News
Years-old bugs in open source tool left every major cloud open to disruption
A series of "trivial-to-exploit" vulnerabilities in Fluent Bit, an open source log collection tool that runs in every major cloud and AI lab, was left open for years, giving attackers an exploit chain to completely disrupt cloud services and alter data.…
Intrusion at real estate finance biz sparks concern for big banks
Real estate finance business SitusAMC says thieves sneaked into its systems earlier this month and made off with confidential client data.…
Shai-Hulud worm returns, belches secrets to 25K GitHub repos
A self-propagating malware targeting node package managers (npm) is back for a second round, according to Wiz researchers who say that more than 25,000 developers had their secrets compromised within three days.…
FCC guts post-Salt Typhoon telco rules despite ongoing espionage risk
The Federal Communications Commission (FCC) has scrapped a set of telecom cybersecurity rules introduced after the Salt Typhoon espionage campaign, reversing course on measures designed to stop state-backed snoops from slipping back into America's networks.…
CISA orders feds to patch Oracle Identity Manager zero-day after signs of abuse
CISA has ordered US federal agencies to patch against an actively exploited Oracle Identity Manager (OIM) flaw within three weeks – a scramble made more urgent by evidence that attackers may have been abusing the bug months before a fix was released.…
Championing cyber security: the national UK cyber team's journey at the European Cyber Security Challenge
Partner Content From 6th to 10th October 2025, ten exceptional cyber enthusiasts proudly flew the flag for the United Kingdom in the European Cyber Security Challenge (ECSC), held this year in the vibrant setting of Poland.…
Cryptology boffins’ association to re-run election after losing encryption key needed to count votes
The International Association for Cryptologic Research will run a second election for new board members and other officers, after it was unable to complete its first poll due to a lost encryption key.…
70-hour work weeks no longer enough for Infosys founder, who praises China’s 996 culture
Asia In Brief Infosys co-founder Narayana Murthy has suggested Indian citizens should work even longer, suggesting his previous target of 70-hour weeks could climb to 72.…
Weaponized file name flaw makes updating glob an urgent job
Infosec In Brief Researchers have urged users of the glob file pattern matching library to update their installations, after discovery of a years-old remote code execution flaw in the tool's CLI.…
ShinyHunters 'does not like Salesforce at all,' claims the crew accessed Gainsight 3 months ago
EXCLUSIVE ShinyHunters has claimed responsibility for the Gainsight breach that allowed the data thieves to snarf data from hundreds more Salesforce customers.…
Four charged over alleged plot to smuggle Nvidia AI chips into China
Four people have been charged in the US with plotting to funnel restricted Nvidia AI chips into China, allegedly relying on shell firms, fake invoices, and covert routing to slip cutting-edge GPUs past American export controls.…
Russia-linked crooks bought a bank for Christmas to launder cyber loot
On Christmas Day 2024, a Russian-linked laundering network bought itself a very special present: a controlling stake in a Kyrgyzstan bank, later used to wash cybercrime profits and funnel money into Moscow's war machine, according to the UK's National Crime Agency (NCA).…
ZTE Launches ZXCSec MAF security solution for large model
Partner Content At MWC Shanghai 2025, ZTE has officially launched its ZXCSec MAF product, a dedicated application-layer security protection device specifically designed for large model services.…
Google links Android’s Quick Share to Apple’s AirDrop, without Cupertino’s help
Google has linked Android’s wireless peer-to-peer file sharing tool Quick Share to Apple’s equivalent AirDrop.…
SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere
The US Securities and Exchange Commission (SEC) has abandoned the lawsuit it pursued against SolarWinds and its chief infosec officer for misleading investors about security practices that led to the 2020 SUNBURST attack.…
Salesforce-linked data breach claims 200+ victims, has ShinyHunters’ fingerprints all over it
Salesforce has disclosed another third-party breach in which criminals - likely ShinyHunters (again) - may have accessed hundreds of its customers' data.…
LLM-generated malware is improving, but don't expect autonomous attacks tomorrow
LLMs are getting better at writing malware - but they're still not ready for prime time.…
Fired techie admits sabotaging ex-employer, causing $862K in damage
An Ohio IT contractor has pleaded guilty to breaking into his former employer's systems and causing nearly $1 million worth of damage after being fired.…
TP-Link accuses rival Netgear of 'smear campaign' over alleged China ties
TP-Link is suing rival networking vendor Netgear, alleging that the rival and its CEO carried out a smear campaign by falsely suggesting, it says, that the biz had been infiltrated by the Chinese government.…
Education boards left gates wide open for PowerSchool mega-breach, say watchdogs
Canadian privacy watchdogs say that school boards must shoulder part of the blame for the PowerSchool mega-breach, not just the ed-tech giant that lost control of millions of student and staff records.…