AI Built Working Browser Ransomware — And the Bar Just Got Lower for Everyone
Wednesday, July 1, 2026 · 5-minute read
Thalha Jubair, 20, and Owen Flowers, 18, admitted in a UK court this week to breaking into Transport for London's computer systems in August 2024 — the attack that knocked out online services for millions of commuters. The pair are key members of Scattered Spider, a group linked to ransomware hits on MGM Resorts, Marks & Spencer, and over 120 other organizations. US prosecutors say victims paid at least $115 million in ransom to the group.
↗ Krebs on SecuritySecurity researchers confirmed this week that millions of unofficial Android TV boxes — the kind that promise free access to streaming services for a one-time fee — are enrolled in a massive botnet called Popa. The botnet quietly turns your home internet connection into a paid proxy service that strangers can route their traffic through. Researchers linked Popa to NetNut, a residential proxy provider operated by Israeli firm Alarum Technologies, which trades on the Nasdaq.
↗ Krebs on SecurityInsurance giant Aflac disclosed a fresh data breach after attackers broke into its Japanese subsidiary and stole personal and bank account details belonging to 4.38 million customers. The incident is a reminder that a company's weakest security link is often a smaller subsidiary in another country. If you're an Aflac customer in Japan, watch your bank statements closely.
↗ BleepingComputerCISA confirmed that ransomware groups are actively exploiting a Windows vulnerability nicknamed BlueHammer. Ransomware gangs are using the flaw to break into Windows machines, encrypt files, and demand payment. CISA added the bug to its Known Exploited Vulnerabilities catalog, meaning US government agencies must patch urgently — and you should too.
Researchers at Palo Alto Networks found that large language models frequently invent web addresses that don't actually exist. Attackers are now registering those made-up domains before anyone else can, then parking phishing pages on them. In a study of 685,339 queries about 913 well-known brands, AI models handed out over 2.1 million links — and more than 13,000 of them were already flagged as malicious. No suspicious email needed: just follow a link your AI assistant gave you.
This Windows flaw lets attackers run malicious code on your machine without needing your password. Ransomware gangs are already using it to lock up victims' files and demand payment. CISA has added it to its official list of vulnerabilities that are actively being exploited right now.
Status: Patch available via Windows Update — install immediately.
Adobe patched seven maximum-severity bugs in ColdFusion, a platform used to build web applications, and Campaign Classic, a marketing tool. Maximum-severity means an attacker could potentially take complete control of an affected server with no login required. If your business uses either product, this needs attention today.
Status: Patch available — Adobe has released security updates. Apply immediately.
Over 900 Oracle E-Business Suite instances are sitting exposed on the public internet and being actively attacked. Oracle EBS is business software used by large companies to manage finance and HR. Attackers are exploiting a known security flaw to break in. If your company uses Oracle EBS, check whether your instance is publicly accessible.
Status: Patch available — ongoing active exploitation means delay is not an option.
Microsoft announced it is speeding up its plan to replace today's encryption standards before powerful quantum computers can crack them. The company's Azure CTO said quantum computers capable of breaking current encryption could arrive sooner than previously expected, so Microsoft is now targeting 2029 for all critical products and services. The program will upgrade network security protocols and bake post-quantum cryptography requirements into its Secure Future Initiative. For most regular users, this will happen quietly in the background — but it signals how seriously the industry is taking the coming shift.
Microsoft rolled out a new admin policy for Teams that lets meeting organizers block third-party bots from joining calls without explicit permission. As AI-powered meeting assistants have multiplied, so have concerns about uninvited bots quietly sitting in on sensitive business conversations and recording or summarizing them. This new control gives IT teams a way to enforce meeting hygiene across the whole organization. It's a small but welcome step toward giving people back control of who — or what — is actually in the room.
Security researchers at Check Point dropped a genuinely unsettling finding today: they used the AI model DeepSeek to generate a working ransomware attack that runs entirely inside a web browser — no download required. Until now, security experts broadly agreed that browsers were safe from ransomware because of something called sandboxing. The idea was that even if an attacker got code running in your browser, it couldn't escape into your files. This research proves that assumption wrong.
Here's the key detail: DeepSeek didn't just write dangerous code on request. It independently figured out how to combine a theoretical attack idea — one that security experts had long dismissed as impractical — with a real, obscure feature of the Chromium browser engine to make it work. The AI bridged a gap that human researchers hadn't crossed. The resulting attack is a Python web application that can lock down browser-accessible content and demand payment, all without ever touching your hard drive directly.
Why does this matter for regular people? Because it means the bar for building new, novel cyberattacks just dropped dramatically. Previously, discovering a brand-new attack method required deep, specialized expertise built up over years. Now an AI can do that discovery step automatically. Check Point put it bluntly: "The expertise needed to discover a new attack path is no longer the bottleneck." That's a fundamental shift in how fast new threats can appear.
For now, this specific attack has only been documented by researchers, not used in real criminal campaigns. But the clock is ticking. Watch for browser security updates from Chrome and Edge in the coming weeks, and be extra cautious about leaving browser sessions open on sensitive accounts when you're not actively using them. The era of "AI-assisted" attacks is no longer hypothetical — it's here.