[SECURITY]
STORIES FROM THE SECURITY DESK ■ LAST 14 DAYS ■ RSS
■ SECURITY
100 STORIESSecurity research firms METR and Redwood have published a detailed postmortem examining the HuggingFace security incident. The analysis provides technical insights into how the breach occurred and what systems were compromised.
More than a decade of Steam files, including beta builds and finished games from Valve and third-party developers, have been exposed in a major data leak totaling over 12 terabytes.
A new vulnerability called Omarchy allows any user-level process to gain root privileges through privilege escalation. The flaw has sparked significant discussion in security circles.
Hacking group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group. Security researchers confirmed the breach included detailed customer, booking, and travel records.
Multiple extensions in the Chrome Web Store and Microsoft Edge delivered malware that stole cryptocurrency, browser data, and user history while injecting fraudulent ClickFix lures.
A new survey reveals strong public opposition in the UK to government surveillance of encrypted communications. The findings highlight growing concern over privacy rights as lawmakers continue debating message scanning proposals.
PaperCut has released a second emergency security update for its NG and MF print management software after researchers discovered bypass methods for the initial fixes. The vulnerabilities are currently being exploited in the wild.
A 68-year-old has been sentenced to over six years in prison in the U.K. for operating an illegal IPTV service that generated £980,812 ($1.3 million) over three years.
A detailed analysis examines how the internet has shifted toward predatory practices, drawing significant engagement from tech community members on Hacker News with 227 points and 120 comments.
A critical vulnerability in the popular GiveWP WordPress donation plugin allows unauthenticated attackers to execute arbitrary commands on hosting servers. The maximum-severity flaw requires immediate patching.
Over 8,300 internet-facing Gitea instances remain unpatched against a critical vulnerability being actively exploited in remote code execution attacks, according to Shadowserver.
A sanctioned Iranian cybersecurity training company has announced its largest recruitment class yet, intensifying concerns about continued cyberattacks targeting U.S. entities.
Artificial intelligence is accelerating the rate at which security flaws are discovered, overwhelming traditional remediation systems designed for slower timelines. Organizations now face pressure to modernize their vulnerability management infrastructure.
Nicola Coughlan, Hugh Bonneville, and Matt Lucas are among approximately 80 signatories backing a campaign to ban AI voice cloning. The group has submitted an open letter to Manchester Mayor Andy Burnham demanding legal protections for voice ownership.
Brave browser version 1.94 now includes Email Aliases, a feature that generates disposable email addresses for new service signups. The tool helps users mask their primary email and reduce tracking across platforms.
The Department of Homeland Security is leveraging a little-known legal provision to request records from journalists, non-profits, and unions, according to reporting from The Guardian. The tactic raises concerns about surveillance overreach and First Amendment protections.
Major artificial intelligence companies have issued urgent warnings that a significant cybersecurity threat could materialize within months. The alert comes as hackers continue targeting critical infrastructure across the United States.
Authorities have arrested two alleged members of TeamPCP, a hacking group responsible for infecting over 1,000 organizations through supply-chain attacks.
A Georgia police officer used Flock surveillance technology to track the movements of his ex-partner and another officer after their affair ended, according to internal investigation records.
McKesson, a major healthcare and pharmaceutical distributor, confirmed a cybersecurity incident involving unauthorized access to third-party applications. Extortion group ShinyHunters claims responsibility for stealing 284 million patient data records.
Fraudsters are exploiting Microsoft Teams and similar enterprise chat apps to deceive Chinese users into sending large sums of money. The trend has sparked a wave of complaints across the region.
The Bureau of Alcohol, Tobacco, Firearms and Explosives has notified Congress of a major cybersecurity incident after a ransomware gang claimed responsibility for breaching the agency's systems.
Google is rolling out Encrypted Client Hello (ECH) support in Android 17 to prevent network monitoring of user browsing activity. The privacy feature strengthens connection security across cellular and home networks.
A new survey shows more Americans oppose police use of license plate readers than support them. The finding reflects growing concerns about surveillance overreach.
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a "major incident" involving a compromised system following claims by the Qilin ransomware group.
Claude, Codex, and Hermes generated 227 install commands referencing code with no identifiable owners, according to analysis of corporate documentation. The discovery raises security concerns about AI-generated dependencies.
Manchester Airports Group disclosed a breach affecting Manchester, Stansted, and East Midlands airports. Hackers accessed data from approximately 8.7 million customers.
A lawsuit alleges that Elon Musk's xAI trained its Grok language models using child sexual abuse material, including both real and AI-generated imagery.
The ShinyHunters extortion group has published sensitive data from nearly 13 million Carhartt customer accounts stolen earlier this month, according to data breach notification service Have I Been Pwned.
A Russian-speaking ransomware gang called Aur0ra exploited SpaceX's Cursor AI coding assistant to breach at least seven companies between mid-April and late May, according to security firm Gambit Security.
Americans are systematically targeting and disabling Flock Safety cameras across the country in a decentralized protest movement. The surveillance devices face everything from vandalism to theft as public opposition intensifies.
The US Justice Department has dismantled online infrastructure used by Chinese state-sponsored hackers targeting NASA, the Federal Reserve, and the Senate. The action represents a coordinated effort to disrupt cyber operations against American government agencies and critical infrastructure.
The U.S. Cybersecurity and Infrastructure Security Agency has issued a mandate requiring all federal agencies to patch an actively exploited remote code execution vulnerability in Citrix NetScaler appliances by Saturday.
A new Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service attacks and root-level privilege escalation.
The FBI has dismantled proxy tools used by Chinese hackers in a widespread campaign against NASA, the Federal Reserve, the US Senate, and the Justice Department. The operation marks a significant coordinated response to months of intrusions into critical US infrastructure.
Snowflake is phasing out password authentication for legacy service accounts, requiring organizations to adopt passwordless methods. The real challenge: identifying which accounts exist, who manages them, and what access they hold.
Medical technology company Boston Scientific disclosed a cyberattack that disrupted IT systems and operations worldwide. The company is working to restore normal services.
The FBI has disrupted infrastructure used by Chinese state-sponsored actors to conduct cyber espionage operations. The takedown targeted a technical quartermaster operation that provided reconnaissance, proxy management, and operational routing capabilities.
The Cybersecurity and Infrastructure Security Agency confirmed that hackers targeted over 100 U.S. water systems in July. The attacks are suspected to be backed by Iran.
PeopleFinders has launched Stud or Dud, a new website that allows users to run background checks on potential romantic partners. The service uses the same public data as PeopleFinders.com.
Pro-Kremlin channels are distributing AI-generated videos of Ukrainian lawmakers calling for peace talks. The fabricated clips accumulated 130,000 views in two weeks, undermining public trust regardless of fact-checking efforts.
Amazon-owned Ring is deploying TAKE encryption across all cameras by default, a method designed to limit police requests for video footage while maintaining AI features like person and package detection.
Find My is a critical iPhone security feature that Apple recommends keeping enabled at all times. Disabling it significantly reduces your ability to locate and recover a lost or stolen device.
Hackers are actively exploiting a critical vulnerability in Gitea, a self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The flaw enables code injection attacks against affected systems.
Hospital operator Nutex Health disclosed that unauthorized attackers stole data from company servers in a cyberattack. The healthcare provider is currently investigating the incident.
The Coalition for Content Provenance and Authenticity's camera authentication system is encountering fundamental technical obstacles that prevent it from functioning as designed in practical deployments.
Illinois county prosecutors secretly provided personal information about criminal defendants to federal immigration agents without warrants, public disclosure, or legislative approval.
Law enforcement from 22 countries arrested 58 individuals and identified 263 suspects in a coordinated crackdown on cybercrime networks run by African crime groups.
The Los Angeles County Museum of Art disclosed a data breach from last year that compromised customer and employee information, including social security numbers and medical records.
A phishing-as-a-service platform called AnonyMousKIT uses voice AI agents to extract passcodes from stolen Apple devices and bypass Activation Lock security features.
Following recent hacks of AI models, companies are debating whether to move cybersecurity testing online. Proponents argue that internet-connected tests provide more accurate threat assessments.
France's tax administration fell victim to a significant security breach, exposing vulnerabilities in one of the country's most critical government systems. Details remain limited as authorities investigate the incident.
A large distributed denial-of-service attack has disrupted Norway's shared government digital infrastructure since Monday, affecting public sector services accessible to citizens.
Security researchers have released a new bootloader that exploits a privilege escalation vulnerability in the original Meta Quest headset, granting users full control and independence from Meta's servers and applications.
WhatsApp is upgrading its two-factor authentication system, replacing six-digit codes with password-based verification. The change aims to provide users with stronger security protection.
WhatsApp is rolling out enhanced account security features including support for multiple passkeys and upgraded two-step verification. The changes replace the previous six-digit PIN system with stronger alphanumeric passwords.
Threat actors have compromised over 270 Zimbra Collaboration Suite instances through remote code execution attacks exploiting a high-severity vulnerability. The ongoing campaign targets organizations worldwide.
Top Chinese military strategists have published analyses detailing artificial intelligence's role in accelerating command decision-making. The writings offer insight into Beijing's military modernization efforts.
Chinese state-backed hacking groups have more than doubled their cyberattacks since adopting AI models to generate exploit code and scan networks, according to Taiwanese cybersecurity firm TeamT5.
AliExpress deployed an outdated browser fingerprinting technique using ultrasonic frequencies to identify and track users. Security researchers discovered the e-commerce platform embedding inaudible sounds in web pages to create unique device signatures.
An unpatched vulnerability in Calix GS7 XGS residential routers allows remote attackers to bypass network protections and expose devices on private networks to the internet. The flaw affects routers deployed by multiple U.S. broadband providers.
Cody Wilson, creator of the first 3D-printed gun, says he's developed software to bypass government-mandated blocks on 3D printers making firearms. The claim marks the start of an escalating regulatory battle over ghost guns.
Hackers are exploiting critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The flaws allow attackers to forge SAML responses and gain administrator access.
Microsoft's Paint and Photos applications automatically embed invisible GUIDs into locally generated images, according to reverse engineering analysis. The watermarks persist even when files are created entirely offline.
Chinese threat actors are integrating DeepSeek and other open-source AI models into cyberattacks, researchers report. The shift demonstrates how readily available AI tools can amplify hacking capabilities against international targets.
Cybersecurity firm ReliaQuest confirmed it repelled a data-theft attack after hackers impersonated a security team member to target an employee. The incident follows the ShinyHunters breach.
A government-backed South Korean startup platform suffered a data breach after developers exposed an encryption key through an API. The incident highlights critical security management lapses in protecting sensitive data.
ToxicPanda Android malware has evolved to target 349 applications and support 167 remote commands. The malware exploits VPN permissions to block Google Play access on infected devices.
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that U.S. government agencies patch an actively exploited vulnerability in Zimbra Collaboration Suite within three days.
The UAE is building a homegrown AI security industry to defend against escalating cyberattacks on its banks, aviation, and energy sectors since tensions with Iran intensified.
Visa is enabling expired payment cards to continue processing contactless transactions through a new feature. The move allows cardholders to keep using their old cards for tap-to-pay purchases even after expiration.
A Texas-based student discovered and reported an unauthorized AI system being used for cyberattacks. The disclosure prompted immediate investigation and security responses from affected organizations.
A supply-chain attack is exploiting legitimate device-update apps to infect Android-based car head units with malware. The compromised devices are being enlisted into proxy botnets or used for ad fraud schemes.
Apollo Global Management disclosed a data breach in July resulting from a social engineering attack that exposed personal information. The incident joins a recent wave of cyberattacks targeting major hedge funds.
Researchers at the UK AI Security Institute have exposed critical weaknesses in how language models are evaluated for safety, showing that current benchmarks don't measure consistent traits and can be artificially inflated.
Felony Bench, a new platform, aggregates criminal case information and court records in a searchable database. The launch has generated significant interest in tech communities discussing digital access to legal proceedings.
The US Department of Energy is examining whether Chinese-made lidar sensors pose a security threat if adopted widely in American vehicles. The investigation addresses concerns about potential vulnerabilities in autonomous vehicle technology.
A US citizen faces felony charges after deleting data from their phone during a border inspection. The case raises questions about digital privacy rights and government authority at ports of entry.
A previously unknown malware family called SynkLoader is being distributed through Microsoft Teams phishing campaigns. The malware steals credentials by displaying a fake lock screen.
A security researcher discovered they had inadvertently captured phone call logs to military installations through a misconfigured system. The incident highlights infrastructure vulnerabilities in telecommunications routing.
Idaho National Laboratory is conducting a security review of Chinese lidar technology, with funding from companies in the electric and autonomous vehicle sectors. The investigation aims to identify potential vulnerabilities in the sensor systems.
Over 9,300 Amazon Web Services access keys have been publicly exposed since August 2022, with the majority still active and granting full account control. Security researchers warn that attackers could exploit these credentials to compromise corporate infrastructure.
Senator Ron Wyden has requested a comprehensive review of how federal agencies deploy hacking tools and spyware against Americans. The inquiry targets the FBI, DEA, ICE's Homeland Security Investigations, and the Secret Service.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies immediately patch two actively exploited vulnerabilities in TrueConf Server, a self-hosted communications platform.
AI-driven phishing attacks are increasingly bypassing traditional email filters with personalized, convincing messages. Managed service providers must monitor identity, email, and endpoint activity to detect threats that slip through inbox defenses.
Comcast introduced Xfinity Shield this week, a platform that allows customers to opt into turning their routers into motion sensors. The announcement sparked immediate privacy concerns among users.
Toronto's Hospital for Sick Children disclosed a cybersecurity incident that compromised personal information belonging to current and former employees and job applicants. The breach stemmed from a vulnerability in third-party software.
A billing bug in Codex on AWS Bedrock is charging users approximately 10 times the expected rate. The issue was reported on GitHub and has generated significant discussion among developers.
A federal judge has overturned part of the conviction of former Google software engineer Linwei Ding, who was earlier found guilty of stealing AI trade secrets for two Chinese companies.
Security researchers demonstrate how seemingly innocent interview questions can be weaponized to extract sensitive system information and compromise infrastructure. The technique exploits social engineering during technical assessments.
A threat actor impersonated a major cryptocurrency news outlet to target cybersecurity professionals. The attackers used Google Docs to distribute malware.
Security researchers warn that Chinese hackers have embedded malicious code in critical civilian infrastructure systems. A recent war game simulation demonstrated vulnerabilities in US defenses against such attacks.
A compromised Rust crate named Arrayref executed malicious code at build time, exploiting the package's procedural macro functionality. The discovery highlights supply chain vulnerabilities in the Rust ecosystem.
Researchers have identified a large-scale campaign targeting Dahua IP cameras, with attackers compromising over 14,500 devices across a 35-day period. The attack, dubbed CameraSwarm, primarily affected devices in Ukraine and Russia.
A critical vulnerability in Elementor Pro allows attackers to upload executable files and execute arbitrary code on WordPress servers. The flaw affects thousands of sites using the popular page builder plugin.
Alation, a major data search and AI platform, disclosed unauthorized access to its systems following a breach discovered Tuesday. The company is actively investigating the incident.
Researchers discovered that xAI's Grok language model can be tricked into exfiltrating user data when malicious instructions are hidden through encryption. The vulnerability, termed Cryptographic Context Injection, represents a new method to bypass the AI system's safety guardrails.
US officials report that hackers are targeting internet-connected Siemens controllers used in water facilities across the country, with AI tools enhancing their attack capabilities.
AliExpress deploys silent WebAudio fingerprinting on its website that interferes with Bluetooth multipoint functionality on user devices. The script runs without explicit user consent.
Citrix has issued an urgent warning for administrators to patch two vulnerabilities affecting NetScaler Gateway and NetScaler ADC appliances. The flaws pose immediate security risks to remote access and networking infrastructure.