Researchers have discovered methods to bypass Windows 11's strongest security defenses without physical access to the machine, though the attack requires the attacker to already possess privileged system access. Last week also saw reports of records allegedly stolen from Azure tenants and Medusa ransomware targeting over 500 organizations, along with law enforcement actions against cybercrime operations.
The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.
TikTok has agreed to pay $400 million to settle a U.S. Department of Justice lawsuit alleging violations of child privacy laws, with $300 million due immediately and the remaining $100 million conditional on vacating a prior consent decree. The settlement resolves claims brought against ByteDance's social media platform in 2024 for its handling of children's personal data.
Three banking trojans are currently active threats: Manic, which incorporates spyware capabilities; Grandoreiro, which maintains persistent campaigns targeting victims in Latin America and Europe; and ToxicPanda 2.0, an expanded variant of the ToxicPanda malware. Security professionals should monitor these banking trojans as they demonstrate ongoing development and geographic targeting sophistication.
Attackers are increasingly focusing on CI/CD pipelines and developer tools rather than application code itself, exploiting gaps in the software development lifecycle supply chain. Organizations need comprehensive visibility across their entire SDLC and implement rigorous security controls to defend these overlooked but critical infrastructure components.
The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii), the subsequent study states, a species that is part of a 20-strong flying squid family that was known to leap from the water but, until then, was only rumoured to also be able to glide above it. The neon flying squid was able to gain such elevation by using the hyponome, a funnel-like muscular organ also present in other cephalopods, such as octopuses. The organ is able to force water out in a jet, propelling the body along both in and out of the sea. Photographs of the gliding squid show them with their arms (they have 10 limbs in all) splayed outwards. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop.
Researchers discovered 14 malicious npm packages disguised as calendar and streak utilities that deliver RedC2 4.0, an AI-powered Linux backdoor to infected systems. Upon installation, the trojanized packages extract and execute a bundled binary as a background process to establish command and control. This supply chain attack demonstrates how legitimate package repositories remain a vector for distributing sophisticated implants with AI-assisted capabilities.
OWASP has released a new top 10 security list designed for the current threat landscape, introducing a Universal Skill Format to standardize and enhance security practices around AI integrations. The framework aims to address the distinct risks associated with AI implementations across development and deployment environments.
Researchers have successfully used AI models to generate synthetic bacteriophage genomes, with 16 of 285 designs synthesized and tested in E. coli proving viable and some more effective than the natural ΦX174 strain at destroying bacteria. While this demonstrates promising applications for phage therapy and biological research, the capability to design functional viral genomes raises significant biosecurity concerns about potential misuse of AI-generated pathogens.
The newly-formed Nakasone Group will counsel government leaders, corporations, prominent families, and other private clients confronting cybersecurity, geopolitical, and personal security risks. The post Former NSA Director Paul Nakasone Launches National Security Advisory Firm appeared first on SecurityWeek.
Check Point Research has disclosed a technique leveraging Microsoft Defender's legitimately signed BTR.sys boot-time remediation driver to perform arbitrary kernel-level file and registry operations across Windows 7 through Windows 11 25H2 without exploiting any software vulnerability. The attack requires no external drivers or patches, instead weaponizing the trusted boot-time removal tool already present on affected systems. This capability allows attackers to delete security software and other protected files during the boot process before standard security mechanisms can intervene.
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. "The malware spread through the built-in updaters of