Jensen puts his thumb on the scales against open-weights fearmongering
American AI flag bearers get in line, at least on paper
Aggregated from vendor advisories, security research, and industry publications.
American AI flag bearers get in line, at least on paper
Just don’t call the WinRT projection for Node.js a lock-in
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. […
A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially …
This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers' access controls.
Researchers find GLM and Kimi can adopt Claude's identity, but the evidence stops short of proving distillation
An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time.
MDASH stuffed with MAI-Cyber-1-Flash and a side of GPT-5.4
As attackers shift from password theft to session and token theft to bypass multifactor authentication controls, organizations must move beyond login security and protect authentic…
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelli…
Confidence in autonomous security tools is declining, and here's why.
Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Stor…
A recent market outlook from energy intelligence firm Currence estimates that between 30% and 50% of the large-scale data center capacity expected to come online in 2026 will likel…
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement o…
Take a Network Break! Scott Robohn steps in for Johna this week. We start with some followup on 3M and then tackle the news. Arista catches up to the rest of the market on a “branc…
The Open Security AI Alliance says the Hugging Face/OpenAI mess proves frontier labs can't be trusted to properly secure sensitive systems
Is there a simulator for the wail when you realize your precious one-off bootleg has just been chewed up?
The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. [...]
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via …
Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The a…
Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. The post New GitHub, PyPI Policies Boost Sup…
Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems sta…
Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and gov…
One bug disabled the security service on restart, another blocked installation on hardened RHEL systems
The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware C…
n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation pla…
History's biggest infrastructure build-out is pushing up hardware and software prices, analyst says
The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The po…
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) …
Tekever AR5 drone regarded as more up-to-date answer to provide battlefield surveillance for soldiers