AI Crawlers Surge on Bank Websites, Radware Data Shows
Traffic from AI training and retrieval bots on financial services sites jumped more than 50% in a single month during the first quarter, new Radware data shows.
RedHook Android Trojan Resurfaces with Root-Level Upgrade
A resurfaced Android banking trojan now hijacks a legitimate developer tool to grant itself system-level access without tricking users into rooting their phones.
Cracks in Claude Code, Cursor, Amazon Q, Codex Expose ‘Trust Boundaries’
Separate disclosures from Wiz and the AI Now Institute this week exposed two different ways attackers can push…
Critical Blocksy WordPress Plugin Bug Lets Attackers Skip Login Entirely
A double-extension trick — naming a file shell.woff2.php — is enough to bypass validation and run code as the web server.
GitHub AI Agent Bug Let Attackers Leak Private Code
One word - "Additionally" - was enough to defeat GitHub's guardrails and expose private repository contents to the open web.
Freight Phishing Attack Disables Windows Defender, Delivers CrySome RAT
A fake rate-confirmation email triggers a five-stage attack that disables Windows Defender and steals browser passwords.
NVIDIA Patches Critical Auth Bypass in AIStore Framework
NVIDIA has addressed a critical authentication-bypass vulnerability in its AIStore framework, which could enable data tampering and system disruptions, urging immediate updates.
AI Model Invents Working Browser-Based Ransomware Technique
Check Point says DeepSeek paired a hallucinated malware request with a real Chrome API.
WinRAR Patches Critical Flaw Enabling Remote Code Execution
CVE-2026-14191 hits RAR5 recovery-volume handling; no auto-update means the fix is on users to install.
Identity Tech Meets the Fourth of July: Your Digital Papers, Please
Elizabeth Garber’s warning to the identity industry is blunt: Better digital ID may expand rights. Built badly, it may also make rights easier to revoke.