ShinyHunters Claims Second Attack Against Instructure
The edtech company is struggling to wrest control from its hackers. PII belonging to hundreds of millions of people is on the line.
Aggregated from vendor advisories, security research, and industry publications.
The edtech company is struggling to wrest control from its hackers. PII belonging to hundreds of millions of people is on the line.
Not just for hated US Presidents, now even tech bros lament their foes
Scott Robohn is joined by networking legend Jeff Doyle to help us understand SONiC: Software for Open Networking in the Cloud. SONiC is an open-source network operating system and …
Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that's capable of targeting 59 banking, fintech, and cryptocurrency platforms. The a…
A Mastercard survey reveals that 46% of small and medium businesses have experienced a cyberattack, and nearly 20% of those that suffered an attack were then forced to file for ban…
Article URL: https://www.jefftk.com/p/ai-is-breaking-two-vulnerability-cultures Comments URL: https://news.ycombinator.com/item?id=48066524 Points: 430 # Comments: 173
Insider trading is rife on Polymarket: Analysis by the Anti-Corruption Data Collective, a non-profit research and advocacy group, found that long-shot bets—defined as wagers of $2…
All your compromised credentials are belong to us now instead of the other gang
Twin brother still faces trial over broader cybercrime allegations
Article URL: https://www.webdesignmuseum.org/flash-game-exhibitions/cartoon-network-flash-games Comments URL: https://news.ycombinator.com/item?id=48065360 Points: 419 # Comments: …
NVIDIA has confirmed in a statement for BleepingComputer that GeForce NOW user information has been exposed in a data breach. [...]
BCS says builders face up to 20% material hikes and patchy deliveries
Sonia Fernández-Vidal has spent her career making the strange world of quantum physics feel tangible: first in the laboratory, then on the page, and now in the gallery. A doctor in…
Cybersecurity researchers have discovered fraudulent apps on the official Google Play Store for Android that falsely claimed to offer access to call histories for any phone number,…
An OpenAI-led consortium of tech giants including AMD, Broadcom, Intel, Microsoft, and Nvidia have unveiled a new networking protocol designed to address network congestion, a prob…
Other noteworthy stories that might have slipped under the radar: US gov targets 72-hour patch cycles, malware uses Windows Phone Link to steal OTPs, spy operation targets Eurasian…
Remote access software could bring mixed fleets under one roof, assuming enough people ask for it
Attackers move faster than overwhelmed SOC teams can realistically investigate alerts. Prophet Security breaks down how AI can help analysts investigate alerts faster and focus on …
Broken disclosure embargo left admins facing a fresh root-level flaw with no CVE
The attack on the Trellix source code repository disclosed last week has been claimed by the RansomHouse threat group, which leaked a small set of images as proof of the intrusion.…
In a word, 'Huh?'
After years of insisting end-to-end encryption was the future of online comms, Zuckcorp has handed itself full visibility into user chats once again
A few hundred lines of Yabasic recreate just enough to keep modal editing muscle memory alive
Home Office finds 80% of code cannot be reused, balks at £26M in extra costs
CISA has given U.S. federal agencies four days to secure their networks against a high-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM) exploited in zero-day attacks…
A power outage triggered by a thermal event inside an Amazon Web Services data center in Northern Virginia disrupted Elastic Compute Cloud (EC2) instances and Elastic Block Store (…
Ryan Cohen briefly banned after bootstrapping cash ostensibly to buy the auction site
The hackers gained the ability to modify equipment operational parameters, creating a direct risk to the public water supply. The post Polish Security Agency Reports ICS Breaches a…
Hackers accessed one of the company’s AWS accounts and compromised AI provider secrets stored in Braintrust. The post AI Firm Braintrust Prompts API Key Rotation After Data Breach …
A previously undocumented Linux implant codenamed Quasar Linux RAT (QLNX) is targeting developers' systems to establish a silent foothold as well as facilitate a broad range of pos…