Cambridge researchers used lab-grown human brain and spinal cord tissues to uncover a hidden mechanism that blocks nerve repair. By reversing that biological brake, they restored the ability of damaged nerve fibers to regrow.
Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called FlutterShell.
According to Palo Alto Networks Unit 42, the campaign is said to be the next stage of a previously reported activity cluster dubbed JSCoreRunner (aka FileRipple) in late August 2025. The cybercrime group behind the two attack chains is being tracked under the moniker CL-CRI-1089. The attackers are assessed to be active since at least 2023.
“Built using the Flutter framework, FlutterShell infects targets with adware via malicious desktop applications,” Unit 42 said. “In addition to its adware functionality, the payload possesses backdoor capabilities, including shell command execution and file system manipulation.”
Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root.
It is tracked as CVE-2026–20230, and proof-of-concept exploit code is already public. Cisco’s PSIRT says it has not seen the flaw used in attacks yet. The PoC shortens that runway.
The flaw is a server-side request forgery. Unified CM and its Session Management Edition fail to validate certain HTTP requests properly, so a crafted request can push the server into writing arbitrary files onto the underlying OS. Those files are the foothold. Cisco says they can be used later to escalate to root, the top privilege on the system.
Brave Software has announced the public release of Origin, a paid minimalist, bloat-free version of its browser that strips out cryptocurrency, AI, rewards, and other monetization-focused features.
The browser maker says Brave Origin is designed for users who want a more streamlined, privacy-focused browser without the company’s optional revenue-generating services and integrations.
“Today, Brave is announcing the release of Brave Origin, a paid version of the browser for users who don’t need all of Brave’s out-of-the-box features, but still want the privacy that only Brave offers,” the company explains.
The Windows version of the Hola Browser has been compromised in a supply chain attack that delivered an undeclared executable identified by researchers as a cryptocurrency miner.
The compromise was uncovered during periodic certification checks on Hola Browser as part of its AppEsteem certification testing procedure, which it had previously passed.
Hola is an Israeli company best known for Hola VPN, a service that allows users to route internet traffic through other users’ devices or through paid proxy infrastructure to bypass geographic restrictions and access content from different countries.
Gov. Jared Polis on Thursday declared a statewide drought emergency, citing the record-low snowpack and prolonged warmer temperatures across Colorado.
He also activated the next phase of the state’s drought response plan. Polis had placed Colorado under Phase 2 in March.
“Today, I am issuing a statewide drought emergency to support Coloradans, our economy, farmers and ranchers, and outdoor enthusiasts in the face of one of the most severe droughts in Colorado’s recorded history. With every county in the state experiencing drought conditions, activating Phase 3 of our Drought Response Plan allows us to better coordinate agencies, prepare for worsening conditions, and support Colorado communities, agriculture, water users, and our environment,” he said in a statement. “State agencies will do their part to reduce water usage at state facilities and I encourage every Coloradan to use water wisely.”