Vue normale
-
BleepingComputer
-
COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. [...]
-
BleepingComputer
-
Google Chrome may soon block New Tab hijacker extensions by default
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]
Google Chrome may soon block New Tab hijacker extensions by default
-
BleepingComputer
-
Rails patches critical Active Storage flaw with RCE potential
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]
Rails patches critical Active Storage flaw with RCE potential
-
BleepingComputer
-
Amgen says cloud data breach exposed patient health, proprietary info
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...]
Amgen says cloud data breach exposed patient health, proprietary info
-
BleepingComputer
-
Arch Linux disables AUR package adoption to stop malware flood
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [...]
Arch Linux disables AUR package adoption to stop malware flood
-
BleepingComputer
-
Online ad firm Adform’s script compromised to steal cryptocurrency
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...]
Online ad firm Adform’s script compromised to steal cryptocurrency
-
BleepingComputer
-
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
-
BleepingComputer
-
CISA warns of cyberattacks disrupting U.S. water utilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. [...]
CISA warns of cyberattacks disrupting U.S. water utilities
-
BleepingComputer
-
ESET tracks rise in malicious AI skills and adaptable malware
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security software. [...]
ESET tracks rise in malicious AI skills and adaptable malware
-
BleepingComputer
-
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...]
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
-
BleepingComputer
-
South Korea fines telco giant KT $39 million for customer data breach
South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. [...]
South Korea fines telco giant KT $39 million for customer data breach
-
BleepingComputer
-
JetBrains warns of critical TeamCity remote code execution flaw
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. [...]
JetBrains warns of critical TeamCity remote code execution flaw
-
BleepingComputer
-
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. [...]
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
-
Articles on TechRepublic
-
Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now. The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic.
Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now.
The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic.
-
Articles on TechRepublic
-
IBM: AI-Enabled Data Breaches Cost Organizations $6 Million on Average
IBM found AI-enabled breaches cost organizations $6 million on average, exposing gaps in vulnerability management, access controls, and AI governance. The post IBM: AI-Enabled Data Breaches Cost Organizations $6 Million on Average appeared first on TechRepublic.
IBM: AI-Enabled Data Breaches Cost Organizations $6 Million on Average
IBM found AI-enabled breaches cost organizations $6 million on average, exposing gaps in vulnerability management, access controls, and AI governance.
The post IBM: AI-Enabled Data Breaches Cost Organizations $6 Million on Average appeared first on TechRepublic.
-
Articles on TechRepublic
-
Google Plans Global Rollout of Privacy-Focused Age Signals API
Google plans to expand its Play Age Signals API globally, helping Android developers tailor app experiences without collecting exact birth dates. The post Google Plans Global Rollout of Privacy-Focused Age Signals API appeared first on TechRepublic.
Google Plans Global Rollout of Privacy-Focused Age Signals API
Google plans to expand its Play Age Signals API globally, helping Android developers tailor app experiences without collecting exact birth dates.
The post Google Plans Global Rollout of Privacy-Focused Age Signals API appeared first on TechRepublic.
-
Articles on TechRepublic
-
US Military App Study Offers a Supply Chain Lesson for Australia
A US study uncovered adversarial software components inside apps marketed to the US military. Similar risks and lessons apply to Australian enterprises reliant on shadow supply chains. The post US Military App Study Offers a Supply Chain Lesson for Australia appeared first on TechRepublic.
US Military App Study Offers a Supply Chain Lesson for Australia
A US study uncovered adversarial software components inside apps marketed to the US military. Similar risks and lessons apply to Australian enterprises reliant on shadow supply chains.
The post US Military App Study Offers a Supply Chain Lesson for Australia appeared first on TechRepublic.
-
Articles on TechRepublic
-
Hugging Face Deepfake Tests Raise New Risks for AI Procurement
Researchers found that seven of nine tested Hugging Face image-editing tools produced sexualized alterations, highlighting gaps in model oversight, provenance, and enterprise vendor controls. The post Hugging Face Deepfake Tests Raise New Risks for AI Procurement appeared first on TechRepublic.
Hugging Face Deepfake Tests Raise New Risks for AI Procurement
Researchers found that seven of nine tested Hugging Face image-editing tools produced sexualized alterations, highlighting gaps in model oversight, provenance, and enterprise vendor controls.
The post Hugging Face Deepfake Tests Raise New Risks for AI Procurement appeared first on TechRepublic.
-
Articles on TechRepublic
-
GitHub Automatically Holds Suspicious Actions Runs, but Repository Owners Must Approve Them
GitHub’s new Actions safeguard pauses potentially malicious workflow runs before execution, leaving repository owners to decide who can approve them and what checks must come first. The post GitHub Automatically Holds Suspicious Actions Runs, but Repository Owners Must Approve Them appeared first on TechRepublic.
GitHub Automatically Holds Suspicious Actions Runs, but Repository Owners Must Approve Them
GitHub’s new Actions safeguard pauses potentially malicious workflow runs before execution, leaving repository owners to decide who can approve them and what checks must come first.
The post GitHub Automatically Holds Suspicious Actions Runs, but Repository Owners Must Approve Them appeared first on TechRepublic.
-
Articles on TechRepublic
-
Apple Sued After Alleged Fake Crypto Wallet App Cost Users $1.8 Million
Three investors allege a fake Sparrow Wallet app listed in Apple’s App Store caused approximately $1.8 million in Bitcoin losses. The post Apple Sued After Alleged Fake Crypto Wallet App Cost Users $1.8 Million appeared first on TechRepublic.
Apple Sued After Alleged Fake Crypto Wallet App Cost Users $1.8 Million
Three investors allege a fake Sparrow Wallet app listed in Apple’s App Store caused approximately $1.8 million in Bitcoin losses.
The post Apple Sued After Alleged Fake Crypto Wallet App Cost Users $1.8 Million appeared first on TechRepublic.