LG TV shown scanning LAN for third-party phones and other devices
1. The statement argues that preserving text indefinitely is inexpensive, implying long-term storage of written information is practical and accessible.
Everything filed under Security & Privacy, newest first.
1. The statement argues that preserving text indefinitely is inexpensive, implying long-term storage of written information is practical and accessible.
Security teams are rapidly releasing patches in anticipation of a likely surge in AI-assisted attacks, aiming to harden systems before adversaries can exploit new automation-driven threats.
A Claude user noticed unexplained token usage while inactive, prompting Anthropic to warn users that hackers may be accessing accounts and consuming resources without permission.
This news roundup highlights multiple cybersecurity threats, including factory-installed backdoors in consumer routers, law enforcement takedowns of hacking domains, China-linked attacks on Cisco IOS-XR routers, malware risks in Android auto infotainment systems, and an OpenAI postmortem.
Google is accelerating Chrome’s release cadence so security fixes and new features can reach users more quickly, improving responsiveness to vulnerabilities and reducing the wait for product updates.
The latest heist ranks among the largest cryptocurrency thefts ever recorded, highlighting the scale and continuing vulnerability of digital asset security.
Automatic Key Exchange probes TLS 1.3-capable customer origins to determine supported key agreement algorithms, then connects using the most secure option available, prioritizing post-quantum methods whenever supported.
Sun Tzu’s *The Art of War* offers surprisingly modern cybersecurity guidance by emphasizing self-knowledge, enemy intelligence, and proactive defense, showing that strong security comes from understanding your attack surface, studying threat actors, and preventing breaches through patching, hardening, authentication, and zero trust.
Last year’s flood of 49,000 CVEs highlights how manual network operations are overwhelmed, and this sponsored discussion with BackBox leaders explores whether AI can help network teams manage vulnerabilities and infrastructure more effectively.
A previously overlooked block of invisible Unicode characters is becoming increasingly widely used, drawing more attention as its applications expand.
OpenAI’s internal monitoring and security systems have suffered another failure, highlighting ongoing weaknesses in the company’s ability to detect and prevent problems.
A senator’s letter says the U.S. military acted to stop location tracking after foreign adversaries used data to identify and target service members, highlighting growing concerns about digital privacy and operational security.
Production traffic and security signals are used to prioritize findings, apply safe edge mitigations, and recommend code patches, with WAF data and OpenAI Daybreak models helping teams focus on the most critical vulnerabilities first.
At DEF CON in Las Vegas, the creators explore the world’s largest hacking conference, highlight its chaotic hands-on security culture, show badge and device setup, warn about insecure Wi‑Fi and Bluetooth, and demonstrate a secure remote upload workflow using Twilgate.
The FBI is reportedly investigating a large, ongoing data breach that is still actively unfolding, suggesting a serious cybersecurity incident with potentially significant consequences.
A crime-focused identity theft search site allegedly exposed over 150 million stolen driver’s license photos from an ID verification service before the site was shut down.
A rare but alarming Google Messages bug on Android is causing sent texts, and sometimes images, to be paired with random old messages from unrelated conversations, occasionally leaking content the sender never intended to share and sometimes only visible to the recipient.
A BGP hijacking incident that poisoned production software reveals how fragile software supply chains can be when network routing is compromised, highlighting the need for stronger verification, monitoring, and resilience across build and distribution systems.
OpenAI’s open letter, signed by 100 organizations including IBM, urges public and private sectors to prioritize cyber defense against increasingly AI-enabled attacks by empowering trusted defenders with advanced AI, sharing remediation strategies and patches, and coordinating collective action to reduce response time and strengthen security.
X is investigating a surge of unsolicited password reset emails, suspecting the issue may be connected to the rollout of its new payments service.
Coruna and DarkSword are exploit frameworks that have been used to compromise Apple iPhones for cryptocurrency theft and data harvesting, while the discussion traces their origins, including Coruna’s development by a U.S. government contractor, and their fast spread through the cybercriminal ecosystem.
Flock’s nationwide network of 130,000 searchable license plate cameras has raised bipartisan concerns about privacy, surveillance, and civil liberties across the United States.
Apple claims it has evidence that a former employee deleted or destroyed evidence related to alleged data theft after discovering he was being investigated, suggesting an attempt to conceal misconduct and complicate the company’s inquiry.
A U.S. medical distributor serving hospitals and healthcare practices reported a hack and warned that customers may experience intermittent service disruptions.
AI is increasingly effective at discovering and exploiting security vulnerabilities, raising concerns that governments may face greater difficulty using hacking tools and spyware and may revive debates over device backdoors.
Cloudflare’s Adaptive Intelligence engine aims to reverse the long-standing advantage of bot operators by learning from live traffic meta-signals and rapidly deploying disposable rules that make automated attacks costlier and harder to sustain.
Testing 100 companies showed that privacy requests frequently resulted in confusion, unclear processes, and dead ends for users seeking to exercise their data rights.
Cancellations have increased at a faster pace, indicating a notable rise in the rate at which planned or existing commitments are being called off.
Brave announced a feature that lets users sign up for websites and online services without revealing their personal email addresses, improving privacy and reducing unwanted exposure of contact information.
The backlash against license plate readers is part of a broader public reaction to police misuse of surveillance cameras, reflecting growing concern over privacy, accountability, and unchecked monitoring.
Meta updated its AI glasses so recording stops whenever the safety light is covered, addressing a privacy loophole that could let users secretly capture video by blocking the indicator meant to signal active recording.
A group carried out a relentless supply-chain attack campaign that infected more than 1,000 organizations, highlighting the scale and persistence of the operation.
Patching vulnerabilities faster is no longer enough because AI-driven discovery accelerates bug finding, so organizations should focus on structural invariants and design choices that eliminate entire classes of bugs rather than repeatedly fixing individual flaws.
The ATF has become the latest federal agency to report a major cybersecurity incident to Congress, highlighting ongoing concerns about government network security and the frequency of serious breaches across federal institutions.
Major tech companies and AI startups are jointly criticizing today’s cybersecurity landscape while promoting a new solution they claim can defend against emerging cyber threats.
Arrests followed a series of cyberattacks earlier this year that targeted technology companies dependent on widely used, high-profile open source software.
The report provides the most complete accounting yet of a cybersecurity incident spanning several separate compromises, offering a broader and more detailed view of what occurred across the event.
The company has not disclosed whether medical devices were impacted or whether any customer data was stolen, leaving the scope of the incident unclear.
The FBI seized domains tied to a botnet used by Chinese-backed hackers to infiltrate multiple U.S. government departments, disrupting infrastructure that supported the cyberattacks and signaling an active law enforcement response to foreign cyber threats.
Apple reversed a planned change that would have moved new iCloud+ Hide My Email addresses from the shared iCloud.com domain to private.icloud.com, preserving a key privacy and usability benefit for users who rely on forwarding addresses to protect their real email across websites.
Ring says users can still choose end-to-end encryption, indicating the security feature remains available as an optional setting rather than being removed entirely.
The federal cyber agency issued a warning as suspected Iran-backed cyberattacks increasingly target critical water systems across the United States, raising concerns about infrastructure security and potential disruption.
The discussion examines GLM-5.3’s unexpectedly strong cybersecurity performance, especially in vulnerability discovery and validation, and weighs whether increasingly capable open-weight models are more beneficial for finding and fixing flaws or more concerning because defensive automation is lagging behind offensive progress.
X has issued cease-and-desist letters to Nitter, the open source project that powers privacy-focused X front ends, demanding removal of its instances and code repository over alleged scraping activity.
AI tool quickstarts for apps like Claude Desktop, Cursor, and Copilot often encourage storing API keys and tokens in plaintext config files, creating a serious local secret-exposure risk that the content warns against.
Grand Theft Auto fans awaiting news about the highly anticipated game appear particularly vulnerable to a new cyberattack targeting their eagerness and curiosity.
Apple will stop using its icloud.com domain for email address masking, changing how it hides users’ real email addresses and likely affecting privacy-related email workflows.
The content explains that AI systems can be compromised and introduces core cybersecurity concepts—authentication, authorization, trust boundaries, untrusted input, attack surface, and blast radius—showing why AI engineers must design, validate, and contain systems securely before, during, and after deployment.
WhatsApp has upgraded two-step verification by allowing users to replace the traditional six-digit PIN with a stronger alphanumeric password that can include special characters for better account security.
Zeiss adopted Cisco Cyber Vision to improve OT security as connected operations and cloud data sharing increased risk, gaining better asset visibility, communication-flow insight, vulnerability awareness, and reduced manual workload while strengthening cyber resilience across manufacturing.