Latest Internet & Cybersecurity News

📅April 16, 2026 at 1:00 PM
AI cybersecurity models from OpenAI and Anthropic advance defenses amid rising ransomware, NTP attacks, and exploits; global threats intensify in 2026.
1

NTP Time Warp Attack Disrupts Global Finance and Emergency Services

Attackers hijacked network time protocol nodes, shifting system clocks by 1.5 seconds to trigger high-frequency trading glitches and disrupt hospitals for eight hours.Source 1 This synchronized attack highlights vulnerabilities in time synchronization infrastructure.Source 1 CISA issued emergency directive 26-47 for audits of modular data center controllers due to Liquid Logic exploit risks.Source 1

2

OpenAI Launches GPT-5.4 Cyber for Defensive Cybersecurity

OpenAI unveiled GPT 5.4 Cyber, a permissive AI model for cyber defense including binary reverse engineering, limited to vetted users via Trusted Access for Cyber.Source 3 It follows Anthropic's Claude Mythos, amid concerns over AI-enabled threats.Source 3 OpenAI offers $10M in API grants to security firms.Source 7

3

Anthropic Restricts Claude Mythos Over Exploit Capabilities

Anthropic's Claude Mythos Preview identifies thousands of unknown vulnerabilities in OS like Linux kernel but is limited to 12 partners due to cyberattack risks.Source 3 Released under Project Glasswing to harden critical software first.Source 3Source 4 Governments review risks from this powerful model.Source 4

4

Ransomware Hits Elevated New Normal in Q1 2026

GuidePoint reports steady ransomware volumes QoQ and YoY, with The Gentlemen rising to second most active at 182 victims.Source 5 Qilin leads with 361 but down 25%, Akira down 22%.Source 5 Clop continues Oracle E-Business Suite exploitation claims.Source 5

5

PwC: Cyber Resilience Spending Lags Behind AI Threats

PwC’s 2026 Digital Trust Insights shows spending lags as AI-driven threats, ransomware, and insider risks rise.Source 2 Organizations must boost investments amid intensifying attacks.Source 2 Report emphasizes need for updated strategies.Source 2

6

Nginx-ui MCP Authentication Flaw Actively Exploited

Missing authentication in Nginx-ui MCP allows same-network attackers to alter configurations for full takeover.Source 6 Exploit is actively used in the wild.Source 6 Organizations urged to patch immediately.Source 6

7

Vishing Attacks Surge on Okta to Bypass MFA

Vishing targets Okta identity systems to bypass MFA and access SSO data broadly.Source 6 Attackers exploit voice phishing for credentials.Source 6 Enhanced verification recommended.Source 6

8

Black Basta Affiliates Use Teams Phishing on Executives

Suspected ex-Black Basta groups impersonate help desks via Teams to deploy RMM software.Source 6 Targets high-level executives for persistence.Source 6 Improved phishing training advised.Source 6

9

OpenAI macOS App Hit by Axios Supply Chain Attack

OpenAI revokes certificates after Axios supply chain attack on macOS app-signing.Source 6 Action taken out of caution to prevent abuse.Source 6 Users should update apps.Source 6

10

Microsoft 365 Mailbox Rules Abused for Exfiltration

Attackers misuse M365 rules to hide data theft and persist post-reset.Source 6 Enables stealthy exfiltration.Source 6 Monitoring rules critical for detection.Source 6

11

AI Browser Extensions Show Higher Vulnerability Risks

Report finds AI extensions more prone to known flaws and risky permissions like cookies.Source 6 Increased scrutiny needed for AI tools.Source 6 Users should review permissions.Source 6

12

Bessent and Powell Meet Bankers on Claude Mythos Impact

Top officials discussed Claude Mythos cybersecurity effects with bankers.Source 6 Urges firms to boost cyber spending like large banks.Source 6 Highlights AI threat urgency.Source 6