Cybersecurity
Ongoing coverage on Cybersecurity.
Latest coverage
Evening Safety Dance
A severe Linux security threat has emerged, catching many by surprise. Separately, the FBI has stated that China's hacker-for-hire operations are 'out of control,' indicating a significant global cybersecurity concern.
Morning Safety Dance
Krebs on Security reports that an anti-DDoS firm allegedly launched attacks against Brazilian internet service providers. The article details how the firm may have used these attacks to promote its own services.
Morning Safety Dance
A DOGE affiliate is reportedly in charge of the US Government's ID platform, raising concerns about data security. Additionally, CISA has flagged a data-theft bug in an NSA-developed networking tool used for operational technology.
State cybersecurity agencies around the world are advising extra care over home routers as they could be used in…
Global cybersecurity agencies, including CISA and NCSC-UK, are warning users about the risks associated with compromised home routers. These devices are increasingly being used as nodes in large-scale covert networks by China-nexus cyber actors. The FCC has also banned certain foreign-made routers, though this does not address existing compromised devices.
Morning Safety Dance
Pitney Bowes has become the latest victim of a supply-chain attack attributed to the group ShinyHunters. The ongoing attack targets security and development tools, indicating a broader trend of breaches affecting software infrastructure.
Morning Safety Dance
Discord users reportedly gained unauthorized access to internal documents belonging to AI company Anthropic. The incident involved the theft of information related to Anthropic's 'Mythos' project, raising cybersecurity concerns.
Saturday Safety Dance
ADT, America's largest home security brand, has confirmed a data breach linked to the ShinyHunters group. Separately, a crime crew is impersonating a help desk and abusing Microsoft Teams chats. These incidents highlight ongoing cybersecurity threats.
Morning Safety Dance
Newly deciphered sabotage malware may have targeted Iran's nuclear program and predates Stuxnet. A separate mention indicates a biobank data leak was caused by 'a few bad apples'.
Morning Safety Dance
The article touches on multiple cybersecurity topics, including the dual attack surfaces of hybrid clouds and the NCSC's recommendation for passkeys as a default authentication standard. It also briefly mentions a cryptocurrency scam that targeted ships.
France's national agency for managing IDs and passports suffered a data breach last week
France Titres, the French agency responsible for national IDs and passports, confirmed a data breach detected on April 15. A hacker claimed responsibility and is attempting to sell up to 19 million records, including names, emails, dates of birth, and phone numbers. While direct portal access was not compromised, the exposed data could be used for phishing attacks.
Apple rolls out iOS 26.4.2 to fix a flaw that allowed the FBI to access push notifications
Apple has released iOS 26.4.2 to address a security flaw that allowed law enforcement, including the FBI, to access deleted push notifications on iPhones and iPads. The update improves data redaction to prevent notifications marked for deletion from being unexpectedly retained. This fix comes after reports that the FBI used a tool to access Signal notification data stored locally, even after deletion.
Someone has apparently snaffled up 31 WordPress plugins and wedged a backdoor in each one
An individual reportedly purchased 31 WordPress plugins and inserted backdoors into each one, with the malicious code being activated around April 5, 2026. The incident highlights a vulnerability in WordPress.org's system, which lacks a mechanism to flag or review plugin ownership transfers, potentially leaving users unaware of compromised software.
Morning Safety Dance
France's national identity agency is investigating a reported data breach affecting approximately 19 million records. The incident raises concerns about the security of sensitive personal information held by the agency.
'Defenders finally have a chance to win, decisively': Firefox CTO raves about Claude Mythos' bug hunting capabilities after it finds 271 vulnerabilities
Mozilla partnered with Anthropic to use an early version of Claude Mythos, an AI tool, in its bug hunting efforts for Firefox. The AI successfully identified 271 vulnerabilities, with Firefox CTO Bobby Holley stating that this technology gives defenders a significant advantage in finding zero-day exploits before they can be exploited.
Anthropic is investigating 'unauthorized access' of its Mythos cybersecurity tool
Anthropic is investigating reports of unauthorized access to its Claude Mythos cybersecurity tool, which was accessed through a third-party contractor portal. The company stated that the access occurred within a vendor environment and that they are looking into the claims. Claude Mythos, part of Project Glasswing, was in a limited preview with companies like Amazon, Microsoft, and Apple, and has been noted for its ability to find security flaws.
Mozilla using Claude Mythos AI Preview to help fix major security issues in Firefox
Mozilla is utilizing Anthropic's Claude Mythos AI Preview, part of Project Glasswing, to identify and fix security vulnerabilities in Firefox. The AI has helped address 271 issues in the recent Firefox 150 release, though Mozilla notes it has not discovered vulnerabilities beyond the capabilities of elite human researchers.
Evening Safety Dance
A cyber official from the UK stated that the AI model Claude could have a net positive impact on the country. The article discusses the potential benefits and implications of advanced AI technologies within the UK.
Mozilla says it patched 271 Firefox vulnerabilities thanks to Anthropic's Claude Mythos
Mozilla has reported that its team successfully identified and patched 271 vulnerabilities in the Firefox browser using Anthropic's Claude Mythos Preview AI model. The foundation stated that the AI has proven capable of finding all categories and complexities of vulnerabilities that humans can discover. This initiative highlights a positive application of AI in enhancing cybersecurity.
Cybersecurity expert turns cybercriminal, pleading guilty to 'conspiracy to deploy ransomware'
Three former cybersecurity professionals have pleaded guilty to deploying Blackcat/ALPHV ransomware, extorting victims for over $1.2 million in Bitcoin. One individual, while working as a ransomware negotiator, leaked confidential victim information to the attackers. The BlackCat/ALPHV group is reportedly defunct due to increased law enforcement efforts.
Anthropic had a 'productive and constructive' meeting with White House officials after the preview release of its new cybersecurity-challenging AI model
Anthropic CEO Dario Amodei met with White House officials, including Secretary Scott Bessent and Chief of Staff Susie Wiles, following the preview release of its new AI model, Claude Mythos. The meeting was described as 'productive and constructive,' focusing on collaboration and safety protocols for AI development. This comes after a period of tension between Anthropic and the US government regarding AI safeguards.