Breaking News

FIND INFORMATION ABOUT THE LATEST ADVANCES IN TECHNOLOGY & NEWS RELATED TO CYBERSECURITY & ARTIFICIAL INTELLIGENCE (AI) 

CoolClient Backdoor created by threat actor group Mustang Panda

Mustang Panda, aka HoneyMyte, is a threat actor that has recently deployed a version of the CoolClient backdoor with a Windows rootkit that protects malicious processes and other backdoors. The kernel is deployed when CoolClient has full access to the Service Control Manager and other privileges, and if it doesn't the malware goes straight to final level implants. Keylogging, client theft, credential harvesting, and other malicious processes are supported by CoolClient. Several hashes have been listed by Russian security provider Kaspersky as indicators and can be used to avoid the backdoor.

LG and Nvidia Expands Alliance Through Robots and AI Factories

LG group chairman Koo Kwang-mo and Nvidia CEO Jensen Huang solidified their alliance with an understanding to dominate the "physical AI" market. They plan to do this by integrating LG's manufacturing process with Nvidia's advanced computing across robotics and AI factories, hoping to prioritize the development of a humanoid robot by 2027 by establishing a scalable AI factory reference site in South Korea. In addition, both of these major companies will work on AI-defined vehicles, enabling LG to expand to global automakers. This collaboration includes a joint task force with industry-leading reference projects, which has already sparked investor optimism, driving LG Electronics shares up 5%.

Squirrels Scavenging: How Hackers Use Expired Domains for a $7 Million Criminal Empire

Cybercriminals are spending nearly $7 million to acquire "dropcatch" domains - expired websites that retain their old reputation and traffic history - to launch large-scale scams and malware campaigns. The threat actor known as Sable Squirrel dominates this space, hoarding over 10,000 domains to power illegal sports streaming, online gambling, and sophisticated malware operations targeting Asia and beyond. These re-registered domains are weaponized with astonishing speed, with 94% becoming active malicious infrastructure within just two weeks of acquisition. By exploiting the lingering trust baked into these aged domains, hackers bypass security checks that often overlook the history of previously legitimate websites.

Neros. Inc raises $250 million for advancements in defense drones

Neros. Inc, a California based company plans to deploy defense drones with $250 million raised in total to asisst the U.S. and their allies. They plan to develop advancements for multi-asset control, and drone development and production. They plan to expand development with 2 drone programs, Archer AI and Bandit, with first-person view and interception systems. By 2028, Neros. plans to make 1 million aerial drones per year with advanced capabilities. Funding for multiple drone companies has increased since the ongoing wars, as the U.S. and other countries continue to prepare their defense forces with new technology.

Some Claude Users are Mad That Anthropic’s New Watermarks will Catch Them Using it at Their Jobs, Classes

Anthropic has begun adding invisible watermarks to Claude’s AI-generated text to comply with the EU AI Act, allowing computer systems to identify content produced or edited by Claude. The move has sparked complaints from some users worried the watermark could expose their use of AI at work or school, although TechCrunch notes that many of the examples involve copying AI-generated material directly, which can raise legitimate ethical concerns.

White House Authorizes Private Firms to Conduct Cyberattacks on Criminal Gangs

The White House will allow vetted private companies to launch cyber operations and surveillance against international criminal gangs for the first time. This policy allows participating firms to disrupt criminal systems and collect intelligence under strict federal supervision, provided they post a $1 million escrow deposit and obtain sign-offs from the Justice Department and Homeland Security. While intended to counter rising threats like ransomware and AI-driven attacks, the move faces criticism for potential legal challenges and risks to American employees operating overseas.

Hackers Launch the First Fully Automated AI Hacking Campaign Against Taiwan

Recently, AI firm Dream was able to discover what experts believe to be the first fully automated hacking campaign targeting a government. The campaign was revealed to have AI agents which mapped 21 Taiwanese government systems, cracked 85 user accounts, and extracted 2,500 personnel records. This attack also compromised systems within Taiwan's nuclear safety agency and other related companies. According to officials and experts, the AI agents adapted strategies during the attack to lower the cost and speed of executing complex intrusions.

macOS-oriented Information Stealer hijacks browser sessions, giving attackers live access

Cybersecurity researchers disclosed a macOS-oriented Rust-based information stealer called AmnesiaStealer that hijacks Chromium(or Chrome-based) browser sessions to steal session-data. It instructs users to copy and paste a Base64-encoded terminal command into the macOS terminal. The script pulls a ZIP archive which opens a Rust program that does reconnaissance, geolocation profiling, uses clipboard hijacking, and gets system password at the guise of an installer. The information stealer sends the information to an external Command-and-Control server, and it also gets its commands from there.

AmnesiaStealer Gives Attackers Live Browser Control on macOS

A new macOS malware called AmnesiaStealer can steal passwords, browser data, and other sensitive information, while giving attackers live control of a victim’s web browser. It spreads through fake GitHub pages that trick users into pasting a command into Terminal, which installs the malware. Once installed, it can steal browser cookies and login data, then use those stolen sessions to access websites as if it were the victim. AmnesiaStealer is especially dangerous because of its live browser control, which allows attackers to interact with accounts in real time without needing the victim’s password.

Simple Robot Design Exceeds Human Hand in Some Core Motions

Researchers developed the BioflexBot, a simple robotic hand that uses a coiled spring, shell, and pneumatic system instead of copying the complex structure of a human hand. Despite its simplicity, it can perform precise tasks like pinching and grasping while exceeding human-hand performance in some areas, including rotating objects nearly four times as much and extending/contracting 3.5 times farther.

New AI Technique Helps Robots Complete Tasks Twice as Fast by Letting Them 'Think Ahead'

A new AI system called VLASH helps robots “think ahead” by planning their next movements while they are still completing their current actions, reducing delays without requiring extra computing power. In tests, robots using VLASH completed tasks 1.5–2 times faster while maintaining similar accuracy, though researchers say more testing is needed to determine how well the technique works in real-world environments, especially around people.

New U.S. Government Memorandum Allows Private Companies to Launch Cyber Attacks

Until now, the U.S. Government has had a long-standing policy prohibiting private companies from carrying out offensive cyber operations. However, the Trump administration recently published a memorandum allowing "private sectors" working with the government to use spyware and make cyberattacks against criminals. Any operation will require authorization from the Justice Department and Homeland Security before being conducted. However, critics are concerned that Americans participating in cyber crimes for the U.S. government could be put at risk of being indicted by a foreign government.

Introducing Grok 4.6

SpaceX released Grok 4.6 today which builds on Grok 4.5 with stronger reasoning, better coding, and a much greater ability to handle long-running, multi-step tasks. It is especially improved at researching unfamiliar topics, working across codebases, self-checking its work, and turning ideas into polished interactive and visual applications, producing stronger first attempts than 4.5.

Vote Us For "Best Technology Services"!

California Business Technology, Inc. has been nominated for Best Technology Services in the 2026 Best of Dublin Competition. We're honored to be nominated and hope we can win with your support! Show your support by voting for us below!

Path-Traversal flaw used in intrusion campaign against VMware

An ongoing intrusion campaign against VMware is using a critical traversal flaw to attempt to gain remote access. 361 unique IP addresses have been victim to persistent threats across 47 countries from August 3 to August 5. Investigation has revealed use of reverse_ssh, aiding attackers in connect-back operation, port forwarding, file transfer, multiple transports and remote-shell management, showing signs of compromise. Systems affected have been connecting attacker controlled infrastructure, posing risk as intruders can target hosted workloads, credentials, or administrative operations. Organizations using VMware appliances need to apply patches immediately, restrict internet exposure, scan for reverse_ssh, and generally audit for malicious activity.