Cybersecurity
Ongoing coverage on Cybersecurity.
Latest coverage
Daybreak is OpenAI's response to Anthropic's Claude Mythos
OpenAI has launched a new cybersecurity initiative named Daybreak. This initiative is powered by their advanced models GPT-5.5 and Codex Security, positioning it as a response to Anthropic's Claude Mythos.
Evening Safety Dance
This article discusses recent incidents of data theft, including "cookie thieves" stealing development secrets and the potential for hackers to breach encrypted USB drives. It highlights the ongoing challenges in cybersecurity and data protection.
A killswitch has been pitched for the Linux kernel that could shut down vulnerable functions while users wait for…
Nvidia staffer Sasha Levin has proposed a 'killswitch' for the Linux kernel that would allow privileged operators to temporarily disable vulnerable functions while a permanent fix is developed. This feature aims to mitigate security risks during the window between a vulnerability's discovery and the release of a patch, though some users express concerns about its potential misuse.
Morning Safety Dance
Venmo is addressing privacy concerns that have persisted for eight years, following reports of 'alarming' security failures. Separately, an AI tool poisoning incident has exposed a significant flaw in enterprise agent security, as detailed by VentureBeat.
Sunday Safety Dance
This article touches on several technology-related security topics, including the potential for fiber optic cables to be used for eavesdropping and the hacking of police robot dogs. It also mentions 'reservation hijacking' scams.
Banned drones and routers in the US will still get critical updates until 2029
The Federal Communications Commission has extended the deadline for critical software and firmware updates for banned drones and routers in the US until January 2029. This decision allows these devices to continue receiving necessary security patches for a limited time.
Evening Safety Dance
A new type of malware has been identified that actively removes competing malware from infected systems before establishing its own control. This aggressive behavior highlights an evolving landscape in cyber threats.
Rockstar ransom hackers claim to have stolen the data of 280 million teachers, school staff, and students in Canvas…
Instructure, the company behind the Canvas learning management system, has experienced a significant data breach. The ransomware group ShinyHunters has claimed responsibility, alleging the theft of data belonging to 280 million teachers, school staff, and students, including names, email addresses, and private messages. The group had previously targeted Rockstar Games and Nvidia.
Morning Safety Dance
The Canvas learning management system, developed by Instructure, has been impacted by a cyberattack. Reports indicate the incident involves a new form of ransomware, with Microsoft also issuing statements regarding password security in relation to such threats.
NEAR Protocol Adopts Post-Quantum Cryptography with FIPS
NEAR Protocol has integrated FIPS-204 post-quantum cryptography, enabling secure key rotation in a single transaction and positioning itself as a leader in quantum-safe blockchain technology. This upgrade allows NEAR accounts to interact across over 35 external chains, including Bitcoin, Ethereum, and Solana, with enhanced security. The announcement led to a 14.25% surge in NEAR's token price.
Instructure hackers claim they stole data from nearly 9,000 schools
Instructure, the company behind the Canvas learning management system, has been targeted by hackers who claim to have stolen data from nearly 9,000 schools. The attackers also locked students out of Canvas and set a negotiation deadline of May 12.
Microsoft reiterates that it's totally fine with Edge storing passwords in cleartext, despite security…
Microsoft has confirmed that Microsoft Edge stores saved passwords in cleartext within the browser's memory, a design choice intended to balance performance and usability. While Microsoft states this requires the device to already be compromised, security researchers highlight that this vulnerability could allow attackers with admin rights to easily access sensitive credentials, especially in shared environments. The company recommends users maintain up-to-date security software.
Morning Safety Dance
Microsoft's Phone Link app is being exploited by Trojan malware to steal user passwords. Additionally, Microsoft Teams is implementing new features to prevent brand impersonation calls. Separately, a critical vulnerability in cPanel is reportedly affecting millions of systems.
Microsoft Edge saves passwords in cleartext 'by design' and researchers argue 'this turns into a credential harvest' on shared PCs
Cybersecurity researcher Tom Jøran Sønstebyseter Rønning discovered that Microsoft Edge saves passwords in memory in cleartext, a behavior Microsoft has stated is "by design." This method differs from other Chromium-based browsers like Chrome, which only decrypt credentials when needed. Critics argue this practice creates a significant security risk, especially on shared PCs, potentially leading to credential harvesting.
Simple Ways to Secure Your Smart Home Devices in 2026
This guide outlines simple steps to enhance the security of smart home devices and networks. Key recommendations include using strong, unique passwords, regularly updating device firmware and software, securing the home Wi-Fi network with WPA3 encryption, and setting up a separate guest network for smart devices. It also emphasizes reviewing privacy settings, using encrypted tools, monitoring devices for suspicious behavior, and educating household members on good digital habits to mitigate risks.
The same group that tried to ransom Rockstar over GTA 6 says it has breached user data from Armenian GeForce Now servers
The hacking group ShinyHunters claims to have breached Nvidia's GeForce Now servers, potentially exposing millions of user records including names, emails, and dates of birth. Nvidia stated that the issue was limited to systems operated by a third-party partner in Armenia and that impacted users would be notified. ShinyHunters is the same group that previously attempted to ransom Rockstar Games over data stolen from Grand Theft Auto 6.
Morning Safety Dance
CISA has issued a warning regarding a critical Linux kernel flaw, dubbed 'Copy Fail,' which is being actively exploited. This vulnerability allows attackers to gain root access on major Linux distributions, posing a significant cybersecurity risk.
Ahmad Dhani Datangi Polisi setelah Instagramnya Hilang
Musician Ahmad Dhani visited the police after his Instagram account disappeared, suspecting a targeted takedown rather than mass reporting. He consulted with cyber experts and reported the issue to Instagram, believing a powerful entity was involved. Dhani suggested his recent posts, including one featuring his daughter Shafeea, might have been perceived as threatening by some, leading to an attempt to silence him.
Saturday Safety Dance
Microsoft and CISA have issued a warning regarding a critical vulnerability affecting millions of systems running major Linux distributions. The article also briefly mentions an FCC vote to ban Chinese labs from certifying electronics sold in the US due to national security concerns.
Canonical, the company that makes Ubuntu Linux, says its web infrastructure is under a 'sustained, cross-border…
Canonical, the company behind Ubuntu Linux, is experiencing a sustained, cross-border cyberattack that has impacted its website, blog, and potentially its software repositories. The company is working to address the issue and provide updates through official channels. Reports suggest a hacktivist group may have claimed responsibility for the attack.