Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The Texas Parks and Wildlife Department suffered a third-party data breach exposing personal data of 3,087,721 hunting and fishing license customers, including driver's license details and addresses, though payment data remained secure. WordPress plugin vendor ShapedPlugin experienced a supply chain attack delivering malicious updates that stole admin credentials and modified websites, while iRhythm Technologies confirmed a social engineering attack compromising health data.
For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND...
The article is a weekly threat intelligence report covering recent attacks and breaches. It highlights a third-party breach affecting Texas Parks and Wildlife, a supply chain attack on WordPress plugin vendor ShapedPlugin, and a cyberattack on digital health company iRhythm Technologies.
Check Point Research discovered a novel browser-based ransomware technique that leverages AI-generated code to exploit the File System Access API in Google Chrome on Android. The attack, dubbed "In-Browser Ransomware," requires no native payload, browser exploit, or root access.
This research explores how AI can generate novel browser-based ransomware techniques. It shows that DeepSeek connected AI hallucinations with real browser capabilities to create a plausible attack using the File System Access API. The technique is particularly concerning on Android, where photo directories can be accessed after user approval via a fake AI image enhancement prompt.
Research by: Alexey Bukhteyev Key Takeaways AI can turn high-level malicious ideas into concrete techniques, and can independently design and implement...