Tech News news.wrst.click
🌐 Español
LIVE EDITORIAL

Artificial Intelligence

Tech coverage, research breakthroughs, and digital industry insights

The Hacker News · September 3, 2026 · 3 min read
Extradited Russian hacker faces charges for Excel malware campaign infecting 80,000 users
Artificial Intelligence
The Hacker News · 2 min read

Extradited Russian hacker faces charges for Excel malware campaign infecting 80,000 users

The U.S. Department of Justice has charged Russian national Searzhudin Tamirlanovich Aktulaev, 40, who was extradited from Cyprus on August 28, with orchestrating a malware campaign using approximately 255 fake accounts on a freelance platform to distribute malicious Excel attachments to approximately 80,000 users during 2016 and 2017. Aktulaev was arrested in Cyprus in May 2025 and made his initial appearance in federal court in San Francisco on August 31, being remanded to federal custody pending trial. The malware campaign delivered Excel attachments that prompted recipients to execute macros, which then downloaded malicious software from the internet. The malware included TVRAT, which exploited a vulnerability in TeamViewer, and DarkVNC, a hidden virtual network computing (hVNC) utility that created a concealed desktop on infected machines for remote control by operators. Avast analysis revealed that the macro fetched a password-protected installer bundling legitimate TeamViewer binaries with a malicious DLL loaded through DLL search order hijacking, a technique that evaded signature checks on the main executable. The indictment charges Aktulaev with conspiracy to commit wire fraud, transmission of commands to damage protected computers, conspiracy to commit computer fraud, unauthorized access to protected computers for financial gain, and aggravated identity theft. Approximately half of the 80,000 victims were located in the United States, many within the district where charges were filed. A shared document in the email account used in the scheme contained e-commerce login credentials and personally identifiable information for hundreds of victims. This case reflects a growing trend of malicious actors leveraging freelance and job-hunting platforms as attack vectors. Cybersecurity firm ESET reported in February 2025 that North Korean hackers were using the same freelance platform lure against software developers. Check Point Research documented fake recruiter campaigns by the Lazarus Group pairing job offers with remote-access backdoors, while Ukraine's CERT-UA reported Sandworm-linked clusters using job-site chats to distribute VPN clients capable of executing commands. Aktulaev has denied guilt, stating he was unaware of the U.S. charges according to the Russian Embassy in Nicosia.

GeoNetwork Fixes Unauthenticated RCE Chain Exposing Government Geoportals
Artificial Intelligence
The Hacker News · 2 min read

GeoNetwork Fixes Unauthenticated RCE Chain Exposing Government Geoportals

The GeoNetwork project, an open-source geospatial metadata catalog platform serving as the backend for numerous government and institutional geoportals, has released patches for a critical vulnerability chain enabling unauthenticated remote code execution (RCE). Tracked as CVE-2026-63219 (CVSS 8.6) and CVE-2026-58400 (CVSS 9.1), the flaws were fixed in versions 4.4.12 and 4.2.17 on July 8, 2026, with full technical details published on August 31. The chain affects all 4.4.x releases up to 4.4.11 and all 4.2.x releases up to 4.2.16, exposing critical spatial data infrastructure systems across Europe and beyond, including the backend of the European INSPIRE geoportal. The first vulnerability involves a missing authorization check on the formatter upload endpoint, allowing any anonymous user to write arbitrary .xsl or .zip files to GeoNetwork's formatter directory. The second flaw stems from an unsafe configuration of the Saxon XSLT processor, which despite running with secure processing enabled and Java extension functions disabled, permits any loaded stylesheet to invoke java.lang.Runtime.exec() or java.lang.ProcessBuilder to execute operating system commands. Individually, the second vulnerability requires upload privileges; however, chaining it with the first enables complete unauthenticated RCE by first uploading a malicious formatter, then triggering the Saxon engine through a public record request. Security firm Ethiack, whose researcher Rafael Castilho discovered both vulnerabilities, identified 121 internet-exposed GeoNetwork instances running vulnerable versions across 39 countries. Approximately 89 percent of these belonged to government, military, or national agency deployments. The Open Source Geospatial Foundation (OSGeo), which maintains the project, has urged all administrators to immediately upgrade to versions 4.4.12 or 4.2.17. As a temporary mitigation, administrators can block write methods to the formatter endpoint at the reverse proxy level to prevent both legitimate and malicious formatter uploads. This disclosure arrives amid a surge of security issues across the broader geospatial stack. Last year, a critical GeoServer flaw (CVE-2024-36401, CVSS 9.8) was exploited by botnets, cryptocurrency miners, and the SideWalk backdoor, while a GeoServer XXE vulnerability (CVE-2025-58360) was added to CISA's KEV catalog following evidence of active exploitation. As of publication, no active exploitation of the GeoNetwork vulnerabilities had been reported in the wild, and the flaws were not listed in CISA's Known Exploited Vulnerabilities catalog.

Sponsored
ZeroTrust Data Platform · Enterprise-Grade Security
Automate privileged access control with real-time audit logs and seamless compliance.
SonicWall SMA 1000: Two Zero-Days Actively Exploited in Attack Chain
Artificial Intelligence
The Hacker News · 2 min read

SonicWall SMA 1000: Two Zero-Days Actively Exploited in Attack Chain

SonicWall has released urgent security updates to address two zero-day vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series VPN appliances, which are currently being actively exploited by threat actors. The flaws, discovered internally by SonicWall researchers William Perry and Adam Babis, can be chained together by attackers to execute arbitrary code on vulnerable devices. The affected versions include SMA 1000 models 6210, 7210, and 8200v, and the company recommends immediate upgrading to versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix). From a technical perspective, these vulnerabilities allow attackers to perform lateral movements within corporate networks once the SMA 1000 device has been compromised. The precise technical details of the flaws have not been publicly disclosed for security reasons, but SonicWall has confirmed that active exploitation indicates a sophisticated attack pattern chaining both vulnerabilities. This type of chained exploitation is particularly dangerous because it enables privilege escalation and long-term persistence within the target network. The context of this disclosure is particularly relevant as it comes more than a month after SonicWall issued patches for two other critical vulnerabilities in the same product: CVE-2026-15409 (with a CVSS score of 10.0, the highest possible severity) and CVE-2026-15410 (CVSS 7.2). These previous vulnerabilities were exploited by the threat actor identified as UTA0533 to deploy KNUCKLEBALL malware, suggesting a sustained pattern of activity targeting SonicWall SMA 1000 devices. From a strategic perspective, the company has not provided details about the exact nature of current exploitations or the identity of the actors behind these attacks. Security researchers warn that any organization using SMA 1000 devices should assume they may be compromised and conduct comprehensive forensic audits. This situation underscores the growing sophistication of attacks targeting critical network infrastructure and the importance of proactively maintaining updated security systems.

Google spared ad-business breakup, but judge orders operational changes
Artificial Intelligence
TechCrunch · 4 min read

Google spared ad-business breakup, but judge orders operational changes

The U.S. Department of Justice will go down in history as the regulator that came closest to dismantling Google's advertising empire after more than five years of legal battles across two separate antitrust fronts. In a decision handed down on Wednesday, September 2, 2026, federal judge Leonie M. Brinkema of the Eastern District of Virginia ruled that Google will keep its lucrative ad-technology division in its entirety, rejecting the divestiture request the U.S. government had been pursuing since 2023. The ruling, however, imposes substantial modifications on the Mountain View giant's business practices to favor competitors, although, as The New York Times reported, the decision did not yet specify the precise compliance mechanisms. Lee-Anne Mulholland, Google's vice president of regulatory affairs, publicly welcomed the verdict, stating the company is "very pleased" the court rejected the proposal to break apart tools that, in its narrative, help small businesses grow. At the heart of the litigation lies an extraordinarily opaque and complex market architecture in which Google allegedly relied for years on exclusive agreements with device manufacturers and revenue-sharing deals with mobile carriers to ensure its search engine remained the default on the vast majority of phones worldwide. That default-search dominance, prosecutors argued and the April 2025 ruling confirmed, directly fueled the strength of Google's advertising platform. Judge Brinkema's determination thus mirrors a pattern already observed in the parallel search case: in September 2025, Judge Amit Mehta likewise rejected the DOJ's requests to force divestiture of Chrome and Android, limiting his remedies to ordering an end to exclusive default-placement deals and the sharing of certain search data with competitors — measures Google is currently appealing. The digital advertising ecosystem is famously labyrinthine, built on a maze of intermediaries, real-time auctions, and opaque supply chains — a structure in which Google has consolidated for more than a decade a quasi-monopolistic position linking advertisers, publishers, and consumers. The DOJ's case, formally known as United States v. Google (ad-tech), challenged not only the default agreements but Google's full vertical integration: from its ad exchange (AdX) to its demand-side platform (DV360) and its publisher ad server (Google Ad Manager), an architecture that, per the complaint, allowed Google to manipulate auctions in its own favor. The April 2025 finding concluded that this configuration constituted an illegal monopoly, and this week's decision addressed only the remedy phase, leaving the details of operational changes for the next 14 days while the full written ruling remains under seal to allow redactions. Strategically, Google secures a critical win by keeping intact the unit that, by various industry estimates, generates tens of billions of dollars annually and forms a central pillar of its revenue model. The ruling nevertheless sets a significant precedent in U.S. antitrust policy, confirming that the vertical integration of big tech firms can be declared illegal even when a structural breakup is not ordered. For the DOJ, accustomed to pursuing structural remedies against digital giants since the Microsoft case, the outcome amounts to a partial legal victory: two courts have now agreed that Google engaged in monopolistic conduct, but neither has imposed the ultimate sanction of breaking up the company. In the coming months, industry attention will shift to the technical details of the ordered remedies, to the appeal Google is already pursuing in the search case, and to whether the European Commission, which has been running parallel actions against Google's ad business, intensifies its own enforcement — a regulatory pressure that remains at historically high levels.

How to Secure Enterprise AI: From Adoption to Incident Readiness
Artificial Intelligence
The Hacker News · 2 min read

How to Secure Enterprise AI: From Adoption to Incident Readiness

According to Sygnia’s 2026 CISO Survey Report, based on a survey of 600 senior IT and security leaders worldwide, nearly one-third of organizations already extensively use AI in threat detection and incident response, with 63% expecting it to be fully embedded by 2027. However, 73% of security decision-makers say their organization would not be fully ready if a significant cyberattack occurred tomorrow. This gap between adoption and control represents a critical risk, especially under board-level pressure to move fast without compromising security. AI security architecture must address each stage of the tool’s lifecycle, from identifying and classifying risks to assigning ownership and limiting access. AI doesn’t always enter through official channels: it also comes via approved platforms, SaaS plugins, vendor tools, and internal experiments. As AI evolves from autonomous assistant to agent acting across systems, the attack surface expands exponentially, demanding continuous technical controls and validation. The investment and competitive ecosystem around enterprise AI is growing rapidly, driven by organizations seeking to balance innovation with resilience. While the article does not cite specific valuations or acquisitions, it reveals that 67% of executives believe their organization has already suffered a breach due to unapproved AI tools. The lack of comprehensive AI policies (only 38% have them) creates fertile ground for shadow AI and automated threats. Looking ahead, AI governance must become an executive responsibility with formal mandates and active board involvement. Organizations must embed AI-specific incident response procedures into their IR plans, provide role-specific workforce training, and maintain an up-to-date inventory of AI applications. Those who wait for a threat to expose their AI security posture are already behind in a landscape where AI redefines the rules of engagement for both defenders and attackers.

Google Releases Gemini 3.8 Flash, Its Third Flash Model in Six Weeks
Artificial Intelligence
Ars Technica · 3 min read

Google Releases Gemini 3.8 Flash, Its Third Flash Model in Six Weeks

Google announced today the release of Gemini 3.8 Flash, its third Flash model in just six weeks, further accelerating its pace of updates in the artificial intelligence space. Described by Google as its best reasoning and coding model yet, Gemini 3.8 Flash comes in two variants: the standard version, designed for agentic tasks and software development, and Gemini 3.8 Flash Cyber, specialized in vulnerability detection and mitigation. Despite the frequency of these releases, Google has not introduced a frontier-level Gemini Pro model since early 2026, suggesting that the promised Gemini 3.5 Pro may be shelved. Google's strategy appears to be focusing on lightweight, fast models rather than larger, more expensive ones. From a technical standpoint, Gemini 3.8 Flash shows marginal improvements over its predecessor, Gemini 3.7 Flash, particularly in coding evaluations where it leads the DeepSWE leaderboard, a measure of a model's ability to solve complex software engineering problems. However, in computer use tasks, as evaluated by OSWorld-2.0, the model still lags behind market leaders like Claude Opus. The Cyber variant, which replaces the 3.5 version, has demonstrated substantial improvement in internal testing, identifying more vulnerabilities and issuing working patches more frequently. The Chrome security team reported a 2.6x increase in patch accuracy, while the Cloud team claimed the model found a critical vulnerability in just two hours. Partners like Wiz and Palo Alto Networks have also endorsed the capabilities of Gemini 3.8 Flash Cyber. For developers and enterprises, Google maintains its strategy of attractive pricing, offering API access to Gemini 3.8 Flash at an introductory rate of $0.75 per million input tokens and $3.75 per million output tokens, with a planned increase at the end of the year. This approach aims to keep customers engaged in a market where competitors like Anthropic and OpenAI have recently reduced their token pricing. The model will be available through Google AI Studio and Vertex AI, allowing users to access both free and advanced features via Pro or Ultra subscriptions in the Gemini app. Strategically, Google's approach reflects a shift toward rapid, iterative releases of smaller models, prioritizing speed and efficiency over the development of larger, more complex models. This approach could be key to driving enterprise adoption of AI solutions, as it allows businesses to access advanced capabilities without incurring prohibitive costs. However, the constant rollout of new models also presents challenges in terms of stability and consistency in enterprise integrations. In the long run, this strategy could solidify Google's position as an agile and accessible provider in the competitive landscape of generative AI.

World's Largest Dark Matter Detector Catches a Strange Particle
Artificial Intelligence
Hacker News · 1 min read

World's Largest Dark Matter Detector Catches a Strange Particle

The world's largest dark matter detector, known as XENONnT, has recorded an unusual particle signal that doesn't match existing particle physics models. Located at Italy's Gran Sasso National Laboratory, the experiment uses more than 8 tons of liquid xenon to capture the faint interactions between dark matter and ordinary matter. The detected signal could potentially be linked to axions, neutrinos, or even an entirely new form of physics that scientists have yet to identify. Researchers emphasize that while the finding is exciting, more data is needed to confirm the exact origin of the particle. The team continues to analyze results and collect new information to rule out possible noise sources or interference. If confirmed, this discovery could transform our understanding of the universe and open new research avenues in the search for elusive dark matter. This breakthrough represents a significant milestone in experimental physics, demonstrating the capability of current detectors to identify extremely weak signals. The international scientific community will closely follow XENONnT's next steps, which could provide crucial clues about the composition of the 85% of matter that makes up the cosmos but remains invisible to our instruments.

Paint.NET 5.2 Alpha Introduces Linux Support After Two Decades of Windows Exclusivity
Artificial Intelligence
Hacker News · 2 min read

Paint.NET 5.2 Alpha Introduces Linux Support After Two Decades of Windows Exclusivity

The renowned Windows image and photo editor Paint.NET has officially released its 5.2 Alpha build (9739), introducing experimental native-compatible Linux support for the first time in the software’s two-decade history. The development has triggered significant excitement across the developer and creative communities, where Paint.NET has long been regarded as one of the most missed desktop applications by users transitioning from Windows to Linux workstations. From an architectural standpoint, porting Paint.NET to Linux posed exceptional engineering hurdles due to the application's deep historical reliance on Windows-specific graphics subsystems, notably Direct2D, DirectWrite, and proprietary .NET desktop APIs. Lead developer Rick Brewster achieved the milestone through an ambitious clean-room reimplementation and abstraction of Direct2D components tailored for Wine and cross-platform display servers, a multi-month effort significantly accelerated by leveraging advanced AI code generation to tackle low-level graphic translation layers. Within the broader desktop software landscape, Paint.NET occupies a uniquely sweet spot between the barebones functionality of standard MS Paint and the intimidating complexity of tools like GIMP. For years, open-source Linux clones such as Pinta struggled to match Paint.NET's stability, plugin maturity, and responsive hardware-accelerated canvas. With official Linux builds entering testing, Linux creators and power users gain access to a premier multi-layer editor without needing full Windows virtual machines or dual-boot configurations. Looking ahead, the arrival of Paint.NET on Linux underscores a broader modernization trend in legacy desktop software powered by modern .NET runtimes and AI-assisted cross-platform porting. While the current 5.2 release remains an alpha targeted at early adopters and bug reporting across various Linux distributions, ongoing development focuses on polishing GPU acceleration and plugin architecture, cementing one of the year’s most anticipated cross-platform milestones.

Google Avoids Breakup of Ad Tech Business in Major Ruling
Artificial Intelligence
Hacker News · 1 min read

Google Avoids Breakup of Ad Tech Business in Major Ruling

Google has successfully avoided a forced breakup of its ad tech business, marking a significant legal victory for the tech giant amid increasing regulatory scrutiny. The ruling, issued by a federal court, preserves Google's current structure in digital advertising operations, allowing the company to maintain its dominant position in the online ad market. This outcome reinforces Google's control over a critical segment of the internet economy. The decision comes after prolonged regulatory battles concerning Google's market power and its effects on competition. Critics and regulators have long argued that Google's vertical integration across the advertising supply chain harms competitors and stifles innovation. However, the court determined that proposed remedies were disproportionate and unsupported by sufficient evidence, ultimately siding with Google's defense. This ruling carries far-reaching implications for the future of tech regulation in the U.S. and globally. As authorities worldwide intensify their scrutiny of major tech companies, the favorable outcome for Google may set a precedent affecting similar cases involving other dominant players in their respective markets.

Palo Alto Networks Acquires Console for $500M to Power Autonomous Cortex AI Agents
Artificial Intelligence
TechCrunch · 2 min read

Palo Alto Networks Acquires Console for $500M to Power Autonomous Cortex AI Agents

Palo Alto Networks has acquired Console, a two-year-old startup that leverages artificial intelligence agents to automate routine enterprise IT helpdesk operations, in a $500 million cash-and-stock transaction. The acquisition marks one of the most significant strategic moves this year bridging proactive cybersecurity and autonomous IT operations. Founded in 2024 by Andrei Serban following the acquisition of his prior startup Fuzzbuzz by Rippling, Console developed an agentic workflow platform capable of resolving repetitive technical requests without direct human intervention. Its autonomous agents routinely handle credentials resets, software provisioning across tools like Figma and Miro, and end-to-end troubleshooting for modern engineering teams, counting high-growth enterprises such as Ramp, Flock Safety, and Scale AI among its core customer base. From a venture capital and valuation standpoint, Console had secured $29 million across two funding rounds led by Thrive Capital and DST Global, having reached a $157 million valuation according to PitchBook. The transaction provides an exceptional and rapid return for early backers including SV Angel and Abstract Ventures, as well as Palo Alto Networks CEO Nikesh Arora, who participated as an early angel investor. In the enterprise automation landscape, Console competed directly with Serval, a ServiceNow challenger recently valued at $1 billion following a Sequoia-led Series B. Palo Alto Networks plans to deeply integrate Console’s autonomous capabilities into its Cortex security platform. As Palo Alto’s seventh acquisition in 2026—following high-profile deals including observability leader Chronosphere ($3.35 billion) and cyber firm Koi ($400 million)—the deal equips Cortex with natural language execution capabilities, providing security and IT teams with the operational autonomy needed to resolve enterprise-wide alerts in real time.

← Previous Page 3 of 6 Next →