14 May

Dirty Frag gets a sequel as Fragnesia hands Linux attackers root-level access

Security Fresh kernel flaw comes with public exploit code and continues ugly run of highly reliable privilege escalation bugs tied to memory and page-cache handling

Author rabih
14 May

FrostyNeighbor: Fresh mischief and digital shenanigans

This blogpost covers newly discovered activities attributed to FrostyNeighbor, targeting governmental organizations in Ukraine. FrostyNeighbor has been running continual cyberoperations, changing and updating its toolset

Author rabih
14 May

To gain root access at this company, all an intruder had to do was ask nicely

Security Human IT managers thought they were being nice to the boss, but were assisting a threat actor PWNED Welcome once again to PWNED, the

Author rabih
14 May

AI models are getting better at replacing cybersecurity pros on certain tasks

AI +ML Binary digits arranged into a bug shape on a black background.Elena Abrazhevich / Shutterstock UK researchers find LLMs are learning to finish jobs

Author rabih
14 May

Cisco to fire 4,000 staff and generously give them free training – on Cisco

Networks Reducing memory requirements to control costs in a new wave of kit Cisco will make around five percent of staff redundant and has generously

Author rabih
13 May

Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits

The vulnpocalypse has begun.  Palo Alto Networks usually finds five vulnerabiilties a month, but on Wednesday said it scanned its entire codecase using the latest

Author rabih
13 May

AWS to Quick admins: The access control didn’t work, but you weren’t using it anyway, so what’s the problem?

Most users put up with AWS the way you put up with the DMV. I say this with love, but it’s hard to disagree that

Author rabih
13 May

Bug hunter tracks down three massive MCP flaws and one vendor won’t fix theirs

Security Apache, Alibaba databases vulnerable and only one has a patch  Security vulnerabilities in MCP servers for three popular database projects could let attackers execute

Author rabih
13 May

Mystery Microsoft bug leaker keeps the zero-days coming

Security Security pros warn YellowKey claim could make stolen laptops a much bigger problem The anonymous security researcher who has already maliciously exposed three Windows

Author rabih
13 May

Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub

Security Where it’s been well and truly forked, seemingly without Microsoft’s code locker noticing Notorious malware crew TeamPCP appears to have open-sourced its Shai-Hulud worm.

Author rabih
13 May

Vietnam to develop domestic cloud so it can ditch risky overseas operators for government workloads

Public Sector Communist government plans personalized ‘data-driven decision-making based on real-time information’ by 2035 Vietnam has decided to develop its own cloud platform, so its

Author rabih
12 May

Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs

Security The good news: no 0-days. The bad news: busy week ahead for Microsoft admins Microsoft released fixes for 137 CVEs on Tuesday, none of

Author rabih
12 May

Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files

cyber-crime Affected factories back up and running, we’re told Foxconn, a critical supplier for major hardware companies like Apple and Nvidia, on Tuesday confirmed a

Author rabih
12 May

US bank reports itself after slinging customer data at ‘unauthorized AI app’

Security Volume and sensitivity of the data cited as chief concerns A US commercial bank just tattled on itself to the Securities and Exchange Commission

Author rabih
12 May

Cache-poisoning caper turns TanStack npm packages toxic

Cyber-Crime Six-minute supply chain blitz pushed 84 malicious versions with credential theft and disk-wiping code An attacker has published 84 malicious versions of official TanStack

Author rabih
12 May

Apple, Google drag cross-platform texting into the encrypted age

Security After years of stopping dead at the green bubble border, iPhone and Android users can finally send E2EE messages without relying on third-party apps

Author rabih
12 May

Japan’s PM orders cybersecurity review to stop Mythos going full CyberZilla

Security Fears exponential increase in attack scale and speed Japan’s prime minister Sanae Takaichi has ordered a review of government cybersecurity strategy, citing the arrival

Author rabih
11 May

Double Canvas breach acknowledged as ShinyHunters sets new pay-or-leak deadline

Security May 12 … time is ticking for nearly 9,000 schools Ed-tech giant Instructure confirmed two rounds of unauthorized activity affecting its online learning platform

Author rabih
Load moreLoadingAll items loaded