Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix
Category: www.theregister.com – Articles
OpenAI commits $1B in AI credits to frontline cyber defenders
Daybreak program brings subsidized models, training, and support to under-resourced teams
Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC
A shared security ‘Nightmare’
Drowning in CVEs and thirsty for answers? Try CTEM
Boards want to know if they’re less exposed than last quarter. Patching metrics aren’t the solution
Cybercrooks trawl Fishbrain to net password hashes
Armed with password hashes and salts, attackers could already be kraken those creds
UK’s Online Safety Act has made ‘absolutely no difference,’ kids say
Children’s Commissioner also furious with Ofcom over a string of failures
To keep the AI hacking genie bottled up, try one-way networks
Sandboxes, permissions, and VMs aren’t enough to keep frontier models at bay. “Data diodes” might do the job
Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
They had more access than the average Joe, and IT didn’t track what needed to be cut off
Claude Mythos only model to complete full cyber kill chain, experts say
Cyber Weapon Index finds AI attacks ‘imminent’
AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
Adding insult to injury
SonicWall’s SMA1000 boxes under active attack again
Miscreants use chained zero days to pwn boxen as third-party SOCs say further attacks ‘almost certain’
Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
Cloud storage biz severs old integration and urges victims to reset credentials
UK cyber bill targets AI users, not the vendors building it
Ministers reject proposed red lines and emergency shutdown powers, pointing instead to voluntary safeguards
Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
23-year-old botnet down
Another Artifactory CVE under attack by AI agents or humans
Unauthenticated intruders can mint admin tokens, and exposed servers are already being hit
Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
The model provider gave METR the credits for free. An actual customer would not have been so lucky
Firefox helps iPhone users bypass ads on web sites while making money showing its own ads
Baked-in Firefox ad blocking on iOS begins rolling out slowly today, and is off by default
Anthropic pledges to try harder to keep models under control, asks partners to chip in
Security … this time it will be different
33-hour BGP hijack of Softaculous traffic prompts security scramble
Hosting software vendor tells customers to reset credentials and hunt for malicious packages
Healthcare cyberattacks hit pacemakers and millions of patient records
McKesson admits breach as ShinyHunters demands $55.2M
