Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021.
The end-to-end...
The idea behind OpenAI's Trusted Access for Cyber program is to give trusted defenders better models so they can report bugs and vulnerabilities to companies, with the aim of getting flaws patched faster.
The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first.
The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop.
'Personally owned body-worn cameras are prohibited,' ICE tells The Reg. Because the last thing DHS needs is more proof of misconduct
Flock's surveillance cameras track drivers across the US. We asked CEO Garrett Langley about abuse, oversight, and who's really in control.
Learn how Flock cameras track vehicles, why communities use them, and what their growing network means for your privacy.
Healthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health record environments.
In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. [...]
A legitimate-looking link or valid digital signature can offer false reassurance. Here’s why familiar download safety checks aren’t always enough.
OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert another Hugging Face-like incident.
"As models become more capabl...
The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.
U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure. [...]
Ubuntu addressed security vulnerabilities in Cap'n Proto affecting multiple LTS versions, which could allow HTTP request or response smuggling. Users should update their systems for protection.
Debian released a security advisory for firefox-esr addressing multiple vulnerabilities, recommending users upgrade to version 140.14.0esr-1~deb13u1 to mitigate risks including code execution and information disclosure.
An exposed operator directory reveals how one actor compromised 14,000+ Dahua cameras across Ukraine and Russia, no password needed for most. A researcher discovered an exposed directory containing the tools of an attacker who compromised more than 14,000 Dahua cameras between June 17 and July 22, 2...
Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud.
The post Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 appeared first on Microso...
The U.S. phone provider escaped a large-scale breach of its network after identifying Chinese-backed hackers early on.
Many teams now deploy AI agents that pull from Amazon DynamoDB tables, document repositories, software as a service (SaaS) platforms, and internal knowledge bases to answer questions and automate workflows. A key risk in these deployments is that the agent has no awareness of who’s asking, so it mig...
L'autorité espagnole sanctionne une société pour ne pas avoir respecté une injonction antérieure lui ordonnant de formaliser sa relation avec un prestataire. La société a tenté de requalifier la relation en coresponsabilité, a fourni des informations contradictoires et a omis d'informer l'autorité d...
L'autorité roumaine sanctionne une entreprise pour une violation de données résultant d'une attaque par hameçonnage, soulignant que l'absence de tests réguliers de l'efficacité des mesures de sécurité et de formation du personnel constitue un manquement à l'obligation de sécurité du traitement.Faits...