Security News
165 posts

An AI found a hole in the Linux kernel that sat open for 18 years, then wrote the exploit that turns a local user into root. The machines were not …

Anyone on your network could take over a Mac with Screen Sharing turned on. All it took was the target’s IP address. The login check handed back an old …

CSS in an email put a fake Microsoft sign-in over a live Outlook inbox and read the password letter by letter. Opening the message is enough. Outlook, Gmail, …

OpenAI, Anthropic and Meta have admitted the same thing in three weeks. Their own models ended up outside the test environment. They broke into at least 5 …

A worm dumped 1,300 stashes of stolen developer keys into public GitHub repos in a day. You ran npm install. That was all. The poison sat in a library npm hands …

One 32-byte key protects the passkeys synced to your Google account. On Windows, a researcher lifted it out of Chrome’s memory and signed into a crypto …

A researcher hid white text in a Word file and turned Microsoft Copilot into a worm that rewrites your documents and copies itself into every file it touches. …

An attacker emptied 1,196 Bitcoin wallets in 41 minutes and took 70 million dollars. The owners did nothing wrong. Their hardware wallet had been quietly …

A sixteen-year-old spotted two memory bugs in the Linux kernel’s NTFS driver. That is the code that reads Windows disks. Both rated 7.8 HIGH. Then the …

A flaw more than 20 years old just left 36,872 servers reachable straight from the internet. Not the websites they run, the servers themselves, through the one …

An attacker can open your bank in your own browser, on a second desktop you will never see, and move money while your screen shows nothing wrong. It is called …

Shared AI Chats Exposed on Search Engines. Grok alone leaked around 370,000 of them. Anthropic pulled the leaked Claude share links out of Google over the …

There is a messaging app with more than 25,000 stars on GitHub that works with no internet. Your phone talks straight to other phones over Bluetooth, and your …

An Adobe extension on roughly 329 million browsers had a flaw the researchers named HermeticReader, and it let any web page you opened read your WhatsApp Web. …

The alarm bolted into your car to protect it can now be used to steal it. A person standing a few steps away pulls out a phone, and your doors pop open. More …

Someone published 204 exploit files on GitHub for software you almost certainly use, and told the vendors nothing. The makers found out the same way the …

For 15 years, a single crafted web request could quietly take over an nginx server, the software that receives and routes incoming traffic for roughly a third …

You opened an archive in 7-Zip, and the code that let it take over your machine had been sitting there since 2018. It was quietly patched on June 25. You were …

For weeks he promised that July 14 would shatter Microsoft’s bones. Patch Tuesday came, Microsoft closed a record 622 holes, and hours later he dropped …

A hole in WordPress handed your database to someone who never logged in. For 227 days it took one request. It needed no password and no plugin, just an address …

Some malware loads before Windows even starts, before your antivirus exists. It survives a full reinstall, and 11 files signed by Microsoft are all it takes. …

IonStack You tap one link, and root is already running on your Android 17 phone. You never download a file or approve a permission box because the page does the …
You are completely anonymous and think no one can trace you. But Windows put a permanent number on your machine, it never turns off, and that number is where …

TrojPix pulled a file off a computer that connects to nothing. 8.1 megabits a second. 208 meters away. Straight through a 30 cm concrete wall. It went out over …

JADEPUFFER is the first documented ransomware operation run by an AI agent. The agent broke in, stole credentials, jumped to a second target, encrypted a …

Millions of devices read an SD card with one small piece of code called FatFs, and researchers just found seven ways to break it. The worst one hands the whole …

Your AI assistant just sent you to a login page that did not exist a few weeks ago, and the person who registered it is already collecting the passwords people …

You unzipped a file with WinRAR, the way you always do. Nothing on screen looked wrong. The next morning you logged in and malware was already running, and the …

A Docker container on a Gitea build runner can break out to root on the host, the setting built to stop that does nothing, and there is no patch yet. CVSS 9.9. …

A flaw in the Linux kernel called pedit COW lets a regular, unprivileged user rewrite /bin/su in memory and become root, while the copy on disk never changes …