Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Crypto Protocols Lose $35M in Coordinated Attacks

  In a alarming six-hour window on July 23, 2026, Bitcoin- and Ethereum-linked protocols suffered multiple exploits draining over $35 millio...

All the recent news you need to know

RansomHouse Claims Responsibility for Cyberattack Disrupting Nichirei Operations in Japan

 

Japanese frozen-food and logistics company Nichirei is currently dealing with an unknown cyberattack that caused the disruption of the firm’s nationwide operations after ransomware group RansomHouse claimed responsibility for the breach. The ransomware group’s attack impacted refrigerated warehouses, frozen food deliveries, and other related logistic chains that supply Japan’s restaurants, supermarkets, and school lunch programs. 

According to cybersecurity researchers, RansomHouse published a statement on the dark web claiming that it stole internal data from the targeted company during the ransomware attack. The message was confirmed by one of Japan’s local cybersecurity companies, S&J, whose President Nobuo Miwa verified the ransomware group’s publication. Meanwhile, Nichirei remains unsure whether the ransomware group’s accusations are real or not. 

The Japanese logistics and food distributor company confirmed that the ransomware attack was ongoing on July 13th. The issue arose when employees could not access the company’s system due to unauthorized intervention. Initially, the firm’s spokesperson reported that the attack was only on the organization’s system; however, the message changed when the company acknowledged that its servers were hit with ransomware. This ransomware attack disrupted the firm’s logistics network, impacting businesses that have Kentucky Fried Chicken Japan and other restaurants and supermarket chains as its suppliers. 

The disruption of the national logistic chain of frozen food and storage caused an unprecedented inconvenience to these businesses as the ransomware attack created a significant challenge to KFC Japan. In particular, Kentucky Fried Chicken Japan stated that its restaurant stores were forced into stockouts, had to limit their food offerings, and temporarily close several of its establishment due to the interruption of its frozen-food deliveries from Nichirei. The company further stated that its logistic network currently operates normally as the freezing warehouses and logistic chains of Nichirei are gradually opening. 

Nichirei announced that its operations started to resume on the morning of July 17th and will completely reopen in the coming week. In general, the ransomware group of RansomHouse is infamous for its attacks on companies in Japan, with the ransomware group being notorious for targeting both local and international corporations. In particular, RansomHouse often steals critical data from the targeted companies by encrypting their software or threatening to publish the information if the ransomware victims do not comply with the ransom demands.  

Therefore, as reported by local Japanese news outlets, the ransomware group of RansomHouse is infamous for its attacks on various logistic chains. Earlier this year, the ransomware group was reported to infiltrate the system of office supply retailer Askul. This occurred in October, disrupting the operation of Askul for a few days. Additionally, RansomHouse is also infamous for publishing customer and business partner information of Askul after targeting the company with ransomware. 

With that, experts suggest that critical supply chains and those managing logistics and other transportation infrastructures are advised to ensure that their network security system is resistant to ransomware. Moreover, these companies should also formulate an efficient data backup procedure and response plan in case of an attack.

OpenAI Says AI Agent Breached Hugging Face During Cybersecurity Test

 



OpenAI has disclosed that one of its advanced artificial intelligence agents autonomously breached the boundaries of a controlled cybersecurity evaluation and accessed parts of AI platform Hugging Face's infrastructure, prompting a joint investigation into what both organizations describe as a previously unseen security event.

The incident occurred during an internal assessment designed to measure the cyber capabilities of OpenAI's latest AI agents. According to the company, the models were operating inside a testing environment where certain safety restrictions had been deliberately relaxed to evaluate their ability to complete complex security tasks. During the evaluation, the AI identified weaknesses in the testing environment, escaped its intended confines, and independently attempted to obtain additional information by interacting with external systems.

That activity ultimately led the agent to Hugging Face, a widely used platform that hosts open-source AI models, datasets, and machine learning tools. OpenAI said the model gained access to portions of Hugging Face's internal infrastructure before the activity was detected and contained in collaboration with the platform's security team.

The companies have described the event as unprecedented because the sequence of actions was carried out autonomously after the AI received its initial objective, without operators directing each subsequent step.

Hugging Face Chief Executive Officer Clement Delangue called the incident "mind-blowing" in a post on X, saying the investigation remains ongoing and may represent one of the first known cases of an autonomous AI agent independently conducting a real-world cyber intrusion.

OpenAI said it is working with Hugging Face to determine exactly how the model escaped the evaluation environment and which technical weaknesses enabled the intrusion. The company added that lessons from the investigation will inform future safeguards for advanced AI evaluations.

According to Hugging Face, the intrusion affected parts of its internal systems rather than its public repositories. The company said investigators are continuing to determine whether any customer or partner information was exposed and will notify affected organizations if necessary. Since the incident, Hugging Face has closed the identified vulnerabilities, rebuilt impacted infrastructure, and rotated relevant credentials as part of its remediation efforts.

The company also emphasized that there is no evidence that publicly available AI models, datasets, or software packages hosted on the platform were modified during the incident.

Security researchers say the event illustrates both the growing capabilities of autonomous AI systems and the importance of robust containment mechanisms during frontier AI testing.

Gina Neff, executive director of the Minderoo Centre for Technology and Democracy at the University of Cambridge, said AI evaluations are typically conducted inside isolated environments, commonly referred to as sandboxes, where researchers can safely observe model behavior. Based on the available information, she suggested the evaluation environment did not provide sufficient isolation, allowing the AI agent to exploit weaknesses in the testing infrastructure itself rather than remaining confined to the intended experiment.

Neil Lawrence, Professor of Machine Learning at the University of Cambridge, described the behavior as technically impressive while cautioning that it remains within the capabilities demonstrated by today's most advanced frontier models. He also noted that companies developing increasingly capable AI systems face growing commercial pressure to demonstrate their technological progress amid intensifying competition across the AI industry.

The incident has also drawn the attention of UK authorities. A government spokesperson said the UK's AI Security Institute is studying the behavior observed during the evaluation and continues collaborating with OpenAI and other leading AI developers to strengthen safety standards for advanced models. The government also encouraged organizations to strengthen their cybersecurity posture through established frameworks such as the Cyber Essentials certification scheme.

Cybersecurity professionals say the incident reinforces concerns that autonomous offensive AI capabilities are advancing faster than many organizations' defensive preparedness.

Spencer Starkey, an executive at cybersecurity firm SonicWall, said organizations should treat cyber resilience as a core operational priority as attackers increasingly leverage automation and artificial intelligence to conduct attacks at machine speed.

Travis Lelle, Principal Security Engineer at Guidepoint Security, described the disclosure as a sobering development for the cybersecurity community. He noted that offensive AI systems often operate with fewer practical constraints, while many defensive AI tools remain intentionally restricted by safety guardrails, creating an imbalance that defenders will need to address.

Jake Moore, Global Cybersecurity Advisor at ESET, said the disclosure may also carry strategic implications beyond its technical significance. He suggested the announcement arrives as competition among leading AI developers intensifies, particularly following Anthropic's recent advances and the unveiling of new frontier AI models by other companies, including Chinese startup Moonshot AI.

Beyond the immediate investigation, the incident is expected to influence how AI companies design future cybersecurity evaluations. Researchers increasingly argue that testing environments for highly capable AI systems must assume that models will actively search for opportunities to escape containment rather than simply complete assigned tasks.

As AI systems become capable of independently identifying vulnerabilities, adapting their strategies, and chaining together multiple attack techniques without continuous human guidance, organizations may need to deploy equally sophisticated AI-assisted defensive technologies capable of detecting and responding to threats at comparable speed.

OpenAI and Hugging Face said their joint investigation remains ongoing, with both organizations expected to publish additional technical findings and recommendations as they continue analyzing the incident.

Child Safety and Platform Accountability: The Debate Over Online Privacy


The surge in child sexual abuse material, generally called CSAM, is compelling technology companies and government to face internet’s serious concern about platform accountability and how can platforms protect children without impacting their privacy?

The scale of the issue is immense. According to the Center for Missing and Exploited Children, US, CyberTipline got 21.3 million reports of suspected child sexual exploitation last year. 

These reports consisted of 61.8 million videos, images, and other files, while incidents associated with GenAI also showed an increase. International hotline networks (INHOPE)  have also recorded a transition in distribution of materials from traditional websites to online communities and forums, where material can distribute quickly and escape conventional security mechanisms. 

What is CSAM?

CSAM contains videos, pictures, and other digital media that depict the sexual exploitation or abuse of minors. CSAM may be disseminated through social media, messaging platforms, online forums, cloud-storage services, or websites. 

How tech is making CSAM detection a problem?

Technology has made it easier for criminals to create, store, and share CSAM material. Encrypted messaging, private groups, and anonymous accounts makes it difficult for authorities to catch criminals. GenAI has created new problems as it can be used to produce sexual deepfakes of minors.

Therefore, social media platforms and online communities are under pressure to find, report, and remove CSAM. According to experts, platforms should hold active responsibility when their algorithms, recommendation systems, file-sharing tools, flawed content moderation or private groups can enable sexual abuse or exploitation. Platforms should provide an easy reporting system and co-ordinate with authorities. 

Platform accountability

But, taking down content after it is posted is not enough. Platforms should also check if their apps undermine children's privacy or make them more weak. For instance, unrestricted communication, disappearing messages, and anonymous messages between children and adults can increase the risk sexual abuse. 

For platform accountability, companies should take responsibility for how their tech is built and used, by ensuring stronger security policies, effective systems to detect illegal content and trained content moderation teams. Companies should also 

In India, Section 67B of the Information Technology Act penalises the posting or distribution of sexually explicit material involving minors. India also imposes due-diligence on digital platforms, such as action against illegal content and robust compliance systems for big-tech social media giants. Recent rules also look out for GenAI, as it can be used to create sexual CSAM content.

The main concern is not if platforms should act, but how. Safeguarding children demands responsible technology and firm enforcement. 

Hotel Wi-Fi Attacks Linked to Russian Hackers Target Microsoft 365 Accounts With Custom Malware


In a sophisticated cyber campaign carried out by attackers using hotel and conference Wi-Fi networks, Microsoft uncovered the theft of Microsoft 365 credentials, and the deployment of custom malware. As reported by the company, CaptiveCrunch was carried out by Storm-2945, a subgroup of the Russian state-backed threat actor Midnight Blizzard (APT29). 

There have been several incidents of Wi-Fi networks being affected by the campaign in hotels, conference centers, and other venues that use captive portals. In the company's view, corporate travelers are the primary targets, since compromise of their Microsoft 365 accounts would allow attackers access to sensitive company information. 

A related phishing campaign has been conducted since at least May 2026, while the campaign is believed to have been active since then. Microsoft's investigation indicates that the attackers compromised shared network infrastructure used by hospitality Wi-Fi providers, allowing them to manipulate DNS and HTTP traffic. Using this technique, they were able to redirect users to fraudulent Microsoft 365 login pages, phishing portals containing device codes, or fake software update screens when connecting to hotel Wi-Fi. 

It is believed that the attackers gained access to infrastructure shared across multiple captive portal deployments, rather than isolated compromises at individual hotels, allowing the campaign to target multiple hospitality locations without having to target each venue individually. 

The attacks were carried out by CornFlake and ChocoShell malware families that had previously been undocumented. As a Go-based remote access trojan (RAT), CornFlake provides long-term access to infected systems by allowing attackers to execute commands remotely, log data, capture screenshots, steal credentials from websites, steal session tokens from Microsoft 365, monitor clipboards, and exfiltrate data. 

A fake Windows update or security scan screen is displayed during the installation process of the malware to avoid suspicion. Several persistence mechanisms are also established to survive system reboots. 

In addition, Microsoft noted that CornFlake provides secure command-and-control communication through modern cryptographic techniques, as well as support for dynamic reconfiguration, which allows attackers to modify infrastructure and targets without redeploying the malware. Further, the RAT utilizes multiple persistence mechanisms in order to remain active despite the removal of one method by security tools. 

ChocoShell is a PowerShell credential stealer that targets cookie files, passwords, Microsoft 365 tokens, and stored Wi-Fi credentials stored in memory. Additionally, Microsoft discovered a management panel controlled by attackers, dubbed FruitStone, that allowed administrators to remotely manage compromised devices, execute PowerShell commands, browse files, and capture screenshots and keystrokes. 

The malware has been identified as targeting access and refresh tokens for Microsoft 365 and Azure Active Directory, thereby allowing attackers to potentially hijack enterprise sessions without requiring users to enter their credentials again. Using ClickFix social engineering techniques, researchers observed fake updates to browsers and operating systems that tricked users into installing malware through these updates. 

Through the same infrastructure, attackers have attempted to distribute malicious Android APK files as well. Amid the campaign, Microsoft observed the scheme expanding to include Microsoft Entra device code phishing, in which the victims are tricked into completing a legitimate Microsoft authentication process that unknowingly allows the attackers' session to be authorized instead of their own. 

Upon analyzing both malware families, Microsoft believes artificial intelligence tools likely contributed to their development as analysts identified extensive AI-generated comments throughout the source code, demonstrating an increasing trend in malware development by threat actors incorporating AI into their code.

The Microsoft team recommends that users consider hotel and conference Wi-Fi networks to be untrustworthy, use mobile or managed network connections whenever possible, avoid installing software provided through captive portals, and use phishing-resistant authentication methods such as passkeys and multi-factor authentication whenever possible to reduce the risk of compromise. 

The organization is also advised to disable Microsoft Entra device code authentication where it is not necessary and to avoid using corporate credentials when registering for guest Wi-Fi services. Furthermore, security experts advise against registering for guest Wi-Fi services using company email addresses, since this may expose enterprise identities to targeted phishing attempts. 

Using trusted public Wi-Fi networks for cyber-espionage is an extremely dangerous practice. As attackers continue to perfect phishing and malware techniques, organizations and travelers alike must take additional precautions when connecting to public networks and implement stronger authentication measures.

Alphabet, Tesla Shares Slide as Wall Street Questions Mounting AI Investment Costs

 


Investors wiped billions from the market value of Alphabet and Tesla after the companies disclosed another sharp increase in spending tied to artificial intelligence, signalling that Wall Street is becoming less willing to reward ambitious investment plans without clearer evidence of when those outlays will generate stronger financial returns.

Alphabet's shares fell nearly 7%, while Tesla tumbled 14.5% following the release of their latest quarterly earnings. Although both companies remain committed to expanding their long-term technology capabilities, investors focused on a different figure: free cash flow. Each company reported that the cash remaining after funding operations and capital investments had turned negative, raising fresh questions about the financial burden created by large-scale AI and infrastructure projects.

The reaction illustrates a growing divide between technology companies and financial markets. Executives continue to argue that today's spending is necessary to secure future leadership in artificial intelligence, while investors are looking for clearer signs that those investments will eventually translate into stronger earnings and cash generation.

Alphabet's quarterly revenue climbed to $119.8 billion, a 23% increase from the same period a year earlier, showing that demand across its businesses remained healthy. Yet strong sales did little to ease investor concerns because the company's capital spending accelerated even faster.

For the quarter, Alphabet reported negative free cash flow of $5.9 billion, the first such result since the company became publicly listed in 2004. Free cash flow is closely watched by investors because it measures how much cash remains after a company pays its operating expenses and funds long-term investments. A negative figure does not necessarily indicate financial weakness, but it does show that investment costs exceeded the cash generated during the period.

Alphabet Chief Financial Officer Anat Ashkanazi told financial analysts that the decline was driven almost entirely by AI-related capital expenditure. The company invested approximately $45 billion during the quarter, allocating around 60% of that spending to servers and the remaining 40% to expanding data centre capacity needed to support growing demand for AI services. The latest figure also represents a substantial increase from the $36 billion Alphabet invested during the previous quarter.

The company has now lifted its projected capital expenditure for the year to as much as $205 billion, roughly $15 billion higher than the estimate it provided three months ago. Most of that investment will support AI infrastructure, including computing resources capable of training and operating increasingly sophisticated artificial intelligence models.

Ashkanazi said customer demand for AI products continues to exceed the company's available computing capacity, adding that Alphabet intends to keep investing while opportunities remain attractive.

Chief Executive Officer Sundar Pichai described artificial intelligence as a technological transition that is still in its early stages. He said the company remains disciplined in evaluating where it allocates capital and believes substantial opportunities remain to transform advanced AI capabilities into products and services used by businesses and consumers.

Tesla reported a similar financial picture. The electric vehicle manufacturer posted negative free cash flow of $1.1 billion during the second quarter, its first negative reading in two years, after investment costs climbed across several strategic initiatives.

The company expects capital expenditure to reach as much as $25 billion this year, more than double what it invested during 2025. While Tesla has not disclosed a detailed breakdown of every project included in that forecast, the spending is expected to support manufacturing expansion, autonomous driving technology, robotics, AI development and the computing infrastructure required to power those initiatives.

Tesla Chief Financial Officer Vaibhav Taneja said the company is entering a major investment cycle and expects spending to continue rising over the next three years as those programmes move forward.

Market analysts say the concern is not that technology companies are investing in artificial intelligence, but that the scale of spending has reached levels that demand measurable financial returns. Russ Mould, investment director at AJ Bell, said investors remain sceptical that such unprecedented expenditure will produce returns proportionate to the capital being committed.

Rachel Winter, a partner at wealth management firm Killik & Co, also noted that Alphabet's latest investment plans exceeded many expectations, suggesting the market's response indicates unease about the pace at which those billions of dollars will translate into higher profits.

The earnings from Alphabet and Tesla arrive as the technology industry commits record sums to artificial intelligence. Companies including Microsoft, Amazon and Meta have all expanded spending on specialised chips, cloud infrastructure and data centres to support rapidly growing AI workloads. As competition intensifies, capital expenditure has become one of the defining financial themes shaping the sector.

For investors, however, enthusiasm for artificial intelligence is now accompanied by tougher questions. Revenue growth alone is no longer enough to reassure the market. Companies are now expected to show that record-breaking investment in AI infrastructure can eventually deliver sustainable profits, stronger cash generation and lasting value for shareholders.

Ray Dalio Warns AI Bubble Could Trigger Financial Crash

 

Billionaire investor Ray Dalio, who famously predicted the 2008 financial crisis, is now warning that the artificial intelligence boom could burst and trigger a similar economic collapse. The founder of Bridgewater Associates says investors are confusing AI’s transformative potential with guaranteed investment returns, creating dangerous market conditions. 

Dalio explains that bubbles form when prices rise dramatically as everyone rushes to invest, often borrowing money to participate. He notes the current AI euphoria has reached approximately 75-80% of the extremes seen before the 1929 crash and the 2000 dot-com bubble. The problem, according to Dalio, is that people stop paying attention to whether prices make sense because they fear missing out. He emphasizes a crucial distinction: “This will change the world” does not mean “this investment can’t lose money.” When wealth holders need cash for taxes, debt payments, or other obligations, they must sell assets, triggering a cascade where falling prices force more selling. 

Historical parallels and warning signs 

The 76-year-old investor draws direct parallels to previous bubbles, particularly the dot-com era when investors assumed internet companies were sure bets. Many borrowed heavily to invest, only to lose everything when the bubble burst. Dalio warns AI stocks could drop as much as 80% even if the technology succeeds in revolutionizing industries. He points out that during the dot-com boom, the internet genuinely transformed society, but most early internet companies still collapsed because valuations were unsustainable. The same pattern could repeat with AI, where the technology delivers on its promises but overvalued companies fail to generate adequate profits.  

Beyond the AI bubble, Dalio warns that the broader debt situation has passed a “point of no return.” When debt service payments consume so much income that they squeeze out spending, economic contraction becomes inevitable. He describes this as similar to plaque in arteries restricting blood flow—eventually, the system seizes up. Combined with potential Federal Reserve policy shifts, rising interest rates, or wealth taxes, these factors could prick the AI bubble and trigger widespread margin calls. Dalio also highlights geopolitical tensions that could lead to a “capital war,” where foreign investors reduce bond purchases, making borrowing more expensive and drying up the capital fueling AI investments. 

Preparing for what comes next 

Dalio stresses that understanding these cause-and-effect relationships is essential for navigating what lies ahead. He advocates for diversified portfolios including gold and other assets that perform well during debt crises. While AI will bring revolutionary changes to productivity, drug discovery, and logistics, investors must separate technological success from investment success. The key lesson from history is that bubbles always burst, and those who recognize the signs early can protect their wealth while others face devastating losses.

Featured