Print Mode Video Only Audio Only Remove Channel Filter Channel A

News chronological

10 items before 1159237 (Channel B) (Keyword: "malware" (~33 currently found))

NYTIMES (Dustin Volz) - A.I. Models Built a Computer Worm That Could Rapidly Hack WeChat Accounts

The attack, discovered by A.I. researchers, could have compromised hundreds of millions of devices within hours, experts said.

AXIOS (Sam Sabin) - How OpenAI's agents broke out of testing to hack Hugging Face

Weeks before OpenAI's agents hacked Hugging Face , the agents worked together to find and exploit a vulnerability in the infrastructure supporting the company's cybersecurity testing, OpenAI researchers said Wednesday. Why it matters: The new findings raise questions about how frontier AI labs are monitoring their testing environments — and the challenges safety testers are finding as they try to rein in increasingly powerful AI. Driving the news: OpenAI's internal research model, one of the models involved in the Hugging Face breach, first discovered and exploited a vulnerability in Artifactory, a third-party file repository connected to the company's testing sandbox, on May 26, two researchers said at the Black Hat cybersecurity…

Weeks before OpenAI's agents hacked Hugging Face , the agents worked together to find and exploit a vulnerability in the infrastructure supporting the company's cybersecurity testing, OpenAI researchers said Wednesday. Why it matters: The new findings raise questions about how frontier AI labs are monitoring their testing environments — and the challenges safety testers are finding as they try to rein in increasingly powerful AI. Driving the news: OpenAI's internal research model, one of the models involved in the Hugging Face breach, first discovered and exploited a vulnerability in Artifactory, a third-party file repository connected to the company's testing sandbox, on May 26, two researchers said at the Black Hat cybersecurity…Open

AXIOS (Sam Sabin) - The number of states targeted in cyberattacks on water systems has jumped to 12

At least a dozen states are reportedly responding to cyberattacks against local water systems . Why it matters: This appears to be one of the broadest known coordinated cyber campaigns against U.S. municipal water systems to date, validating years of warnings that poorly secured utilities could become attractive targets. Driving the news: Hackers have targeted water and wastewater utilities in at least 12 states, ABC News reported on Tuesday. - Last week, the FBI said that at least seven states had experienced cyberattacks targeting the systems that control pumps, water pressure and valves in plants. - Multiple news outlets have reported that officials suspect Iran is behind the widespread attacks, although President Trump said…

At least a dozen states are reportedly responding to cyberattacks against local water systems . Why it matters: This appears to be one of the broadest known coordinated cyber campaigns against U.S. municipal water systems to date, validating years of warnings that poorly secured utilities could become attractive targets. Driving the news: Hackers have targeted water and wastewater utilities in at least 12 states, ABC News reported on Tuesday. - Last week, the FBI said that at least seven states had experienced cyberattacks targeting the systems that control pumps, water pressure and valves in plants. - Multiple news outlets have reported that officials suspect Iran is behind the widespread attacks, although President Trump said…Open

AXIOS (Sam Sabin) - China's new open-source model accelerates AI hacking threat

GLM-5.2 — the latest Chinese open-source model capturing Silicon Valley's attention — is raising fresh concerns among security researchers that advanced AI hacking capabilities are becoming dramatically cheaper and more accessible. Why it matters: The barrier to entry for malicious hackers eager to automate and personalize their attacks is getting lower and lower. Driving the news: Z.ai's GLM-5.2, which was released last week, has agentic capabilities that rival those of Claude Opus 4.8 and OpenAI's GPT-5.5 while costing roughly half as much to run. - Two separate security evaluations from Graphistry and Semgrep found that GLM-5.2 performed on par with leading U.S. models on cybersecurity investigation and vulnerability-discovery…

GLM-5.2 — the latest Chinese open-source model capturing Silicon Valley's attention — is raising fresh concerns among security researchers that advanced AI hacking capabilities are becoming dramatically cheaper and more accessible. Why it matters: The barrier to entry for malicious hackers eager to automate and personalize their attacks is getting lower and lower. Driving the news: Z.ai's GLM-5.2, which was released last week, has agentic capabilities that rival those of Claude Opus 4.8 and OpenAI's GPT-5.5 while costing roughly half as much to run. - Two separate security evaluations from Graphistry and Semgrep found that GLM-5.2 performed on par with leading U.S. models on cybersecurity investigation and vulnerability-discovery…Open

NYTIMES (Cade Metz) - Scientists Find Way to Supercharge Dangerous Computer ‘Worms’ With A.I.

Researchers at the University of Toronto showed how hackers could use artificial intelligence to create a program that could target any known flaw in the world’s computers.

NYTIMES (Timothy D. Haugh) - I Ran the N.S.A. This Is How to Defeat China’s Hacker Army.

Beijing has hacked America, but we have all the tools we need to fight back.

AXIOS (Sam Sabin) - OpenAI makes its rival to Anthropic's Mythos more widely available to cyber defenders

OpenAI is rolling out a more permissible version of GPT-5.5 — aka "Spud" — to vetted cyber defenders, the company said Thursday. Why it matters: Recent security testing suggests that GPT-5.5 model is nearly as good at finding and exploiting software bugs as Anthropic's Mythos Preview . The capabilities of the new models have sparked an urgent debate in Silicon Valley and the White House about how to keep them out of the hands of bad actors. Driving the news: OpenAI is opening a limited preview of GPT-5.5-Cyber to vetted cyber defenders who are "responsible for securing critical infrastructure," per a press release. - A source familiar with GPT-5.5-Cyber's abilities told Axios that they were roughly on par with Mythos. One major…

OpenAI is rolling out a more permissible version of GPT-5.5 — aka "Spud" — to vetted cyber defenders, the company said Thursday. Why it matters: Recent security testing suggests that GPT-5.5 model is nearly as good at finding and exploiting software bugs as Anthropic's Mythos Preview . The capabilities of the new models have sparked an urgent debate in Silicon Valley and the White House about how to keep them out of the hands of bad actors. Driving the news: OpenAI is opening a limited preview of GPT-5.5-Cyber to vetted cyber defenders who are "responsible for securing critical infrastructure," per a press release. - A source familiar with GPT-5.5-Cyber's abilities told Axios that they were roughly on par with Mythos. One major…Open

AXIOS (Sam Sabin) - North Korean hackers implicated in major supply chain attack

Suspected North Korean hackers are believed to be behind an ongoing compromise of the widely used open-source package Axios, which is downloaded millions of times per week, researchers at Google said Tuesday. Why it matters: Hackers briefly turned a widely trusted developer tool into a vehicle for credential-stealing malware that could give attackers ongoing access to infected systems. - Axios, a widely used JavaScript library for making HTTP requests, is not affiliated with Axios Media. Driving the news: Researchers at Google linked the activity to a North Korean group tracked as UNC1069 , which has previously targeted cryptocurrency and decentralized finance companies. - Earlier this week, a maintainer account for the Axios npm…

Suspected North Korean hackers are believed to be behind an ongoing compromise of the widely used open-source package Axios, which is downloaded millions of times per week, researchers at Google said Tuesday. Why it matters: Hackers briefly turned a widely trusted developer tool into a vehicle for credential-stealing malware that could give attackers ongoing access to infected systems. - Axios, a widely used JavaScript library for making HTTP requests, is not affiliated with Axios Media. Driving the news: Researchers at Google linked the activity to a North Korean group tracked as UNC1069 , which has previously targeted cryptocurrency and decentralized finance companies. - Earlier this week, a maintainer account for the Axios npm…Open

AXIOS (Sam Sabin) - Spyware once used by governments is now spreading to cybercriminals

Cybercriminal groups are now using spyware tools once utilized mainly by spies and law enforcement to hack into iPhones, new research shows. Why it matters: Anyone with an iPhone can now be the target of invasive malware that siphons off personal text messages, photos, notes and calendar data. Driving the news: In the last month, researchers at Google, iVerify and Lookout uncovered two campaigns exploiting iPhone vulnerabilities. - Earlier this month, Google researchers said they identified a sophisticated iPhone hacking toolkit, called Coruna , originally built for an unnamed government customer that later ended up in the hands of a Chinese cybercriminal group. TechCrunch later reported that defense contractor L3Harris created the…

Cybercriminal groups are now using spyware tools once utilized mainly by spies and law enforcement to hack into iPhones, new research shows. Why it matters: Anyone with an iPhone can now be the target of invasive malware that siphons off personal text messages, photos, notes and calendar data. Driving the news: In the last month, researchers at Google, iVerify and Lookout uncovered two campaigns exploiting iPhone vulnerabilities. - Earlier this month, Google researchers said they identified a sophisticated iPhone hacking toolkit, called Coruna , originally built for an unnamed government customer that later ended up in the hands of a Chinese cybercriminal group. TechCrunch later reported that defense contractor L3Harris created the…Open

ABCNEWS - US medical equipment company Stryker says cyberattack disrupted its global networks

Stryker, a U.S. medical equipment company, says a cyberattack has disrupted its global networks