19 Mar

Attackers swipe data of 500k+ people from Pennsylvania teachers union

The Pennsylvania State Education Association (PSEA) says a July 2024 “security incident” exposed sensitive personal data on more than half a million individuals, including financial

Author rabih
19 Mar

Names, bank info, and more spills from top sperm bank

One of the world’s largest sperm banks, California Cryobank, is in a sticky situation. It’s had to tell folks their sensitive information, including names and

Author rabih
19 Mar

Show top LLMs some code and they’ll merrily add in the bugs they saw in training

Researchers have found that large language models (LLMs) tend to parrot buggy code when tasked with completing flawed snippets. That is to say, when shown

Author rabih
19 Mar

IBM scores perfect 10 … vulnerability in mission-critical OS AIX

IBM “strongly recommends” customers running its Advanced Interactive eXecutive (AIX) operating system apply patches after disclosing two critical vulnerabilities, one of which has a perfect

Author rabih
19 Mar

Ex-US Cyber Command chief: Europe and 5 Eyes can’t fully replicate US intel

If the United States stopped sharing cyber-threat intel with Ukraine, its European allies and the rest of the Five Eyes nations wouldn’t be able to

Author rabih
19 Mar

Show top LLMs buggy code and they’ll finish off the mistakes rather than fix them

Researchers have found that large language models (LLMs) tend to parrot buggy code when tasked with completing flawed snippets. That is to say, when shown

Author rabih
18 Mar

CISA fires, now rehires and immediately benches security crew on full pay

The upheaval at the US government’s Cybersecurity and Infrastructure Security Agency, aka CISA, took another twist on Tuesday, as it moved to reinstate staffers it

Author rabih
18 Mar

US tech jobs outlook clouded by DOGE cuts, Trump tariffs

A pair of reports on tech sector employment trends in the United States suggest out-of-work techies right now have relatively decent prospects, but economic uncertainty

Author rabih
18 Mar

MirrorFace updates toolset, expands targeting to Europe

The group’s Operation AkaiRyĆ« begins with targeted spearphishing emails that use the upcoming World Expo 2025 in Osaka, Japan, as a lure 18 Mar 2025

Author rabih
18 Mar

Microsoft isn’t fixing 8-year-old shortcut exploit abused for spying

An exploitation avenue found by Trend Micro has been used in an eight-year-long spying campaign, but there’s no sign of a fix from Microsoft, which

Author rabih
18 Mar

Google acquisition target Wiz links fresh supply chain attack to 23K pwned GitHub repos

Wiz security researchers think they’ve found the root cause of the GitHub supply chain attack that unfolded over the weekend, and they say that a

Author rabih
18 Mar

UK wants dirt on data brokers before criminals get there first

The UK government is inviting experts to provide insights about the data brokerage industry and the potential risks it poses to national security as it

Author rabih
18 Mar

Operation AkaiRyƫ: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor

In August 2024, ESET researchers detected cyberespionage activity carried out by the China-aligned MirrorFace advanced persistent threat (APT) group against a Central European diplomatic institute

Author rabih
18 Mar

Extortion crew threatened to inform Edward Snowden (?!) if victim didn’t pay up

Dark web analysts at infosec software vendor Fortra have discovered an extortion crew named Ox Thief that threatened to contact Edward Snowden if a victim

Author rabih
18 Mar

‘Dead simple’ hijacking hole in Apache Tomcat ‘now actively exploited in the wild’

A trivial flaw in Apache Tomcat that allows remote code execution and access to sensitive files is said to be under attack in the wild

Author rabih
17 Mar

Court filing: DOGE aide broke Treasury policy by emailing unencrypted database

A now-former DOGE aide violated US Treasury policy by emailing an unencrypted database containing people’s private information to two Trump administration officials, according to a

Author rabih
17 Mar

Amazon to kill off local Alexa processing, all voice requests shipped to the cloud

Come March 28, those who opted to have their voice commands for Amazon’s AI assistant Alexa processed locally on their Echo devices will lose that

Author rabih
17 Mar

Amazon boots local Alexa processing: All your voice requests shipped to the cloud

Come March 28, those who opted to have their voice commands for Amazon’s AI assistant Alexa processed locally on their Echo devices will lose that

Author rabih
Load moreLoadingAll items loaded