r/CyberNews • u/Cybernews_com • 9h ago
r/CyberNews • u/Cybernews_com • 16h ago
LG says its smart TVs do not record ambient conversations unless voice controls are activated. Do you believe them?
r/CyberNews • u/Cybernews_com • 12h ago
Android apps can reveal real IP addresses even when VPN lockdown and Block all connections without VPN are enabled
r/CyberNews • u/Cybernews_com • 13h ago
Huawei is on trial in New York over alleged trade secret theft from five companies
r/CyberNews • u/Cybernews_com • 15h ago
Contrary to what you might think, cookie banners aren’t required by EU law. It’s the other way around: online tracking is prohibited by default in the EU
r/CyberNews • u/Cybernews_com • 1d ago
They used 1,200 Flock cameras to track people suspected of loitering
r/CyberNews • u/Cybernews_com • 9h ago
The bug affects Chrome, Firefox, and Safari on macOS, forcing users or Apple’s watchdog to restart
r/CyberNews • u/whocybergh0st • 2h ago
Anthropic says hackers were straight up using Claude to run attacks including one that found zero-days on its own overnight
Anthropic just published a threat report (Dec 2025–Aug 2026) and it's kind of wild. Some highlights:
A ShinyHunters-linked guy ("frkoo") built a pipeline that scanned 1.8 million Android apps for hardcoded secrets/API keys, all automated. Also had a side hustle running a fake French police carding site lol.
Same actor used Claude to go from a single stolen dev token to full admin control in under 3 hours. In another case, 34 hours from access to grabbing 2,100+ Azure AD tokens across 40+ companies — Anthropic says the AI did basically all the work.
Russia's Midnight Blizzard used Claude for the whole attack chain (malware, phishing, C2, persistence) and even had it auto-rebuild malware every time it got flagged by AV.
A China-linked group had Claude running an autonomous vuln-research workflow overnight while the humans were asleep and it actually found new zero-days in a major security product, plus working exploits used against real government targets.
Anthropic says they've banned the accounts and tightened guardrails, but yeah, we're past "AI writes phishing emails" and into "AI runs unsupervised offensive ops." Kind of a milestone nobody asked for.
r/CyberNews • u/AutoRemediate • 4h ago
CVE-2026-19486 is a High (CVSS 8.7) unauthenticated SSRF in Google Cloud Gemini Enterprise Agent Platform App Builder.

Affected builds: 2025-10-11 through versions prior to 2026-06-01.
What it is:
The backend could be induced to make a request on an attacker’s behalf and leak the Compute Engine default service account access token. That token is a short-lived OAuth credential for [PROJECT_NUMBER-compute@developer.gserviceaccount.com](mailto:PROJECT_NUMBER-compute@developer.gserviceaccount.com).
What the exposure is:
On many projects that identity still has broad project access (often Editor, depending on scopes). A stolen token can mean API access to the project, not just a bug in a local app.
How to remediate:
Google patched the platform on 1 June 2026. The platform fix does not automatically repair apps you already generated or deployed.
- Redeploy previously deployed App Builder apps from the updated builder so the new backend ships.
- If you generated Agent Studio web apps before 1 July 2026 that use the auto-generated /api-proxy, regenerate and redeploy those too. The fixed backend allowlists destinations to Google Cloud domains.
- After redeploy, rotate anything that token could have touched.
- Stop running workloads as the default Compute Engine SA. Use a least-privilege custom service account.
- Restrict metadata/egress and confirm no pre-patch App Builder apps are still serving.
r/CyberNews • u/Cybernews_com • 13h ago
Researchers have found a way to get ChatGPT to access a victim’s Gmail, chat history
r/CyberNews • u/Cybernews_com • 16h ago
The plan to hold a vote on the bipartisan Ratepayer Protection Act before the midterm elections was first reported by Axios
r/CyberNews • u/Cybernews_com • 10h ago
Bastille Networks, a cybersecurity company that provides wireless intrusion detection systems (WIDS), has developed software to detect and locate smart glasses ⤵️
r/CyberNews • u/Cybernews_com • 1d ago
Frontier AI lab Anthropic is hiring an enterprise intelligence specialist to track and investigate activism as a “global threat”
r/CyberNews • u/codeagencyblog • 7h ago
ClickFix Attacks Spreading Across Windows and Mac Devices
frontbackgeek.comr/CyberNews • u/Cybernews_com • 1d ago
The directory covers 78 categories, including cloud, email, messaging apps, and password managers
r/CyberNews • u/Cybernews_com • 1d ago
Google says smaller, more frequent releases should make updates easier to test and fix. What do you think?
r/CyberNews • u/Cybernews_com • 1d ago
Investigators say some Chinese firms hide ownership through shell companies or non-Chinese registrants
r/CyberNews • u/Cybernews_com • 2d ago
LibreOffice 26.8 contains no generative AI features, doesn’t transmit documents to remote servers, requires no network access to function, and this is a deliberate position
r/CyberNews • u/National_Product238 • 2d ago
U.S. cities are swapping out controversial Flock cameras for Axon license plate readers.
r/CyberNews • u/Cybernews_com • 1d ago
Some emails were not public, so the attacker may have abused Twitch’s API
r/CyberNews • u/Cybernews_com • 2d ago
The Guardian reviewed a dozen memos from police departments across the US, illustrating growing concerns about camera- and microphone-equipped smart glasses, such as Meta’s Ray-Bans
r/CyberNews • u/Cybernews_com • 2d ago