Self-hosted email is in steep decline, Microsoft and Google are taking over
Oh great, Big Tech is now in prime position to decide which messages get through
Aggregated from vendor advisories, security research, and industry publications.
Oh great, Big Tech is now in prime position to decide which messages get through
CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1. The post CISA Warns of Exploited Gitea Vulnerab…
Amid talk of an Nvidia deal, the AI search biz is looking beyond the cloud
Delayed, flawed, yet still beautiful
Cisco is partnering with Supermicro to bring the server vendor’s liquid- and air-cooled systems into Cisco’s AI infrastructure portfolio. Specifically, Cisco will begin offering hi…
The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]
With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.
Article URL: https://sethmlarson.dev/when-str-lower-is-a-security-vulnerability Comments URL: https://news.ycombinator.com/item?id=49440410 Points: 178 # Comments: 75
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock fe…
The cost of memory makes this an expensive ML meal
Shared memory is live, with no option to separate it between services, Anthropic tells us; Claude Code stays apart for now
Attackers can exploit a security bug in Nvidia's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corrup…
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" again…
Fasten your seatbelt and empty that bladder: AI investment is rising, but reported enterprise earnings impact remains stubbornly flat
If you’ve been spinning up AI tools — Claude Desktop, Cursor, Copilot, and so on — there’s a decent chance that API keys, credentials, and access tokens are sitting in plaintext on…
State and local regulators would decide whether the public gets a say on minor-source permits
TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation. The post Linux Foundation to Govern TRACE, an Open Standard for AI Runtime At…
By popular demand, Keith is joined once again by Ferney Muñoz and Tom Hildebrand to answer listener questions and to dive deeper into designing high-density Wi-Fi for large-scale e…
Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert
Current Exchange connector is retiring - and new ones won't work if you don't upgrade
A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...…
OpenAI wants you to thank it for keeping a permanent record of all your discussions with its bots
As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security.
Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]
Dutch electronics giant saw right through ex-engineer’s plot, albeit over a year after it all unravelled
The company, previously known as ActiveFence, has raised a total of $280 million from investors. The post Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails a…
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI age…
Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronger identity verification…
128 chips, 1.7 exaFLOPS, and 27 TB of HBM give Altman and crew a leg up over Blackwell, and maybe even Rubin