Stay Ahead with Exclusive Updates!
Enter your email below and be the first to know what’s happening in the ever-evolving world of technology!
What's Hot
Author: precious
I’m Precious Amusat, Phronews’ Content Writer. I conduct in-depth research and write on the latest developments in the tech industry, including trends in big tech, startups, cybersecurity, artificial intelligence and their global impacts. When I’m off the clock, you’ll find me cheering on women’s footy, curled up with a romance novel, or binge-watching crime thrillers.
Researchers Found an Attack Spreading Through GitHub Like a Parasite. They Named It Cordyceps and It Is Already in 300+ Repositories
Novee Security has confirmed that a vulnerability pattern its researchers call Cordyceps leaves more than 300 GitHub repositories open to full attacker takeover, including projects run by Microsoft, Google, Apache and Cloudflare. The firm scanned roughly 30,000 high impact repositories, flagged 654 of them in a single automated pass, and confirmed that more than 300 were fully exploitable through attacker controlled code execution, credential theft or outright supply chain compromise. Researchers named the pattern after the parasitic fungus known for slowly taking over its host from the inside, since the flaw burrows into software development pipelines in a similar way.…
Hackers Were Inside Cisco’s SD-WAN for Months Before Anyone Noticed. Now CISA Is Forcing Every Company to Patch It
An unnamed communications service provider’s Cisco SD-WAN infrastructure sat under a threat actor’s root level control for months and its own administrators never noticed. Google-owned threat intelligence firm Mandiant disclosed this intrusion last month, tracing the attacker’s full path through a vulnerability now tracked as CVE-2026-20245. It is important to note that Cisco built the software and is not the party that was breached. The flaw only lived inside Cisco’s SD-WAN products, and the actual intrusion took place in a customer’s network of an unnamed service provider that had deployed those products to run its own infrastructure. Mandiant investigated that…
Anthropic Says Chinese Rival Alibaba Copied Claude at Scale. Here Is What Model Extraction Actually Means and Why It Matters
Anthropic has accused Alibaba’s Qwen AI lab of running fake accounts to extract Claude’s capabilities at scale, telling the U.S. Senate Banking Committee that operators linked to Alibaba generated 28.8 million exchanges with Claude through roughly 25,000 fraudulent accounts. The AI safety company calls it the largest “distillation attack” it has documented to date. The accusation was sent in a letter to Senators Tim Scott and Elizabeth Warren as seen by Bloomberg, Reuters, and CNBC. Alibaba has not formally responded to the Senate committee, although its stated position to reporters is that it does not use outputs from proprietary AI…
OpenAI Just Built the One Thing That Could Make It Stop Depending on Nvidia. Here Is What Its First Custom Chip Does
OpenAI has built its first chip from the ground up and it does one specific job – handling ChatGPT and Codex requests without routing every one of them through Nvidia hardware. Called Jalapeño, the chip was developed with Broadcom and marks OpenAI’s entry into a group that every other major AI lab joined years ago, the group of companies that design their own silicon instead of buying all of it from outside vendors. What Jalapeño Does Jalapeño is an ASIC (Application-Specific Integrated Circuit), which means it was built to do one job well rather than many jobs adequately. And this…
Norway Just Banned AI in Elementary Schools. The Country That Already Removed Smartphones From Classrooms Is Now Drawing the Firmest Line Any Government Has Set Between AI and Children.
Norway’s Prime Minister Jonas Gahr Støre has announced that generative AI tools are now off-limits for elementary school students across the country, effective from the new school year beginning in late August. The ban applies to students in first through seventh grade, covering ages 6 to 13, and the decision makes Norway one of the first countries in the world to formally prohibit AI use at that level of education. This means students in lower secondary school, aged 14 to 16, can use generative AI only under a teacher’s direct supervision, while older students aged 17 to 19 are encouraged…
Britain’s Cyber Agency Just Warned That AI-Generated Code Could Trigger the Next Wave of Catastrophic Security Failures. The Advisory Names Vibe Coding Directly and It Is Not a Mild Caution.
The UK’s National Cyber Security Centre (NCSC) has published a formal guidance post telling developers and organisations exactly how much trust to place in AI-generated code, which is otherwise called vibe coding. Written by Toby W, a Principal Security Architect at the NCSC, the blog post lays out what the agency is calling a “vibe coding spectrum,” a framework for how organisations should calibrate their use of AI-assisted software development depending on the risk attached to what they are building. This post is the NCSC’s most practical intervention yet on vibe coding, and it arrives as AI coding tools have…
North Korea Compromised 144 AI Developer Packages in 88 Minutes Without Touching a Single Line of Source Code. The Mastra Attack Is the Most Targeted Supply Chain Strike Against AI Development Tools Ever Documented.
North Korea’s Sapphire Sleet hacking group compromised 144 packages in the Mastra AI framework’s npm scope in a single 88-minute automated campaign. Developers who ran a standard install command during that window may have handed a foreign state actor their cloud credentials, LLM API keys, and cryptocurrency wallet data without any visible warning. Microsoft attributed the attack with “high confidence” to Sapphire Sleet, also tracked as BlueNoroff, a North Korean state actor that primarily targets the financial sector. What Mastra Is and Why It Was Targeted Mastra is an open-source TypeScript AI agent framework with over 1.1 million combined weekly…
A Criminal Group Now Holds Working Credentials for More Than 70,000 Fortinet Firewalls Across 194 Countries and Is Still Active. Accenture, Oracle, Samsung and PwC Are Among the Named Victims of FortiBleed.
Security researchers have identified an active, large-scale credential compromise campaign affecting Fortinet FortiGate firewalls, which has been dubbed FortiBleed. According to Hudson Rock, the dataset contains 73,932 unique firewall URLs across 194 countries and impacts 21,632 unique domains. The number of compromised devices stands at 86,644 as of June 19, 2026, according to data from SOCRadar. And the group behind it is still adding new victims. The dataset was surfaced on June 17, 2026 by security researcher Volodymyr “Bob” Diachenko and verified by Hudson Rock, SOCRadar, Arctic Wolf, and Kevin Beaumont. Among the organizations Hudson Rock says appear in the…
A Dataset of 24 Billion Stolen Usernames and Passwords Just Surfaced Online. Researchers Are Already Calling It the Largest Credential Exposure of 2026.
Cybersecurity researchers at Cybernews recently discovered an exposed database containing roughly 24 billion stolen credential records, making it one of the largest collections of stolen login data ever found on the internet. The records, stored in more than 8.3 terabytes of data, included usernames, email addresses, plaintext passwords, and the login URLs the credentials were meant to unlock. The database was hosted on a publicly accessible Elasticsearch cluster, meaning anyone who knew where to look could browse its full contents without any login or authentication. After the original report was published, researchers learned that the dataset belonged to a threat…
SpaceX Just Signed a $6.3 Billion Compute Deal With Reflection AI. A Company That Went Public to Build Rockets Is Quietly Becoming the Infrastructure Backbone of the Frontier AI Race.
SpaceX has signed a computing power deal worth up to $6.3 billion with Reflection AI, the open-source artificial intelligence startup founded by former Google DeepMind researchers. Under the agreement, Reflection will pay $150 million per month beginning July 1, 2026, for access to Nvidia GB300 chips at SpaceX’s Colossus 2 data center near Memphis, Tennessee. The contract runs through the end of 2029, although both parties can exit with 90 days’ notice after the first three months. The deal adds Reflection to a growing list of outside companies renting compute capacity from SpaceX, following earlier agreements with Anthropic, Google, and…
