News
Colt changes tune, admits data theft as Warlock gang begins auction
A week after its services were disrupted by a cyberattack, UK telco Colt Technology Services has gone back on its initial statement to confirm that data has indeed been stolen.…
Google yet to take down 'screenshot-grabbing' Chrome VPN extension
Security boffins at Koi Security have warned of a shift in behavior of a popular Chrome VPN extension, FreeVPN.One, which recently appears to have begun snaffling screenshots of users' page activity and transmitting them to a remote server without their knowledge – and Google has yet to take it down.…
AI crawlers and fetchers are blowing up websites, with Meta and OpenAI the worst offenders
Cloud services giant Fastly has released a report claiming AI crawlers are putting a heavy load on the open web, slurping up sites at a rate that accounts for 80 percent of all AI bot traffic, with the remaining 20 percent used by AI fetchers. Bots and fetchers can hit websites hard, demanding data from a single site in thousands of requests per minute.…
China cut itself off from the global internet for an hour on Wednesday
China cut itself off from much of the global internet for just over an hour on Wednesday.…
Microsoft stays mum about M365 Copilot on-demand security bypass
UPDATED Microsoft has chosen not to tell customers about a recently patched vulnerability in M365 Copilot.…
Amazon quietly fixed Q Developer flaws that made AI agent vulnerable to prompt injection, RCE
Amazon has quietly fixed a couple of security issues in its coding agent: Amazon Q Developer VS Code extension. Attackers could use these vulns to leak secrets, including API keys from a developer's machine, and run arbitrary code.…
FBI: Russian spies exploiting a 7-year-old Cisco bug to slurp configs from critical infrastructure
The FBI and security researchers today warned that Russian government spies exploited a seven-year-old bug in end-of-life Cisco networking devices to snoop around in American critical infrastructure networks and collect information on industrial systems.…
Commvault releases patches for two nasty bug chains after exploits proven
Researchers at watchTowr just published working proof-of-concept exploits for two unauthenticated remote code execution bug chains in backup giant Commvault.…
'Limited' data leak at Aussie telco turns out to be 280K customer details
Aussie telco giant TPG Telecom has opened an investigation after confirming a cyberattack at subsidiary iiNet.…