-
91. Extortion crews are visiting law firms pretending to be tech support, FBI warns (theregister.com) ▲ -
92. Malware dev tries to steal Claude users' secrets, writes npm slop, leaks own GitHub private token (theregister.com) ▲ -
93. Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries (theregister.com) ▲ -
94. Hackers are now using ChatGPT share links to deliver malware (neowin.net) ▲ -
95. Federal audit reveals NIST’s NVD is plagued by poor planning and duplication (cyberscoop.com) ▲ -
96. No fix yet for critical RCE bug in open-source Git service Gogs - exploit module is out (theregister.com) ▲ -
97. Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops (theregister.com) ▲ -
98. Microsoft tests the 15-character limit of Windows Server admins' patience (theregister.com) ▲ -
99. Carnival confirms ShinyHunters cruised off with 6M customer records after April breach (theregister.com) ▲ -
100. UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace (cyberscoop.com) ▲ -
101. Charter Communications confirms data breach with 40mn records (techradar.com) ▲ -
102. Perfect randomness realized for the first time (phys.org) ▲ -
103. Microsoft SharePoint Has a New RCE Flaw (securityaffairs.com) ▲ -
104. Bosses blinded by confidence about shadow AI use by workers (theregister.com) ▲ -
105. CrowdStrike, Google shatter Glassworm botnet (theregister.com) ▲ -
106. BadHost vulnerability bypasses authentication on AI infrastructure (risky.biz) ▲ -
107. Northern Mariana Islands government email accounts hit by cyberattack (dysruptionhub.com) ▲ -
108. Investigating unauthorized access to GitHub-owned repositories (github.blog) ▲ -
109. Leaked Documents Reveal Russian ‘Cognitive Strikes’ Against the West — Including Islamophobic ‘Pig Head’ Attacks in Paris (occrp.org) ▲ -
110. Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects (securityweek.com) ▲ -
111. Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks (krebsonsecurity.com) ▲ -
112. Scammers are abusing an internal Microsoft account to send spam links (techcrunch.com) ▲ -
113. Domain-Camouflaged Injection Attacks Evade Detection in Multi-Agent LLM Systems (arxiv.org) ▲ -
114. Trump Mobile exposed customers' personal data (techcrunch.com) ▲ -
115. Ordinary WiFi can now identify people with near perfect accuracy (sciencedaily.com) ▲ -
116. Inside Lazarus: How North Korea uses AI to industrialize attacks on developers (expel.com) ▲ -
117. Megalodon: Mass GitHub Repo Backdooring via CI Workflows (safedep.io) ▲ -
118. Critical Cisco Secure Workload Vulnerability Allows Unauthenticated Site Admin Access (truesec.com) ▲ -
119. Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada (krebsonsecurity.com) ▲ -
120. art-template npm Hijack Delivers iOS Browser Exploit Kit (safedep.io) ▲