DeepSeek Helped Build In-Browser Ransomware — and It Worked
Check Point Research has published a detailed technical write-up of what may be the first documented case of a frontier AI model being used to generate functional ransomware from scratch. A researcher prompted DeepSeek to build browser-based ransomware that abuses a legitimate Chromium API; the model obliged, producing working code for both Windows and Android. The attack runs entirely inside the browser — no installation required. Check Point notes the original DeepSeek output needed only minimal refinement to become fully operational. This isn't a theoretical jailbreak exercise. It's a documented proof-of-concept that meaningfully lowers the technical bar for ransomware development.
Check Point Research ↗Microsoft Moves Its Quantum-Safe Deadline Forward to 2029
Microsoft has announced it's pulling forward its post-quantum cryptography migration deadline, saying advances in quantum research have shifted the risk horizon earlier than expected. Azure CTO Mark Russinovich said the company now believes existing encryption standards need replacing sooner than previously planned, and Microsoft is targeting full post-quantum readiness across its platforms by 2029. The announcement follows NIST's finalisation of quantum-safe standards last year and adds pressure on enterprise customers — many of whom haven't begun migration planning — to accelerate. Australian government agencies operating under the ISM should note ASD's own guidance on post-quantum readiness, which currently rates the threat as emergent rather than immediate.
The Hacker News ↗Anthropic's Claude Fable 5 Is Back Online After US Lifts Export Controls
The US Department of Commerce has lifted the export controls it imposed roughly three weeks ago on Anthropic's two most powerful models, Fable 5 and Mythos 5. Anthropic says the restrictions were lifted after it reached a series of agreements with the government, including new guardrails and classifiers. Both models are now available globally via Claude.ai, the Claude Platform, Claude Code, and Claude Cowork. The episode — a frontier AI model briefly taken offline by government order — is a preview of what AI governance friction looks like in practice. The Trump administration's handling has drawn criticism for unpredictability, with observers noting the lack of clear criteria for what triggers or lifts a restriction.
CyberScoop ↗Unpatched Argo CD Flaw Could Hand Attackers Entire Kubernetes Clusters
Security firm Synacktiv has disclosed an unpatched vulnerability in Argo CD's repo-server component — a widely used continuous deployment tool for Kubernetes — that allows an unauthenticated attacker to execute arbitrary code if they can reach the component's internal network port. There is no CVE assigned and no patch available. Synacktiv says exploitation could lead to full cluster takeover. Argo CD is heavily used in cloud-native environments across the industry; any organisation running it should check whether the repo-server port is inadvertently exposed on the internal network, and treat isolation of that component as an immediate priority while a fix is developed.
The Hacker News ↗Phantom Squatting: Attackers Are Buying the Domains AI Hallucinates
Palo Alto Networks' Unit 42 has named a new attack technique: phantom squatting. Large language models frequently invent web addresses for legitimate brands that don't actually exist — and attackers are now registering those hallucinated domains before anyone else can, then parking phishing pages on them to catch traffic that AI tools direct their way. The research shows this is already happening in the wild, not just in theory. The implication is uncomfortable: the more widely AI coding assistants, search tools, and agents are used to recommend software or resources, the more valuable it becomes to own whatever domain they tend to make up. It's typosquatting for the AI era.
The Hacker News ↗Scattered Spider Suspect, 19, Extradited from Finland to Face US Charges
Peter Stokes, a 19-year-old dual US-Estonian citizen, has been extradited from Finland and appeared in a Chicago federal court on charges of conspiracy, computer intrusion, and fraud relating to his alleged membership of Scattered Spider. A complaint unsealed this week includes allegations of involvement in a breach of a luxury jewellery retailer in 2025. The extradition from Finland is notable — it signals that the informal international dragnet for Scattered Spider members is expanding beyond the UK and US. Several alleged members have already been arrested; this extradition suggests prosecutors are working through a larger list of identified suspects.
The Hacker News ↗Adobe Patches Seven CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Adobe has released emergency patches for seven maximum-severity vulnerabilities across ColdFusion and Campaign Classic, all rated 10 out of 10 on the CVSS scale. The ColdFusion flaws could enable arbitrary code execution, privilege escalation, file system reads, and security feature bypass. Campaign Classic vulnerabilities are similarly severe. ColdFusion in particular has a long history of active exploitation — attackers have repeatedly targeted unpatched ColdFusion instances within days of disclosure. Organisations running either platform should treat patching as urgent. Australian government entities using ColdFusion-based web applications should cross-reference ASD's Essential Eight patching timelines, which classify internet-facing critical vulnerabilities as requiring patches within 48 hours.
SecurityWeek ↗Citrix Patches NetScaler's New 'HTTP/2 Bomb' and a CitrixBleed-Style Bug
Citrix has pushed out patches for six NetScaler vulnerabilities, including a newly named denial-of-service technique called the HTTP/2 Bomb attack and a high-severity information disclosure flaw that researchers are comparing to the 2023 CitrixBleed bug — one of that year's most heavily exploited vulnerabilities. Citrix is urging immediate patching. NetScaler appliances sit at the network perimeter of many enterprises and government agencies, making them a high-value target; the original CitrixBleed was exploited by ransomware groups and nation-state actors alike within weeks of disclosure. Any organisation running NetScaler should treat this patch cycle as urgent.
SecurityWeek ↗Claude Science: Anthropic Builds an AI Research Assistant for Pharma and Biotech
Anthropic has announced Claude Science, a new flagship product aimed at scientific research — positioned as the scientific equivalent of Claude Code for software engineering. Unveiled at an event for pharmaceutical executives, biotech founders, and researchers, Claude Science can autonomously execute meaningful research tasks from high-level instructions. Anthropic is pitching it as a way to compress timelines for drug discovery, clinical data analysis, and experimental design. The announcement is significant for the AI-in-science race: Google DeepMind's AlphaFold set the benchmark for AI in biology, but Claude Science targets the broader research workflow rather than a single domain. Australian research institutions and universities exploring AI-assisted research should watch the access terms carefully.
MIT Technology Review ↗Sony Is Ending Physical PlayStation Discs in 2028 — and Already Shutting Older Stores
Sony has confirmed it will stop producing physical discs for new PlayStation games from January 2028, making all future releases digital-only. In the same announcement, it revealed it's winding down the PlayStation Store on both PS3 and PS Vita, with closures rolling out across regions through 2027. The timing is pointed: by announcing both moves simultaneously, Sony inadvertently illustrated the core argument against going all-digital — once the store closes, those purchases vanish. Microsoft, meanwhile, is reportedly testing a disc-to-digital conversion feature for existing Xbox physical libraries, suggesting the two companies are taking meaningfully different approaches to managing the transition for their existing customer bases.
The Verge ↗Cloudflare Gives AI Crawlers Until September to Pay Up or Get Blocked
Cloudflare has announced a new policy giving AI companies until 15 September to separate the web crawlers they use for search indexing from those used for AI training and agents. Miss the deadline, and those crawlers risk being blocked by default across the many publisher sites that use Cloudflare's infrastructure. The policy is a meaningful escalation in the ongoing dispute between publishers and AI companies over the economic value of scraped content. Cloudflare sits in front of a large slice of the web, giving it unusual leverage to enforce this kind of structural separation at scale. For Australian media organisations and publishers, it's worth assessing whether Cloudflare's tooling offers a practical mechanism to enforce their own crawler policies.
TechCrunch ↗Skills SA Builds a Multi-Agent AI Workflow It Plans to Reuse Across Government
South Australia's Skills SA has developed a multi-agent AI workflow to handle compliance checking for vocational education and training providers — and is deliberately architecting it as a reusable pattern for other government processes. Rather than building bespoke AI tools for each task, the agency is treating the underlying workflow structure as an institutional asset that can be adapted. It's a pragmatic approach that contrasts with the one-off AI pilots common across Australian public sector agencies. If the pattern holds, Skills SA could provide a template for how state governments scale AI adoption without repeatedly reinventing the wheel — a live example of the kind of structured AI deployment The Mandarin's recent analysis suggested Australian agencies need.
iTnews ↗