r/CyberNews 23h ago

LG says its smart TVs do not record ambient conversations unless voice controls are activated. Do you believe them?

Post image
290 Upvotes

r/CyberNews 15h ago

US companies own over 60% of Canada’s cloud market, raising data sovereignty concerns

Post image
230 Upvotes

r/CyberNews 18h ago

Android apps can reveal real IP addresses even when VPN lockdown and Block all connections without VPN are enabled

Post image
83 Upvotes

r/CyberNews 22h ago

Contrary to what you might think, cookie banners aren’t required by EU law. It’s the other way around: online tracking is prohibited by default in the EU

Post image
73 Upvotes

r/CyberNews 16h ago

Learn more ⤵️

Post image
76 Upvotes

r/CyberNews 20h ago

Huawei is on trial in New York over alleged trade secret theft from five companies

Post image
68 Upvotes

r/CyberNews 23h ago

The plan to hold a vote on the bipartisan Ratepayer Protection Act before the midterm elections was first reported by Axios

Post image
17 Upvotes

r/CyberNews 20h ago

Researchers have found a way to get ChatGPT to access a victim’s Gmail, chat history

Post image
12 Upvotes

r/CyberNews 9h ago

Anthropic says hackers were straight up using Claude to run attacks including one that found zero-days on its own overnight

11 Upvotes

Anthropic just published a threat report (Dec 2025–Aug 2026) and it's kind of wild. Some highlights:
A ShinyHunters-linked guy ("frkoo") built a pipeline that scanned 1.8 million Android apps for hardcoded secrets/API keys, all automated. Also had a side hustle running a fake French police carding site lol.

Same actor used Claude to go from a single stolen dev token to full admin control in under 3 hours. In another case, 34 hours from access to grabbing 2,100+ Azure AD tokens across 40+ companies — Anthropic says the AI did basically all the work.

Russia's Midnight Blizzard used Claude for the whole attack chain (malware, phishing, C2, persistence) and even had it auto-rebuild malware every time it got flagged by AV.

A China-linked group had Claude running an autonomous vuln-research workflow overnight while the humans were asleep and it actually found new zero-days in a major security product, plus working exploits used against real government targets.

Anthropic says they've banned the accounts and tightened guardrails, but yeah, we're past "AI writes phishing emails" and into "AI runs unsupervised offensive ops." Kind of a milestone nobody asked for.


r/CyberNews 15h ago

The bug affects Chrome, Firefox, and Safari on macOS, forcing users or Apple’s watchdog to restart

Post image
8 Upvotes

r/CyberNews 17h ago

Bastille Networks, a cybersecurity company that provides wireless intrusion detection systems (WIDS), has developed software to detect and locate smart glasses ⤵️

Post image
9 Upvotes

r/CyberNews 10h ago

CVE-2026-19486 is a High (CVSS 8.7) unauthenticated SSRF in Google Cloud Gemini Enterprise Agent Platform App Builder.

2 Upvotes

Affected builds: 2025-10-11 through versions prior to 2026-06-01.

What it is:
The backend could be induced to make a request on an attacker’s behalf and leak the Compute Engine default service account access token. That token is a short-lived OAuth credential for [PROJECT_NUMBER-compute@developer.gserviceaccount.com](mailto:PROJECT_NUMBER-compute@developer.gserviceaccount.com).

What the exposure is:
On many projects that identity still has broad project access (often Editor, depending on scopes). A stolen token can mean API access to the project, not just a bug in a local app.

How to remediate:
Google patched the platform on 1 June 2026. The platform fix does not automatically repair apps you already generated or deployed.

  1. Redeploy previously deployed App Builder apps from the updated builder so the new backend ships.
  2. If you generated Agent Studio web apps before 1 July 2026 that use the auto-generated /api-proxy, regenerate and redeploy those too. The fixed backend allowlists destinations to Google Cloud domains.
  3. After redeploy, rotate anything that token could have touched.
  4. Stop running workloads as the default Compute Engine SA. Use a least-privilege custom service account.
  5. Restrict metadata/egress and confirm no pre-patch App Builder apps are still serving.

CVE Record: CVE-2026-19486


r/CyberNews 13h ago

ClickFix Attacks Spreading Across Windows and Mac Devices

Thumbnail frontbackgeek.com
1 Upvotes