Security
From “death by a thousand AI slops” to fixing 50 bugs in just three months
Nearly three months ago, Daniel Stenberg, creator of the widely used curl utility, complained about the overwhelming flood of low-quality AI-generated vulnerability reports, calling them “AI slop.” However, the lead maintainer now says that AI-generated reports led to 50 bug fixes.
Read more about From “death by a thousand AI slops” to fixing 50 bugs in just three months
You’re owning less: protect yourself from vague digital ownership terms
Imagine finding an old game you bought years ago to relive memories or show a kid, only to discover it...
Read more about You’re owning less: protect yourself from vague digital ownership terms
Steam, Riot Games hit by disruptions: massive DDoS attack suspected
Multiplayer gamers on different platforms have experienced service outages and disruptions simultaneously. The cybersecurity community suspects a major distributed denial of service attack (DDoS) from Aisuru, a massive botnet pushing out record-breaking traffic.
Read more about Steam, Riot Games hit by disruptions: massive DDoS attack suspected
Cyber authorities ring alarm bell over actively exploited Oracle E-Business Suite bug
Cybersecurity authorities are urging organizations to patch a critical zero-day bug in Oracle’s E-Business Suite (EBS) that’s already being actively exploited. The flaw enables unauthenticated attackers to run code remotely.
Read more about Cyber authorities ring alarm bell over actively exploited Oracle E-Business Suite bug
Your gaming mouse can easily eavesdrop: here's how
Researchers at the University of California, Irvine, have turned a humble computer mouse into an unlikely spy.
Read more about Your gaming mouse can easily eavesdrop: here's how
Signal is asking Germany not to “capitulate” for client-side scanning
Meredith Whittaker, CEO of the chat app Signal, has called on Germany to vote against the introduction of chat control.
Read more about Signal is asking Germany not to “capitulate” for client-side scanning
DeepSeek popularity raises concerns: NIST warns of flawed security, CCP narratives, and hidden costs
Rapid adoption of DeepSeek models from China is unnerving to US policymakers. A new study from NIST highlights significant security vulnerabilities, alignment with the Chinese Communist Party (CCP), and a notable performance gap compared to superior US models, while also being more expensive to use.
Read more about DeepSeek popularity raises concerns: NIST warns of flawed security, CCP narratives, and hidden costs
Hackers threaten Salesforce: pay up or over 700 companies’ data will be exposed
The hacking conglomerate, which is believed to be responsible for attacks against Salesforce instances via Salesloft integrations, has posted ransom demands. It’s threatening to release data from over 700 major companies, including Google, FedEx, UPS, Toyota, Stellantis, Adidas, Disney, Home Depot, and many others, unless it gets paid. Salesforce is aware of the extortion attempts and says they relate to past or unsubstantiated incidents.
Read more about Hackers threaten Salesforce: pay up or over 700 companies’ data will be exposed
Henry Schein subsidiary confirms ransomware attack
A Russia-linked cyber gang has claimed that it has cracked open the systems of healthcare giant Henry Schein’s TriMed, leaking sensitive data onto the dark web. The company confirms a cybersecurity incident.
Read more about Henry Schein subsidiary confirms ransomware attack
Japan may run out of its favorite Asahi beer after cyberattack
Japanese retailers are warning customers that they’re running out of Asahi Super Dry, the country’s most popular beer, following a major cyberattack on the producer.
Read more about Japan may run out of its favorite Asahi beer after cyberattack
Boeing supplier data leaked online after alleged hack
A ransomware gang has claimed that it stole internal security documents from a software supplier powering global giants like Boeing, Volkswagen, Siemens, and Samsung.
Read more about Boeing supplier data leaked online after alleged hack
Red Hat confirms breach: one GitLab environment might expose major organizations, including the NSA
Red Hat, a leading software company behind the enterprise Linux distribution, confirms its GitLab instance, containing consulting engagement data, has been compromised. Cybercriminals on Telegram claim they’ve snatched private repositories, which include sensitive data about approximately 800 customers' networks.
Read more about Red Hat confirms breach: one GitLab environment might expose major organizations, including the NSA
New Android banking trojan hijacks thousands of phones
A previously unknown Android malware strain is targeting thousands of banking customers across southern Europe, potentially stealing their hard-earned cash.
Read more about New Android banking trojan hijacks thousands of phones
Russian hackers claim attack on NHS contractor
A notorious ransomware gang claims that it has raided the UK’s hospital builder. Attackers linked to Russia claim to have stolen 4TB of secret data.
Read more about Russian hackers claim attack on NHS contractor
Lifeprinter app on iOS and Android spilled 2 million private photos
A portable photo printer, Lifeprint, meant to share memories just spilled millions of private photos onto the open internet. The company has not addressed the issue.
Read more about Lifeprinter app on iOS and Android spilled 2 million private photos
Massive network of 30,000 websites filters victims before delivering scams or malware
A sprawling, malicious network has turned 30,000 websites into a sinister slot machine for millions of visitors. Most see harmless content, but some will get funneled into scams, and an unlucky 1% will receive malware. Security researchers unveil the overwhelming complexity behind the scenes.
Read more about Massive network of 30,000 websites filters victims before delivering scams or malware
China to hacking victims: you’ve got one hour to spill beans
Major critical infrastructure providers in China will now have a mere hour to report serious cyber incidents like breaches or leaks. The requirement is much stricter than in the United States and the European Union – regions that are regularly attacked by Chinese state-sponsored hackers.
Read more about China to hacking victims: you’ve got one hour to spill beans
German government wants to replace passwords with passkeys
The German government wants to replace passwords as an authentication mechanism with passkeys, as they are considered much safer.
Read more about German government wants to replace passwords with passkeys
Meet Phantom Taurus, the stealth Chinese espionage group you’ve never heard of
Phantum Taurus, a “highly covert” nation-state threat actor linked to China, has been observed stepping up its espionage attacks on foreign governments, militaries, and associated entities, Palo Alto reveals on Tuesday.
Read more about Meet Phantom Taurus, the stealth Chinese espionage group you’ve never heard of
VMware virtual machines under attack: hackers may have exploited zero-day for months
Broadcom has warned about severe zero-day vulnerabilities affecting VMware software, which is widely used to power virtual machines. China-linked hackers may have been exploiting the flaws for months or even years to silently elevate privileges to administrator-level.
Read more about VMware virtual machines under attack: hackers may have exploited zero-day for months