National Cyber Warfare Foundation (NCWF)

Own a Samsung smartwatch? This 30-second fix will keep it running like new


0 user ratings
2025-09-19 09:09:11
milo
Privacy , Developers , Crypto Currency

 - archive -- 
Clear the cache on your Galaxy Watch to fix battery drain, software glitches, and general sluggishness. Here's how.



Source: ADnet
Source Link: https://www.zdnet.com/article/own-a-samsung-smartwatch-this-30-second-fix-will-keep-it-running-like-new/


Comments
new comment
Nobody has commented yet. Will you be the first?
CVE mentions by industry news 
Anthropic Cybersecurity Skills for giving AI agents structured analyst workflows 
shannon for autonomous AI-driven pentesting of web apps and APIs 
web-check for all-in-one website OSINT reconnaissance 
ENISA: Frontier AI Is Changing the Speed of Cyberattacks. Europe Needs to Catch Up 
How a 'swarm' of AI agents hacked another company, in the AI's own words - abc.net.au 
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials 
Interstellar comet 3I ATLAS likely formed where its star's light couldn't touch it 
Fake CAPTCHAs are tricking people into hacking their own computers, and it's working - TechSpot 
China Calls Amodei s AI Proposal a New Cold War Playbook 
Nvidia and Booz Allen Hamilton restrict their use of Fable due to a lack of ZDR assurances; source: Palantir hasn't made Fable available via its  
Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits 
What is Proactive Threat Intelligence? Recorded Future 
Rapid7 Named Among Notable Vendors in Forrester MDR Landscape: Why the Future is Exposure-informed, Preemptive MDR 
No cities on the moon there isn't enough water, scientists say (op-ed) 
Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk 
Anthropic CEO Calls for an AI Slowdown. Is It Possible? 
radare2 for command-line binary analysis and reverse engineering 
strix for autonomous AI-driven penetration testing of your own applications 
dotenv as a Node.js Environment Loading Control Point 
x64dbg for user-mode reverse engineering of Windows binaries 
x64dbg for user-mode reverse engineering of Windows binaries 
strix for autonomous AI-driven penetration testing of your own applications 
Command-and-control channel design: conceptual tradeoffs between beaconing models 
On this day in space! Sept. 12, 1992: NASA astronaut Mae Jemison makes history as the 1st Black woman in space 
OPSEC principles for red team operators: threat-modeling your own footprint 
NASA astronaut Jessica Meir shares zero-G curly hair tips from the ISS (video) 
Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence 
Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks 
Anthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and Weapons 
On this day in space! NASA astronaut Mae Jemison makes history as the 1st Black woman in space 
This Week In Space podcast: Episode 227 Trekmania 
The best 'Star Trek' spaceships: 14 classic vessels from the Federation and beyond 
I've chased the 'false dawn' for years this is the week to find and photograph it 
'The Last Starship' is 2026's most slept-on space game you need to check out this 'FTL'-like shipbuilding strategy gem 
International Space Station astronaut gives out of this world tribute to honor Star Trek s 60th anniversary 
GitLab’s critical flaw is already drawing internet-wide probes 
The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet 
A jailbroken AI agent hacking gadgets broke into a writer s own PC - cryptonews.net 
60 years of Star Trek uniforms: Looking back at the everchanging wardrobe of Starfleet 
The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment 
2 private spacecraft zoom within 650 feet of each other to showcase 'advanced capabilities' in orbit (photos) 
How a 'swarm' of AI agents hacked another company, in the AI's own words - ABC News & Headlines Australian Broadcasting Corporation 
25 years ago, a NASA astronaut witnessed the tragic 9 11 attacks from space. Here's what he saw. 
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware 
Scientists discover mysterious new X-ray objects 'unlike any they have seen before' 
How a swarm of AI agents hacked another company, in the AI s own words - abc.net.au 
UK Council Attack Linked to Mass Exploitation of SonicWall Flaw 
We've got one word for it, and it's usually the wrong one 
Amazon partners with OpenAI to let advertisers buy ChatGPT ads via Amazon DSP as a managed service in a US-only pilot; OpenAI will control ad delivery 
AI lets small actors run state-level hacking campaigns, Anthropic report finds 
Amazon partners with OpenAI to let Amazon DSP users run ads in ChatGPT in a pilot program limited to the US (Peter Adams Marketing Dive) 
How a swarm of AI agents hacked another company, in the AI s own words - ABC News & Headlines Australian Broadcasting Corporation 
Lawmakers call on Commerce to sanction hackers-for-hire 
Scientists study 3,000 supernovas and discover that dark energy may be evolving 
The Intelligible World of Agents 
Amazon partners with OpenAI to let Amazon DSP users run ads in ChatGPT in a pilot program limited to the US; in August, OpenAI said ChatGPT Ads hit $1 
Amazon partners with OpenAI to let users of Amazon's DSP run ads in ChatGPT in a pilot program limited to the US; ChatGPT Ads hit $1B in ARR last 
What comes after the moon? Artemis II commander and pilot shift to 'emeritus' status at NASA 
A New Claude ‘s Sandbox Failure Shows How AI Can Rationalize Real-World Harm 
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key 
The 12 Best Mobile Threat Defense (MTD) Solutions, Compared and Priced 
The 12 Best Unified Endpoint Management (UEM) Solutions, Compared and Priced 
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days 
Massachusetts Gov. Maura Healey signs an EO requiring data centers above 25MW of peak demand to bring their own power and meet 100% of demand with cle 
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities 
International Space Station astronaut gives out of this world tribute to honor Star Trek s 60th anniversary 
Lawmakers call on Treasury to sanction hackers-for-hire 
NASA's newly launched Roman Space Telescope will 'directly' image exoplanets. But what does that mean? 
'Star Trek' imagined strange new worlds 60 years ago, but real exoplanets are even stranger 
OpenAI says it is working with Samsung on its next-gen chips, and Samsung is one of the "largest-scale deployments of ChatGPT globally" (Hee 
Now 40% off, it's your last chance to grab this retired Lego Marvel Baby Rocket Raccoon's Ship, including the most adorable Lego figure ever 
Legal AI startup Harvey raised $550M co-led by Lightspeed and Diffusion at a $15.6B valuation, up from an $11B valuation when it raised $200M in March 
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets 
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval 
Robotics roadmaps from around the world spotlight of the month: United States of America 
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans 
PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory 
The 12 Best Extended Detection & Response (XDR) Platforms, Compared and Priced 
Microsoft s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs 
Hackers Drain $320 Million From Liquid Network, Then Return Most of It 
Did Venus eat its own moon? 
Feds accuse China of systematic distillation of U.S. AI models 
OpenAI's S bastien Bubeck says he reached out to Levent Alp ge to coordinate their releases and denies asking to remove Alp ge from authorship 
'Star Trek' imagined strange new worlds 60 years ago, but are real exoplanets even stranger? 
OpenAI's S bastien Bubeck says he never asked for removal of Levent Alp ge from authorship of the work Alp ge and Tristan Buckmaster did on Na 
As 'Star Trek' turns 60, we take the iconic sci-fi franchise to sickbay for a full health report 
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials 
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager 
Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data 
The Best DNS Security Solutions, Compared and Priced (2026) 
The 12 Best Antivirus (Endpoint Protection) Software for Business, Compared and Priced 
North Korea-linked Hackers Hide a Backdoor Inside HAProxy 
In most cities, nobody owns the whole network 
'The Last Starship' is 2026's most slept-on space game you need to check out this 'FTL'-like shipbuilding strategy gem 
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution 
AI agents can act on their own and sometimes break out - WJCL 
Galaxies tangled in science and spirit Space photo of the day for Sept. 7, 2026 
The 12 Best Wireless Wi-Fi Security Solutions, Compared and Priced 
The 12 Best Secure Web Gateway (SWG) Solutions, Compared and Priced 
The 12 Best Network Sandboxing Solutions, Compared and Priced 
JSCeal Hides Crypto Malware in V8 Bytecode 
Cheaper than Prime Day, this super-portable, beginner-friendly telescope is my number one choice for skywatching 
BYOTC Attack Abuses Trusted Windows Clients to Access Privileged Kernel Driver Operations 
Why AI Agent Sandboxes Are Failing Security Tests 
Feel the Force with these 10 out-of-this-world Lego Star Wars starships 
AI Agents Hijacked German Wiki to Cheat, OpenAI Delayed Disclosure 
NASA expands Deep Space Network with giant new dish in California desert 
OpenAI Announced $1B in Defensive Tools for Water Utilities 
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials 
Venus is disappearing from the evening sky here's how to see it while you can 
This Lego Star Wars UCS AT-ST set is cheaper than ever I'll always love this chicken walker 
This Week In Space podcast: Episode 226 Who Owns The Moon? 
California AG Rob Bonta is investigating OpenAI over the July Hugging Face hack; more than a dozen states joined Alabama in its investigation (Chase D 
California AG Rob Bonta is investigating OpenAI over the Hugging Face hack in July, after more than a dozen states joined Alabama in its investigation 
European parliament members call for slowdown of Serbia s EU entry over spyware use 
Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People 
AI agents can act on their own and sometimes break out - wyff4.com 
AI agents can act on their own and sometimes break out - WYFF 
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic 
On this day in space! Sept. 4, 1962: NASA's Mariner 2 spacecrafts performs the 1st-ever maneuver in deep space so it could reach Venus 
Recorded Future Announces Automated Signature Creation, Accelerating Vulnerability Prioritization 
We played 'Exodus', a sci-fi RPG that should please 'Mass Effect' fans, even if you can't romance the talking octopus 
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors 
Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign 
Angry Birds: Toy Ghouls’ new toys 
Why judgment is emerging as cybersecurity s defining skill 
Exploring the Moon will require rovers that can think for themselves an upcoming NASA mission will test whether they can 
Dark Web Service Nexus Sells 153M+ Driver’s Licenses 
Pegasus and NoviSpy Used Against Serbian Protesters 
Cisco Fixed Critical RCE in Nexus 9000 Series Switches 
The G7 tells industry to hurry up and prep for post-quantum encryption 
The story behind the intelligence 
OpenAI says its AI technology acted on its own in an 'unprecedented' hack of another company - apnews.com 
'Strange New Worlds'' latest episode is a soap opera spoof, but hasn't 'Star Trek' always been a soap opera in space? 
'Strange New Worlds'' latest episode is a soap opera spoof, but hasn't 'Star Trek' always been a soap opera in space anyway? 
'A new mission starting today': 8 years after launch, BepiColombo begins Mercury arrival 
Comet McNaught put on a surprise show this summer: Here's how to spot it before it fades 
412,000 The Town 2025 Ticket Buyers Data Hits the Dark Web 
Sources: neocloud Fluidstack closed a $1.5B round led by Jane Street at an $18B+ valuation; in July, the startup announced a $750M round at a $7.5B va 
Sources: neocloud Fluidstack closed a $1.5B round led by Jane Street at an $18B+ valuation; in July, the company announced a $750M round at a $7.5B va 
2 spacecraft headed to Mercury are about to begin their long-awaited arrival for Europe and Japan watch it live today 
'Alien Isolation 2' creative director talks upping the scare factor for the sequel (interview) 
OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI 
2 spacecraft headed to Mercury are about to begin their long-awaited arrival for Europe and Japan watch it live on Sept. 3 
Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild 
Blue Origin wins $700 million contract to build NASA's next Mars orbiter 
'You re going to feel exposed, vulnerable, and very isolated' 'Alien Isolation 2' creative director talks upping the scare factor for the sequel (in 
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code 
On this day in space! Sept. 2, 2016: Rosetta spacecraft finds long-lost Philae lander on Comet 67P after 2-year search 
$536 and 8 Hours: AI Learns to Attack a Different PLC 
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware 
Hackers Own Malware Infection Exposes Their RATs, Phishing Kits and Attack Infrastructure - cybersecuritynews.com 
FBI Probes Service Selling 153M+ Drivers Licenses 
The 12 best sci-fi movies of the 2000s 
Cross-border Dark Horse Tops Two Charts! Shengshu Technology Launches MotuBrain, Defining a New Standard for Embodied Intelligence Brain 
MotuBrain: An Advanced World Action Model for Robot Control- Alphaxiv.org Article 
MotuBrain: An Advanced World Action Model for Robot Control 
John Deere is testing JD, an AI assistant for farmers, to help with best practices and find trends based on farmers' "field, machine, and op 
NASA's Roman Space Telescope is just one of a few missions named after real-life women 
DataAgent, which is developing AI agents that autonomously fix failures inside companies' own cloud infrastructure, emerges from stealth with a $ 
Hackers Own Malware Infection Exposes Their RATs, Phishing Kits and Attack Infrastructure - CyberSecurityNews 
OpenAI says its AI technology acted on its own in an 'unprecedented' hack of another company - AP News 
Sonos opens its platform to third-party AI assistants, upgrades Sonos 27voice assistant with an in-house LLM, and plans to let users create their own  
The Justice Department rewrote its own hacking announcement two days later - thenextweb.com 
North Korea-linked IT Workers Are Getting Hired Inside Western Companies 
The Collective Cyber Defense letter wrote your next vendor questionnaire 
U.S. CISA adds PaperCut NG MF flaws to its Known Exploited Vulnerabilities catalog 
Filing: OpenAI denies Apple's allegations of trade secret theft, saying "this dispute is a mess of Apple's own making, and it is trying 
ValleyRAT masquerading as adware 
The Justice Department rewrote its own hacking announcement two days later - The Next Web 
Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft 
Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers 
China-linked Fire Ant Hides Inside Trusted Infrastructure 
ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool 
September full moon 2026: When, where and how to see the Harvest Moon 
Roman telescope leaves its rocket behind Space photo of the day for Aug. 31, 2026 
On this day in space! Aug. 31, 1965: NASA's ginormous Super Guppy carrier plane takes 1st flight like a flying whale 
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112 
Partial lunar eclipse stuns skywatchers with an almost blood moon . Here are the best photos 
This Week In Space podcast: Episode 225 Get a Grip! 
Liftoff! NASA's Roman Space Telescope soars to the stars on a SpaceX Falcon Heavy rocket in spectacular launch (video) 
Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch 
What time will SpaceX launch NASA's Roman Space Telescope today? (Full mission timeline) 
A look at the Hugging Face hack, including AI agents sacrificing themselves for the good of the "collective", and later gaining access to Op 
A detailed look at the Hugging Face hack, including AI agents sacrificing themselves for the good of the "collective" and gaining access to  
Security Affairs newsletter Round 592 by Pierluigi Paganini INTERNATIONAL EDITION 
OpenAI's Hugging Face incident report says AI agents used exploits to gain full admin access to OpenAI's own research cluster supporting its 
This Week In Space podcast: Episode 225 Get a Grip! 
Hack One Robot, Reach the Next: Unitree G1 Security Flaws 
Meeting Nancy Grace Roman: What was the 'mother of Hubble' really like? 
What time will SpaceX launch NASA's Roman Space Telscope on Aug. 30? (Full mission timeline) 
Love Electric Breach: 877,000 Driver Records Offered for $600 
Trump Targets Foreign Technology in New U.S. Power Grid Security Order 
On Cloud 9: Have astronomers discovered the first starless galaxy? 
On this day in space! Aug. 28, 1993: Galileo spacecraft flies by asteroid Ida on the way to Jupiter only to find a tiny moon! 
Curiosity climbs to new heights on Mars Space photo of the day for Aug. 28, 2026 
Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations 
Researchers Execute Code Inside Fortune 500 Companies via AI Agent llms.txt Files 
Partial lunar eclipse stuns skywatchers with an almost blood moon . Here are the best photos 
Sources: the FTC has been investigating whether YouTube broke consumer protection laws by violating its own policies when suspending accounts or banni 
Google adds Expert Intelligence to Gemini Notebook, letting users import eligible titles they own in Google Play Books to ask questions, generate podc 
Sorry, I can t help with that : How your guardrails might become the attacker s best friend 
Internal memo: Meta's AI agent Hatch "has its own computer" to perform tasks, works when the app is closed, can connect to email, Insta 
Funksec 
Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs 
'Strange New Worlds' latest episode wastes a lot of time pretending to kill off major 'Star Trek' characters 
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia 
JavaScript obfuscation: From party trick to phishing kit 
Here's what to expect from each stage of the partial lunar eclipse tonight 
What time is the partial lunar eclipse tonight? Here's when to see the 96% 'blood moon' 
'Star Wars: Zero Company' recaptures the magic of your favorite Star Wars films (review) 
CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do 
Anthropic gives Claude Cowork its own built-in browser on the desktop app separate from users' day-to-day browser, rolling out to paying subscrib 
OpenAI Report Says Its Network Was Hacked By Its Own Rogue AI Agents - NDTV 
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency 
OpenAI report says its network was hacked by its own rogue AI agents - WTVB 
OpenAI says AI agents broke into its own networks as regulators probe Hugging Face hack - The Jerusalem Post 
OpenAI report says its network was hacked by its own rogue AI agents - NBC News 
OpenAI says AI agents hacked its own networks during tests - The Jerusalem Post 
OpenAI report says its network was hacked by its own rogue AI agents - The Mighty 790 KFGO 
OpenAI report says its network was hacked by its own rogue AI agents - KELO-AM 
OpenAI report says its network was hacked by its own rogue AI agents - WNWN-FM 
OpenAI report says its network was hacked by its own rogue AI agents - Reuters 
OpenAI: Agent behavior that led to Hugging Face intrusion formed in May 
A black star in a false Spanish twilight: Here's the story of my 1st total solar eclipse 
Deep Cogito, which develops open-weight models and helps companies build their own specialized AI models, raised a $43M Series A led by TQ Ventures (S 
Banks are warming up to launching their own stablecoins as nonbank companies enter the market; sources: JPMorgan Chase evaluated launching its own sta 
Chance gaze at old Hubble Telescope image leads to discovery that could reveal dark matter's secrets 
'Star Wars: Zero Company' review: XCOM-like strategically recaptures the magic of your favorite Star Wars films 
New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode 
I built my own secure network in the cloud to access my home PCs remotely - for free 
Choose your fighter: Balancing competing requirements to select models for your AI SOC 
Exploits and vulnerabilities in Q2 2026 
88 ID Verification Breaches Show the Cost of Collecting Identity Data 
Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode 
Core Werewolf Hackers Deploy New CoreRAT Malware Against Russian Government and Defense Organizations 
OpenAI asks for more regulation after its own cybersecurity incident proves AI's hacking capability - Fortune 
NASA's Roman Space Telescope will reveal the universe in a way the JWST and Hubble cannot 
Starbase Louisiana: SpaceX announces enormous $100 billion Starbase launch site 
When the Algorithm Fires You: Uber Faces 825M Fine 
Norway s Digital Government Infrastructure Hit by a new DDoS Attack 
The Roman Space Telescope will reveal the universe in a way the JWST and Hubble cannot 
Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable 
This Week In Space podcast: Episode 224 The Science of Artemis 
Accelerated Understanding launches an enterprise-focused physics AI model that uses neural operators and handled 5T pieces of data in a single prompt  
The safety penalty: Reclaiming operational sovereignty in the age of AI 
What time is the partial lunar eclipse on Aug. 27-28? Here's when to see the 96% 'blood moon' 
SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules 
'Ghosts of Mars' at 25: Are we any closer to living on the Red Planet? We asked the experts 
Treasury sanctions alleged Iranian hackers as part of economic D-Day  
'Project Hail Mary' and 'The Martian' author Andy Weir is headed back to outer space, but not how you'd expect 
Cybercriminals Turn GTA VI Leaks Into Malware Bait 
I tried Meta's new free vibe coding app to make my own games, and it was surprisingly fun 
Why do we care so much that Pluto isn't a planet? 
At 25% off, this beginner-friendly Celestron telescope will bring the lunar eclipse closer 
The UAE is fighting AI hackers with AI of its own - Rest of World 
The earliest galaxy 'swallowed' by the cannibal Milky Way left a scar at its heart 
What to expect from each stage of the partial lunar eclipse on Aug. 27-28 
It's been 20 years since Pluto lost planet status. Will it ever get its title back? 
These tiny drones are powered by sound 
Anthropic Brings Claude Mythos 5 to Cyber Defenders for Vulnerability Scanning and Patching 
Greg Abbott says data center companies "dug their own grave" by moving into communities without first gaining support, signaling growing Rep 
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection 
Postal Service moves to finalize mail ballot regs before SCOTUS ruling 
ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries 
How will NASA's astronaut training hub change with commercial space stations? 
This Week In Space podcast: Episode 224 The Science of Artemis 
A beginner s guide to observing the night sky with a manual telescope 
Forget 'Halo' the latest 'Futurama' episode has a ring world covered in super-intelligent rats (exclusive) 
I sailed to Greenland for a total solar eclipse what I saw left me speechless 
Ludicrous, nonsensical, an affront to canon 'Strange New Worlds'' puppet episode is an instant classic 
Malware Hijacks Android Car Head Units 
Anthropic hires Amir Salek, who ran Google's TPU business until 2022, to join its compute team as part of a push to develop its own chips (Dina B 
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot 
'Dark stars' could be the seeds of supermassive black holes, scientists say 
Copilot Revealed Its Own Vulnerability Through Meta-Hacking : Varonis - Security Boulevard 
Six Maximum-Severity Flaws Found in Cisco Products 
U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog 
The invisible passenger in your car 
Cl0p Targets 40+ Organizations Through PTC Windchill Flaw 
Source: Anthropic plans a change for later this year that still requires enterprises to retain data for 30 days but lets them do so on their own cloud 
'Wet Hot American Summer': The raunchy 2000s comedy that was actually about a space station falling to Earth 
US DOJ Indictment Re Malicious Iranian Cyber Activity Against the Trump Campaign; Activities Date from 2019 to Present 
Source: Anthropic plans a safety system this year that still requires enterprises to retain data for 30 days but lets them do so on their own cloud sy 
Source: Anthropic plans a safety system this year still requiring enterprises to retain data for 30 days, with an option to do so on their own cloud s 
Is Cyber missing the Marque? 
'Wet Hot American Summer': The raunchy 2000s teen movie that was actually about a space station falling to Earth 
Source: Anthropic plans a safety system this year requiring enterprises to retain data for 30 days, with an option to do so on their own cloud infrast 
Ludicrous, nonsensical, an affront to canon 'Strange New Worlds'' puppet episode is an instant classic 
Google will let you tailor your Discover feed using natural language now 
The push to designate AI as the next critical infrastructure sector 
US Defense Contractors Admit Their Rising CMMC Scores May Not Be Accurate 
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations 
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities 
US Indicts 17 Iranians Over Years-Long Cyber Espionage Campaign 
How To Sign Out Other Users Out On Windows 11 
Private mission to save NASA's Swift space telescope fails 
Scientists create 'laundry gun' for astronauts to clean their clothes by shooting out plasma 
Inside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua Cameras 
Perseverance rover watches alien solar eclipse on Mars Space photo of the day for Aug. 19, 2026 
13 sci-fi books that inspired our favorite shows and movies 
Perseverance rover watchs alien solar eclipse on Mars Space photo of the day for Aug. 19, 2026 
On this day in space! Aug. 19, 1997: 1st Filipino satellite launches into orbit 
I sailed to Greenland for a total solar eclipse what I saw left me speechless 
Copilot is tricked into revealing his own hacking methods. - gigazine.net 
659 Stripe Merchant API Keys Leaked Online, Exposing 688,000 Customer Records 
Astronomers discover a giant, rocky 'mega-Earth' 23 times more massive than our planet 
50,000 Stripe Secrets Leaked in Public Code 
U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog 
Robotics roadmaps from around the world spotlight of the month: Japan 
Copilot is tricked into revealing his own hacking methods. - GIGAZINE 
Cyber Threats Against Energy Sector Surge as Global Tensions Mount 
Forget 'Halo' the latest 'Futurama' episode has a ring world covered in super-intelligent rats (exclusive) 
Harvey announces Harvey Tenet, its first in-house, proprietary model for legal work, trained on mock disputes and case files using its own version of  
The Hugging Face Incident Was a Governance Failure 
Copilot Exposed Its Own Vulnerabilities When Prompted 
Project noRecognition: Teaching AI to Fool Surveillance Cameras 
Medusa ransomware tallies hundreds of new victims, says updated advisory on group s tactics 
Threat Alert: TeamPCP, An Emerging Force in the Cloud Native and Ransomware Landscape 
A beginner s guide to observing the night sky with a manual telescope 
New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles 
Alibaba says its new open-source multimodal model, Qwen3.8-27B, passed 1M+ downloads within a few days of release, making it one of its fastest-growin 
AI inference chip startup Etched raised $700M led by its new server rack customer Jane Street at a $21B valuation, up from $10.3B after raising $300M  
How to watch 'Lanterns' HBO's gritty new Green Lantern show 
This Week In Space podcast: Episode 223 The Lunar Domain 
GitLab Patches Critical Unauthenticated GraphQL Vulnerability 
Pok mon Center Data Breach Exposes Customers Personal and Order Data 
How an ancient collision with another galaxy transformed the Milky Way 
Scientists find dead star that predicts our sun's future: 'Broken apart and returned to the galaxy' 
Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure 
New Intelligence Links TeamPCP to ShadowRay 2.0 and Traces Activity back to 2020 
Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline 
Blue Origin adding second pad to Cape Canaveral launch complex amid rocket explosion repairs 
AI Agents Hacked Taiwan on Their Own. Experts Say It Changes Cyberwarfare - International Business Times 
McDonald s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen 
Akira Ransomware Uses Safe Mode to Bypass EDR 
ChatGPT maker OpenAI says its AI technology acted on its own in an 'unprecedented' hack of Hugging Face - ABC7 New York 
DDoS Attacks Cause Major Threema Outages 
How to watch 'Lanterns' HBO's gritty new Green Lantern show 
'This goes beyond showcasing technological soft power': China's new moon map signals bold space ambitions (video) 
Stomp Rockets: The perfect start to model rocketry for kids? 
Security Affairs newsletter Round 590 by Pierluigi Paganini INTERNATIONAL EDITION 
APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2 
Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware 
'Lanterns': Who's who in HBO's Green Lantern show? 
This Week In Space podcast: Episode 223 The Lunar Domain 
Is empty space really empty? This magnetic star may finally solve a 90-year-old mystery 
Cards Against Humanity wants to erect a monument to 'honor' Elon Musk 
6 space board games to channel the political drama of 'For All Mankind' and 'Star City' 
Apple officially opens ad bookings for businesses on Apple Maps ahead of an upcoming full rollout across the US and Canada (Ryan Christoffel 9to5Mac) 
Hacking your own university and getting credits for it - Universiteit Leiden 
India-US space ties deepen as NASA invites ISRO to join moon base program 
I used OpenFactory to build my own Linux distro overnight - this AI tool is going to be big 
Who’s Tracking You? Use This New Service to Find Out 
SpaceX rocket's moon crash highlights 'a tangible operational risk' of lunar settlement 
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit 
AmnesiaStealer Gives Attackers Live Control of Victims macOS Browsers 
New Bring Your Own EDR Attack Turns SentinelOne Into Trojan Horse to Bypass Windows PPL 
A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo. 
Curiouser and Curiouser 
'The X-Files' creator Chris Carter says new director's cut of 'I Want to Believe' is 'the horror movie that we really wanted to make' (interview) 
U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog 
Malware Crypting Services and the Threat Actors Who Sell Them 
Akira Affiliate Crashes Ransomware After Attempting EDR Evasion 
SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit 
Armored Likho expands its cyber-espionage toolkit 
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job 
This year's 'Masters of the Universe' movie wasn't Hollywood's first attempt at capturing the power of He-Man; they tried back in 1987, and failed the 
Mistral says its platform will support third-party open models, starting with Z.ai's GLM-5.2, and run them on the same infrastructure as its own  
China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan 
Total solar eclipse 2026 has begun. Here are the first views of totality 
Radiation-shielding vest aced Artemis I lunar test, could protect astronauts on moon and Mars missions 
Can Organizations Trust Their Own AI? 
Google plans to launch the $29 Pixel Tag on November 11, with a four-pack priced at $99, matching AirTag 2's pricing, offering UWB, Find Hub supp 
Farthest 'black hole star' ever found could help solve the James Webb Space Telescope's little red dot mystery 
Google plans to launch the $29 Pixel Tag on November 11 with a four-pack priced at $99, matching AirTag 2 pricing, offering UWB, Find Hub support, and 
ShieldBreak: New Windows Zero-Day Bypasses Microsoft s RoguePlanet Patch 
Robotics roadmaps from around the world 
The Best Network Traffic Analysis (NTA) Tools, Compared and Priced (2026) 
Kimwolf botnet rebuilt to survive takedowns, researchers say 
The inconvenient truth about AI pentesting: someone has to check all the work 
What history can teach us about the future of property rights in space (op-ed) 
Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) 
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo 
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants 
Will Perseid shooting stars be visible during the Aug. 12 total solar eclipse? 
Watch the total solar eclipse online Aug. 12 with these free livestreams 
The FTC wants to regulate AI for ideological bias 
Source: Applied Compute, which helps companies customize models with their data, is in talks to raise "hundreds of millions" led by Elad Gil 
NATO and an AI startup can now name and track software vulnerabilities 
The Andromeda galaxy may be getting bullied by a smaller galactic neighbor, scientists find 
Inside the mystery of the James Webb Space Telescope's little red dots and how they might be evolving 
This Week In Space podcast: Episode 222 How to Invade Earth in 22 Easy Steps 
Lego Project Hail Mary review: Amaze, amaze, amaze! 
The Hugging Face Hack Was Cheap Persistence at Work 
A 5-in-1 seed-sized surgical robot 
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development 
This ZWO astronomy camera is perfect for solar and lunar imaging 
9.2 Million Israeli Records Sold as a New Breach Are 20 Years Old 
North Korea’s elite hackers turned on their own government – and got caught 
OpenAI Pauses Astra Model Over Critical Cybersecurity Risk Concerns 
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets 
Pressure-free growing robots for soft medical robotics 
Soft robotic heart offers new way to study disease and test life-saving devices 
Surviving the paper deluge: a one-year study in learning from demonstration 
Operationalizing Secure by Design: a CISO’s guide to closing the gap between policy and reality 
The water sector just got it’s wake-up call. Again. 
Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online 
Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams 
Read This Before You Buy That TV Streaming Stick 
New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery 
Toy Ghouls’ new toy: the GenieLocker ransomware 
An analysis of incidents at Brazilian educational institutions 
Modern Attack Vectors Recorded Future 
Hype vs. Reality: What the Hugging Face Incident Means for AI Safety 
Claude Code Child Process Can Read Its Own OAuth Token From macOS Keychain 
Preview: Cisco Talos at Black Hat USA 2026 
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel 
Don t swing at everything 
Keep going, bro. You ve got this! A data-driven look at how adversaries are weaponizing AI 
Why metaphor may dictate your security strategy 
Arsenal-NG: A Terminal Cheat-Sheet Launcher for Faster Penetration Testing 
Impacket for Pentester: reg 
What Happened Between OpenAI and Hugging Face? 
Rapid7 Analysis: Check Point SmartConsole Authentication Bypass (CVE-2026-16232) 
Metasploit Framework 6.5 Released 
Rapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor Assessment 
KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails 
WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover 
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data 
Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions 
Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools 
A GitHub Misconfiguration Let Kimi K3 Cheat a Cybersecurity Benchmark 
'The Ninth Jedi' review: This anime spin-off abandons 'Star Wars' canon, and it's all the stronger for it 
Plan your perfect 2026 total solar eclipse experience with these smartphone apps 
SpaceX rocket's impact crater on the moon spied by Korean lunar orbiter (photos) 
'Strange New Worlds' latest 'Hangover'-inspired episode is a reminder that 'Star Trek' vacations are never a good idea 
Engineers race to save stricken LINK rescue spacecraft before it's too late 
Inside the mystery of the James Webb Space Telescope's little red dots and how they might be evolving 
This Week In Space podcast: Episode 222 How to Invade Earth in 22 Easy Steps 
'Transformers: The Movie' at 40: the cartoon spin-off that traumatized a generation of kids 
What time is the total solar eclipse on Aug. 12, 2026? 
 
TeamPCP 
CVE-2026-68562 
CVE-2026-18381 
CVE-2026-67316 
CVE-2026-67320 
CVE-2026-67351 
CVE-2026-18089 
CVE-2026-17566 
CVE-2024-14040 
CVE-2026-17350 
CVE-2026-17351 
CVE-2026-65981 
CVE-2026-16635 
CVE-2026-16540 
CVE-2026-65054 
CVE-2026-16503 
CVE-2026-63979 
CVE-2026-64538 
CVE-2026-64092 
CVE-2026-64124 
CVE-2026-64464 
CVE-2026-63914 
CVE-2026-64183 
CVE-2026-64404 
CVE-2026-63894 
CVE-2026-64057 
CVE-2026-64426 
CVE-2026-64527 
The Perseid meteor shower is here! How to see the best shooting stars this summer 
SpaceX Starship Flight 13 launch updates: New launch date under review 
Undergrads weed-killing robot wins top prize 
New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT 
Own a Pixel? You can add device protection now for $5 month - but should you? 
CVE-2026-16089 
SpaceX's Starship Flight 13 test launch aborts at last second (video) 
SpaceX Starship Flight 13 launch updates: Scrub 
SpaceX Starship Flight 13 launch updates: LIFTOFF! 
SpaceX Starship Flight 13 launch updates: Countdown to launch has begun! 
An NYT reporter finds AI-generated, unauthorized biographies of herself and other journalists on Amazon, where AI-made books with elusive "author 
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers 
Google updates its AI video editor Vids with Gemini Omni and a feature that lets users create custom digital avatars using a selfie and voice recordin 
Program to rotate cyber personnel through federal agencies saw little use 
SpaceX Starship Flight 13 launch updates: Elon Musk's future moon rocket is ready for liftoff today 
Begun, the Patch Wars have 
Astronomers discover 1st atmosphere around a rocky Earth-like planet in the habitable zone 
SpaceX stacks massive Starship rocket ahead of today's Flight 13 test launch (video) 
HelloNet campaign new malicious modules launched through the ViPNet update system 
Modular macOS Stealer Uses Kill Loops to Force Password Entry 
OpenAI has created a 'super-hacker' to hack its own AI models - Mezha 
SpaceX Starship Flight 13 launch updates: Rocket stages stacked and ready for liftoff today 
TuxBot v3: The IoT Botnet Built With AI – Bugs, Disclaimers and All 
The Hunter's Paradox: Is it time to embrace automated threat hunting? 
SpaceX will launch Starship, the world's largest rocket, on critical Flight 13 test today. Here's what to expect. 
Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign 
CVE-2026-15992 
Security researchers find stalkers abusing Chrome’s sync feature 
The 10 best British sci-fi shows of all time 
Chaotic Eclipse Unveils LegacyHive Exploit Affecting Fully Patched Windows Systems 
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps 
Forget the model. When it comes to cybersecurity, it s all about the harness 
The Shift: A New Era of AI Regulation 
AsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly Downloads 
SpaceX Starship Flight 13 launch updates: Starship undergoing preparations to launch tomorrow 
What time is SpaceX's Starship Flight 13 launch on July 16? (Full mission timeline) 
Patch Tuesday security updates for July 2026, the largest update ever. 621 CVEs in one month 
Scientists spot 4 superdense stellar corpses hiding behind their red dwarf companions 
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack 
U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses 
Microsoft Patches a Record 570 Security Flaws 
Google Search will let you instantly generate AI images for free - here's how 
Treasury sanctions First VPN Service, others for abetting ransomware gangs 
SpaceX Starship Flight 13 launch updates: Super Heavy booster rolled back for final checkouts 
The biggest skywatching day of 2026 is coming. Here's what you'll see in North America and Europe 
How to watch SpaceX launch Starship Flight 13 on July 16 
Attacker Used AI to Build Custom PowerShell Recon Malware 
The serpent s tongue: Luring the Python out of its den 
Moon landings could destroy evidence of life's origins 
CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper 
SpaceX Starship Flight 13 launch updates: SpaceX sets target date for next Starship rocket launch 
States are building their own election defense networks as federal support evaporates 
SpaceX targets July 16 for Starship Flight 13, reveals what went wrong on previous launch 
Lessons Learned from CISA’s Recent GitHub Leak 
This Week In Space podcast: Episode 218 Which Way to the Moonbase? 
Getting Vikram-1 to orbit: Inside Skyroot Aerospace's coming bid to make spaceflight history 
Wristband enables wearers to control a robotic hand with their own movements 
CVE-2026-15641 
Why space games still struggle with the scale of the universe 
Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here’s What We Know. 
This Week In Space podcast: Episode 218 Which Way to the Moonbase? 
Sci-fi action movies were better in the '90s. 'Independence Day' is full of reasons why 
AWS GovCloud Credential Leak Leads CISA to Share Critical Cyber Incident Lessons 
SpaceX ignites all 33 powerful engines on Starship booster ahead of Flight 13 launch (video) 
Thinking Machines says its mission is to build AI that people and organizations can shape and make their own, and that "extends human will and ju 
In its lawsuit, Apple chronicles in vivid detail how its former employees that went to work for OpenAI allegedly violated their confidentiality agreem 
Launching from 2 continents: Germany's Isar Aerospace leases Canadian pad for $150 million 
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot 
SpaceX ignites all 33 powerful engines on Starship booster ahead of Flight 13 launch 
I ditched Google Drive for my own self-hosted storage - and I wish I'd done it sooner 
SpaceX ignites all 33 powerful engines on Starship booster test ahead of Flight 13 launch 
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites 
222 GitHub Repositories Linked to Fake Go Package Malware Operation 
Making history! China lands rocket during an orbital launch for 1st time ever (video) 
GigaWiper Merges Three Malware Families Into One Destructive Backdoor 
Making history! China lands rocket during an orbital launch for 1st time ever 
CVE-2026-61502 
Winning 54% of the time 
GodDamn Ransomware Uses PoisonX to Blind Security Software 
'Silo' season 3 showrunner Graham Yost explains the time jumps and turning half of the show into a political thriller (interview) 
Character.AI launches three human-written, AI-generated microdramas, whose characters users can chat with, and aims to eventually let users make their 
Enterprise AI agent startup Lyzr is raising a $100M Series B at a $500M valuation, up from $250M in a Series A in 2026, and says agents wrote investm 
China announces plan to build early-warning system for dangerous asteroids 
Staffing the moon base: How many astronauts should live in NASA's lunar outpost? 
Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes 
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It 
CVE-2026-61451 
CVE-2026-61442 
French nonprofit starts global intelligence and research hub for AI cyber threats 
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers 
Windows Privilege Escalation: SeDebugPrivilege 
Prime Intellect, which helps companies build their own AI agents by offering computing power and specialized tools, raised a $130M Series A at a $1B v 
The Threat Isn t the Frontier Model 
CVE-2026-15074 
CVE-2026-15076 
Our Milky Way galaxy might be larger than we thought 
Artemis 2's Jeremy Hansen stepping down from active astronaut duty after epic moon mission 
Sources: Microsoft, looking to reduce AI costs, is starting to replace models from OpenAI and Anthropic with its MAI models in products like Excel and 
China releases 1st photo of Earth's elusive 'quasi-moon' Kamo'oalewa 
Introducing Apex Discovery to secure every domain you actually own 
Sources: DeepSeek is at an early stage of developing its own AI chip designed for inference, in a push that could reduce its reliance on Nvidia and Hu 
Sources: DeepSeek is in the early stages of developing its own AI chip designed for inference, in a bid to reduce its reliance on Nvidia and Huawei ha 
UAT-7810 continues building ORB networks using new malware 
AI-Generated Malware Powers New Armored Likho APT Campaign 
Januscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape Attacks 
CVE-2026-59876 
CVE-2026-59952 
More clues surface about the origins of interstellar comet 3I ATLAS 
NASA just found a planet 'hiding' in TESS spacecraft data, all thanks to Einstein 
Sysdig clocks first documented case of agentic ransomware 
A Day With Your Vector Command Red Team Pod 
How Masayoshi Son is remaking SoftBank in his own image, betting on AI; SoftBank trades at a 50% discount to its net asset value, as some question hi 
Hackers Use Trusted Microsoft Domain and One-Time Codes to Hijack Corporate Accounts 
How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions 
Astronomers discover radio signals coming from rare 'Blue Eye Pulsar' after decades of silence 
How Masayoshi Son is remaking SoftBank in his own image, betting on AI; SoftBank trades at a 50% discount to its net asset value, as some question th 
Seven Bugs in FatFs Put IoT and Embedded Devices at Risk 
Why traditional DAST Tools fail modern AppSec teams (and how to fix it) 
Bad Epoll Flaw Gives Attackers Root Access on Linux and Android 
CVE-2026-59729 
CVE-2026-59695 
He-Man and beyond: 20 sci-fi cartoons (some iconic, some weird) that transported '80s and '90s kids to strange new worlds 
America 250: From 1776 to the moon and beyond (A Space.com series) 
This Week In Space podcast: Episode 217 America in Space 
Human flight was still 7 years away in 1776. Now, we're headed back to the moon 
How to find Uranus this week, the hardest planet I've ever tried to see 
As 'Terminator 2: Judgment Day' turns 35, it's time to accept the truth: Terminator shouldn't be back 
Meta could use its compute for its own models, ad scaling, SpaceX-like neocloud deals, and hosting 3rd-party models; it may be close to an Anthropic d 
Could humans someday explore Saturn's moon Titan, or will humanoid robots do it for us? 
Celebrate 250 years of America with the Estes Liberty Star model rocket 
Space science has come a long way since July 4, 1776. Here's a look back at the saga 
Infant stars celebrate their independence with cosmic fireworks Space photo of the day for July 3, 2026 
JADEPUFFER: First End-to-End AI-Driven Ransomware Operation 
NASA launches rescue mission to save Swift space telescope from burning up in Earth's atmosphere 
How to invade planet Earth: A sci-fi movie alien's guide to bringing the human race to its knees 
America at 500: Where will we be in space in 2276? 
Law enforcememt operation disrupted Malicious Residential Proxy Networks NetNut 
NASA to launch rescue mission today to save Swift space telescope from burning up in Earth's atmosphere 
CVE-2026-14620 
SpaceX fires up all 6 of Starship's engines ahead of 13th test flight (video) 
FBI Seizes NetNut Proxy Platform, Popa Botnet 
Europe Confirms Record 4.1B Penalty Against Google for Android Practices 
Reflections from ICRA 2026 
How to invade planet Earth: An alien's guide to bringing the human race to its knees 
Formalizing Red Teaming Offensive Methodology as a Multi-Agent AI Architecture 
Sources: Anthropic has initiated early-stage development of a custom AI server chip and held preliminary discussions with Samsung about manufacturing  
Microsoft's new Azure Linux 4.0 is here, and it could replace Windows Server in the enterprise 
July full moon 2026: When, where and how to see the Buck Moon 
Rocket issue delays NASA launch of rescue mission to save Swift space telescope 
430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link 
CVE-2026-59093 
CVE-2026-14495 
CVE-2026-14483 
Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack? 
Steven Spielberg sci-fi movies ranked, worst to best 
I had Gemini and Claude write my email replies - but only one sounds like me 
Stunning new NASA space telescope images reveal the universe in red, white and blue for America 250 
5 Myths About AI in the SOC Security Teams Need to Rethink 
New NASA space telescope images reveal the universe in stunning red, white and blue for America 250 
In 1776, the solar system only had 6 planets. Now, it has 8. Does it end there? 
RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow 
NASA to launch rescue mission July 2 to save Swift space telescope from burning up in Earth's atmosphere 
NASA audit puts Boeing's Starliner under an even bigger microscope: When will it fly astronauts again? 
GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents 
[Thread] The US' now-lifted export controls on Anthropic models created uncertainty, are an own goal, and will push service providers towards Chi 
Leaked Apple supplier docs show iPhone 18 Pro and Pro Max may use Qualcomm modems in the US and Apple's own C2 chips elsewhere, A20 Pro packaging 
Hackers Use Vulnerable Windows Drivers to Kill EDR in Ransomware Attacks 
XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t 
CVE-2026-14352 
CVE-2026-14336 
'PROMISE' me the moon? NASA wants to send spare nuclear-powered Mars rover to the lunar surface 
U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog 
Rubin Observatory begins filming the 'greatest cosmic movie ever' beginning a new era of astronomy 
America 250: How has telescope technology evolved since the dawn of the U.S.? 
Active Directory Forest Trust Abuse: Child-to-Root Domain Escalation 
'Titan is actually a very reasonable destination for humans': Scientists start mapping out crewed mission to huge Saturn moon 
NASA to launch rescue mission July 1 to save Swift space telescope from burning up in Earth's atmosphere 
'I'm still a Trekkie at heart': 'Starseeker: Astroneer Expeditions' takes space exploration games in a friendlier direction (interview) 
Inside the inbox: Why cybercriminals want to break into your email account 
CVE-2026-14224 
CVE-2026-58410 
CVE-2026-14191 
CVE-2026-58408 
CVE-2026-58489 
Warner bill would create federally vetted list for secure, trustworthy AI agents 
'Starseeker: Astroneer Expeditions' takes space exploration in a different (and friendlier) direction, and we chatted with System Era's creative direc 
NASA to launch rescue mission June 30 to save Swift space telescope from burning up in Earth's atmosphere 
Supreme Court approves mail-in ballots that arrive after Election Day 
Sources: Amazon is weighing using OpenAI's and its own Nova models to cut costs after Anthropic raised prices for using its models in Amazon prod 
Modernizing Global Vulnerability Standards For The Age Of AI 
StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years 
The James Webb Space Telescope peered into one of the universe's oldest galaxy clusters, and scientists can't explain what they saw 
An interview with Axon CEO Rick Smith, who transformed the Taser maker into a policing software company, as its revenue from AI policing tools rises 7 
CVE-2026-13756 
CVE-2026-13767 
'Superman Returns' at 20: Is it a sequel? Is it a reboot? Two decades on, we're still not sure 
Hospitality Sector Hit by Phishing Campaign Using Fake Guest Complaint Emails 
This Week In Space podcast: Episode 216 Dark Matter Intelligence 
My nephew still uses this kids' star projector every night get it for just $15 at Amazon on Prime Day 
'Exodus: The Helium Sea' author Peter F. Hamilton talks universe crafting and finishing the story in this second prequel novel for sci-fi RPG 'Exodus' 
Beam me up to 4K: Your ultimate sci-fi collection for less than $25 on Prime Day 
Watch a 'Potentially hazardous asteroid' the size of a skyscraper close in on Earth live online tonight 
OpenAI says 97.9% of its employees are now using Codex, up from 40% in August 2025; non-developer Codex usage is up 137x for individuals and 12x with 
Sources: during SpaceX's IPO roadshow, COO Gwynne Shotwell told investors that it may launch a Starlink mobile service and build its own terrestr 
Neon green auroras from space will take your breath away Space photo of the day for June 26, 2026 
NASA's canceled Artemis hardware contracts reached $5.9 billion, audit finds 
Meet the mindset hackers manifesting their own success - telegraph.co.uk 
Activist Phone Hacked With Cellebrite After Russia Contract Cancellation 
NASA is paying $30 million for a 1st-of-its-kind rescue mission to the aging Swift telescope before it falls from space. Is it worth it? 
macOS.Gaslight: North Korea-Linked Malware That Tries to Gaslight the Analyst 
Sources: SpaceX COO Gwynne Shotwell told investors during an IPO roadshow SpaceX may launch a Starlink mobile product and build its own terrestrial US 
OpenAI says 97.9% of its employees are now using Codex, up from 40% in August 2025; non-developer usage of Codex has risen 137x for individual users  
Turn your room into a galaxy: The best Prime Day deals on star projectors for aspiring astronomers 
CVE-2026-13446 
CVE-2026-13444 
Beyond IOCs: AI-enabled threat intelligence 
Federal court rules Trump election-focused executive order illegal 
Inside Mistic, the New Stealth Backdoor in Ransomware Intrusions 
A SpaceX rocket will slam into the moon this August. Will we be able to see it? 
15 of our favorite sci-fi audiobooks to transport you to another planet 
Minnesota man known as Snoopy sentenced in DraftKings hack 
Evaluating Mexico s New Cybersecurity Plan 
Traveling to see the total solar eclipse this August? This solar binocular Prime Day deal is a total-ly bright idea! 
Meet the mindset hackers manifesting their own success - The Telegraph 
Real-world attack surface monitoring at massive scale: how the UK Government protects over half a million public sector domains 
What time is it on the moon? The US and China disagree 
Introduction to COM usage by Windows threats 
We praised this telescope's 'legendary performance,' and the whole range is even cheaper for Prime Day 
Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools 
I regret missing Project Hail Mary on the big screen but I'm not skipping this cheapest-ever UK Prime Day Lego deal 
Nathan Austad Pleads Guilty in DraftKings Hacking Scheme, Gets 18 Months 
My nephew still uses this kids' star projector every night get it for just $15 at Amazon on Prime Day 
Paris-based Tsuga, whose observability software runs in customers' own clouds to help them skip per-byte ingestion costs, raised a $35M Series A  
CVE-2026-57848 
'50% superhero and 50% noir, but 100% totally new': 'Spider-Noir' composers on injecting retro style into the superhero multiverse (interview) 
Documents: Meta's planned prediction markets app will use Meta AI models to generate questions from trending topics, make recommendations, and re 
As 'Avatar: Fire & Ash' hits Disney+, we look at 3 of the weirdest alien creatures in the 'Avatar' movies 
Why Frontier AI makes prioritization the most important part of your CTEM program 
NASA looks for the origins of interstellar comet 3I ATLAS Space photo of the day for June 24, 2026 
I'm obsessed with my Ninja Creami ice cream maker - and Amazon just cut the price 
ESA chief calls for greater European space autonomy as trust in US partnership erodes 
FortiBleed: The Broker Who Turned 73,000 Firewalls Into a Product Catalog 
CVE-2026-13295 
Samsung KNOX Kernel UAF Exposes Millions of Galaxy Devices 
DifyTap: Four Bugs Put over 1 million AI Apps at Risk 
This might be your last chance to pick up a retired Lego Star Wars set before it flies off forever, and it's under $100 on Amazon for Prime Day 
Why SIEM is Moving Toward Unified Security Operations: Rapid7 Named a Major Player in IDC MarketScape 
Anthropic launches Claude Tag, an agentic AI coworker for Slack that can learn context, give suggestions, and more, in beta for Claude Team and Enterp 
China's space plane appears to have released a mystery object in orbit 
'Rick and Morty' cast talk vocal health, hot viscous liquids, and their favorite season 9 moments (interview) 
Ignite a child's imagination with the stars: Our expert-picked Astronaut Galaxy Star Projector is a Prime Day steal at just $25 
Meta unveils Meta Adventurer and Fury glasses, each priced at $299, its first under its own brand, and a $399 Starfire model in collaboration with Kyl 
Meta unveils Meta Adventurer and Fury glasses, each priced at $299, its first under its own brand, and a $399 Starfire model in partnership with Kylie 
AI brings object-level vision prosthetics closer to reality 
This beginner-friendly travel telescope is the reason I turned into a skywatcher 
ShapedPlugin Supply Chain Attack Backdoors Pro Plugin Updates 
CVE-2026-13089 
CVE-2026-57081 
CVE-2026-56843 
CVE-2026-13042 
'This is not like life that we ve experienced' 'Star City' cast on struggling to relate to the brutality of Soviet existence in Apple TV's For All M 
This Week In Space podcast: Episode 215 Disclosure Day 
Anthropic’s Mythos AI broke into almost all NSA classified systems in hours 
A VBScript campaign distributed through WhatsApp deploying RMM software 
CVE-2026-50251 
CVE-2026-12904 
AI-Powered Active Directory Pentesting with Claude, HexStrike AI & NetExec 
Virus vs Worm: Why the Propagation Difference Actually Matters 
Inside GentleKiller: The EDR-Killer Powering The Gentlemen 
FortiBleed Exposes Global Credential-Spraying Operation 
CISA Warns of Active Exploitation Following FortiBleed Leak 
CVE-2026-56321 
CVE-2026-12789 
Oura Ring 5 review: impressive thinness, live activity tracking, and conversational AI, but not very durable, LEDs are distracting, and the app is con 
The Ninja Creami just dropped to an all time low price for Prime Day - and I recommend one 
5 reasons I'm using Android Auto instead of my car's own infotainment system - and can't go back 
CVE-2026-56232 
CVE-2026-12740 
CVE-2026-12746 
CVE-2026-56212 
The Klue Security Incident and Its Impact on Recorded Future 
Congress tees up No FAKES Act, aiming at AI-generated deepfakes 
Sources: APEC, a derivatives exchange founded by the 22-year-old son of pro-crypto Senator Kirsten Gillibrand, raised $30M led by Lux at a $300M valua 
Tor-Based Clipper Malware Targets Wallet Seed Phrases 
Close Encounters of the Human Kind 
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm 
How software development’s speed obsession enabled TeamPCP s chaos crusade 
Report: DeepSeek's first external funding round has a non-negotiable term for investors to not poach its staff or encourage them to start their o 
Scripting the disassembler: Local agentic reverse engineering through vbdec s live COM object model 
AI agents are getting their own search engine 
Prem AI, a Swiss startup that lets hedge funds and law firms run AI models on their own infrastructure, is raising a $100M Series A, targeting a $500M 
Report: DeepSeek's first external funding round has a non-negotiable term that investors should not poach its staff or encourage them to start ow 
FortiBleed Exposes Admin Passwords for 75,000 Fortinet Firewalls 
CVE-2026-56081 
Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed 
A Detailed Guide on Villain C2 Framework 
DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two Months 
From 1% to 26%: How AIDA Orchestration Fixes the Remedial Training Gap 
Malware la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain 
FulcrumSec Targets Novo Nordisk, Leaks Clinical and Research Data 
A look at Wyoming's Frontier Stable Token, which launched in January and currently has a market value of $1M, as other states explore "whit 
CVE-2026-55771 
CVE-2026-55667 
CVE-2026-12525 
CVE-2026-55953 
CVE-2026-12493 
CVE-2026-55838 
The Intelligence No One Else Has: Inside Recorded Future s Proprietary Collection Engine 
Dozens of malicious wallpapers found on Steam Workshop: gamers’ accounts at risk 
CVE-2026-55603 
CVE-2026-12434 
CVE-2026-55388 
CVE-2026-12379 
CVE-2026-12435 
CVE-2026-12407 
CVE-2026-55234 
CVE-2026-12472 
Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails 
Anthropic's belief in its own commitment to safety gives Anthropic the license to aggressively favor its business and even challenge the US gover 
Beyond the Score: Using AI to Translate CVEs into Real-World Business Risk 
Fox says it obtained a $12B loan for the $22B Roku deal; existing Fox shareholders are expected to own 73% of the combined company and Roku sharehol 
Fox says it obtained a $12B loan for the Roku deal; existing Fox shareholders are expected to own 73% of the combined company and Roku shareholders  
Entangled robotic matter with cohesive motion 
Supply Chain Attack Hits Popular WordPress Plugins Through Awesome Motive CDN 
Infostealers, AI, and a 90% Affiliate Cut Fuel The Gentlemen group s Rise 
CVE-2026-54562 
CVE-2026-54763 
CVE-2026-54761 
CVE-2026-54458 
Satya Nadella says companies must own their AI "learning loops" to compound human and token capital, or risk ceding all value to a handful o 
Companies are grappling with whether and how to curb employee wagers on prediction markets that may use confidential info, as platforms tighten their  
Automated Penetration Testing with Claude AI 
Automating Penetration Testing with Claude AI 
U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14 
Penelope A Modern Alternative to Netcat for Red Teamers 
CyberCorps is adapting to AI. The budget isn’t keeping up. 
Zelle owner EWS says it plans to expand the payment service later in 2026 to India, its first international market, and create its own USD-backed stab 
Zelle owner EWS says it plans to expand the payment service to India later this year, its first international market, and create its own USD-backed st 
CVE-2026-54358 
CVE-2026-54249 
CVE-2026-12124 
CVE-2026-54307 
CVE-2026-54272 
A tale of two eras 
CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch Release 
Sources: Anthropic signed 12+ initial agreements for direct data center leases, a first for the company, with Google potentially providing a financial 
Recorded Future Launches Impact and Metrics Dashboard 
Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime 
CVE-2026-11987 
CVE-2026-54017 
CVE-2026-12048 
CVE-2026-54097 
CVE-2026-54010 
CVE-2026-12047 
CVE-2026-54008 
CVE-2026-54029 
CVE-2026-54036 
CVE-2026-12046 
CVE-2026-54012 
CVE-2026-54006 
CVE-2026-54104 
Smashing Security podcast #471: This AI worm just rewrote its own rules 
OpenAI: Likely Chinese influence operation tried to use ChatGPT to stir debate on data centers 
Rapid7 Quarterly Threat Landscape Report: Zero-clicks, geopolitical tensions, and some wins for law enforcement 
LinkedIn debuts its first creator marketplace, in North America, allowing some marketers to search for creators by topic and view "creators cards 
AI Worms , researchers demonstrate autonomous malware capable of adapting to any online device 
France’s Government Messaging App Tchap Got Breached 
CVE-2026-11900 
CVE-2026-53722 
CVE-2026-11943 
CVE-2026-11870 
A Record-Breaking Patch Tuesday for June 2026 
Analysis: Trump and his sons profited $2.3B+ from four crypto ventures including $TRUMP since January 2025, while other investors in those projects lo 
Anthropic’s new model is Mythos on a leash 
CVE-2026-52806: Authenticated RCE via Argument Injection in Gogs (FIXED as of June 7, 2026) 
CVE-2026-53283 
CVE-2026-52969 
CVE-2026-53328 
CVE-2026-53350 
CVE-2026-53175 
CVE-2026-11783 
CVE-2026-53230 
CVE-2026-53447 
CVE-2026-53645 
CVE-2026-53279 
CVE-2026-53536 
CVE-2026-53125 
Amazon expands its print-on-demand features to AI-generated designs created using Alexa for Shopping for products like T-shirts, water bottles, and ho 
Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint 
Microsoft has shut down 70+ of its own repositories on GitHub after hackers pushed malware that would steal credentials from users of AI coding agents 
A look at Ireland's Bring Your Own Power policy, which requires new data centers to have their own power plants on site or contracts for energy p 
A look at Ireland's Bring Your Own Power policy, which requires new data centers to have their own power plants on site or sources of energy prod 
UNC3753 Escalates: From Vishing Calls to Physical Office Intrusions at US Legal and Financial Firms 
Meta AI Recovery Tool Flaw Exposed 20,000+ Instagram Accounts 
Authenticated RCE via Argument Injection in Gogs (FIXED as of June 7, 2026) 
CVE-2026-11580 
CVE-2026-11616 
CVE-2026-52812 
Security Affairs newsletter Round 580 by Pierluigi Paganini INTERNATIONAL EDITION 
Report: Anthropic Deploys Engineers to Support NSA Use of Mythos 
The Apple Watch needs a better Siri more than the iPhone right now 
AI-Powered Penetration Testing with Metasploit 
Did Meta s own AI help hack into Instagram users accounts? Explained - The Hindu 
5 ways Android Auto beats your car's own infotainment system - hands down 
Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away 
How Google could turn Siri into the AI health coach my Apple Watch needs 
Fake Context Alignment: The Attack That Made Gemini Obey Strangers Through Your Notifications 
AI-Powered Worm Leverages Stolen Compute to Target Linux, Windows, and IoT Devices 
VECT 2.0 Ransomware Breaks Files Beyond Its Own Recovery 
Reporting from Vegas: Networking, AI, and good boys 
Meta’s own AI chatbot to blame for Instagram accounts being stolen in seconds 
Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories 
How the Swiss Cheese model can help you choose the right MDR provider 
Inside the race to adapt to an AI-powered security world 
Robinhood plans to route some 2026 soccer World Cup bets to Rothera, shifting away from Kalshi as it seeks to diversify its prediction markets provide 
Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting 
CVE-2026-50567 
CVE-2026-50281 
CVE-2026-10834 
CVE-2026-10855 
I tested Microsoft Copilot Health with my real medical records - here's my verdict 
Red Hat hit by npm supply chain attack - here's how to stay safe 
Russia’s FSB Says Foreign Spies Infected Officials’ Phones With Malware 
How hackers used Meta s own AI to break into Instagram accounts - The Indian Express 
CVE-2026-50148 
CVE-2026-50132 
CVE-2026-10780 
Instagram Account Hijacks Expose the Security Risks of AI-Powered Support 
DOD wants to integrate cyber in all operations, and integrate security into AI 
Meta's Own AI Helped Hackers Steal Instagram Accounts Before Emergency Patch - NDTV Profit 
RoboChem Flex: democratisation of the autonomous synthesis robot 
Hackers trick Meta s own AI into revealing passwords of popular Instagram accounts - Yahoo Finance UK 
Hackers trick Meta s own AI into revealing passwords of popular Instagram accounts - The Independent 
AI will significantly disrupt IT consultancies as AI labs build their own advisory arms and execs expect more outcome-based pricing over hourly billin 
How I built my own DIY cyberdeck straight out of 80s sci-fi - and all the cool things it can do 
Meta s own AI was exploited to hijack Instagram accounts - The Verge 
CVE-2026-10660 
CVE-2026-49956 
CVE-2026-10652 
CVE-2026-10654 
CVE-2026-50010 
CVE-2026-49973 
CVE-2026-10646 
CVE-2026-49991 
Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight 
Palo Alto Networks says Mythos found 24+ critical bugs using $1M+ in tokens; Anthropic subsidizes Mythos but some companies plan to boost their Mythos 
Chrome stops hackers from stealing your browser cookies now - how its new security feature works 
Chrome now protects you from hackers who steal browser cookies - how it works 
Ransomware Operators Keep Business Hours. The Data Proves It 
Palo Alto Networks says Mythos found 24+ critical bugs, burning $1M+ of tokens, subsidized by Anthropic; some companies say they plan to boost Mythos  
CVE-2026-0826: How an Old Bug Can Feed AI-Powered Impersonation 
Why I built my own DIY cyberdeck straight out of 80s sci-fi - and how you can too 
CIFSwitch, a Linux Root Bug Hidden in Plain Sight for 19 Years 
Containers on fire: from container escapes to supply chain attacks 
I've been leaving FaceTime voicemails, and the hidden iOS feature surprised my own family 
CVE-2026-49822 
CVE-2026-49755 
CVE-2026-49824 
AI Powered Nmap using ShellGPT 
'The Arrival' at 30: Charlie Sheen s criminally underrated alien invasion thriller feels much scarier today 
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 99 
This hidden FaceTime feature is incredibly useful - and surprised my own family 
CVE-2026-49482 
Meet GREYVIBE, the Russia-Linked Hacking Group Using AI to Target Ukraine and Still Making Rookie Mistakes 
Federal audit reveals NIST’s NVD is plagued by poor planning and duplication 
DIL Observatory: when the World Escalates, the Underground Responds 
Red dwarf stars are cosmic killers that eat their own planets 
AI-Generated npm Malware Leaks Its Own GitHub Token 
What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant 
CVE-2026-10096 
Less panic patching, more precision 
CVE-2026-35616: FortiClient EMS Flaw Actively Exploited in Malware Attacks 
AI Agent Conducted a Cyberattack on Its Own It Took Less Than One Hour 
Zapier fixes bug chain that researchers say risked widespread account takeover 
Authenticated RCE via Argument Injection in Gogs (NOT FIXED) 
AI-Generated npm Malware Leaks Hacker s Private GitHub Token 
Sources: ByteDance is developing its own CPUs to support its growing AI infrastructure needs, as chip price hikes and supply shortages constrain expan 
19.6 Billion Files Are Sitting Open on the Internet. No Password Required 
Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years 
Sources: ByteDance is developing its own CPUs to support growing AI infrastructure needs, as chip price hikes and supply shortages constrain expansion 
Kirkland & Ellis, the world's highest-grossing law firm, is setting aside $500M to build its own AI platform rather than rely on tools availa 
Tucker Carlson, hacked on his own podcast, blames mental patients and asks for biometrics - Boing Boing 
CVE-2026-9796 
CVE-2026-10023 
The LA Metro Attack Wasn’t Hacktivism. It Was a State Operation With a Costume On. 
Own a Hisense TV? I'd change these 12 settings to noticeably improve the picture quality 
How cybersecurity firms took down Glassworm botnet in one shot 
Introducing EvidenceForge: Synthetic security logs that don t look (as) fake 
Dutch Government just said no to an American firm buying the keys to their digital State 
CVE-2026-49099 
CVE-2026-9756 
CVE-2026-49098 
The Hidden Ransomware Economy Running on Exposed Databases 
I built my own Wi-Fi router with a Raspberry Pi for Starlink and solar control - here's how 
Could a cosmic uncertainty principle help explain dark matter? 
How I easily built my own Wi-Fi router with a Raspberry Pi - for Starlink and solar control 
EU Regulators Prepare Landmark Fine Against Google Under Digital Markets Act 
Handelsblatt: the EU plans to fine Google a high triple-digit million euro amount as part of a 2025 probe over concerns it favors its own services in  
CVE-2026-48943 
CVE-2026-9595 
Report: the EU plans to fine Google a high triple-digit million euro amount as part of a 2025 probe over concerns it favors its own services in search 
Zero-Click WhatsApp Account Takeover Hits iPhone Users Running iOS 16. No Linked Devices, No Warning 
I saw the future of Android Auto, and now Google has me dreading my own car 
10 Free Dating Sites With Unlimited Messaging Without Payment 
dotenv as a Node.js Environment Loading Control Point 
CVE-2026-9516 
Why pure extortion is replacing traditional ransomware 
CVE-2026-9358 
Metasploit Wrap Up 05 22 2026 
Lawmakers Demand Answers as CISA Tries to Contain Data Leak 
CVE-2026-48745 
CVE-2026-48595 
CVE-2026-48788 
CVE-2026-48783 
[Heads Up] GitHub Breach Shows Developer Tools Are Social Engineering Targets 
Lawmakers from both parties say CISA cuts have gone too far 
Google showed me the future of Android Auto - and now I dread my own car 
Why Are Teens "Rebelling" By Hacking Their Own Computers? The Surprising Trend - Futura, le m dia qui explore le monde 
Robinhood Glitch Allowed Attackers to Send Phishing Emails to Customers 
Windows Privilege Escalation: Bypass UAC 
Attackers are bypassing MFA on SonicWall VPNs because something was wrong with previous fix 
6 pet deals you don't want to miss this Memorial Day weekend, including robot litter boxes 
Q1 2026 Threat Landscape Report: Zero-clicks, geopolitical tensions, and some wins for law enforcement 
The readiness paradox: Why a false sense of cyber confidence is becoming a liability 
CVE-2026-9188 
CVE-2026-9187 
CVE-2026-9224 
CVE-2026-9199 
CVE-2026-9230 
Meet Rampart and Clarity, Microsoft s new red team combo AI agents 
A Detailed Guide on Nmap Firewall Scan 
Carding site B1ack s Stash dumps 4.6 Million stolen cards for free 
Operationalizing CTEM Faster: Build Surface Command Dashboards in Minutes 
DirtyDecrypt: PoC Released for yet another Linux flaw 
Mini Shai-Hulud returns, compromising hundreds of npm packages 
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat 
Shai-Hulud worm copycats emerge after source code leak 
NetExec for OSCP: AD Pentesting 
CVE-2026-8995 
CVE-2026-47385 
CVE-2026-47407 
CVE-2026-47657 
CVE-2026-47405 
CVE-2026-47416 
CVE-2026-47696 
AI might cut false positives, but it won t stop the slop 
Cloudflare tests Mythos against 50+ repositories, highlights its ability to chain bugs into a single exploit, and details a vulnerability discovery ha 
Internal chats: in March, xAI offered employees $420 in exchange for completed tax filings as training data for Grok, but the bonuses haven't bee 
This metal detector for $60 off on Amazon is a smart buy - here's why I recommend it 
CVE-2026-47209 
CVE-2026-47081 
CVE-2026-47203 
CVE-2026-47074 
CVE-2026-8829 
CVE-2026-47102 
CVE-2026-47181 
CVE-2026-8796 
CVE-2026-47101 
CVE-2026-47272 
Developers say Chinese AI labs lead US rivals in video generation, as ByteDance and Kuaishou train models on vast short-form video libraries from thei 
Mythos, the AI model that learned Hacking on its own - Escudo Digital 
Colorado governor commutes prison sentence for election denier Tina Peters 
Why this metal detector is a smart buy in 2026 - especially at $60 off on Amazon 
Gunra Ransomware Expands RaaS After Conti Locker Shift 
What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface 
CVE-2026-46625 
CVE-2026-46716 
CVE-2026-46715 
CVE-2026-46590 
CVE-2026-46671 
Fired hacker twins forget to end Teams recording, capture own crimes - Ars Technica 
Cerebras co-founders CEO Andrew Feldman and CTO Sean Lie own stakes worth $3.2B and $1.7B, respectively, representing about 5.5% and 3% of the company 
NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior Signals 
The time of much patching is coming 
Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities 
Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defense 
CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED) 
Major tech manufacturer Foxconn confirms cyberattack hit North American factories 
Kimsuky targets organizations with PebbleDash-based tools 
CVE-2026-46516 
Researchers say AI just broke every benchmark for autonomous cyber capability 
Closed briefing sets stage for House hearing on Anthropic s Mythos and cyber risks 
Remember 'Choose Your Own Adventure' books? Now there's a gorgeous graphic novel version heading to 'Space and Beyond' (exclusive) 
DOJ releases legal rationale for nationwide voter data collection 
Weaponized AI: The new frontier of fraud and identity spoofing 
When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise 
Quest KACE SMA flaw CVE-2025-32975: when one unpatched tool opens the door to 60 organizations 
Hackers tipped off Dutch telco Odido about its own data breach - Techzine Global 
CVE-2026-46408 
CVE-2026-46110 
CVE-2026-45707 
CVE-2026-46340 
CVE-2026-45849 
CVE-2026-46115 
CVE-2026-46147 
CVE-2026-45812 
CVE-2026-46152 
CVE-2026-46114 
CVE-2026-46210 
CVE-2026-45687 
CVE-2026-46415 
Mini Shai-Hulud malware compromises hundreds of open-source packages in sprawling supply-chain attack 
Major world economies spell out key elements of AI ingredients list  
Google announces Gemini Intelligence, bundling existing and new Gemini features, including task automation across apps and vibe-coding own Android wid 
Sources: Google is in talks with SpaceX and other companies for a rocket launch deal, as Google expands its own efforts to put orbital data centers in 
Artificial Intelligence in Cybersecurity, Part 14: Turning OSquery into an AI-Powered Forensics Engine 
The world’s most “Dangerous” AI, Anthropic s Mythos, found only one flaw in curl 
Instructure claims hackers returned stolen Canvas data after an extortion standoff 
State-sponsored actors, better known as the friends you don t want 
Android banking Trojan TrickMo evolves using TON network for C2 
State of ransomware in 2026 
CVE-2026-45549 
CVE-2026-45446 
Pressure mounts on Canvas as data leak extortion deadline looms 
Cell Phone Privacy: How Law Enforcement and Hackers Use Your Cell Phone to Invade Your Privacy 
How to teach the same skill to different robots 
The missing cybersecurity leader in small business 
CVE-2026-45296 
CVE-2026-45259 
CVE-2026-45282 
CVE-2026-45349 
CVE-2026-45279 
CVE-2026-8206 
The Different Types of Payment Fraud and How to Prevent Them 
A Complete History of Cybersecurity: From Early Viruses to AI-Powered Threats 
Zara Data Breach: 197,000 Customers Exposed in Third-Party Security Incident 
CVE-2025-68670: discovering an RCE vulnerability in xrdp 
AI, Cyberwarfare, and Autonomous Weapons: Inside America s New Military Strategy 
Canvas Breach Disrupts Schools & Colleges Nationwide 
The Ransomware that copies Conti 
CVE-2026-45108 
CVE-2026-45134 
Rapid7 and OpenAI: Helping Defenders Move at Machine Speed 
While Anthropic will use the Colossus 1 data center, which has a really bad environmental record, xAI retains the larger Colossus 2 for its own AI tra 
Python for Hackers: Building a Custom Telegram OSINT Toolkit for Automated Intelligence Gathering 
Why Security in 2026 Requires Continuous Threat and Exposure Management (CTEM) at Scale 
New understanding of insect flight points way to stable flapping-wing robots 
Arm expects the AGI CPU, its own AI chip for data centers, to drive $2B in sales in FY2027 and FY2028, doubling its March 2026 sales guidance for the  
CVE-2026-44832 
CVE-2026-44707 
CVE-2026-44652 
CVE-2026-44730 
A DOD contractor s API flaw exposed military course data and service member records 
Recorded Future Named a Leader in the 2026 Gartner Magic Quadrant for Cyberthreat Intelligence Technologies. And there s more. 
OceanLotus suspected of using PyPI to deliver ZiChatBot malware 
Army asks missile makers to hack their own weapons - MSN 
Iran-Linked Hackers Target Oman Ministries in Webshell and Data Theft Campaign 
Army Asks Missile Makers to Hack Their Own Weapons - WSJ 
CVE-2026-44490 
CVE-2026-44426 
CVE-2026-44429 
CVE-2026-44454 
CVE-2026-44587 
CVE-2026-44436 
CVE-2026-44494 
Signals Intelligence: Scanning for Cell Towers in Your Vicinity 
Hacking Embodied AI 
Active Directory Exploitation with Metasploit 
CVE-2026-44322 
CVE-2026-44358 
CVE-2026-44166 
CVE-2026-44292 
CVE-2026-44244 
CVE-2026-44224 
Why there is a 60%+ chance of AI systems autonomously building their own successors by the end of 2028, and a look at the consequences of fully automa 
A college student is suing a dating app that allegedly used her TikTok videos to target men in her dormitory 
Offensive Security: Speeding up Active Directory Pentests with ADScan and ADPulse 
Evading Antivirus: Bypassing Windows Defender with Tenebris-Gate 
CVE-2026-44007 
CVE-2026-43867 
CVE-2026-43880 
CVE-2026-43977 
CVE-2026-43879 
CVE-2026-43875 
CVE-2026-7819 
CVE-2026-43865 
New this month, this Lego Star Wars Yoda bust would terrify Darth Vader and I have to have it 
Why I own 4 different pairs of headphones, and how I effectively use each one 
New Deep#Door RAT uses stealth and persistence to target Windows 
Metasploit Wrap-Up 05 01 2026 
A Detailed Guide on Local Port Forwarding 
Active Directory Lab Setup for Penetration Testing Using PowerShell 
Blue Teaming Active Directory: EVENmonitor 
Impacket for Pentester: Net 
115 off for Star Wars Day, I think this Lego Star Wars UCS set is the most mind-blowing Lego starship you'll ever own 
Privilege Escalation: Getting Started with the Pack2TheRoot (CVE-2026-41651) Vulnerability to Escalate Privileges 
Vulnerability remediation: Match CVEs to asset owners in seconds with Tenable Hexa AI 
Carding service Jerry s Store leak exposes 345,000 stolen payment cards 
New Android Spyware Platform Enables Rebranding and Resale 
China Has its Sights Set on Scammers, Just Not Those Targeting Americans 
CVE-2026-43326 
CVE-2026-43136 
CVE-2026-43420 
CVE-2026-43251 
CVE-2026-43073 
CVE-2026-42998 
CVE-2026-43140 
CVE-2026-43434 
CVE-2026-43039 
CVE-2026-43483 
CVE-2026-43346 
CVE-2026-43433 
CVE-2026-43314 
Former incident responders sentenced to 4 years in prison for committing ransomware attacks 
Copy Fail: New Linux bug enables Root via page cache corruption 
Risk Scenarios for the US s Strategic Pivot 
Netflix rolls out a vertical video feed in its own Clips tab in Australia, Canada, India, Malaysia, Pakistan, the Philippines, South Africa, the UK, a 
Artificial Intelligence in Cybersecurity, Part 12: OWASP APTS and the Governance of Autonomous Penetration Testing 
Spying on Its Own Ally: Chinese Hackers Accessed Secret Emails at the Cuban Embassy in the US - International Business Times UK 
Meta accused of violating DSA by failing to safeguard minors 
Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution 
Adaptive Security Leadership in an Expanding Threat Surface 
Digital advertising is booming for Google and Meta, helped by AI tools used for language translation, real-time changes to ad copy, and easier ad targ 
CVE-2026-42843 
CVE-2026-42845 
Five Things we Took Away from Gartner SRM Sydney 2026 
Hackers Abuse Robinhood Signup Process to Deliver Phishing Emails 
Congress, industry ponder government posture for protecting data centers 
Sources: PayPal is separating Venmo into its own standalone unit and is looking to recruit a digital banking executive to run the new Venmo segment (H 
Internet censorship index reveals Russia s lead and widespread content blocking 
Social Engineering: Building Your Own BadUSB 
Mastering agentic AI security through exposure management 
Poll: 31% of US adults expect driverless cars to be common within five years, up from 19% in 2018, and 19% say they would own or lease one, the same a 
Artificial Intelligence in Cybersecurity, Part 11: Targeting LLM Supply Chains with Router-in-the-Middle Attacks 
CVE-2026-42592 
CVE-2026-7422 
CVE-2026-42602 
CVE-2026-42597 
CVE-2026-42591 
Federal CIO cautious on Anthropic s Mythos despite planned rollout 
The Facebook ID problem breaking your DLP alerts 
Five defender priorities from the Talos Year in Review 
Lazarus Doesn't Need AGI 
Off-Grid Communications, Part 6: Internet-over-LoRa with deadmesh 
New Android spyware Morpheus linked to Italian surveillance firm 
MDR Selection is a Partnership Decision 
CVE-2026-7311 
CVE-2026-42556 
As the NVD scales back CVE enrichment, here s what Tenable customers need to know 
LINKEDIN BROWSERGATE 
CVE-2026-42493 
CVE-2026-7163 
CVE-2026-7252 
CVE-2026-7161 
Own a Hisense TV? I'd change these expert settings to noticeably improve the picture quality 
CVE-2026-42363 
CVE-2026-42278 
CVE-2026-42369 
Europe's dependence on US companies in tech and finance is in no small part its own fault after overregulation left European businesses too weak  
CVE-2026-7047 
CVE-2026-42176 
From Overwhelmed to Autonomous: Rethinking Threat Intelligence in 2026 
TDL 020 | Why DNS Is Your First Line of Cyber Defense | Chris Buijs 
Signal phishing campaign targets Germany s Bundestag President Julia Kl ckner 
It pays to be a forever student 
iOS Flaw Let Deleted Notifications Linger, Apple Issues Fix 
Trailmark turns code into graphs 
AI is Changing Vulnerability Discovery and your Software Supply Chain Strategy has to Change with it 
Today, trust is the superpower that makes innovation possible 
What is Bring Your Own Encryption (BYOE)? 
SpaceX's S-1 excerpts list "manufacturing our own GPUs" among the "substantial capital expenditures" it is undertaking, with  
Evolution of Chinese-Language Guarantee Telegram Marketplaces 
Thales named a 2026 Google Partner of the Year Infrastructure Modernization: Sovereign Cloud Category 
CVE-2026-42074 
CVE-2026-42086 
Tropic Trooper Pivots to AdaptixC2 and Custom Beacon Listener 
House Republicans roll out national privacy bill 
Satellite Hacking: Listening to Unencrypted GEO Satellite Traffic 
Mirai Botnet exploits CVE-2025-29635 to target legacy D-Link routers 
EDR & XDR for Cyberwarriors: How Endpoints Are Monitored, Attacked, and Defended 
IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist 
CVE-2026-41687 
CVE-2026-41890 
Former DigitalMint ransomware negotiator pleads guilty to extortion scheme 
Phishing and MFA exploitation: Targeting the keys to the kingdom 
From Bulk Export to AI-ready Security Workflows: Introducing Rapid7 s Open-Source MCP Server and Agent Skill 
The US NSA is using Anthropic’s Claude Mythos despite supply chain risk 
Bad Apples: Weaponizing native macOS primitives for movement and execution 
Mythos can find the vulnerability. It can’t tell you what to do about it. 
GitHub Issue Alerts Exploited in OAuth Phishing Scam Targeting Developers 
Watch the Lyrid meteor shower 2026 online today with these free livestreams 
Manhattan DA Bragg Pushes Meta to Put a Stop to Immigration Scams 
Tim Cook reshaped Apple in his own image and exits as CEO on his own terms, seemingly picking the right successor in John Ternus, much like Jobs did w 
Own a Sony TV? 3 quick settings I'd change to meaningfully improve the picture quality 
CVE-2026-41574 
CVE-2026-41660 
Q&A with Canva CEO Melanie Perkins on the company's growth in enterprise, competing with AI labs, token pricing, investing in its own models, 
SDR (Signals Intelligence) for Hackers: Building Your Own Fake GPS Satellite 
Project Glasswing and the Next Challenge for Defenders: Turning Faster Discovery into Faster Action 
Watch the Lyrid meteor shower 2026 online this week with these free livestreams 
Watch the Lyrid meteor shower 2026 online with these free livestreams 
Simplifying CMMC Compliance and Breaking Down Its Controls 
Artificial Intelligence (AI) in Cybersecurity: Targeting LLM Supply Chains with Router-in-the-Middle Attacks 
AI system learns to keep warehouse robot traffic running smoothly 
FakeWallet crypto stealer spreading through iOS apps in the App Store 
AI Model Claude Opus turns bugs into exploits for just $2,283 
CVE-2026-41233 
CVE-2026-41208 
CVE-2026-41246 
DraftKings hacker sentenced to prison, ordered to pay $1.4 Million 
The Cyberwarrior Handbook, Part 2 
Satellite Hacking: Building the Ground Station for Satellite Tracking and Radio Communication 
We beat Google s zero-knowledge proof of quantum cryptanalysis 
Inside ZionSiphon: politically driven malware aims at Israeli water systems 
Mozilla launches Thunderbolt, an open-source AI client for users and businesses who want to run their own self-hosted AI infrastructure, available on  
CVE-2026-41174 
CVE-2026-6506 
CVE-2026-41141 
Article 12 and the Logging Mandate: What the EU AI Act Actually Requires – FireTail Blog 
The Shadow AI Trap: Why Your AI Inventory is Your Biggest EU AI Act Compliance Risk – FireTail Blog 
Beating the Mythos clock: Using Tenable Hexa AI custom agents for automated patching 
From Bazooka to Fake Nikes 
Point-in-time GRC is obsolete. What s replacing it? It isn t AI alone 
OpenAI's Codex Desktop can run your computer now - and has its own browser 
Linux Basics for Hackers, Part 10: Loadable Kernel Modules (LKM) 
Shadow AI and the evolution of Shadow IT Security – What to do when your code moves faster than your security 
CVE-2026-40976 
Smashing Security podcast #463: This AI company leaked its own code. It’s also built something terrifying 
Myth and Mythos: A Decades Old Problem in the Spotlight – FireTail Blog 
NIST narrows scope of CVE analysis to keep up with rising tide of vulnerabilities 
A Clearer Path from Prioritized Exposures to Remediation Progress 
We re only seeing the tip of the chip-smuggling iceberg 
OpenAI Launches GPT-5.4-Cyber with Expanded Access for Security Teams 
Google launches Skills, repeatable AI prompts that Chrome users can run with a keyboard shortcut; users can set up their own Skills or choose from 50+ 
Claude Mythos: Prepare for your board s cybersecurity questions about the latest AI model from Anthropic 
A New Way to Buy Recorded Future: Solutions and Packages Built for the 2026 Threat Landscape 
Google launches Skills, repeatable AI prompts users can run in Chrome with a keyboard shortcut; users can set up their own Skills or choose from 50+ p 
What I ve learned from 25 years of automated science, and what the future holds: an interview with Ross King 
Taming Network Policy Sprawl with AI 
Claude Mythos Changed Everything. Your APIs Are the First Target. 
Digital Forensics: Analyzing Crashed ArduPilot Drones 
Fake Claude AI installer abuses DLL sideloading to deploy PlugX 
CVE-2026-40682 
CVE-2026-40566 
Amazon unveils the Amazon Leo Aviation Antenna, saying it can deliver up to 1 Gbps download and 400 Mbps upload speeds "simultaneously" for  
Best of the Worst: Five Attacks That Already Knew Your Name 
Here s how cyber heavyweights in the US and UK are dealing with Claude Mythos 
Signals Intelligence: How the Iranian Regime is using Starlink’s Signature to Hunt Down People Using It 
When AI Finds a Way Out: The Alibaba Incident and Why Zero Trust Matters More Than Ever 
Amazon Leo unveils the Aviation Antenna, saying it can deliver up to 1 Gbps download and 400 Mbps upload speeds for in-flight Wi-Fi (Michael Kan PCMag 
Digital Forensics: Extracting Secrets After a Cold Boot Attack 
GitHub and Jira Alerts Hijacked for Trusted-SaaS Phishing 
iPhone forensics expose Signal messages after app removal in U.S. case 
7 Privilege Management Mistakes That Put Business Data at Risk 
CVE-2026-6228 
CVE-2026-40486 
Hackers claim control over Venice San Marco anti-flood pumps 
The Linux Kernel Organization now lets developers submit AI-generated code, as long as it complies with the guidelines, licensing, and attribution req 
GlassWorm evolves with Zig dropper to infect multiple developer tools 
Breaking the Patch Sound Barrier: Your Vulnerability Remediation Will Not Keep Up With AI Exploit  
Analysis: Trump's World Liberty Financial used 5B of its WLFI tokens to borrow $75M from a platform its adviser co-founded; WLFI falls to an all- 
TDL 019 | The Psychology Behind a Cyber Breach and the Leaders Who Survive It | Nim Nadarajah 
NASA took this camera gear to space aboard Artemis 2, and you can own it, too! 
EngageLab SDK flaw opens door to private data on 50M Android devices 
DesckVB RAT Uses Fileless .NET Loader to Evade Detection 
CVE-2026-40349 
CVE-2026-40291 
CVE-2026-40295 
CVE-2026-40304 
Sources: Anthropic is weighing the possibility of designing its own chips, but it has yet to commit to a design or put together a dedicated team for t 
What to Know About CyberAv3ngers: The IRGC-Linked Group Targeting Critical Infrastructure 
Why is the timeline to quantum-proof everything constantly shrinking? 
The threat hunter s gambit 
Third-Party Risk Is an Intelligence Operation. It's Time We Treated It Like One. 
From the field to the report and back again: How incident responders can use the Year in Review 
The long road to your crypto: ClipBanker and its marathon infection chain 
CVE-2026-40071 
Wi-Fi Hacking: Building Your Own Pineapple, Part 3 
'The Expanse: Osiris Reborn' has lots of 'Mass Effect' DNA, but its developers are teasing a far more grounded sci-fi RPG 
Alibaba and China Telecom launch a data center in southern China that is powered by 10,000 of Alibaba's Zhenwu chips designed for AI training and 
Pineapple Attacks: Building Your Own Pineapple, Part 3 
FortiGate CVE-2025-59718 Exploitation: Incident Response Findings 
Understanding and Anticipating Venezuelan Government Actions 
AI Security Risks: How Enterprises Manage LLM, Shadow AI and Agentic Threats – FireTail Blog 
The Era of Agentic Security is Here: Key Findings from the 1H 2026 State of AI and API Security Report 
New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations 
Iranian hackers used Stryker's own security tools against it and U.S. agencies say it's just the beginning - siliconcanals.com 
Cybercriminals Use Fake Zoom, Teams Calls to Deliver Malware 
Iranian hackers used Stryker's own security tools against it and U.S. agencies say it's just the beginning - Silicon Canals 
As breakout time accelerates, prevention-first cybersecurity takes center stage 
CVE-2026-5821 
A group of US agencies including the FBI and the NSA warns that Iran-linked hackers have targeted industrial control devices used in US critical infra 
Iran-Linked Hackers Are Sabotaging US Energy and Water Infrastructure 
GrafanaGhost bypasses Grafana’s AI defenses without leaving a trace 
Open Source Intelligence (OSINT): Extracting Information from Threads 
The Trojan horse of cybercrime: Weaponizing SaaS notification pipelines 
'Maul Shadow Lord' is the darkest and most focused animated 'Star Wars' show yet 
'Star Wars: Maul Shadow Lord' is Lucasfilm's darkest and most focused animated show yet 
CVE-2026-39903 
CVE-2026-39961 
Best of the Worst: The Week Your Security Tools Became the Disguise 
'Star Wars: Maul Shadow Lord' is Lucasfilm's darkest and most focused animated show yet (review) 
Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools 
Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab 
CVE-2026-39315 
CVE-2026-37982 
CVE-2026-36608 
CVE-2026-39381 
Drift details how suspected North Korean attackers stole $270M posing as a quant trading firm in a 6+ month operation with in-person meetings and a $1 
The developer credential economy: Why exposure data is the new front line in the supply chain war 
Do not get high(jacked) off your own supply (chain) 
Blocking children from social media is a badly executed good idea 
Wyden warns Social Security chief: Trump s voter database is blatant voter suppression  
Your KnowBe4 Fresh Content Updates from March 2026 
You Don t Have a Security Problem, You Have a Visibility Problem 
Simplifying MBA obfuscation with CoBRA 
Brick vs. Bloom Card: I tested both for my screen addiction, and the winner depends on you 
CVE-2026-5465 
CVE-2026-35595 
When Your Own Eyes Turn Against You: How Compromised Security Cameras and IoT OT Devices Become Tools for Your Attackers 
Latin America and the Caribbean Cybercrime Landscape 
New Whitepaper: Stealthy BPFDoor Variants are a Needle That Looks Like Hay 
Qilin EDR killer infection chain 
An overview of ransomware threats in Japan in 2025 and early detection insights from Qilin cases 
A whistleblower alleges Delve pitched a modified copy of open-source no-code tool SimStudio as its own, a practice that could violate the software&apo 
CVE-2026-35412 
CVE-2026-35443 
CVE-2026-35448 
Anthropic Claude Code Leak 
GrayBravo s CastleLoader Activity Clusters Target Multiple Industries 
What s Next for Enterprise Threat Intelligence in 2026 
Cyber on the Geopolitical, Battlefield: Beyond the, Big Four  
Autonomous Threat Operations in action: Real results from Recorded Future s own SOC team Recorded Future 
Apple Is Breaking Its Own Rules To Protect iPhone Users From A Dangerous iOS 18 Hack - bgr.com 
Sources: Paradigm, a major investor in Kalshi, is building its own prediction markets trading terminal that will cater to professional traders and mar 
NASA's Artemis 2 moon launch may be visible from Florida and southern Georgia today. Here's when to look 
Google links Axios npm supply chain attack to North Korea-linked APT UNC1069 
Mutation testing for the agentic era 
A laughing RAT: CrystalX combines spyware, stealer, and prankware features 
Apple forced to break its own rules after dangerous DarkSword hack targets iPhone users - India Today 
Source: Google plans to release a screenless Fitbit band later this year; it will include basic features and require a paid subscription for more func 
CVE-2026-35179 
CVE-2026-35173 
Attackers hijack Axios npm account to spread RAT malware 
Nearly half a Million mobile customers of Lloyds Banking Group affected by security incident 
Digital Forensics: Quick Analysis with KAPE 
Open Source Intelligence (OSINT): AI-Powered Image Geo-location 
Initial Access Brokers have Shifted to High-Value Targets and Premium Pricing 
How we made Trail of Bits AI-native (so far) 
CVE-2026-34993 
CVE-2026-5229 
CVE-2026-5269 
Bluetooth Hacking and Security: The WhisperPair Exploit and Bluehood Surveillance 
CVE-2026-34726 
CVE-2026-5199 
CVE-2026-34744 
CVE-2026-5175 
CVE-2026-34532 
CVE-2026-5144 
Bluesky's CEO talks about Attie, a new agentic social app built on Bluesky's AT Protocol that uses Claude and lets users build custom feeds  
Iran-linked group Handala hacked FBI Director Kash Patel s personal email account 
Iranian hackers, Handala, claim to compromise FBI Director Kash Patel s personal data 
How AI Will Reshape the MSP Market 
Sources: SpaceX's IPO plans include investor visits to its sites, unusual lockup periods, and preferential treatment for investors in Musk's 
Sources: SpaceX's IPO plans include visits to its sites, unusual lockups for early investors, and preferential treatment for investors in Musk&ap 
CVE-2026-34384 
CVE-2026-4977 
CVE-2026-34374 
CVE-2026-34427 
CVE-2026-4984 
CVE-2026-34460 
CVE-2026-5065 
CVE-2026-34390 
CVE-2026-34406 
ODNI tackles AI, threat hunting, app cybersecurity in year-one tech review 
Sources: Apple granted out-of-cycle bonuses worth several hundred thousand dollars to iPhone hardware designers, as OpenAI and others poach its engine 
I can't stop talking about the Ninja Creami Swirl - and it's on sale at Amazon right now 
Anduril Wants to Own the Future of War Tech. Mishaps, Delays, and Challenges Abound 
Anduril Wants to Own the Future of War Tech. Mishaps, Delays and Challenges Abound. 
Drone Hacking: Dronesploit – Metasploit for Drones 
Aim for the stars for under $15 with this Estes 2441 Mini Arcas Model Rocket Kit at Walmart, now 17% cheaper in the spring sales 
Coruna: the framework used in Operation Triangulation 
CVE-2026-34180 
CVE-2026-4925 
CVE-2026-34227 
Alleged RedLine infostealer conspirator extradited to US 
Google moves post-quantum encryption timeline up to 2029 
This gadget lets you use your own Bluetooth headphones on a plane - and it's on sale 
Source: as part of its Google deal, Apple has full access to the Gemini model in its own data centers and can use distillation to produce smaller mode 
Novee Brings Autonomous Red Teaming to LLM Applications, Built From Its Own Vulnerability Research 
Security for AI: A guide to managing the risks of vibe coding and AI in software development 
Q&A with Arm CEO Rene Haas on changing Arm's culture, working with Arm owner SoftBank, developing Arm's AGI CPU data center chip fabrica 
Recent Navia data breach impacts HackerOne employee data 
The Kill Chain Is Obsolete When Your AI Agent Is the Threat 
Q&A with Arm CEO Rene Haas on changing Arm's culture, working with SoftBank, developing its Arm AGI CPU data center chip fabricated by TSMC,  
Iranians Don t Have a Missile Alert System, So Volunteers Built Their Own Warning Map 
ClickFix Campaigns Targeting Windows and macOS 
Large US corporations are not ditching core business software for AI yet, instead seeking better vendor deals and "vibe-coding" smaller apps 
AiStrike Launches Continuous Detection Engineering to Fix Alert Noise at the Source 
Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR 
Arm unveils its own AI chip called the AGI CPU, a departure from its traditional role as a designer of chips for others; Meta and OpenAI will be early 
Spotting issues in DeFi with dimensional analysis 
A history of RoboCup with Manuela Veloso 
Introducing IP Range Scanning: continuous Surface Monitoring for your entire network 
After hack, some ignition interlock users couldn't start their own cars - Ars Technica 
State officials, election experts question California sheriff s seizure of ballots 
Meta hires the founders and team behind Dreamer, which lets users create AI agents; co-founder Hugo Barra is joining Meta Superintelligence Labs (Kurt 
Memo: Meta hires the founders and team behind Dreamer, which lets users create AI agents; co-founder Hugo Barra is joining Meta Superintelligence Labs 
Booz Allen Rolls Out Vellox, a Five-Product AI Cyber Suite Built on Adversary Tradecraft 
CVE-2026-33684 
CVE-2026-33711 
CVE-2026-33706 
CVE-2026-33700 
CVE-2026-33764 
CVE-2026-33665 
CVE-2026-33678 
CVE-2026-33805 
Russia-linked actors target WhatsApp and Signal in phishing campaign 
Elon Musk announces Terafab, an Austin-based project run by Tesla and SpaceX to manufacture robotics, AI, and space data center chips for Tesla, xAI,  
NVIDIA Built Its Own CPU and Vera Is Designed for the Agentic Workload GPUs Can’t Handle Alone 
The US Department of Energy announces a partnership with SoftBank and its affiliate SB Energy to develop a 10 GW data center with its own power supply 
TDL 018 | How To Think, Not What To Think | Mitch Prior 
Microsoft releases MAI-Image-2, ranked third on Arena AI's text-to-image leaderboard behind only models from Google and OpenAI, available in the  
Global law enforcement operation targets AISURU, Kimwolf, JackSkid botnet operators 
54 EDR Killers Use BYOVD to Exploit 35 Signed Vulnerable Drivers and Disable Security 
Microsoft releases MAI-Image-2, ranked #3 on the text-to-image Arena leaderboard behind models from Google and OpenAI, available in the MAI Playground 
Key Aspects of EASA Certification and Compliance 
MiniMax releases M2.7, a proprietary "self-evolving" LLM that the company used to build, monitor, and optimize the model's own reinforc 
CVE-2026-33527 
CVE-2026-33493 
CVE-2026-33503 
CVE-2026-33505 
CVE-2026-33504 
Anton s Security Blog Quarterly Q1 2026 
54 EDR Killers Use BYOVD to Exploit 34 Signed Vulnerable Drivers and Disable Security 
You have to invite them in 
Adobe launches Firefly Custom Models in public beta, letting users train AI image generators on their own assets; the custom models are private by def 
An analysis of a NYT article load finds 422 network requests totaling 49MB, triggering a sprawling programmatic ad auction, an example of "hostil 
Walmart is embedding its own chatbot Sparky in ChatGPT, after conversion rates via OpenAI's Instant Checkout were 3x lower than those requiring c 
Walmart is embedding its own chatbot Sparky in ChatGPT after conversion rates via OpenAI's Instant Checkout were 3x lower than those requiring cl 
CVE-2026-33433 
CVE-2026-33356 
U.S. robotics companies want federal help to keep Chinese robots out of America s networks 
Google’s $32B Wiz Bet: Why Security Consolidation Means You’re Losing Negotiating Power 
LeakNet boosts ransomware with ClickFix lures, stealthy Deno loader 
The SOC Files: Time to “Sapecar”. Unpacking a new Horabot campaign in Mexico 
Robotic surgery firm Intuitive reports data breach after targeted phishing attack 
FAQ on CVE-2026-21514: OLE bypass N-Day in Microsoft Word 
CVE-2026-33246 
CVE-2026-33318 
CVE-2026-33320 
CVE-2026-33354 
CVE-2026-33290 
Anton s Vibe Coding Experience: A Reflection on Risk Decisions 
Mistral announces Mistral Forge to help enterprises build custom models actually trained on their own data, using Mistral open-weight models as a star 
Appeals court temporarily pauses order blocking Perplexity s AI shopping agent on Amazon 
Own a Sony TV? I changed 3 settings to noticeably improve the picture quality 
Digital Forensics: Registry Analysis for Beginners, Part 3 Evidence of Execution 
CVE-2026-33124 
Nvidia wants to own your AI data center from end to end 
Own a Samsung phone? I changed 10 settings to greatly improve its performance 
Poland Suspects Iranian Actors are Behind Attack on Its Nuclear Power Center 
2025 Identity Threat Landscape Report: Inside the Infostealer Economy: Credential Threats in 2025 
'Villains are the heroes of their own movie': We chat to 'Star Trek: Starfleet Academy' showrunners about building an iconic Trek villain 
Advanced Protection Mode in Android 17 prevents apps from misusing Accessibility Services 
The ransomware economy is shifting toward straight-up data extortion 
When insider risk is a wellbeing issue, not just a disciplinary one 
CVE-2026-32915 
CVE-2026-32886 
CVE-2026-32821 
Privacy Protection Checklist 
How relieved are teams with managed machine identities 
Can't wait for Artemis 2 to make history? Get up to 20% off these awesome Lego NASA Artemis rocket sets 
Your Linux PC should never be running slow when this built-in diagnostic tool exists (for free) 
How Breach-Focused Microsegmentation Could Have Contained AWS s AI Agent Outages 
Building Trust in AI SOC Analyst Solutions: A UK and EU CISO Perspective 
CVE-2026-32700 
CVE-2026-32767 
I didn't need this, but I found a free Linux app that makes memes in seconds (no GIMP required) 
How to diagnose your slow-booting Linux PC in seconds - without spending a dime 
Ericsson US Hit by Cyber Attack, Hackers Steal Personal Data of Employees and Customers 
A small cottage industry offering OpenClaw installation services and preconfigured hardware emerges in China as the tool becomes the country's la 
CVE-2026-32608 
CVE-2026-4057 
Agents of Chaos : New Study Shows AI Agents Can Leak Data, Be Easily Manipulated 
Sources: xAI's AI agent project Macrohard has stalled as Tesla ramps up its own AI agent project Digital Optimus; Elon Musk says it is a joint xA 
Sources: xAI's AI agent project Macrohard has stalled as Tesla ramps up its own AI agent project Digital Optimus; Musk says they are a joint xAI- 
Six mistakes in ERC-4337 smart accounts 
If consequences matter, they should apply to vendors, too 
Google Warns of AI Driven Adaptive Malware Rewriting Its Own Code 
How to Disable macOS 26 Tahoe Upgrade Notifications and Nagging 
CVE-2026-32252 
CVE-2026-32245 
Patch Tuesday - March 2026 
Federal judge blocks Perplexity s AI browser from making Amazon purchases 
Critical defect in Java security engine poses serious downstream security risks 
This free Linux app lets you make memes in seconds - no GIMP required 
When Trusted Websites Turn Malicious: WordPress Compromises Advance Global Stealer Operation 
LeakyLooker: Hacking Google Cloud s Data via Dangerous Looker Studio Vulnerabilities 
BeatBanker: A dual mode Android Trojan 
No, it s not unnecessarily burdensome to control your own data 
Cloudflare Pingora Flaws Enable Request Smuggling and Cache Poisoning Attacks 
CVE-2026-32126 
CVE-2026-32132 
CVE-2026-32106 
Meta’s AI Safety Chief Couldn’t Stop Her Own Agent. What Makes You Think You Can Stop Yours? 
NCIS Season 23 Resurrects Its Own Famously Stupid Hacking Trope - looper.com 
Pineapple Attacks: Building Your Own Pineapple, Part 2 
From Firehoses to Flutes – Mastering the Art of Drinking Our Own Champagne 
Nexperia's Chinese subsidiary says it has begun producing its own chips using 12-inch wafers, a further step toward independence from its Dutch p 
Future spacecraft could fix their own damage using 'self-healing' materials 
Anthropic Claude Opus AI model discovers 22 Firefox bugs 
CVE-2026-31740 
CVE-2026-31719 
CVE-2026-31712 
CVE-2026-31502 
CVE-2026-31668 
How AI Assistants are Moving the Security Goalposts 
CVE-2026-30954 
TDL | Defense Before Offense: Leadership, Risk, and the Cost of Bad Decisions | Steven Elliott 
Buy the new Google Pixel 10a and get a free $100 Amazon gift card (or Pixel Buds 2a) 
Congress looks to revive critical cyber program for rural electric utilities 
Vibe Coding Your Own CRM With AI. When It Works, When It Fails, and What Leaders Should Know 
Your KnowBe4 Fresh Content Updates from February 2026 
Hack of the day: Create your own custom QR codes - The Times of India 
Own a Sony TV? Changing these 3 settings will greatly improve its picture quality 
CVE-2026-3655 
CVE-2026-30898 
CVE-2026-30886 
FBI targeted with suspicious activity on its networks 
Patch, track, repeat: The 2025 CVE retrospective 
HHS updates a free risk tool to help hospitals size up their cybersecurity exposure 
The Top 5 Questions: How DSPM Illuminates the Murky World of Multi-Cloud Data Security 
Network Forensics: Capturing Network Traffic with Alligator Clips 
From Code to Runtime: The Critical Role of DAST in Application Security 
February 2026 Product Notes: New Test Catalogue & API Scanning experience 
ClickFix Campaign Exploits Fake LinkedIn VCs to Spread Malware Among Crypto and Web3 Experts 
Smashing Security podcast #457: How a cybersecurity boss framed his own employee 
CVE-2026-30857 
CVE-2026-3601 
New Mexico child safety trial: Mark Zuckerberg downplayed Meta's own research on how the company's apps affect teens; Adam Mosseri made simi 
Auroras on Jupiter's giant moon Ganymede look like Earth's northern lights, NASA spacecraft reveals 
Shadow AI vs Managed AI: What s the Difference? – FireTail Blog 
CVE-2026-29180 
CVE-2026-3568 
CVE-2026-3565 
CVE-2026-30269 
Lessons from 'The Martian': How astronaut poop could help us settle the Red Planet 
Linux PC booting slowly? This handy tool shows why in seconds - here's how 
Claude Code Security and the AI Market Reaction: What Security Leaders should Actually Focus on 
CVE-2026-3488 
Google addresses actively exploited Qualcomm zero-day in fresh batch of 129 Android vulnerabilities 
Ongoing Iran Conflict: What You Need to Know 
The FBI s cyber chief is using Winter SHIELD to accelerate China prep, threat intelligence sharing 
Dust Specter APT Targets Government Officials in Iraq 
Own a business? Save on TurboTax Expert Assist Business right now - here's how 
From fake nudes to fake quotes: AI deepfakes plagued Olympic athletes 
How ‘silent probing’ can make your security playbook a liability 
Can you trust your AI to manage its own security 
CVE-2026-3429 
Is it legal to own, buy, or sell Apollo mission moon rocks and lunar samples? 
Source: Sam Altman told employees the DOD is willing to let OpenAI build its own "safety stack" and won't force OpenAI to comply if its 
The US Air Force's latest X-plane looks like a missile that shoots other missiles 
OpenClaw Insights: A CISO s Guide to Safe Autonomous Agents – FireTail Blog 
CVE-2026-28445 
CVE-2026-28444 
CVE-2026-28408 
Microsoft Copilot DLP Bypass: A Data Trust Wake-Up Call for AI Security 
APT37 Adds New Capabilities for Air-Gapped Networks 
I developed an app that uses drone footage to track plastic litter on beaches 
Recorded Future Expands Coverage of Scams and Financial Fraud with Money Mule Intelligence from CYBERA 
Own a Samsung TV? I changed these 6 settings to give my system a speed boost 
Several UK consultants have left large firms to start AI consultancy startups, as growth in the country's AI consulting sector outpaces the broad 
Smashing Security podcast #456: How to lose friends and DDoS people 
CVE-2026-28354 
CVE-2026-28355 
Source: Google plans to test search changes in Europe, displaying results from competing vertical search services next to its own, seeking to avoid EU 
Regional Airline Sues Two of its Own Pilots Over Allegations They Hacked Computer Systems To Steal Personal Details of Coworkers - PYOK 
Source: Amazon, Google, Meta, Microsoft, xAI, Oracle, and OpenAI will sign White House's initiative to build their own electricity supply for AI  
SOTU: Trump says he told tech companies to build their own plants to power data centers; sources say the White House expects to formalize the effort i 
SOTU: Trump says he told tech companies they must build their own power plants for their data centers; sources: the WH expects to formalize the effort 
Own a Fire TV? Changing these 10 settings made my system run like new again 
CVE-2026-27962 
CVE-2026-27946 
CVE-2026-27945 
CVE-2026-28215 
New Malicious npm Package “ambar-src” Targets Developers with Open Source Malware 
Digital Forensics: How Hackers Defeat Microsoft’s 2026 NTLM Patch 
Meta agrees to acquire up to 6GW of AMD Instinct GPUs in a deal valued at $100B+ that could see Meta own up to 10% of AMD; Meta plans to deploy 1GW in 
Anthropic Says Chinese AI Firms Used 16 Million Claude Queries to Copy Model 
CVE-2026-27812 
CVE-2026-27899 
CVE-2026-27905 
Anthropic accuses Chinese labs of trying to illicitly take Claude s capabilities 
Wormable XMRig campaign leverages BYOVD and timed kill switch for stealth 
Drone Forensics: Analyzing Flights with DJI Logbook 
Anthropic says DeepSeek, MiniMax, and Moonshot violated its ToS by prompting Claude a combined 16M+ times and using distillation to train their own pr 
CVE-2026-1731 fuels ongoing attacks on BeyondTrust remote access products 
How Exposed Endpoints Increase Risk Across LLM Infrastructure 
How OpenAI scrambled for compute as Stargate stalled amid clashes with SoftBank; sources say OpenAI building its own data centers is not its near-term 
How OpenAI scrambled for compute as Stargate stalled amid SoftBank disagreements; sources say OpenAI building its own data centers is not its near-ter 
How OpenAI scrambled for compute as Stargate stalled amid disagreements with SoftBank; sources: building its own data centers is not OpenAI's nea 
Silver Fox APT Deploys DLL Sideloading and BYOVD in Advanced Malware Campaign 
OpenAI scrambled for compute power after the Stargate project stalled; sources: OpenAI still plans to build its own data centers, but not in the near  
A profile of Hong Kong-based Neil Shen, founder of HSG, formerly Sequoia China, and an early investor in Manus, who is using US capital to fund China& 
Own a TCL TV? Changing these 12+ settings made a big difference for mine 
I changed 13 settings on my TV to dramatically improve its performance - here's how 
Anthropic unveils Claude Code Security to detect and fix code bugs 
A profile of Neil Shen of HSG, formerly Sequoia China, which raised $9B from US investors before US restrictions and has funded Manus and other Chines 
NASA's Perseverance rover now has its own 'GPS' on Mars: 'We've given the rover a new ability' 
Please Don’t Feed the Scattered Lapsus ShinyHunters 
Long Range Acoustic Device (LRAD), Part 3: Building Your Own Audio Laser 
CVE-2026-2941 
Anthropic rolls out embedded security scanning for Claude 
TDL 016 | Speed, Risk, and Responsibility in the Age of AI | Rafael Ramirez 
Hack of the day: Speak to anyone in India in their own language - The Times of India 
Hack of the day: Speak to anyone in India in their own language - Times of India 
Tech companies are increasingly building private power plants to fuel off-grid data centers, a move some warn has reliability challenges and hurts cli 
Tech companies are increasingly building private power plants to fuel off-grid data centers, a move some warn faces reliability challenges and climate 
Tech companies are increasingly building private power plants to fuel off-grid data centers, a move experts warn face reliability challenges and clima 
Tech companies are increasingly building private power plants to fuel off-grid US data centers, a move experts warn is a risky bet for the grid and cl 
Tech companies are increasingly building their own private power plants in the US to power off-grid data centers, that some experts warn are a risky b 
How tech companies, including Meta and OpenAI, are building data centers with their own private power plants, a risky bet that will increase carbon em 
CVE-2026-2917 
CVE-2026-27637 
CVE-2026-27636 
State Dept. official says post-quantum transition plans will outlive current leadership 
Using AI to defeat AI 
FBI: Threats from Salt Typhoon are still very much ongoing  
2025 Cloud Threat Hunting and Defense Landscape 
The Caracas operation suggests cyber was part of the plan just not the whole operation 
Cyber on the Geopolitical, Battlefield: Beyond the, Big Four  
CVE-2026-2836 
CVE-2026-27314 
 
The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security 
GrayCharlie Hijacks Law Firm Sites in Suspected Supply-Chain Attack 
VS Code extensions with 125M+ installs expose users to cyberattacks 
Dutch police arrest man for “hacking” after accidentally sending him confidential files 
CVE-2026-27167 
CVE-2026-2673 
CVE-2026-27192 
Meta commits to buy millions of Nvidia Blackwell and Rubin GPUs in a multiyear deal; source: Meta's in-house AI chip strategy has suffered techni 
Meta commits to a multiyear deal to buy Nvidia chips, including Vera Rubin; source: Meta's in-house chip strategy had suffered technical challeng 
CyberheistNews Vol 16 #07 Uncovering the Sophisticated Phishing Campaign Bypassing M365 MFA 
Own a TCL TV? I would change these 16 settings ASAP - here's why 
Why secure-by-design systems are non-negotiable in the AI era 
Network Intelligence: Your Questions, Global Answers 
CVE-2026-27112 
CVE-2026-27117 
CVE-2026-27125 
'I do not have enough self-preservation. Send help': This streamer hacked her own balance to 'feel' racing games - PC Gamer 
ClickFix added nslookup commands to its arsenal for downloading RATs 
ShinyHunters leaked 600K+ Canada Goose customer records, but the firm denies it was breached 
Pineapple Attacks: Building Your Own Pineapple, Part 1 
Microsoft alerts on DNS-based ClickFix variant delivering malware via nslookup 
CVE-2026-26973 
Former NPR host David Greene sues Google for allegedly replicating his voice in NotebookLM without permission; Google says the voice is based on a pai 
CVE-2026-26369 
CVE-2026-2559 
Has 'Star Trek: Starfleet Academy' just unleashed its very own Khan? 
InfoSec: Getting Started with Identity and Access Management (IAM) 
Google warns that the EU risks undermining its own competitiveness drive with the "tech sovereignty package" the bloc is set to present in t 
Google: state-backed hackers exploit Gemini AI for cyber recon and attacks 
Chrome Extensions Infect 500K Users to Hijack VKontakte Accounts 
Own a smart TV? These 13 features can dramatically improve your performance - here's how 
Own a Samsung TV? My 5-second 'cold boot' trick makes any system run like new again 
List of Secure Dark Web Email Providers in 2026 
Top 5 Free Websites to Learn Hacking this 2026 
MSP Strategic Defense: Where Prevention Meets Compliance 
CVE-2026-25253: How Malicious Links Can Steal Authentication Tokens and Compromise OpenClaw AI Systems 
Gartner Names Tenable as the Current Company to Beat for AI-Powered Exposure Assessment in a 2025 Report 
Carding-as-a-Service: The Underground Market of Stolen Cards 
Anthropic donates $20M to Public First, a super PAC pushing for AI guardrails and transparency in opposition to OpenAI-backed PACs, ahead of the US mi 
Google unveils WAXAL, a new open speech dataset for 21 African languages to ease speech technology development; African institutions own the dataset ( 
Reynolds ransomware uses BYOVD to disable security before encryption 
I created the ultimate Wi-Fi password key with the most unsuspecting gadget - how it works 
GOP Congress moves to shape election law in Trump s image 
Spam and phishing in 2025 
GPT-5.3-Codex and Claude Opus 4.6 can handle the full app development lifecycle on their own, a sign of what's coming for most knowledge work wit 
I turned my AirTag into the secret Wi-Fi password key - here's how it works 
CVE-2026-26209 
CVE-2026-2360 
CVE-2026-2336 
LayerZero Labs unveils a new Layer 1 blockchain called Zero, in collaboration with Citadel Securities, DTCC, Google Cloud, and Intercontinental Exchan 
Sources: KPMG negotiated a 14% lower fee for its 2025 audit by threatening to find a new accountant if Grant Thornton didn't pass on its cost sav 
Sources: KPMG negotiated lower fees from auditor Grant Thornton by arguing that AI will make it cheaper to do the work, and threatened to find a new a 
ZeroDayRAT spyware grants attackers total access to mobile devices 
Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools 
I created the ultimate Wi-Fi password key with the most unexpected gadget - how it works 
Critics warn America s ‘move fast’ AI strategy could cost it the global market 
Hackers breach SmarterTools network using flaw in its own software - BleepingComputer 
CVE-2026-2305 
CVE-2026-26064 
Oxide Computer, which lets companies build their own cloud, raised $200M led by USIT, taking its total funding to nearly $390M since its 2019 founding 
Vulnerability Found in InsightVM & Nexpose: CVE-2026-1814 (FIXED) 
Linux: Using Advanced Linux Commands in Recon 
5 Linux servers that let you ditch the public cloud and reclaim your privacy - for free 
File your taxes with H&R Block for 25% off right now with this Presidents' Day deal 
New Telegram Phishing Scam Hijacks Login Flow to Steal Fully Authorized User Sessions 
As China and the US vie for the moon, private companies are locked in their own space race 
DHS privacy probe will focus on biometric tracking by ICE, OBIM 
Metasploit Wrap-Up 02 06 2026 
Record-breaking 31.4 Tbps DDoS attack hits in November 2025, stopped by Cloudflare 
Drone Hacking: Build Your Own Hacking Drone, Part 4 
Companies their own worst enemy says IBM X-Force report 
Low-cost security tag for mobile phones 
Now Koobface creates its own malicious web pages 
eBay comes under attack, says Red Condor 
$8.94 an hour will rent you your very own botnet 
CESG adopts IISP skills framework for Information Assurance 
VASCO purchases Dutch digital certificates provider 
NewNet Communication purchases encryption specialist Traxcom 
Zeus malware appears with fake digital certificate 
Amazon announces plans to security-check Android apps 
Amex leapfrogs Visa in secure micropayments market 
Relatives lose out as deceased IT users take their passwords with them 
Android iPhone app allows spoofed caller ID calls to be made 
WebGL graphics technology creates browser and system risks, Microsoft warns 
Antichat hacker forum data breach reveals weak passwords are endemic 
Future of SSL in doubt? Researcher Marlinspike unveils alternative to certificate authorities 
Newer, simpler tools bring malware analysis to smaller enterprises 
Infosecurity writers take home more hardware 
ISACA research shows bring-you-own-device to workplace trends rising rapidly 
Proactive Detection of Network Security Incidents: a new report from ENISA 
Internet action against SOPA under discussion within Net Coalition 
The contradictions of password psychology 
RSA 2012: BYOD often means bring your own danger  
UK companies are cyber self-confident 
iOS 5.5.1 jailbreak done; iOS 6 jailbreak pending 
Warning about the dangers in browser syncing 
New Mac trojan discovered: OSX Crisis (or Morcut) 
Security issues increase corporate BYOD costs 
90% leading paid mobile apps have been hacked 
Microsoft faces $7 billion fine by EU 
Opera users urged to check for malware 
The cloud is loved, but not trusted 
Reddit co-founder dies from apparent suicide 
Adobe patches four exploited ColdFusion flaws 
Canadian student threatened, expelled and then hired 
Pinkie Pie slices out $40K reward at Google Pwnium 3 hacking contest 
Department of Labor website delivered malware to visitors 
Man made redundant fined for stealing sensitive information 
The European Parliament has voted in favor of a new directive on cybercrime 
Colin Powell's Emails Tapped by Hacker 
Facebook Report Discloses Number of Government Requests for User Data 
Dropbox Hackable; Well, in a Way 
FireEye Goes Public; Trading on NASDAQ Expected Today 
UK Lauches Its Own FBI: The NCA 
Apple iOS Apps Found to Have a Common Hijacking Vulnerability 
Cameron Says China Should Be More Open About Cyber-spying, but Guardian Should be Less 
Industry Predictions for 2014; Part 3: The Effect and Influence of Government 
NSA Maintains Its Own Catalog of Advanced Hacking Tools 
SAP Combines MDM with NAC to Solve its Own Mobile Security Challenges 
Target May Have Ignored Pre-breach Intrusion Warning 
Commercial RAT Used by Malicious Hackers 
Full Disclosure Mailing List Shuts Down 
Facebook Builds its Own Threat Information Framework 
China, Vietnam and PlugX Dominate APT Landscape 
US Tried to Fire Stuxnet Malware at North Korean Nuke Plant 
Google Debuts 'Bring Your Own Encryption' 
VTech Tells Customers to Assume Responsibility Following Breach 
One-Third of IT Staff Are Hackers 
DDoS-for-Hire Services Go Up on Fiverr for 5 Bucks 
UK Cert Body Crest Signs NSA MoU 
Google AI Can Create Its Own Encryption 
Deutsche Bank to Ban Texts and Messaging Apps 
Polish Banking Sector Hit with System-wide Hack 
US Uni DDoS-ed by its Own IoT Devices 
Juniper to Acquire Cyphort 
Consumers Overwhelmingly Blame Businesses for Breaches 
Most IT Execs Have Zero Control Over Password Hygiene 
London Football Exchange to Launch Its Own Cryptocurrency 
#RSAC: Culture of Online Humiliation & Bullying Has to Stop, Says Monica Lewinsky 
UK Teen Hacker Arrested After DDoS-ing Own Email Provider 
Cybersecurity Is Getting Its Own Agency 
#BSidesSF2019: We Must Question Unintentional Biases to Fix the Cybersecurity Diversity Gap 
Facebook Boss Calls for Greater Internet Regulation 
England and Wales Police Get Dedicated Cybercrime Units 
DCMS Shares UK Journalists Emails, Potential GDPR Breach 
Companies Act to Defend Privacy of Kazakhstanis 
Global Study Finds Orgs Are Failing to Protect Data in the Cloud 
New US Privacy Bill Would Intro Jail Time for CEOs 
US Soldier Indicted Over Mass Murder Plot 
39% of Employees Access Corporate Data on Personal Devices 
EC Finds Amazon Breached Antitrust Rules 
SonicWall Probes Attack Using Zero-Days in Own Products 
Troll Fined $81 After Victim Kills Herself 
Cyber-bullied Teen Takes Own Life 
INSA Forms Critical Infrastructure Subcommittee 
French Antitrust Regulator Slaps $268 Million Fine on Google 
Ransomware Group Rebrands Multiple Times to Evade Detection 
Forensics Expert Kept Murder Snaps on PC 
Half of IT Leaders Store Passwords in Shared Docs 
Some 98% of Global Firms Suffer Supply Chain Breach in 2021 
WhatsApp Unveils Proxy Support to Tackle Internet Censorship 
EU Commission Liable for Breaching EU s Own Data Protection Rules 
Sapiom, which is developing a financial layer for enterprises to let AI agents automatically buy the services they need, raised a $15M seed led by Acc 
ICE and CBP s Face-Recognition App Can t Actually Verify Who People Are 
Off-Grid Communications, Part 5: Choosing the Right Hardware for Your Meshtastic Network 
Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework 
Why boards should be obsessed with their most ‘boring’ systems 
Securing Agents Isn t the Customer s Job, It s the Platform’s 
Adaption Labs, which aims to create AI systems that learn continuously and cost less to run, raised a $50M seed round led by Emergence Capital Partner 
CVE-2026-1999 
Lunar Energy, which develops software that syncs batteries across homes into "virtual power plants" and began deploying its own batteries in 
Lunar Energy, which develops software that syncs home batteries into "virtual power plants" and began deploying its own batteries last year, 
LookOut: Discovering RCE and Internal Access on Looker (Google Cloud & On-Prem) 
Long Range Acoustic Device (LRAD), Part 1: From Navy Origins to Venezuela’s 2026 Raid 
Woman hacked dead by own neighbor in Aloguinsan, Cebu - GMA Network 
I hacked my own computer using OpenClaw and it was terrifyingly easy - Android Authority 
CVE-2026-1934 
CVE-2026-25639 
Chinese Money Laundering Jargon via Google’s Gemini 
The weirdest tool I own is also one of the most useful (and it's only $6 on Amazon) 
Introducing Detectify Internal Scanning for internal scanning behind the firewall 
CyberheistNews Vol 16 #05 [Heads Up] New Fancy QR Codes Are Making Quishing More Dangerous 
Off-Grid Communications, Part 4: Securing Your Meshtastic Communications 
Introducing Detectify Internal Scanning for internal vulnerability scanning behind the firewall 
New frontiers in robotics at CES 2026 
If assumptions hold, SpaceX-xAI could own a full stack of capabilities, from launch to orbital bandwidth to frontier AI models, and offer AI on demand 
Own a Samsung phone? Changing these 7 settings will extend its battery life by hours 
Cybercrime Enters a New Era as Autonomous AI Agents Take Center Stage 
What s New in Tenable Cloud Security: Multi-cloud Risk Analysis, Attack Surface Assessments, Improved IAM Security and More 
OpenAI's Codex just got its own Mac app - and anyone can try it for free now 
Autonomous Threat Operations in action: Real results from Recorded Future s own SOC team Recorded Future 
The Chrysalis Backdoor: A Deep Dive into Lotus Blossom s toolkit 
Own a Google Pixel? 8 settings I changed to prolong the battery life by hours 
SEC complaint: a whistleblower alleges Google broke its ethics rules in 2024 to help an Israeli military contractor use AI to analyze drone surveillan 
Parental Controls Keep Resetting on iPhone or iPad? How to Stop It Permanently 
A MacOS 26 bug bricked my $3,700 Mac Studio - here's how I miraculously got it back 
CVE-2026-25545 
Why is disaster recovery vital with NHI 
NDSS 2025 – PropertyGPT 
 
Cybersecurity can be America’s secret weapon in the AI race 
Own a Sonos soundbar? I made 3 easy adjustments to instantly improve the audio quality 
CVE-2026-1681 
Open Directory Exposure Leaks BYOB Framework Across Windows, Linux, and macOS 
Digital Forensics: Registry Analysis for Beginners, Part 2 System Information and Basic Persistence 
The coolest character in all of Star Wars returns with his own Disney+ show in April check out the gorgeous 1st trailer (video) 
US-based AI startup Arcee releases Trinity Large, a 400B-parameter open-weight model that it says compares to Meta's Llama 4 Maverick 400B on som 
CVE-2026-25137 
Lawmakers wonder when Trump administration will weigh on soon-expired surveillance powers 
Fidelity Investments announces its own stablecoin, the Fidelity Digital Dollar, or FIDD, available to institutional and retail clients in the coming w 
How Can DLP Keep Up With AI Speed? 
Patch Tuesday and the Enduring Challenge of Windows Backwards Compatibility 
Artificial Intelligence in Cybersecurity, Part 9: How to Test MCP Servers for Security Vulnerabilities 
Stop Staring at JSON: How GenAI is Solving the API “Context Crisis” 
If you don t control your keys, you don t control your data 
PackageGate bugs let attackers bypass protections in NPM, PNPM, VLT, and Bun 
CVE-2026-25045 
Critical vulnerabilities in Fortinet CVE-2025-59718, CVE-2025-59719, CVE-2026-24858 exploited in the wild 
When Hospitals Go Dark and Browsers Turn Rogue 
Threat Actors Using AWS WorkMail in Phishing Campaigns 
The coolest character in all of Star Wars returns with his own Disney+ show in April check out the gorgeous 1st trailer (video) 
U.S. CISA adds Microsoft Office, GNU InetUtils, SmarterTools SmarterMail, and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog 
LevelBlue scoops up Alert Logic s managed services from Fortra 
The End of the Road for Cisco Kenna: Take a Measured Path into Exposure Management 
CVE-2026-24901 
APT Attacks Target Indian Government Using GOGITTER, GITSHELLPAD, and GOSHELL | Part 1 
My favorite USB-C accessory of all time has a magnetic superpower (and is priced well) 
Drone Hacking: Build Your Own Hacking Drone, Part 3 
CVE-2026-24763 
CVE-2026-24739 
CVE-2026-24764 
In hacked-off Harry, the press has created its own worst nightmare - Prospect Magazine 
Google Photos' latest generative AI-powered feature, "Me Meme", lets users create memes from their own images, launching first in the U 
Browser Wars, Continued: Why Everyone Is Building Their Own AI Browser 
The $20 magnetic USB-C accessory I can't live without - and why you need one too 
Hackers Disable Windows Security With New Malware Attack 
Vine-inspired robotic gripper gently lifts heavy and fragile objects 
CVE-2026-1375 
Watchdog group sues for TSA data sharing agreement with ICE 
This Android phone with a massive battery and an auto-focus projector made me a fan instantly 
New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack 
I scan, you scan, we all scan for... knowledge? 
Finally, I found an Android phone with a projector that isn't a gimmick 
Sony may have just beaten Bose at its own game - these earbuds surprised me big time 
Off-Grid Communications, Part 2: Getting Started with Meshtastic on LILYGO T-Echo Device 
Behavioral Scientists Say That People Who Walk Faster Than Average Consistently Share the Same Indicators Across Multiple Studies 
Social Security Spousal Benefits in 2026: Eligibility, Payment Amounts, and How to Claim 
Securing the Future: Practical Approaches to Digital Sovereignty in Google Workspace 
GCVE launches as a decentralized system for tracking software vulnerabilities 
SCADA (ICS) Hacking and Security: Hacking Nuclear Power Plants, Part 1 
Rapid7 MDR Integrates Microsoft Defender Signals to Create Tangible Security Outcomes 
The thin line between saving a company and funding a crime 
Sources: Applied Compute, which lets companies customize models with their own data, is in talks to raise funding at a $1.3B valuation, up from $500M  
HackerOne rolls out industry framework to support good faith AI research 
Metasploit Wrap-Up 01 16 2026 
The LimaCharlie Manifesto: Security for an Autonomous Future 
James Webb Space Telescope discovers young galaxies age rapidly: 'It's like seeing 2-year-old children act like teenagers' 
1976 Bicentennial Quarters: Four Rare Versions Worth Collecting 
Rare 1976 Bicentennial Quarter With No Mint Mark Could Be Valued at $2.8 Million 
Winter Storm Warning Issued as 70-MPH Winds and Up to Three Feet of Snow Arrive Faster Than Expected 
Researchers hack malware gang via its own weak spot - Techzine Global 
CVE-2026-24039 
CVE-2026-24058 
CVE-2026-1251 
StealC malware control panel flaw leaks details on active attacker 
Digital Forensics: Browser Fingerprinting, Part 2 – Audio and Cache-Based Tracking Methods 
Psychologists Say Habitual Interrupting Can Reflect Deeper Psychological Needs 
CVE-2026-23981 
CVE-2026-24000 
CVE-2026-1217 
CVE-2026-23963 
Grid operator PJM plans to require large data centers to either bring their own power generation or curtail electricity use to prevent a large-scale o 
Vulnerability in Anthropic s Claude Code Shows Up in Cowork 
Metasploit Wrap-Up 01 16 2025 
AI Breach Case Studies: Lessons for CISOs – FireTail Blog 
Own a PS5? I changed these 3 settings to give the system a big performance boost 
China-linked APT UAT-9686 abused now patched maximum severity AsyncOS bug 
This automatic espresso machine is like having my own barista, and it's not by De'Longhi or Breville 
Can a newbie really vibe code an app? I tried Cursor and Replit to find out 
Own a Roku TV? I changed these 6 settings to make my system run like new again 
CVE-2026-23896 
CISA s secure-software buying tool had a simple XSS vulnerability of its own 
The Cost of EKS Auto + Capabilities vs Fairwinds Managed KaaS 
AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain Attacks 
Predicting 2026 
2025 Threat Landscape in Review: Lessons for Businesses Moving Into 2026 
The quiet way AI normalizes foreign influence 
Digital Forensics: AnyDesk Favorite Tool of APTs 
Classroom Device Management: 8 Strategies for K-12 Success 
UAT-8837 targets critical infrastructure sectors in North America 
Scientists say that AI has become a powerful and rapidly improving research tool, and that whether it is generating ideas on its own is, for now, a mo 
CVE-2025-15526 
California AG launches investigation into X s sexualized deepfakes 
Predator spyware demonstrates troubleshooting, researcher-dodging capabilities 
Own a Samsung smartwatch? My 30-second routine will keep your device running like new 
Artificial Intelligence in Cybersecurity, Part 8: AI-Powered Dark Web Investigations 
Can AI manage its own security keys effectively 
Deploying AI agents is not your typical software launch - 7 lessons from the trenches 
CVE-2026-0953 
Reducing Cloud Chaos: Rapid7 Partners with ARMO to Deliver Cloud Runtime Security 
Own a Roku TV? I changed these 6 settings to instantly speed up the performance 
Lack of isolation in agentic browsers resurfaces old vulnerabilities 
1980s Hacker Manifesto 
Drone Hacking: Build Your Own Hacking Drone, Part 2 
Can this $25 multimeter hold its own against my $250 unit? I put it to the test 
Microsoft changes its data center approach, pledging to pay its own power costs, reject tax breaks, and replenish more water than it uses, amid local  
Own an Android phone? I changed these 12 settings to greatly improve the battery life 
Own an Apple TV? I changed these 12 settings to make the system run like new again 
Trump says Microsoft will "ensure" Americans don't face higher bills due to data centers' power use and Big Tech must "pay th 
CVE-2026-22979 
CVE-2026-23171 
CVE-2026-23103 
CVE-2026-23346 
CVE-2026-23086 
CVE-2026-22976 
CVE-2026-23016 
CVE-2025-15516 
Claude Cowork automates complex tasks for you now - at your own risk 
GoFundMe Ignores Own Rules by Hosting a Legal-Defense Fund for the ICE Agent Who Killed Renee Good 
Digital Forensics: How Hackers Compromise Servers Through File Uploads 
World Liberty Financial launches World Liberty Markets, letting users lend and borrow digital assets among one another, supporting its own token USD1  
Tenable Is a Gartner Peer Insights Customers Choice for Cloud-Native Application Protection Platforms 
Psychology Explains What It Means to Walk Slowly With Your Hands Behind Your Back 
Robots to navigate hiking trails 
The ideals of Aaron Swartz in an age of control 
Psychology Says People Who Neatly Fold Grocery Bags Share These 7 Personality Traits 
We Have Successfully Accessed Many IP Cameras in Ukrainian Territory to Spy on Russian Activities 
Psychology Says Letting Others Go First When They re Rushed Reflects These 6 Awareness Traits 
Who Benefited from the Aisuru and Kimwolf Botnets? 
Astaroth banking Trojan spreads in Brazil via WhatsApp worm 
Trump pulls US out of international cyber orgs 
The Silent Scourge: A Call to Action Against Burnout in Cybersecurity 
Elon Musk is playing with fire: All the legal risks that apply to Grok s deepfake disaster 
Psychology Says Happier People in Later Life Let Go of These 9 Common Habits 
Own a Samsung TV? I changed these 6 settings to speed up the whole system 
Taiwan blames Chinese cyber army for rise in millions of daily intrusion attempts 
I bricked my $3,700 Mac Studio by upgrading to MacOS 26 - here's how I got it back 
Misconfigured email routing enables internal-spoofed phishing 
Filing: Samsung plans to acquire $1.73B of its stock for employee and executive compensation, as part of a performance-linked scheme introduced in Oct 
Chronically Negative People Obsess Over These 10 Things Here s Why It Matters 
How Cisco Talos powers the solutions protecting your organization 
Samsung says it expects memory chip supply shortages to raise prices across the electronics industry, including potentially among its own consumer pro 
As data center development puts pressure on power grids, US officials propose requiring data centers to power down or switch to a backup as blackout r 
As data center development pressures power grids, officials have proposed requiring data centers to power down or switch to a backup when blackout ris 
CVE-2026-22561 
CVE-2026-22588 
Internal memo: Hark, the new AI lab from Figure AI CEO Brett Adcock, backed by $100M of his own capital, has hired 30+ engineers from Apple, Meta, and 
The Silent Threat to the Agentic Enterprise: Why BOLA is the #1 Risk for AI Agents 
Drone Hacking: Build Your Own Hacking Drone, Part 1 
What is Identity Dark Matter? 
92-Year-Old Judge Handling Maduro Case Doesn t Give a S–T What Anyone Thinks About Him 
Digital Threat Detection Tools & Best Practices 
AI, Quantum, and the New Threat Frontier: What Will Define Cybersecurity in 2026? 
AI, voting machine conspiracies fill information vacuum around Venezuela operation 
Kimwolf botnet leverages residential proxies to hijack 2M+ Android devices 
MongoBleed CVE-2025-14847: Critical Memory Leak in MongoDB Allowing Attackers to Extract Sensitive Data 
My Top 5 Recommendations on OT Cybersecurity Student Upskilling 
CVE-2026-22037 
CVE-2026-21863 
What is happening to the Internet in Venezuela? Did the U.S. use cyber capabilities? 
NDSS 2025 – DLBox: New Model Training Framework For Protecting Training Data 
Cybersecurity Snapshot: Predictions for 2026: AI Attack Acceleration, Automated Remediation, Custom-Made AI Security Tools, Machine Identity Threats,  
Password Cracking: Stealing Credentials with PCredz 
The Kimwolf Botnet is Stalking Your Local Network 
Google Tasks Feature Exploited in New Sophisticated Phishing Campaign 
Brookfield is starting cloud company Radiant and a new $10B AI fund, after saying it plans to acquire up to $100B in land, data centers, and power ass 
Brookfield is launching a cloud company called Radiant and a new $10B AI fund, and plans to acquire up to $100B in land, data centers, and power asset 
Trust Wallet confirms second Shai-Hulud supply-chain attack, $8.5M in crypto stolen 
Top 10 Cybersecurity Predictions for 2026 
Top 10 Best Gacha Club Outfit Ideas (2026) 
How AI labs are deploying on-site gas generators for power as the US electric grid struggles to keep pace with the growing demands of AI infrastructur 
Detect Go s silent arithmetic bugs with go-panikint 
Singapore CSA warns of maximun severity SmarterMail RCE flaw 
Sources: Nvidia is in advanced talks to acquire Tel Aviv-based AI21, which is building its own LLMs, for $2B to $3B; the deal would resemble an acquih 
Digital Forensics: Browser Fingerprinting – Visual Identification Techniques, Part 1 
Want the Samsung Frame TV? A major competitor just announced its own version 
Anton s Security Blog Quarterly Q4 2025 
AI doesn t care if it s in California or Texas. It just runs. 
How I ditched Google Photos for my own private self-hosted alternative - for free 
Own a DJI drone? Here's how the FCC ban affects you today 
The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor 
CVE-2025-69202 
CVE-2025-69207 
CVE-2026-21447 
Own a Roku TV? You're missing out on these hidden settings and menu screens 
Stranger Things Creators Reveal Whether Mike Understood He’s Will’s Crush In Coming Out Scene (Exclusive) 
TDL 012 | The Architect of the Internet on the Future of Trust 
The Groq deal secures key talent for Nvidia, including CEO Jonathan Ross, creator of the TPU, and keeps them from companies that may try to make their 
Cybersecurity Snapshot: 2025 Rewind: Essential Cyber Insights, Strategies and Tactics 
Goodbye To Concrete As We Know It – Welcome To Living Bricks That Repair Themselves 
As startups flood the market with AI shopping agents, Amazon is playing defense by blocking agents' access to its site and investing heavily in i 
CVE-2025-68944 
Astronauts beam home Christmas wishes from International Space Station: 'I think we may be orbiting a little higher than Santa' (video) 
How Larry Ellison is helping his son David build a media empire, including making the case to Trump for why Paramount, not Netflix, should acquire WBD 
Hack Your Own Password Windows Users Urged To Take Action Now - Forbes 
Italian regulator rules Apple s ATT feature limits competition 
The science of human touch and why it s so hard to replicate in robots 
Evasive Panda APT poisons DNS requests to deliver MgBot 
Microsoft Windows Hack Your Own Password Attack Warning Issued - Forbes 
CVE-2025-68774 
CVE-2025-68733 
Artificial Intelligence in Cybersecurity, Part 7: AI-Powered Vulnerability Scanning with BugTrace-AI 
MacSync Stealer Malware Targets macOS Users Through Digitally Signed Apps 
How to determine if agentic AI browsers are safe enough for your enterprise 
2025 Year in Review at Cloud Security Podcast by Google 
OpenAI rolls out Your Year with ChatGPT, a Spotify Wrapped-like feature, to Free, Plus, and Pro users in the US, the UK, Canada, Australia, and New Ze 
FanDuel and CME Group launch a prediction market app called FanDuel Predicts in five US states, just days after DraftKings rolled out a similar produc 
Digital Forensics: Analyzing BlackEnergy3 with Volatility 
Own a Samsung phone? I changed 10 settings to give it an instant performance boost 
China issues new rules letting online merchants set their own prices across platforms for goods and services they sell, effective April 10, 2026, for  
Dismantling Defenses: Trump 2.0 Cyber Year in Review 
Own a Samsung TV? I changed these 6 settings to make the system run like new again 
The WAF must die – some interesting thoughts – FireTail Blog 
5 AirPods Pro features that made me ditch my old pair instantly - and how to access them 
Own a Roku TV? 6 settings I always change first for the best performance (and they only take seconds) 
Cloud Atlas activity in the first half of 2025: what changed 
China-linked APT UAT-9686 is targeting Cisco Secure Email Gateway and Secure Email and Web Manager 
Yet another DCOM object for lateral movement 
CVE-2025-68620 
CVE-2025-14963 
CVE-2025-14977 
Internal memo: TikTok has signed a deal to sell its US unit; Oracle, Silver Lake, MGX will collectively own 45% of the US entity, and ByteDance will r 
Adios 2025, you won t be missed 
Hacking the Media: The PR Tactics of Cybercriminals 
5 AirPods Pro features that made me ditch my old AirPods - and how to use them 
The Biggest Cyber Stories of the Year: What 2025 Taught Us 
Tokyo-based Resonac, a crucial cutting-edge chip chemicals supplier whose shares are up 40%+ YTD, says it has bolstered China production capacity to m 
LLM10: Unbounded Consumption – FireTail Blog 
CVE-2025-40602: SonicWall Secure Mobile Access (SMA) 1000 Zero-Day Exploited 
CVE-2025-68467 
CVE-2025-68481 
Parents of sextortion victim sue Meta for alleged wrongful death (Libby Brooks The Guardian) 
Test for React2Shell with Application Security using New Functionality 
Google brings its vibe coding tool Opal to Gemini on the web, letting users create their own custom AI-powered mini apps, called Gems, which can be re 
Google brings its vibe coding tool Opal to Gemini on the web, letting users create their own custom apps called Gems; the mini apps can be reused late 
Mobile Forensics: Simple Methods to Extract Media and Messages from WhatsApp, Signal, and Telegram 
Own a Roku TV? My 20+ best shortcuts to get the most out of the system 
Operation ForumTroll continues: Russian political scientists targeted using plagiarism reports 
Leading Through Ambiguity: Decision-Making in Cybersecurity Leadership 
Most Parked Domains Now Serving Malicious Content 
Own a OnePlus phone? I changed 10 settings that gave mine a big performance boost 
Cisco Duo Unveils First Production Deployment of Foundation AI 
God Mode On: how we attacked a vehicle’s head unit modem 
The Burnout Nobody Talks About: When Always-On Leadership Becomes a Liability 
CVE-2025-68205 
CVE-2025-68359 
CVE-2025-68380 
CVE-2025-68335 
CVE-2025-14802 
The most useful electric tool I own just got replaced - and the successor is $20 off on Amazon 
Own an Apple TV? I changed 12 settings to instantly make the system run like new again 
 
What s Next for Enterprise Threat Intelligence in 2026 
Good news for lunar bases? Earth's atmosphere leaks all the way out to the moon 
Own a Fire TV? I changed 10 settings to make the system run like new again 
Frogblight threatens you with a court case: a new Android banker targets Turkish users 
Why are companies free to choose their own AI-driven security solutions? 
Password Cracking: Getting Started with John the Ripper 
TDL 011 | The Hidden Layer of Cybersecurity: Andreas Taudte on DNS & DDI Defense 
Policymakers behind key state AI bills scoff at Trump's EO; some GOP governors are pushing ahead with their own AI bills; Steve Bannon says Sacks 
Building Trustworthy AI Agents 
Weaponized AI risk is 'high,' warns OpenAI - here's the plan to stop it 
Turn me on, turn me off: Zigbee assessment in industrial environments 
CVE-2025-67875 
Critical Gogs zero-day under attack, 700 servers hacked 
One newsletter to rule them all 
Rivian says it is building its own 5nm AI chip called the Rivian Autonomy Processor and a foundational "Large Driving Model", to enable full 
2026 API and AI Security Predictions: What Experts Expect in the Year Ahead 
Own a Google Pixel Watch? 7 hidden features that are incredibly useful (and where to find them) 
Palestine Action: Operations and Global Network 
Geopolitics and Cyber Risk: How Global Tensions Shape the Attack Surface 
Beyond Cargo Audit: Securing Your Rust Crates in Container Images 
Empowering Security and Control: Thales CipherTrust Cloud Key Management Integrates with Oracle Fusion Cloud Services 
Operation Bluebird, a Virginia-based startup, has petitioned the USPTO to acquire the "abandoned" Twitter trademark and launch its own socia 
2025 Year of Browser Bugs Recap: A Year of Unmasking Critical Browser Vulnerabilities 
Be Your Own Secret Santa: Staying Private and Secure While Holiday Shopping Online 
New EtherRAT backdoor surfaces in React2Shell attacks tied to North Korea 
Implications of Russia-India-China Trilateral Cooperation 
Digital Forensics: Volatility – Analyzing a Malicious VPN 
CVE-2025-67722 
CVE-2025-14426 
5 Real-Word Third-Party Risk Examples 
Goodbye, dark Telegram: Blocks are pushing the underground out 
New BYOVD loader behind DeadLock ransomware attack 
GrayBravo s CastleLoader Activity Clusters Target Multiple Industries 
The Future of Humanoid Robotics 
US lawmakers remove provisions in the National Defense Authorization Act for 2026 that would have ensured military members' right to repair their 
UK cyber agency warns LLMs will always be vulnerable to prompt injection 
Critical React2Shell Vulnerability Under Active Exploitation by Chinese Threat Actors 
AWS: China-linked threat actors weaponized React2Shell hours after disclosure 
Nikita Bier accuses the European Commission of trying to deceptively amplify the reach of its post about its 120M fine on X; X terminates the EC&ap 
Nikita Bier accuses the European Commission of trying to deceptively amplify the reach of its post about the 120M fine on X; X terminates the EC&ap 
Attackers launch dual campaign on GlobalProtect portals and SonicWall APIs 
Digital Forensics: An Introduction to Basic Linux Forensics 
Attackers hit React defect as researchers quibble over proof 
Metasploit Wrap-Up 12 05 2025 
Network Security: Get Started with QUIC and HTTP 3 
OpenAI is training models to 'confess' when they lie - what it means for future AI 
Claude Code made an astonishing $1B in 6 months - and my own AI-coded iPhone app shows why 
CVE-2025-14115 
Intellexa remotely accessed Predator spyware customer systems, investigation finds 
Sen. Mark Kelly: Investing in safe, secure AI is key to U.S. dominance 
Sources: Amazon, the USPS' top customer with $6B+ in revenue in 2025, is considering ending its deal at the end of 2026 and expanding its own del 
OpenAI is testing training LLMs to produce "confessions", or self-report how they carried out a task and own up to bad behavior, like appear 
Korea Zinc Faces Criminal Investigation Over Alleged Irregularities in Rights Offering 
CVE-2025-66553 
CVE-2025-66551 
CVE-2025-66570 
Developers scramble as critical React flaw threatens major apps 
Own a PS5? I changed 3 settings on my console for a big performance boost 
CVE-2025-66513 
Filings: after EA's buyout, Saudi Arabia's PIF would own 93.4% of EA, implying it needs to put up $29B, while Silver Lake and Affinity woul 
Amazon puts ChatGPT on the naughty list, blocking shopping access - what we know 
Amazon launches the Trainium3 UltraServer, powered by the 3nm Trainium3 AI training chip, and teases Trainium4, which will be able to work with Nvidia 
A dying satellite could use its final moments to photograph the infamous asteroid Apophis in 2029 
AI Malware: Hype vs. Reality 
CVE-2025-66474 
Google addresses 107 Android vulnerabilities, including two zero-days 
SITE NEWS: How to contact Techmeme about news 
This bizarre tool I own actually solves a real problem (and it's only $9 on Amazon) 
I can't stop talking about the Ninja Creami Swirl - and it's at an all-time low price 
Best Black Friday Dell deals 2025: I found the top 15 Dell laptop sales live now 
Using Artificial Intelligence (AI) in Cybersecurity: Automate Threat Modeling with STRIDE GPT 
Grab the telescope that helped me stargaze in a light-polluted city the Unistellar Odyssey Pro is now $1149 cheaper for Black Friday 
This Marshall portable speaker is one of my favorite things I own - and it's under $100 right now 
MDR ROI, Proven Outcomes, and What Security Leaders Need to Ask For 
Protecting What Powers Business: Rapid7 and Microsoft Partner to Simplify Security 
6 MagSafe chargers, wallets, and phone stands I'd buy if I didn't already own them (all are on sale) 
Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’ 
Best sci-fi action movies of all time, ranked 
Integrating Threat Intelligence and Vulnerability Management: A Modern Approach 
Mobile Forensics: Investigating a Murder 
The weirdest tool I own is also one of the most useful (and it's $14 on Amazon) 
The popular Ninja Creami Swirl just dropped to its best Black Friday price - how the deal works 
Command and Control (C2): Using Browser Notifications as a Weapon 
Why is this star so weird? Maybe because it ate one of its own planets 
Old tech, new vulnerabilities: NTLM abuse, ongoing exploitation in 2025 
Sources: a new network of super PACs plans to raise $50M to counter the Leading the Future super PAC and back candidates who prioritize AI regulation 
Gainsight CEO downplays impact of attack that spread to Salesforce environments 
FBI: bank impersonators fuel $262M surge in account takeover fraud 
What You Can’t See Can Hurt You: Are Your Security Tools Hiding the Real Risks? 
Best Black Friday Dell deals 2025: 15 laptop sales out now 
I swear by the viral Ninja Creami Swirl at home - here's the best discount on Black Friday 
Polish antitrust office UOKiK is probing whether Apple's ATT limits third-party data collection in mobile ads while giving Apple's own ads s 
Poland's antitrust office UOKiK is probing whether Apple's ATT limits third-party data collection in mobile ads while giving Apple's ow 
FAQ About Sha1-Hulud 2.0: The “Second Coming” of the npm Supply-Chain Campaign 
Internal memo: Amazon asks engineers to use its in-house AI coding assistant Kiro over third-party tools like Cursor, aiming to gather feedback for im 
Google is starting to bridge OpenAI's product moat, like with Gemini's "dynamic view" option, which converts a text answer into an 
Sources: Google has begun pitching customers, including Meta and big financial institutions, on the idea of using TPUs in their own data centers (The  
Grindr ends talks on a $3.46B take-private deal by shareholders Ray Zage and James Lu, who own 60%+ of Grindr, citing uncertainty over the deal's 
Is Your Android TV Streaming Box Part of a Botnet? 
Own an iPhone? I changed these 15 settings on iOS 26 to instantly extend the battery life 
Sources: Shopify salespeople engaged in a sales fraud scheme inflating deal values for over a year, leading to internal investigations in mid-2024 and 
Choosing a Digital Risk Intelligence Platform: 5 Key Capabilities to Evaluate 
To buy or not to buy: How cybercriminals capitalize on Black Friday 
AI attack agents are accelerators, not autonomous weapons: the Anthropic attack 
Make soft-serve ice cream at home with the Ninja Creami Swirl - down to the lowest price yet for Black Friday 
Own an Android phone? 12 settings I changed to greatly extend its battery life 
Arbiter, which is using AI to automate healthcare administrative tasks, emerges from stealth with a $52M seed from multiple family offices at a $400M  
Own AirPods? I changed these 3 iPhone settings for an instant audio boost 
CVE-2025-66172 
Cybersecurity Snapshot: Global Agencies Target Criminal Bulletproof Hosts, as CSA Unveils Agentic AI Risk Framework 
Automating Your Digital Life with n8n 
Cl0p gang hacks Oracle, exploiting Oracle's own EBS zero-day - Cybernews 
Cl0p ransomware hacks Oracle exploiting Oracle's own EBS zero-day - Cybernews 
It s not personal, it s just business 
Coordinated sanctions hit Russian bulletproof hosting providers enabling top ransomware Ops 
Top Senate Intel Dem warns of catastrophic cyber consequences of Trump admin national security firings, politicization 
Threat Intelligence Automation 
Inside the dark web job market 
Smashing Security podcast #444: We re sorry. Wait, did a company actually say that? 
Own a Roku TV? I changed 6 settings to give the system a noticeable speed boost 
APIs, Microservices and Risk Management – FireTail Blog 
Warner Music settles its lawsuit with AI music startup Udio, which is planning a service that lets users create songs from licensed tracks of artists  
Amazon warns of global rise in specialized cyber-enabled kinetic targeting 
Sources: Warner Music settles its suit with AI startup Udio, which is planning a service that lets users create songs from licensed tracks of artists  
Operational Cyber Threat Intelligence 
When AI Turns on Its Team: Exploiting Agent-to-Agent Discovery via Prompt Injection 
The Cloudflare Outage May Be a Security Roadmap 
Own AirPods? I changed 3 settings on my iPhone to significantly improve the audio experience 
IT threat evolution in Q3 2025. Non-mobile statistics 
As TSMC readies its 10B Germany plant for 2027, its Taiwanese suppliers say they're struggling with the EU's complex permitting, labor, a 
Hackers turn open-source AI framework into global cryptojacking operation 
Lambda, which rents access to AI chips, raised a $1.5B Series E led by TWG Global, after raising $500M in April 2024, taking its total funding to $2.3 
New in Snort3: Enhanced rule grouping for greater flexibility and control 
I tried Google's new trip-planning AI tool, and I'll never plan my own trip again 
CVE-2025-65821 
CVE-2025-65841 
What is NVIDIA’s CUDA and How is it Used in Cybersecurity? 
Your data, your model: Self-serve custom entity types in Tonic Textual 
Investigation: $28B+ in crypto tied to illicit activity flowed into crypto exchanges like Binance over the past two years, as President Trump embraced 
Investigation: $28B+ in crypto tied to illicit activity flowed into crypto exchanges like Binance over the last two years, as President Trump embraces 
Microsoft Patch Tuesday, November 2025 Edition 
NDSS 2025 – The Discriminative Power Of Cross-layer RTTs In Fingerprinting Proxy Traffic 
Security Analysts Skeptical That Claude Code Really Hacked 30 Orgs on Its Own - PCMag UK 
Digital asset treasuries increasingly rely on in-kind contributions, with sponsors using their own crypto instead of cash, shifting risk to retail inv 
Security Analysts Skeptical That Claude Code Really Hacked 30 Orgs on Its Own - PCMag Middle East 
China s autonomous AI-powered hacking campaign still required a ton of human work 
TDL 009 | Inside DNS Threat Intelligence: Privacy, Security & Innovation 
SDR (Signals Intelligence) for Hackers: Getting Started with Anti-Drone Warfare 
China's Shenzhou 20 astronauts return to Earth on different spacecraft after finding window cracks in their own (video) 
Critical FortiWeb flaw under attack, allowing complete compromise 
Germany s BSI issues guidelines to counter evasion attacks targeting LLMs 
Third-Party Risk Statistics 
Viasat and the terrible, horrible, no good, very bad day 
Unlocking Cloud Security: Introducing the New AWS Key Rotation Feature in CipherTrust Cloud Key Management 
Satya Nadella says Microsoft has access to "all" of OpenAI's custom AI chip work and plans to use it to help develop its own in-house c 
CVE-2025-65020 
CVE-2025-65021 
Former Twitter CEO Parag Agrawal's Parallel Web Systems, which is building tools for AI agents to search the web, raised a $100M Series A at a $7 
While White House demands deterrence, Trump shrugs 
Digital Forensics: Investigating a Cyberattack with Autopsy 
Australia s spy chief warns of China-linked threats to critical infrastructure 
Introducing the 2025 State of Threat Intelligence Report: Threat Intelligence Shifts from Defense to Strategy 
Planets may make their own water as they form could that mean more habitable worlds in the universe? 
From Firewalls to the Cloud: Unifying Security Policies Across Hybrid Environments 
Amazon rolls out AI bug bounty program 
Sources: Meta Chief AI Scientist Yann LeCun plans to leave Meta in the coming months to found his own startup; a source says he is in early talks to r 
Sources: Meta Chief AI Scientist Yann LeCun plans to leave in the coming months to found his own startup; a source says he is in early talks to raise  
CoRL2025 RobustDexGrasp: dexterous robot hand grasping of nearly any object 
Beware of Security Alert-Themed Malicious Emails that Steal Your Email Logins 
Faster Than Real-Time: Why Your Security Fails and What to Do Next 
Planets may make their own water as they form could that mean more habitable worlds in the universe? 
Web App Hacking:Tearing Back the Cloudflare Veil to Reveal IP’s 
Agentic AI in Cybersecurity: Beyond Triage to Strategic Threat Hunting 
Own a Ring camera? This new update fixes its biggest annoyance for free 
The Unistellar eQuinox 2 is our telescope experts' pick as the best overall smart telescope, and is now $700 off in this early Black Friday telescope  
CVE-2025-64711 
Drilling Down on Uncle Sam’s Proposed TP-Link Ban 
Security Affairs newsletter Round 549 by Pierluigi Paganini INTERNATIONAL EDITION 
Balancer hack analysis and guidance for the DeFi ecosystem 
Cybersecurity Snapshot: AI Will Take Center Stage in Cyber in 2026, Google Says, as MITRE Revamps ATT&CK Framework 
ClickFix Attack Evolves: Weaponized Videos Trigger Self-Infection Tactics 
CVE-2025-12882 
Remember, remember the fifth of November 
Google sounds alarm on self-modifying AI malware 
Own a Google Pixel Watch? 7 hidden features you should take advantage of (and where to find them) 
Microsoft AI CEO Mustafa Suleyman lays out the company's plans to develop AI self-sufficiency from OpenAI, like releasing its own voice, image, a 
Malicious Infrastructure Finds Stability with aurologic GmbH 
Own a Samsung phone? I changed these 7 settings to extend the battery life by hours 
CVE-2025-12847 
With each cloud outage, calls for government action grow louder 
Congressional leaders want an executive branch strategy on China 6G, tech supply chain 
Amazon, Perplexity, and the future of AI shopping assistants 
This AI ring takes notes for you and even talks back - in your own voice 
How to Prevent Ransomware 
Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly 
Using Artificial Intelligence (AI) in Cybersecurity: Creating a Custom MCP Server For Log Analysis 
XPeng says it plans to launch three self-developed robotaxis in 2026, the first Chinese EV maker to do so, using in-house chips and its own software s 
How the F5 breach, CISA job cuts, and a government shutdown are eroding U.S. cyber readiness 
HackedGPT: Novel AI Vulnerabilities Open the Door for Private Data Leakage 
CVE-2025-64517 
Chicago firm that resolves ransomware attacks had rogue workers carrying out their own hacks, FBI says - Chicago Sun-Times 
Own a Samsung smartwatch? These 8 features and settings are very useful (but often overlooked) 
Prosecutors allege incident response pros used ALPHV BlackCat to commit string of ransomware attacks 
Mars is the ultimate sandbox in 'Mars First Logistics', a physics-based delivery game where you build your own rovers 
Digital Forensics: Volatility – Memory Analysis Guide, Part 1 
Own a Samsung watch? My 30-second routine keeps the system running like new 
AI is becoming introspective - and that 'should be monitored carefully,' warns Anthropic 
TDL 008 | Defending the Frontline: Ransomware, AI, and Real-World Lessons 
Alleged Jabber Zeus Coder ‘MrICQ’ in U.S. Custody 
Alleged 764 leader arrested in Arizona, faces life in prison 
Own a PS5? Changing these 3 settings gave my system a big performance boost 
Transnational Organized Crime Gang Steals $1 Million from Ontario Couple 
Own a Roku TV? 6 settings I always change to give it an instant performance boost 
Government and industry must work together to secure America s cyber future 
Trick, treat, repeat 
Canva launches a foundational design model that generates editable layered designs, expands Canva AI, makes Affinity free for all users, and more (Iva 
How to Implement a Secure BYOD Policy for a Modern Workforce 
The ROI of Threat-Led Defense: Reducing Waste in the Security Stack 
Hacking Artificial Intelligence (AI): Hijacking AI Trust to Spread C2 Instructions 
China s Militia Forces Train to Get Strong in the New Era 
Resistance leader 
Dynamic binary instrumentation (DBI) with DynamoRio 
CVE-2025-12535 
CVE-2025-12524 
CVE-2025-12512 
Ethical Prompt Injection: Fighting Shadow AI with Its Own Weapon 
Aisuru Botnet Shifts from DDoS to Residential Proxies 
Security for AI: A Practical Guide to Enforcing Your AI Acceptable Use Policy 
Rethinking Identity Security in the Age of AI 
Western Union plans to launch a dollar-backed stablecoin, USDPT, that is built on the Solana blockchain and issued by Anchorage Digital Bank, in H1 20 
Space and Cyber: The Race Above and the Battle Below 
The API vulnerabilities nobody talks about: excessive data exposure 
Grokipedia, a Grok-based encyclopedia, launches with 885K+ articles, drawing from Wikipedia content; Elon Musk called it "a massive improvement&q 
Crypto wasted: BlueNoroff’s ghost mirage of funding and jobs 
Grokipedia, a Grok-powered online encyclopedia, launches with over 885K articles; Elon Musk has touted it as a less biased alternative to Wikipedia (W 
CVE-2025-64175 
How to Take Vulnerability Management to the Next Level and Supercharge Your Career 
Scanning GitHub Gists for Secrets with Bring Your Own Source 
SCADA (ICS) Hacking and Security: An Introduction to SCADA Forensics 
Sources: JPMorgan Chase is giving staff the option to use its in-house LLM to write year-end performance reviews, a shortcut to the often painstaking  
Mem3nt0 mori The Hacking Team is back! 
CVE-2025-64105 
SCADA Forensics: Introduction 
How to Prevent Ransomware Recorded Future 
Hidden in Plain Sight: How we followed one malicious extension to uncover a multi-extension  
Artificial Intelligence (AI) in Cybersecurity: Getting Started with Model Context Protocol (MCP) 
Cybersecurity Snapshot: Top Advice for Detecting and Preventing AI Attacks, and for Securing AI Systems 
National cyber director says U.S. needs to counter Chinese surveillance, push American tech 
Amazon Reveals Technical Fault Behind Widescale AWS Service Outage 
Shifting from reactive to proactive: Cyber resilience amid nation-state espionage 
Think passwordless is too complicated? Let's clear that up 
Neuroscientists have a new stress hack: Spend 36 minutes listening to your own brain waves - Fast Company 
Strings in the maze: Finding hidden strengths and gaps in your team 
Microsoft unveils Mico, a character that responds with real-time expressions when talked to, now on by default in Copilot's voice mode in the US, 
Migrating Critical Messaging from Self-Hosted RabbitMQ to Amazon MQ 
New API testing category now available 
Lawyers for a teen who died by suicide after allegedly discussing methods with ChatGPT call OpenAI's request for all memorial documents "int 
TikTok pushes merchants to use a new ad-buying tool that promotes videos linking to TikTok Shop rather than merchants' own sites, frustrating som 
Cybersecurity Awareness Month Is for Security Leaders, Too 
Upgrading your Windows laptop? I built my own Linux machine in minutes (and you can, too) 
Top 10 Takeaways from Predict 2025: Turning Intelligence Into Action 
Dark Covenant 3.0: Controlled Impunity and Russia s Cybercriminals 
Bridging the Remediation Gap: Introducing Pentera Resolve 
Deep analysis of the flaw in BetterBank reward logic 
AWS Outage: Lessons Learned 
First impressions of ChatGPT Atlas, as browser agents remain confusing, with insurmountable security and privacy risks including prompt injection atta 
CVE-2025-12030 
Ransomware Protection: Source Code Stolen, Patients Exposed, and Utilities Breached 
 
My 6 favorite Spotlight actions in MacOS Tahoe so far - and how to add your own 
 
 
Adobe might've just solved one of generative AI's biggest legal risks 
How luxury brands' stiffest competition is coming from secondhand online resellers like The RealReal and Fashionphile, driven by Gen Z and millen 
OpenAI researchers delete X posts claiming a GPT-5 math breakthrough after pushback from Hassabis, others; LeCun says they were "hoisted by their 
Own an Apple TV? Changing these 12 settings should give it an instant speed boost 
Physicist and author Brian Greene to host 1st Global Space Awards in London 
TDL 007 | Cyber Warriors & Digital Shadows: Insights from Canada s Cybersecurity Leader 
OpenAI's own support bot has no idea how ChatGPT works 
SEO spam and hidden links: how to protect your website and your reputation 
CVE-2025-11923 
Tenable Discovers Critical Vulnerabilities in SimpleHelp Tool: CVE-2025-36727 and CVE-2025-36728 
F5 BIG-IP Breach: 44 CVEs That Need Your Attention Now 
The Sweetest Disney Cruise Hack: Bring Your Own Cup for Unlimited Ice Cream - DCL Fan 
Ransomware attacks and how victims respond 
What Is Shadow AI and Why It Matters? – FireTail Blog 
A View from the C-suite: Aligning AI security to the NIST RMF – FireTail Blog 
 
The Human Cost of Cyber Risk: How Exposure Management Can Ease Security Burnout 
Own a Google Pixel? 8 settings I changed to extend the battery life by hours 
A survey of 28K+ adults in 25 countries on AI: 81% have heard a lot or a little, 34% are more concerned than excited, and 42% are equally concerned an 
Mysterious Elephant: a growing threat 
Roll your own bot detection: server-side detection (part 2) 
Flax Typhoon APT exploited ArcGIS server for over a year as a backdoor 
CVE-2025-62506 
How to Mitigate Supply Chain Attacks 
Researchers find a startlingly cheap way to steal your secrets from space 
Flax Typhoon can turn your own software against you - CyberScoop 
Document: to avoid an EU fine, Google offered to tweak its search results to show vertical search engines in their own box on Search (Foo Yun Chee Reu 
 
Flax Typhoon can turn your own software against you 
Why API security is different (and why it matters) 
Sovereign Data, Sovereign Access: Introducing Modern FIDO Authentication for SAS PCE 
Sources: OpenAI is working with Arm to develop a CPU designed to work with the AI chip OpenAI is developing with Broadcom; TSMC will manufacture the A 
'More joyous and sillier than 'Rick and Morty': 'Solar Opposites' showrunners on creating their own legacy as final season lands (exclusive) 
 
From sea to space, this robot is on a roll 
Driving Innovation with Secure NHIs 
CVE-2025-11690 
DDoS Botnet Aisuru Blankets US ISPs in Record DDoS 
Get a phone line with unlimited 5G for $25 month from Metro by T-Mobile - here's how 
Russian spyware ClayRat is spreading, evolving quickly, according to Zimperium 
CVE-2025-11578 
CVE-2025-62378 
PowerShell for Hackers, Part 8: Privilege Escalation and Organization Takeover 
PowerShell for Hackers – Survival Edition, Part 2: Advanced Recon 
PowerShell for Hackers, Part 6: Privilege Escalation and Organization Takeover 
PowerShell for Hackers: Survival Edition, Part 2 
Sen. Peters tries another approach to extend expired cyber threat information-sharing law 
Prime Day is over, but some of our favorite Best Buy deals are still live. 
Digital Forensics: Investigating a Ransomware Attack 
Voting groups ask court for immediate halt to Trump admin s SAVE database overhaul 
Here's your last chance on the 30 best Prime Day Best Buy deals 
 
PowerShell for Hackers: Privilege Escalation and Organization Takeover 
German government says it will oppose EU mass-scanning proposal 
ShinyHunters Wage Broad Corporate Extortion Spree 
Purdue 2.0? : Rising to the Challenge to secure OT with Zero Trust Connectivity 
Own a Google Pixel? 10 settings I always change first for the most optimal performance 
Roll your own bot detection: fingerprinting JavaScript (part 1) 
SpamGPT – When Phishing Gets a Marketing Degree 
OpenAI: Threat actors use us to be efficient, not make new tools 
Got a Samsung TV? I changed these 6 settings to greatly improve the performance 
Don t Let Your Cloud Security Catch a Bad Case of Permission Creep 
CVE-2025-11437 
TDL 006 | Beyond the Firewall: How Attackers Weaponize Your DNS 
Best Amazon Prime Day Best Buy deals in October 2025: Save up to $300 on laptops, phones and headphones 
Massive Malicious NPM Package Attack Threatens Software Supply Chains 
How Exposure Management Helped Three Companies Transform Their Cybersecurity Program 
How we trained an ML model to detect DLL hijacking 
This tiny magnetic USB-C accessory changed how I charge everything (and it's cheap) 
Own a MacBook? I recommend this compact wall charger over Apple's (and it's cheaper) 
A look at challenges facing Tether and Circle's stablecoin duopoly, such as intermediaries like exchanges and DeFi protocols exploring their own  
CVE-2022-50498 
CVE-2022-50471 
Kids in the UK are hacking their own schools for dares and notoriety - Yahoo Finance 
Advanced Linux Persistence: Strategies for Remaining Inside a Linux Target 
Family group chats: Your (very last) line of cyber defense 
The Buy Vs. Build Dilemma: Pitfalls of the DIY Approach to Exposure Management 
Real-World Executive Protection: How We Secure Our Own Leadership Team 
PowerShell for Hackers, Part 5: Finding Modules and Using Dsquery 
PowerShell for Hackers: Finding Modules and Using Dsquery 
Mars rovers serve as scientists eyes and ears from millions of miles away here are the tools Perseverance used to spot a potential sign of ancient  
 
 
SDR (Signals Intelligence) for Hackers: Capturing Aircraft Signals 
Your Peloton is getting an AI-powered face lift 
Own a Roku TV? This 30-second routine will keep it running like new 
GOP senator confirms pending White House quantum push, touts legislative alternatives 
Google unveils new Home products: $99 Google Home Speaker, set for spring 2026, third-gen $100 Nest Cam Indoor, second-gen $150 Nest Cam Outdoor, and  
European version of SpaceX's Starship? ESA signs deal for reusable upper stage demonstrator 
Top Best Buy deals ahead of Amazon Prime Day 2025: My 20+ favorite sales in October 
Forensic journey: hunting evil within AmCache 
Stripe launches Open Issuance, a Bridge-powered platform that lets companies create its own stablecoins, used by crypto wallet Phantom to issue its CA 
Stripe launches Open Issuance, a stablecoin issuance platform built on Stripe's Bridge, which lets companies create their own stablecoins with mi 
Microsoft launches a Security Store with SaaS tools and AI agents from Darktrace and others, and now lets Security Copilot users build their own AI ag 
New Smish: New York Department of Revenue 
Harrods Data Breach Explained 
How Jensen Huang, who engaged little in politics until 2024, is using his newfound star power to strike deals in Europe, the Middle East, Japan, and e 
How Jared Kushner and Silver Lake co-CEO Egon Durban brokered the EA takeover using Kushner's deep Saudi Arabia ties; sources: Kushner's fir 
ChatGPT lets parents restrict content and features for teens now - here's how 
Top Best Buy deals ahead of Amazon Prime Day 2025: My 20+ favorite sales before October 
London-based Evantic Capital, founded by ex-Sequoia VC Matt Miller, raised a $400M fund, with 12.5% coming from 135 "legends", including CE 
SMS Pools and what the US Secret Service Really Found Around New York 
 
An App Used to Dox Charlie Kirk Critics Doxed Its Own Users Instead 
Postal Thief Arrested in Oregon 
UN seeks to build consensus on safe, secure and trustworthy AI 
Microsoft uncovers new variant of XCSSET macOS malware in targeted attacks 
Cybersecurity Snapshot: CISA Highlights Vulnerability Management Importance in Breach Analysis, as Orgs Are Urged To Patch Cisco Zero-Days 
CVE-2025-11031 
CVE-2025-61084 
Sources: Oracle, Silver Lake, and Abu Dhabi's MGX will be the main TikTok USA investors, with a 45% stake; ByteDance will own 19.9% and ByteDanc 
Sources: Oracle, Silver Lake, and MGX will be the main investors in TikTok USA, with a 45% stake; ByteDance will own 19.9%, and ByteDance investors 3 
Thales Named a Leader in the Data Security Posture Management Market 
AT&T customers will soon get their own AI receptionist to answer calls and block spam 
RoboCup Logistics League: an interview with Alexander Ferrein, Till Hofmann and Wataru Uemura 
Massive npm infection: the Shai-Hulud worm and patient zero 
This bizarre tool I own actually solves a real problem (and it's only $7 on Amazon) 
PowerShell for Hackers, Part 5: Detecting Users, Media Control, and File Conversion 
Own a Samsung TV? I changed these 6 settings to instantly improve the performance 
Reasonable Expectations for Cybersecurity Mentees 
Why SASE Vendors Are Finally Admitting the Need for Browser Security Solutions 
Children hacking their own schools for 'fun', watchdog warns - bbc.com 
Own a PS5? I changed 3 quick settings to give my console a huge performance boost 
How RainyDay, Turian and a new PlugX variant abuse DLL search order hijacking 
Service Accounts in Active Directory: These OG NHIs Could Be Your Weakest Link 
Crypto hacker falls victim to own scam losing $50 million to phishing attack - CryptoSlate 
Crypto hacker falls victim to own scam losing $50 million to Inferno Drainer s phishing attack - CryptoSlate 
Why I can't live without this magnetic USB-C accessory - and all the devices it can charge 
Adolescence writer on new phone-hacking drama: 'It's a celebration of journalists who called out their own industry' - AOL.com 
Anton s Security Blog Quarterly Q3 2025 
CVE-2025-10871 
CVE-2025-59951 
CVE-2025-59895 
CVE-2025-59945 
CVE-2025-59960 
TDL 005 | A Defender’s Journey: From Passion Project to Protecting Children Online 
Telecom exec: Salt Typhoon inspiring other hackers to use unconventional techniques 
Scammers are now faking the FBI's own website - here's how to stay safe 
The magnetic USB-C accessory I can't live without - and why you need one too 
Call for AAAI educational AI videos 
Cyber threat information law hurtles toward expiration, with poor prospects for renewal 
Why federal IT leaders must act now to deliver NIST s post-quantum cryptography transition 
MalTerminal: New GPT-4-Powered Malware That Writes Its Own Ransomware 
ESET uncovers Gamaredon Turla collaboration in Ukraine cyberattacks 
Security Affairs newsletter Round 542 by Pierluigi Paganini INTERNATIONAL EDITION 
SCADA Hacking: Inside Russian Facilities, Part 5 
Huawei says DeepSeek-R1-Safe, which was trained on 1,000 of its Ascend AI chips, is "nearly 100% successful" in preventing politically sensi 
Trump administration planning expansion of U.S. quantum strategy 
Sliver: Building C2 During a Cyber War – Part 6: Lateral Movement 
Self-supervised learning for soccer ball detection and beyond: interview with winners of the RoboCup 2025 best paper award 
Recap of Our Passkeys Pwned Talk at DEF CON 
 
Top Best Buy deals ahead of Amazon Prime Day 2025: My 23 favorite sales before October 
Who Owns Threat and Exposure Management in Your Organization? 
Alex Ryan: From zero chill to quiet confidence 
Smashing Security podcast #435: Lights! Camera! Hacktion! 
Detect Secrets in GitLab CI Logs using ggshield and Bring Your Own Source 
Wyze launched a new biometric smart lock, and its price might be the best part 
How Meta's California super PAC, rare as a single-company entity, lets Mark Zuckerberg spend Meta's money on his own political choices, incl 
CVE-2025-10619 
Microsoft announces a $30B investment in the UK over four years to support AI infrastructure and ongoing operations, including $15B to build a superco 
"A dare, a challenge, a bit of fun:" Children are hacking their own schools' systems, says study - Malwarebytes 
Top 10 Best MSSP (Managed Security Service Providers) in 2025 
RevengeHotels: a new wave of attacks leveraging LLMs and VenomRAT 
The Gravity of Process: Why New Tech Never Fixes Broken Process and Can AI Change It? 
How to Apply CISA s OT Inventory and Taxonomy Guidance for Owners and Operators Using Tenable 
CVE-2025-10579 
https://dronexl.co/2025/01/07/autel-robotics-dod-chinese-military-companies-list/ 
#ICML2025 outstanding position paper: Interview with Jaeho Kim on addressing the problems with conference reviewing 
CVE-2025-59390 
SITE NEWS: Explaining, at some length, Techmeme's 20 years of consistency 
IBM is holding its own in the quantum computing race against Google, Microsoft, and others, as they tackle enormous scientific and engineering challen 
UK students hacking their own schools for dares - Cybernews 
Pupils hacking their own schools for fun, watchdog warns - AOL.com 
Sources: Alibaba and Baidu have begun using their own chips, like the Zhenwu and the Kunlun P800, to train their AI models, partly replacing Nvidia&ap 
I built my own AirTag-like tracker with this Raspberry Pi alternative - how it works 
Pupils hacking their own schools for fun, watchdog warns - the-independent.com 
I built my own AirTag-like finder with this Raspberry Pi alternative - here's how 
Sources: Alibaba and Baidu have begun using their own internally designed chips to train their AI models, partly replacing AI chips made by Nvidia (Qi 
Pupils hacking their own schools for fun, watchdog warns - Yahoo News UK 
Apertus: a fully open, transparent, multilingual language model 
Are cybercriminals hacking your systems or just logging in? 
CVE-2025-59330 
CVE-2025-59331 
OpenAI says its nonprofit parent will continue to have oversight over the company and will own an equity stake of more than $100B (Ashley Capoot CNBC) 
Children are hacking their own schools' IT systems 'for fun' - watchdog warns - Daily Mail 
Children are hacking their own schools' IT systems 'for fun' - watchdog warns - MSN 
After coding catastrophe, Replit says its new AI agent checks its own work - here's how to try it 
Pupils hacking their own schools for fun, watchdog warns - The Independent 
Code-to-Cloud Visibility: Why Fragmented Security Can t Scale 
From Alert Fatigue to Proactive Defense: The Case for AI-Driven Prevention 
Kids in the UK are hacking their own schools for dares and notoriety - TechCrunch 
Kids hacking their own schools for fun, claims ICO - Tech Digest 
Children hacking their own schools for 'fun', watchdog warns - BBC 
A Framework for Understanding and Anticipating Vladimir Putin s Foreign Policy Actions 
Children hacking their own schools for 'fun', watchdog warns - Yahoo News Canada 
Use Claude's new feature at your own risk - here's why 
Three states team up in investigative sweep of companies flouting data opt-out laws 
Hacker exposes own tactics through Huntress trial - SC Media 
Apple s new Memory Integrity Enforcement system deals a huge blow to spyware developers 
TDL004 | Understanding Microsoft Zero Trust DNS with Aditi Patange 
Alibaba's mapping app Amap launches its own ranking of restaurants, hotels, and tourist destinations, intensifying its competition with Chinese r 
Training for the Unexpected Why Identity Simulation Matters More Than Unit Tests 
Elevating Data Security in AI & Analytics Workloads: Thales & Databricks 
Robots to the rescue: miniature robots offer new hope for search and rescue operations 
National cyber director: U.S. strategy needs to shift cyber risk from Americans to its adversaries 
Advanced Windows Persistence, Part 2: Using the Registry to Maintain Persistence 
Breaking Down Silos: Why You Need an Ecosystem View of Cloud Risk 
Mitsubishi Electric to acquire Nozomi Networks in $1 billion deal 
Qualys Confirms Cyberattack Campaign Targeting Salesforce via Salesloft and Drift 
18 Popular Code Packages Hacked, Rigged to Steal Crypto 
CVE-2025-59144 
CVE-2025-59141 
CVE-2025-59143 
CVE-2025-59142 
CVE-2025-59140 
CVE-2025-59162 
CVE-2025-59145 
Report: OpenAI will launch its own AI chip next year 
APT37 Targets Windows with Rust Backdoor and Python Loader 
This oddball screwdriver is one of the most ergonomic tools I own (and it's only $15) 
CVE-2025-10095 
CVE-2025-59021 
OnePlus ends its five-year partnership with camera company Hasselblad and plans to develop its own imaging engine called DetailMax Engine for upcoming 
Fix: Sky Remote Volume Not Working (Sky Q, Sky Stream, Sky+ HD) 
Critical SAP S 4HANA flaw CVE-2025-42957 under active exploitation 
Own a Samsung smartwatch? This 30-second routine will keep your device running like new 
Data Resilience Reality Check: Why Most Organizations are Failing Their Own Audits 
Ex-Champ Admits Public Complaints His Own, Comes Clean on Hacking Claim - sherdog.com 
Ex-Champ Admits Public Complaints His Own, Comes Clean on Hacking Claim - Sherdog 
Source: Nvidia agreed to rent 10,000 of its own AI chips from Lambda for $1.3B over four years, the latest example of Nvidia's circular financial 
Identity-First Security: Mitigating the Cloud s Greatest Risk Vector 
Stripe and Paradigm unveil Tempo, a Layer-1 blockchain for stablecoins; a source says Tempo will not launch with its own token and there is no launch  
From CastleLoader to CastleRAT: TAG-150 Advances Operations with Multi-Tiered Infrastructure 
This new Spotify feature almost made me ditch Apple Music - but iOS 26 changed my mind 
#IJCAI2025 distinguished paper: Combining MORL with restraining bolts to learn normative behaviour 
Why Misconceptions About Cloud Managed Services Can Cost You 
Sources: Apple plans an AI search tool, World Knowledge Answers, for a spring 2026 Siri revamp; Apple and Google have agreed to test a Google AI model 
Sources: Apple plans an AI search tool, World Knowledge Answers, for spring 2026 as part of a Siri revamp; Apple and Google plan to test a Google mode 
Hackers of Jaguar Land Rover cyber attack that disrupted systems own up - NationalWorld 
The Full Lifecycle Imperative: Why “Shift Left” Must Meet “Shift Right” 
FTC announces settlement with toy robot makers that tracked location of children 
Google patches two Android zero-days, 120 defects total in September security update 
Garmin unveils the $1,200+ Fenix 8 Pro, featuring new satellite and cellular communications tools, and a $2,000 microLED version, both shipping from S 
Digital Forensics: System Monitoring with osquery 
Garmin unveils the $1,200+ Fenix 8 Pro, including new satellite and cellular communications tools, and a $2,000 microLED version, both shipping Septem 
Own a Samsung phone? Changing these 10 settings gave mine a big performance boost 
Watch out, Whoop: Polar joins the fitness band race with a premium option 
Own a PS5? I changed 3 settings to give my console a big performance boost 
TDL 002 | Defending the DNS: How Quad9 Protects the Internet with John Todd 
Trusted Cloud Edge in Practice: Transforming Critical Industries 
Advanced Windows Persistence, Part 1: Remaining Inside the Windows Target 
Influence Operations and Conflict Escalation in South Asia 
Introducing Dynamic API Scanning 
Researchers are teaching robots to walk on Mars from the sand of New Mexico 
Cookies and how to bake them: what they are for, associated risks, and what session hijacking has to do with it 
Prolific Russian ransomware operator living in California enjoys rare leniency awaiting trial 
Silver Fox Exploits Microsoft-Signed WatchDog Driver to Deploy ValleyRAT Malware 
Microsoft to Require Multi-Factor Authentication on Azure Portal Logins 
Open Online Mentoring Guide 
CVE-2025-9889 
Hasbro Vs. Disney lightsabers: What's the difference? 
Fraudster stole over $1.5 million from city of Baltimore 
How Turkmenistan turned censorship into a lucrative extortion scheme by intentionally restricting internet access in order to sell its own VPNs to cit 
How attackers adapt to built-in macOS protection 
Dutch intelligence warn that China-linked APT Salt Typhoon targeted local critical infrastructure 
CVE-2025-58365 
 
Affiliates Flock to ‘Soulless’ Scam Gambling Machine 
 
I took this 360-degree camera around the world - why it's still the most versatile gear I own 
How SafeLine WAF Turns Hackers Scanners into Trash 
Trump administration setting the stage for elections power grab, voting rights group warns 
H1 2025 Malware and Vulnerability Trends 
Google Cloud says its Universal Ledger, a layer-1 blockchain for financial products, is in a private testnet, and plans to reveal more details at a la 
Google goes live with on-premise Gemini AI 
Google Cloud says its Universal Ledger, a layer-1 blockchain for financial products, is in a private testnet, and more details will be revealed at a l 
TDL001 | Cybersecurity Explained: Privacy, Threats, and the Future | Chester Wisniewski 
We Are Still Unable to Secure LLMs from Malicious Inputs 
The One-Man APT Part II: Stealthy Exfiltration with AI 
One Step Ahead: Stark Industries Solutions Preempts EU Sanctions 
Malaysian chip designer SkyeChip unveils the MARS1000, the country's first edge AI processor, as Malaysia seeks to climb the global semiconductor 
TDL003 | Breaking Barriers: IPv6 Adoption and DNS Transformation with Tommy Jensen 
New ZipLine Campaign Targets Critical Manufacturing Firms with In-Memory MixShell Malware 
Court ruling in Epic-Google fight could have catastrophic cyber consequences, former gov t officials say 
Gartner says add AI agents ASAP - or else. Oh, and they're also overhyped 
The AI Fix #65: Excel Copilot will wreck your data, and can AI fix social media? 
Formal Methods for Stellar DeFi: Verifying Lending Protocol with Certora Sunbeam Prover 
Finally, my ultimate smart home setup is complete thanks to this display gadget 
An interview with Nicolai Ommer: the RoboCup Soccer Small Size League 
It's our choice as the best deep space viewing telescope, and it's rarely discounted now with $200 off, this telescope deal is worth grabbing fast 
Changing these 6 settings on my Samsung TV greatly improved the performance 
How Exposure Management Has Helped Tenable Reduce Risk and Align with the Business 
Blistering Wyden letter seeks review of federal court cybersecurity, citing incompetence, negligence  
What is Single Sign-On (SSO) 
It's our choice as the best deep space viewing telescope, and it's rarely discounted now with $200 off, this telescope deal is worth grabbing fast 
AI Agents Need Data Integrity 
Modern vehicle cybersecurity trends 
Perplexity's Comet AI browser could expose your data to attackers - here's how 
CVE-2025-58051 
The Imperative of Tunnel-Free Trusted Cloud Edge Architectures 
How do the biggest stars in the universe grow so large? 
FTC warns tech companies not to weaken encryption, free speech practices for foreign governments 
CrowdStrike warns of uptick in Silk Typhoon attacks this summer 
'DripDropper' Hackers Patch Their Own Exploit - Dark Reading 
Russian cyber group exploits seven-year-old network vulnerabilities for long-term espionage 
Behind the Curtain: How Lumma Affiliates Operate 
The New Frontier: Why You Can’t Secure AI Without Securing APIs 
AIhub coffee corner: Agentic AI 
'DripDropper' Hackers Patch Their Own Exploit - Dark Reading Security 
JJ Cummings: The art of controlling information 
GodRAT – New RAT targeting financial institutions 
Source: Arm hires Amazon AI chip director Rami Sinno to help develop its own chips; Sinno previously worked on Amazon's Trainium and Inferentia c 
CVE-2025-57766 
Source: Arm has hired Amazon AI chip director Rami Sinno to help develop its own chips; he previously worked on Amazon's Trainium and Inferentia  
Claude can now stop conversations - for its own protection, not yours 
Sources: Anthropic asked Menlo to use the VC firm's own capital for investment in the startup and not an SPV, as Menlo did in a previous funding  
The weirdest tool I own is also one of the most useful (and it's $10 on Amazon) 
Machine Learning, Part 01: Getting Started with the Basics 
As boards and executives mandate using AI to make their businesses more efficient and competitive, many have yet to fully integrate it into their own  
Digital bank Monzo, which has 13M UK customers, plans to launch a mobile phone service; Revolut and Klarna, each with 11M UK customers, announced sim 
As CEOs and executives mandate AI adoption to make their businesses more efficient and competitive, many have yet to fully integrate it into their own 
Own a Dreame robot vacuum? Don't use public WiFi to control it - Australian Broadcasting Corporation 
CVE-2025-56558 
CVE-2025-56800 
Open Source Intelligence (OSINT): Leaked Secrets with TruffleHog 
Scammers Compromised by Own Malware, Expose $4.67M Operation 
CVE-2025-56400 
Court rebuffs request by telecoms to review $92 million privacy fine 
PowerShell for Hackers, Part 4: Operational Scripts 
Own a PS5? Changing these 3 settings gave my console an instant performance boost 
Cloud Threat Hunting and Defense Landscape 
Ghost-Tapping and the Chinese cybercriminal retail fraud ecosystem 
2024 Threat Analysis and 2024 Predictions Recorded Future Annual Threat Report 
Working in Singapore at the World s Largest Intelligence Company 
Russian Influence Operations Targeting Germany s 2025 Elections 
How Security Leaders Defend Their Attack Surface 
How Threat Intelligence Enhances Security Spending Efficiency 
Iran s AI Ambitions: National Security, Global Influence, and Strategic Challenges 
US-China AI Gap: 2025 Analysis of Model Performance, Investment, and Innovation 
GrayAlpha Unmasked: New FIN7-Linked Infrastructure, PowerNet Loader, and Fake Update Attacks 
Threats to the 2025 NATO Summit: Cyber, Influence, and Hybrid Risks 
US Extremists in 2025: Shift Toward Targeted Physical Threats Recorded Future 
Beyond the Prompt: Securing the “Brain” of Your AI Agents 
Attackers Need Just One Vulnerability to Own Your Rooted Android 
Just $35 gets you 18 ethical hacking courses you own forever - Mashable 
Russia restricts WhatsApp, Telegram calls, alleging criminal, terrorist activity 
The overlooked changes that two Trump executive orders could bring to cybersecurity 
Charon Ransomware targets Middle East with APT attack methods 
Bring Your Own Source: Plug GitGuardian into Any Workflow in Minutes 
How Larry Ellison is focusing his philanthropic efforts on the Oxford-based, for-profit Ellison Institute of Technology, promising to spend 1B on th 
How Larry Ellison is focusing his philanthropic efforts on the Ellison Institute of Technology, an Oxford-based, for-profit entity set to spend 1B b 
From Risk to ROI: How Security Maturity Drives Business Value 
CVE-2025-55292 
CVE-2025-8900 
PowerShell for Hackers, Part 3: Exploring PowerView 
MedusaLocker ransomware group is looking for pentesters 
CVE-2025-8850 
ReVault! When your SoC turns against you deep dive edition 
OSINT for Business: Getting Started Using Open-Source Techniques for Business 
OSINT: Getting Started with Business Intelligence 
Tea App Data Breach Fallout: A New App with Security Flaws and Lawsuits 
How Google's Genie 3 could change AI video - and let you build your own interactive worlds 
Scammers mass-mailing the Efimer Trojan to steal crypto 
SonicWall dismisses zero-day fears after Ransomware probe 
CVE-2025-55210 
Why Your Growing B2B Company Shouldn’t Build AI Infrastructure (And What to Do Instead) 
Why I no longer recommend pre-built SSDs for Windows PCs - and what you should buy instead 
Hackers Exploit Legitimate Drivers to Disable Antivirus and Weaken System Defenses 
Why I stopped recommending pre-built SSDs for Windows PCs - and what to buy instead 
CVE-2025-55123 
Driver of destruction: How a legitimate driver is being used to take down AV processes 
Microsoft unveils Project Ire, a prototype AI system that can reverse engineer and identify malicious software autonomously, without human assistance  
Why identity is the definitive cyber defense for federal agencies 
Beyond Anomalies: How Autonomous Threat Hunting Uncovers the Full Attack Story 
Securing Non-Human Identities in Complex Hybrid, Multi-Cloud, and Agentic AI Environments 
Web App Hacking: Getting Started with Caido 
My go-to LLM tool just dropped a super simple Mac and PC app for local AI - why you should try it 
Roku launches Howdy, an ad-free streaming service for $2.99 per month, initially only on Roku devices, with content from Lionsgate, WBD, FilmRise, and 
Healthcare Under Pressure 
SonicWall investigates possible zero-day amid Akira ransomware surge 
SOC Visibility Triad is Now A Quad SOC Visibility Quad 2025 
India's IT giants face revenue erosion from challenges including corporations establishing their own global capability centers in the country and 
Google addresses six vulnerabilities in August s Android security update 
Backdoors & Breaches: How Talos is helping humanitarian aid NGOs prepare for cyber attacks 
Akira Ransomware targets SonicWall VPNs in likely zero-day attacks 
CETC China Electronics Technology Group 
Why Custom Database Software Matters in 2025 
China accuses US of exploiting Microsoft zero-day in cyberattack 
Web App Hacking: OWASP-ZAP Introduction 
Own a Samsung phone? 10 settings I always change first for the best user experience 
Hackers Abuse EDR Free Trials to Bypass Endpoint Protection 
CVE-2025-54941 
The Booker Prize Longlist and Hacker Summer Camp 
Insecure De-serialization: Millions of Applications May Be Vulnerable 
Using LLMs as a reverse engineering sidekick 
Researchers released a decryptor for the FunkSec ransomware 
Arm CEO Rene Haas says the company is accelerating its R&D spending as it considers offering "full end solutions", suggesting plans to l 
IP Camera Hacking: The FFmpeg Tool for Streaming Camera Video 
CVE-2025-54888 
Senate Democrats call Trump admin s focus on state voter rolls a pretext for disenfranchisement 
Amazon-backed AI streaming service Showrunner debuts on Thursday, charging users $10 to $40 per month to create their own animated shows or build on o 
Securing the Next Era: Why Agentic AI Demands a New Approach to API Security 
Powershell for Hackers, Part 2: LDAP Filters for Active Directory Reconnaissance 
Showrunner, an Amazon-backed AI streaming service, launches Thursday, letting users paying $10-$40 mo. to create their own animated shows or build on  
James Webb Space Telescope finds giant, lonely exoplanets can build their own planetary friends without a parent star 
Sources: Revolut considers buying a US bank to get an American banking license to expand lending capabilities, a faster route than applying for its ow 
#RoboCup2025: social media round-up part 2 
How Bonds is hacking the retail calendar with its own branded sales day - Inside Retail Asia 
Powershell for Hackers: Part 2 – Filters 
Own a Samsung phone? Changing these 7 settings will drastically improve the battery life 
The AI Fix #61: Replit panics, deletes $1M project; AI gets gold at Math Olympiad 
Insights from Talos IR: Navigating NIS2 technical implementation 
How to Fix Stick Drift on Xbox Controllers (Permanent Solutions) 
Athens-based defense tech startup Delian Alliance Industries, which makes its own hardware, software, and sensor fusion systems, raised a $14M Series  
Hundreds of registered data brokers ignore user requests around personal data 
My 5 favorite Linux distros for home office desktops - and I've tried them all 
I've tested nearly every distro - these 5 rock solid Linux OSes run my home office 
At TrustCon 2025, trust and safety professionals expressed anxiety over the industry's retreat, but no leaders condemned platforms' rollback 
CVE-2025-54599 
Own a OnePlus phone? I changed 10 settings to significantly improve the user experience 
Critical Remote Code Execution (RCE) in Roundcube, CVE-2025-49113: Your Email is Not Safe! 
Public companies are loading up on crypto tokens, including $TRUMP, HYPE, and litecoin, as they expand beyond bitcoin to boost their own share prices  
ToolShell: a story of five vulnerabilities in Microsoft SharePoint 
BRB, pausing for a "Sanctuary Moon" marathon 
Who is Fancy Bear (APT28) and What Do They Do? 
Stealth backdoor found in WordPress mu-Plugins folder 
Trump AI plan pushes critical infrastructure to use AI for cyber defense 
PowerShell for Hackers, Part 1 – The Basics 
Meet Hazel Burton 
Alibaba releases its new Qwen3-235B-A22B-Instruct-2507 model on Hugging Face, improving on Qwen 3's reasoning, accuracy, and multilingual underst 
How earthquake alerts work on Android - and how to make sure they're enabled on your phone 
SCADA Hacking: Inside Russian Facilities, Part 3 
Why it’s time for the US to go on offense in cyberspace 
The SOC files: Rumble in the jungle or APT41’s new target in Africa 
Rumble in the jungle: APT41’s new target in Africa 
5 tips for building foundation models for AI 
UK sanctions Russian hackers, spies as US weighs its own punishments for Russia - CyberScoop 
UK sanctions Russian hackers, spies as US weighs its own punishments for Russia 
Sources: the US State Department has effectively dismantled its three-year-old Bureau of Cyberspace and Digital Policy, firing between nine and 11 sta 
This is your sign to step away from the keyboard 
How I started my own LinkedIn newsletter for free - in 5 easy steps 
How I started my own LinkedIn newsletter - in 5 easy steps 
The password manager I recommend most has its own VPN and long list of features 
Hate Windows 11? Here's how you can make it work more like Windows 10 
House hearing will use Stuxnet to search for novel ways to confront OT cyberthreats 
Volodymyr, the Ukrainian hacker who sabotages Moscow between two video conferences 
Couple lives rent free in their own home thanks to 'house hacking' - it's been 10 years and they haven't paid a dime - The US Sun 
How to Live for Free in Your Own Home by House Hacking - Business Insider 
An interview with Nicolai Ommer: the RoboCupSoccer Small Size League 
CVE-2025-7699 
CVE-2025-54129 
Sliver: Building a C2 During a Cyber War, Part 1 
An attacker using a $500 radio setup could potentially trigger train brake failures or derailments from a distance 
CVE-2025-7695 
Why skipping security prompting on Grok s newest model is a huge mistake 
Scientists find Uranus is surprisingly warm, heating up the case for a new planetary mission 
Forensic journey: Breaking down the UserAssist artifact structure 
APT-Q-20 
CVE-2025-53940 
Sock Puppets: Creating Fake Accounts for OSINT Operations 
Jio Platforms debuts JioPC, a cloud PC service offered via its set-top box; Counterpoint: 70% of Indian households have a TV, but only 15% of them own 
CVE-2025-53889 
UK Arrests Four in ‘Scattered Spider’ Ransom Group 
This Asus portable monitor transformed my remote work setup (and it's only $170) 
Patch, track, repeat 
UK Charges Four in ‘Scattered Spider’ Ransom Group 
Agora, which offers a white-labeling service to let other companies launch their own, self-branded versions of its stablecoin, AUSD, raised a $50M Ser 
US Violent Extremists Likely Shifting Focus to Targeted Physical Threats in 2025 
Brave Browser For Android via F Droid: Now Fully Available 
Ikea plans to relaunch its smart home line with 20+ new Matter-over-Thread devices, starting in January 2026, and releases a beta update for its Dirig 
Ikea plans to relaunch its smart home line with 20+ new Matter-over-Thread devices, set to release in January 2026, and updates its Dirigera smart hom 
Hackers weaponize Shellter red teaming tool to spread infostealers 
A look at Yahoo Creators, launched in March 2024, offering creators a 50 50 ad revenue split for posting original written content, with 135 creators s 
A look at Yahoo Creators, launched in March 2024, offering creators a 50 50 ad revenue split for posting original written content and has signed up 13 
Private stock investment platform Linqto files for bankruptcy, citing SEC and DOJ probes and an internal probe that found users didn't own shares 
El Salvador-based Tether says it holds nearly 80 tons of gold, worth $8B, in a vault in Switzerland; precious metals made up nearly 5% of its reserve 
Approach to mainframe penetration testing on z OS. Deep dive into RACF 
Cambodia dismisses Thai hacking allegations, cites own cyberattacks - Asia News Network 
Call of Duty takes PC game offline after multiple reports of RCE attacks on players 
Security Affairs newsletter Round 531 by Pierluigi Paganini INTERNATIONAL EDITION 
Catwatchful stalkerware app spills secrets of 62,000 users – including its own admin 
Google fined $314M for misusing idle Android users’ data 
China-linked group Houken hit French organizations using zero-days 
Sources: In 2024, Apple explored a cloud service renting its own chips to developers; it spends $7B per year on renting Nvidia chips from AWS and Goo 
The “Homeland” VP Pacemaker Hack: Is This Attack Realistic? 
Why I no longer recommend pre-built SSDs for Windows PCs - buy this instead 
Got a Samsung TV? I recommend changing these 6 settings for the best performance 
Own a PS5? I changed 3 settings on my gaming console for an instant performance boost 
Exoplanets that cling too tightly to their stars trigger their own doom: 'This is a completely new phenomenon' 
Building an XDR Integration With Splunk Attack Analyzer 
Apple TV+ might have found its own Mr. Robot in this upcoming hacker drama - Boy Genius Report 
CVE-2025-53532 
X will start to publish Community Notes written by AI agents; developers will soon be able to submit their own "fact-checking" AI agents for 
NeuraLink: What Could Possibly Go Wrong? The ultimate invasion reading or leaking your innermost thoughts? 
Ghost in the Machine: A Spy s Digital Lifeline 
U.S. House Homeland Security Appropriations Bill Seeks to Modernize Border Infrastructure Security with Proactive OT IT Security Measures 
Wi-Fi Hacking: The Nearest Neighbor Attack, Attacking Your Neighbor Through the Backdoor 
Genesis AI, which generates its own synthetic data for training an AI model for robots, emerges from stealth with a $105M seed co-led by Eclipse and K 
The best 98-inch TVs of 2025: Cinema-sized and expert tested 
An interview with Claude AI product lead Scott White on Claude Code writing 90% of its own code, MCP, coding being accessible to non-technical workers 
After criticism, Sen. Blackburn backs off her own AI compromise for the tax bill, saying "we can't block states from making laws that protec 
After criticism, Senator Marsha Blackburn backs off her own AI provision compromise, saying "we can't block states from making laws that pro 
CVE-2025-6994 
Circle applies for a US national trust bank license, which would let it act as a custodian for its own reserves and hold crypto for its institutional  
How Cloudflare Works: The Hacker Blueprint 
Canada bans Hikvision over national security concerns 
Denmark moves to protect personal identity from deepfakes with new copyright law 
Hacker pleads guilty to breaching company networks to pitch his own services - TechRadar 
Denmark plans to clamp down on AI-generated deepfakes by changing copyright law to give its citizens rights to their own body, facial features, and vo 
Sources: mass production of Microsoft's next AI chip is delayed to 2026 and is expected to underperform Nvidia's Blackwell chip, released in 
NASA's been pulling out of major astronomy meetings and scientists are feeling the effects 
Getting a career in cybersecurity isn t easy, but this can help 
AI usage is stalling out at work from lack of education and support 
Sources: Apple execs discussed starting their own theatrical distribution unit; Warner Bros. is distributing the F1 movie and getting a share of the b 
Decrement by one to rule them all: AsIO3.sys driver exploitation 
Short-term extension of expiring cyber information-sharing law could be on the table 
Many data brokers aren t registering across state lines, privacy groups say 
Tired of upgrading your phone? This sustainable Android lets you do your own repairs 
Tired of upgrading your phone? This new, sustainable Android lets you do your own repairs 
900 routers infected 
Anthropic launches new AI feature to build your own customizable chatbots 
Cybercriminal abuse of large language models 
Why I no longer buy pre-built SSDs for my PC (and what I recommend instead) 
As Apple rolls out CarPlay Ultra, many carmakers are developing their own infotainment systems in hopes of generating more revenue from in-car service 
CVE-2025-53108 
Network Forensics: Getting Started With Stratoshark 
Anton s Security Blog Quarterly Q2 2025 
Why I stopped buying pre-built SSDs (and what I recommend instead) 
OpenAI Used Globally for Attacks – FireTail Blog 
Fiserv aims to launch its own stablecoin by 2025's end, and partners with PayPal and Circle to develop new products for financial institutions an 
I used Google's Flow AI to create my own videos with sound and dialogue - Here's how it went 
Wi-Fi Hacking: Inside DragonFly, the WPA3 s Next-Gen Wireless Authentication Protocol 
The SAVE database was already a headache for states. Now it s fueling Trump s voter fraud allegations. 
Taiwan Is Rushing to Make Its Own Drones Before It's Too Late 
LinuxFest Northwest: Project Caua: Start Your Own Business, Be Your Own Boss 
Godfather Android trojan uses virtualization to hijack banking and crypto apps 
How to enable earthquake alerts on your Android phone (including these Samsung models) 
How to turn AI into your own research assistant with this free Google tool 
Amazon ends an experiment started in 2023 to make same-day deliveries with drivers in Kia Souls and will rely on Amazon Flex drivers who use their own 
How Android earthquake alerts work (and how to enable them) 
New Detection Method Uses Hackers Own Jitter Patterns Against Them - Hackread 
New Detection Method Uses Hackers Own Jitter Patterns Against Them 
How Artificial Intelligence (AI) Large Language Models (LLMs) Work, Part 1 
Linux flaws chain allows Root access across major distributions 
Understanding EchoLeak: What This Vulnerability Teaches Us About Application Security | Impart Security 
Gearing up for RoboCupJunior: Interview with Ana Patr cia Magalh es 
Secure your data throughout its lifecycle with End-to-End Data Protection 
MIT researchers unveil Self-Adapting LLMs, a framework that enables LLMs to keep improving by generating their own training data based on the input re 
 
Threats to the 2025 NATO Summit 
When legitimate tools go rogue 
CVE-2025-52554 
CVE-2022-50086 
CVE-2025-52572 
CVE-2025-52556 
Cyber experts call for supercharging volunteer network to protect community organizations 
VPN Hacking: Authentication Bypass on Fortinet Fortios 
What Is Vulnerability Prioritization? A No-Fluff Playbook 
OpenID Connect (OIDC) Explained 
Exposure Management Is the Future of Proactive Security 
DNS Rebind Protection Revisited 
Social Engineering: Delivering Phishing EMail to Russian Companies and Government 
VPN Hacking: How VPN’s Work and How They Break Our Security 
Cybersecurity Snapshot: NIST Offers Zero Trust Implementation Advice, While OpenAI Shares ChatGPT Misuse Incidents 
Hacking the Hackers: When Cybercriminals Get a Taste of Their Own Medicine - The420.in 
GrayAlpha Uses Diverse Infection Vectors to Deploy PowerNet Loader and NetSupport RAT 
Inside a Dark Adtech Empire Fed by Fake CAPTCHAs 
CVE-2025-6082 
Know thyself, know thy environment 
WordPress Sites Turned Weapon: How VexTrio and Affiliates Run a Global Scam Network 
This mandatory Pixel 6a update may limit your battery - but it's for your own good 
Looking for a Python Developer or a Team of Python Developers 
Sources: CoreWeave will provide computing capacity to Google as part of Google's cloud deal with OpenAI; Google will also supply its own compute  
Outlook Vulnerability Allows Remote Execution of Arbitrary Code by Attackers 
How Amazon Web Services uses AI to be a security force multiplier  
Capabilities Unlocked by Advanced NHI Management 
CVE-2025-5999 
CVE-2025-49845 
Google rolls out Android 16 to Pixel phones, unveils AI-powered edit suggestion for Google Photos (Ivan Mehta TechCrunch) 
Google rolls out Android 16 to Pixel phones, adding group chat to RCS, AI-powered edit suggestions to Google Photos, live notifications on lock screen 
The AI Fix #54: Will AI collapse under its own garbage, and AI charity Hunger Games  
Mark Zuckerberg says Threads users will soon be able to send DMs to each other without having to leave the platform, first in Hong Kong, Argentina, an 
Mark Zuckerberg says Threads users will soon be able to send direct messages to each other without having to leave the platform, adding a separate inb 
With 35% off, the Estes Rockets Journey Launch set is a brilliant introduction to the joys of space flight and model rocketry and at its cheapest  
BlackSuit Continues Social Engineering Attacks in Wake of Black Basta s Internal Conflict 
Cisco reveals its AI-ready data center strategy - boosted by its Nvidia partnership 
Rare Werewolf APT Uses Legitimate Software in Attacks on Hundreds of Russian Enterprises 
New Report Uncover That Chinese Hackers Attempted To Compromise SentinelOne's Own Servers - CybersecurityNews 
How to Post and Comment Anonymously on Facebook Group 
Update: Dumping Entra Connect Sync Credentials 
Every Apple Watch that will get WatchOS 26 (and which models won't be supported) 
OffensiveCon25 – Entrysign: Create Your Own x86 Microcode for Fun and Profit 
Friendly fire: Hackers target their own with fake malware and gaming cheats - TechRadar 
Sleep with one eye open: how Librarian Ghouls steal data by night 
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 48 
Sources: Mistral AI has closed or is closing a handful of commercial contracts, each worth $100M+ over three to five years, as it expands its own infr 
CVE-2025-5874 
Justin Sun-linked BiT Global dismisses with prejudice its lawsuit against Coinbase for delisting wBTC; the delisting followed Coinbase launching rival 
I recommend the Pixel 9 to most people looking to upgrade - especially while it's $250 off 
Google's viral research assistant just got its own app - here's how it can help you 
Cybersecurity Snapshot: Experts Issue Best Practices for Migrating to Post-Quantum Cryptography and for Improving Orgs Cyber Culture 
Cultivating Growth and Development at Rapid7 
Analysis of the latest Mirai wave exploiting TBK DVR devices with CVE-2024-3721 
Proxy Services Feast on Ukraine’s IP Address Exodus 
Sean Cairncross has policy coordination in mind if confirmed as national cyber director 
Signal Intelligence with a Software Defined Radio (SDR): The Quiet Revolution in Cybersecurity and Cyberwarfare 
IT threat evolution in Q1 2025. Non-mobile statistics 
What the Arc Browser Story Reveals About the Future of Browser Security 
CVE-2025-5733 
When AI Turns Against Us – FireTail Blog 
Vibe coding is here to stay. Can it ever be secure? 
Mistral releases Mistral Code, a "vibe coding" client forked from open-source project Continue, in private beta on JetBrains development pla 
Mistral releases Mistral Code, a "vibe coding" client forked from open source project Continue, in private beta on JetBrains platforms and V 
Killer skinned his own cat then hacked schoolboy, 14, to death during Samurai sword rampage when he also tried - Daily Mail 
This Dangerous Email Tricks You Into Hacking Your Own PC - Forbes 
I changed 6 settings on my Samsung TV to instantly improve the performance 
How Morgan Stanley is using its DevGen.AI tool, built in-house on OpenAI's GPT models, to translate legacy code into modern coding languages (Isa 
Sources: Pump.fun plans to raise $1B via a token sale at a $4B valuation; Pump.fun has generated over $700M in cumulative revenue since its launch in  
Google addresses 34 high-severity vulnerabilities in June s Android security update 
CrowdStrike, Microsoft aim to eliminate confusion in threat group attribution 
What Tackling the SaaS Security Problem Means to Me 
Analysis: since his inauguration, President Trump posted 2,262 times on Truth Social in 132 days, 3x+ the volume of tweets in the same period of his f 
Future-ready cybersecurity: Lessons from the MITRE CVE crisis 
Host-based logs, container-based threats: How to tell where an attack began 
EU Regulating InfoSec: How Detectify helps achieving NIS 2 and DORA compliance 
CVE-2025-49199 
Getting the Most Value Out of the OSCP: After the Exam 
Snowflake agrees to acquire Crunchy Data, a cloud-based database service that helps businesses and government agencies use PostgreSQL, a source says f 
Filing: neobank Chime plans to sell 26M shares in its IPO at $24 to $26, valuing it a $10.3B to $11.1B; co-founders Chris Britt and Ryan King each ow 
Filing: neobank Chime plans to sell 26M shares in its IPO at $24 to $26, giving it a valuation between $10.3B and $11.1B; its two co-founders own 4% t 
OAuth 2.0 in Practice: Building an OAuth Client 
Experts published a detailed analysis of Cisco IOS XE WLC flaw CVE-2025-20188 
CVE-2025-49148 
Scientists Use AI Chatbots to Carry Encrypted Messages Undetectable by Cybersecurity Systems 
Microsoft Opens Windows Update to 3rd-Party Apps 
Streamline SCA with Sonatype’s build-safe automation 
Unmasking ECH: Why DNS-at-the-Root-of-Trust Holds the Key to Secure Connectivity 
New Malware Spotted Corrupts Its Own Headers to Block Analysis 
New Malware Spooted Corrupts Its Own Headers to Block Analysis 
Questions mount as Ivanti tackles another round of zero-days 
How to set up your own article archiving service - and why I did (RIP, Pocket) 
Life after Pocket: How to set up your own self-hosted article archiving service 
The AI Fix #52: AI adopts its own social norms, and AI DJ creates diversity scandal 
China signs deal with Russia to build a power plant on the moon potentially leaving the US in the dust 
A Hyperscaler for Cybersecurity 
Operation Endgame 2.0: DanaBusted 
Oops: DanaBot Malware Devs Infected Their Own PCs 
Ghosted by a cybercriminal 
What the Take Command 2025 Survey Tells Us About the State of Security 
New Signal update stops Windows from capturing user chats 
NSIS Abuse and sRDI Shellcode: Anatomy of the Winos 4.0 Campaign 
Amazon plans to sell Nike products directly for the first time since 2019, when Nike stopped selling through Amazon due to lingering counterfeit issue 
Protecting Against Brand Impersonation Attacks with Browser Detection and Response 
LLM03: Supply Chain – FireTail Blog 
Lumma Stealer toppled by globally coordinated takedown 
A house full of open windows: Why telecoms may never purge their networks of Salt Typhoon 
KrebsOnSecurity Hit With Near-Record 6.3 Tbps DDoS 
Where Is Anton Nikolaevich Korotchenko ( ) Also Known as Koobface Botnet Master KrotReal? – Part Five 
Google's viral NotebookLM AI tool gets its own Android app - what you can do with it 
Governance in the Age of Citizen Developers and AI 
Whatever we did was not enough : How Salt Typhoon slipped through the government’s blind spots 
2 hacked by own kin in Samboan, Cebu - GMA Network 
CVE-2025-4979 
Google's popular AI tool gets its own Android app - how to use NotebookLM on your phone 
Microsoft unveils new AI agent customization and oversight features at Build 2025 
UK Supermarket Avoided Ransomware Because They Yanked Their Own Plug, Hackers Say - TechRepublic 
Nvidia unveils NVLink Fusion, letting customers use its NVLink to pair non-Nvidia CPUs or accelerators with Nvidia's products in their own rack-s 
Security Affairs newsletter Round 524 by Pierluigi Paganini INTERNATIONAL EDITION 
Michael Novogratz says Galaxy Digital is in talks with the US SEC about tokenizing its own stock as well as other equities using its digital-asset pla 
Hacking Artificial Intelligence (AI) Large Language Models (LLMs) 
FCC commissioner blasts Trump administration censorship policies 
Linux Basics for Hackers: Building a Router with nftables 
Mr Robot Hacks: Building a Deadman’s Switch in Python 
BASH Scripting for Hackers, Part 01: BASH Scripting Basics 
SDR (Signals Intelligence) for Hackers: Building a Low- Cost, Private 4G LTE Network 
AI in the Cloud: The Rising Tide of Security and Privacy Risks 
Closing the Loop: Continuous API Security Testing – FireTail Blog 
'They yanked their own plug': how Co-op averted an even worse cyber attack - BBC 
CVE-2025-48150 
DHS won t tell Congress how many people it s cut from CISA 
Patch Tuesday, May 2025 Edition 
Databricks agrees to acquire cloud database startup Neon for $1B, set to close in Databricks' Q2 2025; Neon's platform is based on the open 
Databricks agrees to acquire cloud database startup Neon for $1B, set to close in Q2 2025; Neon's platform is based on open-source database Post 
CVE Foundation eyes year-end launch following 11th-hour rescue of MITRE program 
CVE-2025-47938 
Patch Tuesday - May 2025 
Copyright office criticizes AI fair use before director s dismissal 
Patch Tuesday = 
China-Nexus Nation State Actors Exploit SAP NetWeaver (CVE-2025-31324) to Target Critical Infrastructures 
Dallas-based Bestow, which offers software and services to life insurance companies, raised a $120M Series D led by Goldman Sachs and Smith Point Capi 
Dallas-based Bestow, which offers underwriting and insurance software to carriers, raised a $120M Series D led by Goldman Sachs and Smith Point Capita 
Vendor-Agnostic Security: The Key To Smarter Risk Management 
Redefining IABs: Impacts of compartmentalization on threat tracking and modeling 
Defining a new methodology for modeling and tracking compartmentalized threats 
Using a Mythic agent to optimize penetration testing 
CVE-2025-4659 
CVE-2025-4672 
BSidesLV24 – GroundFloor – WHOIS The Boss? Building Your Own WHOIS Dataset For Reconnaissance 
What CIOs and CISOs Are Saying About Fake IT Workers: 4 Key Takeaways 
Six Ways Exposure Management Helps You Get Your Arms Around Your Security Tools 
20-Year-Old Proxy Botnet Network Dismantled After Exploiting 1,000 Unpatched Devices Each Week 
Security Affairs newsletter Round 523 by Pierluigi Paganini INTERNATIONAL EDITION 
Did LockBit Just Get Locked Out? The Walmart of Ransomware s Massive Leak 
Source: Tel Aviv-based AI21 Labs, which is building its own LLMs and launched an AI orchestration system in March, is raising a $300M Series D (Ben Be 
Senators move to quash the use of Chinese AI system by federal contractors 
If you own an AirTag, you need these accessories to maximize its potential 
The IT help desk kindly requests you read this newsletter 
Taming the Machine: Putting Security at the Core of Generative AI 
Measuring the US-China AI Gap 
CVE-2025-4473 
Multiple vulnerabilities in SonicWall SMA 100 series (FIXED) 
Stronger Cloud Security in Five: Securing Your Cloud Identities 
State of ransomware in 2025 
NSO Group must pay WhatsApp over $167M in damages for attacks on its users 
Trump calls on Colorado to release election-denying clerk from jail 
Google updates its iOS app to add a "Simplify" feature to simplify complex text in a Search result or Discover article, powered by its Gemin 
Unblocked, an AI-powered tool that helps devs understand codebases by answering contextual questions, raised a $20M Series A from B Capital and Radica 
New ‘Bring Your Own Installer (BYOI)’ technique allows to bypass EDR 
Data anonymization techniques defined: transforming real data into realistic test data 
My secret trick to easily share Wi-Fi passwords with guests (and why I can't go back) 
Ireland’s DPC fined TikTok 530M for sending EU user data to China 
How I make my own NFC tags to share my Wi-Fi password with guests - it's easy! 
Google's best AI research tool is getting its own app - preorder it now 
Cybersecurity Snapshot: CISA s Best Cyber Advice on Securing Cloud, OT, Apps and More 
RSAC 2025 Expo Recap: Goats, Puppies, and Threat Intelligence 
Memo: the US DOD seeks to secure right-to-repair provisions in Army contracts to access tools, software, and technical data without hindrance by IP co 
Memo: the US DOD seeks to secure right-to-repair provisions in Army contracts to access tools, software, and technical data without IP constraints (Re 
National Security Council cyber lead wants to normalize offensive operations 
CVE-2023-53084 
The best MP3 players of 2025 
Quantum computer threat spurring quiet overhaul of internet security 
Epic Games says it will take a 0% store fee from developers on their first $1M in revenue per app per year, and plans to let developers open their own 
Understanding the challenges of securing an NGO 
Epic Games says it will take a 0% store fee from developers on their first $1M in revenue per app per year, and plans to let developers launch own web 
Pinterest rolls out an "AI modified" label globally to indicate AI-generated or AI-edited images, identified via metadata analysis and its o 
State-of-the-art phishing: MFA bypass 
Why is Ransomware Still a Thing in 2025? 
Visualizing research in the age of AI 
Multi-agent path finding in continuous environments 
Visa partners with Stripe's Bridge to help fintechs launch their own stablecoin-linked card programs in multiple countries at once, starting in L 
Researchers Turned Azure Storage Wildcards into a Stealthy Internal SOCKS5 Backdoor 
Xiaomi unveils open-source AI reasoning model MiMo, joining other Chinese tech leaders hoping to make a splash in the burgeoning AI field endorsed by  
CVE-2025-46818 
RSAC 2025 Sets A Dangerous Precedent for Cybersecurity Leadership 
The AI Fix #48: AI Jesus, and is the AI Singularity almost upon us? 
House passes legislation to criminalize nonconsensual deepfakes 
Oligo researchers detail AirBorne, a set of vulnerabilities in Apple's AirPlay SDK that could affect 10M+ third-party devices; Apple has patched  
Oligo researchers detail AirBorne, a set of vulnerabilities in Apple's AirPlay SDK that may affect 10M+ third-party devices; Apple patched its ow 
Millions of Apple Airplay-Enabled Devices Can Be Hacked via Wi-Fi 
Driving down MTTR with Remediation Hub, Available in Rapid7 Exposure Command 
From Exposure to Assurance: Unified Remediation Across the Security Lifecycle 
2025 The International Year of Quantum Science and Technology 
Transforming Malware Defense for the AI Era 
Cybersecurity vendors are themselves under attack by hackers, SentinelOne says 
The best blood pressure watches of 2025: Expert tested 
How Breaches Start: Breaking Down 5 Real Vulns 
CVE-2025-4035 
CVE-2025-46733 
CVE-2025-46653 
Triada strikes back 
Adobe says Firefly users can now generate images using OpenAI's GPT, Google's Imagen 3 and Veo 2, and Flux 1.1 Pro, in addition to its own F 
Lessons from Ted Lasso for cybersecurity success 
THE NEW Rapid7 MDR for Enterprise: Tailored Detection and Response for Complex Environments 
Operation SyncHole: Lazarus APT goes back to the well 
Securing AI Innovation Without Sacrificing Pace – FireTail Blog 
CVE-2025-46551 
Can Hubble still hang? How the space telescope compares to its successors after 35 years of cosmic adventures 
Why red teaming matters even more when AI starts setting its own agenda 
Star Wars anime fans rejoice! 'Star Wars: Visions' returns for Volume 3, and 'The Ninth Jedi' is getting its own spin-off series 
From Noise to Action: Introducing Intelligence Hub 
Introducing ToyMaker, an Initial Access Broker working in cahoots with double extortion gangs 
AI can help defenders stop nation-state threat actors at machine speed 
Getting the Most Value Out of the OSCP: The Exam 
Not All Multipath Is Created Equal 
CVE-2025-44043 
Turn to Exposure Management to Prioritize Risks Based on Business Impact 
How Threat Intel Drives Smarter Security Spend 
Cybersecurity Snapshot: NIST Aligns Its Privacy and Cyber Frameworks, While Researchers Warn About Hallucination Risks from GenAI Code Generators 
Metasploit Wrap-Up 04 18 2025 
House investigation into DeepSeek teases out funding, security realities around Chinese AI tool 
Mobile Security – Emerging Risks in the BYOD Era 
Iran s AI Ambitions: Balancing Economic Isolation with National Security Imperatives 
TSMC CEO C. C. Wei says "TSMC is not engaged in any discussion with other companies regarding any joint venture", after a recent report of a 
IronHusky updates the forgotten MysterySnail RAT to target Russia and Mongolia 
CVE-2025-43861 
CVE-2025-43856 
Frequently Asked Questions About the MITRE CVE Program Expiration and Renewal 
CVE Program Almost Unfunded 
CISA reverses course, extends MITRE CVE contract 
Microsoft adds a "computer use" tool in Copilot Studio to let AI agents use websites and desktop apps; the feature is designed to detect UI  
Chinese Android phones shipped with malware-laced WhatsApp, Telegram apps 
Germany's military wants its own Starlink-like satellite constellation 
Funding Expires for Key Cyber Vulnerability Database 
CVE-2025-38117 
CVE-2025-37843 
CVE-2025-38453 
CVE-2025-42967 
CVE-2022-49765 
CVE-2025-39915 
CVE-2025-38037 
CVE-2025-41067 
CVE-2022-49769 
CVE-2025-40337 
CVE-2025-38502 
In the first update to its Preparedness Framework since 2023, OpenAI says it "may adjust" its own safeguards if rival frontier labs release  
RansomHouse ransomware: what you need to know 
OpenAI to launch AI models that can think up their own experiments, says report 
Sources: OpenAI is in the early stages of building its own X-like social network, focused on ChatGPT image generation, and is asking some outsiders fo 
Top Four Considerations for Zero Trust in Critical Infrastructure 
Trump Revenge Tour Targets Cyber Leaders, Elections 
CVE-2025-36747 
CVE-2025-34209 
CVE-2025-36087 
CVE-2025-33100 
CVE-2025-34298 
CVE-2025-32988 
CVE-2025-34283 
An affordable Windows laptop with great specs for work travel? I found the one to buy 
Sapphire Ticket Attack: Abusing Kerberos Trust 
China admitted its role in Volt Typhoon cyberattacks on U.S. infrastructure 
Google says some terms in AI Overviews will link to Google's search results "to help people more easily explore topics and discover relevant 
Google Eyes User Browsing Data Search in New Patent Filing 
China-based SMS Phishing Triad Pivots to Banks 
WordPress' new AI website builder helps you quickly create your own site - and it's free 
Navigating PCI DSS 4.0 Compliance: How Automated Data Discovery Can Help 
Unraveling the U.S. toll road smishing scams 
An APT group exploited ESET flaw to execute malware 
GOFFEE continues to attack organizations in Russia 
BadBazaar and Moonshine malware targets Taiwanese, Tibetan and Uyghur groups, U.K. warns 
BadBazzar and Moonshine malware targets Taiwanese, Tibetan and Uyghur groups, U.K. warns 
Nearby exoplanet could offer clues about atmospheres around hot, rocky alien worlds 
Apple Pay and security - what you need to know 
Italy says it is withdrawing its support for STMicro CEO Jean-Marc Chery and his management team as chip demand slumps; Italy and France own nearly 28 
How to Delete a Netflix Profile on TV, Mobile & Desktop 
Building Resiliency in Critical Infrastructure Networks Using Microsegmentation: Lessons Learned in the Real World 
The Renaissance of NTLM Relay Attacks: Everything You Need to Know 
Tech experts recommend full steam ahead on US export controls for AI 
Patch Tuesday - April 2025 
2025 Ransomware: Business as Usual, Business is Booming 
Attackers distributing a miner and the ClipBanker Trojan via SourceForge 
I found an affordable OLED laptop with great specs for work and travel - and it's on sale 
Google hopes its experimental AI model can unearth new security use cases 
5 expert-backed tips to get better sleep - especially if you own a health-tracking wearable 
The controversial case of the threat actor EncryptHub 
How ToddyCat tried to hide behind AV software 
AD Certificate Exploitation: ESC1 
Expert used ChatGPT-4o to create a replica of his passport in just 5 minutes bypassing KYC 
A flaw in Verizon s iOS Call Filter app exposed call records of millions 
Trump EO Presses States to Bear the Weight of CI Resilience 
When AI Agents Start Whispering: The Double-Edged Sword of Autonomous Agent Communication 
Cyber Forensic Expert in 2,000+ Cases Faces FBI Probe 
Top Crypto Wallets of 2025: Balancing Security and Convenience 
Vimeo launches Vimeo Streaming, letting creators launch subscription streaming services without any coding experience and offering features like AI tr 
Vimeo launches Vimeo Streaming, letting creators launch subscription streaming services without coding experience and with features like AI-driven tra 
By embracing Trump, Big Tech risks losing access to Europe, pushing Europe to build its own companies and platforms as Chinese companies try to expand 
Pentales: Red Team vs. N-Day (and How We Won) 
Big Tech risks losing access to Europe by embracing Trump, pushing Europe to build its own companies and platforms and letting Chinese companies expan 
A journey into forgotten Null Session and MS-RPC interfaces, part 2 
CVE-2025-3278 
How To Harden GitLab Permissions with Tenable 
Elon Musk's X and xAI all-stock merger broke Wall Street's rulebook by having the same advisers, Morgan Stanley and Sullivan & Cromwell, 
Elon Musk's X and xAI all-stock merger broke Wall Street's usual rules, with the same advisers, Morgan Stanley and Sullivan & Cromwell,  
Wiz s Security GraphDB vs. DeepTempo s LogLM 
Democratic groups sue to block Trump administration s elections order 
Cryptocurrency billionaire watches SpaceX rocket launch on the way to his own SpaceX rocket launch 
The best Google Pixel phones to buy in 2025: Expert Tested 
France s antitrust authority fines Apple 150M for issues related to its App Tracking Transparency 
Why delaying software updates is a terrible idea 
5 Impactful AWS Vulnerabilities You're Responsible For 
This newly found super-Earth might have blown off its own atmosphere 
How Each Pillar of the 1st Amendment is Under Attack 
CVE-2025-3026 
Prolific fintech VC and QED Investors co-founder Frank Rotman says he will become partner emeritus by the end of 2025 and focus on launching his own s 
Experts warn of the new sophisticate Crocodilus mobile banking Trojan 
I cracked open a cheap 600W charger to test its build, and the 'goo' inside was not right 
ClickFix: Social Engineering That Bypasses EDRs, SWGs and Humans 
Building with Bitcoin: A Survey of the Use of Its Scripting System Across Projects 
Gemini hackers are using its own tools against it - Android Authority 
The Return of the Baby ASO: Why SOCs Still Suck? 
Are wind power generators actually viable at home? I tested one (and it's on sale right now) 
Hundreads of orgs targeted 
2 newly found exoplanets reignite an outstanding question about our solar system 
Anthropic is expanding Claude AI to the enterprise with domain-specific AI agents 
Takeaways after using AI search exclusively for one month: AI search is more of a UX revamp than a replacement for Google's blue links-based web  
Anthropic and Databricks ink a five-year deal, expected to jointly generate $100M in revenue, by selling AI tools to businesses developing their own A 
You can access free Gemini Gems on Android and iOS now - where to find them 
New ReaderUpdate malware variants target macOS users 
Commerce limits 19 Chinese, Taiwanese companies from buying U.S. tech 
Do You Own Your Permissions, or Do Your Permissions Own You? 
Sources: Fidelity Investments is in the advanced stages of testing its own stablecoin, managed by its digital assets arm; Trump pledged to back USD st 
Sources: Fidelity Investments is in the advanced stages of testing its own stablecoin, managed by its digital assets arm, as Trump pledges to back sta 
This IKEA Hack Is Giving Me Major Inspo for My Own Awkward Dining Room Corner - Apartment Therapy 
Introducing Agentic Risk Scoring | Impart Security 
Getting the Most Value Out of the OSCP: The PEN-200 Labs 
Privacy Roundup: Week 12 of Year 2025 
Despite challenges, the CVE program is a public-private partnership that has shown resilience 
How Businesses Can Turn the Expanding Attack Surface into an Opportunity 
Security Affairs newsletter Round 516 by Pierluigi Paganini INTERNATIONAL EDITION 
Sources: Apple plans to build its own AI models for Visual Intelligence and add cameras to the Watch; the redesigned plastic Apple Watch SE faces seri 
Arrests in Tap-to-Pay Scheme Powered by Phishing 
Medusa Ransomware Uses Malicious Driver to Disable Anti-Malware with Stolen Certificates 
Tomorrow, and tomorrow, and tomorrow: Information security and the Baseball Hall of Fame 
The 10 best space RPGs of all time: Explore the galaxy in these stellar role-playing games 
CERT-UA warns of cyber espionage against the Ukrainian defense industry using Dark Crystal RAT 
DOGE to Fired CISA Staff: Email Us Your Personal Data 
CVE-2025-2578 
Trump moves to fire Democratic FTC commissioners 
Trump 2.0 Brings Cuts to Cyber, Consumer Protections 
How Phished Data Turns into Apple & Google Wallets 
Who is the DOGE and X Technician Branden Spikes? 
Microsoft: 6 Zero-Days in March 2025 Patch Tuesday 
2024 Annual Report 
Stimmen aus Moskau: Russian Influence Operations Target German Elections 
How Security Leaders Defend Their First- and Third-Party Attack Surfaces 
MDR + SIEM: Why Full Access to Your Security Logs is Non-Negotiable 
Why MDR In 2025 Is About Scaling With Purpose 
Inside the Take Command Summit 2025 Agenda: What s in Store for This Year s Event? 
Building a High Performance Team in India: Meet Swami Nathan 
Patch Tuesday - March 2025 
Sending billions of daily requests without breaking things with our rate limiter 
Inside the tech that continuously monitors our customers’ attack surface 
How to Prevent a Subdomain Takeover in Your Organization 
DNS is the center of the modern attack surface – are you protecting all levels? 
Introducing Alfred for fully autonomous AI-built vulnerability assessments 
Making security a business value enabler, not a gatekeeper 
Denmark warns of increased state-sponsored campaigns targeting the European telcos 
California s legal push on geolocation data collection must take aim at the right targets, privacy experts say 
Cloudflare rolls out post-quantum encryption for enterprise users 
Robot Talk Episode 92 – Trust and acceptance of robots, with Gisela Reyes-Cruz 
AI moves to your PC with its own special hardware 
Head Mare and Twelve join forces to attack Russian entities 
Your item has sold! Avoiding scams targeting online sellers 
Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools 
Who is Responsible and Does it Matter? 
Abusing with style: Leveraging cascading style sheets for evasion and tracking 
Patch it up: Old vulnerabilities are everyone s problems 
Shadow Credentials Attack 
On Cybersecurity Mentorship 
CVE-2025-30144 
CVE-2025-27818 
CVE-2025-27146 
CVE-2025-27167 
CVE-2025-25732 
CVE-2025-25568 
CVE-2025-0867 
CVE-2025-24888 
CVE-2025-24887 
CVE-2025-24860 
CVE-2024-13724 
CVE-2025-24784 
CVE-2024-13537 
CVE-2024-13539 
CVE-2024-13536 
CVE-2024-13538 
CVE-2024-13535 
CVE-2025-24365 
CVE-2024-13540 
Do we still have to keep doing it like this? 
CVE-2025-23197 
CVE-2025-23168 
In a first, an EU court fines the EC €400 for breaching its own data protection rules by transferring a citizen's data to the US via &qu 
In a first, an EU court fines the EC €400 for breaching its own data protection law by transferring a user's data to the US via a Sign i 
National Cyber Director Harry Coker looks back (and ahead) on the Cyber Director office 
A Day in the Life of a Prolific Voice Phishing Crew 
ADFS Living in the Legacy of DRS 
Mitigating CVE exploitations: Putting the rapid into rapid response 
CVE-2025-22601 
CVE-2025-22609 
The Connectivity Standards Alliance announces that Apple, Google, and Samsung will accept its Matter certification for their own "Works With" 
AMD's next mobile chipset promises to provide faster 3D rendering than Apple's M4 Pro 
Uber and Lyft are embracing autonomous vehicle operators like Waymo, May Mobility, and others, after abandoning developing their own driverless taxis  
Uber and Lyft are embracing autonomous vehicle operators like Waymo, May Mobility, and others, after abandoning their own self-driving car programs (P 
EAGERBEE, with updated and novel components, targets the Middle East 
Exit interview: FCC s Jessica Rosenworcel discusses her legacy on cybersecurity, AI and regulation 
Metasploit 2024 Annual Wrap-Up 
Eating Your Own Dog Food 
Russian media outlets Telegram channels blocked in European countries 
CVE-2025-22271 
CVE-2025-0177 
Elon Musk got new support for his OpenAI lawsuit in filings last week, including from tech advocacy group Encode, backed by AI researchers like Geoffr 
Top CVEs & Vulnerabilities of December 2024 
U.S. Army Soldier Arrested in AT&T, Verizon Extortions 
Johns Hopkins and Stanford researchers say they trained robots with videos to perform surgical tasks with the skill of human doctors, even correcting  
As Tether says it is on track for a record $10B net profit in 2024, banks around the world are exploring launching their own stablecoins for payments  
Minimizing CISO personal liability through end of year budgeting 
Happy 15th Anniversary, KrebsOnSecurity! 
CVE-2025-21939 
CVE-2025-21644 
CVE-2025-21952 
CVE-2025-21664 
CVE-2025-21684 
CVE-2025-21632 
CVE-2025-21710 
CVE-2025-21768 
CVE-2025-21884 
CVE-2024-56694 
CVE-2024-56678 
CVE-2024-56714 
How to generate your own music with the AI-powered Suno 
Build Your Own Cat-Themed Hacking Console (with DevKitty!) - Hackster.io 
How to use Microsoft's Copilot AI on Linux 
U.S. Court rules against NSO Group in WhatsApp spyware Lawsuit 
How to create your own Bluesky domain - and why I recommend it 
Feds lay blame while Chinese telecom attack continues 
Cloud Atlas seen using a new tool in its attacks 
I converted this Windows 11 Mini PC into a Linux workstation - and didn't regret it 
This midrange Yamaha soundbar holds its own against systems that are twice its price 
Exploring vulnerable Windows drivers 
IAM Predictions for 2025: Identity as the Linchpin of Business Resilience 
CVE-2024-56335 
This hidden Apple feature turns your iPhone or iPad into an AI image generator 
What s New in Rapid7 Products & Services: Q4 2024 in Review 
Irish Data Protection Commission (DPC) fined Meta 251 million for a 2018 data breach 
How to use Apple's Genmoji to create your own custom emoji 
Detectify year in review 2024 
Take Command of Your Career: Practicing Self-Advocacy as a Woman in Tech 
Data Security Predictions for 2025: Putting Protection and Resilience at Center Stage 
CVE-2024-54681 
Hack a Roland P-6 pocket sampler with its own amp and speaker - Create Digital Music 
James Webb Space Telescope witnesses Firefly Sparkle galaxy 'being assembled brick by brick' (image, video) 
PHP backdoor looks to be work of Chinese-linked APT group 
I converted this Mini PC from Windows to Linux, and it came alive. Here's how 
Worry About Misuse of AI, Not Superintelligence 
Dark web threats and dark market predictions for 2025 
Addressing BYOD Vulnerabilities in the Workplace 
In a blog post, OpenAI says "You can't sue your way to AGI", and publishes emails from Elon Musk showing he wanted to own OpenAI and ru 
The EU finds it breached its own privacy rules in a 2023 ad campaign on X that intended to sway opinions for a proposal to force messaging apps to sca 
U.S. authorities seized cybercrime marketplace Rydox 
Oklahoma's Own In Focus: Hackers Targeting SNAP Benefits, Leaving Families in Financial Bind. Here's How To Protect Your Info - News On 6 
CVE-2024-55963 
Sources: Apple plans to roll out its own Wi-Fi and Bluetooth chip as part of Apple TV and HomePod mini updates in 2025, and in iPhones later in the ye 
Careto is back: what’s new after 10 years of silence? 
Russia’s Secret Blizzard APT targets Ukraine with Kazuar backdoor 
Binance and Circle partner to promote USDC; Binance plans to list more crypto trading pairs denominated in USDC and hold USDC for its own corporate tr 
How Cryptocurrency Turns to Cash in Russian Banks 
'We are preparing to make history': NASA's Parker Solar Probe gears up for epic sun flyby on Christmas Eve 
'We are preparing to make history:' NASA's Parker Solar Probe gears up for epic sun flyby on Christmas Eve 
Modular Java Backdoor Dropped in Cleo Exploitation Campaign 
Turla living off other cybercriminals tools in order to attack Ukrainian targets 
New CISA Hardening Guidance Provides Valuable Insights for Network Security Engineers 
Latest round of MITRE ATT&CK evaluations put cybersecurity products through rigors of ransomware 
Exxon says it is in the early stages of designing a natural gas plant for data centers, the first time it would build a plant not supplying its own op 
Why Americans must be prepared for cybersecurity s worst 
Join Costco and get a $45 gift card with your membership - the best deal this year 
Wyden legislation would mandate FCC cybersecurity rules for telecoms 
The best blood pressure watches of 2024: Expert tested 
The Resilience Dilemma 
Steady leadership prepares TSA to face evolving cyber threats 
Sources: in October 2024, EU regulators asked Google for more information on its secret ads deal with Meta which skirted Google's own rules for t 
Cybersecurity Companies Must Practice What They Preach to Avoid the Data Paradox 
Sources: in October, EU regulators asked Google for more information about its secret ads deal with Meta which skirted Google's own rules for tar 
Sources: EU regulators asked Google for more info in October about a secret ads partnership with Meta which skirted Google's own rules for target 
Reddit says it is testing Reddit Answers, which lets select US users ask questions and receive curated summaries of relevant responses and threads in  
Prepare for 2025 with This CompTIA Training Bundle for $50 
Reddit says it is testing Reddit Answers to let select US users ask questions and receive curated summaries of relevant responses and threads in Engli 
A look at chipmaker Marvell, whose market cap surpassed Intel's, driven by its data center business; CEO Matt Murphy has reportedly been floated  
A look at Marvell, a chipmaker whose market cap surpassed Intel's, driven by its data center business; CEO Matt Murphy is reportedly been floated 
CVE-2024-12369 
CVE-2024-12390 
Join Costco and get a $45 gift card with your membership right now 
Sources: with its own modem in the pipeline, Apple is investigating bringing cellular connectivity to the Mac and headsets like Vision Pro for the fir 
Cybersecurity Snapshot: Study Raises Open Source Security Red Flags, as Cyber Agencies Offer Prevention Tips Against Telecom Spying Attacks 
Russian Hackers Hijacked Pakistani Actor Servers For C2 Communication 
Rapid7 Extends Cloud Security Capabilities with Updates to Exposure Command 
Exploits and vulnerabilities in Q3 2024 
NSFOCUS s Coogo: An Automated Penetration Testing Tool 
CVE-2024-55070 
CVE-2024-55073 
CVE-2024-55072 
How to create your own Bluesky domain - and why you should (or shouldn't) 
She Escaped An Abusive Marriage Now She Helps Women Battle Cyber Harassment 
Russia-linked APT Secret Blizzard spotted using infrastructure of other threat actors 
Our secret ingredient for reverse engineering 
Microsoft and Lumen's Black Lotus Labs researchers find Russia-linked Turla hackers are hijacking Pakistan-based hackers' servers to launch  
Analyzing Tokenizer Part 2: Omen + Tokenizer 
CVE-2024-12281 
Russia-Linked Turla Exploits Pakistani Hackers' Servers to Target Afghan and Indian Entities 
Russian hackers hijack Pakistani hackers' servers for their own attacks - BleepingComputer 
Russian-linked Turla caught using Pakistani APT infrastructure for espionage 
Join Costco and get a $45 gift card with your membership - the best deal of the year 
Inside a new initiative to lend cybersecurity volunteers to organizations that need it most 
One of the most portable power stations I've tested 
I recommend this $50 anti-spy camera finder to anyone traveling 
CVE-2024-12099 
The Cruel Twist: When Fake Firing Leads to Real Hacking 
Notorious ransomware developer charged with computer crimes in Russia 
Talk about an own goal - Bologna FC hit by ransomware hackers - TechRadar 
I recommend this $60 anti-spy camera finder to anyone traveling (get 38% off for Cyber Monday) 
Join Costco and get a $45 gift card with your membership -- the best deal this year 
Join Costco and get a $45 gift card with your membership -- the best deal we've seen 
Sources: ByteDance execs fear that launching its own AI models, or apps powered by the models, in the US could give lawmakers another excuse to attack 
This clever Bluetooth device lets you use your own headphones for in-flight movies (and it's 20% off) 
IT threat evolution Q3 2024 
I've tested dozens of power banks. This one is in a class of its own and you can get it for $85 
How Altera deployed up to 1,000 AI agents that used LLMs to interact in Minecraft, finding that they formed a remarkable range of personality traits a 
Experience the galaxy in your own home for less this Black Friday with 30% off this Govee Star Light Projector 
From 6th Ave to space: Haribo gummi candies blast off into Macy's Thanksgiving Day Parade 
APT trends report Q3 2024 
Filing: Intel's $7.86B US government subsidy requires the company to own at least 50.1% of Intel Foundry if the unit is split into a new privatel 
Nearest neighbor attack 
Appeals court tosses sanctions on Tornado cash crypto mixer 
Pro-Russian Hacktivists Launch Branded Ransomware Operations 
I recommend this $60 anti-spy camera finder to anyone traveling (get 38% off for Black Friday) 
Best Black Friday gaming PC deals 2024: Live sales on prebuilt PCs, GPUs, monitors, and more 
Best Black Friday gaming PC deals 2024: Sales live now on prebuilt PCs, GPUs, monitors, and more 
CVE-2024-11951 
Sources: Xiaomi prepares its own mobile chip for its smartphones, to reduce reliance on Qualcomm and MediaTek, with mass production expected to begin  
Join Costco and get a $45 gift card with your membership - the best deal yet 
James Webb Space Telescope 'pushed to its limits' to see most distant galaxies ever 
Walking the Walk: How Tenable Embraces Its “Secure by Design” Pledge to CISA 
This E Ink tablet revived my inspiration, and it's on sale for $60 off 
Finding vulnerabilities in ClipSp, the driver at the core of Windows Client License Platform 
An opportunity for Trump s deregulation journey: Cybersecurity harmonization 
Malware campaign abused flawed Avast Anti-Rootkit driver 
Advanced threat predictions for 2025 
Researchers Uncover Malware Using BYOVD to Bypass Antivirus Protections 
Thoughts on Apple TV's history and future; sources: Apple postponed a larger-than-usual number of iOS 19 features to spring 2026, when iOS 19.4 i 
Thoughts on Apple TV's history and future; sources: a larger-than-usual number of features scheduled for iOS 19 have been postponed to iOS 19.4 i 
Microsoft seized 240 sites used by the ONNX phishing service 
Kansas City hacker used computer intrusion to pitch his own security services: prosecutors - Kansas City Star 
The Scale of Geoblocking by Nation 
Cybersecurity Snapshot: Prompt Injection and Data Disclosure Top OWASP s List of Cyber Risks for GenAI LLM Apps 
One of the most portable power stations I've tested is $200 off for Black Friday 
CVE-2024-53848 
Sources: Amazon will likely face an EU investigation next year into whether it breaches the DMA by favoring its own brand products on its online marke 
Rabbit releases its teach mode in beta for all R1 users, letting them create and ask their own AI agents to automate tasks on websites (Igor Bonifacic 
Enhancing Cyber Resilience: Insights from CISA Red Team Assessment of a US Critical Infrastructure Sector Organization 
Privacy-focused mobile phone launches for high-risk individuals 
Decade-old local privilege escalation bugs impacts Ubuntu needrestart package 
Threads lets you create your own custom feeds now, just like Bluesky - here's how 
Microsoft announces its own Black Hat-like hacking event with big rewards for AI security - TechRadar 
Threads begins rolling out the ability to create custom feeds globally, giving users options beyond "For You" and "Following" feed 
Malicious QR Codes: How big of a problem is it, really? 
Join Costco and get a $45 gift card with your membership - the best deal we've seen 
Malicious QR codes 
Ransomware is doubling down What you need to know about the recent surge 
Bipartisan Senate bill targets supply chain threats from foreign adversaries 
Unraveling Raspberry Robin's Layers: Analyzing Obfuscation Techniques and Core Mechanisms 
Sources: Apple has started selling its own ad inventory for Apple News; publishers will get a 70% cut of the ad revenue generated by Apple within thei 
The AI Fix #25: Beware of the superintelligence, and a spam-eating AI super gran 
Attackers are hijacking Jupyter notebooks to host illegal Champions League streams 
Microsoft announces its own Black Hat-like hacking event with big rewards for AI security - The Verge 
Scammer Black Friday offers: Online shopping threats and dark web sales 
Scammer Black Friday offers: Online shopping threats and dark web 
CVE-2024-53140 
CVE-2024-53253 
Vulnerability Summary for the Week of November 11, 2024 
Is Apple finally going to make a TV set? Maybe. Here's what it'll depend on 
5 ways to use Google Scholar to supercharge your research efforts 
Q&A with The Verge EIC Nilay Patel on a likely FCC Chair Brendan Carr, Elon Musk's alliance with Donald Trump and how it threatens the First  
Q&A with The Verge EIC Nilay Patel on upcoming FCC chair Brendan Carr, the alliance between Trump and Musk and how it threatens the First Amendmen 
Increased GDPR Enforcement Highlights the Need for Data Security 
Analyzing JtR’s Tokenizer Attack (Round 1) 
I recommend this $60 anti-spy camera finder to anyone traveling (and it's 38% off for Black Friday) 
I recommend this $60 anti-spy camera finder and bug detector to anyone traveling (get 38% off in this Back Froday deal!) 
Join Costco and get a $20 gift card with your membership right now 
CVE-2024-52887 
NSO Group used WhatsApp exploits even after Meta-owned company sued it 
Musk v. Altman: email shows Brockman and Sutskever had concerns about Altman in 2017, Musk claims Altman proposed OpenAI sell its own cryptocurrency,  
Glove Stealer bypasses Chrome s App-Bound Encryption to steal cookies 
Can't find the perfect stock photo? Create you own with Getty Images' AI tool 
Filing: Samsung plans to buy back about $7.2B of its own stock in stages over the next year, in one of the larger shareholder return programs in its h 
CVE-2024-11265 
HackerOne urges U.S. to advocate for research protections in UN cybercrime treaty 
Blinded by Silence 
Join Costco right now and get a $20 gift card with your membership 
How Grab built GrabMaps by using data from drivers, users, and merchants in 500+ Southeast Asian cities, adding 800,000+ km of missing roads to OpenSt 
Online hands-on science communication training sign up here! 
Iranian Hackers Use "Dream Job" Lures to Deploy SnailResin Malware in Aerospace Attacks 
Sealing Entry Points and Weak Links in the Environment – How Dell is Building an Iron Wall of Defense 
SabersPro Vader lightsaber review: "An elegant replica that doesn't come cheap" 
Vulnerability Summary for the Week of November 4, 2024 
United States of America Veterans Day 2024 
Join Costco and get a $20 gift card with your membership with this deal 
CVE-2024-52516 
Meta, OpenAI, Microsoft, and other AI companies have created their own internal benchmarks for AI as new models approach or exceed 90% accuracy on pub 
The 249th United States Marine Corps Birthday: A Message From The Commandant Of The Marine Corps 
Meta, OpenAI, Microsoft, and other AI companies create their own internal benchmarks as new models approach or exceed 90% accuracy on existing public  
China planning to build its own version of SpaceX's Starship 
UnifyApp, which lets companies build their own AI chatbots by connecting their SaaS apps and data, raised a $20M Series A, around six months after a $ 
QSC: A multi-plugin framework used by CloudComputating group in cyberespionage campaigns 
CVE-2024-11023 
Context Is King: From Vulnerability Management to Exposure Management 
Avoiding Blocklistings: Part 3 – Take Matters into Your Own Hands to Protect Your Senders 
Cathal O Neill - Taking Command of Your Career in Tech 
Congress must demand a study of America s cyber forces 
CVE-2025-21056 
CVE-2025-21065 
False bomb threats at polling sites only blemish on Election Day voting process 
Canadian Man Arrested in Snowflake Data Extortions 
German Police Disrupt DDoS-for-Hire Platform dstat[.]cc; Suspects Arrested 
CVE-2024-52008 
CVE-2024-51997 
Why Bluesky not adding the federation systems that would let users leave the Bluesky server and take their community to other hosts can cause "en 
Why Bluesky not adding the federation systems that let users leave the Bluesky server and take their community to other hosts can lead to "enshit 
Join Costco and get a $20 gift card - here's how 
Booking.com Phishers May Leave You With Reservations 
Finding the LNK: Techniques and methodology for advanced analysis with Velociraptor 
SmokeBuster: Keeping Systems SmokeLoader Free 
Join Costco and get a $20 gift card with your membership - here's how 
Sophos details a five-year battle with Chinese hackers exploiting its firewalls, and how its device "implants" traced the hacks to a univers 
Kuo: Apple plans to use its own Wi-Fi and Bluetooth chips made by TSMC's N7 process and with Wi-Fi 7 in the iPhone 17 lineup, reducing its relian 
Inside Sophos' 5-Year War With the Chinese Hackers Hijacking Its Devices 
CVE-2024-51735 
DEF CON 32 – AppSec Village – Navigating The Cyber Security Labyrinth Choose Your Own Security Adventure 
Legal barriers complicate justice for spyware victims 
Ubisoft quietly debuted its first blockchain game, Champions Tactics: Grimoria Chronicles, for free on PC last week; in-game figurines are listed for  
Change Healthcare Breach Hits 100M Americans 
Ubisoft quietly launches its first blockchain game, Champions Tactics: Grimoria Chronicles, available for free on PC; in-game figurines cost $7 to $63 
Risk reduction redefined: How compromise assessment helps strengthen cyberdefenses 
Pixelfed's founder creates Loops, a fediverse TikTok competitor set to go open-source and integrate with ActivityPub, now accepting signups and u 
This E Ink tablet revived my inspiration, and it's on sale for $50 off 
Vulnerability Summary for the Week of October 21, 2024 
Cybersecurity Awareness Month: Gamifying Cybersecurity Training 
Loops, a fediverse TikTok competitor, begins accepting signups, plans to become open-source and integrate with ActivityPub, and seeks user donations ( 
Third-Party Identities: The Weakest Link in Your Cybersecurity Supply Chain 
CVE-2024-51324 
Join Costco and get a $20 gift card with your membership right now - here's how 
Mastering Cybersecurity: A Comprehensive Guide to Self-Learning 
'Star Trek: Lower Decks' scores an inventive interactive graphic novel, 'Warp Your Own Way' 
5 helpful Alexa routines I rely on every day - and how to easily build your own 
Change Healthcare breach affected 100 million Americans, marking a new record 
Building a Custom Risk Prioritization and Risk Scoring Methodology with Surface Command 
In a post, Perplexity criticizes media companies that have sued over AI, saying they wish AI tools didn't exist and prefer that corporations own  
HYPR is latest firm to reveal hiring of fraudulent IT worker overseas 
Apple now lets third-party browsers add web apps to an iPhone's Home Screen using their own custom engine in the EU in iOS 18.2 beta 1 (Filipe Es 
Join Costco now and get a $20 gift card with your membership - here's how 
Raspberry Pi just released its own high-performance SSDs and SSD kits 
The Global Surveillance Free-for-All in Mobile Ad Data 
The Crypto Game of Lazarus APT: Investors vs. Zero-days 
Joseph Gordon-Levitt criticizes AI, calling Hollywood a "canary in the coal mine" for other industries, and says studios "own the IP an 
Cybersecurity Awareness Month: How We Continuously Improve Security Practice 
North Korean IT Worker Threat: 10 Critical Updates to Your Hiring Process 
Vulnerability Summary for the Week of October 14, 2024 
Join Costco and get a $20 gift card - here's how 
CVE-2024-50066 
CVE-2024-50174 
CVE-2024-50116 
CVE-2024-50230 
CVE-2024-49806 
CVE-2024-49805 
Brazil Arrests ‘USDoD,’ Hacker in FBI Infragard Breach 
macOS HM Surf flaw in TCC allows bypass Safari privacy settings 
Sources describe OpenAI and Microsoft's fraying relationship, OpenAI renegotiating its deal for more computing power, Microsoft's own LLM ef 
One of the most portable power stations I've tested is $200 off right now 
What I ve learned in my first 7-ish years in cybersecurity 
Abusing AD-DACL : Generic ALL Permissions 
Own a business? Apple will let you display your logo icon in iPhone calls 
CVE-2024-49616 
Pyongyang on the payroll? Signs that your company has hired a North Korean IT worker 
Brazil’s Pol cia Federal arrested the notorious hacker USDoD 
Test Driving a New Benefit Programme in Belfast 
Iranian Cyber Actors Brute Force and Credential Access Activity Compromises Critical Infrastructure Organizations 
Vulnerability Summary for the Week of October 7, 2024 
More Details on Israel Sabotaging Hezbollah Pagers and Walkie-Talkies 
In a report citing experts, China rejects US and Microsoft claims that Chinese hackers were behind Volt Typhoon, calling the claims a "political  
China Accuses U.S. of Fabricating Volt Typhoon to Hide Its Own Hacking Campaigns 
China Accuses U.S. of Fabricating Volt Typhoon to Hide Its Own Hacking Campaigns - The Hacker News 
In a report citing experts, China's cybersecurity agency rejects US and Microsoft claims that Chinese hackers were behind Volt Typhoon as a " 
In a report, China's cybersecurity agency rejects US and Microsoft claims that Chinese hackers were behind Volt Typhoon, calling the claims a &qu 
CVE-2020-36838 
Matt Mullenweg responds to DHH's claim that "Automattic is doing open source dirty", pointing out Rails' own trademark policy and  
How satellites are pushing security innovation at Amazon 
The E Ink tablet that revived my inspiration is not a ReMarkable or Amazon Kindle 
Apple to counter new Meta products with its own cheaper headset 
How Exertis and Seceon Are Redefining Cybersecurity for MSPs: A Partnership Built on Innovation 
Happy United States of America Indigenous Peoples’ Day 
Hacker confesses he stole his own brother's identity in taunting letter to 7 On Your Side, challenges ABC7 to help victim - ABC7 Bay Area 
Sources: Microsoft plans to test the ability to stream games that users own but aren't in the Xbox Game Pass library, starting with Xbox Insiders 
Sources: Microsoft plans to test the streaming of games that users own and are not part of the Xbox Game Pass library, starting with Xbox Insiders in  
IronNet Has Shut Down 
PayPal launches PayPal Ads, meant to help US marketers tap into data about the billions of transactions across PayPal's platforms, including Venm 
CVE-2024-48991 
PayPal formally launches PayPal Ads, which looks to help US marketers tap into data about transactions across PayPal's platforms, including Venmo 
Marriott agrees to pay $52 million settlement, improve data security practices 
Sign up for Costco and get a free $20 gift card with this deal - here's how 
CVE-2024-48953 
CVE-2025-20341 
CVE-2025-20139 
OpenAI says it has disrupted 20-plus foreign influence networks in past year 
Cybercriminals Are Targeting AI Conversational Platforms 
MediaTek unveils the 3nm Dimensity 9400 mobile SoC, featuring a CPU with eight "big" cores and its own 8th-gen NPU, claiming 80% "faste 
Court filing: OpenAI says Elon Musk's "altruism versus greed" lawsuit is part of his "blusterous campaign to harass OpenAI for his 
MediaTek announces the 3nm Dimensity 9400 mobile chip, which features its own 8th-gen NPU, claiming "80 percent faster large language model promp 
CVE-2024-48924 
Marketing tech company Zeta Global agrees to acquire LiveIntent, another marketing tech provider, for $250M in cash and stock, in a deal set to close  
Marketing tech company Zeta Global agrees to buy LiveIntent, another marketing tech provider, for $250M in cash and stock in a deal expected to close  
Securing Teradata VantageCloud Lake to Ensure Data Security, Compliance, and Sovereignty 
Vulnerability Summary for the Week of September 30, 2024 
Critical Apache Avro SDK RCE flaw impacts Java applications 
Sign up for Costco and get a free $20 gift card - here's how 
CVE-2024-9598 
Exclusive: Kevin Mandia joins SpecterOps as chair of the board 
Multinational police effort hits sections of Lockbit ransomware operation 
America’s allies are shifting: Cyberspace is about persistence, not deterrence 
Former Mesa County clerk sentenced to 9 years for 2020 voting system breach 
Robot Talk Episode 92 – Gisela Reyes-Cruz 
U.S. Indicts 2 Top Russian Hackers, Sanctions Cryptex 
Timeshare Owner? The Mexican Drug Cartels Want You 
A Single Cloud Compromise Can Feed an Army of AI Sex Bots 
Key Group: another ransomware group using leaked builders 
Scam Information and Event Management 
Multiple Vulnerabilities in Common Unix Printing System (CUPS) 
Modernizing Your VM Program with Rapid7 Exposure Command: A Path to Effective Continuous Threat Exposure Management 
Ransomware Groups Demystified: CyberVolk Ransomware 
How the FBI and Mandiant caught a serial hacker who tried to fake his own death - TechCrunch 
Vulnerability Summary for the Week of September 23, 2024 
Targets, Objectives, and Emerging Tactics of Political Deepfakes 
Simple Mail Transfer Pirates: How threat actors are abusing third-party infrastructure to send spam 
CISA is warning us (again) about the threat to critical infrastructure networks 
Are hardware supply chain attacks cyber attacks?  
Microsoft and DOJ seized the attack infrastructure used by Russia-linked Callisto Group 
Security Affairs newsletter Round 492 by Pierluigi Paganini INTERNATIONAL EDITION 
CVE-2024-47867 
CVE-2024-47882 
CVE-2024-9546 
CVE-2024-47741 
CVE-2024-47765 
CVE-2024-47736 
CVE-2024-9180 
UNC1860 and the Temple of Oats: Iran’s Hidden Hand in Middle Eastern Networks 
Adversaries generative AI use isn t fooling the masses 
Harmonic, a startup co-founded by Robinhood CEO Vlad Tenev that aims to build AI better at math than humans, raised a $75M Series A at a $325M valuati 
Sign up for Costco and get a $20 gift card, free 
Vulnerability Summary for the Week of September 16, 2024 
5 handy Alexa routines I depend on every day - and how to build your own 
Sign up for Costco and get a $20 gift card, free - here's how 
Cybersecurity Snapshot: Critical Infrastructure Orgs Found Vulnerable to Basic Hacks, While New MITRE Tool Uses ML to Predict Attack Chains 
CVE-2024-47210 
Tor Project responded to claims that law enforcement can de-anonymize Tor users 
OIG audit calls for more clarity from CISA, DHS on disinformation mission 
5 Compelling Reasons Not to Manage Your Own VoIP Server 
September 2024 Patch Tuesday: Four Zero-Days and Seven Critical Vulnerabilities Amid 79 CVEs 
CrowdStrike Unveils AI Innovations to Expedite Security Operations and Upgrade the Analyst Experience 
-=TWELVE=- is back 
BingX Hacked for $43M: We Will Fully Compensate for the Loss With Our Own Capital - DailyCoin 
Sign up for Costco and get a $20 gift card, free. Here's how 
Re-Imagining Zero Trust With an In-Office Experience, Everywhere 
Help, I can t see! A Primer for Attack Surface Management blog series 
Despite challenges, Minnesota s top election official is an optimist heading into November 
Contemplate us getting our own Moon (group) and theaters hacking together house bands - Cambridge Day 
CVE-2024-47178 
CVE-2024-47180 
U.S. agencies say Iranian hackers tried to pass non-public Trump campaign docs to Biden s campaign 
Apple says the iPhone 16 is a lot easier to repair than its predecessor. Here's how 
Two-Thirds of Security Leaders Consider Banning AI-Generated Code, Report Finds 
10 Best Attack Surface Management Tools 
Rapid7 Named a Leader in IDC MarketScape: Worldwide SIEM for SMB and Enterprise 
Move over, Sonos. Bose just announced its own twist to headphones and soundbar compatibility 
Deterrence in cyberspace is possible and urgent amid alarming hybrid attacks, State cyber ambassador says 
Interview with Jerry Tan: Service robot development for education 
Snap debuts a tool that lets creators generate AI videos from text prompts and, soon, from image prompts, powered by Snap's own foundation video  
AT&T agrees to $13 million fine for third-party cloud breach 
Snap debuts a tool to let creators generate AI videos from text prompts and, soon, from image prompts, powered by Snap's own foundational video m 
Your Costco membership comes with a free $20 gift card right now. Here's how to get it 
CVE-2024-47053 
CVE-2024-47080 
House Dem urges FCC to press ahead with disclosure rule around AI in political ads 
New CISA Plan Aligns Federal Agencies in Cyber Defense 
Treasury hits Predator spyware makers with more sanctions 
Apple Seeks to Drop Its Lawsuit Against Spyware Maker NSO 
Vulnerability Summary for the Week of September 9, 2024 
Linux kernel 6.11 is out - with its own BSOD 
Slack unveils Agents for Slack, letting paid users access Salesforce AI agents, third-party agents from Asana, Cohere, Adobe, and others, and users&ap 
Sources: ByteDance aims to mass produce two AI chips designed alongside TSMC in 2026; a source says ByteDance plans to order several hundred thousand  
[4-Minute Survey] Share Your Thoughts on AI in InfoSec With Me? 
James Webb Telescope goes 'extreme' and spots baby stars at the edge of the Milky Way (image) 
Get a Costco membership and a free $20 gift card now. Here's how 
SquareX: The Future of BYOD Security for Enterprises 
CosmicBeetle joins the ranks of RansomHub affiliates Week in security with Tony Anscombe 
New Office of the CISO Paper: Organizing Security for Digital Transformation 
Our 4 Essential Strategy Takeaways from the Gartner 2024 Report How to Prepare for Ransomware Attacks 
CVE-2024-8789 
Cybersecurity, disinformation dominates hearing on elections 
Two Lies, One Truth in Securing Your SaaS Stack 
BYOD Policies Fueling Security Risks 
The bubbling surface of a distant star was captured on video for the 1st time ever 
Vancouver-based Spare, whose software helps transit agencies offer transport services based on riders' own needs, raised a CA$42M Series B led by 
RansomHub ransomware gang relies on Kaspersky TDSKiller tool to disable EDR 
CosmicBeetle steps up: Probation period at RansomHub 
CVE-2024-46828 
CVE-2024-45877 
Patch Tuesday - September 2024 
Paris-based Neat, which helps other companies sell insurance products to their own customers, raised a €50M Series A, with 60% in equity and 
Four Delaware men charged in international sextortion scheme that netted nearly $2 million 
Rapid7 Named a Leader in IDC MarketScape: Worldwide SIEM for SMB 
Phishing Threats Surround Trump Digital Trading Cards: How Attackers Are Exploiting the Trend 
Risk Assessment and Gap Analysis for Industrial Control System infrastructure: the core essentials 
Australia Threatens to Force Companies to Break Encryption 
Vulnerability Summary for the Week of September 2, 2024 
Our 4 Essential Strategy Takeaways from the Gartner 2024 Report How to Prepare for Ransomware Attacks 
Loki: a new private agent for the popular Mythic framework 
Major Iranian IT vendor paying large ransom to resolve recent cyberattack 
The UK CMA objects to Google's ad tech practices, saying Google harmed competition by using its online display ad dominance "to favour its o 
5 Crucial Steps to Protect Your Resources in Google Cloud 
Cloud Security Takes the Stage at Fal.Con 2024 
The UK CMA objects to Google's ad tech practices, says Google harms competition by using its online display ad dominance "to favour its own  
CVE-2024-8538 
BlindEagle Targets Colombian Insurance Sector with BlotchyQuasar 
Salesforce agrees to acquire Own Company, which provides data management and protection services, for $1.9B in cash; Own was valued at $3.35B as of A 
FCC filing: Larry Ellison will own 77.5% of Paramount Global parent company National Amusements after his son David completes the purchase of Paramoun 
Russia s Most Notorious Special Forces Unit Now Has Its Own Cyber Warfare Team 
Russia s Most Notorious Special Forces Unit Now Has Its Own Cyber Warfare Team - WIRED 
Cyber Command leader says budget powers are shaving time to complete tasks that once took years 
Some tech and crypto firms, and Wyoming rush to launch their own stablecoins to profit from a recovering crypto market, as experts say tokens are of l 
The Malware Chronicles: Urelas, Sality, LockBit and StealC Examined 
Netflix struggles to reduce its productions' carbon footprint, with more emissions in 2022 vs. 2019, partly because it doesn't own any equip 
Robinhood launches a new feature in the UK to let retail investors lend stocks they own to interested borrowers, in a bid to grow its international fo 
Leveraging Threat Intelligence in Cisco Secure Network Analytics 
Mallox ransomware: in-depth analysis and evolution 
Vulnerability Summary for the Week of August 26, 2024 
Vulnerabilities in Microsoft apps for macOS allow stealing permissions 
Threat actors using MacroPack to deploy Brute Ratel, Havoc and PhantomCore payloads 
A deep dive into the most interesting incident response cases of last year 
Who would be the cyber pros in a second Trump term? 
Fidelity values X at 72% below Elon Musk's purchase price, meaning Prince Alwaleed bin Talal Al Saud would be down $1.4B and Dorsey and Ellison  
'Warm Jupiter' exoplanet 300 light-years away found by amateur astronomers 
Fidelity values X at 72% below Elon Musk's purchase price, meaning Prince Alwaleed bin Talal Al Saud is down $1.4B and Dorsey and Ellison are do 
Fidelity's latest valuation of X, 72% lower than when Musk took over, would mean top investor Prince Alwaleed bin Talal al Saud is down $1.4B and 
An air transport security system flaw allowed to bypass airport security screenings 
Security Affairs newsletter Round 487 by Pierluigi Paganini INTERNATIONAL EDITION 
'Slingshot' is a surreal sci-fi head trip that questions its own reality (review) 
H1 2024 Check Fraud Report: Geographic Trends and Threat Actor Patterns 
Google: apparent Russian hackers play copycat to commercial spyware vendors 
Mythic 3.3 Out of Beta 
Special Bulletin: US Election Phishing Alert 
Threads now lets users see and like fediverse replies on other posts besides their own, and posts submitted via Threads API will be syndicated to the  
Fuzzing C OS protocol stacks, Part 3: TCP IP server fuzzing, implementing a TAP driver 
Fuzzing C OS protocol stacks, Part 1: HTTP server fuzzing 
The vulnerabilities we uncovered by fuzzing C OS protocol stacks 
BlackByte Ransomware group targets recently patched VMware ESXi flaw CVE-2024-37085 
Iranian hackers tickle targets in US, UAE with custom tool, Microsoft says 
BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks 
Source: in 2023, Meta abandoned plans to build its own custom chips for its AR glasses, instead opting to rely on third-party chipmakers like Qualcomm 
Not a SOC FAQ! This is SOC FMD! 
Source: last year, Meta abandoned plans to build its own custom chips for its AR glasses, instead opting to rely on third-party chipmakers like Qualco 
Researchers unmasked the notorious threat actor USDoD 
An overview of AI startups largely founded by former AI researchers from Google, including Reka, Ideogram, H, and Inflection, and the challenges they  
Vulnerability Summary for the Week of August 19, 2024 
An overview of AI startups largely founded by former AI researchers from Google, including Reka, Ideogram, H, Inflection, and Character AI (The Inform 
CVE-2024-45299 
CVE-2024-45293 
Security Affairs newsletter Round 486 by Pierluigi Paganini INTERNATIONAL EDITION 
CVE-2024-45257 
CVE-2024-45256 
Man tried to hack database, fake own death to skirt child support - SC Media 
Meta deep-sixes WhatsApp accounts tied to Iranian hacking group 
Kentucky man gets 81 months in prison for cyber fraud to fake his own death 
Local Networks Go Global When Domain Names Collide 
How we improved vulnerability prioritization with machine learning 
Sources: Stripe plans a tender offer to buy back shares held by current employees with its own cash; Stripe is offering $27.51 share, implying a $70B  
GitHub fixed a new critical flaw in the GitHub Enterprise Server 
Hackers leak their own operations through exposed Telegram Bot API tokens - SC Media 
The Great Cloud Security Debate: CSP vs. Third-Party Security Tools 
CVE-2022-48981 
CVE-2022-49001 
CVE-2022-48991 
CVE-2022-48998 
Best Practices for Event Logging and Threat Detection 
Man sentenced for hacking state registry to fake his own death - BleepingComputer 
Telecom behind AI-powered Biden robocall agrees to $1 million FCC fine 
Sources: Apple App Store VP Matt Fischer is leaving in October; App Store group will split into two teams, one for its own store, one for alt app dist 
North Korea-linked APT used a new RAT called MoonPeak 
Hacking state records to fake his own death and not pay alimony to his children: Jesse Kipf sentenced - Decripto.org 
Cowardly hacker impersonated doctor & faked his own death to avoid paying child support and taught othe... - The US Sun 
Styx Stealer Creator's OPSEC Fail Leaks Client List and Profit Details 
Exploits and vulnerabilities in Q2 2024 
Kentucky man gets prison for hacking state systems to fake own death and avoid paying child support - Yahoo! Voices 
MoonPeak malware from North Korean actors unveils new details on attacker infrastructure 
OpenAI launches fine-tuning for GPT-4o, letting developers customize a version of the model with their own datasets to improve domain-specific perform 
Sources: Walmart, JD.com's largest shareholder, is raising about $3.6B by selling its stake in the Chinese e-commerce firm; JD falls 9%+ (Amy Or  
Deadbeat dad faked his own death by hacking government databases - The Register 
Sources: Walmart, JD.com's largest shareholder, is raising about $3.6B by selling its stake in the Chinese e-commerce firm; JD falls 9%+ after ho 
Man who faked own death by hacking into death registry to avoid paying child support sentenced to over 6 years in prison - CNN 
Kentucky man gets prison for hacking state systems to fake own death and avoid paying child support - AOL 
Kentucky man gets prison for hacking state systems to fake own death and avoid paying child support - Fox News 
Man who hacked Hawaii state registry to forge his own death certificate sentenced to 81 months - The Record from Recorded Future News 
CVE-2024-45007 
CVE-2024-45037 
What You Get with AKS, EKS, GKE vs. Managed Kubernetes-as-a-Service 
Podcast Episode 18: From Application Developer to CEO: Greg Samuels on Entrepreneurial Success and Cybersecurity Priorities 
Google to wind down app store bug bounty 
OpenAI launches fine-tuning for GPT-4o, which lets developers customize a version of the model with their own datasets to improve domain-specific perf 
Digital Wallets Bypassed To Allow Purchase With Stolen Cards 
Approach to mainframe penetration testing on z OS 
Echoes of Rome: Leveraging Ancient Tactics for Modern Malware 
Black Hat USA 2024: Key Takeaways and Industry Trends 
Vulnerability Summary for the Week of August 12, 2024 
National Public Data Published Its Own Passwords 
Doritos new safe-for-outer-space chips set for blast off: Here's how to get your own 
How multiple vulnerabilities in Microsoft apps for macOS pave the way to stealing permissions 
After Google's antitrust loss, what comes next is not clear, besides the court ordering Google to stop or reduce TAC payments; Apple may build it 
Microsoft Zero-Day CVE-2024-38193 was exploited by North Korea-linked Lazarus APT 
CMIYC2024: Wifi Cracking Challenge 
Google to Remove App that Made Google Pixel Devices Vulnerable to Attacks 
Tech Analysis: Addressing Claims About Falcon Sensor Vulnerability 
Google Pixel Devices Shipped with Vulnerable App, Leaving Millions at Risk 
AI, election security headline discussions at Black Hat and DEF CON 
Klarna debuts a checking account-like service and a cashback offering in its app in 12 markets, including the US and across Europe, as it prepares for 
Klarna rolls out a checking account-like product and a cashback offering in 12 markets including the US and across Europe, as it prepares for a US IPO 
Your SOHO Router is a Juicy Target for Hackers 
How Amazon, Alphabet, Microsoft, and Meta are using accounting techniques to hide their growing emissions, while working to influence pollution disclo 
Black Hat 2024: Key Takeaways and Industry Trends 
BYOVDLL – A New Exploit That Is Bypassing LSASS Protection 
Six 0-Days Lead Microsoft’s August 2024 Patch Push 
Sleeping With the Phishes 
On the Voynich Manuscript 
A refresher on Talos open-source tools and the importance of the open-source community 
APT trends report Q2 2024 
Trump Celebrated Email Hacks. His Campaign Wants Their Own Docs to Stay Private - Rolling Stone 
CVE-2024-7747 
CVE-2024-7764 
CVE-2024-7768 
CrowdStrike's president appeared at DEF CON to accept the "Most Epic Fail" Pwnie Award, saying "we got this horribly wrong" a 
Vulnerability Summary for the Week of August 5, 2024 
HYAS Investigates Threat Actors Hidden In Gaming Services 
Crowdstrike, or How to Own the Planet  
Indirect prompt injection in the real world: how people manipulate neural networks 
Google’s Quick Share Vulnerabilities Let Attackers Execute Remote Code 
A detailed look at China's chip buildout and how US chip sanctions and industrial policies have accelerated China's push to develop its own  
CVE-2024-43414 
QuickShell: Sharing Is Caring about an RCE Attack Chain on Quick Share 
How cybersecurity researcher Jon DiMaggio used fake personas to infiltrate LockBit and trick its alleged administrator into revealing operation detail 
Researchers Uncover 10 Flaws in Google's File Transfer Tool Quick Share 
Not Just Us: North Korean Remote IT Fraudster Arrested in Tennessee 
Since the OpenAI board dispute, Microsoft diversified AI investments and partnerships, built its own models, and hired aggressively for its consumer A 
New APT Actor240524 Weaponizing Official Documents To Deliver Malware 
The top stories coming out of the Black Hat cybersecurity conference 
US Space Force will make history when SpaceX's Crew-9 mission launches in September 
Watch How a Hacker s Infrared Laser Can Spy on Your Laptop s Keystrokes 
CIAM Build versus Buy 
Keys to the Kingdom - Gaining access to the Physical Facility through Internal Access 
New Android spyware LianSpy relies on Yandex Cloud to avoid detection 
BloodHound Operator Dog Whispering Reloaded 
Tech giants reveal plans to combat AI-fueled election antics 
Gov. Tim Walz, Harris VP pick, has a notable record on cyber 
The Prevalence of DarkComet in Dynamic DNS 
Rapid7 s Ransomware Radar Report Shows Threat Actors are Evolving Fast. 
Intelligence bill would elevate ransomware to a terrorist threat 
How Using a VPN May Benefit Your Privacy 
Vulnerability Summary for the Week of July 29, 2024 
CrowdStrike points finger back at Delta after airline threatened to sue over outages 
Ryan Pentney reflects on 10 years of Talos and his many roles from the Sourcefire days 
CVE-2024-7457 
Canadarm2 was not designed to catch spacecraft at the ISS. Now it's about to grab its 50th 
U.S. released Russian cybercriminals in diplomatic prisoner exchange 
CVE-2024-7426 
CVE-2024-7414 
CVE-2024-7411 
CVE-2024-7413 
CVE-2024-7412 
CVE-2024-7415 
CVE-2024-7410 
CVE-2024-7416 
EPA urgently needs to step up cybersecurity assistance for the water sector, GAO says 
Rabbit says a June security breach was caused by an employee who leaked API keys and has since been terminated, and it has revoked and rotated those A 
There is no real fix to the security issues recently found in GitHub and other similar software 
Production and Proliferation: The Risks of the Burgeoning Iranian Drone Industry 
The Strategic and Economic Implications of Iran s Expanding Drone Industry 
How “professional” ransomware variants boost cybercrime groups 
Detecting evolving threats: NetSupport RAT campaign 
CVE-2024-7382 
TrustCloud Product Updates: July 2024 
Less is More |more or |less 
Celebrating Excellence: Rapid7 Recognized in Newsweek's Greatest Workplaces in America 2024 
"There is no business school class that would ever sit down and design Talos" 
Learn ethical hacking at your own pace with this $40 course bundle deal - BleepingComputer 
Detection Rules & MITRE ATT&CK Techniques 
Meta scraps its celebrity AI chatbot feature less than a year after launch and now expects people to use Meta's new AI Studio to customize their  
Microsoft calls out apparent ESXi vulnerability that some researchers say is a nothing burger  
Pair of lawsuits seek to revive fight over alleged censorship campaigns 
New Research: The Proliferation of Cellular in IoT 
OCI Customers Can Now Externally Manage Encryption Keys from a Cloud-Based Service 
Canva acquires AI image generation service Leonardo.ai for an undisclosed amount; Leonardo.ai launched in December 2022 and has more than 19M register 
CVE-2024-42293 
Vulnerability Summary for the Week of July 22, 2024 
South Korea plans to provide $400M to SMBs hit by payment delays on two Qoo10 e-commerce platforms, and Qoo10's founder pledges to use his own as 
South Korea will provide $400M to vendors hit by payment delays on two Qoo10 e-commerce platforms, and Qoo10's founder pledges to use his own ass 
CVE-2024-42146 
Musk reposts an edited Kamala Harris campaign video that mimics her voice, possibly with deepfake tech; it has 125M+ views and seemingly breaks X&apos 
French authorities launch disinfection operation to eradicate PlugX malware from infected hosts 
Musk reposts an edited Kamala Harris campaign video that mimics her voice, possibly with deepfake tech; it has 120M+ views and seemingly breaks X&apos 
Tech Analysis: Channel File May Contain Null Bytes 
Musk reposts an edited Kamala Harris campaign video that mimics her voice, possibly with deepfake tech; it has 114M+ views and seemingly breaks X&apos 
Musk reposts an edited Kamala Harris campaign video that mimics her voice, possibly with deepfake tech; it has 104M+ views and seemingly breaks X&apos 
NASA astronauts hold their own Summer Olympics in space (video) 
Webworm 
TAG-56 
TwoSail Junk 
Storm-0558 
AtlasCross 
GOLD NORTHFIELD 
TRAVELING SPIDER 
Nazar 
NOTROBIN 
DOPPEL SPIDER 
CLOCKWORK SPIDER 
PIZZO SPIDER 
Liquidmatrix Security Digest Podcast – Episode 7E 
Kamala Harris joins TikTok, following an explosion of Harris memes since announcing her presidential run; her account has attracted 1M+ followers in  
Kamala Harris joins TikTok, following an explosion of Harris memes since announcing her presidential run; her account has attracted 400K+ followers in 
Discovery of 'dark oxygen' from deep-sea metal lumps could trigger rethink of origins of life 
North Korean Fake IT Worker FAQ 
#RoboCup2024 daily digest: 20 July 
Researchers Detail on How Defenders Eliminate Detection Gaps in AWS Environments 
CrowdStrike says the problematic July 19 software update that affected 8.5M Windows devices was deployed into production due to "a bug in the Con 
CVE-2024-41942 
Deep Sea Phishing Pt. 1 
Liquidmatrix Security Digest Podcast – Episode 7D 
Mark Zuckerberg argues "open source AI" is the path forward, that closed models are vulnerable to vendor lock-in, state-backed espionage, an 
Simple FrostyGoop malware responsible for turning off Ukrainians heat in January attack 
New Microsoft Recovery Tool for CrowdStrike Issue on Windows Endpoints 
Vulnerability Summary for the Week of July 15, 2024 
CVE-2024-41777 
Trump's comments on Taiwan hollowing out the US chip industry are incorrect, and risks opening up a fissure for China to exploit and push its own 
Inflatable planetarium Stories in the sky 
How to make a comet 
Global Microsoft Meltdown Tied to Bad Crowdstrike Update 
Global Microsoft Meltdown Tied to Bad Crowstrike Update 
Pro-Houthi Group Targets Yemen Aid Organizations with Android Spyware 
Adobe: US shoppers spent $14.2B during Amazon's 48-hour Prime Day sale, up 11% YoY and in line with estimates; Numerator: the average household s 
CVE-2024-6873 
CVE-2024-41663 
Disney 1.2 TB Slack Hack: NullBulge Claims Leak is its Own - Security Boulevard 
Disney 1.2 TB Slack Hack: NullBulge Claims Leak is its Own 
Hacking An IP Camera To Run Your Own Software - Hackaday 
CVE-2024-41178 
After Trump was shot, Elon Musk endorsed him and stepped up his own political speech in 100+ posts, entering uncharted territory for a social media le 
Caught in the Act: StealC, the Cyber Thief in C 
Mythic 3.3 Beta: Rise of the Events 
Vulnerability Summary for the Week of July 8, 2024 
ViperSoftX Weaponizing AutoIt & CLR For Stealthy PowerShell Execution 
Is the universe still making new galaxies? 
Weight-loss coach shares catchy fitness hack on TikTok as nutritionist has her own take - Fox News 
CVE-2024-40918 
AI models are inching closer to hacking on their own - Axios 
MoonWalk: A deep dive into the updated arsenal of APT41 | Part 2 
Checking in on the state of cybersecurity and the Olympics 
Liquidmatrix Security Digest Podcast – Episode 7C 
CISA Red Team s Operations Against a Federal Civilian Executive Branch Organization Highlights the Necessity of Defense-in-Depth 
Train for Entry-Level or Advanced IT Positions for Just $50 
33 million Authy users exposed in authentication app's own security nightmare - Fox News 
DodgeBox: A deep dive into the updated arsenal of APT41 | Part 1 
Year in Review: GitGuardian’s Own Security Team 
Drink Like a Phish 
Developing and prioritizing a detection engineering backlog based on MITRE ATT&CK 
People s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action 
Policy: Volunteer and Visitor Physical Safety 
Rapid7 completes IRAP PROTECTED assessment for Insight Platform solutions 
Investigation: the US Cyber Safety Review Board didn't investigate, for unclear reasons, the weaknesses in Microsoft tools that the SolarWinds ha 
Vulnerability Summary for the Week of July 1, 2024 
Investigation: the US Cyber Safety Review Board, created by Biden in 2021, didn't investigate, for unclear reasons, the underlying weaknesses use 
Europol Concerns Over Privacy Enhancing Technologies Challenge Lawful Interception 
CloudSorcerer A new APT targeting Russian government entities 
CVE-2024-6557 
CVE-2024-6571 
CVE-2024-6556 
CVE-2024-6552 
CVE-2024-40648 
CVE-2024-6587 
CVE-2024-6544 
CVE-2024-6551 
CVE-2024-6565 
CVE-2024-6554 
CVE-2024-6568 
CVE-2024-6550 
CVE-2024-6559 
CVE-2024-6553 
CVE-2024-6574 
CVE-2024-6548 
CVE-2024-6546 
CVE-2024-6566 
CVE-2024-6545 
CVE-2024-6573 
CVE-2024-6555 
CVE-2024-6567 
CVE-2024-6569 
CVE-2024-6547 
CVE-2024-6560 
CVE-2024-40637 
CVE-2024-6562 
CVE-2024-6570 
CVE-2024-6549 
APT98 
APT2 
Cloudflare Details 1.1.1.1 Service Outage Following BGP Hijack 
Sources: to lessen its reliance on Safari for iOS, Google considered limiting AI Overviews to its own mobile apps, but ultimately decided against such 
Metasploit Weekly Wrap-Up 07 05 2024 
Liquidmatrix Security Digest Podcast – Episode 7B 
Sources: to reduce its reliance on Safari on the iPhone, Google considered limiting AI Overviews to its own apps, but ultimately decided against that  
Cloudflare Details 1.1.1.1 Service Outage Incident 
Hackers could ruin your 4th of July cookout if you own one of these smart grills update right now - Tom's Guide 
Hackers could ruin your 4th of July cookout if you own a Traeger smart grill what to do now - Tom's Guide 
CVE-2024-6512 
The Not-So-Secret Network Access Broker x999xx 
Gogs Vulnerabilities Let Attackers Hack Instances & Steal Source Code 
Alerts on Policy Breaches Now Available via API 
Gogs Vulnerabilities Let Attackers Hack Instances And Steal Source Code 
A Brief History of SmokeLoader, Part 2 
CVE-2024-6499 
Supreme Court puts content moderation on solid legal ground 
Like Shooting Phish in a Barrel 
5 Threat Intelligence Solution Use Cases 
CVE-2024-6448 
Graduating? Get your cybersecurity career started via the National Cyber Warfare Foundation 
Vulnerability Summary for the Week of June 24, 2024 
Kasada s Reflections on the Q3 2024 Forrester Wave Bot Management Evaluation 
Russia-linked Midnight Blizzard stole email of more Microsoft customers 
SBOM Attestation by 3PAOs: Everything You Need to Know 
HYAS Protects Against Polyfill.io Supply Chain Attack with DNS Safeguards 
Liquidmatrix Security Digest Podcast – Episode 7A 
Margrethe Vestager says Apple's decision not to launch its AI features in the EU is a "stunning, open declaration" of the company' 
Understanding Market Making in the Cryptocurrency 
Kimsuky deploys TRANSLATEXT to target South Korean academia 
Snowblind Abuses Android seccomp Sandbox To Bypass Security Mechanisms 
US businesses struggle to obtain cyber insurance, lawmakers are told 
PortSwigger, the startup behind the Burp Suite of security testing tools founded by security expert "Daf", raised $112M, its first outside i 
PortSwigger, the company behind the Burp Suite of security testing tools founded by security expert "Daf", raised $112M, its first outside i 
Protecting the Soft Underbelly of the Data Center 
Supreme Court rejects effort to limit government communication on misinformation 
Indian e-commerce giant Flipkart quietly rolls out a payments app, Super.money, after separating from PhonePe, India's largest payments app, in D 
Maven Central and the tragedy of the commons 
Indian e-commerce giant Flipkart quietly rolls out its own payments app, Super.money, after separating from India's largest payments app PhonePe  
Protecting America s cybersecurity demands showing our teeth 
Hacking APIs with HTTPie 
From Top Dogs to Unified Pack 
k-ID, a platform that helps game developers comply with child safety and data privacy regulations, raised a $45M Series A led by a16z and Lightspeed ( 
Securing the Journey to AI with Thales Sovereign Solutions for AWS 
CVE-2024-39548 
StealC & Vidar Malware Campaign Identified 
Uber has begun locking NYC drivers out of its app during low demand periods to fight a local rule that requires drivers be paid for idle time between  
Millions and Millions of Fraud Domains: China attacks Illegal Gambling and Telecom Fraud 
Diplomats and others fear that a rift between SoftBank and Naver over the ownership of messaging app Line could put stress on ties between Japan and S 
Diplomats and others fear a rift between SoftBank and Naver over the ownership of messaging app Line could put stress on ties between Japan and South  
Vulnerability Summary for the Week of June 17, 2024 
The End of Our Dog Era 
New Highly Evasive SquidLoader Attacking Employees Mimic As Word Document 
My health information has been stolen. Now what? 
CVE-2024-39324 
Stopping Cyber Attacks Against the Financial Sector: Four Use Cases 
KrebsOnSecurity Threatened with Defamation Lawsuit Over Fake Radaris CEO 
Tabletop exercises are headed to the next frontier: Space 
Picketed at work, confronted at church: Why election workers have left the job 
HeyGen, which uses AI to let users create realistic-looking avatars, raised $60M led by Benchmark at a $500M valuation, taking its total funding to $7 
Certik returns funds on its own terms after hacking Kraken for $3M - Protos 
CVE-2024-6210 
DNS and Your Privacy: Should you use encrypted DNS? 
Xbox Underground 
TESO 
Operation High Roller 
Conti 
Beware of Nevermore Actor Promoting Ransomware Builder 
SpaceX launching European TV satellite today on 1st leg of doubleheader 
Feeding the Phishes 
How are attackers trying to bypass MFA? 
Exploring malicious Windows drivers (Part 2): the I O system, IRPs, stack locations, IOCTLs and more 
Dragonfly 
Grim Spider 
Shuckworm 
FIN7 
Magecart Group 6 
DragonOK 
SNAKEMACKEREL 
CVE-2024-38513 
Vulnerability Summary for the Week of June 10, 2024 
Google begins rolling out "Listen to this page" in Chrome for Android, letting the browser read text-heavy web pages in US, UK, Indian, and  
Google begins rolling out a "Listen to this page" feature on Chrome for Android, letting the browser read text-heavy web pages (Abner Li 9to 
Hackers Employing New Techniques To Attack Docker API 
CVE-2024-6087 
One Hack That Will Elevate Every Outfit You Own (& No, It Doesn't Involve Buying More Clothes) - Refinery29 Australia 
Alleged Boss of ‘Scattered Spider’ Hacking Group Arrested 
How are galaxies destroyed? 
Liquidmatrix Security Digest Podcast – Episode 79 
Operation Celestial Force employs mobile and desktop malware to target Indian entities 
Cinterion EHS5 3G UMTS HSPA Module Research 
Microsoft s Brad Smith should prepare for ritual punishment before House hearing 
Microsoft s Recall puts the Biden administration s cyber credibility on the line 
Patch Tuesday - June 2024 
SSLoad Malware Employs MSI Installer To Kick-Start Delivery Chain 
Apple's OpenAI partnership took up just two minutes of its one hour and 45 minute WWDC keynote, as the company focused on its own Apple Intellige 
Apple set to launch a new password management app for iPhone and Mac Users 
Apple announces Genmoji, an Apple Intelligence-powered iOS 18 feature to let users create their own custom emoji using text prompts in the Messages ap 
Senators demand UnitedHealth own patient data hack - CNN 
Utah Consumer Privacy Act (UCPA) 
Bypassing 2FA with phishing and OTP bots 
Duckduckgo Launches Anonymous AI Chatbots 
A push by global governments to develop AI locally and train LLMs in their native languages and on their citizens' data offers new growth for Nvi 
Researchers find malicious Microsoft Visual Studio Code extensions with millions of installs, and also easily create their own, which trended in the m 
Push from global governments to develop AI locally and train LLMs in their native languages and on their citizens' data offers new growth for Nvi 
Researchers find malicious Microsoft Visual Studio Code extensions with millions of installs and also easily create their own, which trended in the ma 
Push from governments to develop AI locally and train LLMs in their native languages and on their citizens' data, is a new growth opportunity for 
CVE-2024-37895 
CVE-2024-5815 
CVE-2024-37903 
ShrinkLocker: Turning BitLocker into ransomware 
IT threat evolution Q1 2024 
Trusted relationship attacks: trust, but verify 
Vulnerability Summary for the Week of May 27, 2024 
Vulnerability Summary for the Week of May 13, 2024 
Vulnerability Summary for the Week of May 20, 2024 
Building and Operationalising an Empowered CTI Team 
Patch Tuesday, May 2024 Edition 
Why Your Wi-Fi Router Doubles as an Apple AirTag 
Stark Industries Solutions: An Iron Hammer in the Cloud 
‘Operation Endgame’ Hits Malware Delivery Platforms 
Security Affairs newsletter Round 475 by Pierluigi Paganini INTERNATIONAL EDITION 
Commando Cat Cryptojacking Attacks Target Misconfigured Docker Instances 
Microsoft Details On Using KQL To Hunt For MFA Manipulations 
The murky world of password leaks and how to check if you ve been hit 
LeakSearch - Search & Parse Password Leaks 
Liquidmatrix Security Digest Podcast – Episode 77 
Liquidmatrix Security Digest Podcast – Episode 78 
AI Trust Risk and Security Management: Why Tackle Them Now? 
See a Sneak Peek of Tuesday s Take Command Summit 
The Take Command Summit: A Day of Resilience and Preparation 
Securing AI Development in the Cloud: Navigating the Risks and Opportunities 
Talos joins CISA to counter cyber threats against non-profits, activists and other at-risk communities 
Talos releases new macOS open-source fuzzer 
Rounding up some of the major headlines from RSA 
Apple and Google are taking steps to curb the abuse of location-tracking devices but what about others? 
Attackers are impersonating a road toll payment processor across the U.S. in phishing attacks 
New banking trojan CarnavalHeist targets Brazil with overlay attacks 
The sliding doors of misinformation that come with AI-generated search results 
Falcon Fusion SOAR and Machine Learning-based Detections Automate Data Protection Workflows 
CVE-2024-5714 
CVE-2024-36523 
CVE-2021-47531 
CVE-2021-47595 
CVE-2024-36116 
CVE-2024-36115 
The Impact of Open Source Intelligence in Ukraine’s Defense Against Russian Forces and Propaganda (Dec. 2022) 
Long Version: The Belt and Road Initiative and Human Trafficking (April 2024) 
CVE-2024-35871 
CVE-2024-5040 
CVE-2024-35238 
Forget AI: Physical threats are biggest risk facing the 2024 election 
Emerald Divide Uses GenAI to Exploit Social, Political Divisions in Israel Using Disinformation 
Microsoft plans to launch its mobile game store in July on the web, first with its own games, including Candy Crush Saga, and later opening to other p 
Make WAAP Interesting Again by Quantifying Operational Efficiency and Secure by Design. 
Stack Overflow Users Delete Posts in Protest Over OpenAI Partnership 
CVE-2024-35183 
Microsoft plans to launch its mobile game store in July on the web, first with its own games including Candy Crush Saga, and later open it to other pu 
CrowdStrike Enhances Cloud Asset Visualization to Accelerate Risk Prioritization 
Rapid7 Signs 100% Talent Compact with Boston Women s Workforce Council 
State of ransomware in 2024 
MITRE attributes the recent attack to China-linked UNC5221 
Exploits and vulnerabilities in Q1 2024 
HYAS Threat Intel Report May 6 2024 
CVE-2024-34701 
CVE-2024-34626 
CVE-2024-34738 
CVE-2024-34630 
Sources: Apple has been working on its own chip designed to run AI software in data center servers; the project is internally codenamed Project ACDC ( 
Vulnerability Summary for the Week of April 29, 2024 
Recorded Future at RSA: Platform Capabilities to Drive the Future of Threat Intelligence 
Why Your VPN May Not Be As Secure As It Claims 
Best SIEM Tools List For SOC Team – 2024 
Recorded Future at RSA: Platform Innovations to Drive the Future of Threat Intelligence 
Financial cyberthreats in 2023 
CEO Discusses MDR Service With a Risk-Based Approach 
Metasploit Weekly Wrap-Up 05 03 24 
CrowdStrike Named a Leader in IDC MarketScape for Worldwide MDR 
CrowdStrike Named the Only Customers Choice in 2024 Gartner Voice of the Customer for External Attack Surface Management 
Dirty stream attack poses billions of Android installs at risk 
Stock photographers prepare for AI disruption, as stock photo companies say traditional photography still has a market but work on building their own  
Manual LDAP Querying: Part 2 
What can we learn from the passwords used in brute-force attacks? 
The Take Command Summit: A Stacked Agenda, and Killer Guest Speakers Coming Your Way May 21 
A look at Ukraine's combat drone startup industry; Kyiv estimates 200 local startups produce drones based on commercial first-person-view or pho 
A look at Ukraine's combat drone startup industry, based on commercial first-person-view or photography drones; an estimated 200 local companies 
IAM and Passkeys: 4 Steps Towards a Passwordless Future 
Inside Ukraine s Killer-Drone Startup Industry 
CISA’s incident reporting requirements go too far, trade groups and lawmakers say 
ADCS Attack Paths in BloodHound Part 2 
Learn Cybersecurity Skills From Scratch for Just $40 
A look at GM's risky bet to replace Apple's CarPlay with its own infotainment system, gambling on its software group, as carmakers worry ove 
Muddling Meerkat, a mysterious DNS Operation involving China’s Great Firewall 
IBM wins a court decision overturning $1.6B in damages it was ordered to pay BMC in 2022 for swapping in its own software while servicing a mutual cli 
CISA guidelines to protect critical infrastructure against AI-based threats 
FCC takes $200 million bite out of wireless carriers for sharing location data 
Vulnerability Summary for the Week of April 22, 2024 
James Nutland studies what makes threat actors tick, growing our understanding of the current APT landscape 
1,200+ Vulnerabilities Detected In Microsoft Products In 2023 
Android Malware Brokewell With Complete Device Takeover Capabilities 
Security Affairs newsletter Round 469 by Pierluigi Paganini INTERNATIONAL EDITION 
Brokewell Android malware supports an extensive set of Device Takeover capabilities 
Metasploit Weekly Wrap-Up 04 26 24 
Nemesis 1.0.0 
The private sector probably isn t coming to save the NVD 
Salt Security Addresses Critical OAuth Vulnerabilities Enhancing API Security with OAuth Protection Package 
Talos IR trends: BEC attacks surge, while weaknesses in MFA persist 
Campaigns and political parties are in the crosshairs of election meddlers 
Hackers hijacked the eScan Antivirus update mechanism in malware campaign 
CoralRaider Hacker Evade Antivirus Detections Using Malicious LNK File 
Spyroid RAT Attacking Android Users to Steal Confidential Data 
Assessing the Y, and How, of the XZ Utils incident 
Block says it has finished the development of its own 3nm bitcoin mining chip and is working through the design with a "leading global semiconduc 
Russian FSB Counterintelligence Chief Gets 9 Years in Cybercrime Bribery Scheme 
Vulnerability Summary for the Week of April 15, 2024 
CrowdStrike and Google Cloud Expand Strategic Partnership to Deliver Unified Cloud Security 
Take Command Summit: Take Breaches from Inevitable to Preventable on May 21 
Windows MagicDot Path Flaw Lets Attackers Gain Rootkit-Like Abilities 
Researchers Claim that Windows Defender Can Be Bypassed 
Fix Windows 11 Error 0x8096002A – No Error Description Found 
MITRE revealed that nation-state actors breached its systems via Ivanti zero-days 
Metasploit Weekly Wrap-Up 04 19 24 
From DAST to dawn: why fuzzing is better solution | Code Intelligence 
What s the deal with the massive backlog of vulnerabilities at the NVD? 
How Attackers Can Own a Business Without Touching the Endpoint 
The Dark Side of EDR: Repurpose EDR as an Offensive Tool 
The Ultimate Guide to SBIR and STTR Program Budgeting 
CVE-2024-32877 
Short-form video app Triller is merging with Hong Kong financial services company AGBA; Triller shareholders will own 80% of the combined company valu 
OnlyFans Filter: A New Frontier in School Safety and CIPA Compliance 
How Amazon built Just Walk Out starting in the early 2010s, driven by Jeff Bezos, as Amazon removes the tech from its stores but expands it to other r 
How Amazon built Just Walk Out starting in the early 2010s, driven by Jeff Bezos, as the company removes the tech from its stores but expands to other 
Mandiant: Notorious Russian hacking unit linked to breach of Texas water facility 
Stop Ransomware in its Tracks With CipherTrust Transparent Encryption Ransomware Protection 
How Amazon developed Just Walk Out since the early 2010s, driven by Jeff Bezos, as the company removes the tech from stores while expanding third-part 
FGVulDet – New Vulnerability Detector to Analyze Source Code 
OfflRouter virus causes Ukrainian users to upload confidential documents to VirusTotal 
SoumniBot: the new Android banker’s unique techniques 
HYAS Threat Intel Report April 15 2024 
Vulnerability Summary for the Week of April 8, 2024 
Congressional privacy bill looks to rein in data brokers 
This Startup Aims To Simplify End-to-End Cybersecurity, So Anyone Can Do It 
Metasploit Weekly Wrap-Up 04 12 24 
XZ backdoor story – Initial analysis 
CVE-2024-32468 
Met police failed to act on Commons honeytrap sexting reports last year 
The internet is already scary enough without April Fool s jokes 
Fortra For Windows Vulnerability Let Attackers Escalate Privilege 
Improving Dark Web Investigations with Threat Intelligence 
Cybersecurity in the Evolving Threat Landscape 
Piper Sandler survey of 6,020 US teens: 33% now own a VR device, up from 31% in fall 2023, and weekly users of VR devices increased to 13% from 10%  
Piper Sandler survey of 6,020 US teens: 33% now own a VR device, up from 31% in fall 2023; Instagram was teen's second favorite app, closing its  
Piper Sandler survey of 6,020 US teens: 33% now own a VR device, up from 31% in fall 2023, and weekly usage of VR devices increased to 13% from 10%  
CVE-2021-47226 
Patch Tuesday - April 2024 
US man faked his own death via hacking state records to avoid over RM475,000 in child support payments - The Star Online 
Grow Therapy, which provides services like patient-provider matching and EHR to help therapists run their own practices, raised an $88M Series C led b 
CVE-2024-32030 
Vulnerability Summary for the Week of April 1, 2024 
Father fakes his own death to avoid paying $100000 in child maintenance - The Telegraph 
Father faked his own death by hacking into death registry system to avoid paying more than $100,000 in outstan - Daily Mail 
Hacker fakes his own death to avoid paying $100,000 in child maintenance - The Telegraph 
Hacker fakes his own death to avoid paying $100,000 in child maintenance - Yahoo! Voices 
CVE-2024-31997 
CVE-2024-31873 
Email: Galaxy Digital's venture arm, which has long invested its own money, is raising a $100M fund with outside capital, focused on early-stage  
Sources: OpenAI transcribed 1M+ hours of YouTube videos through Whisper and used the text to train GPT-4; Google also transcribed YouTube videos to ha 
Sources: ByteDance, which was directly involved in countering US efforts to ban TikTok in 2020, has let the US TikTok team lead the response this time 
An MP who gives colleagues numbers to blackmailers. Isn t William Wragg just right for this Westminster? Marina Hyde 
Supply Chain Resilience & the Power of Continuous Monitoring 
An MP who gives out colleagues numbers to blackmailers. Isn t William Wragg just right for this Tory party? Marina Hyde 
Chinese hackers turn to AI to meddle in elections 
There are plenty of ways to improve cybersecurity that don t involve making workers return to a physical office 
Wormhole initially included its own hacker in 670 million token airdrop - The Block 
FBI seeks to balance risks, rewards of artificial intelligence 
Ripple plans to launch its own stablecoin later this year "100% backed by US dollar deposits, short-term US government Treasuries, and other cash 
Fake Lawsuit Threat Exposes Privnote Phishing Sites 
CoralRaider targets victims data and social media accounts 
An interview with Andres Freund, a Microsoft database engineer working on PostgreSQL, on discovering the XZ Utils backdoor, doubting his own findings, 
Stability AI releases Stable Audio 2.0, which lets users create three-minute sound clips from copyright-free audio samples, available for free via its 
Vulnerability Summary for the Week of March 25, 2024 
‘The Manipulaters’ Improve Phishing, Still Fail at Opsec 
Stability AI releases Stable Audio 2.0, letting users create three minute sound clips from copyright-free audio samples, available for free via its we 
This IT Career Kickstarter Bundle is An Extra 20% Off Through April 7th 
How to Fix Lyca Mobile Outgoing Calls Not Working 
Cyber review board blames cascading Microsoft failures for Chinese hack 
CVE-2024-3279 
CVE-2024-31446 
Sophos: Backups are in Ransomware Groups’ Crosshairs 
CISA faces resource challenge in implementing cyber reporting rules 
Getting Intune with Bugs and Tokens: A Journey Through EPM 
Sophos: Backups are in the Crosshairs of Ransomware Groups 
Swalwell for Congress Campaign Partners with Wolfsbane.ai to Protect Against AI-Generated Cloning 
Challenges Drive Career Growth: Meet Rudina Tafhasaj 
Google agreed to erase billions of browser records to settle a class action lawsuit 
CVE-2024-31391 
CVE-2024-3183 
HYAS Threat Intel Report April 1 2024 
An interview with Morris Chang on starting TSMC at the age of 55, the company not designing or selling its own chips, returning to Taiwan from the US, 
German BSI warns of 17,000 unpatched Microsoft Exchange servers 
Implications of AI for Corporate Security 
CVE-2024-31213 
Plan to resuscitate beleaguered vulnerability database draws criticism 
Enter the substitute teacher 
DinodasRAT Linux implant targeting entities worldwide 
Treasury report calls out cyber risks to financial sector fueled by AI 
The DDR Advantage: Real-Time Data Defense 
Security Vulnerability in Saflok s RFID-Based Keycard Locks 
Chinese hackers target family members to surveil hard targets 
US investors, like General Atlantic and Sequoia, are facing increased pressure from state and federal lawmakers about their investments in Chinese com 
Source: Tencent agrees to release some of its most important apps on the Apple Vision Pro; sources: Meta plans to release a cheaper Quest for China in 
Adobe adds a "structure reference" feature to Firefly AI, letting users upload an image to guide the model about the "arrangement" 
Source: Tencent agrees to release some of its most important apps on the Apple Vision Pro (Wayne Ma The Information) 
Vulnerability Summary for the Week of March 18, 2024 
Keep the lines of communication open by building your own infrared transmitter 
Metasploit Framework 6.4 Released 
Fortnite: When Dollars and Cents Trumps Security! 
Having The Security Rug Pulled Out From Under You 
Liquidmatrix Security Digest Podcast – Episode 74 
Exploring Legacy Unix Security Issues 
Liquidmatrix Security Digest Podcast – Episode 75 
Liquidmatrix Security Digest Podcast – Episode 76 
Unsaflok flaws allow to open millions of doors using Dormakaba Saflok electronic locks 
Some experts say the DOJ's Apple lawsuit makes a strong case for harm to consumers and developers, but proving Apple's market power could be 
Texas Eclipse Festival offers a 'choose your own adventure experience' for April total solar eclipse 
German political party targeted by SVR-linked group in spearphishing campaign, Mandiant says 
German political party targeted by SVR in spearphishing campaign, Mandiant says 
CrowdStrike Enhances Cloud Detection and Response (CDR) Capabilities to Protect CI CD Pipeline 
Proven Methods for the Quiet Security Professional To Own Their Narrative 
Sources: the BBC plans to build its own AI models, and is holding talks with tech companies, including Amazon, about selling its content for AI traini 
U.S. Sanctions Russians Behind 'Doppelganger' Cyber Influence Campaign 
CVE-2024-29891 
CVE-2024-29888 
Epic plans to release the Epic Games Store on iOS and Android later this year, with the same terms as the ones for PC, including a 12% commission on s 
Pwned by the Mail Carrier 
Android malware, Android malware and more Android malware 
Navigating the EU compliance landscape: How Detectify helps support customers in their NIS2 Directive, CER, and DORA compliance challenges 
Solaris, which lets companies offer their own financial services via APIs, raised a €96M Series F led by SBI Group, bringing its total fundin 
Michigan lawyer in voting machine tampering case arraigned in D.C. 
Source: Ant Group CEO and Chair Eric Jing says Han Xinyi will be named president and some units plan to set up their own boards to operate more indepe 
Source: Ant CEO and Chair Eric Jing says Han Xinyi will become Ant Group president and some units plan to set up their own boards to operate more inde 
5 Best Practices to Secure Azure Resources 
Vulnerability Summary for the Week of March 11, 2024 
Automate your Crypto Journey With Binance Auto Invest 
Rapid7 offers continued vulnerability coverage in the face of NVD delays 
Inside generative AI music startup Suno, whose model can compose songs, including human vocals, using a text prompt, as Suno aims to "democratize 
Remote Access Policy 
Inside generative AI music startup Suno, whose model can compose songs, including human vocals, using a text prompt, as Suno aims to democratize music 
Inside generative AI music startup Suno, whose model can compose songs, including human vocals, using a text prompt, as it aims to democratize music m 
CVE-2024-29181 
Overcoming our “bossypants” bias 
Taiwan is building its own satellite internet network, as China's threats, Ukraine war, and Elon Musk's total control over Starlink make Tai 
CEO of Data Privacy Company Onerep.com Founded Dozens of People-Search Firms 
Keeping Customer Data Safe: AI’s Privacy Paradox 
FCC approves cybersecurity label for consumer devices 
Rapid7 s Ciara Cullinan Recognized as Community Trailblazer in Belfast Awards Program 
The Anatomy of an ALPHA SPIDER Ransomware Attack 
Does Your MDR Deliver Outcomes or Homework? 
Keep Your Network Secure With This $39.99 CompTIA Bundle 
Researchers found multiple flaws in ChatGPT plugins 
Security Flaws within ChatGPT Ecosystem Allowed Access to Accounts On Third-Party Websites and Sensitive Data 
CVE-2024-29018 
CVE-2024-29033 
CVE-2024-29037 
Summoning RAGnarok With Your Nemesis 
Threat Intelligence for Financial Services 
Google DeepMind details SIMA, an AI agent training to learn gaming skills to play like a human; SIMA trained on No Man's Sky, Goat Simulator 3, a 
Ethical Hacking: Getting Started on Your Own - Analytics Insight 
Tweaks Stealer Targets Roblox Users Through YouTube and Discord 
Bluesky open sources its collaborative moderation tool Ozone and plans to let users run their own independent moderation services later this week (Ais 
Top 10 web application vulnerabilities in 2021 2023 
EU countries reach a compromise deal on gig economy workers' rights, breaking a logjam by letting states make decisions; EU Parliament and member 
Biden’s budget proposal seeks funding boost for cybersecurity 
Vulnerability Summary for the Week of March 4, 2024 
Thomson Reuters CEO Steve Hasker says the group has $8B to spend on AI acquisitions and investments, to transform its businesses of supplying professi 
Thomson Reuters CEO Steve Hasker says the group has $8B to spend on M&A and AI investments, to help transform its businesses of supplying professi 
CVE-2024-28850 
An interview with Slack CEO Denise Dresser about bringing her own personality to the job, plans to use generative AI, competing with Microsoft Teams,  
Salt Security, API Posture Governance, and the NIST Cybersecurity Framework 2.0 
Indian political parties BJP and Congress have created and shared AI-crafted political content on Instagram, Facebook, and YouTube, without explicit d 
A Close Up Look at the Consumer Data Broker Radaris 
WhatDR or What Detection Domain Needs Its Own Tools? 
CVE-2024-2339 
CVE-2024-2338 
Around We Go: Planet Stealer Emerges 
The EU confirms requesting further explanations from Apple over removing Epic's developer account under the DMA, and is examining if Apple broke  
The EU confirms requesting further explanations from Apple over barring Epic's developer account under the DMA, and is examining if Apple broke a 
Spam and phishing in 2023 
Hackers Exploiting iOS 0-Day To Attack iPhones – Patch Now! 
CVE-2024-28240 
CVE-2024-28244 
Browserless Entra Device Code Flow 
Hackers Abuse QEMU Hardware Emulator for Stealthy C2 Communication 
CVE-2024-28189 
Badgerboard: A PLC backplane network visibility module 
CISA ADDS MICROSOFT WINDOWS KERNEL BUG USED BY LAZARUS APT TO ITS KNOWN EXPLOITED VULNERABILITIES CATALOG 
7 Rapid Questions with #77 Ray Bourque 
Network tunneling with QEMU? 
TrustCloud Welcomes Security and Compliance Expert Dixon Wright as VP GRC Transformation 
Vulnerability Summary for the Week of February 26, 2024 
New GTPDOOR backdoor is designed to target telecom carrier networks 
Sources: Google is offering to relist the apps of ten big Indian developers on the Play Store if they agree to route any payments through their own we 
ALPHV website goes down amid growing fallout from Change Healthcare attack 
Metasploit Weekly Wrap-Up 03 01 2024 
Predator spyware endures even after widespread exposure, analysis shows 
Five Eyes Warn of Ivanti Vulnerabilities Exploitation, Detection Tools Insufficient 
Ex-Cybercrime Forum Community Member Runs a Profitable Penetration Testing Business – An Analysis 
TunnelBear VPN Free vs. Paid: Which Plan Is Right for You? 
Tools of the (Illegitimate) Trade: Mock API 
How better key management can close cloud security gaps troubling US government 
Chinese Mini PC Maker Acemagic Ships machines with Malware Pre-installed 
Lazarus APT exploited zero-day in Windows driver to gain kernel privileges 
MyBKExperience.com Survey for Free Whopper Online in 2024 
Lazarus Hackers Exploited Windows 0-Day to Gain Kernel read write Access 
CISA Releases Resource Guide for University Cybersecurity Clinics 
Adobe unveils Project Music GenAI Control, a platform that can generate audio from text descriptions or a reference melody and let users customize the 
Researchers Uncover Tools And Tactics Used By Chinese Hackers 
Possibly habitable Trappist-1 exoplanet caught destroying its own atmosphere 
Vulnerability Summary for the Week of February 19, 2024 
Feds say AI favors defenders over attackers in cyberspace so far 
An educational robot security research 
TimbreStealer campaign targets Mexican users with financial lures 
Russia-linked APT29 switched to targeting cloud services 
LockBit claims a comeback less than a week after major disruption 
CVE-2024-27899 
CVE-2021-46964 
Zombie star earns metal scar while chewing its own planets: 'Nothing like this has been seen before' 
SVR Cyber Actors Adapt Tactics for Initial Cloud Access 
FBI’s LockBit Takedown Postponed a Ticking Time Bomb in Fulton County, Ga. 
LockBit is back and threatens to target more government organizations 
CVE-2024-27403 
The Problem is the People, but Which People? 
After LockBit takedown, police try to sow doubt in cybercrime community 
Microsoft released red teaming tool PyRIT for Generative AI 
Yelp says its tests show the design tweaks Google made to its search results to comply with the EU's DMA are unfair and one made users less likel 
Sources: staff warned Meta in 2023 that its Facebook and Instagram subscription tools were being misused by adults profiting from exploiting their own 
Yelp says its tests show design tweaks Google made to its search results to comply with EU's DMA are unfair and make users even more likely to st 
An investigation finds thousands of parent-run Instagram accounts posting images of their own children attracting pedophiles, who sometimes pay for mo 
Sources: staff warned Meta in 2023 that its subscription tools on Facebook and Instagram allowed adults to profit from exploiting their own children ( 
Bluesky opens up federation, letting anyone run their own server that connects to Bluesky's network, which uses the AT Protocol; Mastodon uses Ac 
Beyond the border scam , pay attention to the instance of the new Nigerian fraud 
TikTok s latest actions to combat misinformation shows it s not just a U.S. problem 
Bluesky opens up federation, letting anyone run their own server connecting to Bluesky's network, which uses the AT Protocol; Mastodon uses Activ 
New 'Lunarcraft' game lets you build your own moon base in the Minecraft world 
New Leak Shows Business Side of China’s APT Menace 
SCCM Hierarchy Takeover with High Availability 
Leaked documents show how firm supports Chinese hacking operations 
Microsoft rolls out expanded logging six months after Chinese breach 
HYAS Product Enhancements – Part 1 – February 2024 
Biden signs executive order to give Coast Guard added authority over maritime cyber threats 
New Redis miner Migo uses novel system weakening techniques 
How CVSS 4.0 changes (or doesn t) the way we see vulnerability severity 
Biden to sign executive order to give Coast Guard added authority over maritime cyber threats 
Mitigating the Identity Risks of Ex-Employees Accounts 
Biden executive order gives Coast Guard added authority over maritime cyber threats 
How to protect your machinelearning Models 
What Channel Is Peacock on DIRECTV: Detailed Guide 
Demos from AI chipmaker Groq go viral after the startup's inference engine shows lightning-fast speeds when running LLMs, including for real-time 
Demos from AI chip maker Groq go viral after the company's inference engine shows remarkable speeds running LLMs, including with real-time conver 
Vulnerability Summary for the Week of February 12, 2024 
Feds Seize LockBit Ransomware Websites, Offer Decryption Tools, Troll Affiliates 
Explanation of New Authenticated Scanning PCI DSS Requirement 11.3.1.2 in PCI DSS V4.0 and how InsightVM can help meet the Requirement 
Royal Mail hackers locked out of own website after raid - The Telegraph 
Britain and FBI lock notorious hackers out of their own site - The Times 
Britain and FBI lock notorious hackers out of their own website in major operation - The Independent 
UK and US hack the hackers to bring down LockBit crime gang 
Russian hackers locked out of their own website as police and FBI launch cyber raid - The Telegraph 
UK and FBI take over ransomware group s website 
UK and FBI lock cybercrime group out of ransomeware group s website 
Build your own moon base and explore the lunar surface in 'Moonshot' (video) 
How BRICS Got “Rug Pulled” Cryptocurrency Counterfeiting is on the Rise 
Does moving to the cloud mean compromising on security? 
BucketLoot - An Automated S3-compatible Bucket Inspector 
PurpleKeep - Providing Azure Pipelines To Create An Infrastructure And Run Atomic Tests 
BounceBack - Stealth Redirector For Your Red Team Operation Security 
CVE-2024-26690 
CVE-2024-26606 
CVE-2024-27092 
CVE-2024-26769 
FalconHound - A Blue Team Multi-Tool. It Allows You To Utilize And Enhance The Power Of BloodHound In A More Automated Fashion 
Raven - CI CD Security Analyzer 
Pmkidcracker - A Tool To Crack WPA2 Passphrase With PMKID Value Without Clients Or De-Authentication 
CloudRecon - Finding assets from certificates 
EasyEASM - Zero-dollar Attack Surface Management Tool 
WebCopilot - An Automation Tool That Enumerates Subdomains Then Filters Out Xss, Sqli, Open Redirect, Lfi, Ssrf And Rce Parameters And Then Scans For  
CATSploit - An Automated Penetration Testing Tool Using Cyber Attack Techniques Scoring 
WiFi-password-stealer - Simple Windows And Linux Keystroke Injection Tool That Exfiltrates Stored WiFi Data (SSID And Password) 
ProcessStomping - A Variation Of ProcessOverwriting To Execute Shellcode On An Executable'S Section 
Linpmem - A Physical Memory Acquisition Tool For Linux 
Lean In for Yourself 
Sources: Nintendo told game publishers the Switch 2's launch is delayed from late 2024 to Q1 2025; source: Nintendo needs more time to prepare it 
The Most Dangerous Entra Role You ve (Probably) Never Heard Of 
Metasploit Weekly Wrap-Up 02 16 2024 
CrowdStrike Named the Only Customers’ Choice: 2024 Gartner Voice of the Customer for Vulnerability Assessment 
Wireshark 4.2.3 Released – What s New! 
Private Odysseus lunar lander heads for the moon after SpaceX launch 
Private 'Odysseus' lander heads for the moon after SpaceX launch 
DOJ, FBI disrupt Russian intelligence botnet 
How to Protect Your Machine Learning Models 
Hackers got nearly 7 million people s data from 23andMe. The firm blamed users in very dumb move 
C can be memory safe, part 2 
Zuckerberg makes valid points on the Quest 3 being better overall than the Vision Pro today, but he risks having his own "Ballmer laughs off the  
U.S. Internet Leaked Years of Internal, Customer Emails 
Meta details actions against eight spyware firms 
LogMeOnce Review (2024): Is It a Safe & Reliable Password Manager? 
Ubuntu 'command-not-found' Tool Could Trick Users into Installing Rogue Packages 
Google: Iranian, regional hacking operations that target Israel remain opportunistic but focused 
Patch Tuesday - February 2024 
How to Secure Business-Critical Applications 
Vulnerability Summary for the Week of February 5, 2024 
Canadian astronaut reveals Indigenous art patch for Artemis 2 moon mission 
Black History Month - The Art of Intelligence: Portraits of Diversity, Learning, & Skill 
A Valentine s warning about heartbreak hackers 
9 Possible Ways Hackers Can Use Public Wi-Fi to Steal Your Sensitive Data 
Cybercriminals are creating their own AI chatbots to support hacking and scam users - Tech Xplore 
Exploiting a vulnerable Minifilter Driver to create a process killer 
John Walker, a computer programmer and co-founder of 3D design software maker AutoDesk, died on February 2 at the age of 75 (Steven Sinofsky @stevesi) 
Cybercriminals are creating their own AI chatbots to support hacking and scam users - The Conversation Indonesia 
CVE-2024-25707 
Spyware isn t going anywhere, and neither are its tactics 
Cybercriminals are creating their own AI chatbots to support hacking and scam users - The Conversation 
Cybercriminals are creating their own AI chatbots to support hacking and scam users - Yahoo News UK 
Super Bowl security tips for planning corporate security strategy 
How to Activate & Access PlayStation Plus 14 Day Trial Codes 
CVE-2024-25604 
Left to their own devices: Security for employees using personal devices for work 
New Webinar: 5 Steps to vCISO Success for MSPs and MSSPs 
Inside Zuzalu, a co-living experiment organized by Vitalik Buterin in Montenegro in 2023, as the techno-utopian "Network State" concept insp 
Fox, ESPN, and WBD announce a new joint venture to launch a streaming sports service in the US in the fall of 2024; each entity will own a third of th 
Google: Governments need to do more to combat commercial spyware 
How are user credentials stolen and used by threat actors? 
Migrate Off That Old SIEM Already! 
What the 6 Phases of the Threat Intelligence Lifecycle Mean for Your Team 
Vulnerability Summary for the Week of January 29, 2024 
What is the Cyber Kill Chain? And How to Use It with Threat Intelligence? 
Applying Threat Intelligence to the Diamond Model of Intrusion Analysis 
CVE-2024-25114 
Microsoft Breach What Happened? What Should Azure Admins Do? 
Microsoft Breach How Can I See This In BloodHound? 
Metasploit Weekly Wrap-Up 02 02 2024 
Stomp Rocket 'targets' NASA history with new space toy collection 
U.S. government sanctions Iranian officials over Pennsylvania water facility hack 
Rapid7 in Prague: Pete Rubio Shares Insights and Excitement for the New Office 
Passkeys and The Beginning of Stronger Authentication 
The many ways electric cars are vulnerable to hacks, and whether that matters in a real-world 
Google plans to limit news publishers to tracking users across five of their own websites under its Privacy Sandbox, which is set to replace third-par 
Arrests in $400M SIM-Swap Tied to Heist at FTX? 
US military eyes SpaceX Starship for 'sensitive and potentially dangerous missions': report 
Unveiling the AWS Public IP Puzzle: Solvo s Query and Cost-Saving Tips 
ICS and OT threat predictions for 2024 
Sources: TikTok plans to open studios in several cities, including LA, where creators can livestream and sell products, a strategy that worked for Dou 
White House releases report on securing open-source software 
Fla. Man Charged in SIM-Swapping Spree is Key Suspect in Hacker Groups Oktapus, Scattered Spider 
'Starfield' spacesuit contest: ESA and Xbox will build the winner their own custom design (video) 
Vulnerability Summary for the Week of January 22, 2024 
CVE-2024-24747 
In his new book, a16z investor Chris Dixon argues that blockchain is morally neutral tech that regulators must detach from the crypto industry's  
In his new book, a16z VC Chris Dixon argues blockchain is a morally neutral tech that regulators must differentiate from the crypto industry's ca 
Mozilla criticizes Apple's plans to restrict BrowserEngineKit to EU-specific apps, forcing "Firefox to build and maintain two separate brows 
Source: Chamath Palihapitiya shelved plans to raise $1B for an early-stage investment fund, in part due to fundraising challenges (Kia Kokalitcheva Ax 
Source: Chamath Palihapitiya shelved plans to raise $1B for an early-stage investment fund due to fundraising challenges and other issues (Kia Kokalit 
90 Days of Learning, Good Surprises and Extreme Optimism 
Apple will allow third-party apps to use the iPhone's NFC chip in the EU, letting third-party payment services and banks offer their own tap-to-p 
Apple will allow apps to access and use the iPhone's NFC chip in the EU, letting third-party payment services and banks offer their own tap-to-pa 
Building the Best SOC Takes Strategic Thinking 
Some Chinese investors are using creative methods to own bitcoin and other crypto that they believe are safer than China's crumbling stock and pr 
Kasseika Ransomware Using BYOVD Trick to Disarm Security Pre-Encryption 
CVE-2024-24576 
Ahead of the EU's DMA, Spotify shares iOS app mockups with full in-app payments, rolling out in part on March 7; Apple hasn't yet shared its 
Kasseika Ransomware Using BYOVD Trick to Disarms Security Pre-Encryption 
What is Nudge Security and How Does it Work? 
CFPB’s proposed data rules would improve security, privacy and competition 
Ahead of the EU's DMA, Spotify shares iOS app mockups with full in-app payments, rolling out in part on March 7; Apple has not yet shared details 
CVE-2024-0860 
How to Use Context-Based Authentication to Improve Security 
A look at Nvidia and Convai's AI-powered video game NPCs, which are effectively generative AI chatbots that players can talk to, instead of using 
A look at Nvidia and Convai's AI-powered video game NPCs, which are effectively generative AI chatbots that interact with the players (Sean Holli 
Your data is under siege. Here s how to win the war. 
Jailed BreachForums creator, admin sentenced to 20 years of supervised release 
Metasploit Weekly Wrap-Up 01 19 24 
X rolls out audio and video calling to Android, after launching on iOS in October 2023; all users can receive calls, but only Premium subscribers can  
Canadian Man Stuck in Triangle of E-Commerce Fraud 
X rolls out audio and video calling to Android following the October 2023 iOS launch; all users can receive calls but only Premium subscribers can pla 
The Unseen Threats: Anticipating Cybersecurity Risks in 2024 
CVE-2024-23637 
What to do with that fancy new internet-connected device you got as a holiday gift 
Zuckerberg says Meta wants to build and open source AGI, and brings AI group FAIR closer to the generative AI team; Meta will own 340K+ H100 GPUs by 2 
Zuckerberg says Meta wants to build AGI and open source it, brings Meta's AI group FAIR closer to generative AI team; Meta will own 340K+ H100 GP 
Privacy, Security, and Connected Devices: Key Takeaways From CES 2024 
StatCounter: Bing ended 2023 with 3.4% global search market share, up less than 1 percentage point after ChatGPT; Google had 91.6%, Yandex 1.6%, and Y 
StatCounter: Bing ended 2023 with 3.4% global search market share, up less than one percentage point after ChatGPT; Google had 91.6%, Yandex 1.6%, and 
How To Bypass Starlink Router: Activate Bypass Mode 
CVE-2024-23564 
Vulnerability Summary for the Week of January 8, 2024 
Cyber Safety Review Board needs stronger authorities, more independence, experts say 
Metasploit 2023 Annual Wrap-Up: Dec. 29, 2023 
E-Crime Rapper ‘Punchmade Dev’ Debuts Card Shop 
It s Friday, I m [Writing That Typical CISO Email 
Application Security Posture Management 
A lightweight method to detect potential iOS malware 
CVE-2024-23349 
CVE-2024-23340 
Classic Baggie: A Delaware BEC Case calls him the leader of an International Criminal Organization 
DWARFLAB Dwarf II smart telescope review 
What Is Adversary Infrastructure? 
Cypher Queries in BloodHound Enterprise 
Patch Tuesday - January 2024 
Alert: New Vulnerabilities Discovered in QNAP and Kyocera Device Manager 
How to Activate My First Phase Card in 2024: Step-by-Step Guide 
The Mayo Clinic partners with Cerebras to use Cerebras' computing chips and systems to develop its own AI models based on anonymized medical reco 
Vulnerability Summary for the Week of January 1, 2024 
Meet Ika & Sal: The Bulletproof Hosting Duo from Hell 
Security Firm Certik s Account Hijacked to Spread Crypto Drainer 
CVE-2024-22313 
CVE-2024-22272 
CVE-2024-22281 
Exoplanet-hunting instrument measures Jupiter's wild wind speeds 
Ripples in the oldest known spiral galaxy may shed light on the origins of our Milky Way 
Genie Aladdin Connect Retrofit Garage Door Opener: Multiple Vulnerabilities 
The FBI is adding more cyber-focused agents to U.S. embassies 
Don t trust links with known domains: BMW affected by redirect vulnerability 
Navigating Election Risks: A Guide for Executives 
Starship, Starlink and more: SpaceX poised for huge 2024 
10 Ways to Fix Instagram Post Stuck on Sending 
Vulnerability Summary for the Week of December 25, 2023 
Top 5 Free Websites to Learn Hacking this 2024 
List of Secure Dark Web Email Providers in 2024 
50+ Network Penetration Testing Tools for Hackers & Security Professionals – 2024 
Lidar sensor tech is the latest flashpoint in the US-China trade war, as the US lidar industry mounts a lobbying offensive against Chinese companies l 
Metasploit 2023 Wrap-Up 
CVE-2024-21669 
Operation Triangulation attacks relied on an undocumented hardware feature 
NCWF - Resolve to improve your career 
CVE-2018-25096 
Operation Triangulation: The last (hardware) mystery 
2 Easy Methods to Bypass Netflix Household 
Vulnerability Summary for the Week of December 18, 2023 
Medical Emergency Assistance – Thank You 
CVE-2023-52079 
Learn Cybersecurity Skills From Scratch for Just $30 Through January 1 
Mobile virtual network operator Mint Mobile discloses a data breach 
Former staff say Meta considered exempting underage Facebook and Instagram user accounts from encryption but chose not to due to costs and potential l 
Securely Build AI ML Applications in the Cloud with Rapid7 InsightCloudSec 
Former employees say Meta considered exempting underage user accounts from encryption but rejected the plan due to associated costs and potential liab 
Former employees say Meta considered measures to limit encryption but rejected them to avoid potential liability for kids' safety on its apps and 
How to Use Claude Alternative To ChatGPT 
CVE-2024-21583 
Metasploit Weekly Wrap-Up: Dec. 15, 2023 
Missing the Lock Icon in Chrome s Address Bar? It s a Move to Make You More Secure 
Windows CLFS and five exploits used by ransomware operators (Exploit #1 – CVE-2022-24521) 
Windows CLFS and five exploits used by ransomware operators 
How to Fix Disney Plus Stuck on Loading Screen on PC TV Phone 
Fix My Singing Monsters Facebook Login Not Working or Down 
Interviews with 20 current and former Meta and Google staff say FTC consent decrees blocked some user data harvesting, but they are now outdated and i 
Interviews with 20 Meta and Google staff say FTC consent decrees sometimes blocked data harvesting, but the agreements are now outdated and inadequate 
Interviews with 20 current and former Meta and Google staff say FTC consent decrees sometimes blocked misuse, but the agreements are now outdated and  
BMW dealer at risk of takeover by cybercriminals 
FBI claims to have dismantled AlphV Blackcat ransomware operation, but the group denies it 
Chinese, Russian interference attempts on 2022 midterms didn t impact voting, intelligence agencies say 
10 Cybersecurity Trends That Emerged in 2023 
Choosing the Best EDR for Your Organization Can Be Complicated But It Doesn t Need To Be 
Episode 254: Dennis Giese’s Revolutionary Robot Vacuum Liberation Movement 
Vulnerability Summary for the Week of December 11, 2023 
How to Fix Samsung Phone Not Detecting Sim Card 
SEC disclosure rule for material cybersecurity incidents goes into effect 
Info stealers and how to protect against them 
OpenAI says "ByteDance's use of our API was minimal", but suspends the account and investigates, after a report that ByteDance used Ope 
Disney, WBD, and other studios are licensing more content to Netflix in return for much-needed cash, but are holding back their most popular movies an 
OpenAI says ByteDance's use of its API was minimal, suspends ByteDance's account while it investigates a report that ByteDance used OpenAI&a 
CVE-2023-50948 
Docs: ByteDance used OpenAI's API to develop its own LLM, codenamed Project Seed; employees discussed "whitewashing" the evidence throu 
Docs: ByteDance used OpenAI API to develop its own LLM, codenamed Project Seed; employees discussed "whitewashing" the evidence through &quo 
Okta’s Cinderella Story 
Idaho National Laboratory data breach impacted 45,047 individuals 
Ubiquiti users claim to have access to other people s devices 
A personal Year in Review to round out 2023 
China launches secret space plane on 3rd-ever mission 
Ten Years Later, New Clues in the Target Breach 
Russia-linked APT29 spotted targeting JetBrains TeamCity servers 
Amazon launches Your Books, a feature that lets users organize all their books, including print, Kindle, and Audible titles, while providing recommend 
Taking a Proactive Approach to Mitigating Ransomware Part 2: Avoiding Vulnerabilities in SAP Applications 
Amazon launches Your Books, a hub to let users organize all of their books, including print, Kindle, and Audible titles, while also providing recommen 
Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally 
CVE-2023-6788 
AI threats pose great cyber risks to smaller companies, experts tell House panel 
Patch Tuesday - December 2023 
SAP Patch Day: December 2023 
CISA Releases SCuBA Google Workspace Secure Configuration Baselines for Public Comment 
Will Google Gemini Win the AI Race? 
Vulnerability Summary for the Week of December 4, 2023 
Living our Values and Leveraging Diverse Skill Sets: How Jonathan Atwood Built a Successful Career as a Customer Advisor at Rapid7 
Ukraine Is Crowdfunding Its Reconstruction 
Operation Blacksmith: Lazarus targets organizations worldwide using novel Telegram-based malware written in DLang 
Story of the year: the impact of AI on cybersecurity 
Paris-based Mistral AI raised €385M, or $415M, from investors including a16z and Lightspeed; sources say the deal values the 22-person start 
Paris-based Mistral AI has raised €385M, or about $415M, from investors including a16z and Lightspeed; sources say the deal values the 22-per 
CVE-2023-6687 
CVE-2023-50723 
54-year-old Wayanad woman takes own life after hacking friend to death: Report - Mathrubhumi English 
Paris-based Mistral AI has raised €385M, or about $415M, with investors including a16z and Lightspeed; sources: the deal values Mistral at ab 
How to Connect a Samsung Tablet to Windows 11 PC 
5Ghoul flaws impact hundreds of 5G devices with Qualcomm, MediaTek chips 
WTH is Modern SOC, Part 1 
Ekran System s Cyber Essentials Certification: Enhanced Software & Supply Chain Security 
Metasploit Wrap-Up 12 8 2023 
Cybersecurity considerations to have when shopping for holiday gifts 
India sets sights on a moon base by 2047 
Spying through Push Notifications 
Sony's Discovery content removals due to licensing "arrangements" and unexpected account bans are timely reminders of why users don&apo 
New Krasue Linux RAT targets telecom companies in Thailand 
Top Security Trends and Predictions for 2024 
New Stealthy 'Krasue' Linux Trojan Targeting Telecom Firms in Thailand 
CVE-2023-50332 
Iran launches 'bio-space capsule' protoype, aims to fly astronauts by 2030 
Beers with Talos episode 141: The TurkeyLurkey Man wants YOU to read Talos' Year in Review report 
New macOS Trojan-Proxy piggybacking on cracked software 
The Critical Importance of Cyber Health in Personal Cybersecurity for Executives 
Behind EB Control s Revolutionary Patented Key Management System 
How The Disinformation Machine Works, And How $400 Can Stop It 
How to Install Third-Party Apps in Samsung Smart TV 
Nvidia CEO Jensen Huang says the company plans to build a network of chip plants in Japan in partnership with the country's companies to meet AI  
CVE-2024-20837 
USB-C For Hackers: Program Your Own PSU - Hackaday 
Project PowerUp Helping to keep the lights on in Ukraine in the face of electronic warfare 
Internal memo: ByteDance plans to release a "bot development platform" in beta by the end of December, to let users create their own AI chat 
Active Attacks Targeting Google Chrome & ownCloud Flaws: CISA Warns 
Fortune-telling website WeMystic exposes 13M+ user records 
CVE-2023-49922 
The Qlik Cyber Attack: Why SSPM Is a Must Have for CISOs 
Threat Sequencing from the Darkside 
CISA adds ownCloud and Google Chrome bugs to its Known Exploited Vulnerabilities catalog 
IT threat evolution Q3 2023 
$19 Stanely cups, fake Amazon Prime memberships all part of holiday shopping scams circulating 
Artemis 2 moon astronauts autograph their own rocket 1 year before launch 
Rapid7 Takes Next Step in AI Innovation with New AI-Powered Threat Detections 
How deepfake porn victims in NYC suburb Levittown helped convict the perpetrator, a former classmate, an ordeal further complicated by the lack of cle 
How a group of deepfake porn victims in NYC suburb Levittown helped convict the perpetrator, an ordeal that was further complicated by the lack of cle 
Okta reveals additional attackers’ activities in October 2023 Breach 
Threat actors started exploiting critical ownCloud flaw CVE-2023-49103 
AWS Launches New Chips for AI Training and Its Own AI Chatbot 
AWS plans to offer access to Nvidia's H200 chips, following Azure's similar dual-pronged approach of offering its own Maia chips as well as  
ID Theft Service Resold Access to USInfoSearch Data 
CrowdStrike s View on the New U.S. Policy for Artificial Intelligence 
Vulnerability Summary for the Week of November 20, 2023 
Building our Team in Prague: Meet Martin Votruba 
How to Enable Remote Desktop Connection in Windows 11 
Save 40% on this adorable LEGO Battle of Endor Heroes set this Black Friday weekend 
50% Black Friday discount: Star Wars fans, build your own Grogu with this huge LEGO deal 
Grab a mesmerizing star projector for less than $20 this Black Friday 
Smashing Security podcast #349: Ransomware gang reports its own crime, and what happened at OpenAI? 
CISA adds Looney Tunables Linux bug to its Known Exploited Vulnerabilities catalog 
Shadow IT Has Met Its Match: Ensuring Compliance When Your Employees Skirt the Rules 
Tor Project removed several relays associated with a suspicious cryptocurrency scheme 
Navigating the Evolving Landscape of File-Based Cyber Threats 
Apple has hired team of hackers in attempt to break into its own ... - UNILAD 
Source: OpenAI board members seek to hire their own CEO to succeed Sam Altman; sources: Mira Murati plans to rehire Altman and Greg Brockman in some c 
Hotel Hacker Faked His Own Death by Hacking Into State Death ... - The Messenger 
A Hacker Faked His Own Death Then Claimed To Have Sold Marriott Customer Data To Russians, FBI Says - Forbes 
Scattered Spider Casino Hackers Evade Arrest in Plain Sight 
A Hacker Faked His Own Death Then Claimed To Have Sold ... - Forbes 
A deep dive into Phobos ransomware, recently deployed by 8Base group 
What is Data Protection By Design? 
Hacker group files SEC complaint against its own victim - SC Media 
Microsoft downplays damaging report on Chinese hacking its own ... - CyberScoop 
Sources: Apple may again postpone releasing its own iPhone modem chip, until at least late 2025 or early 2026, the final year of its extended Qualcomm 
Vulnerability Summary for the Week of November 6, 2023 
Sources: Apple may postpone the release of its own iPhone modem chip until at least the end of 2025 or early 2026, the final year of its contract with 
U.S. officials urge more information sharing on prolific cybercrime group 
We all just need to agree that ad blockers are good 
The ABCs of API Security: A New (Free!) Learning Center 
High-energy cosmic rays may originate within the Milky Way galaxy 
Tether plans to spend $500M over the next six months to become one of the world's top Bitcoin miners, after acquiring a 20% stake in Northern Da 
Scattered Spider 
Making Proxy Security a Priority For a Safer Future 
Google rolls out Bard access for teens that "meet the minimum age requirement to manage their own Google Account" and have English set, with 
Merlin s Evolution: Multi-Operator CLI and Peer-to-Peer Magic 
Amazon plans to merge its Comixology app with Kindle on December 4, and automatically integrate all comics that Comixology users own into their Kindle 
Google launches two Titan Security Keys with FIDO2 that can store up to 250 unique passkeys, and commits to giving 100K security keys to high-risk use 
Amazon is merging the Comixology app with Kindle on December 4, and all comics that users own via Comixology will be integrated into their Kindle libr 
Google updates its Titan Security Key lineup with FIDO2 models that can store more than 250 unique passkeys (Abner Li 9to5Google) 
Northern lights webcams: Watch the aurora borealis online for free 
Microsoft unveils Copilot Studio, a no-code tool that lets companies customize Microsoft 365 Copilot or integrate custom ChatGPT chatbots made with Op 
Microsoft announces Copilot Studio, a no-code tool to build on 365 Copilot to let businesses create a custom copilot or integrate a custom ChatGPT cha 
Google launches Notes, an experiment to let users that opt-in via Search Labs annotate search results, including with images and colorful fonts (Jay P 
The Art of Defending Your Attack Surface 
Daniel plays the hackers at their own game! - Donegal Daily 
Patch Tuesday - November 2023 
NASA's Mars robots are on their own right now here's why 
Advanced threat predictions for 2024 
Palo Alto Networks SOC Update Extends Machine Learning Reach 
New Ransomware Group Emerges with Hive's Source Code and Infrastructure 
North Korea-linked APT Sapphire Sleet targets IT job seekers with bogus skills assessment portals 
Domain Control Validation (DCV) Methods & How to Choose 
Top 8 Ways to Fix NFL Fantasy App Not Working or Crashing 
How to Fix Samsung TV Half Screen Dark on One Side 
Whatsapp Web Keeps Logging Out? Here’s How to Fix 
The Power of Complex Binary Analysis 
This viral hack makes your sofa look brand new using household items you already own - Yahoo Life 
Build your own AI-powered Perseverance Mars rover with this new DIY kit 
A new video series, Google Forms spam and the various gray areas of cyber attacks 
NEW RESEARCH: Artificial intelligence and Machine Learning Can Be Used to Stop DAST Attacks Before they Start 
The Intricacies of Constructing an Efficient Security Operations Center 
What is NIS2, and how can you best prepare for the new cybersecurity requirements in the EU? 
Spammers abuse Google Forms quiz to deliver scams 
Modern Asian APT groups’ tactics, techniques and procedures (TTPs) 
A Deep Dive into GraphQL API with Python Client 
Decoupling for Security 
Samsung unveils a generative AI model called Gauss, which is being used for employee productivity internally and will be expanded to product applicati 
CVE-2024-20381 
CVE-2024-20444 
Reddit starts testing its own add-ons, including those that make posts with live scoreboards and that help mods ban spammers, with a small number of s 
Reddit starts testing add-ons, first with a small number of communities, including tools to make posts with live scoreboards and to help mods ban spam 
New GootLoader Malware Variant Evades Detection and Spreads Rapidly 
Domain of Thrones: Part II 
Vulnerability Summary for the Week of October 30, 2023 
Europe is trading security for digital sovereignty 
Gootloader Aims Malicious, Custom Bot Army at Enterprise Networks 
Gaming-related cyberthreats in 2023: Minecrafters targeted the most 
You d be surprised to know what devices are still using Windows CE 
Okta customer support system breach impacted 134 customers 
Amazon settles UK CMA probes over use of third-party data, agreeing not to use "non-public" third-party seller data to benefit its own produ 
Grow Your Business with Identity Data, Part 2 
Russian Reshipping Service ‘SWAT USA Drop’ Exposed 
Join the Cloud Native Community at KubeCon + CloudNativeCon North America 
CVE-2023-20244 
.US Harbors Prolific Malicious Link Shortening Service 
Arid Viper disguising mobile spyware as updates for non-malicious Android applications 
AAAI Fall Symposium: Patr cia Alves-Oliveira on human-robot interaction design 
SBF blamed top FTX executives on his second day of testimony, and lawyers disputed his answers using his own emails, DMs, tweets, and more; some were  
Vulnerability Summary for the Week of October 23, 2023 
SBF blamed top FTX execs on day two of testimony, and lawyers disputed his answers by confronting him with his own emails, chats, tweets, and more, so 
Lateral Movement: Abuse the Power of DCOM Excel Application 
Do humans get lazier when robots help with tasks? 
CVE-2022-22466 (security_verify_governance) 
The Full Hunter's Moon experiences a partial lunar eclipse on Oct. 28. Here's what to expect 
The Full Hunter's Moon experiences a partial lunar eclipse tomorrow. Here's what to expect 
A recap of FTX co-founder Sam Bankman-Fried's testimony at his own criminal fraud trial in NYC over the collapse of his cryptocurrency exchange ( 
How helpful are estimates about how much cyber attacks cost? 
A live blog of FTX co-founder Sam Bankman-Fried's testimony at his own criminal fraud trial in NYC over the collapse of his cryptocurrency exchan 
CVE-2023-46238 
How to catch a wild triangle 
Code to Joy: Why Everyone Should Learn a Little Programming Interview with Michael Littman 
StripedFly: Perennially flying under the radar 
CVE-2023-45134 
CVE-2023-39231 
CVE-2023-37909 
How it feels to be a victim of deepfake pornography 
Sam Bankman Fried's lawyers say SBF plans to testify in his own trial when they start their case later this week, after damaging testimony from h 
Sam Bankman Fried's lawyer says SBF plans to testify in his own trial when they start their case later this week, after damaging testimony from a 
Security provider Okta reports hack to its own support system - KGUN 9 Tucson News 
Kazakhstan-associated YoroTrooper disguises origin of attacks as Azerbaijan 
Domain of Thrones: Part I 
YouTube finally lets users update the cover art of their YouTube Music playlists, but only using images created by YouTube's generative AI, not t 
YouTube finally lets users update the cover art for YouTube Music playlists, but only using images created by YouTube's generative AI, not their  
Sources: many people inside Apple do not believe its own AI ML team can deliver on generative AI, and worry that the company will only use that team&a 
Why Digital Risk Protection Is Critical to Your Reputation 
October 2023 Patch Tuesday: 104 Vulnerabilities Including Three Actively Exploited Zero-Days 
Vulnerability Summary for the Week of October 16, 2023 
Sources: many people inside Apple do not believe its own AI ML team can deliver on generative AI, and worry that the company will only use its own tea 
A look at POSSE, a decade-old idea that a user should Publish (on your) Own Site and Syndicate Elsewhere, and the challenges of building a system base 
Security provider Okta reports hack to its own support system - Scripps News 
CVE-2022-22466 
Security provider Okta reports hack to its own support system - 25 News KXXV and KRHD 
Security provider Okta reports hack to its own support system - KMTV 3 News Now Omaha 
Security provider Okta reports hack to its own support system - KRIS 6 News Corpus Christi 
CVE-2023-45802 
Defending federal networks requires more than money, CSIS study finds 
Man takes his own life after hacking wife, son to death in Wayanad - Mathrubhumi English 
How to Connect Sony Headphones to Mac 2023: Quick Guide 
CVE-2023-4822 (grafana) 
CVE-2023-46117 
On Detection: Tactical to Functional 
Hackers Stole Access Tokens from Okta’s Support Unit 
CVE-2021-4335 
How Smart SOAR Enables Better Co-Managed SIEM Services 
CVE-2023-41893 
More helpful resources for users of all skill levels to help you Take a Security Action 
CVE-2023-33836 (security_verify_governance) 
Threat Informed Defense: Making ATT&CK Your Own 
How to Fix Lyca Mobile Outgoing Calls Not Working 2023 
Android TV Devices: Pre-0wned Supply Chain Security Threats 
ExpressVPN Review (2023): Pricing, Features, Pros, & Cons 
What is Cracktivator software? 
Updated MATA attacks industrial companies in Eastern Europe 
Roblox CEO David Baszucki says the company is "transitioning away" from remote work, as virtual workspaces aren't as engaging or produc 
APT trends report Q3 2023 
Spooky Experiments: Building Your Own Security Research Lab 
Vulnerability Summary for the Week of October 9, 2023 
More Aggressive Time-to-Exploit Vulnerability Trends Affect Oracle and SAP Security Too 
Securing the Cloud 
CVE-2023-4822 
Interview with Marek uppa: insights into RoboCupJunior 
CVE-2023-33836 
Easing job jitters in the digital revolution 
A look at the efforts by companies and governments to build their own satellite networks that can deliver internet connectivity anywhere on Earth (Chr 
A look at the efforts of companies and governments to build their own satellite networks that can deliver internet connectivity anywhere on Earth (Chr 
Should You Use Controversial Simulated Phishing Test Emails? 
ChatGPT at work: how chatbots help employees, but threaten business 
Filing: Sam Altman is the largest investor in Humane, which plans to unveil its AI Pin in November, with a 14.93% equity; Humane's two co-founder 
Top resources for Cybersecurity Awareness Month 
As Pat Gelsinger tries to revive Intel, his own deadline to add a big foundry client in 2023 looms and, even then, revenue from such a deal could be y 
Filing: Sam Altman is the largest investor in Humane, which plans to unveil its AI Pin next month, with a 14.93% equity; Humane's two co-founders 
USB-C For Hackers: Build Your Own PSU - Hackaday 
A Paramedic s Top 2 Tips for Cloud Incident Response 
What to know about the HTTP 2 Rapid Reset DDoS attacks 
Patch Tuesday - October 2023 
Vulnerability Summary for the Week of October 2, 2023 
CVE-2023-31096 
Exposed security cameras in Israel and Palestine pose significant risks 
Perfect Loader Implementations 
8 ways MSSPs gain competitive advantage with the SecOps Cloud Platform 
The source code of the 2020 variant of HelloKitty ransomware was leaked on a cybercrime forum 
How looking at decades of spam led Jaeson Schultz from Y2K to the metaverse and cryptocurrency 
Genshin Impact developer miHoYo has made two short-lived attempts since August to set up a payment system for iOS users, to avoid Apple's 30% App 
Facebook's own account is 'hacked': Social media users left bemused by bizarre posts including one demanding t - Daily Mail 
Multiple experts released exploits for Linux local privilege escalation flaw Looney Tunables 
Sources: OpenAI is exploring making its own AI chips and has evaluated a potential acquisition target; Sam Altman made acquiring more AI chips a top p 
Unlocking MDM for Small Business: What you need to know 
Sources: OpenAI is exploring making its own AI chips and has evaluated a potential acquisition target, as Sam Altman makes acquiring more chips a top  
Is it bad to have a major security incident on your r sum ? (Seriously I don t know) 
What s New in Rapid7 Detection & Response: Q3 2023 in Review 
How a Major Network and Cloud Security Provider Uses SafeBreach for Security Control Validation 
10 Bot Detection Tools for 2023: Features & Mitigation Methods 
Global CRM Provider Exposed Millions of Clients Files Online 
Free Roblox Hair Code Combos 2023 
Insurance Companies Have a Lot to Lose in Cyberattacks 
CVE-2023-42449 
50 women in robotics you need to know about 2023 
A cyberattack disrupted Lyca Mobile services 
Frec, which uses AI to let customers create their own investment strategies, comes out of stealth with $26.4M in Series A and seed funding led by Grey 
API Security Trends 2023 Have Organizations Improved their Security Posture? 
Researcher Reveals New Techniques to Bypass Cloudflare's Firewall and DDoS Protection 
CVE-2023-44129 (android) 
Vulnerability Summary for the Week of September 25, 2023 
What Does Zero Trust Mean in Data Security? 
Sources: John Giannandrea's team built a next-gen search engine, "Pegasus", for Apple's own apps, used in Spotlight and Siri, and  
A Closer Look at the Snatch Data Ransom Group 
FBI warns of dual ransomware attacks 
Python Serialization Vulnerabilities – Pickle 
A history of Vine's failure to build relationships with its top creators, who Vine leadership resented for gaming the app's ranking algorith 
What s New in InsightVM and Nexpose: Q3 2023 in Review 
Q3 2023 Analytic Co-Pilot Use Cases 
Vulnerability Summary for the Week of September 18, 2023 
Q&A: UK Ambassador on Creating New Cybersecurity Agencies Around the World 
The security pitfalls of social media sites offering ID-based authentication 
CVE-2023-43656 
Sources: Meta VP of Infrastructure Alexis Black Bjorlin, who oversees the company's efforts to develop AI chips, plans to step down at the end of 
Sources: Meta's VP of infrastructure, who oversees the company's efforts to develop its own chips for AI work, is leaving at the end of Sept 
CVE-2023-44129 
People's Republic of China-Linked Cyber Actors Hide in Router Firmware 
Snap closes AR Enterprise Services, launched in March 2023 to let retailers adapt Snap's AR technology for their own websites, citing high costs  
Building Custom Scenarios with CNAPPgoat 
People's Republic of China-Linked Cyber Actors Hide in Router Firmware 
Secrets of Aviator Popularity In India 
A short guide to Multidisciplinary Research 
Google Messages has been installed 5B+ times, after crossing 1B installations in May 2020 and becoming the default messaging app on most new Android d 
Embracing ESG Risk Management: It s Simpler Than You Imagine 
Google Messages has been installed 5B+ times, after crossing the 1B threshold in 2020 and since becoming a default installation on a majority of Andro 
ICS protocol coverage using Snort 3 service inspectors 
Spotify launches Jam, a new feature that lets up to 32 people curate a single playlist; only Premium subscribers can create Jams, but all users can co 
Introducing Active Risk 
Introducing InsightVM Active Risk 
CVE-2023-43631 (edge_virtualization_engine) 
Spotify partners with OpenAI to launch an AI-powered voice translation feature that reproduces podcasts in other languages using the podcaster's  
Unlock BYOD Benefits: Policy Guide for Small Business 2023! 
CVE-2023-42451 (mastodon) 
Building a Kubernetes Platform: How to Handle Cost Management & Reporting 
What s the point of press releases from threat actors? 
CVE-2023-43631 
Tether confirms resuming lending its stablecoins to clients, less than a year after committing to end such loans; $5.5B of its assets were loans as of 
LUCR-3 Attacking Fortune 2000 Companies Using Victims’ Own Tools & Apps 
Tether confirms resuming lending its stablecoins to customers, less than a year after saying it would end such loans; $5.5B of its assets were loans o 
Source: Google has extensively discussed dropping Broadcom for AI chips as early as 2027 to design its own TPUs, aiming to save billions of dollars an 
Overview of IoT threats in 2023 
T-Mobile App Glitch Exposes Other User s Sensitive Data 
Brainless robot can navigate complex obstacles 
Sources: the Kirin 9000S SoC has four CPUs that use Arm designs, the other four use Huawei-modified Arm designs, HiSilicon developed the GPU and NPU,  
DeepMind researchers detail Optimization by PROmpting to improve LLM performance by using "meta-prompts" like "take a deep breath" 
Sources and analysis: four of the eight CPUs in the Kirin 9000S SoC use Arm designs and four use Huawei-modified Arm designs, HiSilicon made the GPU,  
Companies Rely on Multiple Methods to Secure Generative AI Tools 
How to Fix Upgrade to iCloud for Windows Failed Error 
Battery-free origami microfliers from UW researchers offer a new bio-inspired future of flying machines 
CVE-2023-42451 
Who’s Behind the 8Base Ransomware Website? 
Vulnerability Summary for the Week of September 11, 2023 
Hispanic Heritage Month: ERG Employee Stories, Authenticity, and Learning 
'Star Wars' fan favorite Lando Calrissian is getting his own movie on Disney+ 
White House grapples with harmonizing thicket of cybersecurity rules 
Deepfake and smishing. How hackers compromised the accounts of 27 Retool customers in the crypto industry 
CVE-2023-41885 (piccolo) 
What is Tier Zero Part 2 
Kubernetes flaws could lead to remote code execution on Windows endpoints 
FBI Hacker Dropped Stolen Airbus Data on 9 11 
A new ransomware family called 3AM appears in the threat landscape 
Averting Catastrophe: How Votiro Cloud Shielded ALYN Hospital from a Potentially Devastating Attack 
Adobe, Apple, Google & Microsoft Patch 0-Day Bugs 
CVE-2023-41885 
Dreamforce 2023: Salesforce Expands Einstein AI and Data Cloud Platform 
You can try to hide your firmware from Kelly Patterson, but she ll find it (and break it) 
Qualcomm says Apple extended its modem deal for three more years, covering "smartphone launches in 2024, 2025, and 2026"; the prior deal was 
AI Chatbots Are Invading Your Local Government and Making Everyone Nervous 
Mysterious moonquake traced to Apollo 17 lunar lander base 
From Caribbean shores to your devices: analyzing Cuba ransomware 
Sources: Meta plans to begin training a new LLM in Q1 2024 on its own infrastructure and hopes the model will be roughly as capable as OpenAI's G 
Sources: Meta plans to begin training an LLM in Q1 2024 on its own infrastructure that it hopes will be roughly as capable as OpenAI's GPT-4 (Wal 
Some Wyze security camera owners report that they were briefly able to see feeds from cameras they didn't own or recognize; Wyze blames "a w 
Some Wyze security camera owners report briefly seeing feeds from cameras they didn't own or recognize; Wyze blames "a web caching issue&quo 
Ragnar Locker gang leaks data stolen from the Israel’s Mayanei Hayeshua hospital 
Microsoft, Google Take on Obsolete TLS Protocols 
Roblox announces Roblox Connect, letting users video chat with other people as their Roblox avatar in a shared virtual space, available later in 2023  
How to safeguard your AI ecosystem: The imperative of AI ML security assessments 
Software Supply Chain Strategies to Parry Dependency Confusion Attacks 
AI Data Consumption and Analysis are a Cybersecurity Force Multiplier 
Beyond the Code: Unearthing the Subtle Business Ramifications of Six Months in Vulnerabilities 
Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475 
Two flaws in Apache SuperSet allow to remotely hack servers 
Attention CISOs: Closing Your Identity Protection Gaps is Urgent 
Smashing Security podcast #338: Catfishing services, bad sports, and another cockup 
Vulnerability Summary for the Week of August 28, 2023 
This SUCKS: Cars Are a Privacy Nightmare, Mozilla Fumes 
Cyber professionals say industry urgently needs to confront mental health crisis 
Researchers identify high-grade phishing kits attacking nearly 60,000 Microsoft 365 accounts 
Experts Fear Crooks are Cracking Keys Stolen in LastPass Breach 
Shadow Wizard Registry Gang: Structured Registry Querying 
Bilyana Lilly on Western cybersecurity assistance to Ukraine 
Tackling loneliness with ChatGPT and robots 
How to Disable VPN From Your PC 2023: Turning Off VPN 
Jennifer Williams Most Influential People in Security 2023 
“Smishing Triad” Targeted USPS and US Citizens for Data Theft 
Avoid The Hack: 7 Best Private Search Engine Recommendations 
Talos wars of customizations of the open-source info stealer SapphireStealer 
Why is .US Being Used to Phish So Many of Us? 
Exploitation of Juniper Networks SRX Series and EX Series Devices 
CVE-2023-41034 
Pentagon UFO office unveils official website for US government personnel to report sightings 
SapphireStealer Malware: A Gateway to Espionage and Ransomware Operations 
Infamous Chisel Malware Analysis Report 
PenTales: What It s Like on the Red Team 
Abusing Windows Container Isolation Framework to avoid detection by security products 
Hashcat Tips and Tricks for Hacking Competitions: A CMIYC Writeup Part 3 
How Protective DNS Empowers MSSPs 
The Dangers of DIY Network Security Policy Management 
DOE launches cyber contest to benefit rural utilities 
Microsoft plans to address a Windows 11 "unintended behavior" that for months has caused malware-like notification pop-ups promoting Bing se 
Identification and Disruption of QakBot Infrastructure 
LockBit Builder Leak Leads to Flood of Ransomware Variants 
Microsoft plans to address an "unintended behavior" causing malware-like notification pop-ups in Windows 11 for months that promote Bing sea 
Microsoft plans to address an "unintended behavior" that has caused malware-like notification pop-ups in Windows 11 for months that promote  
Converging Narratives on Hawaii Wildfires Advance Different Influencers Objectives 
IT threat evolution in Q2 2023 
Huawei quietly launches the $960 Mate 60 Pro, giving no advance notice and releasing no ads; some investors speculate that Huawei used its own 5G chi 
FBI: Operation ‘Duck Hunt’ dismantled the Qakbot botnet 
Google previews AlloyDB AI, an integrated set of capabilities built into AlloyDB for PostgreSQL to help developers build generative AI apps using thei 
Google Cloud unveils Vertex AI improvements to better compete with Azure AI Studio and Amazon Bedrock; Nvidia announces PaxML, built on Google's  
Google Cloud unveils improvements to Vertex AI to better compete with Azure AI studio and Amazon Bedrock; Nvidia announces PaxML, built on top of Goog 
What's in a name? Strange behaviors at top-level domains creates uncertainty in DNS 
Vulnerability Summary for the Week of August 21, 2023 
Black Hat USA 2023 NOC: Network Assurance 
Lockbit 3.0 Builder Leaked: Anyone Can Blend Ransomware 
Massive MOVEit campaign already impacted at least 1,000 organizations and 60 million individuals 
Leaked LockBit 3.0 ransomware builder used by multiple threat actors 
BSides Cheltenham 2023 – Simon Gurney – Making Your Own Cool Conference Badges! 
Adversary On The Defense: ANTIBOT.PW 
A More Resilient Future with Automated Ransomware Recovery 
Top 10 Ways to Make the Most of Your Cybersecurity Internship 
How to Get a Tech Internship in 5 Steps 
EPSS and Its Role in Cisco Vulnerability Management Risk Scoring 
Lockbit leak, research opportunities on tools leaked from TAs 
CVE-2023-40356 
Lazarus Group exploits ManageEngine vulnerability to deploy QuiteRAT 
Naver unveils its generative AI product HyperCLOVA X, including chatbot app CLOVA X available in beta, and AI search service Cue, launching in beta in 
Take control over data in a SaaS environment with BYOK 
Spotify introduces new podcaster tools, including customized pages, impression analytics, controls for previews, and a new dashboard for Megaphone pub 
Ahsoka season 1 episodes 1 & 2 review: A continuation, but also an expansion of the Star Wars canvas 
Why 'Star Wars' needs its own answer to 'Star Trek: Lower Decks' 
OpenAI adds fine-tuning to GPT-3.5 Turbo, letting developers customize models with their own data to make them perform better for their use cases for  
OpenAI adds fine-tuning to GPT-3.5 Turbo, letting developers, for a fee, customize models with their own data to make them perform better for their us 
Tourists Give Themselves Away by Looking Up. So Do Most Network Intruders. 
Ransomware-as-a-Service cheat sheet 
Apache Ivy Injection Flaw Let Attackers Exfiltrate Sensitive Data 
Rapid7 Takes 2023 SC Awards for Vulnerability Management and Threat Detection 
Google CFO Ruth Porat and other executives have either shifted roles or left the company in recent months, as the search giant tries to find its own i 
A look at Google executives like CFO Ruth Porat who have either shifted roles or left the company in recent months, as the company searches for its ow 
Three Ways to Enhance Your Cloud Security with External Attack Surface Management 
10 episodes of Star Wars to watch before Ahsoka 
Vulnerability Summary for the Week of August 14, 2023 
A Basic Guide to Router and Wireless Security for Regular People 
Ten episodes of Star Wars to watch before Ahsoka 
CVE-2022-46751 
People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection 
Vulnerability Summary for the Week of June 5, 2023 
Vulnerability Summary for the Week of June 19, 2023 
Vulnerability Summary for the Week of July 3, 2023 
Vulnerability Summary for the Week of June 26, 2023 
Vulnerability Summary for the Week of July 24, 2023 
People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection 
Preventing Web Application Access Control Abuse 
Threat Actors Exploiting Ivanti EPMM Vulnerabilities 
MAR-10365227-2.v1 - Impacket 2 
CVE-2023-40171 
CVE-2023-40027 
CVE-2023-39125 
West Point researchers explore a virtual future for training 
The Army wants to bolster its local cybersecurity defenders 
The US Army will soon be able to see itself in cyberspace on the battlefield 
Cyberwarriors will soon have access to more training tools 
DoD must focus on skilled cyber defenders, not just new tech, warns weapons tester 
DoD needs to improve how it tests cyber weapons architecture, weapons tester says 
Estonia, US launch effort to ease sharing of cyberthreat intel 
Hackers could shut down satellites or turn them into weapons 
Why the US chose to name and shame Russia over cyberattacks 
What s the next step? : US officials are rethinking how to dissuade cyberattacks 
The battle against disinformation is global 
How To Present SecOps Metrics (The Right Way) 
InsightAppSec Advanced Authentication Settings: Token Replacement 
PenTales: A Badge, a Tag, and a Bunch of Unattended Chemicals; Why Physical Social Engineering Engagements are an Important Part of Security 
Patch Tuesday - August 2023 
Join us for VeloCON 2023: Digging Deeper Together! 
Criminals Have Created Their Own ChatGPT Clones 
On Ukraine, China Prioritizes Its International Ambitions 
What is Threat Intelligence? 
Xiaoqiying Genesis Day Threat Actor Group Targets South Korea, Taiwan 
New Capabilities To Enhance Visibility, Increase Automation, and Reduce Threat Exposure 
Recorded Future News Recap: The Biggest Stories Coming Out of RSAC 2023 
I Have No Mouth, and I Must Do Crime 
Threat Intelligence to Elevate Your Security Defenses 
Recruiter Tips: Insights on the Hiring Process at Recorded Future 
log4jmemes.com 
Talking with Stewart Baker 
A Skeleton Key of Unknown Strength 
Hacking the Universe with Quantum Encraption 
The Vulnerability of Zero Trust: Lessons from the Storm 0558 Hack 
Resilient bug-sized robots keep flying even after wing damage 
Robot Talk Episode 42 – Thom Kirwan-Evans 
Education and healthcare are set for a high-tech boost 
Interactive fleet learning 
Robotic hand can identify objects with just one grasp 
The 5 Laws of Robotics 
Automate 2023 recap and the receding horizon problem 
Ranking the best humanoid robots of 2023 
Flowstate: Intrinsic s app to simplify the creation of robotics applications 
Titan submersible disaster underscores dangers of deep-sea exploration an engineer explains why most ocean science is conducted with crewless submar 
Submersible robots that can fly 
Heat-resistant drone could scope out and map burning buildings and wildfires 
Enabling autonomous exploration 
3D display could soon bring touch to the digital world 
Can charismatic robots help teams be more creative? 
Adversaries Can Log In with Microsoft through the nOAuth Azure Active Directory Vulnerability 
Prevention Is the Best Preparation for the SEC s New Breach Disclosure Rules 
SVB's collapse is a scammer s dream: Don t get caught out 
The danger within: 5 steps you can take to combat insider threats 
The Guardian view on Northern Ireland s data leak: putting lives at risk Editorial 
#OpFukushima: Anonymous group protests against the plan to dump Fukushima RADIOACTIVE wastewater into Pacific 
Windows Privilege Escalation: Server Operator Group 
Steps To Increase Your Smartphone Security 
Unlock Jailbreak iPhone Using Unlock iPhone Software 
Why These Days Hacking Is Easy And Everyone Is Hacked? 
New Headache: Hackers Targeting Android Browser 
Most Friendly Tricks For Your iPhone 
How To Change Default Google Chrome Icon with Golden Color? 
How To Create Your Own Website For Free With uCoz? 
WordPress Security: Securing Sites From Hackers Future Attacks 
Smuggler - An HTTP Request Smuggling Desync Testing Tool 
Hashdb-Ida - HashDB API Hash Lookup Plugin For IDA Pro 
AzureHunter - A Cloud Forensics Powershell Module To Run Threat Hunting Playbooks On Data From Azure And O365 
Ukraine Continues to Face Cyber Espionage Attacks from Russian Hackers 
How SSPM Simplifies Your SOC2 SaaS Security Posture Audit 
Msticpy - Microsoft Threat Intelligence Security Tools 
EXOCET - AV-evading, Undetectable, Payload Delivery Tool 
NSA: Codebreaker Challenge Helps Drive Cybersecurity Education 
Few Fortune 100 Firms List Security Pros in Their Executive Ranks 
How Malicious Android Apps Slip Into Disguise 
Meet the Brains Behind the Malware-Friendly AI Chat Service ‘WormGPT’ 
Karma Catches Up to Global Phishing Service 16Shop 
Google Support Passkeys for Password Free Sign-in 
Apple Sacks it’s Server Supplier After Finding Infected Firmware in Siri Servers 
Vault 7: Marble Framework Reveals How the CIA Evaded Forensics & Attributed Malware to Other Countries 
Chelsea Manning, Alleged Wikileaks Whistleblower Released from Jail 28 Years Early 
List of Secure Dark Web Email Providers in 2023 
List of Secure Email Providers that take Privacy Serious 
Release: You are now able to add your own subdomains 
Vulnerability Scanning with OpenVAS 9 part 4: Custom scan configurations 
Email crypto phishing scams: stealing from hot and cold crypto wallets 
Focus on DroxiDat SystemBC 
Common TTPs of attacks against industrial organizations 
Anomaly detection in certificate-based TGT requests 
Ask Lesley: From Ops to DFIR, a Tough Transition 
Infosec Mastodon Lists! 
Lessons Learned from Cybersecurity Mentoring 
Cyber-attacks hit hospital construction companies 
CFRipper – CloudFormation Security Scanning & Audit Tool 
WikiLeaks Creator Julian Assange Arrested After Ecuador Withdraws Asylum 
Complex Malware 'Exodus' Found Hitting Apple iOS Holders 
Hacker Hijacks a Microsoft Service Using Loophole in Azure Cloud 
Introducing Data Security: Why is it Important for Every Organization? 
Three Key Ways Attack Simulations Can Help Tighten Enterprise Security 
The Future Of iTunes For Windows: Bright or Not Much? 
An Overview of the Jooble Platform 
How to Become a Cyber Security Expert 
5G - A Business Owner s Dream, A Hacker s Fantasy 
Every company has its own version of ChatGPT now 
Code leaks are causing an influx of new ransomware actors 
What Cisco Talos knows about the Rhysida ransomware 
Recapping the top stories from Black Hat and DEF CON 
At Least 4 New Reasons Every Day To Check Your Email Security Stack 
Shifting Left in Cybersecurity: Balancing Detection and Prevention - Part 2 
100 Days of YARA: Everything You Need to Know 
How a hacking crew overtook a satellite from inside a Las Vegas convention center and won $50,000 
Feds to hackers in Vegas: Help us, you’re our only hope 
Online influence operators continue fine-tuning use of AI to deceive their targets, researchers say 
Fifty minutes to hack ChatGPT: Inside the DEF CON competition to break AI 
CVE-2023-39913 
CVE-2023-37264 
CVE-2023-37192 
CVE-2023-36469 
CVE-2023-35927 
CVE-2023-34845 
CVE-2021-4344 
CVE-2023-34382 
CVE-2023-33778 
CVE-2023-26125 
CVE-2023-22452 
CVE-2022-46337 
CVE-2022-46167 
CVE-2022-45544 
CVE-2022-4068 
CVE-2022-3958 
CVE-2022-3913 
CVE-2023-21026 
CVE-2022-2576 
CVE-2022-36944 
CVE-2022-36115 
CVE-2022-36037 
CVE-2022-36114 
CVE-2022-36113 
CVE-2022-35629 
CVE-2022-35287 
CVE-2022-32151 
CVE-2022-32168 
CVE-2022-1896 
CVE-2022-31042 
CVE-2022-31185 
CVE-2022-31122 
CVE-2022-31043 
CVE-2022-31168 
CVE-2022-31091 
CVE-2022-31022 
CVE-2022-29164 
CVE-2022-29257 
CVE-2022-29237 
CVE-2022-25780 
CVE-2022-24823 
CVE-2022-24707 
CVE-2022-24782 
CVE-2022-24710 
CVE-2022-24839 
CVE-2022-24797 
CVE-2022-24800 
CVE-2022-24842 
CVE-2022-24190 
CVE-2022-23513 
CVE-2022-23616 
CVE-2022-23457 
CVE-2021-46283 
CVE-2021-46249 
CVE-2022-0129 
CVE-2021-45810 
CVE-2021-44731 
CVE-2021-44043 
CVE-2022-21702 
CVE-2022-21704 
CVE-2021-43784 
CVE-2021-42856 
CVE-2021-23192 
CVE-2021-42581 
CVE-2021-41117 
CVE-2021-41273 
CVE-2021-40309 
CVE-2021-3712 
CVE-2021-38616 
CVE-2021-38469 
CVE-2021-37845 
CVE-2021-35946 
CVE-2021-35395 
CVE-2021-35193 
CVE-2021-34413 
CVE-2021-32993 
CVE-2021-32762 
CVE-2021-32688 
CVE-2021-32573 
CVE-2021-31338 
CVE-2021-30118 
CVE-2021-29728 
CVE-2021-29691 
CVE-2021-29792 
CVE-2021-29472 
CVE-2021-29461 
CVE-2021-28912 
CVE-2021-28687 
CVE-2021-28698 
CVE-2021-28660 
CVE-2021-28128 
CVE-2021-27509 
CVE-2021-27440 
CVE-2021-27438 
CVE-2021-24914 
CVE-2021-24306 
CVE-2021-24480 
CVE-2021-24884 
CVE-2021-24698 
CVE-2021-23890 
CVE-2021-3047 
CVE-2021-22877 
CVE-2021-22538 
CVE-2021-22556 
CVE-2020-36128 
CVE-2021-21981 
CVE-2020-35951 
CVE-2021-21465 
CVE-2020-35674 
CVE-2021-21303 
CVE-2021-21283 
CVE-2021-21290 
CVE-2021-21355 
CVE-2021-21261 
CVE-2021-20442 
CVE-2021-20426 
CVE-2021-20537 
CVE-2020-35514 
CVE-2021-20412 
CVE-2021-20220 
CVE-2021-20401 
CVE-2020-29669 
CVE-2020-29482 
CVE-2020-29483 
CVE-2020-29254 
CVE-2021-1522 
CVE-2020-27826 
CVE-2020-27831 
CVE-2021-0292 
CVE-2021-0290 
CVE-2020-26733 
CVE-2020-26679 
CVE-2020-26160 
CVE-2020-25597 
CVE-2020-25476 
CVE-2020-25180 
CVE-2020-15909 
CVE-2020-15245 
CVE-2020-13972 
CVE-2020-13697 
CVE-2020-13335 
CVE-2019-20794 
CVE-2020-12743 
CVE-2020-11492 
CVE-2020-11498 
CVE-2020-11075 
CVE-2020-10728 
CVE-2020-9451 
CVE-2020-9347 
CVE-2020-9049 
CVE-2020-8791 
CVE-2020-8557 
CVE-2020-7959 
CVE-2020-7308 
CVE-2020-6363 
CVE-2020-5821 
CVE-2020-5504 
CVE-2020-5213 
CVE-2020-5211 
CVE-2020-5212 
CVE-2020-5246 
CVE-2020-5214 
CVE-2020-4283 
CVE-2020-4385 
CVE-2020-4150 
CVE-2020-4690 
CVE-2020-4622 
CVE-2020-4190 
CVE-2020-4177 
CVE-2020-4459 
CVE-2020-4854 
CVE-2020-4932 
CVE-2020-4157 
CVE-2020-4044 
CVE-2020-4269 
CVE-2020-4208 
CVE-2020-3972 
CVE-2020-4216 
CVE-2019-20059 
CVE-2019-20061 
CVE-2019-20047 
CVE-2019-19905 
CVE-2020-3442 
CVE-2019-19732 
CVE-2019-19734 
CVE-2019-19726 
CVE-2019-19579 
CVE-2020-1754 
CVE-2020-1764 
CVE-2019-19202 
CVE-2019-18675 
CVE-2019-17636 
CVE-2019-17590 
CVE-2019-16951 
CVE-2019-16403 
CVE-2019-16303 
CVE-2019-15953 
CVE-2019-15350 
CVE-2019-15345 
CVE-2019-15346 
CVE-2019-15349 
CVE-2019-15341 
CVE-2019-15062 
CVE-2019-12784 
CVE-2019-12783 
CVE-2019-12749 
CVE-2019-12494 
CVE-2019-11875 
CVE-2019-11741 
CVE-2019-11279 
CVE-2019-11231 
CVE-2019-11021 
CVE-2019-10175 
CVE-2019-10164 
CVE-2019-10168 
CVE-2019-10167 
CVE-2019-9834 
CVE-2019-9534 
CVE-2019-1000023 
CVE-2019-7350 
CVE-2019-5697 
CVE-2019-5542 
CVE-2019-5517 
CVE-2019-5516 
CVE-2019-5541 
CVE-2019-5536 
CVE-2019-4694 
CVE-2019-3775 
CVE-2019-4675 
CVE-2019-2023 
CVE-2019-1552 
CVE-2019-1201 
CVE-2019-1205 
CVE-2019-0345 
CVE-2018-19576 
CVE-2019-0224 
CVE-2018-16307 
CVE-2018-15480 
CVE-2018-14866 
CVE-2018-13844 
CVE-2018-13001 
CVE-2018-13002 
CVE-2018-12891 
CVE-2018-12579 
CVE-2018-12556 
CVE-2018-11747 
CVE-2018-10534 
CVE-2018-8857 
CVE-2018-7718 
CVE-2018-7285 
CVE-2017-18191 
CVE-2018-7206 
CVE-2017-18176 
CVE-2018-6182 
CVE-2017-1000484 
CVE-2018-3988 
CVE-2018-4058 
CVE-2018-1944 
CVE-2018-1818 
CVE-2018-1992 
CVE-2018-1887 
CVE-2018-1959 
CVE-2018-1742 
CVE-2018-0422 
CVE-2018-0436 
CVE-2017-1000133 
CVE-2017-1000141 
CVE-2017-16021 
CVE-2016-10550 
CVE-2017-16030 
CVE-2016-10551 
CVE-2017-15304 
CVE-2017-15014 
CVE-2017-14191 
CVE-2017-13209 
CVE-2017-12172 
CVE-2017-10718 
CVE-2017-9378 
CVE-2016-10364 
CVE-2017-8305 
CVE-2017-8245 
CVE-2017-7820 
CVE-2017-7618 
CVE-2017-7406 
CVE-2017-7358 
CVE-2017-6911 
CVE-2017-6507 
CVE-2017-6466 
CVE-2017-6339 
CVE-2016-10142 
CVE-2017-5397 
CVE-2017-5189 
CVE-2017-5167 
CVE-2016-9902 
CVE-2017-3209 
CVE-2016-9604 
CVE-2016-9489 
CVE-2016-8631 
CVE-2016-8508 
CVE-2016-7402 
CVE-2016-5374 
CVE-2016-5259 
CVE-2016-2980 
CVE-2015-8832 
CVE-2016-1632 
CVE-2015-4456 
CVE-2015-4381 
CVE-2015-1810 
CVE-2014-9498 
CVE-2014-9026 
CVE-2014-8730 
CVE-2014-3120 
CVE-2013-4954 
CVE-2013-4698 
CVE-2013-4500 
CVE-2013-3735 
CVE-2013-2308 
CVE-2013-2129 
CVE-2013-0340 
CVE-2013-0339 
CVE-2012-5539 
CVE-2012-2372 
CVE-2012-2359 
CVE-2012-1172 
CVE-2012-0814 
CVE-2011-3824 
CVE-2010-4011 
CVE-2010-1438 
CVE-2010-1362 
CVE-2009-3832 
CVE-2009-3782 
CVE-2009-1596 
CVE-2009-1477 
CVE-2009-1203 
CVE-2009-0806 
CVE-2009-0489 
CVE-2009-0089 
CVE-2008-3618 
CVE-2008-3356 
CVE-2008-0793 
CVE-2001-1311 
CVE-2003-0026 
CVE-2003-1392 
CVE-2002-0843 
CVE-2007-4529 
CVE-2007-2595 
CVE-2007-2475 
CVE-2007-1679 
CVE-2007-1257 
CVE-2007-1030 
CVE-2006-3766 
CVE-2006-2825 
CVE-2006-2452 
CVE-2005-4780 
CVE-2006-1365 
CVE-2006-1221 
CVE-2005-4515 
CVE-2005-4261 
CVE-2004-1811 
CVE-2005-1124 
CVE-2005-0747 
CVE-2003-0525 
CVE-2002-1473 
CVE-2003-0095 
CVE-2002-0204 
CVE-2001-1142 
CVE-2002-0424 
CVE-2002-1138 
CVE-1999-1545 
CVE-2000-1202 
CVE-1999-0144 
CVE-1999-0250 
CVE-2001-0062 
CVE-2001-1322 
CVE-2000-0415 
CVE-1999-0364 
CVE-2000-0824 
CVE-2000-0406 
CVE-1999-0284 
 
Forum
Privacy
Developers
Crypto Currency



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.