Frontier AI is compressing the attack lifecycle from vulnerability discovery to exploitation, forcing defenders to detect, patch and respond at machine…
Tag: EN
Microsoft 365 Passkey Phishing Turns Login Into a Cloud Breach
Microsoft warns that passkey-themed phishing is hijacking Microsoft 365 accounts, adding rogue MFA methods, and slowly stealing business cloud data.
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
A flaw in Telegram Desktop let a bot’s message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch…
whitelist-bypass – WebRTC Tunnels Through Video-Calling Platforms
whitelist-bypass tunnels traffic through commercial video calls, for networks that allow only approved domains. How its two tunnels work, and the claim to…
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
An attacker was operating inside the network of 3BB, one of Thailand’s largest broadband providers, and maintained remote control of internal machines…
Upcoming Speaking Engagements
This is a current list of where and when I am scheduled to speak: I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September…
China Calls Amodei’s AI Proposal a New Cold War Playbook
China rejects Amodei’s AI slowdown proposal, calling it fearmongering and a US attempt to contain China’s technology sector. The debate over whether the…
New hardware device can RAM into encrypted memory, expose your data
Attackers would need physical access to the server to pull off the DDR5 trick
Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin
On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a…
Apple Updates Everything, (Mon, Sep 14th)
Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different…
OpenAI’s malicious bot swarm attacked RubyGems
Ruby are you ok? Ruby are you ok? Are you ok Ruby?
ClickFix attacks are tricking Mac and Windows users into hacking themselves
If you clicked on a fake HBO Max ad on Reddit in the past week, you might have fallen victim to a rising ‘ClickFix’ security threat.
Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider
Researchers have uncovered an exposed attacker-controlled staging server containing evidence of a wide-ranging intrusion targeting 3BB, the consumer brand…
Microsoft Offers Up to $30,000 for Critical AI Flaws in Dynamics 365 and Power Platform
Microsoft is offering security researchers up to $30,000 for finding critical AI vulnerabilities in Dynamics 365 and Power Platform, sharpening its focus…
UK Government Begins Moving 23 Million Users Away From Passwords
The UK government has begun rolling out passkeys across GOV.UK One Login, offering more than 23 million users a passwordless way to access public…
Data Governance for the Agentic Era
The modern enterprise generates and consumes unprecedented volumes of data across operational systems, customer interactions, partner ecosystems, cloud…
Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials
Hackers are conducting a large-scale automated scanning campaign against internet-exposed Vite development servers, attempting to steal AWS credentials,…
AWS Security Reference Architecture: A deep dive into PCI DSS compliance
Amazon Web Services (AWS) is excited to announce the publication of the AWS Security Reference Architecture (AWS SRA) Payment Card Industry (PCI) Data…
Nintendo Switch Vulnerability Allows Attackers to Run Unauthorized Code on Your Console
Nintendo has patched a high-severity vulnerability in the original Nintendo Switch that could let a nearby attacker execute unauthorized code and access…
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
A Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to…