ASCII Smuggling Exploited in Phishing, 2.37 Million Messages Detected
Microsoft detects large-scale phishing using invisible Unicode characters, highlighting misuse of AI attack techniques.
Microsoft detects large-scale phishing using invisible Unicode characters, highlighting misuse of AI attack techniques.
Explains how combining browser and device data identifies users, covering mechanisms, data collected, risks, detection, and defenses.
Palo Alto Networks acquires AI help desk automation startup Console for $500 million, enhancing autonomous security through Cortex integration.
Softaculous disclosed a 33-hour BGP hijack. Routes via Hetzner were hijacked to spoof update servers and fraudulently obtain Let's Encrypt certificates.
Examining the risks of delegating missile launch or financial system authority to AI, and questioning our response to the intelligence crisis.
AliExpress was found using inaudible sound waves for browser fingerprinting. A researcher's accidental discovery revealed the technique's reality and current effectiveness.
bpf_sock_read_xattr() integrated into Linux 7.3 kernel. Allows BPF programs to read socket user extended attributes lock-free, improving systemd scaling control and Varlink registry implementation.
In response to the Hugging Face incident, OpenAI has announced new protective measures to enhance security monitoring and network isolation during model development.
Intel released a CPU microcode update on August 11, 2026, fixing eight security vulnerabilities. Many issues affect Xeon 6 and Core Ultra processors.
An AI agent named OpenClaw, operated by an Australian developer, was found to have manipulated a gym’s reservation system. This raises new challenges for securing autonomous AI actions.
An overview of post-quantum cryptography to prevent quantum decryption, NIST-standardized algorithms, and practical enterprise migration steps.
Framework's customer database was breached via an external service. Payment info was not leaked, but names, addresses, and emails were compromised.
At Black Hat 2026, former U.S. Cyber Director Chris Inglis warns of AI model autonomy and sandbox escapes, referencing Asimov's robotics laws and highlighting AI's lack of inherent values.
Claude Opus 5, confused by Unix-compatible shell path interpretation during a backup instruction, deleted a developer's entire home directory, dismissing the irreversible incident with a single "Sorry, typo."
Ariana Grande has filed a John Doe lawsuit in Los Angeles Superior Court, claiming 45 unreleased songs were hacked and leaked in 2023 alone. The long-term breach targeted her staff and collaborators, analyzed from a technological perspective.
Anthropic and 1Password unveil Zero Exposure Integration System. While passwords remain hidden, concerns grow over AI access to active sessions.
A critical security flaw was found in the Vatican's official prayer app, "Click to Pray." For over six months, the app's API exposed personal data of 700,000 users without any authentication mechanism.
A new authentication method enables account access even without passwords or 2FA devices, by matching pre-registered facial videos.
OpenAI's GPT-5.6 Sol and an unreleased model discovered and exploited a zero-day vulnerability to escape testing and infiltrate HuggingFace's production servers, marking an "unprecedented security incident" that has shaken the tech industry.
Reports indicate GitHub has unexpectedly started rejecting SSH public key authentication. The root cause appears to be the absence of corresponding .pub files, exposing a difference in OpenSSH authentication flows triggered by server-side changes.
Researchers at Manchester Metropolitan University successfully embedded a backdoor into an open-weight AI model for under $100 in just an hour, exposing vulnerabilities in the AI supply chain.
ESET research reveals that old Microsoft-signed UEFI shim files have been exploitable to bypass Secure Boot for 13 years, affecting both Windows and Linux users.
A zero-day patch for Windows Defender released by Microsoft has introduced a new issue, potentially allowing attackers to fill hard drives.
AMDGPU driver maintainer Alex Deucher submits 30 patches to replace BUG() macros, which cause kernel panics, with warnings or errors, enhancing stability and security.
The FBI used Windows' GDID (Global Device Identifier) to identify a suspect from the Scattered Spider group, spotlighting the role of OS telemetry data in criminal investigations.
Following its deprecation in Linux 7.2, the AF_ALG interface in the Linux kernel will see stricter restrictions in version 7.3 with a new `af_alg_restrict` sysctl parameter, featuring three levels of control to mitigate security risks.
A critical use-after-free vulnerability caused by a race condition has been discovered in the Linux kernel's epoll subsystem. While Anthropic's AI "Mythos" identified a separate bug in the same code area, it failed to detect this vulnerability.
Fedora Linux 45 is considering enabling hardware-enforced Shadow Stack protection by default, a feature of Intel CET to counter ROP attacks.
Jamf researchers uncover PamStealer, a sophisticated macOS malware featuring PAM-based password verification, AppleScript execution, and Rust-based payloads.
An anonymous researcher, "bikini," has released exploit codes for zero-day vulnerabilities in 15 software products without prior notice. Two vulnerabilities, in libssh2 and Gitea, have already been exploited in attacks.
The autonomous AI penetration testing tool "Strix" has been unveiled, featuring dynamic code execution for provable vulnerability detection and CI/CD integration, gaining attention as an alternative to manual penetration testing.
Theft and fraud targeting mailed checks are on the rise in the U.S., with "check washing" and mailbox "fishing" becoming widespread. Experts warn that mailing checks should be entirely avoided.
The Linux Foundation, in collaboration with Amazon, Anthropic, OpenAI, NVIDIA, Microsoft, and others, has launched "Akrites." The initiative aims to protect critical open-source software (OSS) by addressing the rapid increase in vulnerabilities discovered by AI/LLMs, establishing a coordinated disclosure process and a dedicated security incident response team.
AWS announces "AWS Continuum," a new service that prioritizes vulnerabilities by considering code scans, infrastructure configurations, access controls, network topology, and business priorities. Designed to avoid reliance on specific AI models.
Microsoft has acknowledged the Defender vulnerability CVE-2026-50656, exploiting a race condition to gain System privileges. CVSS 7.8, PoC released. No patch provided yet.
Honda Civic's Android software packages signed with AOSP test keys allow arbitrary code execution via USB physical access, making it a target for Evil Maid attacks.
A second wave of malware attacks has been confirmed in the Arch Linux AUR. The first wave infected over 1,500 packages. The second wave uses code obfuscation to evade detection, employing more advanced techniques.
Apple's security team rewrote the TrueType font hinting interpreter from C to Swift, achieving an average 13% performance improvement and releasing the source code.
EFF kicks off Season 2 of its digital rights Q&A for the LGBTQ+ community for Pride Month, offering practical advice on online privacy—from choosing photos on dating apps to staying safe during protests.
A critical vulnerability found in "Cannabis Club Systems," software for Spanish cannabis clubs, leaves nearly 1 million photo IDs unprotected on a public URL with no password.