12 May

Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs

Security The good news: no 0-days. The bad news: busy week ahead for Microsoft admins Microsoft released fixes for 137 CVEs on Tuesday, none of

Author rabih
12 May

Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files

cyber-crime Affected factories back up and running, we’re told Foxconn, a critical supplier for major hardware companies like Apple and Nvidia, on Tuesday confirmed a

Author rabih
12 May

US bank reports itself after slinging customer data at ‘unauthorized AI app’

Security Volume and sensitivity of the data cited as chief concerns A US commercial bank just tattled on itself to the Securities and Exchange Commission

Author rabih
12 May

Cache-poisoning caper turns TanStack npm packages toxic

Cyber-Crime Six-minute supply chain blitz pushed 84 malicious versions with credential theft and disk-wiping code An attacker has published 84 malicious versions of official TanStack

Author rabih
12 May

Apple, Google drag cross-platform texting into the encrypted age

Security After years of stopping dead at the green bubble border, iPhone and Android users can finally send E2EE messages without relying on third-party apps

Author rabih
12 May

Japan’s PM orders cybersecurity review to stop Mythos going full CyberZilla

Security Fears exponential increase in attack scale and speed Japan’s prime minister Sanae Takaichi has ordered a review of government cybersecurity strategy, citing the arrival

Author rabih
11 May

Double Canvas breach acknowledged as ShinyHunters sets new pay-or-leak deadline

Security May 12 … time is ticking for nearly 9,000 schools Ed-tech giant Instructure confirmed two rounds of unauthorized activity affecting its online learning platform

Author rabih
11 May

Cookie thieves caught stealing dev secrets via fake Claude Code installers

Security New IElevator2 COM interface? No problem An ongoing campaign steals developers’ secrets via fake Claude Code installers and other popular coding tools, according to Ontinue’s

Author rabih
11 May

Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator

cURL developer Daniel Stenberg has seen Anthropic’s Mythos, a model the AI biz has suggested is too capable at finding security holes to release publicly,

Author rabih
11 May

BWH Hotels guests warned after reservation data checks out with cybercrooks

Cyber-Crime Customers urged to keep an eye out for phisherfolk BWH Hotels is informing customers about a third-party data breach that gave cybercriminals access to

Author rabih
11 May

Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged

DevOps Cybercrooks ruin engineers’ weekends with Saturday attack Checkmarx’s software engineers are still working to remove a malicious version of the code security outfit’s Jenkins

Author rabih
11 May

Eyes wide open: How to mitigate the security and privacy risks of smart glasses

Smart glasses allow anyone to track and record the world around them. That could put your data and the privacy of those nearby at risk.

Author rabih
11 May

Taiwan’s train cyber-trauma reveals a global system that’s coming off the tracks

OPINION There are three little words to make the heart beat faster in anyone who knows what they mean: critical infrastructure resilience. If you run

Author rabih
08 May

Worm rubs out competitor’s malware, then takes control

Security Copyright (c) 2024 kungfu01/Shutterstock. No use without permission. All your compromised credentials are belong to us now instead of the other gang There’s a

Author rabih
08 May

‘Dirty Frag’ Linux flaw one-ups CopyFail with no patches and public root exploit

Security Broken disclosure embargo left admins facing a fresh root-level flaw with no CVE A fresh Linux privilege escalation bug dubbed “Dirty Frag” has dropped

Author rabih
08 May

Meta U-turns on encryption push for Instagram as DMs go plaintext

Security After years of insisting end-to-end encryption was the future of online comms, Zuckcorp has handed itself full visibility into user chats once again Meta

Author rabih
08 May

Hackers ate my homework: Educational SaaS Canvas down after cyberattack

Security ShinyHunters takes the credit and gives developer an F for security Students around the world have an excuse to bunk off after hacking crew

Author rabih
08 May

Meta fights Ofcom over how many billions count as billions

security Social media biz says watchdog’s fine formula is ‘disproportionate’ and should stop counting global revenue Meta appears to have decided Britain’s Online Safety Act

Author rabih
Load moreLoadingAll items loaded