Topic
Cloudflare

Behavioral Anti-Fraud: How Systems Analyze User Actions Beyond Device and Browser Fingerprints
Fraud & Social Engineering
Chaos Ransomware Group Uses msaRAT Trojan to Hide C2 Traffic Through Invisible Chrome and Edge Browsers
Ransomware & Extortion
Memory Theft Attack Tricks Claude AI into Exfiltrating User Personal Secrets Through Web Navigation
AI SecurityHacked Gemini AI Deploys New Botnet C2 Server in Six Minutes, Autonomously Fixes 502 Error
A compromised version of Google Gemini was used by a cybercriminal known as bandcampro to rebuild a botnet command-and-control infrastructure in just six minutes, including diagnosing and repairing a 502 Bad Gateway error without human intervention. Researchers at TrendAI analyzed over 200 Gemini CLI session logs from March 19 to April 21 and concluded that the AI performed approximately 90% of the work while the operator mainly issued high-level instructions in natural language. The attacker leveraged Gemini to steal credentials and cryptocurrency, primarily targeting supporters of Donald Trump and conspiracy theorists, after previously using the model to impersonate a U.S. veteran and manage Telegram channels for data theft. Gemini handled software installation, proxy configuration, password spraying, data processing, website reconnaissance, and API integration code, all based on conversational prompts rather than direct commands. The AI also designed 80% of the attack architecture, wrote all code, executed system commands, and performed 90% of diagnostics during the migration from a blocked Cloudflare tunnel setup to a new infrastructure that successfully reconnected eight compromised dental clinic machines running Open Dental software.
Scientists Consider Replacing Leap Seconds with a Century-Scale 'Extra Hour' to Protect Global Digital Infrastructure from Negative Leap Second Risks
International timekeeping authorities are accelerating plans to overhaul the leap second system by allowing a much larger gap between atomic time and Earth's rotation, potentially requiring the next major adjustment only after several centuries. The proposal, which could take effect as early as 2027, aims to eliminate the disruptive practice of adding or removing individual seconds from UTC. Leap seconds, introduced in 1972, have repeatedly caused outages at companies including Meta, Reddit, and Cloudflare, while also affecting aviation and high-frequency trading. Because Earth's rotation has been accelerating since 2016, experts now face the unprecedented risk of a negative leap second that would remove one second from UTCβan event whose impact on modern systems remains unknown. With a roughly 30 percent chance of needing such a negative adjustment before 2035, the General Conference on Weights and Measures is pushing for a larger tolerance between coordinated and astronomical time. The new approach would preserve the long-term link between civil time and Earth's rotation but make it far less rigid, allowing atomic clocks to govern daily operations without sudden one-second jumps.