Cybersecurity
204 articles RSS
CISA, FBI, and NSA Warn Iran-Linked Hackers Are Breaching US Water and Energy Providers Through Exposed Industrial Controllers
A joint US advisory says Iran-linked hackers are exploiting exposed industrial controllers at water and energy providers, and disabled shutdown alarms at one breached facility.
UC San Diego Researchers Find Bluetooth Flaw in Dealer-Installed KARR and SWDS Car Alarms, Exposing 2.2 Million Vehicles
A shared Bluetooth key in dealer-installed KARR/SWDS anti-theft devices lets nearby attackers unlock or immobilize at least 2.2 million cars, UC San Diego researchers found.
Paidwork Breach Exposes Banking and Personal Data of More Than 23 Million Microtask Platform Users
A breach at gig-work platform Paidwork exposed names, bank details, and bcrypt-hashed passwords for over 23 million users, per Have I Been Pwned.
16-Year-Old Linux KVM Flaw 'Januscape' Lets Guest VMs Escape to the Host on Intel and AMD Systems
A 16-year-old use-after-free bug in Linux's KVM hypervisor, dubbed Januscape and rated CVSS 8.8, lets malicious VMs escape to the host on both Intel and AMD systems; OVHcloud patched roughly a million VMs across its fleet in an 11-day campaign.
GitHub Cuts Public Bug Bounty Payouts by Half, Moves Top Rewards Behind a New Invite-Only VIP Tier
GitHub is halving public bug bounty payouts starting July 27, reserving its largest rewards for a new invite-only VIP tier as it fights a flood of low-quality, AI-generated reports.
Linux Foundation Launches Akrites, an Industry Alliance to Patch Open Source Flaws Before AI Turns Them Into Exploits
The Linux Foundation and roughly 20 companies including AWS, Anthropic, Google, IBM and major banks launched Akrites, a coordinated incident-response alliance for open source software, after finding fewer than 5% of recently surfaced vulnerabilities have been patched.
Hugging Face Says an Autonomous AI Agent Breached Its Systems, Executing More Than 17,000 Actions Over a Weekend
Hugging Face disclosed that an autonomous AI agent system breached its data-processing pipeline over a weekend, harvesting credentials before defenders turned to a self-hosted open-weight model to analyze the attack.
42 Attorneys General Win $18 Million From 23andMe Over Genetic Data Breach as Bankruptcy Court Blocks California's Damages Claim
A 42-attorney-general coalition settled bankruptcy claims against 23andMe for $18 million over the 2023 breach of 6.9 million genetic profiles, days after a court barred California from separately pursuing damages.
GitHub Makes a Three-Day Package Cooldown the Default for Dependabot Version Updates, Citing Supply-Chain Attacks Through New Releases
Dependabot now waits three days before proposing new dependency versions by default. GitHub says the delay keeps freshly compromised releases out of update pull requests; security updates are exempt and repositories can opt out.
WordPress Forces Automatic Updates to Patch wp2shell, a Pre-Authentication RCE Chain in Core, as Public Exploits Circulate
WordPress shipped 7.0.2 and 6.9.5 on July 17 and enabled forced auto-updates to fix wp2shell, a two-CVE chain allowing unauthenticated remote code execution in core, as public proof-of-concept exploits circulate.
Kaspersky Uncovers GoSerpent, a Go-Based Backdoor Spying on Southeast Asian Governments Since Late 2025
Kaspersky's GReAT team found a new Go-language RAT and toolkit hitting government and diplomatic targets in Southeast Asia, with a possible link to the TetrisPhantom espionage actor.
JetBrains Patches Critical Path-Traversal Flaw in IntelliJ IDEA, Five More Bugs Across TeamCity and YouTrack
JetBrains disclosed six vulnerabilities across IntelliJ IDEA, TeamCity, and YouTrack on July 16, led by a critical 9.8 CVSS path-traversal flaw in IntelliJ IDEA.