BleepingComputer
·
17h ago
Critical SharePoint RCE flaw exploited to steal machine keys Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affecte…
BleepingComputer
·
21h ago
Critical wp2shell WordPress flaws exploited to install webshells Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent websh…
BleepingComputer
·
2h ago
CISA orders urgent action on actively exploited Langflow RCE flaw The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vuln…
BleepingComputer
·
1d ago
Closing the Identity Gaps in Critical Infrastructure Security Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust shoul…
SecurityWeek
·
4h ago
Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI. The post Oracle Patches Over 1,400 Vulne…
BleepingComputer
·
just now
How enterprise GenAI can amplify ransomware risk — and how to contain it Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis exp…
BleepingComputer
·
19h ago
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish allegedl…
EFF
·
3w ago
Primed for Malware: Stop Selling Compromised Android Devices Time and time again, researchers have found numerous compromised Android devices for sale at large online retailers like Amazon. When these devices get indivi…
Wired
·
15h ago
OpenAI Models Escaped Containment and Hacked Hugging Face The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off…
NIST
·
6w ago
NIST Mathematical Proof Supports Transition to a Continuous-Monitor-and-Update Security Model for AI Systems The proof extends to AI the logic used by famed mathematician Kurt Gödel, whose incompleteness theorems have h…
BleepingComputer
·
7h ago
Chick-fil-A discloses data breach after credential stuffing attacks American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential…
Wired
·
4d ago
Your Period Tracker Is (Probably) Spying on You Plus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more.
Dark Reading
·
12d ago
Fresh ATM Crypto Software Bugs: Jackpot or Bust? Organizations, and possibly ATMs, are at risk of compromise, thanks to holes in a Microsoft BitLocker security wrapper.
BleepingComputer
·
just now
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform…
BleepingComputer
·
15h ago
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more t…
Wired
·
21h ago
A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots A new type of malware can worm deep into AI coding systems to steal data and logins—and can flip a “death switch” to destroy files and…
BleepingComputer
·
just now
New InfraTrust report reveals infrastructure flaws admins should patch first Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help orga…
BleepingComputer
·
3h ago
Microsoft to stop Exchange 2016 / 2019 security updates in October Microsoft has reminded customers that it will stop shipping security updates for Exchange 2016 and 2019 through the Extended Security Update (ESU) progr…
arXiv AI
·
10h ago
One Rewrite to Fix Them All? Type-Aware Repair Allocation for Text-to-Image Prompt Optimization arXiv:2607.18724v1 Announce Type: new Abstract: Text-to-image (T2I) generators often fail to follow their prompts faithfull…
Wired
·
1d ago
A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them.
CoinTelegraph
·
just now
SEC’s Peirce says crypto vaults and onchain lending may fall under securities laws The SEC commissioner said crypto vaults, onchain lending products and other asset management tools may trigger US securities laws depend…
NIST
·
17w ago
NIST Submits Annual Report to Congress Summarizing FY 2025 Progress on National Construction Safety Team Investigations The report includes an overview of work completed on the Champlain Towers South investigation.
EFF
·
2w ago
EFF and Allies: X’s FTC Petition to Waive Privacy Violation Order Should be Rejected X Corp. should not be able to escape privacy compliance because it changed its name.
Decrypt
·
just now
Clarity Act Latest Draft Bars Trump From Crypto Ventures—But Only Until 2029 The long-awaited market-structure bill would block officials and their spouses from issuing digital assets and shield non-custodial developers…
GitHub Blog
·
just now
Next chapter: Restructuring GitHub’s bug bounty program GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team. The p…
TechCrunch
·
just now
If you pay a hacker’s ransom, chances are that they’ll come back for more The long-held understanding among security researchers and network defenders is that it's impossible to negotiate in good faith with an extortion…
SecurityWeek
·
just now
Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts. The post Flaw in Ad…
BleepingComputer
·
37m ago
Adobe Chrome extension flaw let sites access private WhatsApp chats The Adobe Acrobat extension for Chrome could be used to access conversations and data rendered in WhatsApp Web without any form of authentication. [...]
BleepingComputer
·
2h ago
Stop renting storage space — this lifetime 2TB plan is yours for $59 Cloud storage costs tend to creep up over time, since most services charge monthly or annually for as long as you use them. FileJump's Lifetime Plan s…
Wired
·
3h ago
States Want ICE Agents to Show Their Faces. The Trump Administration Is Blocking Them Federal lawyers say anti-mask laws would endanger immigration agents, citing an ICE face-recognition art project that doesn’t actuall…
CoinTelegraph
·
4h ago
Galaxy pledges $5M for developers quantum-proofing Bitcoin Galaxy pledged up to $5 million in grants for developers working on Bitcoin’s quantum security and elected a council of quantum-advisory experts to research qua…
BleepingComputer
·
8h ago
OpenAI says its AI models hacked Hugging Face during testing OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested i…
VentureBeat
·
9h ago
OpenAI's models broke containment and cyberattacked Hugging Face — what enterprises need to know Yesterday afternoon, OpenAI and Hugging Face published a joint disclosure outlining a cybersecurity event that redefines t…
arXiv AI
·
10h ago
PhoenixRepair: Rethinking Repair Strategy Exploration in Software Agents arXiv:2607.18859v1 Announce Type: new Abstract: While Large Language Models have greatly advanced automated issue resolution, existing agent-based…
arXiv AI
·
10h ago
Reliability Scales Inversely: Bigger Models Compound Mistakes Faster via a Hidden Auto-Regressive Risk Regime arXiv:2607.18292v1 Announce Type: cross Abstract: As language models scale, answers start truer but degrade f…
arXiv AI
·
10h ago
Quantum Cryptanalysis on IBM Quantum Hardware: Extending Even--Mansour Period Recovery from $N=4$ to $N=10$ arXiv:2607.18340v1 Announce Type: cross Abstract: We report genuine-un-compiled, textbook-faithful-quantum cryp…
arXiv AI
·
10h ago
MambaLSTM: A Spatio-Temporal Framework for Enhanced Traffic Accident Risk Prediction arXiv:2607.18353v1 Announce Type: cross Abstract: In traffic accident risk prediction, most studies overlook the extra noise that coul…
arXiv AI
·
10h ago
OPD-IAD: From Language Judgment to Industrial Anomaly Detection via On-Policy Self-Distillation arXiv:2607.18850v1 Announce Type: cross Abstract: Large vision-language models (LVLMs) have recently shown strong potential…
arXiv AI
·
10h ago
Prompt Design at Scale: How Format, Instruction Count, and Context Length Shape Instruction Adherence and Hallucination in Large Language Models arXiv:2607.19257v1 Announce Type: cross Abstract: Practitioners make three…
arXiv Security
·
10h ago
0-Cyclic Equalizability of Binary Words Characterized by Hamming Weight arXiv:2607.18452v1 Announce Type: new Abstract: The random cut is one of the most fundamental shuffles in card-based cryptography: it rotates a seq…
arXiv Security
·
10h ago
SoK: Adversarial Robustness of the Variational Quantum Eigensolver via Red-Teaming arXiv:2607.19318v1 Announce Type: cross Abstract: The Variational Quantum Eigensolver (VQE) is a leading algorithm for estimating molecu…
arXiv Security
·
10h ago
Architecture-Derived CBOMs for Cryptographic Migration: A Security-Aware Architecture Tradeoff Method arXiv:2603.22442v2 Announce Type: replace Abstract: Cryptographic migration driven by algorithm deprecation, regulato…
arXiv Security
·
10h ago
Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages arXiv:2607.06596v2 Announce Type: replace Abstract: Trusted monitoring is a central defense in AI control: a cheaper trusted model…
BleepingComputer
·
14h ago
Police dismantle Kratos phishing platform, arrest developer Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its develo…
VentureBeat
·
19h ago
Evals are the new PRD, Expedia’s AI chief tells VB Transform 2026 “The new PRD are the evals,” Xavi Amatriain, Expedia Group’s first chief AI and data officer, told the VB Transform 2026 audience last week in Menlo Park…
Decrypt
·
1d ago
Russia's First Comprehensive Crypto Law Is Two Votes Away From Passing The bill licenses exchanges, caps retail investors at about $3,800 a year, and creates a legal pathway for Russian companies to pay foreign partners…
Wired
·
2d ago
The ACLU Is Arming Lawyers to Expose State Surveillance Secrets A new toolkit for attorneys in Massachusetts targets the technologies police use—and conceal—to build criminal cases, from facial recognition to AI-written…
Wired
·
2d ago
Apps Marketed to US Troops Are Shipping Chinese and Russian Code A first-of-its-kind analysis found more than one in eight apps built for US service members carried foreign code—some from firms in nations the Pentagon d…
Cloudflare Blog
·
4d ago
Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities Cloudflare has deployed two WAF rules in response to high-severity vulnerabilities disclosed to us by the WordPress security team. Th…
KrebsOnSecurity
·
7d ago
Microsoft Patches a Record 570 Security Flaws Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerab…
Meta Engineering
·
8d ago
Modernizing the Meta Ads Service With an Open-Source Kernel Scheduler TL; DR At Meta’s scale, a few milliseconds of latency degradation can have a significant negative impact on ads performance. When a Linux kernel upgr…
Dark Reading
·
11d ago
Jen Ellis: Connecting Cyber Community With Political Machinery Security Pro File: On the heels of her recent honors as a Member of the Order of the British Empire (MBE), we take a look back at the events that shaped Jen…
Cloudflare Blog
·
2w ago
Cloudflare proudly joins the UK government's Cyber Resilience Pledge The pledge is a voluntary framework inviting organizations to commit to foundational cyber security governance, board-level accountability, and supply…
Cloudflare Blog
·
3w ago
Your site, your rules: new AI traffic options for all customers For our second Content Independence Day, we’re giving website owners finer options to manage AI traffic. Instead of a one-size-fits-all block, all customer…
SecurityWeek
·
1h ago
Vibe-Coded Apps Riddled With Exploitable Security Flaws Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post…
arXiv AI
·
10h ago
FindStatBench: Evaluating Large Language Models on Combinatorial Code Synthesis arXiv:2607.18260v1 Announce Type: new Abstract: We introduce FindStatBench, an execution benchmark for evaluating large language models on…
arXiv AI
·
10h ago
CoGoal3D: Collaborative 3D Object Detection with 3D-Aware Fusion and Refinement arXiv:2607.19036v1 Announce Type: cross Abstract: V2X collaborative object detection features overcoming the limitations of single-vehicle…
arXiv Security
·
10h ago
The Express Lane to Spam and Centralization: An Empirical Analysis of Arbitrum's Timeboost arXiv:2509.22143v2 Announce Type: replace Abstract: DeFi applications are vulnerable to MEV, where specialized actors profit by…
TheHackerNews
·
2d ago
Mythos Didn't Break Your Security Program. Your Exposure Window Could.
Decrypt
·
1h ago
Justin Sun's HTX 'Rotating' On-Chain Wallets Amid UK Sanctions: TRM Labs TRM Labs says the UK-sanctioned exchange has rotated hot wallets across blockchains, leaving address-list screening struggling to keep pace.