Deepfake Voice Attacks are Outpacing Defenses: What Security Leaders Should Know
Deepfake voice attacks outpace defenses, enabling CEO fraud and authentication bypass. Most organizations lack countermeasures against synthetic voice impersonation.
ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know
The full HackWire archive — 3,892 stories, newest first.
Deepfake voice attacks outpace defenses, enabling CEO fraud and authentication bypass. Most organizations lack countermeasures against synthetic voice impersonation.
Medtronic disclosed a 9 million-record breach affecting the medical device sector globally. The incident raises critical security concerns for an industry where device integrity directly impacts patient care.
OpenSSH had a 15-year-old authentication bypass flaw where comma characters in certificate principals were misinterpreted as list separators, allowing attackers root access. The code reuse vulnerability went undetected despite widespread deployment.
An incomplete Windows security patch enables zero-click attacks by Russia-linked APT28, allowing code execution without user interaction and actively targeting Ukraine and EU nations.
Frontier LLMs could enable autonomous cyberattacks that adapt in real time, making traditional cybersecurity defenses harder to predict and block. Researchers argue these same AI capabilities offer equal defensive opportunities for organizations willing to evolve.
Researchers uncovered fast16, a malware framework targeting industrial control systems that operated five years before Stuxnet, pushing back the timeline of advanced nation-state cyber sabotage to the early 2000s. The modular framework, active from 2004-2010, exhibited capabilities similar to Stuxne
A 22-year-old California resident received a 70-month federal prison sentence for laundering $230 million in stolen cryptocurrency by routing funds through multiple digital wallets to obscure their origin. The case demonstrates law enforcement's increasing ability to trace illicit crypto transaction
Romance scams cause $1.3B+ in annual losses, yet victims lack support and fear shame reporting. The article demands coordinated action from law enforcement, financial institutions, and government to address this emotionally devastating crime.
Researchers identified 73 malicious VS Code extensions on Open VSX spreading GlassWorm v2 spyware to steal developer credentials, source code, and project data. The extensions mimic legitimate tools to exploit developer trust.
PhantomCore conducts sustained cyberattacks on Russian TrueConf servers since September 2025, exploiting three chained vulnerabilities for unauthenticated remote code execution and data exfiltration.
Mythos AI discovers vulnerabilities 10x faster than traditional tools, forcing a remediation crisis. Organizations now face thousands of actionable findings while remediation capacity remains fixed—creating dangerous operational debt they cannot manage.
Microsoft Outlook.com experienced a widespread outage affecting authentication and mailbox access for millions of users globally. The incident caused sign-in failures and email loading issues across multiple regions, impacting 400+ million active users while Microsoft investigated the root cause.
A Firefox vulnerability (CVE-2026-6770) enables attackers to fingerprint and identify Tor users, compromising their anonymity without requiring special permissions or user interaction. Patched in Firefox 150 and Tor Browser 15.0.10, users should update immediately to prevent targeted surveillance.
Criminals use fake CAPTCHA prompts to trick users into sending premium-rate SMS to high-cost international numbers, generating millions through silent mobile billing charges ($15-$20 per message). The scheme scales via 120 Keitaro landing pages and IaaS platforms to systematically exploit telecom in
Romance scams drain over $1 billion from Americans annually, leaving victims struggling without institutional support. Security experts and law enforcement are calling for unprecedented coordination between banks, government agencies, and law enforcement to help victims navigate fragmented systems a
Itron disclosed a breach of internal IT systems but has contained it and is investigating with external experts, highlighting ongoing vulnerabilities in critical utility infrastructure serving millions of customers.
Microsoft revamped the Windows Insider Program to address Windows 11 performance and stability issues. The upgrade enhances feedback tools, enabling Insiders to report detailed performance metrics and bugs more effectively.
Threat actors use Microsoft Teams to deliver 'Snow' malware, exploiting weaker defenses than email. Spoofed accounts send malware-laden messages disguised as IT updates to hundreds of organizations.
GopherWhisper, a Chinese APT, targets governments using legitimate services and custom Go-based malware. Their abuse of trusted infrastructure minimizes detection while maintaining persistence across compromised networks.
**Summary:** A 2005 malware called 'fast16' targeted Iran's nuclear enrichment—predating Stuxnet by years. The discovery reveals an earlier cyber sabotage campaign against Iran's nuclear facilities, suggesting sophisticated cyberwarfare operations began well before the infamous 2010 Stuxnet attack.
CISA added four exploited vulnerabilities to its KEV catalog and enforced a May 2026 deadline for federal agencies to patch all known flaws. Non-compliance risks funding loss, audit failures, and contract termination.
ADT confirmed a data breach after ShinyHunters extortion group threatened to release stolen customer data for ransom. The breach highlights vulnerabilities in residential security infrastructure targeted by criminal extortion operations.
Microsoft expanded Active Hours to 18 hours daily with per-day customization, letting users better control Windows restart timing—addressing years of frustration with forced updates disrupting work.
Firestarter malware targets Cisco firewalls and survives security patches, enabling persistent network access and lateral movement into critical infrastructure. U.S. and U.K. cybersecurity agencies warn organizations that this sophisticated threat represents a major vulnerability in firewall perimet