Google halts open-source bug bounty program amid AI spam surge
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. The company’s OSS VRP incentivizes security researchers to responsibly disclose security flaws across open-source projects maintained by Google, including Golang, Angular, Bazel, Protocol Buffers, Fuchsia, and critical third-party dependencies, as well as repository settings […]
Citrix patches NetScaler SAML zero-day exploited in attacks
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. The vulnerability is a memory buffer flaw affecting NetScaler ADC and NetScaler Gateway appliances using SAML authentication with Gateway or AAA […]
Anthropic asks Claude users to share voice data for AI model training
Anthropic has started asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. The new prompt appears when using Claude’s voice features and explicitly asks users to allow Anthropic to use their voice data for AI training. “Allow us to use your voice data to improve our AI […]
Google Gemini could soon get full access to your Mac’s files, apps and the web
Google’s Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. As spotted by TestingCatalog on X, Google is testing desktop control for Gemini, and there are references to a new hidden “Additional sandbox options” setting in the Gemini Desktop app. […]
ShinyHunters hacker reportedly detained in Jordan, aiding FBI
A suspected ShinyHunters hacking group member known online as “Rey” has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. According to Reuters, Jordanian authorities detained Rey, identified as Saif al-Din Khader, this week, with two sources saying he was taken into custody on […]
Danish university DTU breach exposes data of up to 200,000 people
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. ​The university says the attacker used compromised credentials to log into DTUBasen, its identity and access management (IAM) system, allowing access […]
Frontline Education breach exposes school district employee data
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. Frontline Education is an edtech company that provides administration and workforce management software and services used by school districts. Last night, a […]
Warlock ransomware breach SharePoint in water, telecom operator attacks
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. ​Over the past two months, the threat actor appears to have focused on countries speaking Portuguese and Spanish across Europe, Africa, and Latin America. The gang emerged in […]
GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. AI Gateway is a service that gives access to AI-native GitLab Duo features. While GitLab operates its own cloud-based AI Gateway instance used by GitLab.com, GitLab Self-Managed, and GitLab Dedicated, users can also […]
US sanctions Tren de Aragua gang members in ATM hacks crackdown
The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. In jackpotting attacks, criminals deploy malware (e.g., ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus) on bank and credit union […]