News
Infosec community panics as Anthropic rolls out Claude code security checker
ai-pocalypse Anthropic sent the infosec community into a tizzy on Friday when it rolled out Claude Code Security, a new feature that scans codebases for vulnerabilities and suggests patches to fix the issues.…
Global regulators say AI image tools don't get a free pass on privacy rules
A global coalition of privacy watchdogs has fired a warning shot at the generative AI industry, saying companies churning out realistic synthetic images can't pretend that data protection rules don't apply.…
Break free of Ring's servers, earn a five-figure bounty
If the sour taste has still not left your mouth after Ring's Super Bowl ad, there is a $10,000 prize for anyone who can find a security flaw in the company's cameras.…
Suspected Anonymous members detained in Spain over post-flood DDoS blitz
Spanish police say four self-proclaimed members of Anonymous are in custody after allegedly carrying out several cyberattacks on public authorities in the wake of the 2024 DANA floods.…
AWS says more than 600 FortiGate firewalls hit in AI-augmented campaign
Cybercriminals armed with off-the-shelf generative AI tools compromised more than 600 internet-exposed FortiGate firewalls across 55 countries in just over a month, according to a new incident report from AWS.…
Every day in every way, passwords are getting worse and worse
Passwords turn 65 this year. They became a feature of computer users' lives in 1961, with MIT's Compatible Time-Sharing System (CTSS). Before then, sysops were real sysops. All jobs went through them, one at a time, and access by others was forbidden by laws written on blocks of stone.…
Attacker gets into France's database listing all bank accounts, makes off with 1.2 million records
Infosec In Brief An unknown attacker accessed the French government’s database listing every bank account in the country and made off with 1.2 million records.…
UK council faces data breach claim after mishandling trans complaints
A UK councillor has dubbed her local authority's data breach "crazy" after the personal details of individuals behind a series of complaints were revealed to her.…
PayPal app code error leaked personal info and a 'few' unauthorized transactions
PayPal has notified about 100 customers that their personal information was exposed online during a code change gone awry, and in a few of these cases, people saw unauthorized transactions on their accounts.…
AI coding assistant Cline compromised to create more OpenClaw chaos
Someone compromised open source AI coding assistant Cline CLI's npm package earlier this week in an odd supply chain attack that secretly installed OpenClaw on developers' machines without their knowledge. …
ShinyHunters demands $1.5M not to leak Vegas casino and resort chain data
Las Vegas hotel and casino giant Wynn Resorts appears to be the latest victim of data-grabbing and extortion gang ShinyHunters.…
Ukrainian gets five years for helping North Koreans secure US tech jobs
Ukrainian national Oleksandr Didenko will spend the next five years behind bars in the US for his involvement in helping North Korean IT workers secure fraudulent employment.…
Founder ditches AWS for Euro stack, finds sovereignty isn't plug-and-play
Building a startup entirely on European infrastructure sounds like a nice sovereignty flex right up until you actually try it and realize the real price gets paid in time, tinkering, and slowly unlearning a decade of GitHub muscle memory.…
CISA gives federal agencies three days to patch actively exploited Dell bug
Uncle Sam's cyber defenders have given federal agencies just three days to patch a maximum-severity Dell bug that's been under active exploitation since at least mid-2024.…
Ex-Google engineers accused of helping themselves to chip security secrets
Two former Google engineers and a third alleged accomplice are facing federal charges after prosecutors accused them of swiping sensitive chip and security technology secrets and then trying to cover their tracks when the scheme began to unravel.…
Attackers have 16-digit card numbers, expiry dates, but not names. Should org get £500k fine?
The UK's data protection watchdog has scored a small win in a lengthy legal battle against a British retail group that lost millions of data records during a 2017 breach.…
Snyk CEO bails, wants someone with more AI experience to replace him
The CEO of code review platform provider Snyk has announced he will stand down so the company can find someone better-equipped to steer the company into the age of AI.…
AI agents abound, unbound by rules or safety disclosures
AI agents are becoming more common and more capable, without consensus or standards on how they should behave, say academic researchers.…
Crims create fake remote management vendor that actually sells a RAT
Researchers at Proofpoint late last month uncovered what they describe as a "weird twist" on the growing trend of criminals abusing remote monitoring and management software (RMM) as their preferred attack tools.…
Crims hit a $20M jackpot via malware-stuffed ATMs
Thieves stole more than $20 million from compromised ATMs last year using a malware-assisted technique that the FBI says is on the uptick across the United States.…