Cybersecurity
Ongoing coverage on Cybersecurity.
Latest coverage
Morning Safety Dance
Microsoft has released an emergency update for Windows 11 to address issues caused by a broken March preview update. The update also includes a fix for a poisoned web-code library that had millions of weekly downloads.
Web-code library with millions of weekly downloads poisoned by malicious release: 'This is unironically a malware…
The popular JavaScript library Axios was targeted in a sophisticated supply chain attack, with malicious versions distributing a remote access trojan. Attackers, identified as a North Korea-nexus threat actor, pre-built payloads and poisoned release branches, with malware calling home within seconds of installation. While malicious versions were quickly removed, cybersecurity firms warn of potential compromise and recommend thorough security assessments.
Iran threatens imminent attacks on US tech companies in the Middle East
Iran's Islamic Revolutionary Guard Corps has threatened imminent attacks on US tech companies operating in the Middle East, including Apple, Google, Meta, NVIDIA, Microsoft, and others. The IRGC warned employees to leave their workplaces immediately and stated that these companies are legitimate targets in response to US actions. This threat follows recent drone strikes on Amazon data centers in Bahrain and the UAE.
Morning Safety Dance
This article discusses phone security in 2026, focusing on protection against warrantless searches. It also touches upon cyber threats, mentioning Iran's offensive actions against the US and Israel.
Evening Safety Dance
OpenAI has addressed a DNS data smuggling vulnerability within its ChatGPT service. The flaw, reported by The Register, allowed for potential data exfiltration through DNS queries.
'The most boring protocol on the internet is also, quietly, one of the most abusable': Doom has been broken down into 1,964 DNS text records and can be run via a PowerShell script
The classic game Doom has been successfully run by splitting its code into 1,964 DNS text records and reassembling them using a PowerShell script. This innovative method, developed by Adam Rice, highlights the potential for abuse within the DNS protocol, which was not designed for file storage. The project demonstrates how even seemingly mundane internet protocols can be creatively exploited.
Morning Safety Dance
The European Commission has admitted to a breach of its public web systems, with a security contractor reporting issues with the support crew. The article also touches upon a US router ban being characterized as industrial policy rather than a measure for improved security.
Kash Patel's personal email account was accessed by hackers linked to Iran
A hacking group known as Handala, believed to be affiliated with the Iranian government, has gained access to FBI Director Kash Patel's personal email account. The group published some of the stolen content online, which the FBI has confirmed is historical and does not involve government information. The FBI is offering a reward for information on the hackers.
European Commission confirms data breach
The European Commission has confirmed a cyber attack on its cloud infrastructure, resulting in a data breach affecting its web presence on the Europea.eu platform. Threat actors reportedly accessed over 350GB of data, including employee information, via Amazon Web Services accounts. The investigation into the breach is ongoing, with the Commission notifying affected entities.
Duet Night Abyss preps a gun-toting bartender, a mech specialist, and the finale of its current story April 7
Duet Night Abyss is preparing for a major update on April 7th, introducing new characters like Camilla, a bartender with an assault rifle, and Su Yi, an aerial mech combatant. The update also marks the finale of the game's current story arc, Huaxu, with new regions and a giant sword mount. Developer Pan Studio has also apologized for recent backend attacks on their servers.
Engadget Podcast: Can Microsoft fix Windows 11 by dumping AI?
This podcast episode discusses Microsoft's potential shift in Windows 11 strategy, moving away from heavy AI integration like Copilot towards core features and customization. The hosts also touch upon OpenAI's Sora, Meta's legal troubles regarding child engagement and social media addiction, an iOS exploit, Epic Games layoffs, and the dissolution of the Afeela EV collaboration between Honda and Sony.
Google says it's preparing for the quantum apocalypse, when traditional encryption methods are broken by quantum computers, by 2029—which is much sooner than originally expected
Google is preparing for a 'quantum apocalypse' by 2029, a timeframe when quantum computers are expected to break current encryption methods. The company aims to migrate to post-quantum cryptography (PQC) and encourages the tech industry to follow suit. This proactive approach addresses concerns about data security in the face of advancing quantum computing capabilities.
Star Citizen Reveal MK2 Redesign of Its Most Classic Starter Ship
Cloud Imperium Games experienced a sophisticated cyberattack on January 21, 2026, leading to unauthorized access of some backup systems and limited personal user data. The company has since contained the breach, secured its systems, and assured players that there is no ongoing threat to the games or users.
Evening Safety Dance
The Register reports on potential security risks within documentation, specifically highlighting the danger of malicious instructions embedded within them for agents. This poses a threat in software development environments.
Morning Safety Dance
The Flipper Zero device, a popular tool for penetration testing, has received a new AI-powered companion app. This app introduces a natural language interface, aiming to make hacking tasks faster and more accessible.
Morning Safety Dance
A self-propagating malware has been discovered in a popular Python library, turning it into a backdoor that can compromise entire machines. The attack specifically targeted and wiped machines based in Iran, highlighting significant open-source software security vulnerabilities.
The FCC says foreign routers 'pose an unacceptable risk' and now require special approval to be sold in the US
The US Federal Communications Commission (FCC) has added foreign-produced consumer routers to a 'Covered List,' deeming them an unacceptable national security risk. New foreign routers will require special approval to be sold in the US, though existing devices are unaffected. This measure aims to mitigate risks such as network surveillance and cyberattacks, particularly those linked to state-sponsored actors.
Evening Safety Dance
Cisco Talos emphasizes the need for rapid patching in response to lightning-fast exploits, citing an incident where a cyberattack on an Iowa company led to widespread car failures. The article also notes that the messaging app Signal is being targeted.
Crunchyroll responds to data breach claims and promises to investigate the alleged cyber attack: "We are aware...…
Crunchyroll has acknowledged claims of a significant data breach affecting its ticketing system, with over 100 GB of personal customer data and credit card information allegedly exfiltrated. The company stated it is aware of the situation and is investigating with cybersecurity experts. The article also briefly mentions upcoming anime releases, including Chainsaw Man – The Movie: Reze Arc and the potential for Demon Slayer: Infinity Castle.
AI Yi-Yi!
TikTok has removed AI-generated videos depicting sexualized Black women following a BBC investigation. Separately, XDA reports that AI agents pose a security risk for home labs, with Tailscale releasing a fix for related vulnerabilities.