179
2
CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root (qualys.com)
3
Injectable "satellite livers" could offer alternative to liver transplantation (news.mit.edu)
3
White House Unveils President Trump's Cyber Strategy for America (whitehouse.gov)
1
FBI investigating 'suspicious' cyber activity on system holding wiretaps (abcnews.com)
3
China's new 5-year plan calls for AI throughout its economy, tech breakthroughs (reuters.com)
2
OpenAI admits defense deal 'looked opportunistic and sloppy' amid backlash (cnbc.com)
8
Ubuntu 26.04 ends a 40-year old sudo tradition (omgubuntu.co.uk)
1
Disrupting the Gridtide Global Cyber Espionage Campaign (cloud.google.com)
2
AI-augmented threat actor accesses FortiGate devices at scale (amazon.com)
2
IcedID malware developer fakes his own death to escape the FBI (risky.biz)
1
Employee Monitoring and SimpleHelp Software Abused in Ransomware Operations (huntress.com)
4
Right-to-Compute Laws Spread Across the US, as Electricity Bills Skyrocket (gizmodo.com)
1
Nitrogen Ransomware: ESXi malware has a bug (coveware.com)
2
European and allied cybersecurity strategies shift from defence to offence (bindinghook.com)
1
Julius: open-source LLM Service Fingerprinting (praetorian.com)
1
Gov't to notify people of possible data leaks, not just confirmed cases (joins.com)
3
A LinkedIn Job Offer Tried to Install Malware on My Machine (codecrank.ai)
1
Malicious Extension Bot (infosec.exchange)
3
The abandoned airport being transformed into a $30B sustainable city (cnn.com)
2
Hit squad recruiter for Sweden's Foxtrot criminal network arrested in Iraq (thenationalnews.com)
1
The Limits of Binary Interoperability (randomoracle.io)
11
Trump administration removes three spyware-linked executives from sanctions list (reuters.com)
6
America's work-from-home capitals are in a sorry state (economist.com)
3
SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies and WSDL (watchtowr.com)
2
Japan teen arrested for alleged ChatGPT-assisted cyberattacks (nhk.or.jp)
8
$2B Counter-Strike 2 crash exposes a legal black hole (theconversation.com)
1
New OWASP Top (owasp.org)
2
State-Sponsored Remote Wipe Tactics Targeting Android Devices (genians.co.kr)
1
Spoofed numbers blocked in crackdown on scammers (gov.uk)
2
Analysis of NGate malware campaign (NFC relay) (cert.pl)
1
The ZeroAccess Developer and His Windows Kernel-Mode Debugger (r136a1.dev)
57
Czech police forced to turn off facial recognition cameras at the Prague airport (edri.org)
2
AFP cracked a criminal's crypto wallet (afp.gov.au)
1
A hacking gang held Italy's political elites to ransom (politico.eu)
1
Teams: Automatically update your work location via your organization's Wi-Fi (microsoft.com)
2
ZeroDisco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits (trendmicro.com)
1
Securing the Future: Changes to Internet Explorer Mode in Microsoft Edge (microsoftedge.github.io)
1
Top Russian defense boss tries to lift sanctions, spills own secrets instead (kyivindependent.com)
2
Crates.io: Malicious crates faster_log and async_println (rust-lang.org)
2
Singapore Became Obsessed by Shade (bbc.com)
2
New Olympic calendar likely because of climate change (bbc.com)
33
Teen suspect surrenders in 2023 Las Vegas casino cyberattack case (casino.org)
3
Inboxfuscation: Because Rules Are Meant to Be Broken (permiso.io)
32
Qantas is cutting executive bonuses after data breach (flightglobal.com)
2
Turkmenistan turned internet censorship into a business (torproject.org)
1
Nevada Governor's Office says state offices 'will likely be closed' Tuesday (carsonnow.org)
1
Detecting CVE-2025-43300: A Deep Dive into Apple's DNG Processing Vulnerability (msuiche.com)
1
Oregon Man Charged in 'Rapper Bot' DDoS Service (krebsonsecurity.com)
3
Windows 11 Latest Security Update Is Causing SSD Failures (wccftech.com)
1
Belgium Targets Internet Archive's Open Library in Site Blocking Order (torrentfreak.com)
2
HBO Max to aggressively crack down on password sharing (ghacks.net)
3
Swarm of jellyfish shuts nuclear power plant in France (theguardian.com)
1
China is using cyber attribution to pressure Taiwan (bindinghook.com)
16
Lovense: The Company That Lies to Security Researchers (bobdahacker.com)
2
Amnban Files: Inside Iran's Cyber-Espionage Factory Targeting Global Airlines (narimangharib.com)
2
How Military Insignia Revealed Russia's Hidden Sigint Network (checkfirst.network)
1
Golden DMSA: What Is DMSA Authentication Bypass? (semperis.com)
2
SMM callout vulnerabilities identified in Gigabyte UEFI firmware (cert.org)
3
State Secrets for Sale: More Leaks from the Chinese Hack-for-Hire Industry (spycloud.com)
1
New NightEagle North American Apt Group [pdf] (github.com/reddrip7)
4
Interpol releases new information on globalization of scam centres (interpol.int)
2
Pakistani freelancers building cracking websites for stealer-delivery (intrinsec.com)
1
Butian Platform: Forging China's Next Generation of White Hat Hackers (nattothoughts.substack.com)
1
FileFix – A ClickFix Alternative (mrd0x.com)
4
Iran Hacks Tirana Municipality in Retaliation over MEK (tiranatimes.com)
2
Nationalization of Cyber Threat Intelligence (fromcyberia.substack.com)
1
Army Cyber Corps – A Prehistory (army.mil)
1
Introducing: GitHub Device Code Phishing (praetorian.com)
1
DanaBleed: DanaBot C2 Server Memory Leak Bug (zscaler.com)
2
SonicDoor – Cracking SonicWall's SMA 500 (scrt.ch)
2
Malicious Ruby Gems Exfiltrate Telegram Tokens, Messages Following Vietnam Ban (socket.dev)
5
Paper Fingerprinting and Ballot Tracking (princeton.edu)
2
NSA Publish Advisory on Russian Cyber Campaign Targeting Western Logistics (nsa.gov)
2
Stateful Connection with Spoofed Source IP – NetImpostor (tastypepperoni.medium.com)
1
ICANN kills off diversity and inclusion (domainincite.com)
3
Iranian Cyber Actors Impersonate Model Agency in Suspected Espionage Operation (paloaltonetworks.com)
4
Be Careful of Your UDP Service: Preauth DoS on Windows Deployment Service (sites.google.com)
2
The rise and fall of eXch – the dark service used by North Korean hackers (elliptic.co)
1
Investigating an in-the-wild campaign using RCE in CraftCMS (sensepost.com)
1
Meta is not adequately meeting the demands of CERT Polska (cert.pl)
1
Rapid Proxy Rotation Explained (kybervandals.com)
1
Mandatory short duration TLS certificates are probably coming soon (utcc.utoronto.ca)
7
Ukrainian Intel op blew up Russian drone pilots' goggles, official says (politico.eu)
6
Russians Capture Ukrainian Drones Which Infect Their Systems with Malware (forbes.com/sites/vikrammittal)
4
Analyzing open-source bootloaders: Finding vulnerabilities faster with AI (microsoft.com)
3
Apple adds support for TCC events in macOS (objective-see.org)
1
Operation ForumTroll: APT attack with Google Chrome zero-day exploit chain (securelist.com)
2
Clevo Boot Guard Keys Leaked in Update Package (binarly.io)
97
Sign in as anyone: Bypassing SAML SSO authentication with parser differentials (github.blog)
2
FreeType Bug Exploited in the Wild (facebook.com)
1
FlippyRAM Study (flippyr.am)
1
KU Leuven researchers uncover security issues in computer servers (persdienst.kuleuven.be)
22
Python's official documentation contains textbook example of insecure code (XSS) (seclists.org)
6
Thousands flee Santorini as quakes rattle Greek tourist haven (cnn.com)
12
Malicious extensions circumvent Google's remote code ban (palant.info)
2
Vigilante Justice on GitHub (trufflesecurity.com)
1
Mystery volcano that cooled Earth in 1831 has been identified (cnn.com)
52
Northern Ireland police unlawfully put reporters under surveillance (reuters.com)
2