New York becomes first state to halt datacenter buildouts
50 MW-plus bit barn builds on hold while Empire State hashes out rules to protect the environment and ratepayers
Aggregated from vendor advisories, security research, and industry publications.
50 MW-plus bit barn builds on hold while Empire State hashes out rules to protect the environment and ratepayers
Microsoft has released the Windows 10 KB5099539 extended security update, which includes this month's record-breaking July 2026 Patch Tuesday fixes, along with additional security …
The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. The post Synopsys Finds No Evidence of Data …
SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The v…
Today is Microsoft's July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and on…
Risk tolerance, exposure visibility, board oversight — handling third-party risk is complicated but achievable with disciplined, precise governance.
Host Keith Parsons recently launched the WLAN Pros Toolbox, a multi-function app with all the calculators, live tools, reference materials, and Wi-Fi readings you need. Today, Keit…
Microsoft has released Windows 11's June 2026 Update for version 25H2, 24H2, and 23H2, bringing fixes for over 570 security issues. [...]
Drew talks with Joao Soares, Lead IT Security Consultant, about a project Joao undertook to automate firewall rule changes. Firewall changes can be fraught in any environment, but …
Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Cale…
The ColdFusion security defects could allow attackers to execute arbitrary code or elevate their privileges. The post Adobe Patches Critical ColdFusion Vulnerabilities appeared fir…
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target …
Industry, regulate thyself
Callum Dare encouraged others to carry out dangerous hoaxes, made mini-movies from the footage
Progress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released securi…
This is a current list of where and when I am scheduled to speak: I’m speaking (virtually) at the Policy-Relevant Privacy Research Workshop in Calgary, Canada, on Monday, July 20,…
Cutting-edge artificial intelligence models are deploying with more independence and less human oversight. Several state governments are trying to legislate transparency in their u…
The attack vector is available for rent at scale, and evades AV and EDR, leaving YARA analysis as the best detection option.
Who are you, and what have you done with Microsoft?
LastPass is warning users about an ongoing phishing campaign that is using fake security notices to direct them to fraudulent websites. [...]
HFI proposes a familiar PC-style route from power-on to operating system
CEO Krishna: Customers blew their Z budgets on servers and storage before prices spike, Q2 financials 'disappointing'
Many vulnerabilities cannot be safely validated with live exploits, either because no exploit exists or the affected systems are too critical to test. Picus explains how TTP chaini…
The flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal. The post 7 Severe Vulnerabilities Patched in VMware Avi …
Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client s…
Solar observatory awaits a new launch date after its original ride hit booster trouble
'Performance is abysmal, bus contention is bonkers, but it does work'
A ClaudeBleed-linked vulnerability reportedly persists across eight patches, exposing potentially sensitive data to other extensions. The post Unpatched Claude for Chrome Flaw Let…
Researchers reported the vulnerability to Cursor in December, but it still remains in the popular AI coding platform and can be exploited in poisoned repository attacks.
Microsoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026. [...]