Five Eyes spooks warn AI means infosec incidents can become ‘major operational and financial crises’
Bosses told to step up and get cybersecurity right
Aggregated from vendor advisories, security research, and industry publications.
Bosses told to step up and get cybersecurity right
PLUS: Indian telco ponders broadband satellites; Samsung goes all-in on OpenAI; Vietnam centrally plans ten tech giants; and more!
OpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative the artificial intelligence (AI) company…
Package dependencies can create vulnerabilities that are fiendishly hard to find and stamp out
A plethora of pwn-prevention, including a 'Patch The Planet' pledge
An ongoing malware campaign is targeting WhatsApp users in multiple countries with deceptive messages that push VBScript files, leading to remote system access. [...]
The JaredFromSubway Ethereum MEV (Maximal Extractable Value) bot suffered a $15 million loss after an attacker manipulated the opportunity-detection logic by creating fake cryptocu…
Four vulnerabilities allow attackers to exploit Dify, a platform for AI application building and management, to silently access and exfiltrate sensitive data.
A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-servic…
Dell’s new high-end Nvidia-based server is a centerpiece for its integrated AI platform aimed at enterprise customers with major AI infrastructure plans. The Dell PowerEdge XE88…
Nvidia has formally launched the Vera Rubin platform, a combination CPU and GPU platform billed as a major step forward in the convergence of artificial intelligence and high-perfo…
The air turns brown when bit barns come to town … deep in the heart of Texas
The Bundesliga has long talked about turning “data into devotion,” and now it has an agentic AI companion in its official app that lets fans chat in natural language, access live s…
Makers of Chrome, Edge, Firefox back bot-fraud defense called Private Access Control Tokens
Security firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from compromised firewal…
As yet another extortion crew Icarus exploits Salesforce-linked integrations
Tireless AI agents could help scientists do research humans alone can't, says GPU giant
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push bac…
From academic toss-aside to cloud substrate
Microsoft has confirmed that Windows 11 version 26H2 will be the next feature update and that devices running Windows 11 24H2 and 25H2 will be able to upgrade using a small enablem…
Take a Network Break! Our Red Alert covers critical vulnerabilities found in OpenClaw, the open-source AI assistant. On the news front, we discuss the status of Anthropic’s Project…
A vulnerability chain dubbed AutoJack in Microsoft's AutoGen Studio interface for prototyping AI agents could let attackers manipulate an agent into executing arbitrary commands on…
TrophyLab bad for Vlad as battlefield losses spill the secrets they had
One can't help but see a very clear instance of the triple constraint problem in action here
Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, that could allow att…
Attackers are using multiple online channels — including GitHub, YouTube, and VirusTotal — to build an illusion of trust to spread a cross-platform clipboard hijacker.
Some hardware firms redesigning products to use older DDR2 and DDR3 components
'Humans are not going to be using data platforms in the next three to five years,' product exec tells us
A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send tr…
London Hydro says names, addresses, account details may have been exposed, but much about the intrusion is unknown