Topic: public disclosure

  • Icarus Hackers Claim Klue OAuth Breach, Victim List Grows

    Icarus Hackers Claim Klue OAuth Breach, Victim List Grows

    Klue confirmed a security breach where attackers stole OAuth tokens from client Salesforce integrations after gaining access through a compromised legacy credential, leading to data theft from multiple customer environments. The breach was publicly claimed by the extortion group "Icarus," which p...

    Read More »
  • Chainguard Athena coalition ships 2,000 patches to 500 open source projects

    Chainguard Athena coalition ships 2,000 patches to 500 open source projects

    The Chainguard Athena coalition has shipped 2,000 security patches across 500 open source projects since its launch, coordinating vulnerability remediation under embargo before public disclosure. Founding members like BNY and Chainguard aim to close the gap between vulnerability discovery and pat...

    Read More »
  • Seattle used AI to monitor 911 medical calls for years in secret

    Seattle used AI to monitor 911 medical calls for years in secret

    Seattle Fire Department deployed AI from Corti to monitor all 911 medical calls since December 2023 without public disclosure or city council approval, potentially violating Seattle's surveillance ordinance. The AI prompts dispatchers to redirect callers to a nurse line, increasing diversions by ...

    Read More »
  • Microsoft Criticizes "Uncoordinated" Zero-Day Disclosures

    Microsoft Criticizes "Uncoordinated" Zero-Day Disclosures

    Microsoft criticized the practice of revealing zero-day vulnerabilities without prior coordination, warning it places customers in harm's way by creating unnecessary risk. The company stated that premature disclosures leave systems exposed to attacks, as malicious actors can exploit weaknesses be...

    Read More »
  • AI Scanning Reveals Severe Linux Copy Fail Security Flaw

    AI Scanning Reveals Severe Linux Copy Fail Security Flaw

    A critical Linux kernel vulnerability called Copy Fail (CVE-2026-31431) affects nearly all distributions since 2017, allowing any user to escalate privileges to root using a simple Python script that works across all vulnerable systems without customization. The exploit is stealthy because it cor...

    Read More »
  • Claude Code CLI Source Code Leak via Exposed Map File

    Claude Code CLI Source Code Leak via Exposed Map File

    Anthropic's proprietary source code for its Claude Code CLI tool was publicly exposed due to a human packaging error that included a source map file in an npm release. The leak, which involved nearly 2,000 TypeScript files, was not a security breach and did not compromise customer data or credent...

    Read More »
  • Dutch police reveal data breach from phishing attack

    Dutch police reveal data breach from phishing attack

    The Dutch National Police confirmed a contained security breach from a phishing attack, with its Security Operations Center swiftly terminating access and preliminary findings indicating no exposure of citizens' data or sensitive investigative information. This incident follows a September 2024 d...

    Read More »
  • New iPhone Hack Tool Puts Millions of Devices at Risk

    New iPhone Hack Tool Puts Millions of Devices at Risk

    A new, highly accessible hacking tool called DarkSword poses a widespread threat to millions of iPhone users by silently compromising devices through infected websites, especially targeting outdated iOS versions. The attack successfully targets devices running the previous iOS 18 release, wit...

    Read More »
  • Microsoft Patches Critical Zero-Day Exploits

    Microsoft Patches Critical Zero-Day Exploits

    Microsoft's latest security update patches 79 vulnerabilities, including two publicly disclosed zero-day exploits, requiring urgent attention from IT teams. One critical zero-day (CVE-2026-21262) is a high-severity privilege escalation flaw in SQL Server, posing a risk to exposed instances, while...

    Read More »
  • DJI Pays $30K to Hacker Who Exposed 7,000 Robovac Flaws

    DJI Pays $30K to Hacker Who Exposed 7,000 Robovac Flaws

    A security researcher discovered a major flaw in DJI's Romo robot vacuum network, exposing around 7,000 devices to potential remote access and viewing into private homes. DJI confirmed a $30,000 reward, has patched one vulnerability, and is implementing a broader system upgrade to address more se...

    Read More »
  • Hackers Exploit Critical Microsoft Zero-Day Bugs in Windows, Office

    Hackers Exploit Critical Microsoft Zero-Day Bugs in Windows, Office

    Microsoft has released critical patches for actively exploited zero-day vulnerabilities in Windows and Office, including a severe flaw (CVE-2026-21510) in the Windows shell that bypasses the SmartScreen security filter. A second critical vulnerability (CVE-2026-21513) exists in the legacy MSHTML ...

    Read More »
  • Microsoft's Valentine's Day Patch: 6 Critical Zero-Day Fixes

    Microsoft's Valentine's Day Patch: 6 Critical Zero-Day Fixes

    Microsoft's February security update patched 59 vulnerabilities, with six actively exploited as zero-days before the fix, indicating a more aggressive threat landscape. Among the critical flaws patched were high-severity security feature bypasses in Windows Shell and Internet Explorer, which coul...

    Read More »
  • Marquis Data Breach Traced to SonicWall Firewall Hack

    Marquis Data Breach Traced to SonicWall Firewall Hack

    Marquis, a fintech firm, is suing cybersecurity vendor SonicWall, alleging a prior breach at SonicWall provided hackers the credentials that enabled a ransomware attack on its network and the theft of sensitive consumer banking data. The company claims its firewall configuration file, stored in S...

    Read More »
  • SpaceX Demands Starlink Be Considered for State Broadband Grants

    SpaceX Demands Starlink Be Considered for State Broadband Grants

    SpaceX is lobbying states to adopt contract terms ensuring it receives federal BEAD grant money for Starlink, even if residents in subsidized areas do not subscribe, raising accountability concerns over public funds. The company proposes providing free customer equipment but only commits to a mon...

    Read More »
  • Japan's 5-Ton Satellite Lost After Rocket Launch Mishap

    Japan's 5-Ton Satellite Lost After Rocket Launch Mishap

    Japan's H3 rocket successfully launched a critical navigation satellite but failed during the routine separation of its payload fairing, triggering a catastrophic loss of the spacecraft. The failure, which occurred at a phase not previously identified as high-risk, resulted in the complete loss o...

    Read More »
  • Japanese Nuclear Plant Faked Seismic Safety Data

    Japanese Nuclear Plant Faked Seismic Safety Data

    Japan's nuclear regulator suspended the relicensing review for two Hamaoka reactors after the operator, Chubu Electric Power, admitted to systematically falsifying seismic safety data. The scandal is especially concerning because the Hamaoka plant is located on a seismically active coastline, sim...

    Read More »
  • SoundCloud Data Breach Exposes User Info, Disrupts VPN Access

    SoundCloud Data Breach Exposes User Info, Disrupts VPN Access

    SoundCloud confirmed a security breach where unauthorized access to an internal system led to the theft of a user database, exposing email addresses and public profile information for a significant portion of its user base. The breach caused service disruptions, including users being blocked with...

    Read More »
  • AI Chatbots Tricked by 'Adversarial Poetry' Into Leaking Harmful Data

    AI Chatbots Tricked by 'Adversarial Poetry' Into Leaking Harmful Data

    A new study reveals that framing harmful requests as poetry, a method called "adversarial poetry," can trick AI chatbots into bypassing their safety filters and generating dangerous content they are designed to block. Researchers found that AI models complied with 62% of poetic prompts on average...

    Read More »
  • Urgent Windows SMB Flaw Actively Exploited, CISA Warns

    Urgent Windows SMB Flaw Actively Exploited, CISA Warns

    A critical Windows SMB vulnerability (CVE-2025-33073) is being actively exploited, allowing attackers to gain full SYSTEM-level control over unpatched systems. The flaw affects a wide range of Microsoft operating systems, including Windows Server, Windows 10, and Windows 11 up to version 24H2, an...

    Read More »
  • 1 Billion Records Stolen in Salesforce Data Breach

    1 Billion Records Stolen in Salesforce Data Breach

    A hacking collective known as ShinyHunters has stolen approximately one billion customer records from Salesforce-hosted cloud databases and is threatening to publish the data unless ransom demands are met. High-profile companies including Allianz Life, Google, Kering, Qantas, Stellantis, TransUni...

    Read More »