29 Apr

GitHub: Zounds, a genuinely helpful AI-assisted bug report that isn’t total slop! Here, Wiz, take this wad of cash

Wiz researchers are set for a tidy payday thanks to their discovery of a high-severity flaw in GitHub’s git infrastructure that handed remote attackers full

Author rabih
29 Apr

Researchers move in the right direction, develop powerful GPS interference alarm

GPS spoofing, which sends fake satellite-like signals, and GPS jamming, which drowns receivers in noise, are increasingly serious problems. Researchers at Oak Ridge National Laboratory

Author rabih
29 Apr

Microsoft’s patch for a 0-day exploited by Russian spies fell short. Another Windows flaw is under attack

Microsoft and the US Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers are exploiting a zero-click Windows flaw that can expose sensitive information on

Author rabih
29 Apr

Legacy TLS tour continues with Exchange Online blocking old versions from July 2026

Microsoft has warned users still clinging to legacy TLS versions that the end is nigh for TLS 1.0 and 1.1 on POP3 and IMAP4 connections

Author rabih
29 Apr

Yet another experiment proves it’s too damn simple to poison large language models

Unlike search engines that let you judge competing sources, search-backed AI chatbots can turn shaky web material into confident answers. Case in point: A security

Author rabih
29 Apr

CISA flags data-theft bug in NSA-built OT networking tool

The Cybersecurity and Infrastructure Security Agency (CISA) is warning anyone who uses GrassMarlin, a tool developed by the National Security Agency (NSA), about a new

Author rabih
29 Apr

GitHub: Woah, a genuinely helpful AI-assisted bug report that isn’t total slop. Here, Wiz, take this wad of cash

Wiz researchers are set for a tidy payday thanks to their discovery of a high-severity flaw in GitHub’s git infrastructure that handed remote attackers full

Author rabih
29 Apr

EU waves through open source age-check tool to keep kids safe online

The European Commission has recommended EU member states adopt an age verification app designed to protect children from harmful online content. In an announcement, the

Author rabih
29 Apr

GoDaddy customer claims registrar transferred 27-year-old domain without any security checks

GoDaddy is currently investigating claims that it handed complete control of a valid 27-year-old domain to another customer, without requiring them to pass any authentication

Author rabih
29 Apr

30 ClawHub skills secretly turn AI agents into a crypto swarm

Thirty ClawHub skills published by a single author are silently co-opting AI agents and creating a mass cryptocurrency mining swarm – without any malware or

Author rabih
28 Apr

Don’t pay Vect a ransom – your data’s likely already wiped out

Organizations hit by the wave of Trivy and LiteLLM supply-chain compromises that paid Vect in hopes of recovering their data likely did not get much

Author rabih
28 Apr

Have I Been Pwned claims Pitney Bowes hit by 8.2M email address leak

Logistics technology company Pitney Bowes, which makes franking machines for US postage, is the latest scalp claimed by ShinyHunters and its ongoing spree of pay-or-leak

Author rabih
28 Apr

From DMV to Wallet: Understanding Verifiable Digital Credential Issuance

In our last post in this series, we compared two credential formats that shape the digital identity ecosystem: ISO/IEC 18013-5 and -7 mobile documents (mdocs)

Author rabih
28 Apr

SUSE’s sovereignty pitch meets an inconvenient $6 billion question

European-based SUSE devoted much of the annual SUSECON event to its sovereignty-focused pitch – even as reports swirl that its majority stakeholder is exploring a

Author rabih
27 Apr

Ongoing supply-chain attack ‘explicitly targeting’ security, dev tools

Software security testing outfit Checkmarx has become the latest organization caught up in an ongoing attack on security-tool providers. The biz said data posted online

Author rabih
27 Apr

Cursor-Opus agent snuffs out startup’s production database

Jer (Jeremy) Crane, the founder of automotive SaaS platform PocketOS, spent the weekend recovering from a data extinction event caused by the company’s AI coding

Author rabih
27 Apr

Medical and utility tech companies admit digital breakins

Digital intruders recently broke into two major tech suppliers – utility-technology firm Itron and medical-device maker Medtronic – according to filings with federal regulators. Itron,

Author rabih
27 Apr

Trump’s Golden Dome gets $3.2B of contractors and an AI sprinkle

The United States Space Force (USSF) has awarded eleven companies contracts to develop space-based interceptors for President Trump’s Golden Dome program, in agreements worth up

Author rabih
Load moreLoadingAll items loaded