Security News
129 posts

A researcher hid white text in a Word file and turned Microsoft Copilot into a worm that rewrites your documents and copies itself into every file it touches. …

An attacker emptied 1,196 Bitcoin wallets in 41 minutes and took 70 million dollars. The owners did nothing wrong. Their hardware wallet had been quietly …

A sixteen-year-old spotted two memory bugs in the Linux kernel’s NTFS driver. That is the code that reads Windows disks. Both rated 7.8 HIGH. Then the …

A flaw more than 20 years old just left 36,872 servers reachable straight from the internet. Not the websites they run, the servers themselves, through the one …

An attacker can open your bank in your own browser, on a second desktop you will never see, and move money while your screen shows nothing wrong. It is called …

Shared AI Chats Exposed on Search Engines. Grok alone leaked around 370,000 of them. Anthropic pulled the leaked Claude share links out of Google over the …

There is a messaging app with more than 25,000 stars on GitHub that works with no internet. Your phone talks straight to other phones over Bluetooth, and your …

An Adobe extension on roughly 329 million browsers had a flaw the researchers named HermeticReader, and it let any web page you opened read your WhatsApp Web. …

The alarm bolted into your car to protect it can now be used to steal it. A person standing a few steps away pulls out a phone, and your doors pop open. More …

Someone published 204 exploit files on GitHub for software you almost certainly use, and told the vendors nothing. The makers found out the same way the …

For 15 years, a single crafted web request could quietly take over an nginx server, the software that receives and routes incoming traffic for roughly a third …

You opened an archive in 7-Zip, and the code that let it take over your machine had been sitting there since 2018. It was quietly patched on June 25. You were …

For weeks he promised that July 14 would shatter Microsoft’s bones. Patch Tuesday came, Microsoft closed a record 622 holes, and hours later he dropped …

A hole in WordPress handed your database to someone who never logged in. For 227 days it took one request. It needed no password and no plugin, just an address …

Some malware loads before Windows even starts, before your antivirus exists. It survives a full reinstall, and 11 files signed by Microsoft are all it takes. …

IonStack You tap one link, and root is already running on your Android 17 phone. You never download a file or approve a permission box because the page does the …
You are completely anonymous and think no one can trace you. But Windows put a permanent number on your machine, it never turns off, and that number is where …

TrojPix pulled a file off a computer that connects to nothing. 8.1 megabits a second. 208 meters away. Straight through a 30 cm concrete wall. It went out over …

JADEPUFFER is the first documented ransomware operation run by an AI agent. The agent broke in, stole credentials, jumped to a second target, encrypted a …

Millions of devices read an SD card with one small piece of code called FatFs, and researchers just found seven ways to break it. The worst one hands the whole …

Your AI assistant just sent you to a login page that did not exist a few weeks ago, and the person who registered it is already collecting the passwords people …

You unzipped a file with WinRAR, the way you always do. Nothing on screen looked wrong. The next morning you logged in and malware was already running, and the …

A Docker container on a Gitea build runner can break out to root on the host, the setting built to stop that does nothing, and there is no patch yet. CVSS 9.9. …

A flaw in the Linux kernel called pedit COW lets a regular, unprivileged user rewrite /bin/su in memory and become root, while the copy on disk never changes …

Google told a security researcher his bug was a nice catch, lined up his payout, then eleven days later called it harmless and refused to pay a cent. The flaw …

usbliter8 takes control of the iPhone XS and iPhone 11 before iOS even loads, and no update Apple ships can ever close it. The flaw lives in the SecureROM, the …

FortiBleed Fortinet credential leak. Attackers can log into more than 80,000 corporate firewalls right now, and on 2,645 of them the password was 123456. The …

A 27-year-old flaw in OpenBSD let attackers bypass its PPP login with nothing more than an empty username and an empty password. Hand a vulnerable system a …

1.2 million WordPress sites were caught in a supply chain attack last week, where the admin’s own login quietly created a secret account and planted a …

More than 400 packages in the Arch User Repository (AUR) were hijacked this week, and the attacker never broke into a single system to do it. They took over …