Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
Audit logs found no unexpected visitors, but release verification still needs an update
Aggregated from vendor advisories, security research, and industry publications.
Audit logs found no unexpected visitors, but release verification still needs an update
Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the compa…
Interesting empirical research: “Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI.” Abstract: How is AI transforming decision-making in modern confli…
The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data. The post Extension Banned for Stealing AI Chats Returns to Chrome Store, Re…
Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) a…
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM acc…
The bigger risk is underinvestment, claims consulting biz McKinsey
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obvious…
Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did. The post Hacker Conversations: Marcu…
U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomwar…
OpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI. The post OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber appeared…
Researchers find standards-compliant functionality can be abused to hijack modems, downgrade connections, and even execute code
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the worl…
SPONSORED EXPLAINER: There's nothing wrong with hybrid cloud. It's the one-size-fits-all strategy on top of it that's the problem.
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid o…
The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appe…
Gaming servers get the steepest rises but sticker shock is also coming to conventional instances running on old and new boxes
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins tea…
H3 rocket gets the job done after losing a bird last year
Solves tech support tickets faster and more accurately by keeping them away from LLMs
EU rules cited as reason for effort to trace AI output ancestry
Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Tech…
New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents.
Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.
$125 a month? So, how good are those open-weight models getting, again?
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' …
Franklin project adds new security providers, employs digital twins and AI
The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.
Mark Zuckerberg muses about 'superintelligence' and 'arc of human civilization'
30-billion parameter LLM, Meta's first in more than a year, signals Meta's return to the open weights arena. Open version of Muse Spark to follow