Apple issues emergency update to fix zero-day exploit in iPhone and macOS
techspot - According to Apple, the issue lies within Image I/O, the company's framework for handling a wide range of image file formats. If a device processes a specially crafted image, it can trigger memory corruption. While Apple has not disclosed what specific ou…
Back to Top / Thursday, August 21, 2025, 9:20 am / permalink 12787 / 4 stories in 6 months
Perplexity's Comet browser naively processed pages with evil instructions
Thomas Claburn / theregister - Rival Brave flags prompt injection vulnerability, now patched To the surprise of no one in the security industry, processing untrusted, unvalidated input is a bad idea.…
Back to Top / Wednesday, August 20, 2025, 3:20 pm / permalink 12742 / 2 stories in 6 months
Microsoft’s August 2025 security updates are breaking recovery tools on Windows 10 and Windows 11 PCs
tomshardware - Microsoft admits its latest security updates break Windows recovery tools like "Reset this PC" and "Fix problems using Windows Update" on multiple Windows versions.
Back to Top / Wednesday, August 20, 2025, 5:20 am / permalink 12692 / 8 stories in 6 months
PyPI now blocks domain resurrection attacks used for hijacking accounts
Bill Toulas / bleepingcomputer - The Python Package Index (PyPI) has introduced new protections against domain resurrection attacks that enable hijacking accounts through password resets. [...]
Back to Top / Tuesday, August 19, 2025, 4:21 pm / permalink 12653 / 3 stories in 6 months
Cisco's Secure Firewall Management Center now not-so secure, springs a CVSS 10 RCE hole
Jessica Lyons / theregister - Switchzilla's summer of perfect 10s Cisco has issued a patch for a maximum-severity bug in its Secure Firewall Management Center (FMC) software that could allow an unauthenticated, remote attacker to inject arbitrary shell commands on vulnerable systems.…
Back to Top / Friday, August 15, 2025, 1:21 pm / permalink 12419 / 2 stories in 6 months
Fortinet warns of FortiSIEM pre-auth RCE flaw with exploit in the wild
Bill Toulas / bleepingcomputer - Fortinet is warning about a remote unauthenticated command injection flaw in FortiSIEM that has in-the-wild exploit code, making it critical for admins to apply the latest security updates. [...]
Back to Top / Wednesday, August 13, 2025, 4:21 pm / permalink 12262 / 3 stories in 6 months
Alarm raised over 'high-severity' vulnerabilities in Matrix messaging protocol
therecord - An urgent patch has been released for two bugs affecting the Matrix messaging protocol used by some governments for secure communications.
Back to Top / Wednesday, August 13, 2025, 8:21 am / permalink 12206 / 2 stories in 6 months
Details emerge on WinRAR zero-day attacks that infected PCs with malware
Bill Toulas / bleepingcomputer - Researchers have released a report detailing how a recent WinRAR path traversal vulnerability tracked as CVE-2025-8088 was exploited in zero-day attacks by the Russian 'RomCom' hacking group to drop different malware payloads. [...]
Back to Top / Monday, August 11, 2025, 3:21 pm / permalink 12079 / 6 stories in 6 months
Hyundai tells Ioniq 5 owners it will fix keyless security flaw – for a $65 "contribution"
techspot - Kia, Hyundai, and Genesis EVs have been targeted by thieves in the UK and other locations in recent times who use a handheld emulation device disguised to look like a Game Boy. It features radio transmission components that crack the wireless protocols us…
Back to Top / Monday, August 11, 2025, 11:20 am / permalink 12057 / 2 stories in 6 months
Library of Congress explains how parts of US Constitution vanished from its website
Dominic-Madori Davis, Zack Whittaker / techcrunch - The U.S. congressional agency confirmed to TechCrunch that the removal of key sections of the Constitution from its website were removed in error. The full text has now been reinstated.
Back to Top / Thursday, August 7, 2025, 12:21 pm / permalink 11847 / 2 stories in 6 months
Microsoft warns of serious vulnerability in hybrid Exchange deployments
Sofia Elizabella Wyciślik-Wilson / betanews - Microsoft has issued a warning about a high-severity vulnerability in hybrid Microsoft Exchange Server deployments. Tracked as CVE-2025-53786, the vulnerability could allow for privilege escalation by cyber threat actors with administrative access to an o…
Back to Top / Thursday, August 7, 2025, 8:21 am / permalink 11829 / 6 stories in 6 months
United Airlines IT Glitch Resolved, Flights Resume After Grounding Issues
United Airlines experienced a disruptive IT malfunction that forced the grounding of flights across major US airports, prompting widespread travel delays. After persistent technical difficulties, the airline resolved the issue and resumed its flight operations, restoring normal service. The incident highlighted vulnerabilities in the carrier’s system management.
Back to Top / Wednesday, August 6, 2025, 11:20 pm / permalink 11810 / 0 stories in 7 months
There's a Tea app for men, and it also has security problems
Anna Washenko / engadget - Tea bills itself as a safety dating app for women, allowing users to anonymously share details about men they have met. A new app called TeaOnHer has emerged that attempts to flip the script, with men sharing information about women they date. And while T…
Back to Top / Wednesday, August 6, 2025, 6:20 pm / permalink 11785 / 2 stories in 7 months
Call Of Duty Has New Security Measures, Adding Secure-Boot Requirement
S.E. Doster / gamespot - Call of Duty's battle against hackers continues, and Activision has announced some major updates to the game's Ricochet anti-cheat for Season 5 and beyond. The publisher also confirmed legal action taken against several cheat makers.Season 5 of Black Ops …
Back to Top / Wednesday, August 6, 2025, 1:20 pm / permalink 11765 / 4 stories in 7 months
Hackers Used An Infected Calendar Invite To Hack Gemini And Take Control Of A Smart Home
bgr - The dangers of AI are becoming increasingly apparent, as hackers found a way to use Google's Gemini chatbot to take over a stranger's smart home devices.
Back to Top / Wednesday, August 6, 2025, 1:20 pm / permalink 11762 / 4 stories in 7 months
Microsoft’s ‘Agentic Web’ Ambition Hit by Embarrassing Security Flaw
Markus Kasanmascheff / winbuzzer - A critical security flaw in Microsoft's new NLWeb protocol raises questions about its 'agentic web' strategy, despite a quick patch from the company.The post Microsoft’s ‘Agentic Web’ Ambition Hit by Embarrassing Security Flaw appeared first on WinBuzzer.
Back to Top / Wednesday, August 6, 2025, 10:20 am / permalink 11731 / 3 stories in 7 months
UK MoD taps Australian cybersecurity startup Castlepoint after Afghan data breach
Lucy Adams / tech - Britain's Ministry of Defence (MoD) has selected Australian firm Castlepoint Systems to provide services for automating data classification and reducing the risk of human error. The company is now hea...
Back to Top / Wednesday, August 6, 2025, 7:21 am / permalink 11716 / 2 stories in 7 months
Nvidia rejects US demand for backdoors in AI chips
Dominic Preston / theverge - Nvidia’s chief security officer has published a blog post insisting that its GPUs “do not and should not have kill switches and backdoors.” It comes amid pressure from both sides of the Pacific, with some US lawmakers pushing Nvidia to grant the governmen…
Back to Top / Wednesday, August 6, 2025, 7:21 am / permalink 11713 / 11 stories in 7 months
Dell fixed security chip vulnerability that left millions open to attack
Brad Bennett / mobilesyrup - Tens of millions of Dell laptops were recently discovered to have a vulnerability that could have allowed hackers to steal sensitive data from users and monitor some of their computer activities. Dell validated this security analysis in June, and it appea…
Back to Top / Tuesday, August 5, 2025, 4:20 pm / permalink 11679 / 2 stories in 7 months
NVIDIA Patches Critical Triton Server Vulnerabilities Enabling Full AI System Takeover
Markus Kasanmascheff / winbuzzer - NVIDIA has patched critical RCE flaws in its Triton Inference Server after Wiz Research found an exploit chain allowing full AI system takeover. Update now.The post NVIDIA Patches Critical Triton Server Vulnerabilities Enabling Full AI System Takeover app…
Back to Top / Tuesday, August 5, 2025, 12:21 pm / permalink 11645 / 2 stories in 7 months