Cybersecurity
Ongoing coverage on Cybersecurity.
Latest coverage
Your Nvidia GPU Needs A Driver Update Right Now, Unless You Enjoy Surprise Malware DLC
Nvidia has issued a critical security alert for its graphics card drivers on Windows and Linux, urging users to update to version 596.49 immediately. Hackers have exploited a vulnerability to gain unauthorized access to PCs, potentially stealing data or injecting malware. The company also introduced Auto Shader Compilation for RTX 50-series cards, designed to compile shaders in the background during idle times.
Another Steam Game Gets Removed Over Malware
Valve has removed the free-to-play survival-horror game Beyond the Dark from Steam after YouTuber Eric Parker exposed it for containing malware designed to steal player data. The game was previously uploaded under the name Rodent Race in December 2024, suggesting an attempt to bypass security checks. The FBI is investigating similar incidents of malware on Steam and has asked players who downloaded infected games between May 2024 and January 2026 to report it.
Morning Safety Dance
A significant cybersecurity vulnerability was discovered on GitHub, where sensitive digital keys were inadvertently left publicly accessible. This oversight, described as one of the worst leaks witnessed by a U.S. cybersecurity agency, could potentially expose user passwords and digital wallets.
Sony Is Looking To Keep More Single-Player Games On PlayStation & Faces Hacking Concerns
Sony is reportedly shifting its strategy to keep more single-player games exclusive to the PlayStation 5, reversing a trend of multi-platform releases for titles like Ghost of Yotei and the upcoming Saros. This move aims to strengthen the PlayStation brand and console sales, though it coincides with recent hacking concerns where user accounts are being compromised through social engineering tactics targeting PSN IDs and old transaction data.
PlayStation Account Hacking Problem Getting Worse, Sony Silent
PlayStation users are experiencing a worsening account hacking problem where attackers gain access to accounts, even with two-factor authentication and passkeys enabled, by contacting PlayStation Support. Victims like journalist Nicolas Lellouche and podcaster Colin Moriarty have had their accounts compromised using publicly available information, with Moriarty needing internal Sony connections to recover his. Sony has remained silent on the issue, prompting advice for users to separate public and private email addresses and avoid sharing their PlayStation account names online.
Evening Audio Files
Pro-Iran hackers have claimed responsibility for a recent Spotify outage, stating it was an act of revenge for US actions in their country. The incident highlights the growing intersection of geopolitical conflicts and cybersecurity threats targeting major online platforms.
Evening Safety Dance
This article provides a summary of cybersecurity vulnerabilities for the week of May 11, 2026, as reported by CISA. It highlights potential risks and offers information for maintaining digital safety.
Linux head says "AI tools are great" but they're making the security list "almost entirely unmanageable"
Linux head Linus Torvalds has stated that while AI tools are beneficial for finding bugs, they are making the security list for the Linux kernel unmanageable due to duplicated reports. He emphasized that AI-detected bugs are not secret and that developers should add value by reading existing documentation and creating patches rather than submitting redundant reports.
Security researchers, aided by Anthropic's Mythos, claim to have breached macOS
Security researchers, reportedly assisted by Anthropic's Mythos, have claimed a breach of macOS. Apple is reportedly taking these claims seriously.
Evening Safety Dance
A zero-day exploit has been discovered that completely bypasses Windows 11's default BitLocker encryption. Separately, security experts are skeptical of claims made by "Canvas" attackers that they deleted stolen student data.
The ChatGPT desktop app for Mac just got hit with a security breach
OpenAI has reported a security breach affecting its ChatGPT desktop application for Mac. The company stated that there is no evidence to suggest that user data was accessed during the incident.
Morning Safety Dance
The FBI has remotely reset thousands of home and small office routers, potentially including TP-Link devices, to address security vulnerabilities. Microsoft has also introduced Cloud-Initiated Driver Recovery for remote rollback of system drivers.
There's a devious hacking scheme that involves a hijacked Microsoft Teams account, a fake IT helpdesk, and a covert…
A new hacking scheme involves hijacked Microsoft Teams accounts impersonating IT helpdesks to trick users into downloading malicious files. This social engineering tactic uses a covert PowerShell command to unpack a WinPython environment, leading to the ModeloRAT malware infecting PCs without detection. The malware aims to embed itself in corporate environments to harvest data and establish connections to other devices.
Teaching software company strikes a deal with hackers to get customer data back, defying FBI guidance
Education technology company Instructure has reached an agreement with the hacker group ShinyHunters, who exfiltrated hundreds of gigabytes of data from its Canvas learning management system. The stolen data, potentially exposing the names, email addresses, and private messages of about 280 million users, has reportedly been returned and confirmed as destroyed. This action defies FBI guidance that advises against paying ransoms to cybercriminals.
Popular emulator Cemu was recently compromised with malware in Linux downloads
The popular Nintendo Wii U emulator Cemu was compromised, with malware found in certain Linux builds distributed via GitHub. The malicious code targeted user credentials and security keys, with a special payload for users in Israel. The developers have since removed the affected versions and are working to secure their distribution channels.
Evening Safety Dance
This article from Krebs on Security discusses the May 2026 Patch Tuesday, focusing on cybersecurity updates and patch management. It provides an analysis of the security landscape and the importance of timely software updates.
Android Show: I/O Edition Reveals Gemini Intelligence, Googlebook, And More Tech Updates
Google's Android Show: I/O Edition previewed Gemini Intelligence, an advanced generative AI set to launch on Samsung Galaxy and Google Pixel phones this summer. A new laptop, the Googlebook, designed for Gemini Intelligence, will also be released this fall. The event also detailed updates for Android Auto, including enhanced navigation and media playback features, alongside significant security enhancements for Android and Gemini.
Google announces upcoming security tools for Android, including enhanced protection against banking scam calls
Google announced new security tools for Android devices, including enhanced protection against fraudulent banking calls. The Live Threat Detection feature is also receiving a significant upgrade to bolster mobile security.
Morning Safety Dance
The company Canvas reported that data stolen in a hack affecting thousands of schools has been returned. Separately, Google discovered the first AI-developed zero-day exploit that bypasses two-factor authentication, utilizing self-morphing malware and Gemini technology.
A 'JobStealer' Trojan virus has popped up that attacks PCs via fake job interviews
A new Trojan virus named 'JobStealer' is targeting PCs by posing as a fake job interview invitation. Attackers use spoofed video conferencing apps and social media accounts to trick users into downloading malicious software that steals data, including cryptocurrency wallets. Versions for macOS, iOS, Android, and Linux are also noted, though not yet widely distributed.