17 Apr

Locked-out iPhone user tells The Reg that Apple is scrambling to fix character flaw passcode bug

Apple is finally working on a fix for a bug that has locked some users out of their iPhones for months, The Register understands. Cupertino’s

Author rabih
17 Apr

That data breach alert might be a trap

Ignoring a real breach notification invites risk, but falling for a bogus one could be even worse. Stop reacting on autopilot. Phil Muncaster 17 Apr

Author rabih
17 Apr

Claude Opus wrote a Chrome exploit for $2,283

Anthropic withheld its Mythos bug-finding model from public release due to concerns that it would enable attackers to find and exploit vulnerabilities before anyone could

Author rabih
17 Apr

Anthropic won’t own MCP ‘design flaw’ putting 200K servers at risk, researchers say

A design flaw – or expected behavior based on a bad design choice, depending on who is telling the story – baked into Anthropic’s official

Author rabih
16 Apr

Anthropic won’t own MCP ‘design flaw’ putting 200K servers at risk, researcher says

A design flaw – or expected behavior based on a bad design choice, depending on who is telling the story – baked into Anthropic’s official

Author rabih
16 Apr

North Korea targets macOS users in latest heist

North Korean criminals set on stealing Apple users’ credentials and cryptocurrency are using a combination of social engineering and a fake Zoom software update to

Author rabih
16 Apr

Nobody knows how many CVEs Anthropic’s Project Glasswing has actually found

Last week, Anthropic surprised the world by declaring that its latest model, Mythos, is so good at finding vulns that it would create chaos if

Author rabih
16 Apr

Americans who masterminded Nork IT worker fraud sentenced to 200 months behind bars

Two Americans have been jailed for a combined 200 months for helping North Korea generate $5 million through fraudulent IT worker schemes. Kejia “Tony” Wang,

Author rabih
16 Apr

Git identity spoof fools Claude into giving bad code the nod

Security boffins say Anthropic’s Claude can be tricked into approving malicious code with just two Git commands by spoofing a trusted developer’s identity. In a

Author rabih
16 Apr

Supply chain dependencies: Have you checked your blind spot?

Some cyber business risks only show up when you take a closer look. Supply chain blind spots are a perfect example. Behind these essential third-party

Author rabih
16 Apr

Textbook titan McGraw Hill on ransomware crew’s reading list after 13.5M records exposed

Textbook giant McGraw Hill has landed on a ransomware crew’s leak site after an alleged Salesforce-linked misconfiguration spilled 13.5 million records into the wild. Have

Author rabih
16 Apr

Microsoft announces product it doesn’t want you to buy: Extended security updates for old Exchange, and Skype for Biz

Microsoft will keep delivering security updates for old versions of Exchange Server and Skype for Business Server, after admitting that some customers aren’t ready to

Author rabih
16 Apr

Server-room lock was nothing but a crock

PWNED Welcome back to Pwned, the column where we immortalize the worst vulns that organizations opened up for themselves. If you’re the kind of person

Author rabih
16 Apr

Google Chrome lacks protection against one of the most basic and common ways to track users online

Google markets its Chrome browser by citing its superior safety features, but according to privacy consultant Alexander Hanff, Chrome does not protect against browser fingerprinting

Author rabih
15 Apr

Anthropic’s Project Glasswing CVE tally is still anyone’s guess

Last week, Anthropic surprised the world by declaring that its latest model, Mythos, is so good at finding vulns that it would create chaos if

Author rabih
15 Apr

Patch these critical Fortinet sandbox bugs that let attackers bypass login, run commands over HTTP

Watch out for more Fortinet vulns! Two critical bugs in Fortinet’s sandbox could allow unauthenticated attackers to bypass authentication or execute unauthorized code on vulnerable

Author rabih
15 Apr

Automotive data biz Autovista blames ransomware for service disruption

Autovista confirms that it called in outside support to help clean up a ransomware infection currently affecting systems in Europe and Australia. The automotive data

Author rabih
15 Apr

French cops free mother and son after 20-hour crypto kidnap ordeal

A mother and her ten-year-old son are now free after being kidnapped for around 20 hours while the father was being extorted for hundreds of

Author rabih
Load moreLoadingAll items loaded