Millions of California-bought cars can be hijacked via Bluetooth
Aftermarket dealer-installed KARR/SWDS security systems all use the same secure key, say UCSD researchers
Aggregated from vendor advisories, security research, and industry publications.
Aftermarket dealer-installed KARR/SWDS security systems all use the same secure key, say UCSD researchers
Linux systems using the XFS filesystem suffer from a race condition that could enable an unprivileged local user to gain full root access. The flaw affects systems with Linux ke…
Microsoft is impacted by a massive outage affecting Teams and Microsoft 365 services, primarily affecting users in North America. [...]
Experts say the era of AI bug hunting is here, so defenders will simply have to adapt to busier workloads
Code shack also putting new limits on first-time researchers, and reserving the biggest rewards for a hand-picked group of proven hunters
AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. The post OpenAI Fixes ChatGPT Agent Flaw That C…
Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders…
You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. The post Is Patching D…
Threat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts. The post Chick-fil-A Accounts Get Fried in Credential Stuffing Attack appeared f…
Defense research agency DARPA made its largest quantum computing award ever this week, with a $125 million agreement announced on Wednesday. The same day, the White House announced…
CISA widens alert beyond Rockwell controllers as intruders target internet-facing devices across critical infrastructure
Revenue from IBM’s z mainframe portfolio sunk 42% in the quarter ended June 30, dragging infrastructure revenue down 7% compared to the year-ago quarter. But Big Blue executives re…
FedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition fr…
The latest investment round brings the total raised by Abstract to nearly $50 million. The post Abstract Raises $25 Million to Expand Composable Security Operations Platform appear…
Optimus remains 'very complex' and Robotaxis will try not to flatten your cat
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine …
The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised…
Researchers say OpenAI flaw let phishing bait create an autonomous corporate mole armed with employee access
SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips…
Google’s AI offerings span its internal and cloud offerings. Its data centers are processing seven times more AI tokens compared to last year. To keep up, Google is upgrading its d…
The European Commission fined Google €890 million ($1 billion) on Thursday after finding the company had violated the European Union's Digital Markets Act (DMA), which ensures fair…
You'll need to be able to move your head side to side to make sure you're not a deepfake
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations …
Google’s data center team is racing to turn its infrastructure into a well-oiled machine for AI and the onslaught of agents. At this year’s Google I/O, CEO Sundar Pichai shared sta…
Stadler refuses $12.3M demand after thieves swipe technical data through supplier platform
Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instea…
A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root priv…
Big Blue says customers postponed rather than abandoned major purchases as hardware soaked up enterprise budgets
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel…
Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers.