A Chinese-speaking threat actor is using a leaked version of the DarkSword offensive security kit to deliver GHOSTBLADE, a previously undocumented malware targeting iOS devices. The campaign highlights how leaked hacking tools can lower the barrier for deployment of sophisticated mobile threats.
Thermo Fisher has released a patch for a security flaw that could allow attackers to modify DNA files while evading detection. The vulnerability affects software used in genetic analysis, potentially enabling manipulated data to pass as legitimate. This matters because undetected tampering in DNA samples could have serious consequences in research and diagnostics.
Michigan has joined Minnesota in disclosing cyberattacks as authorities investigate potential security breaches. The FBI is looking into the incidents, which affect state government systems and raise concerns about election and infrastructure security.
Security expert Bruce Schneier highlights that Anthropic's latest AI model, Opus 5, demonstrates significantly improved resistance to prompt injection attacks. This matters because prompt injection is a critical vulnerability that can trick AI systems into bypassing their safety rules or taking unintended actions. The improvement signals a step forward in making advanced AI models more secure and trustworthy.
A spear-phishing campaign targeted a law firm using the HollowFrame loader to deliver the Matryoshka backdoor. The attack likely aims to steal sensitive legal data, demonstrating the growing sophistication of modular malware.
Security researchers found that low-cost Android TV boxes are pre-installed with malware that disguises them as mobile devices. These devices silently route other people's internet traffic through owners' home connections, turning their broadband into anonymous proxies without consent. This poses a privacy and security risk to consumers, as attackers can abuse the hijacked bandwidth and IP addresses.
Google recently shipped three Chrome updates that together patched a record 1,442 security flaws, more than the combined fixes from the previous 23 releases. The surge suggests a major clean-up of accumulated vulnerabilities, likely following a thorough internal audit. Users should update Chrome promptly to stay protected against these now-publicly disclosed issues.
Madison Square Garden deployed facial recognition technology to identify and bar attorneys involved in litigation against the venue. The practice raises significant privacy and civil liberties concerns about the use of biometric surveillance in private spaces open to the public.
Security researchers have identified vulnerabilities in popular TV streaming sticks that could expose users' data and privacy. The article advises consumers to research device security features before purchasing, as many sticks lack adequate protections. This matters because streaming devices are increasingly used for sensitive transactions and home network access.