Home/News

Security & Lifecycle News

Aggregated from vendor advisories, security research, and industry publications.

The Hacker News

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. "The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second

Schneier on Security

Some Claude Chats Are Searchable on Google

And it’s personal information (alternate link): The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard some…

Schneier on Security

More on the OpenAI Agent’s Attack on Hugging Face

Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchma…

Network World

Nvidia’s next move? Financing AI

Over the past two decades, Nvidia has greatly expanded beyond its gaming GPU roots, delving into high-performance computing, entering the CPU business, establishing a dominant posi…

↑ Top