Toggle light / dark theme

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29.

The activity was previously disclosed in a report from cybersecurity company ReliaQuest, which detailed how the attacker changed DNS settings on Wi-Fi devices to steal Microsoft 365 accounts.

Besides attributing the campaign to Russian hackers tracked as Storm-2945 — a sub-cluster of Midnight Blizzard, Microsoft identified two malware families called CornFlake and ChocoShell with capabilities for persistent access, credential theft, surveillance, and data exfiltration.

New Pass-ta-key attacks let malware hijack Google-synced passkeys

Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager’s synced passkeys to take over accounts, bypass user verification, and extract passkey private keys.

Passkeys are a passwordless authentication method that uses cryptographic keys stored on a user’s device to sign in to online accounts.

They are considered safer than passwords because they cannot be guessed, reused, or easily stolen through phishing, while also allowing users to authenticate with a PIN or biometrics, such as a fingerprint or facial recognition.

New DOUBLECUP ClickFix service hides malware in browser cache images

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.

SOCRadar’s Threat Research Unit says DOUBLECUP has operated since early June 2026, providing customers with licenses and a Go-based Windows tool for creating malicious campaigns and generating the code operators add to their websites.

The service handles much of the infrastructure required to conduct the attacks, including hosting the steganographic PNG images, managing session and signal endpoints, providing encryption keys, and automatically rebuilding payloads.

Hidden prompts can plant false memories in AI agents, researchers warn

Large language models (LLMs), the computational algorithms underpinning ChatGPT, Gemini and other artificial intelligence (AI)-powered conversational platforms, are now widely used worldwide. These models can rapidly answer questions, source information online, assist users with specific tasks and produce text tailored for specific purposes.

Over the past few years, computer scientists have introduced a wide range of LLMs, some of which can also complete tasks autonomously and take actions on a user’s behalf, for instance, answering messages, scheduling online appointments or updating programming code. More recently, they have also provided many of these models with memory, as this allows them to tailor responses around a user’s typical preferences or earlier requests without repeatedly receiving the same information.

While memory-enhanced AI agents have notable advantages and could better meet the needs of individual users, they also pose new security risks. Researchers at New Mexico State University recently described a cyberattack that secretly poisons an AI agent’s long-term memory, which they dubbed GhostWriter. Their paper, published on the preprint arXivserver, introduces two promising strategies that could help prevent or limit the risk of this attack without adversely affecting an AI agent’s performance.

Arch Linux disables AUR package adoption to stop malware flood

The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages.

The decision was announced on the distribution’s mailing list by contributor Robin Candau, who said that the situation is temporary until a solution is found.

“Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation,” announced Candau.

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors.

A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or user-initiated download. The Korea Internet & Security Agency (KISA) says AnySign4PC versions 1.1.4.4 through 1.1.4.6 are affected and lists version 1.1.5.0 as the fixed release. It recommends deleting vulnerable installations.

AhnLab refers to two exploited products only as financial-security software A and I. Its report does not disclose their identities, affected or fixed versions, or vulnerability identifiers.

Analog Devices discloses data breach, says operations unaffected

American semiconductor company Analog Devices announced that an unauthorized party accessed some of its systems and exfiltrated certain files.

The company detected the incident on June 23 and reacted by activating its incident response protocols to limit the breach. External cybersecurity experts have been contracted to assist with the containment and investigation activities.

Currently, there are no details about the type of data that has been compromised.

Google says AI helped Chrome fix 1,072 security bugs in two releases

Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser’s two most recent releases as it expands its use of AI.

According to Google, Chrome 149 and Chrome 150 fixed 1,072 security bugs, surpassing the total number fixed across the previous 23 Chrome milestones combined.

The company says it now uses large language models throughout the vulnerability management process, including discovering flaws, reproducing reports, determining severity, assigning bugs to developers, generating candidate patches, and creating tests.

/* */