REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
64 reports · page 1 of 2

ars_security · tlp:amber · 7/20/2026, 2:00:50 PM
Pay up or not? Ransomware surge has victims facing tough choices. Governments look at banning ransom payments in face of increasingly sophisticated threats. Nearly half of companies that are targets of a ransomware cyber attack end up paying a ransom to release their data or systems, according to 2025 research from cybersecurity group Sophos, while the median amount demanded is rising. Globally, some jurisdictions are responding by banning payments to hackers. In the UK, fo…
Read original ↗https://arstechnica.com/security/2026/07/pay-up-or-not-ransomware-surge-has-victims-facing-tough-choices
ars_security · tlp:amber · 7/16/2026, 7:28:33 PM
Now, even Russia's most elite hackers are using Clickfix to infect devices The social-engineering technique has primarily been a tool of financially motivated criminals. One of the Russian government’s most elite hacking groups has adopted an attack, known as Clickfix, to compromise devices belonging to sensitive organizations in Ukraine, the latter country’s CERT center is warning. Clickfix has emerged as an effective attack technique that attackers, primarily financially …

ars_security · tlp:amber · 7/15/2026, 7:59:48 PM
Windows 0-day drops the same day Microsoft releases record number of patches HiveLegacy is a "powerful primitive" that's likely capable of other nefarious actions. Right on the heels of Microsoft releasing a record number of security patches, a researcher has published exploit code that can enable low-privilege Windows accounts to make sensitive changes to administrator accounts. The exploit, which multiple researchers say works , is sending Microsoft scrambling, yet again,…
Read original ↗https://arstechnica.com/security/2026/07/windows-0-day-drops-the-same-day-microsoft-releases-record-number-of-patches
ars_security · tlp:amber · 7/14/2026, 10:20:48 PM
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now Old and forgotten "shims" Microsoft failed to revoke have made Secure Boot bypasses simple. An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, tha…
Read original ↗https://arstechnica.com/security/2026/07/microsoft-secure-boot-has-been-broken-for-most-of-its-existence
ars_security · tlp:amber · 7/13/2026, 9:03:07 PM
The US government warns that Russia state hackers are coming after your router With residential proxies all the rage, CISA urges router users to be vigilant. The federal government is warning users of home and small office routers to secure their devices as Russia state hackers continue to mass-compromise them for use in obscuring nefarious actions against sensitive organizations in the public and private sectors. Both the Russian and Chinese governments have been compromis…
Read original ↗https://arstechnica.com/security/2026/07/the-us-government-warns-that-russia-state-hackers-are-coming-after-your-router
ars_security · tlp:amber · 7/13/2026, 3:06:34 PM
Now, defenders are embracing the prompt injection, too "Context bombing" tricks hacking agents into shutting down before they can do harm. Prompt injections, the malicious commands attackers embed into content to entice large language models to follow them, have been attackers’ go-to tool for turning AI platforms against their users. A well-phrased command sneaked into an email or calendar invitation is often all it takes to cause the LLM to exfiltrate sensitive data or fol…
Read original ↗https://arstechnica.com/security/2026/07/now-defenders-are-embracing-the-prompt-injection-too
ars_security · tlp:amber · 7/9/2026, 8:52:55 PM
Patch for Windows Defender 0-day could allow attackers to fill hard disk The feud between NightmareEclipse and Microsoft shows no signs of resolving soon. A patch Microsoft released on Wednesday to fix a zero-day vulnerability in its Defender security engine may cause Windows machines to write files large enough to completely consume available disk space, the researcher who discovered the flaw said. RoguePlanet, tracked as CVE-2026-50656, came to public notice in June when …
Read original ↗https://arstechnica.com/security/2026/07/patch-for-windows-defender-0-day-could-allow-attackers-to-fill-hard-diskars_security · tlp:amber · 7/8/2026, 7:01:19 PM
Google pays $250K for Linux vulnerability allowing guest VM escapes Both vulnerabilities allow untrusted users to gain root privileges. A Linux vulnerability that allows untrusted virtual machines to gain root access to host machines is one of two high-severity flaws to surface this week in the open source operating system. The vulnerability resides in KVM, which is, in essence, a virtual machine app included in the kernel of many Linux distributions. The vulnerability, tra…
Read original ↗https://arstechnica.com/security/2026/07/high-severity-guest-vm-escape-is-1-of-2-linux-vulnerabilities-to-surface-this-weekars_security · tlp:amber · 7/8/2026, 7:00:51 AM
Hackers can use 9 of the most popular AI tools to assemble massive botnets "HalluSquatting" weaponizes LLMs' inability to say "I don't know." In the brief history of AI security, the prompt injection has quickly become the top threat. Large language models are inherently unable to distinguish between legitimate instructions provided by users and malicious ones sneaked into emails, source code, and other third-party content the models are processing. This makes it trivial to…
Read original ↗https://arstechnica.com/security/2026/07/hackers-can-use-9-of-the-most-popular-ai-tools-to-assemble-massive-botnetsars_security · tlp:amber · 7/2/2026, 7:38:57 PM
Newly discovered PamStealer isn't your typical macOS malware The discovery underscores the increased effort being poured into Mac infostealers. Researchers have found a never-before-seen piece of macOS malware that combines a series of clever tradecraft to infect Macs with stealthy, custom-developed credential-stealing code. The malware is delivered in two stages. The first is distributed in a disk image that masquerades as Maccy , a clipboard manager for Macs. It’s compile…
Read original ↗https://arstechnica.com/security/2026/07/new-pamstealer-macos-malware-uses-clever-tradecraft-to-remain-stealthyars_security · tlp:amber · 7/1/2026, 4:11:39 PM
NASA inspector general suggests Boeing's Starliner will now be a decade late Starliner's certification may be delayed to 2027, 10 years later than Boeing's original schedule. NASA's inspector general released an audit Tuesday of the agency's Commercial Crew Program, and it looks increasingly likely that Boeing's Starliner crew capsule won't be certified for operational flights to the International Space Station until next year. That's just three years before NASA's official…
Read original ↗https://arstechnica.com/space/2026/07/nasa-inspector-general-suggests-boeings-starliner-will-now-be-a-decade-latears_security · tlp:amber · 6/30/2026, 8:03:14 PM
New attack provides one more reason why AI browsers are a bad idea Telling an LLM that 2 + 2 = 5 is enough to make it follow forbidden instructions. Makers of AI browsers make lofty promises. With a single prompt, users can ask one to find a restaurant in a particular part of town, reserve a table, invite a colleague to lunch, and email a confirmation. These makers are much more reticent about the risks of blurring the once fine line between browsing sites and asking a larg…
Read original ↗https://arstechnica.com/security/2026/06/ai-browsers-can-be-lulled-into-a-dream-world-where-guardrails-no-longer-applyars_security · tlp:amber · 6/29/2026, 10:05:33 PM
US offers $10 million for info on group behind Signal and WhatsApp hacking spree Operation by two Russia-state groups has been ongoing since at least March. Federal authorities are offering a reward of up to $10 million for information leading to the identification or location of a Russian state cyber group that has compromised thousands of Signal and WhatsApp accounts belonging to investigative reporters and US government employees. The operation has been active since at l…
Read original ↗https://arstechnica.com/information-technology/2026/06/us-offers-10-million-for-info-on-group-behind-signal-and-whatsapp-hacking-spreears_security · tlp:amber · 6/24/2026, 9:03:34 PM
One-two punch delivered in global operation disrupts cybercrime "assembly line" "Operation Endgame" simultaneously disrupts two widely used crime tools. International authorities and a raft of private technology companies say they have disrupted a cybercrime “assembly line” that allowed crooks to collect millions of login credentials and steal more than $47 million in ransom payments and by other fraudulent means. The crux of the operation was the simultaneous targeting of …
Read original ↗https://arstechnica.com/security/2026/06/one-two-punch-delivered-in-global-operation-disrupts-cybercrime-assembly-linears_security · tlp:amber · 6/23/2026, 10:30:57 PM
White House drastically shortens deadline for dropping quantum-vulnerable crypto Order warns of national security risks if post-quantum cryptography isn't adopted in time. The White House is drastically shortening the deadline for government agencies and organizations to adopt new quantum-resistant encryption systems that will withstand attacks that use quantum computers, as the federal government seeks to protect decades’ worth of secrets belonging to militaries, banks, go…
Read original ↗https://arstechnica.com/information-technology/2026/06/executive-order-bumps-up-deadline-to-move-off-quantum-vulnerable-cryptoars_security · tlp:amber · 6/22/2026, 7:16:52 PM
Following user outcry, AMD reinstates memory encryption in consumer CPUs Critics saw the move as an underhanded way to steer them toward more costly chips. Consumer AMD CPUs will once again offer encryption protections against physical attacks after facing user backlash for silently removing the feature. As Ars reported last week, AMD stripped the protection, known as TSME , from consumer Ryzen processors. Short for Transparent Secure Memory Encryption, TSME encrypts the en…
Read original ↗https://arstechnica.com/security/2026/06/following-user-outcry-amd-reinstates-memory-encryption-in-consumer-cpusars_security · tlp:amber · 6/18/2026, 11:28:52 PM
Microsoft discovers new lightweight backdoor that steals cryptocurrency Crypto Clipper spreads over USB and communicates over Tor. Microsoft says it has detected new self-propagating malware that spreads through USB drives in search of cryptocurrency credentials, which it then sends to attacker-controlled servers. The company named the worm Crypto Clipper because it monitors the contents of device clipboards for patterns consistent with wallet addresses or seed phrases. Whe…
Read original ↗https://arstechnica.com/security/2026/06/microsoft-spots-new-self-propagating-malware-for-stealing-cryptocurrencyars_security · tlp:amber · 6/18/2026, 7:41:35 PM
Apple patches high-severity eavesdropping vulnerability in Beats Studio Buds The vulnerability, disclosed 12 months ago, affects multiple manufacturers. Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users. The vulnerability, CVE-2025-20701 , allowed improper authentication in the firmware running on the Bluetooth-related chips, enabling people within signal range to i…
Read original ↗https://arstechnica.com/apple/2026/06/apple-patches-high-severity-eavesdropping-vulnerability-in-beats-studio-budsars_security · tlp:amber · 6/17/2026, 7:54:31 PM
Massive breach spills credentials for thousands of sensitive networks The affected include Oracle, Lenovo, FedEx, a NATO contractor, and Fortinet. Researchers have uncovered a massive breach of Fortinet firewalls that has given Russian-speaking attackers near-unrestricted access to some of the world’s largest and most powerful organizations, including Oracle, Chevron, Lenovo, Federal Express, a NATO defense contractor, and Fortinet itself. Nearly 74,000 Fortinet devices fro…
Read original ↗https://arstechnica.com/security/2026/06/massive-breach-spills-credentials-for-thousands-of-sensitive-networksars_security · tlp:amber · 6/17/2026, 5:50:46 PM
"Dangerous" AI models are coming no matter what AI models with advanced hacking capabilities will soon be the norm. Late last week, Anthropic took its new Claude Fable 5 and Mythos 5 AI models offline following a United States government export-control directive barring “any foreign national” from using the services. The company has been in talks with the White House since Friday but has yet to secure an agreement that would allow it to reinstate the offerings. Since Mythos…
Read original ↗https://arstechnica.com/ai/2026/06/dangerous-ai-models-are-coming-no-matter-whatars_security · tlp:amber · 6/17/2026, 11:15:17 AM
Windows and Linux users: The deadline to update Secure Boot keys is near What you need to know about the expiration of keys securing your machine's boot sequence. The clock is ticking for Windows and Linux users to update cryptographic keys that protect their systems against firmware-based UEFI infections, a pernicious form of malware that loads before operating system and anti-malware protections start. Beginning June 24, three certificates that cryptographically verify th…
Read original ↗https://arstechnica.com/security/2026/06/windows-and-linux-users-the-deadline-to-update-secure-boot-keys-is-nearars_security · tlp:amber · 6/16/2026, 11:15:46 AM
Critical Copilot vulnerability allowed hackers to seal 2FA code from users SearchLeak exploit shows why the industry's approach to LLM security fails over and over. Last Tuesday, Microsoft patched a vulnerability it rated as max critical in its M365 Copilot AI platform. On Monday, the researchers who discovered the vulnerability and reported it to Microsoft revealed how their proof-of-concept exploit could retrieve 2FA codes and other sensitive data from emails accessible t…
Read original ↗https://arstechnica.com/security/2026/06/critical-copilot-vulnerability-allowed-hackers-to-seal-2fa-code-from-usersars_security · tlp:amber · 6/15/2026, 5:55:46 PM
Users cry foul after AMD stripped memory crypto from its consumer CPUs AMD's stripping of TSME from consumer CPUs appears to be a deliberate, covert move. A decade ago, AMD added a protection to its high-end CPUs to protect them against cold boot attacks and other types of physical exploits that siphon sensitive data out of the connected memory chips. Short for Transparent Secure Memory Encryption, TSME encrypts the entire contents stored in memory, making the data useless …
Read original ↗https://arstechnica.com/security/2026/06/users-cry-foul-after-amd-stripped-memory-crypto-from-its-consumer-cpusars_security · tlp:amber · 6/12/2026, 7:26:47 PM
PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data Vulnerability in the Oracle-owned PeopleSoft software is about as critical as they come. One of the world’s most active ransomware groups exploited a critical vulnerability in Oracle’s PeopleSoft software suite and used it to target about 100 customers and extort at least one of them to pay up in exchange for not leaking stolen data, researchers said. The group, tracked as ShinyHunters, had been e…
Read original ↗https://arstechnica.com/security/2026/06/peoplesoft-0-day-affecting-hundreds-of-organizations-steals-gigabytes-of-dataars_security · tlp:amber · 6/9/2026, 8:56:52 PM
Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed A separate zero-day also disclosed by Nightmare Eclipse appears to be patched as well. Microsoft on Tuesday released fixes for two high-severity zero-days that were disclosed by a researcher who has been locked in a testy beef with the software giant. Nightmare Eclipse, the pseudonym the researcher goes by, released a handful of high-severity vulnerabilities in recent months, making them zero-day…
Read original ↗https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosedars_security · tlp:amber · 6/9/2026, 3:12:43 PM
High-severity vulnerability in Linux caused by a single faulty character Use-after-free bug can be exploited to evade sandbox defenses. Researchers have analyzed a high-severity vulnerability in Linux that’s able to escalate untrusted users to root by exploiting a bug you don't often see: a single errant character inside the kernel. The vulnerability, tracked as CVE-2026-23111 , is located in nf_tables, a subsystem of the Linux kernel that provides packet filtering capabili…
Read original ↗https://arstechnica.com/security/2026/06/a-single-errant-character-in-the-linux-kernel-allows-attacker-to-gain-rootars_security · tlp:amber · 6/8/2026, 6:34:23 PM
For the 2nd time in weeks, Microsoft packages laced with credential stealer 73 packages run self-replicating stealer as soon as they're opened by an AI agent. Dozens of cryptographically verified open source packages from Microsoft were compromised late last week to add advanced credential-stealing code that was triggered when developers opened them in AI coding agents. In all, multiple researchers said , 73 packages were flagged as malicious when automated systems on GitHu…
Read original ↗https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealerars_security · tlp:amber · 6/5/2026, 9:00:29 PM
How a USB-connected speaker can infect a PC without ever being touched Seller of the Sound Blaster Katana V2X doesn't consider the behavior a vulnerability. Operating system makers take many steps to prevent their wares from accepting commands from remote devices. The safeguards, designed to thwart malicious attacks, typically require hackers to jump through all kinds of hoops to bypass the measures. But what if remote code execution were as simple as being within Bluetooth…
Read original ↗https://arstechnica.com/security/2026/06/highly-reviewed-speaker-can-be-hacked-over-the-air-to-infect-connected-devicesars_security · tlp:amber · 6/4/2026, 8:02:04 PM
Dashlane explains how attackers managed to download encrypted password vaults By targeting large numbers of users, attackers increased their chances of success. Dashlane said that attackers mounted a coordinated hacking campaign against a large base of its users in an attempt to recover as many encrypted password vaults as possible. The password manager provider said fewer than 20 personal user vaults were downloaded before it shut down the operation. In a campaign that sta…
Read original ↗https://arstechnica.com/security/2026/06/dashlane-explains-how-attackers-managed-to-download-encrypted-password-vaultsars_security · tlp:amber · 6/3/2026, 7:53:14 PM
Can't make sense of Dashlane's vault theft notification? You're not alone. Security advisory leaves out key details. Dashlane maintains complete silence. There’s a lot that doesn’t add up in a security advisory password manager Dashlane published Monday, warning that attackers managed to obtain 20 encrypted user vaults. “Starting on Sunday, May 31, 2026, an external party launched a brute force attack against certain Dashlane user accounts,” the company said . “The goal of …
Read original ↗https://arstechnica.com/security/2026/06/dashlane-issues-opaque-advisory-warning-20-encrypted-vaults-were-stolenars_security · tlp:amber · 6/1/2026, 8:44:37 PM
Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts Pricey Instagram handles were stolen and resold before Meta patched the exploit. Meta’s AI support chatbot proved unusually helpful to hackers looking to steal and resell notable Instagram accounts—the hackers simply asking the bot to change the accounts’ associated email addresses while using VPN to mask their true locations. Videos featuring the “shockingly easy” exploit have been circulating amon…
Read original ↗https://arstechnica.com/ai/2026/06/meta-ai-support-chatbot-gave-hackers-access-to-notable-instagram-accountsars_security · tlp:amber · 6/1/2026, 7:49:09 PM
Dozens of Red Hat packages backdoored through its official NPM channel Anyone who has downloaded affected Red Hat packages should investigate immediately. Official Red Hat NPM accounts have been compromised and used to push a malicious worm that spreads from machine to machine, where it pilfers sensitive credentials in hopes of stealing yet more confidential data, researchers said. The supply-chain attack began Monday and remained active at the time this post went live, acc…
Read original ↗https://arstechnica.com/security/2026/06/dozens-of-red-hat-packages-backdoored-through-its-offical-npm-channelars_security · tlp:amber · 5/29/2026, 6:46:33 PM
Botnet of more than 17 million devices dismantled The botnet was reportedly tied to a Russia-based residential proxy network. Authorities in the Netherlands said they dismantled a botnet that comprised more than 17 million devices and were managed by 200 servers in a joint operation by the police and the National Cyber Security Center. The action, announced Thursday , came about after a security researcher reported the sprawling network to authorities. The host infrastructu…
Read original ↗https://arstechnica.com/security/2026/05/botnet-of-more-than-17-million-devices-dismantledars_security · tlp:amber · 5/28/2026, 8:29:53 PM
Fed up with vibe coders, dev sneaks data-nuking prompt injection into their code Undisclosed addition in jqwik instructed AI coding agents to delete app output. The controversy over vibe coding reached a new high this week after a developer added hidden instructions to his open source Java testing app to sabotage projects performed by AI coding agents. The instructions were added to jqwik , a test engine for JUnit 5, a platform for testing Java virtual machine frameworks. O…
Read original ↗https://arstechnica.com/security/2026/05/fed-up-with-vibe-coders-dev-sneaks-data-nuking-prompt-injection-into-their-codears_security · tlp:amber · 5/27/2026, 8:56:03 PM
Websites have a new way to spy on visitors: Analyzing their SSD activity Telltale SSD activity can be measured in the browser using simple JavaScript. Over the decades, there has been no shortage of sites using clever techniques to covertly track visitors’ browsing histories , device fingerprints , and keystrokes and mouse movements in real time. Even Meta and Yandex were recently caught joining in the privacy-invasive free-for-all . Now sites have a new way to spy on their…
Read original ↗https://arstechnica.com/security/2026/05/websites-have-a-new-way-to-spy-on-visitors-analyzing-their-ssd-activityars_security · tlp:amber · 5/26/2026, 7:50:33 PM
Millions of AI agents imperiled by critical vulnerability in open source package "BadHost" was found in Starlette, a package with 325 million weekly downloads. Millions of AI agents and tools around the world have been imperiled by a critical vulnerability that can allow hackers to breach the servers running them and make off with sensitive data and credentials to third-party accounts, a security researcher is warning. The vulnerability is present in Starlette, an open sour…
Read original ↗https://arstechnica.com/information-technology/2026/05/millions-of-ai-agents-imperiled-by-critical-vulnerability-in-open-source-packagears_security · tlp:amber · 5/22/2026, 6:43:54 PM
Police boast of hacking VPN where criminals "believed themselves to be safe" Law enforcement intercepted VPN traffic, seized domains, and arrested its operator. European law enforcement say they hacked into a VPN (virtual private network) service used for ransomware attacks and other crimes, and identified thousands of users before shutting the VPN down and arresting its administrator. Europol announced yesterday the results of the operation against the service, First VPN. …
Read original ↗https://arstechnica.com/tech-policy/2026/05/police-boast-of-hacking-vpn-where-criminals-believed-themselves-to-be-safears_security · tlp:amber · 5/22/2026, 6:13:05 PM
Texas AG sues Meta over claims that WhatsApp doesn't provide end-to-end encryption Critics note a lack of factual support in lawsuit filed by US Senate candidate. The Texas Attorney General has sued Meta over allegations that the company’s WhatsApp messenger, used by more than 3 billion people, doesn’t provide the end-to-end encryption (E2EE) it has long claimed. Since at least 2016, Meta (then named Facebook) has said WhatsApp provides robust end-to-end encryption, meaning…
Read original ↗https://arstechnica.com/security/2026/05/texas-ag-sues-meta-over-claims-that-whatsapp-doesnt-provide-end-to-end-encryptionars_security · tlp:amber · 5/22/2026, 10:30:14 AM
A hacker group is poisoning open source code at an unprecedented scale GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks. A so-called software supply chain attack , in which hackers corrupt a legitimate piece of software to hide their own malicious code, was once a relatively rare event but one that haunted the cybersecurity world with its insidious threat of turning any innocent application into a dangerous fo…
Read original ↗https://arstechnica.com/information-technology/2026/05/a-hacker-group-is-poisoning-open-source-code-at-an-unprecedented-scalears_security · tlp:amber · 5/20/2026, 7:10:36 PM
Google publishes exploit code threatening millions of Chromium users Google publishes exploit code before patch, reported 29 months earlier, is fixed. Google on Wednesday published exploit code for an unfixed vulnerability in its Chromium browser codebase that threatens millions of people using Chrome, Microsoft Edge, and virtually all other Chromium-based browsers. The proof-of-concept code exploits the Browser Fetch programming interface, a standard that allows long video…
Read original ↗https://arstechnica.com/security/2026/05/google-publishes-exploit-code-threatening-millions-of-chromium-users