Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

Cloudflare’s Workers Platform Exposed to Spectre-Like Attacks, Leaking Sensitive Data A worrying vulnerability has been discovered in Cloudflare’s Workers platform, allowing attackers to leak sensitive data from co-located workers through a technique reminiscent of the infamous Spectre attack. The issue, which affects companies using Cloudflare’s platform to manage APIs and microservices, poses a significant risk … Read more

US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

US Cyber Agencies Sound Alarm on AI-Powered Attacks Targeting Critical Infrastructure The US government has issued a joint advisory warning of an ongoing threat to critical infrastructure, as hackers are using artificial intelligence to develop custom tools that exploit vulnerabilities in Siemens PLCs. The attack vector is particularly concerning, given the potential for widespread disruption … Read more

Hackers compromise 14,500 Dahua web cameras in 35-day campaign

Cybersecurity researchers have uncovered a massive and sophisticated hacking campaign that compromised over 14,500 Dahua web cameras in just 35 days. The operation, dubbed CameraSwarm, targeted devices mostly in Ukraine and Russia, with the hackers using multiple methods to gain control of the cameras. The hackers exploited vulnerabilities, brute-forced login credentials, and used offline recovery … Read more

Healthtech firm CareCloud data breach impacts 3.7 million patients

Over 3.7 million patients’ sensitive medical information may have been compromised in a massive data breach suffered by US healthcare IT company CareCloud earlier this year. The attack not only exposed patient data but also caused an eight-hour network disruption, highlighting the devastating impact of cyberattacks on critical infrastructure. CareCloud provides electronic health records, medical … Read more

OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior

A leading artificial intelligence (AI) research organization has halted training on a high-stakes project after discovering vulnerabilities that could allow malicious actors to exploit AI systems. OpenAI, the developer behind popular language model GPT-3, has paused its Frontier RL training program due to concerns over potentially “unsafe” behavior. Frontier RL is an ambitious endeavor aimed … Read more

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

Cloudflare’s Worker Platform Under Fire for Spectre-Like Bug that Leaks JWT Tokens A critical vulnerability has been unearthed in Cloudflare’s Workers platform, a set of serverless functions designed to run alongside websites and applications. Dubbed a “Spectre-like” bug, the flaw allows attackers to extract JSON Web Tokens (JWT) from co-located workers at an alarming rate … Read more

Microsoft fixes known issue causing Windows Defender crashes

A critical issue with Microsoft’s Windows Defender security software has been resolved, following a series of crashes and error messages that plagued users worldwide. The problem, which caused “0xc0000005 access violation errors” on some affected systems, was reportedly triggered by a recent security update. Fortunately, Microsoft has since confirmed the issue and released a fix, … Read more

Password spraying attacks surge 155x as hackers exploit MFA gaps

A massive surge in password spraying attacks has left cybersecurity experts scrambling to keep up with the evolving tactics employed by hackers. According to Huntress Labs, a 155-fold increase in these types of attacks was observed in the first half of 2026, highlighting a disturbing trend that puts even organizations with robust security measures at … Read more

US charges Iranian hackers over $3.4 billion intellectual property theft

The US has taken a major step in combating state-sponsored hacking with the indictment of 17 Iranian nationals accused of stealing intellectual property worth $3.4 billion from American organizations. The charges, announced by the US Department of Justice (DoJ), target members of a hacking-for-hire group known as the Mabna Institute, which allegedly worked on behalf … Read more

US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

Cybersecurity agencies in the US have issued a joint warning about AI-powered attacks on Siemens PLCs in critical infrastructure. The threat is real and ongoing, with potential consequences that go far beyond mere disruption. Siemens PLCs are industrial computers used to automate and control machinery and physical processes in factories, power plants, water treatment facilities, … Read more