Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This research explores how AI can generate novel browser-based ransomware techniques. It shows that DeepSeek connected AI hallucinations with real browser capabilities to create a plausible attack using the File System Access API. The technique is particularly concerning on Android, where photo directories can be accessed after user approval via a fake AI image enhancement prompt.
Unit 42's analysis of phantom squatting reveals how attackers exploit LLM domain hallucinations to register domains that AI models falsely generate. These hallucinated domains become vectors for software supply chain attacks when developers use AI-generated code without verification.
Unit 42's analysis of phantom squatting reveals how attackers exploit LLM domain hallucinations to register domains that AI models falsely generate. These hallucinated domains become vectors for software supply chain attacks when developers use AI-generated code without verification.
This article discusses how attackers can exploit AI hallucinated domain names to perform phantom squatting. By registering domains that large language models incorrectly generate, attackers can target software supply chains.
WeLiveSecurity's June 2026 edition with Tony Anscombe covers critical security topics including three-day patching deadlines becoming regulatory mandates, exposed fuel-tank OT systems, billion-dollar cyber scams, and social media bans for children. The monthly roundup provides a broad view of the evolving security and policy landscape.
This article covers key cybersecurity events from June 2026, including urgent patching deadlines, vulnerabilities in fuel-tank systems, and social media restrictions for children. Tony Anscombe discusses these topics to highlight emerging threats and regulatory responses.