Topic

Cyber security

Live headlines from 21 curated sources in this topic.

Latest

Updated 03:15 PM
Krebs on Security

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the sus…

Sep 28, 03:08 PM
Latest news

Your Bose headphones are getting a major Bluetooth upgrade – what to expect

Key Bluetooth technologies and upgrades to USB-C audio are coming to the company’s flagship over-ears.

Sep 28, 02:40 PM
Schneier on Security

New Attack Against RSA

ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring. First, this attack isn’t new. The original research is from 2007. What is new is the implementation. Second, it is a forgery attack. It…

Sep 28, 11:02 AM
Darknet – Hacking Tools, Hacker News & Cyber Security

http-terminator – AI-Assisted HTTP Request-Smuggling Discovery

http-terminator is PortSwigger's AI pipeline for discovering HTTP request-smuggling bugs. Which stages run, its dependencies, and its testing limits.

Sep 28, 07:09 AM
CyberWire Daily

The Insider You Built with author Camille Stewart Gloster. [Special Edition]

On this special edition podcast, N2K CyberWire's Dave Bittner spoke with Camille Stewart Gloster⁠. Camille is the author of The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents, and founder of…

Sep 27, 05:00 AM
CyberWire Daily

Space cybersecurity starts on the ground. [T-Minus: Space-Cyber Briefing]

Though spacecraft are important, space cybersecurity extends well beyond these assets touching ground stations, mission-control assets, and other critical components. Host Maria Varmazis speaks with Milenk Starcevic, …

Sep 27, 05:00 AM
CyberWire Daily

An apple a day, a phish away. [Research Saturday]

Today we are joined by Ensar Seker, VP of Research and CISO at SOCRadar, discussing their work on "Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain." An investigation into AnonyMousKIT reveals an AI-powered Phishing-…

Sep 26, 07:00 AM
Krebs on Security

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in feder…

Sep 25, 09:44 PM
Schneier on Security

Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee

I feel like someone who reads this blog will want to go to this: Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Cent…

Sep 25, 09:08 PM
CyberWire Daily

Shut it down before they do.

Kiteworks urges customers pull the plug on vulnerable servers. CISA lays out its election security plan. Known vulnerabilities linger unpatched. Big AI labs consider a new standards body. Questions surround claims of an …

Sep 25, 08:30 PM
Latest news

This one WatchOS 27 feature just solved my biggest issue with Apple Watch

Sometimes less is more, and the most helpful software update is the simplest.

Sep 25, 04:51 PM
Latest news

Your LG TV is constantly collecting your data – here’s how to stop it

Factory resetting your LG TV is the only way to remove certain data logs from its hardware.

Sep 25, 12:18 PM
Latest news

Microsoft’s new Copilot app puts everything in one place – but the price is ‘evolving’

Microsoft says Copilot has gotten ‘actually really good.’ The new app has AI agents and can write code. So how much is all this going to cost?

Sep 25, 12:00 PM
Schneier on Security

On Anthropic’s AI Misuse Report

Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings. A few of the highlights: AI agents increasingly han…

Sep 25, 11:07 AM
Latest news

Google Wallet got a lot of new tricks in 2026 – these 5 are my favorites

You can do a whole lot more than tap to pay with Google’s Wallet app.

Sep 24, 08:31 PM
CyberWire Daily

No factoring necessary.

Researchers find a new way to weaken RSA. ShinyHunters allegedly exposes sensitive FBI details. CISA and the FBI warn of third-party ICS risks. An OpenAI agent hacks an Australian government portal. SolarWinds patches cr…

Sep 24, 08:30 PM
Latest news

Microsoft’s Surface Mouse is back, now with haptic feedback – and I need it

Due October 13, the $80 Surface mouse packs an impressive array of features. I want one.

Sep 24, 04:22 PM
Blackhat Library: Hacking techniques and research

SourceHut account takeover via build logs

submitted by /u/arusekk_pl [link] [comments]

Sep 24, 03:48 PM
Schneier on Security

Malicious npm Packages That Evade Defenses

This is an impressive piece of malware. Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.

Sep 24, 11:07 AM
Hacking Humans

404: scam not found.

This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠…

Sep 24, 05:00 AM
CyberWire Daily

The hunters go after the bureau.

ShinyHunters claims to have breached FBI systems. CLOSEDQUORUM malware delegates command-and-control decisions to commercial LLMs. An IT error erases 11 years of hospital maternity data. F5 patches a critical BIG-IP APM …

Sep 23, 08:30 PM
Schneier on Security

Research on Models Engaging in Genie-Like Behavior

New paper: “Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training.” Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reas…

Sep 23, 11:03 AM
Blackhat Library: Hacking techniques and research

Masterhacker

Ramsoftware is 1337 submitted by /u/Quirky-Anybody5491 [link] [comments]

Sep 22, 04:45 PM
Darknet Diaries

LOW - Now Available

After 8 years, LOW is finally here. A story about the weight of being and the wreckage of waking up. Five episodes. Five descents. LOW is an audio journey into the unlit corners of human experience. Choices we made in th…

Sep 22, 02:00 PM
Blackhat Library: Hacking techniques and research

A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight

submitted by /u/wiredmagazine [link] [comments]

Sep 22, 12:11 PM
Schneier on Security

GPT-6 Astra Breaks an Old Enigma Message

This is pretty amazing: However, the most astonishing thing about this break is that the GPT­6 Astra did it entirely on its own. Carter Leffer only directed GPT­6 Astra to see if it could break any of the unbroken Enigma…

Sep 22, 11:02 AM
Blackhat Library: Hacking techniques and research

How do coordinated comment-bot rings manipulate short-form video algorithms to force "Top Comments"? (Technical Breakdown)

I’ve been studying comment sections on short-form video platforms (like TikTok and Reels) & keep noticing a highly coordinated automation phenomenon that I want to understand from a technical and architectural standpoint…

Sep 22, 09:27 AM
Hacking Humans

dumpster diving (noun) [Word Notes]

Please enjoy this encore of Word Notes. The act of searching through an organization's trash for discarded sensitive material.  CyberWire Glossary link: ⁠https://thecyberwire.com/glossary/dumpster-diving⁠ Audio refer…

Sep 22, 07:00 AM
ISF Podcast

357: Legal Owl Podcast: Steve Durbin on Cyber Risk in the Legal Industry

The tables turn in this episode, as Steve becomes the guest on “Legal Owl,” a podcast by John “Jock" Brocas, the executive coach whom you might remember from one of our shows earlier this year. In this first part of two,…

Sep 22, 04:01 AM
Darknet – Hacking Tools, Hacker News & Cyber Security

Hash Identifier Tools – Command-Line Password Hash Identification

hashID and Name-That-Hash tested against current password formats. Both miss bcrypt's $2b$ prefix; only Name-That-Hash recognises Argon2id.

Sep 21, 01:13 PM
Blackhat Library: Hacking techniques and research

Back when you could just freely login to hundreds of active servers a day

Just found these in my photobucket while looking for so.e old screenshots. submitted by /u/Sea_Manufacturer6590 [link] [comments]

Sep 19, 08:05 PM
Hacking Humans

Scamazon prime.

This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠…

Sep 17, 05:00 AM
Krebs on Security

Data Broker Radaris Loses Domains in Privacy Fight

The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recent…

Sep 16, 06:14 PM
Hacking Humans

SEO poisoning (noun) [Word Notes]

Please enjoy this encore of Word Notes. The manipulation of search engine optimization, SEO, to promote malicious sites in search engine results. CyberWire Glossary link: ⁠https://thecyberwire.com/glossary/search-engi…

Sep 15, 07:00 AM
ISF Podcast

356: From the archive – Communication, Listening and Being Heard

In this episode, ISF Chief Executive Steve Durbin talks with Dame Inga Beale, the former CEO of Lloyd’s of London, about the role that listening played when she became the first (and only) female CEO in Lloyd’s more than…

Sep 15, 04:01 AM
Darknet – Hacking Tools, Hacker News & Cyber Security

whitelist-bypass – WebRTC Tunnels Through Video-Calling Platforms

whitelist-bypass tunnels traffic through commercial video calls, for networks that allow only approved domains. How its two tunnels work, and the claim to verify.

Sep 14, 07:53 PM
Hacking Humans

Love, lies, and a fake 49er.

This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠…

Sep 10, 05:00 AM
Krebs on Security

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping …

Sep 8, 09:44 PM
Hacking Humans

catfish (noun) [Word Notes]

Please enjoy this encore of Word Notes. The practice of crafting a fake online persona for malicious purposes. CyberWire Glossary link: ⁠https://thecyberwire.com/glossary/catfish⁠ Audio reference link: netbunny, 2013…

Sep 8, 07:00 AM
Darknet – Hacking Tools, Hacker News & Cyber Security

WRAITH – Browser Hooking and Blind XSS Page Mirroring

WRAITH combines BeEF-style browser hooks with blind-XSS capture and a credentialed Page Mirror. Tested locally, with its limits examined.

Sep 7, 07:58 AM
Krebs on Security

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose l…

Sep 1, 10:40 PM
ISF Podcast

355: Eric O'Neill – Hackers Don't Break In, They Log In: Trust as the New Perimeter

Today, Steve is joined by former FBI agent Eric O’Neill. Eric is a cyber security expert and author, but he’s probably most well-known as the man who brought down Peter Hanssen, a Russian spy who became one of the most n…

Sep 1, 10:00 AM
Darknet Diaries

179: The Courthouse - Revisited

In this episode we follow up with Gabby and Justin from Episode 59 - two seasoned penetration testers who tell us a story about the time when they tried to break into a courthouse but it went all wrong, and what happened…

Sep 1, 07:00 AM
Darknet – Hacking Tools, Hacker News & Cyber Security

Praetorian – Offensive Security Tools Built Around Portable Go Workflows

Praetorian's Go security tools consolidate established offensive workflows, with portable binaries, direct pipelines and a partial shared SDK.

Aug 31, 07:40 AM
Darknet – Hacking Tools, Hacker News & Cyber Security

AI IR Overlay – Incident Response Specification for AI Agents

AI IR Overlay specifies containment for agents using valid credentials, with a working kill-switch contract and an admitted gap when no SOC is staffed.

Aug 28, 06:35 AM
Krebs on Security

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. …

Aug 27, 11:04 AM
ISF Podcast

354: SUMMER LISTENING: Emerging Threats for 2026

Today, Steve looks toward the horizon, at the threats and challenges that enterprises and business leaders will face in 2026 and beyond. He also gives advice on how everyone, from the board to the practitioner, can meet …

Aug 25, 04:01 AM
ISF Podcast

353: SUMMER LISTENING: Rest After Stress: The Psychology of High Performance

Today, Steve speaks with Lauren Farina, psychotherapist and founder of Invited Psychotherapy & Coaching. Lauren and Steve discuss how wellness is becoming a bigger part of the workplace and how we can stay mentally healt…

Aug 18, 04:01 AM
ISF Podcast

352: SUMMER LISTENING: Geoff White – Ransomware Is a Business and It's Competing Against You

In today’s episode, we welcome another ISF veteran: journalist Geoff White. The last time Geoff was a guest on the podcast, it was 2024 and he had just released a book about how the tech industry launders money for crimi…

Aug 11, 04:01 AM
Darknet Diaries

178: Ubiquiti

Nickolas Sharp worked for Ubiquiti, a company that makes networking equipment. He noticed that there were some security problems at work. He tried to point them out, but didn't feel like he was being listened to enough. …

Aug 4, 07:00 AM
Darknet Diaries

177: National Public Data

This is the story of the hacker known as "USDoD". When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spr…

Jul 21, 07:00 AM
Darknet Diaries

176: NSL

One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violat…

Jul 7, 07:00 AM
Darknet Diaries

175: Bayrob

It started with a fake car listing on eBay. What looked like a simple online scam quietly grew, over more than a decade, into one of the most sophisticated cybercrime operations the FBI had ever traced. Custom malware. O…

Jun 2, 07:00 AM
Google Online Security Blog

AI threats in the wild: The current state of prompt injections on the web

Posted by Thomas Brunner, Yu-Han Liu, Moni Pande At Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impac…

Apr 23, 09:38 PM
Google Online Security Blog

Bringing Rust to the Pixel Baseband

Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizin…

Apr 10, 03:12 PM
Google Online Security Blog

Protecting Cookies with Device Bound Session Credentials

Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public…

Apr 9, 05:07 PM
Google Online Security Blog

Google Workspace’s continuous approach to mitigating indirect prompt injections

Posted by Adam Gavish, Google GenAI Security Team Indirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This …

Apr 2, 04:00 PM
Google Online Security Blog

VRP 2025 Year in Review

Posted by Dirk Göhmann, Tony Mendez, and the Vulnerability Rewards Program Team 2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉! Origina…

Mar 31, 04:55 PM
Google Online Security Blog

Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

Posted by Eric Lynch, Product Manager, Android and Dom Elliott, Group Product Manager, Google Play Modern digital security is at a turning point. We are on the threshold of using quantum computers to solve "impossible"…

Mar 25, 01:00 PM
Malicious Life

Weev, Part 2

The Electronic Frontier Foundation, long time critics of the Computer Fraud and Abuse Act, followed Weev's trial - but did not get involved. For the appeal, however, the organization decided to step it. But althought the…

Dec 10, 11:03 AM