Is this email difficult to read? View it in a web browser. ›

The Wall Street Journal ProThe Wall Street Journal Pro

CybersecurityCybersecurity

Sponsored by Zscaler logo.

Zcash Plunges After Researcher Discovers Critical Bug

By Kim S. Nash

 

Hello. Zcash, a digital token backed by some of bitcoin’s early evangelists, plunged about 40% in the 24 hours after a security bug was widely disclosed.

This, despite Zcash having fixed the bug the day after it was discovered.

The researcher, using Anthropic's Opus 4.8 AI model, identified a counterfeiting vulnerability in Zcash’s “Orchard pool,” a part of the blockchain where users’ transaction details are hidden to protect their privacy. Read more from WSJ. 

Also today: 

  • U.S. intel, military bodies must step up use of AI: Trump memo
  • Meta says 20,000+ Instagram users breached
  • OpenAI's new 'lockdown mode'
  • What's in the House's new AI bill
  • Cyber stocks hit in tech rout last week
 

‏‏‎ ‎

CONTENT FROM: ZSCALER
The CSA Mandate: Deploy Deception In the Next 90 Days

In response to Mythos, the Cloud Security Alliance issued an emergency briefing with 11 priority actions, endorsed by 250+ CISOs. One is urgent: build a deception capability in the next 90 days. Watch Zscaler EVP & CSO, Deepen Desai, explain why traditional detection controls fail against agentic threats and why Deception is needed to stop these machine-speed attacks. Protect your business today.

Watch the video

 

More Cyber News

PHOTO: SGT. COLLIN MACKALL/U.S. ARMY

U.S. intelligence and military bodies will accelerate their use of AI under a national-security memo out Friday from President Trump. Defense Secretary Pete Hegseth must update within 90 days an existing directive on weapons autonomy "to ensure the deliberate adoption of AI systems that respect the chain of command," the memo said. (Reuters) 

U.S. AI bill calls for “independent verification organizations” to check that makers of frontier AI models comply with rules for being transparent about security and other risks. The Great American Artificial Intelligence Act, proposed by a bipartisan group of lawmakers in the House, would preempt state AI laws. (Cybersecurity Dive)

  • Here is the full 269-page draft of the bill.
 

Friday’s carnage in tech stocks​ took cybersecurity shares with it. Just four of the largest cyber stocks by market cap closed in the black on Friday, pushing the WSJ Pro CyberIndex down nearly 9% for the week.

Lumen registered the biggest loss, falling 17.8%. Six stocks fell more than 10% in the period.

No stock rose more than 2%, with Cisco seeing the biggest gain at 1.82%.   — Jon Leckie

OpenAI began rolling out "lockdown mode" for ChatGPT, to help protect users of the chatbot from having data stolen by hackers using prompt injection attacks. 

Worst breaches: Six months into 2026, TechCrunch outlined the biggest breaches so far this year. Among them are hacks on water and energy grids worldwide, the cyberattack at medical-device maker Stryker by hackers linked to Iran, and various data leaks attributed to missteps in the U.S. government during DOGE purges across agencies.

20,225

Number of people affected in a May 31 hack of an AI-assisted account recovery tool in Instagram, according to a notice to state regulators from parent company Meta.  

Data at risk for these users includes: 

● Email address, phone number
● Date of birth
● Social media posts and content (photos, videos, stories)
● Direct messages and communications
● Account activity and interaction history
● Profile information (biography, profile photo)
● Connected accounts and linked services

Meta said it is reviewing similar account recovery flows across its platforms for similar issues. 

 

About Us

The WSJ Pro Cybersecurity team is Deputy Bureau Chief Kim S. Nash and reporters Angus Loten and James Rundle. Follow us on X @WSJCyber. Reach the team by replying to any newsletter you receive or by emailing Kim at kim.nash@wsj.com.

 
Share this email with a friend.
Forward ›
Forwarded this email by a friend?
Sign Up Here ›
 
Desktop, tablet and mobile. Desktop, tablet and mobile.
Access WSJ‌.com and our mobile apps. Subscribe
Apple app store icon. Google app store icon.
Unsubscribe   |    Newsletters & Alerts   |    Contact Us   |    Privacy Notice   |    Cookie Notice
Dow Jones & Company, Inc. 4300 U.S. Ro‌ute 1 No‌rth Monm‌outh Junc‌tion, N‌J 088‌52
You are currently subscribed as [email address suppressed]. For further assistance, please contact Customer Service at pro‌newsletter@dowjones.com or 1-87‌7-975-6246.
Copyright 2026 Dow Jones & Company, Inc.   |   All Rights Reserved.
Unsubscribe