Items tagged with security

Uh-oh, e-commerce giant AliExpress has been caught running hidden, silent audio processes inside visitors' browsers to generate unique device tracking profiles without user consent. This naughty deed was uncovered after software... Read more...
Cybersecurity researchers at Kaspersky have uncovered a malware downloader that targets Android-based automotive head units, marking the first documented case of malicious code explicitly engineered to compromise vehicle infotainment... Read more...
Municipal public comment periods are usually home to standard local grievances, but a recent San Diego City Council meeting received an Imperial visit when Darth Vader stepped up to endorse Flock cameras and automated surveillance... Read more...
Researchers from the University of Massachusetts Amherst have uncovered a critical security flaw in contactless payment processing that allows expired credit cards to be reanimated and used for fraudulent purchases. Presented at the USENIX Security 2026 conference, the UMass researchers... Read more...
Microsoft nemesis Nightmare-Eclipse is at it again, this time with a bypass exploit for his original RoguePlanet Windows Defender privilege escalation exploit. The new exploit, dubbed ShieldBreak, also allows for elevation of privilege... Read more...
The National Cyber Security Centrum (NCSC) of the Netherlands says it has evidence that hackers are actively exploiting a vulnerability in one of macOS’ sharing features, which can provide attackers with complete access over a victim’s... Read more...
Apple has issued high-confidence threat notifications to targeted users across 110 countries, warning that their devices may have been targeted by sophisticated mercenary spyware attacks. The global alert is Cupertino's latest push to... Read more...
ASUS has patched another serious security vulnerability in Armoury Crate and several other hardware-management utilities that could let an unprivileged application gain kernel-level access on Windows systems. The vulnerability, tracked as... Read more...
If your phone has been spared an endless barrage of sketchy pop-ups, phishing scams, and fake security warnings lately, you have Google's multi-layered browser defenses to thank. In a recent security deep dive, Google claims that Chrome’s... Read more...
Microsoft has discovered a Russian malware campaign called CaptiveCrunch, which is designed to compromise users of public Wi-Fi with falsified prompts at the captive sign-in screen. This includes phishing pages that steal logins or even falsified Windows or Android system update/download... Read more...
Cybersecurity researchers at Palo Alto Networks' Unit 42 have uncovered three novel post-compromise attack vectors that allow local malware on Windows PCs to quietly hijack Google-synced passkeys, bypassing biometric checks and PIN... Read more...
Generative AI has drastically lowered the bar for finding software vulnerabilities, but it has simultaneously unleashed a flood of machine-generated noise that is overloading security teams and breaking bug bounty programs.  According... Read more...
Google has begun piloting a twice-weekly update cadence for its massively popular Chrome web browser, a decision it made in the wake of fast-moving, AI-powered attacks. And for major Chrome milestones, the company is aiming to deliver new... Read more...
Securing the tech supply chain has become one of Washington's biggest priorities, and the latest move takes direct aim at the machines meant to power the next industrial era. The Federal Communications Commission has banned the import and... Read more...
Microsoft wants to fight AI-powered cyberattacks with AI defenders of its own. The company has unveiled Project Perception, a new agentic security system designed to hunt down weaknesses, investigate threats, and strengthen defenses at... Read more...
A cyberattack on Georgia-based medical billing provider Medical Computer Business Services (MCBS) has exposed sensitive personal and health records of over 1.2 million individuals. MCBS, an Augusta-headquartered company, which provides... Read more...
A new remote access trojan (RAT) has been discovered by the cybersecurity research team at Cisco Talos, and experts are sounding the alarm since it enables the installation of ransomware on the victim's system. The attack is dubbed msaRAT... Read more...
Another new vulnerability for Microsoft SharePoint, tracked as CVE-2026-50522, is now being actively exploited in the wild, Microsoft warns. Security team watchTowr found evidence of exploits in use, and noted that attacks started the same... Read more...
The CERT Coordination Center warns that Wi-Fi routers built by Tenda may have a hidden, authentication backdoor in firmware. Researchers from CERT, the Computer Emergency Response Team for the Software Engineering Institute at Carnegie... Read more...
Microsoft's drive to improve Windows security with AI-driven vulnerability discovery has led to another record-breaking Patch Tuesday. This time around, there's a whopping 570 security fixes for Windows 11, which is more than double the... Read more...
As it turns out, the batch of expiring Secure Boot certificates isn't the only Secure Boot-related concern that Microsoft and the public need to worry about this year. ESET Researchers have uncovered 11 vulnerable UEFI shim bootloaders... Read more...
Cyber criminals are constantly looking for new ways to compromise systems and devices, and sometimes that means going back to the well with malware that’s been successful in the past. That’s exactly what the researchers at security firm... Read more...
1 2 3 4 5 Next