Tech & Science

56

AI Vulnerability Chaining Overwhelms Open Source Disclosure Channels

Tech & ScienceAI·1 source·

GENEVA (June 8, 2026) — The global open source software ecosystem is facing a critical bottleneck as AI-driven vulnerability chaining outpaces existing coordinated disclosure systems, prompting indust...

56

China-Nexus Group VerdantBamboo Deploys New Malware on Linux Systems

Tech & ScienceAI·1 source·

BEIJING — A China-nexus cyber espionage group known as VerdantBamboo has deployed a new variant of the BRICKSTORM backdoor alongside two other malware families on Linux appliances, including Synology ...

56

Hackers Hijack Over 20,000 Instagram Accounts via Meta AI Support Flaw

Tech & ScienceAI·1 source·

UNAUTHORIZED THIRD PARTIES HAVE HIJACKED MORE THAN 20,000 INSTAGRAM ACCOUNTS AFTER EXPLOITING A VULNERABILITY IN META'S AI-POWERED HIGH TOUCH SUPPORT SYSTEM. THE ATTACKERS RESET PASSWORDS WITHOUT REQU...

56

Microsoft Launches AI-Integrated 'Intelligent Terminal' for Developers

Tech & ScienceAI·1 source·

REDMOND, Wash. (AP) — Microsoft has released an open-source fork of its Windows Terminal application, introducing a new AI-powered tool designed to assist developers directly within their command-line...

56

OpenAI Introduces 'Lockdown Mode' for ChatGPT to Curb Data Exfiltration Risks

Tech & ScienceAI·1 source·

SAN FRANCISCO (June 6, 2026) — OpenAI has deployed a new security feature for ChatGPT, dubbed "Lockdown Mode," designed to restrict the artificial intelligence model's ability to make outbound network...

56

Researcher reveals Bright Data iOS SDK turns consumer devices into AI web-scraping nodes

Tech & ScienceAI·1 source·

LONDON (June 6, 2026) — A security researcher has reverse-engineered software embedded in consumer applications by Bright Data, revealing a mechanism that converts smart TVs and mobile phones into exi...

56

Autonomous AI Agent Uncovers 21 Zero-Day Flaws in FFmpeg as Chrome Sets Patch Record

Tech & ScienceAI·1 source·

SAN FRANCISCO — An autonomous artificial intelligence agent developed by security startup depthfirst identified 21 previously unknown vulnerabilities in the widely used FFmpeg multimedia framework, ma...

56

Toshiba and Muji Websites Compromised by Malicious CDN Scripts

Tech & ScienceAI·1 source·

TOKYO (AP) — Japanese electronics giant Toshiba and lifestyle retailer Muji faced a cybersecurity breach on Wednesday after malicious scripts embedded in a third-party content delivery network began g...

56

CISA Warns of Active Exploitation of SolarWinds Serv-U Flaw

Tech & ScienceAI·1 source·

WASHINGTON — Cybersecurity officials issued an urgent alert Thursday warning that hackers are actively exploiting a recently patched high-severity vulnerability in SolarWinds Serv-U software to crash ...

56

Chinese Espionage Group Deploys New Malware in U.S. Microsoft 365 Campaign

Tech & ScienceAI·1 source·

WASHINGTON — A Chinese state-sponsored espionage group known as UNC5221 has deployed new malware variants to maintain persistent access to compromised Microsoft 365 environments and other networks acr...

56

Asin Spyware Campaign Targets Arabic-Speaking Journalists via Fake News Sites

Tech & ScienceAI·1 source·

BEIRUT (AP) — A sophisticated Android spyware campaign known as Asin has been identified targeting journalists and open-source intelligence researchers across Arabic-speaking regions. The operation, w...

56

Most Security Operations Centers Report Limited Value from AI Adoption

Tech & ScienceAI·1 source·

LONDON (Reuters) - Only 10% of global Security Operations Centers report excellent value from artificial intelligence adoption, a 2026 survey by SOC-CMM reveals, as fragmented tools and weak governanc...

56

DentaQuest Data Breach Exposes 2.6 Million Accounts, ShinyHunters Claims Responsibility

Tech & ScienceAI·1 source·

NEW YORK — A major data breach at DentaQuest, a dental benefits administrator owned by Sun Life, has exposed the sensitive personal information of approximately 2.6 million accounts, the company confi...

56

Threat Actors Exploit Critical Vulnerability in Everest Forms Pro Plugin

Tech & ScienceAI·1 source·

LONDON, June 5 (AP) — Cybersecurity researchers have identified active exploitation of a critical remote code execution vulnerability in the Everest Forms Pro WordPress plugin, allowing threat actors ...

73

Cisco Issues Alert for SD-WAN Zero-Day Exploited in 2026

Tech & ScienceAI·1 source··UPDATED

SAN FRANCISCO — Cisco Systems issued an urgent advisory on Wednesday warning customers that a critical zero-day vulnerability in its SD-WAN software is being actively exploited in the wild. The vulne...

56

Malware Infects 36 npm Packages in Supply-Chain Attack

Tech & ScienceAI·1 source·

LONDON (AP) — A sophisticated supply-chain attack has compromised 36 packages on the Node Package Manager (npm), distributing malware designed to steal credentials and cryptocurrency wallet files. Th...

56

Hola Browser Windows Version Compromised in Supply Chain Attack

Tech & ScienceAI·1 source·

JERUSALEM — The Windows version of the Hola Browser was compromised in a supply chain attack that delivered an undeclared executable identified as a cryptocurrency miner, security researchers confirme...

56

Brave Software Launches Paid 'Brave Origin' Browser Stripping Crypto and AI Features

Tech & ScienceAI·1 source·

SAN FRANCISCO — Brave Software announced on Wednesday the public release of Brave Origin, a paid, minimalist version of its web browser that removes cryptocurrency, artificial intelligence, and other ...

56

WFP Gaza Self-Registration App Breached, Exposing Beneficiary Data

Tech & ScienceAI·1 source·

GENEVA (AP) — The United Nations World Food Programme confirmed Wednesday that its self-registration application for Palestine was breached, resulting in unauthorized access to personal data of aid be...

56

Hacking Tutorial by 'Hercules' Emerges on Underground Forums

Tech & ScienceAI·1 source·

LONDON (AP) — A threat actor operating under the pseudonym 'Hercules' has published a comprehensive tutorial on underground forums, instructing novice hackers on how to scan, exploit, and monetize vul...

56

Microsoft Fixes Windows Update Glitch That Bypassed Corporate Policies

Tech & ScienceAI·1 source·

Microsoft has resolved a technical issue that caused Windows devices to install driver updates without user or administrator consent, even when corporate policies were configured to block automatic up...

69

Cisco Warns of Critical Vulnerability in Unified Communications Manager

Tech & ScienceAI·1 source··UPDATED

SAN JOSE, Calif. — Cisco issued a security advisory on Wednesday warning that proof-of-concept code exists for a critical vulnerability affecting its Unified Communications Manager and Unified Communi...

56

Cisco Issues Critical Patch for Unified Communications Manager Root Privilege Flaw

Tech & ScienceAI·1 source·

SAN JOSE, Calif. — Cisco Systems Inc. released emergency security updates on Wednesday to address a critical vulnerability in its Unified Communications Manager software that allows remote attackers t...

56

SANS Internet Storm Center Releases Weekly Security Update Covering New Threats and Tools

Tech & ScienceAI·1 source·

JACKSONVILLE, Fla. — The SANS Internet Storm Center released a weekly security update Wednesday detailing emerging reconnaissance tactics, new mobile security features, and improved vulnerability disc...

56

U.S. Agencies Warn of Cyberattacks Targeting Fuel Storage Systems

Tech & ScienceAI·1 source·

WASHINGTON (June 3, 2026) — The Cybersecurity and Infrastructure Security Agency, alongside the FBI, the National Security Agency, and the Department of Energy, issued a joint alert Tuesday warning of...

56

New HTTP/2 Bomb Attack Exposes Critical Vulnerability in Major Web Servers

Tech & ScienceAI·1 source·

SAN FRANCISCO — A newly discovered denial-of-service attack dubbed the HTTP/2 Bomb can crash major web servers within seconds by exploiting a flaw in the HTTP/2 protocol's header compression mechanism...

56

Security Researchers Identify Prompt Injection Flaw in Google Gemini Voice Assistant

Tech & ScienceAI·1 source·

JUN 3, 2026 — A critical security vulnerability in Google Gemini's voice assistant has been identified by the SafeBreach security research team, allowing attackers to execute unauthorized commands thr...

56

CISA Warns of Active Exploits in Linux and Android Systems

Tech & ScienceAI·1 source·

WASHINGTON — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a critical alert on Tuesday warning federal agencies and critical infrastructure operators of active cyberattacks e...

56

One-Click Attack in Visual Studio Code Exposes GitHub OAuth Tokens

Tech & ScienceAI·1 source·

A critical vulnerability in Microsoft Visual Studio Code allows attackers to steal full GitHub OAuth tokens through a one-click attack, researchers disclosed Wednesday. The flaw exploits a message-pas...

56

Orchid Security Launches Identity Visibility Platform to Address Enterprise Gaps

Tech & ScienceAI·1 source·

Orchid Security introduced the Identity Visibility and Intelligence Platform (IVIP) model on June 3, 2026, to address fragmented enterprise identity activity that occurs outside centralized identity a...