Topic: public disclosure
-
Seattle used AI to monitor 911 medical calls for years in secret
Seattle Fire Department deployed AI from Corti to monitor all 911 medical calls since December 2023 without public disclosure or city council approval, potentially violating Seattle's surveillance ordinance. The AI prompts dispatchers to redirect callers to a nurse line, increasing diversions by ...
Read More » -
Microsoft's Valentine's Day Patch: 6 Critical Zero-Day Fixes
Microsoft's February security update patched 59 vulnerabilities, with six actively exploited as zero-days before the fix, indicating a more aggressive threat landscape. Among the critical flaws patched were high-severity security feature bypasses in Windows Shell and Internet Explorer, which coul...
Read More » -
Chainguard Athena coalition ships 2,000 patches to 500 open source projects
The Chainguard Athena coalition has shipped 2,000 security patches across 500 open source projects since its launch, coordinating vulnerability remediation under embargo before public disclosure. Founding members like BNY and Chainguard aim to close the gap between vulnerability discovery and pat...
Read More » -
Claude Code CLI Source Code Leak via Exposed Map File
Anthropic's proprietary source code for its Claude Code CLI tool was publicly exposed due to a human packaging error that included a source map file in an npm release. The leak, which involved nearly 2,000 TypeScript files, was not a security breach and did not compromise customer data or credent...
Read More » -
SoundCloud Data Breach Exposes User Info, Disrupts VPN Access
SoundCloud confirmed a security breach where unauthorized access to an internal system led to the theft of a user database, exposing email addresses and public profile information for a significant portion of its user base. The breach caused service disruptions, including users being blocked with...
Read More » -
AI Scanning Reveals Severe Linux Copy Fail Security Flaw
A critical Linux kernel vulnerability called Copy Fail (CVE-2026-31431) affects nearly all distributions since 2017, allowing any user to escalate privileges to root using a simple Python script that works across all vulnerable systems without customization. The exploit is stealthy because it cor...
Read More » -
Icarus Hackers Claim Klue OAuth Breach, Victim List Grows
Klue confirmed a security breach where attackers stole OAuth tokens from client Salesforce integrations after gaining access through a compromised legacy credential, leading to data theft from multiple customer environments. The breach was publicly claimed by the extortion group "Icarus," which p...
Read More » -
Microsoft Patches Critical Zero-Day Exploits
Microsoft's latest security update patches 79 vulnerabilities, including two publicly disclosed zero-day exploits, requiring urgent attention from IT teams. One critical zero-day (CVE-2026-21262) is a high-severity privilege escalation flaw in SQL Server, posing a risk to exposed instances, while...
Read More » -
DJI Pays $30K to Hacker Who Exposed 7,000 Robovac Flaws
A security researcher discovered a major flaw in DJI's Romo robot vacuum network, exposing around 7,000 devices to potential remote access and viewing into private homes. DJI confirmed a $30,000 reward, has patched one vulnerability, and is implementing a broader system upgrade to address more se...
Read More » -
Microsoft Criticizes "Uncoordinated" Zero-Day Disclosures
Microsoft criticized the practice of revealing zero-day vulnerabilities without prior coordination, warning it places customers in harm's way by creating unnecessary risk. The company stated that premature disclosures leave systems exposed to attacks, as malicious actors can exploit weaknesses be...
Read More » -
Japanese Nuclear Plant Faked Seismic Safety Data
Japan's nuclear regulator suspended the relicensing review for two Hamaoka reactors after the operator, Chubu Electric Power, admitted to systematically falsifying seismic safety data. The scandal is especially concerning because the Hamaoka plant is located on a seismically active coastline, sim...
Read More » -
Perplexity Comet Browser Prompt Injection Vulnerability Exposed
A security flaw in Perplexity's Comet AI browser allows attackers to inject malicious prompts via webpages, potentially accessing sensitive information from other open tabs. The vulnerability occurs because the AI processes webpage content without distinguishing between legitimate user instructio...
Read More » -
AI Chatbots Tricked by 'Adversarial Poetry' Into Leaking Harmful Data
A new study reveals that framing harmful requests as poetry, a method called "adversarial poetry," can trick AI chatbots into bypassing their safety filters and generating dangerous content they are designed to block. Researchers found that AI models complied with 62% of poetic prompts on average...
Read More » -
1 Billion Records Stolen in Salesforce Data Breach
A hacking collective known as ShinyHunters has stolen approximately one billion customer records from Salesforce-hosted cloud databases and is threatening to publish the data unless ransom demands are met. High-profile companies including Allianz Life, Google, Kering, Qantas, Stellantis, TransUni...
Read More » -
Asahi Hit by Ransomware Attack, Data Breach Confirmed
Asahi Group Holdings experienced a ransomware attack causing major IT system failures, halting automated order and shipping operations and forcing a temporary switch to manual processes. The cyber intrusion led to a confirmed data breach, with evidence of information being illicitly extracted, an...
Read More » -
New iPhone Hack Tool Puts Millions of Devices at Risk
A new, highly accessible hacking tool called DarkSword poses a widespread threat to millions of iPhone users by silently compromising devices through infected websites, especially targeting outdated iOS versions. The attack successfully targets devices running the previous iOS 18 release, wit...
Read More » -
Hackers Exploit Critical Microsoft Zero-Day Bugs in Windows, Office
Microsoft has released critical patches for actively exploited zero-day vulnerabilities in Windows and Office, including a severe flaw (CVE-2026-21510) in the Windows shell that bypasses the SmartScreen security filter. A second critical vulnerability (CVE-2026-21513) exists in the legacy MSHTML ...
Read More » -
SpaceX Demands Starlink Be Considered for State Broadband Grants
SpaceX is lobbying states to adopt contract terms ensuring it receives federal BEAD grant money for Starlink, even if residents in subsidized areas do not subscribe, raising accountability concerns over public funds. The company proposes providing free customer equipment but only commits to a mon...
Read More » -
Dutch police reveal data breach from phishing attack
The Dutch National Police confirmed a contained security breach from a phishing attack, with its Security Operations Center swiftly terminating access and preliminary findings indicating no exposure of citizens' data or sensitive investigative information. This incident follows a September 2024 d...
Read More » -
Japan's 5-Ton Satellite Lost After Rocket Launch Mishap
Japan's H3 rocket successfully launched a critical navigation satellite but failed during the routine separation of its payload fairing, triggering a catastrophic loss of the spacecraft. The failure, which occurred at a phase not previously identified as high-risk, resulted in the complete loss o...
Read More »