Tag Directory / INFOSEC     showing 181–200 of 308   RSS



Apple issues emergency update to fix zero-day exploit in iPhone and macOS

techspot - According to Apple, the issue lies within Image I/O, the company's framework for handling a wide range of image file formats. If a device processes a specially crafted image, it can trigger memory corruption. While Apple has not disclosed what specific ou…

#infosec #apple #ios #security

6 months / bgr

6 months / techspot


Back to Top / Thursday, August 21, 2025, 9:20 am / permalink 12787 / 4 stories in 6 months


Perplexity's Comet browser naively processed pages with evil instructions

Thomas Claburn / theregister - Rival Brave flags prompt injection vulnerability, now patched To the surprise of no one in the security industry, processing untrusted, unvalidated input is a bad idea.…

#cybersecurity #software #infosec #browsers

Back to Top / Wednesday, August 20, 2025, 3:20 pm / permalink 12742 / 2 stories in 6 months


Microsoft’s August 2025 security updates are breaking recovery tools on Windows 10 and Windows 11 PCs

tomshardware - Microsoft admits its latest security updates break Windows recovery tools like "Reset this PC" and "Fix problems using Windows Update" on multiple Windows versions.

#software #infosec #windows #microsoft

6 months / tomshardware


Back to Top / Wednesday, August 20, 2025, 5:20 am / permalink 12692 / 8 stories in 6 months


PyPI now blocks domain resurrection attacks used for hijacking accounts

Bill Toulas / bleepingcomputer - The Python Package Index (PyPI) has introduced new protections against domain resurrection attacks that enable hijacking accounts through password resets. [...]

#cybersecurity #opensource #infosec #python

Back to Top / Tuesday, August 19, 2025, 4:21 pm / permalink 12653 / 3 stories in 6 months


Cisco's Secure Firewall Management Center now not-so secure, springs a CVSS 10 RCE hole

Jessica Lyons / theregister - Switchzilla's summer of perfect 10s Cisco has issued a patch for a maximum-severity bug in its Secure Firewall Management Center (FMC) software that could allow an unauthenticated, remote attacker to inject arbitrary shell commands on vulnerable systems.…

#cybersecurity #infosec

Back to Top / Friday, August 15, 2025, 1:21 pm / permalink 12419 / 2 stories in 6 months


Fortinet warns of FortiSIEM pre-auth RCE flaw with exploit in the wild

Bill Toulas / bleepingcomputer - Fortinet is warning about a remote unauthenticated command injection flaw in FortiSIEM that has in-the-wild exploit code, making it critical for admins to apply the latest security updates. [...]

#cybersecurity #software #enterprise #infosec

Back to Top / Wednesday, August 13, 2025, 4:21 pm / permalink 12262 / 3 stories in 6 months


Alarm raised over 'high-severity' vulnerabilities in Matrix messaging protocol

therecord - An urgent patch has been released for two bugs affecting the Matrix messaging protocol used by some governments for secure communications.

#cybersecurity #software #infosec

6 months / therecord


Back to Top / Wednesday, August 13, 2025, 8:21 am / permalink 12206 / 2 stories in 6 months


Details emerge on WinRAR zero-day attacks that infected PCs with malware

Bill Toulas / bleepingcomputer - Researchers have released a report detailing how a recent WinRAR path traversal vulnerability tracked as CVE-2025-8088 was exploited in zero-day attacks by the Russian 'RomCom' hacking group to drop different malware payloads. [...]

#cybersecurity #software #infosec #security

6 months / bgr

6 months / therecord


Back to Top / Monday, August 11, 2025, 3:21 pm / permalink 12079 / 6 stories in 6 months


Hyundai tells Ioniq 5 owners it will fix keyless security flaw – for a $65 "contribution"

techspot - Kia, Hyundai, and Genesis EVs have been targeted by thieves in the UK and other locations in recent times who use a handheld emulation device disguised to look like a Game Boy. It features radio transmission components that crack the wireless protocols us…

#cybersecurity #infosec #cars #security

6 months / techspot


Back to Top / Monday, August 11, 2025, 11:20 am / permalink 12057 / 2 stories in 6 months


Library of Congress explains how parts of US Constitution vanished from its website

Dominic-Madori Davis, Zack Whittaker / techcrunch - The U.S. congressional agency confirmed to TechCrunch that the removal of key sections of the Constitution from its website were removed in error. The full text has now been reinstated.

#infosec #government #internet #law

Back to Top / Thursday, August 7, 2025, 12:21 pm / permalink 11847 / 2 stories in 6 months


Microsoft warns of serious vulnerability in hybrid Exchange deployments

Sofia Elizabella Wyciślik-Wilson / betanews - Microsoft has issued a warning about a high-severity vulnerability in hybrid Microsoft Exchange Server deployments. Tracked as CVE-2025-53786, the vulnerability could allow for privilege escalation by cyber threat actors with administrative access to an o…

#cybersecurity #infosec #microsoft

6 months / therecord


Back to Top / Thursday, August 7, 2025, 8:21 am / permalink 11829 / 6 stories in 6 months


United Airlines IT Glitch Resolved, Flights Resume After Grounding Issues

United Airlines experienced a disruptive IT malfunction that forced the grounding of flights across major US airports, prompting widespread travel delays. After persistent technical difficulties, the airline resolved the issue and resumed its flight operations, restoring normal service. The incident highlighted vulnerabilities in the carrier’s system management.

#infosec #aviation #travel

Back to Top / Wednesday, August 6, 2025, 11:20 pm / permalink 11810 / 0 stories in 7 months


There's a Tea app for men, and it also has security problems

Anna Washenko / engadget - Tea bills itself as a safety dating app for women, allowing users to anonymously share details about men they have met. A new app called TeaOnHer has emerged that attempts to flip the script, with men sharing information about women they date. And while T…

#cybersecurity #infosec #apps #security

Back to Top / Wednesday, August 6, 2025, 6:20 pm / permalink 11785 / 2 stories in 7 months


Call Of Duty Has New Security Measures, Adding Secure-Boot Requirement

S.E. Doster / gamespot - Call of Duty's battle against hackers continues, and Activision has announced some major updates to the game's Ricochet anti-cheat for Season 5 and beyond. The publisher also confirmed legal action taken against several cheat makers.Season 5 of Black Ops …

#gaming #infosec

7 months / tomshardware


Back to Top / Wednesday, August 6, 2025, 1:20 pm / permalink 11765 / 4 stories in 7 months


Hackers Used An Infected Calendar Invite To Hack Gemini And Take Control Of A Smart Home

bgr - The dangers of AI are becoming increasingly apparent, as hackers found a way to use Google's Gemini chatbot to take over a stranger's smart home devices.

#cybersecurity #infosec #cybercrime #hack

7 months / bgr


Back to Top / Wednesday, August 6, 2025, 1:20 pm / permalink 11762 / 4 stories in 7 months


Microsoft’s ‘Agentic Web’ Ambition Hit by Embarrassing Security Flaw

Markus Kasanmascheff / winbuzzer - A critical security flaw in Microsoft's new NLWeb protocol raises questions about its 'agentic web' strategy, despite a quick patch from the company.The post Microsoft’s ‘Agentic Web’ Ambition Hit by Embarrassing Security Flaw appeared first on WinBuzzer.

#cybersecurity #infosec #microsoft #security

Back to Top / Wednesday, August 6, 2025, 10:20 am / permalink 11731 / 3 stories in 7 months


UK MoD taps Australian cybersecurity startup Castlepoint after Afghan data breach

Lucy Adams / tech - Britain's Ministry of Defence (MoD) has selected Australian firm Castlepoint Systems to provide services for automating data classification and reducing the risk of human error. The company is now hea...

#cybersecurity #infosec #defensetech #uk

Back to Top / Wednesday, August 6, 2025, 7:21 am / permalink 11716 / 2 stories in 7 months


Nvidia rejects US demand for backdoors in AI chips

Dominic Preston / theverge - Nvidia’s chief security officer has published a blog post insisting that its GPUs “do not and should not have kill switches and backdoors.” It comes amid pressure from both sides of the Pacific, with some US lawmakers pushing Nvidia to grant the governmen…

#infosec #nvidia #gpu #security

7 months / tomshardware

7 months / techspot


Back to Top / Wednesday, August 6, 2025, 7:21 am / permalink 11713 / 11 stories in 7 months


Dell fixed security chip vulnerability that left millions open to attack

Brad Bennett / mobilesyrup - Tens of millions of Dell laptops were recently discovered to have a vulnerability that could have allowed hackers to steal sensitive data from users and monitor some of their computer activities. Dell validated this security analysis in June, and it appea…

#cybersecurity #infosec

Back to Top / Tuesday, August 5, 2025, 4:20 pm / permalink 11679 / 2 stories in 7 months


NVIDIA Patches Critical Triton Server Vulnerabilities Enabling Full AI System Takeover

Markus Kasanmascheff / winbuzzer - NVIDIA has patched critical RCE flaws in its Triton Inference Server after Wiz Research found an exploit chain allowing full AI system takeover. Update now.The post NVIDIA Patches Critical Triton Server Vulnerabilities Enabling Full AI System Takeover app…

#cybersecurity #infosec #nvidia #gpu

Back to Top / Tuesday, August 5, 2025, 12:21 pm / permalink 11645 / 2 stories in 7 months


Back to Top


INFOSEC Heatmap


90 days, weeks are vertical, left is older; hover for info, click to see that day's coverage.



More Top Stories...


Pentagon labels Anthropic a supply‑chain risk; company vows legal fight

The Pentagon has designated Anthropic and its products as a “supply‑chain risk,” prompting the company to announce a court challenge. Experts warn the move could chill collaboration and talent flows into AI, while Anthropic insists it will contest the determination to protect its operations and customers. More...


SoftBank seeks massive $40B loan to back OpenAI investment, courting big risk

SoftBank is reportedly seeking up to a $40 billion loan to finance its planned stake in OpenAI, an audacious use of leverage to double down on the AI boom. The move would be one of the largest single‑company financing gambits in recent memory, raising questions about balance‑sheet strain versus potential upside. More...


Oracle and OpenAI scrap Texas data-center expansion; Meta eyes the spare capacity

Oracle and OpenAI have abandoned plans to expand a flagship Texas data center, leaving substantial compute capacity up for grabs. Nvidia reportedly brokered interest from Meta to take the unused slots as OpenAI downscales that particular buildout, a move that rattled markets and highlights shifting demand for large-scale on-prem AI infrastructure. More...


OpenAI launches Codex Security agent to automatically detect software vulnerabilities

OpenAI rolled out Codex Security, an AI agent that scans codebases to find complex vulnerabilities, suggests actionable fixes, and uses sandbox testing to limit false positives. The tool has already flagged issues in major projects and aims to compete with traditional application security tooling by automating deep, contextual code review. More...


Google releases Workspace CLI enabling AI agents to access Gmail, Drive, Calendar

Google has shipped an open-source Workspace CLI that gives AI agents like OpenClaw programmatic access to Gmail, Drive, Calendar and other Workspace services via a built-in MCP server. The tool standardizes agent integration, making it easier — and slightly creepier — for automated assistants to act on users’ behalf across core productivity apps. More...



NorthFeed Inc.

Disclaimer: The information provided on this website is intended for general informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the content. Users are encouraged to verify all details independently. We accept no liability for errors, omissions, or any decisions made based on this information.