters to disguise key words in emails, enabling attackers to evade spam filters and machine learning-based detection. Microsoft tracked this method, known as ASCII smuggling, in more than 2.3 million messages over two days. While invisible to recipients, these tags break up high-risk words like “credit” or “loan,” allowing them to slip past automated screening systems.
Pegasus spyware infects Serbian student activist's iPhone
Citizen Lab and the SHARE Foundation have confirmed that Pegasus spyware, developed by NSO Group, infected the iPhone of a Serbian student protest movement member through a zero-click iMessage exploit. Forensic evidence showed signs of infection between December 2025 and January 2026. At least 14 members of Serbia's student movement, civil society, and opposition politicians have been targeted with advanced spyware, coinciding with the country's local elections.
Broadcom fixes critical flaws in VMware Workstation and Fusion
Broadcom has released updates for two security vulnerabilities in VMware Workstation and Fusion, including a critical bug that allows users with local administrative rights in a virtual machine to execute code on the host system. Both flaws require local admin access to exploit. Broadcom says there is no evidence these vulnerabilities have been used in real attacks. The company has released patches and says no workarounds are available.
G7 urges urgent shift to quantum-safe encryption
The G7 Cyber Security Working Group has called on governments and businesses to speed up efforts to switch their computer systems and encrypted data to quantum-resistant technology, warning that quantum computers could someday break current methods of encryption. In a new advisory, officials said the threat is already present, as attackers may be storing data now to decrypt later with quantum tools. They recommend starting migration now and prioritizing sensitive systems.
CrowdStrike and Nvidia unveil new AI cybersecurity platform
CrowdStrike, in partnership with Nvidia, announced a new AI-powered cybersecurity system called SafeMind at CrowdStrike’s annual Fal.Con event in Las Vegas. The platform uses Nvidia's Nemotron models, trained on CrowdStrike's threat data, to create a continuously evolving defense mechanism against automated cyber attacks. CrowdStrike also introduced new products for automated cyber workload management and advanced safety solutions. Both companies say this approach aims to close the gap with attackers using frontier AI tools.
Cloudflare launches AI-driven vulnerability detection service
Cloudflare has launched early access to a new service for customers called Vulnerability Discovery and Remediation, part of its Managed Defense offering. The invite-only tool uses OpenAI's Daybreak models to scan approved codebases for potential security issues, validate them, and suggest fixes. The service prioritizes vulnerabilities by analyzing production traffic and existing protections, aiming to help organizations address the most critical risks first.
METR discloses API key theft used for $600,000 in AI credits
METR, an AI safety research organization, reported that attackers stole an API key from its systems and used it over three weeks to consume AI model credits worth about $600,000. The organization says no sensitive information appears to have been accessed in this or a separate probing attack. The stolen credits were provided free by a model developer, representing potential rather than actual financial loss.
Attackers exploit critical bug in Sangoma Switchvox
Attackers are exploiting a critical vulnerability (CVE-2026-9586) in Sangoma Switchvox SMB Edition 8.3 that allows unauthenticated remote code execution without credentials. The flaw is actively being used to deploy reverse shells and access sensitive data on exposed systems. Sangoma released a patch on July 14. Security researchers report about 4,000 internet-facing systems are at risk, most in the U.S. Exploitation has been observed since August 30.
Red Hat urges automated response to rising AI-era cyber threats
Red Hat says security and IT teams face rising risks as attackers use AI to identify software vulnerabilities faster than manual defenses can respond. According to Red Hat, organizations need to accelerate software patching, automate responses to threats, and adopt multi-layered security strategies to contain and limit the impact of vulnerabilities. Red Hat highlights the importance of automation in maintaining effective cyber defenses as threat landscapes evolve rapidly.
Red Hat CEO says AI changes open source security
Red Hat CEO Matt Hicks said artificial intelligence is transforming open source security, increasing the need for transparent processes and faster patching. Red Hat introduced Lightwell as a tool to help organizations counter AI-enabled exploitation of vulnerabilities by accelerating the patching of open source software. Hicks emphasized the importance of these measures for enterprises facing AI-related threats and discussed evolving security strategies in the context of modern, AI-driven workloads.
Smashing Security discusses AI aiding iPhone theft
A recent Smashing Security podcast episode discussed how artificial intelligence is being used to help criminals steal Apple iPhones. The hosts explored current cybersecurity issues involving AI, including methods that reportedly assist thieves in bypassing device security. Details about the specific AI tools or techniques involved were not disclosed in the segment. The discussion signals concern about evolving digital threats targeting personal electronics.
North Korean hackers target South Korean firms with Linux backdoor
Researchers at Rapid7 have discovered a new Linux-based toolkit, dubbed the 'ted backdoor,' embedded within HAProxy servers at two South Korean companies in the automotive and media sectors. The toolkit lets attackers remotely control the servers, intercept and alter web traffic, steal credentials, and monitor systems unnoticed. Rapid7 attributes the campaign to North Korean state-backed groups with moderate confidence. The toolkit went undetected for months and does not exploit a HAProxy vulnerability.
Email spammers use AI attack trick to dodge filters
Email spammers have started using a tactic from AI attacks called ASCII smuggling to sneak messages past spam filters. Microsoft reports that starting in February, it saw daily detections go from 21,000 to 2.5 million within four days—a spike that lasted months. The trick? Hackers hide keywords inside special invisible characters, so filters miss them but computers still read them. The surge dropped sharply mid-May.
Zscaler surpasses quarterly forecasts but shares decline
Zscaler reported fiscal fourth-quarter results that beat Wall Street expectations on both earnings and revenue, with adjusted earnings at $1.19 per share and revenue reaching $898 million, both up 25% from a year ago. Despite this performance and issuing guidance above estimates, Zscaler shares dropped following the report. The company also reduced its net loss and recorded annual recurring revenue of $3.77 billion, partially boosted by the recent Red Canary acquisition.
BGP hijack used to deliver malicious Virtualizor updates
Attackers used a Border Gateway Protocol hijack to reroute traffic from Virtualizor's software update service and deliver malicious updates to some servers. At least one hosting provider reported five of its 34 Virtualizor hypervisors were compromised, resulting in root account access for attackers. The incident occurred between August 28 and August 30. Virtualizor urged all operators to review their systems, as no complete list of affected installations exists.
JFrog Artifactory flaw exploited for admin access after patch
Hackers are actively abusing a critical vulnerability in JFrog Artifactory, days after its public disclosure and patch. The flaw, CVE-2026-82329, lets attackers bypass authentication and gain administrator privileges under default configurations. Security researchers report attackers have already used the flaw to generate admin tokens and probe user data. No evidence of mass exploitation has been observed so far, but targeted attacks are ongoing.
Hackers exploit WordPress plugin flaws for remote code execution
Hackers are actively exploiting two major vulnerabilities in the Super Forms and Elementor Pro WordPress plugins, both of which allow attackers to upload malicious files that grant remote control over sites. Security firm Wordfence reports blocking over 440,000 such attempts. The Super Forms flaw and Elementor Pro flaw have both been patched, but sites running outdated versions remain at risk of takeover or data theft.
Chinese Cybercrime Group Used Brazilian Government Sites for Gambling Scam
A cybercrime group identified as Gambling Goblin has compromised Brazilian government and educational websites by installing malicious Apache modules. These modules redirect selected visitors to phishing pages that impersonate app stores and promote online gambling. Check Point Research connected the group to another Chinese-speaking cluster, Earth Berberoka, and said the campaign targets Brazil’s growing online betting market. Municipal government portals made up a large share of affected sites, alongside commercial organizations.
Russian man extradited to US for alleged freelance platform malware
Searzhudin Tamirlanovich Aktulaev, a Russian national, has been extradited to the US, where he faces federal charges for allegedly orchestrating a malware campaign targeting users of a major freelance platform in 2016 and 2017. Prosecutors say thousands of victims, about half in the US, were affected by malicious Excel attachments distributed through around 255 fake accounts. Aktulaev remains in US custody and has been formally indicted.
Thomson Reuters court system breach exposes sensitive records
Thomson Reuters has reported a data breach in its C-Track court management software, affecting courts in 11 US states, the US Virgin Islands, and Ontario, Canada. The breach exposed a range of sensitive court records, including possible personal data like Social Security numbers, medical information, and details from sealed or confidential cases. Investigations are ongoing, and no evidence of misuse has been found. Credit monitoring is being offered to those potentially affected.
International police disrupts Sality botnet after 20 years
Authorities from the US, Bulgaria, Hungary, and Romania, with help from Europol and cybersecurity firms, disrupted the peer-to-peer Sality botnet in a coordinated operation on August 31. The effort focused on 'sinkholing,' which cut off communications between infected computers and the botnet. Sality is reported to have run for over 20 years, at times controlling more than one million machines used for criminal activities.
Google donates ZKP cryptography library to Linux Foundation Europe
Google just handed off its open-source Longfellow cryptography tool to the Linux Foundation Europe. This library helps apps confirm details like your age without exposing other personal info—think proving you're over 18 without giving your birthdate. The move aims to make the tool a vetted standard worldwide, especially for digital IDs. Google says it'll keep developing the code, but now everyone can audit or use it.