Items tagged with security
by
Chris Harper - Wed, Aug 05, 2026
Microsoft has discovered a Russian malware campaign called CaptiveCrunch, which is designed to compromise users of public Wi-Fi with falsified prompts at the captive sign-in screen. This includes phishing pages that steal logins or even falsified Windows or Android system update/download...
Read more...
by
Aaron Leong - Tue, Aug 04, 2026
Cybersecurity researchers at Palo Alto Networks' Unit 42 have uncovered three novel post-compromise attack vectors that allow local malware on Windows PCs to quietly hijack Google-synced passkeys, bypassing biometric checks and PIN...
Read more...
by
Aaron Leong - Mon, Aug 03, 2026
Generative AI has drastically lowered the bar for finding software vulnerabilities, but it has simultaneously unleashed a flood of machine-generated noise that is overloading security teams and breaking bug bounty programs.
According...
Read more...
by
Paul Lilly - Fri, Jul 31, 2026
Google has begun piloting a twice-weekly update cadence for its massively popular Chrome web browser, a decision it made in the wake of fast-moving, AI-powered attacks. And for major Chrome milestones, the company is aiming to deliver new...
Read more...
by
Tim Sweezy - Wed, Jul 29, 2026
Securing the tech supply chain has become one of Washington's biggest priorities, and the latest move takes direct aim at the machines meant to power the next industrial era. The Federal Communications Commission has banned the import and...
Read more...
by
Tim Sweezy - Tue, Jul 28, 2026
Microsoft wants to fight AI-powered cyberattacks with AI defenders of its own. The company has unveiled Project Perception, a new agentic security system designed to hunt down weaknesses, investigate threats, and strengthen defenses at...
Read more...
by
Aaron Leong - Tue, Jul 28, 2026
A cyberattack on Georgia-based medical billing provider Medical Computer Business Services (MCBS) has exposed sensitive personal and health records of over 1.2 million individuals.
MCBS, an Augusta-headquartered company, which provides...
Read more...
by
Chris Harper - Sat, Jul 25, 2026
A new remote access trojan (RAT) has been discovered by the cybersecurity research team at Cisco Talos, and experts are sounding the alarm since it enables the installation of ransomware on the victim's system. The attack is dubbed msaRAT...
Read more...
by
Chris Harper - Thu, Jul 23, 2026
Another new vulnerability for Microsoft SharePoint, tracked as CVE-2026-50522, is now being actively exploited in the wild, Microsoft warns. Security team watchTowr found evidence of exploits in use, and noted that attacks started the same...
Read more...
by
Chris Harper - Sun, Jul 19, 2026
The CERT Coordination Center warns that Wi-Fi routers built by Tenda may have a hidden, authentication backdoor in firmware. Researchers from CERT, the Computer Emergency Response Team for the Software Engineering Institute at Carnegie...
Read more...
by
Chris Harper - Thu, Jul 16, 2026
Microsoft's drive to improve Windows security with AI-driven vulnerability discovery has led to another record-breaking Patch Tuesday. This time around, there's a whopping 570 security fixes for Windows 11, which is more than double the...
Read more...
by
Chris Harper - Wed, Jul 15, 2026
As it turns out, the batch of expiring Secure Boot certificates isn't the only Secure Boot-related concern that Microsoft and the public need to worry about this year. ESET Researchers have uncovered 11 vulnerable UEFI shim bootloaders...
Read more...
by
Alan Velasco - Mon, Jul 13, 2026
Cyber criminals are constantly looking for new ways to compromise systems and devices, and sometimes that means going back to the well with malware that’s been successful in the past. That’s exactly what the researchers at security firm...
Read more...
by
Chris Harper - Sat, Jul 11, 2026
The open source, enterprise email software Zimbra was recently updated to version 10.1.19, and parent company Synacor urged users to update as soon as possible. Specifically, the update addresses a vulnerability in the Classic Web Client...
Read more...
by
Tim Sweezy - Fri, Jul 10, 2026
There has never been a better time to be a bug hunter, whether the goal is patching Windows or breaking into it. With AI now capable of digging up software flaws faster than any human team could manage, Microsoft has announced a sweeping...
Read more...
by
Tim Sweezy - Wed, Jul 08, 2026
Removing the privacy light from Meta's AI glasses turned into a small business, with modders openly advertising the work on Meta's own marketplace. Meta is now slamming that door shut with a software update that kills the camera entirely...
Read more...
by
Alan Velasco - Mon, Jul 06, 2026
Nefarious actors are becoming adept at deploying Large Language Models (LLMs) in their malware campaigns. Case in point, the threat research team at security firm Sysdig has discovered what looks to be the first instance of an attack using...
Read more...
by
Tim Sweezy - Mon, Jul 06, 2026
Fans of the Flipper Zero have spent the past few weeks wondering whether the beloved pocket multi-tool was quietly being put out to pasture. A stretch of perceived silence from Flipper Devices, which recently announced its Busy Bar smart...
Read more...
by
Chris Harper - Thu, Jul 02, 2026
Since the introduction of premium iCloud+ in 2021, Apple has offered a privacy-centric feature for its users dubbed Hide My Email. Conceptually, Hide My Email allows iCloud+ users to create anonymous burner email accounts that can't be...
Read more...
by
Chris Harper - Wed, Jul 01, 2026
A new form of AI prompt injection malware has been discovered, dubbed BioShocking by the LayerX security team. And that name is no coincidence: it's a direct reference to the 2007 survival horror FPS BioShock and its iconic hypnotic phrase...
Read more...
by
Tim Sweezy - Tue, Jun 30, 2026
Anyone who's rooted their Android phone or jailbroken their iPhone to squeeze out a little extra control over the device is about to hit a wall, at least when it comes to using it for work or school. Microsoft has quietly armed...
Read more...
by
Chris Harper - Mon, Jun 29, 2026
Mozilla's 0din security team has discovered widespread prompt injection AI malware plaguing the GitHub ecosystem. This exploit, dubbed "indirect prompt injection," isn't the first of its kind. Previously, we've seen prompt injection...
Read more...