Cybersecurity
Ongoing coverage on Cybersecurity.
Latest coverage
CPUID's download page has been hacked, with its popular processor and PC info tools replaced with links to files…
CPUID's official download page for its popular CPU-Z and HWMonitor software has been compromised, with malicious files replacing legitimate downloads. The altered files, detected by antivirus software, are part of a sophisticated malware campaign that deeply trojanizes the executables and uses advanced evasion techniques. This incident follows a similar attack on FileZilla, suggesting a pattern by the same threat group.
Evening Safety Dance
China is intensifying its efforts to combat scams, though the focus appears to be on domestic issues rather than those affecting international entities like Americans. A significant data breach has exposed sensitive files belonging to the Los Angeles Police Department, which were stored within the city attorney's system.
Morning Metaverse
The United Kingdom has reportedly deployed military assets to protect undersea communication cables from potential Russian submarine threats. This action is a response to concerns over the security of critical infrastructure.
Morning Safety Dance
A zero-day vulnerability in Adobe Reader is being exploited through PDFs, allowing attackers to target users. Separately, Microsoft has stated that a reported glitch in Windows 11 and Windows 10 is considered 'by design' and will not be fixed.
Hackers claim they've breached a Chinese supercomputer and are demanding huge amounts of crypto for the data, but…
Hackers claiming to be 'FlamingChina' have alleged they stole 10 petabytes of data from China's National Supercomputing Center in Tianjin, including sensitive defense and science information. However, security researchers have expressed skepticism regarding the leak's legitimacy due to the unusual hacker moniker and the immense difficulty and cost of exfiltrating and storing such a massive amount of data.
Project Zomboid bans rogue mods deploying "malicious code" to players' PCs
The Indie Stone has banned a user and removed 14 malicious mods from the Steam Workshop that were creating harmful files outside the Project Zomboid directory. While the perpetrator has been banned and affected mods removed, players who downloaded them are advised to take security measures as the full scope of the exploit is still being determined. The malicious code was found in add-ons for the 'True Moozic' soundtrack expander and only affected Build 42 branches.
Morning Safety Dance
Iran-linked hackers are reportedly targeting US energy and water infrastructure, while NHS Scotland-linked domains have been compromised to push inappropriate content. These incidents highlight ongoing cybersecurity threats to critical infrastructure and digital domains.
Anthropic's new Claude Mythos AI model has apparently found thousands of vulnerabilities in 'every major operating system and every major web browser, along with a range of other important pieces of software'
Anthropic's new AI model, Claude Mythos, has identified thousands of high-severity vulnerabilities across major operating systems and web browsers. This discovery was made as part of Project Glasswing, an initiative involving major tech companies aimed at securing critical software. The AI's ability to detect these flaws quickly raises hopes for staying ahead of cyber threats.
Evening Safety Dance
Hackers can gain full account access by exploiting stolen session cookies for less than $1000 per month without triggering alerts. This method was used to compromise Microsoft Office tokens by hacking Russian routers.
Anthropic launches Project Glasswing, an effort to prevent AI cyberattacks with AI
Anthropic has launched Project Glasswing, an initiative aimed at securing critical software against AI-powered cyberattacks, in partnership with major tech companies like Amazon Web Services, Apple, Google, and Microsoft. The project will utilize Anthropic's Claude Mythos Preview model to identify vulnerabilities and develop defensive strategies against malicious AI use. This effort comes amidst broader concerns about AI's impact on cybersecurity and follows a previous incident where Anthropic's Claude was reportedly used in an attack against Mexican government agencies.
Evening Safety Dance
The FBI has issued a warning to users of both iPhone and Android devices, urging them not to install certain applications due to potential security risks. The advisory highlights the importance of app vetting for mobile device safety.
Morning Safety Dance
Hackers are reportedly distributing the leaked Claude AI code, bundling it with malware. This development follows Malwarebytes' confirmation of its no-logs VPN policy.
The MOP Up: The Quinfall loses some data after a global hosting glitch
The Quinfall has announced a limited amount of data loss due to a global technical issue affecting Amazon's Middle East servers. This disruption impacted the game's website and Twitch Drops system. Other smaller MMO news includes Warframe clarifying a data breach claim, The Finals bringing back its Bunny Hop mode, and updates for Wakfu, World of Tanks, Neverwinter, Runescape, Titan Quest II, and Synduality Echo of Ada.
Sunday Safety Dance
LinkedIn has been found to secretly search users' browsers for installed extensions, an issue that also appears to affect Google Chrome. This discovery raises cybersecurity concerns regarding user privacy and data access.
Hacking Is Personal - Free Online Browser Based HTML5 Game
Hacking Is Personal is a browser-based HTML5 game that simulates the life of a cybercriminal. Players can hack into procedurally generated victims, steal data, deploy viruses, and evade law enforcement. The game features an economy system, virus warfare, and a terminal interface, challenging players to build a digital criminal empire.
Alleged Warframe data breach "confirmed false" by Digital Extremes
Digital Extremes has confirmed that an alleged data breach affecting Warframe user information is false, stating the data was repackaged from a 2014 incident. Community director Megan Everett assured players that their online safety is a priority and encouraged the use of strong passwords and two-factor authentication. The recent launch delay of the Operation: Atramentum update was unrelated to the investigation.
Advanced Security Layers for Competitive Streamers and Tournament Broadcasters
Competitive streaming setups require robust cybersecurity measures due to the complexity of broadcasting software and the public-facing nature of content creation. Features like OS-level protection, encrypted storage, and virtualization-based security are crucial for protecting game accounts, creator platforms, and system stability during high-stakes events. Digital marketplaces also play a role in providing secure access to gaming software and tools for streamers.
Evening Safety Dance
New Rowhammer attacks have been discovered that grant complete control over machines equipped with Nvidia GPUs. These vulnerabilities exploit hardware weaknesses to compromise system security.
Morning Safety Dance
The FBI has declared a suspected Chinese hack of a US surveillance system a major cyber incident. Additionally, two significant security vulnerabilities have been discovered in Gigabyte's Control Center software.
Two high-rated motherboard security vulnerabilities have been identified in Gigabyte Control Center, so come update your…
Gigabyte has released advisories for two high-severity security vulnerabilities found in its Gigabyte Control Center (GCC) software. The vulnerabilities, CVE-2026-4415 and CVE-2026-4416, affect file handling and the EasyTune Engine Service respectively, potentially allowing for arbitrary code execution. Gigabyte strongly advises users to update to the latest version of GCC immediately to patch these issues.