SevenTnewS

Cybersecurity

Vulnerabilities, ransomware, CVEs, pentesting, OSINT and the latest in information security.

38 published articles

5 min read

Cyber espionage

Hotel Wi-Fi is the SVR's new espionage front door

Microsoft links the CaptiveCrunch campaign to Storm-2945, an SVR-affiliated Midnight Blizzard sub-cluster that compromised hotel Wi-Fi portals worldwide to deliver malware and steal corporate credentials through fake sign-in pages and update prompts.

2026-07-30

Featured3 min read

Cybersecurity AI

Microsoft's MAI-Cyber-1-Flash delivers top CyberGym scores at half the cost

Microsoft's new MAI-Cyber-1-Flash model, integrated into the MDASH harness, promises frontier-level vulnerability detection at half the cost. The company says the system outperforms Mythos, Gemini, and GPT on the CyberGym benchmark.

2026-07-29

3 min read

Model Security: Specialists vs. Generalists

Why the Best General AI Model Keeps Losing to Narrower Ones on Security

Claude Opus 5's deliberately capped cybersecurity skills, Alibaba's in-session code review, and a new zero-query model-theft technique together show AI security fragmenting into specialized layers rather than converging on one trustworthy general model.

2026-07-28

3 min read

FCC vs. DJI front companies

The FCC is about to retroactively ban DJI front companies, and that changes the rules for every imported gadget

The FCC is preparing to retroactively ban disguised DJI products sold by front companies like Xtra and Skyrover, marking the first time it has wielded this power. A $25,000 fine was already proposed. Public comments are open for 30 days, but the real question is whether the FCC will use this test case to change the rules for every imported gadget.

2026-07-28

3 min read

Side-Channel Attack Steals Cloud AI Models

Model Stealing Attacks on Cloud-Based AI: A New Zero-Query Trojan Method Emerges

A new zero-query attack method called 'Zero-Query Model Stealing' allows adversaries to steal proprietary AI models from cloud APIs without sending any queries, using side-channel information from timing and memory patterns. This raises serious cybersecurity concerns for AI-as-a-service providers.

2026-07-27

Featured1 min read

DJI front companies

The shadow world of DJI clones is collapsing, and the FCC still won't explain why

Xtra Technology has stopped selling its latest DJI camera clone and is refunding preorders after the FCC proposed fines and retroactive bans. The case highlights a regulatory enforcement campaign built on a national security claim the government has never shared with the public.

2026-07-27

Featured2 min read

Penetration Testing

Sakana's Fugu-Cyber finds the vulnerabilities Claude Opus 5 was designed to miss

Anthropic capped Claude Opus 5's security skills. Specialized models like Google's Gemini 3.5 Flash Cyber and Sakana's Fugu-Cyber outperform it in vulnerability discovery. A case for testing alternatives before renewing enterprise licenses.

2026-07-26

3 min read

Cybersecurity

The wiper that bundles three flavors of destruction into a single backdoor

Microsoft found a Golang backdoor that packs three separate malware families into one implant. GigaWiper can wipe disks, encrypt files without decrypting, and maintain full remote access from a single binary.

2026-07-26

Featured4 min read

AI Coding Security

The blind spot in AI-generated code that Alibaba fixes mid-sentence

Alibaba's in-session code review catches vulnerabilities before they reach the repo, but the real test is whether developers will let it run.

2026-07-26

3 min read

Cybersecurity

Two new CISA alerts, one hard question: did they get in before you patched?

CISA adds CVE-2026-16232 (Check Point SmartConsole) and CVE-2026-50522 (Microsoft SharePoint) to its KEV catalog. Under BOD 26-04, agencies must now check for pre-patch compromises and prioritize by risk, making breach detection just as critical as patching speed.

2026-07-25

4 min read

Cybersecurity

Google's cheap fine-tune found vulnerabilities that Claude Opus 4.6 missed

Google's lightweight Gemini 3.5 Flash Cyber fine-tune outperforms Anthropic's largest model in vulnerability discovery, finding 55 unique issues in the V8 engine versus 36 for Claude Opus 4.6. The model is locked to governments via a limited pilot.

2026-07-24

Featured3 min read

Cybersecurity

Anthropic's new security tool treats your code like a researcher would, then suggests fixes

Anthropic's Claude Security scans codebases for vulnerabilities, validates findings with an adversarial pass, and suggests patches without leaving your workflow.

2026-07-22

← PreviousPage 2 / 4 · 38 articlesNext →