Latest in Cyber security

Updated 02:05 PM
Latest news I used OpenFactory to build my own Linux distro overnight - this AI tool is going to be big
Latest news

Need a custom Linux distribution, but don't have time to learn how to build one? OpenFactory can help you.

Aug 14, 11:53 AM
Krebs on Security Who’s Tracking You? Use This New Service to Find Out
Krebs on Security

Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily pa…

Aug 14, 11:24 AM
Schneier on Security If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them
Schneier on Security

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian. OpenAI, and then Anthropic, were each formed by AI developers who feared unrestrained corporate AI development—specifically, that co…

Aug 14, 11:03 AM
Latest news This free Android assistant fixes my biggest Gemini frustration - and keeps my data private
Latest news

With Google set to retire Assistant, and Gemini not exactly the replacement many of us want, Dicio is a solid option. There's one catch.

Aug 14, 12:00 AM
Latest news I tried the new ChatGPT Desktop App for Linux - but I'll stick to my browser for now
Latest news

This preview release of ChatGPT Desktop for Linux supports Ubuntu, Debian, and Fedora is here.

Aug 13, 08:46 PM
CyberWire Daily Please hack responsibly.
CyberWire Daily

President Trump deputizes private-sector companies to target cybercriminals. The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations. Data-theft campaign targets misconfigured Salesfor…

Aug 13, 08:30 PM
Latest news Gemini voice calling on Android Auto keeps failing me - and Google has until September to fix it
Latest news

With Google Assistant shutting down this fall, Android users will be left with inferior voice calling, thanks to Gemini.

Aug 13, 05:07 PM
Latest news This Micro RGB TV rivals pricier OLED models - and I'd recommend it, especially on sale
Latest news

The Samsung R95H is built with an all-new Micro RGB panel that delivers truly impressive color and contrast.

Aug 13, 04:00 PM
Latest news I wore Samsung's and Apple's Ultra smartwatches for 3 weeks - apps made all the difference
Latest news

The Apple Watch Ultra 3 and the Samsung Galaxy Watch Ultra 2 are top-tier rugged smartwatches with similar features, but one stands out.

Aug 13, 03:30 PM
Schneier on Security Separating AI’s Technological Problems from Its Capitalism Problems
Schneier on Security

This essay was written with Nathan E. Sanders, and originally appeared in Tech Policy Press. AI represents the first time we humans can do cognitive work outside of our bodies at scale. The only comparable moment is the …

Aug 13, 11:07 AM
Hacking Humans A golden opportunity...for fraud.
Hacking Humans

This week, while Dave is out, hosts ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Joe Carrigan⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠…

Aug 13, 05:00 AM
CyberWire Daily A flurry of fixes.
CyberWire Daily

We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data breach following exto…

Aug 12, 08:30 PM
Schneier on Security Prompt Injections for Defense
Schneier on Security

This seems to work: Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was neede…

Aug 12, 09:56 AM
Krebs on Security Microsoft Plugs Nearly 400 Security Holes
Krebs on Security

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others tha…

Aug 11, 09:28 PM
CyberWire Daily A private route to public risk.
CyberWire Daily

Poland’s CERT describes winter cyberattack against heat-and-power plant. Russian military hackers target Ukrainian IT workers in fake recruitment scheme. Chinese IP connections spark security review in UK Navy drones. US…

Aug 11, 08:30 PM
Schneier on Security AI Genie in the Wild
Schneier on Security

When I give talks about AI genies, I use this sort of example as a hypothetical. It’s happened. The story is from Australia. Someone named Andrew tasked OpenClaw to book gym classes for him. And…. Minutes later, his AI a…

Aug 11, 03:55 PM
Schneier on Security AI for Military Support
Schneier on Security

Interesting empirical research: “Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI.” Abstract: How is AI transforming decision-making in modern conflict? This study provides a unique empiric…

Aug 11, 11:18 AM
Hacking Humans spearphishing (noun) [Word Notes]
Hacking Humans

spearphishing (noun) [Word Notes]

Please enjoy this encore of Word Notes. A type of cyber attack where an attacker sends a targeted and personalized email or other form of communication to a specific individual or a small group of individuals with the …

Aug 11, 07:00 AM
ISF Podcast 352: Summer Listening: Geoff White – Ransomware Is a Business and It's Competing Against You
ISF Podcast

352: Summer Listening: Geoff White – Ransomware Is a Business and It's Competing Against You

In today’s episode, we welcome another ISF veteran: journalist Geoff White. The last time Geoff was a guest on the podcast, it was 2024 and he had just released a book about how the tech industry launders money for crimi…

Aug 11, 04:01 AM
CyberWire Daily Now with extra vulnerabilities.
CyberWire Daily

Researchers find that only a quarter of AI-generated patches are fully successful. Ransomware attacks exploit critical N-able flaw. Atlassian fixes critical flaw in Rovo AI. LexisNexis disables some services following su…

Aug 10, 08:30 PM
Schneier on Security Python Now Has a Post-Quantum Encryption Library
Schneier on Security

This is good: Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support for ML-KEM, the NIST-standard key-establishment pri…

Aug 10, 11:02 AM
CyberWire Daily Designing space systems for the AI era. [T-Minus: Space-Cyber Briefing]
CyberWire Daily

Designing space systems for the AI era. [T-Minus: Space-Cyber Briefing]

As commercial space activity accelerates, satellite manufacturers are rethinking how spacecraft are designed, built, and secured. In this week's episode, host Maria Varmazis sits down with Jason Roberson, an Industry Va…

Aug 9, 05:00 AM
CyberWire Daily A little help from your search engine. [Research Saturday]
CyberWire Daily

A little help from your search engine. [Research Saturday]

Today we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Cyderes, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identified an SEO poisonin…

Aug 8, 07:00 AM
Krebs on Security Canadian Man Pleads Guilty in Snowflake Extortions
Krebs on Security

Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the…

Aug 6, 05:00 PM
Darknet Diaries LOW - Trailer
Darknet Diaries

LOW - Trailer

After 8 years, LOW is finally here. A story about the weight of being and the wreckage of waking up. Five episodes. Five descents. LOW is an audio journey into the unlit corners of human experience. Choices we made in th…

Aug 6, 07:00 AM
Hacking Humans Cosmic brownie crimes.
Hacking Humans

This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠…

Aug 6, 05:00 AM
Darknet Diaries 178: Ubiquiti
Darknet Diaries

178: Ubiquiti

Nickolas Sharp worked for Ubiquiti, a company that makes networking equipment. He noticed that there were some security problems at work. He tried to point them out, but didn't feel like he was being listened to enough. …

Aug 4, 07:00 AM
Hacking Humans resiliency (noun) [Word Notes]
Hacking Humans

resiliency (noun) [Word Notes]

Please enjoy this encore of Word Notes. The ability to continuously deliver the intended outcome despite adverse cyber events. CyberWire Glossary link: ⁠https://thecyberwire.com/glossary/resiliency⁠ Audio reference l…

Aug 4, 07:00 AM
Hacking Humans Class is in session—for cybercriminals. [OMITB]
Hacking Humans

Class is in session—for cybercriminals. [OMITB]

Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Proofpoi…

Aug 4, 07:00 AM
ISF Podcast 351: Summer Listening: Steve Durbin – How Quantum and Geopolitics Are Redefining Resilience
ISF Podcast

351: Summer Listening: Steve Durbin – How Quantum and Geopolitics Are Redefining Resilience

Today, Steve returns to Business Matters with Juliette Foster. In this conversation, Steve recaps 2025 in cyber and shares what he sees as the biggest risks heading into 2026. The two also discuss resilience and complian…

Aug 4, 04:01 AM
Krebs on Security Read This Before You Buy That TV Streaming Stick
Krebs on Security

Read This Before You Buy That TV Streaming Stick

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connectio…

Jul 30, 04:49 PM
Hacking Humans Nothing but the spoof.
Hacking Humans

This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠…

Jul 30, 05:00 AM
ISF Podcast 350: Summer Listening: Alex Bovee – Identity in the Age of Agentic AI
ISF Podcast

350: Summer Listening: Alex Bovee – Identity in the Age of Agentic AI

In this episode, Steve speaks with Alex Bovee, co-founder and CEO of C1, a technology company focused on identity security online. Steve and Alex discuss why identity still often is an afterthought when businesses look a…

Jul 28, 04:01 AM
Krebs on Security LG to Ban Residential Proxies from Smart TV Apps
Krebs on Security

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after …

Jul 22, 01:10 AM
ISF Podcast 349: Steve Durbin – When Governments Shift: Reimagining UK Cyber Strategy and Business Resilience
ISF Podcast

349: Steve Durbin – When Governments Shift: Reimagining UK Cyber Strategy and Business Resilience

Today, Steve returns to Business Matters with Juliette Foster. The United Kingdom has a new Prime Minister: Andy Burnham, and Steve speaks with Juliette from a cyber and business perspective about what to expect from the…

Jul 21, 12:20 PM
Darknet Diaries 177: National Public Data
Darknet Diaries

177: National Public Data

This is the story of the hacker known as "USDoD". When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spr…

Jul 21, 07:00 AM
Krebs on Security Microsoft Patches a Record 570 Security Flaws
Krebs on Security

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-…

Jul 14, 07:22 PM
Darknet Diaries 176: NSL
Darknet Diaries

176: NSL

One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violat…

Jul 7, 07:00 AM
ISF Podcast 348: Geoff White – Ransomware Is a Business and It's Competing Against You
ISF Podcast

348: Geoff White – Ransomware Is a Business and It's Competing Against You

In today’s episode, we welcome another ISF veteran: journalist Geoff White. The last time Geoff was a guest on the podcast, it was 2024 and he had just released a book about how the tech industry launders money for crimi…

Jul 7, 04:01 AM
ISF Podcast 347: Alex Bovee – Identity in the Age of Agentic AI
ISF Podcast

347: Alex Bovee – Identity in the Age of Agentic AI

In this episode, Steve speaks with Alex Bovee, co-founder and CEO of C1, a technology company focused on identity security online. Steve and Alex discuss why identity still often is an afterthought when businesses look a…

Jun 30, 04:01 AM
Darknet Diaries 175: Bayrob
Darknet Diaries

175: Bayrob

It started with a fake car listing on eBay. What looked like a simple online scam quietly grew, over more than a decade, into one of the most sophisticated cybercrime operations the FBI had ever traced. Custom malware. O…

Jun 2, 07:00 AM
Darknet Diaries 174: Pacific Rim
Darknet Diaries

174: Pacific Rim

For six years, Sophos fought a secret cyber war against a state-backed hacking group targeting its firewalls. This forced Sophos to drastically change tactics to properly secure their firewalls. Was it ethical? Was it ef…

May 5, 07:00 AM
Google Online Security Blog AI threats in the wild: The current state of prompt injections on the web
Google Online Security Blog

AI threats in the wild: The current state of prompt injections on the web

Posted by Thomas Brunner, Yu-Han Liu, Moni Pande At Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impac…

Apr 23, 09:38 PM
Google Online Security Blog Bringing Rust to the Pixel Baseband
Google Online Security Blog

Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizin…

Apr 10, 03:12 PM
Google Online Security Blog Protecting Cookies with Device Bound Session Credentials
Google Online Security Blog

Protecting Cookies with Device Bound Session Credentials

Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public…

Apr 9, 05:07 PM
Google Online Security Blog Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Online Security Blog

Google Workspace’s continuous approach to mitigating indirect prompt injections

Posted by Adam Gavish, Google GenAI Security Team Indirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This …

Apr 2, 04:00 PM
Google Online Security Blog VRP 2025 Year in Review
Google Online Security Blog

VRP 2025 Year in Review

Posted by Dirk Göhmann, Tony Mendez, and the Vulnerability Rewards Program Team 2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉! Origina…

Mar 31, 04:55 PM
Google Online Security Blog Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Google Online Security Blog

Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

Posted by Eric Lynch, Product Manager, Android and Dom Elliott, Group Product Manager, Google Play Modern digital security is at a turning point. We are on the threshold of using quantum computers to solve "impossible"…

Mar 25, 01:00 PM
Darknet – Hacking Tools, Hacker News & Cyber Security MSSQLand – Lightweight MS-SQL Interaction Tool for Lateral Movement and Post-Exploitation
Darknet – Hacking Tools, Hacker News & Cyber Security

MSSQLand enables red teams to interact with MS-SQL servers and linked instances in restricted environments without complex T-SQL queries. Assembly-ready tool for lateral movement.

Mar 24, 01:00 AM
Darknet – Hacking Tools, Hacker News & Cyber Security Credential Stuffing in 2025 – How Combolists, Infostealers and Account Takeover Became an Industry
Darknet – Hacking Tools, Hacker News & Cyber Security

Credential stuffing drove 22% of all breaches in 2025. How combolists, infostealers and ATO tooling are fuelling enterprise account takeover at scale

Mar 11, 01:00 AM
Darknet – Hacking Tools, Hacker News & Cyber Security DumpBrowserSecrets – Browser Credential Harvesting with App-Bound Encryption Bypass
Darknet – Hacking Tools, Hacker News & Cyber Security

DumpBrowserSecrets extracts saved passwords, cookies, OAuth tokens and autofill data from Chrome, Edge, Firefox, Opera and Vivaldi, bypassing App-Bound Encryption via Early Bird APC injection.

Mar 9, 01:00 AM
Darknet – Hacking Tools, Hacker News & Cyber Security Systemic Ransomware Events in 2025 – How Jaguar Land Rover Showed What a Category 3 Supply Chain Breach Looks Like
Darknet – Hacking Tools, Hacker News & Cyber Security

Systemic ransomware events in 2025, how Jaguar Land Rover’s shutdown exposed Category 3 supply chain risk, with lessons from Toyota, Nissan and Ferrari.

Nov 26, 01:00 AM
Darknet – Hacking Tools, Hacker News & Cyber Security SmbCrawler – SMB Share Discovery and Secret-Hunting
Darknet – Hacking Tools, Hacker News & Cyber Security

SmbCrawler is a credentialed SMB share crawler for red teams that discovers misconfigured shares and hunts secrets across Windows networks.

Nov 24, 01:00 AM
Darknet – Hacking Tools, Hacker News & Cyber Security Heisenberg Dependency Health Check – GitHub Action for Supply Chain Risk
Darknet – Hacking Tools, Hacker News & Cyber Security

Heisenberg Dependency Health Check is a GitHub Action that flags risky or newly introduced dependencies in pull requests using supply-chain signals.

Nov 21, 01:00 AM
Malicious Life Weev, Part 2
Malicious Life

Weev, Part 2

The Electronic Frontier Foundation, long time critics of the Computer Fraud and Abuse Act, followed Weev's trial - but did not get involved. For the appeal, however, the organization decided to step it. But althought the…

Dec 10, 11:03 AM
Malicious Life Weev, Part 1
Malicious Life

Weev, Part 1

Much like Aaron Swartz did, Andrew "weev" Auernheimer fought against the Computer Fraud and Abuse Act, a law both men belived to be dangerous and unjust. But unlike Swartz, the internet's own boy, weev is an unapologetic…

Nov 27, 11:40 AM
Malicious Life Cuckoo Spear [B-Side]
Malicious Life

Cuckoo Spear [B-Side]

APT-10 is a Chinese nation-state threat actor that in recent years has been targeting Japanese IT & Instrastructure organizations using a sophisticated backdoor malware known as LODEINFO. Recently, Jin Ito & Loic Castel,…

Nov 20, 06:30 AM
Malicious Life The Man Who Went To War With Anonymous - And Lost
Malicious Life

The Man Who Went To War With Anonymous - And Lost

Aaron Barr was en-signals intelligence officer specializing in analytics. As part of HBGary Federal, he came up with a plan to unmask the key leaders of Anonymous, the infamous hacker collective. People who worked with A…

Nov 13, 10:31 AM
Malicious Life What Can Organizations Learn from "Grim Beeper"? [B-Side]
Malicious Life

What Can Organizations Learn from "Grim Beeper"? [B-Side]

On 17 and 18 of September 2024, thousands of pagers and hand held radio devices used by Hezbollah, exploded simultaneously across Lebanon and Syria, killing at least 42 terrorists and wounding more than 3,000.  Devon Ack…

Nov 5, 07:00 AM
Malicious Life The Fappening/Celebgate
Malicious Life

The Fappening/Celebgate

Could thousands of people keep a secret? Common sense says no—secrets spread, and people talk. But for over a decade, from 2006 to 2017, a website managed to stay under law enforcement’s radar, despite the fact that its …

Oct 29, 03:20 PM