Popular LiteLLM PyPI Package Backdoored To Steal Credentials, Auth Tokens
joshuark shares a report from BleepingComputer: The TeamPCP hacking group continues its supply-chain rampage, now compromising the massively popular “LiteLLM” Python package on PyPI and claiming to have stolen data from hundreds of thousands of devices during the attack. LiteLLM is an open-source Python library that serves as a gat … ⌘ Read more
Trapped! Inside a Self-Driving Car During an Anti-Robot Attack
A man crossing the street one San Francisco night spotted a self-driving car — and decided to confront its passenger, 37-year-old tech worker Doug Fulop. The New York Times reports the man yelled that “he wanted to kill Fulop and the other two passengers for giving money to a robot.”
A taxi driver would have simply driven away. But Fulop’s vehicle had … ⌘ Read more
Trivy Supply Chain Attack Spreads, Triggers Self-Spreading CanisterWorm Across 47 npm Packages
“We have removed all malicious artifacts from the affected registries and channels,” Trivy maintainer Itay Shakury posted today, noting that all the latest Trivy releases “now point to a safe version.” But “On March 19, we observed that a threat actor used a compromised credential…”
And … ⌘ Read more
iPhone Exploit DarkSword Steals Data In Minutes With No Trace
BrianFagioli writes: A new iOS exploit chain called DarkSword shows how attackers can break into certain iPhones, grab sensitive data like messages, credentials, and even crypto wallets, and then disappear without leaving obvious traces. It targets older iOS 18 builds using Safari and WebGPU flaws to escape Apple’s sandbox, which is pretty wild on its … ⌘ Read more
Polymarket Gamblers Threaten To Kill Journalist Over Iran Missile Story
An anonymous reader quotes a report from the Times of Israel, written by journalist Emanuel Fabian: On Tuesday, March 10, a massive explosion shook the city of Beit Shemesh, just outside Jerusalem, in yet another Iranian ballistic missile attack during the ongoing war. Rescue services scrambled to the scene in search of possible casu … ⌘ Read more
My twtxt instance is under a de-facto attack. Or, at this point, I can’t even differentiate an attack from the other in the constant barrage or malicious requests.
There were so many bots hammering it, in only 3 days, they consumed the ironically significant amount of 666 MB — I kid you not! In the last 24 hours, there were 59,673 hits on this endpoint alone.
I had to put my twtxt web interface behind a password-protected BasicAuth directive. As I’m the only one using it, it’s fine.
Bots, scrappers and Large Laggy Manglers are poisoning the open web.
@lyse@lyse.isobeef.org Hm, I’m not sure I would want to do that:
ForwardAgent
...
Agent forwarding should be enabled with caution. Users
with the ability to bypass file permissions on the remote
host (for the agent's Unix-domain socket) can access the
local agent through the forwarded connection. An attacker
cannot obtain key material from the agent, however they
can perform operations on the keys that enable them to au‐
thenticate using the identities loaded into the agent.
** WARNING: connection is not using a post-quantum key exchange algorithm.
** This session may be vulnerable to “store now, decrypt later” attacks.
** The server may need to be upgraded. See https://openssh.com/pq.html
😱😱😱
US Cybersecurity Adds Exploited VMware Aria Operations To KEV Catalog
joshuark writes: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a VMware Aria Operations vulnerability tracked as CVE-2026-22719 to its Known Exploited Vulnerabilities catalog, flagging the flaw as exploited in attacks. VMware Aria Operations is an enterprise monitoring platform that helps organizations track t … ⌘ Read more
The 19th Century Silent Film That First Captured a Robot Attack
The Library of Congress has restored Gugusse et l’Automate, an 1897 short by Georges Melies that likely features the first robot ever shown on film. Long thought lost, the reel was discovered in a box of decaying nitrate films donated from a Michigan family collection. NPR reports: The film, which can be viewed on the Library of Congress’ websi … ⌘ Read more
America Used Anthropic’s AI for Its Attack On Iran, One Day After Banning It
Engadget reports:
In a lengthy post on Truth Social on February 27, President Trump ordered all federal agencies to “immediately cease all use of Anthropic’s technology” following strong disagreements between the Department of Defense and the AI company. A few hours later, the U.S. conducted a major air attack on Iran with … ⌘ Read more
After US-Israel Attacks, 90 Million Iranians Lose Internet Connectivity
CNN reports that images from Iran’s capital “have shown cars jammed along Tehran’s street, with heavy traffic on major roads after today’s wave of attacks by the US and Israel.” And though Iran has a population of 93 million, the attacks suddenly plunged Iran into “a near-total internet blackout with national connectivity at 4% of or … ⌘ Read more
Google Quantum-Proofs HTTPS
An anonymous reader quotes a report from Ars Technica: Google on Friday unveiled its plan for its Chrome browser to secure HTTPS certificates against quantum computer attacks without breaking the Internet. The objective is a tall order. The quantum-resistant cryptographic data needed to transparently publish TLS certificates is roughly 40 times bigger than the classical cryptographic material used today. Today’s X.509 c … ⌘ Read more
Hacker Used Anthropic’s Claude To Steal Sensitive Mexican Data
A hacker exploited Anthropic’s AI chatbot to carry out a series of attacks against Mexican government agencies, resulting in the theft of a huge trove of sensitive tax and voter information, according to cybersecurity researchers. From a report: The unknown Claude user wrote Spanish-language prompts for the chatbot to act as an elite hacker, finding vu … ⌘ Read more
CrowdStrike Says Attackers Are Moving Through Networks in Under 30 Minutes
An anonymous reader shares a report: Cyberattacks reached victims faster and came from a wider range of threat groups than ever last year, CrowdStrike said in its annual global threat report released Tuesday, adding that cybercriminals and nation-states increasingly relied on predictable tactics to evade detection by exploiting … ⌘ Read more
EVs Are Already Making Your Air Cleaner, Research Shows
Fossil fuels produce NO2, which is linked to asthma attacks, bronchitis, and higher risks of heart disease and stroke, according the EV news site Electrek. But the nonprofit news site Grist.org notes a new analysis showing that those emissions decreased by 1.1% for every increase of 200 electric vehicles — across nearly 1,700 ZIP codes.
“A pretty small addition of … ⌘ Read more
Hit Piece-Writing AI Deleted. But Is This a Warning About AI-Generated Harassment?
Last week an AI agent wrote a blog post attacking the maintainer who’d rejected the code it wrote. But that AI agent’s human operator has now come forward, revealing their agent was an OpenClaw instance with its own accounts, switching between multiple models from multiple providers. (So “No one company had … ⌘ Read more
Wikipedia Blacklists Archive.today, Starts Removing 695,000 Archive Links
An anonymous reader quotes a report from Ars Technica: The English-language edition of Wikipedia is blacklisting Archive.today after the controversial archive site was used to direct a distributed denial of service (DDoS) attack against a blog. In the course of discussing whether Archive.today should be deprecated because of the DD … ⌘ Read more
Apple Patches Decade-Old IOS Zero-Day, Possibly Exploited By Commercial Spyware
This week Apple patched iOS and macOS against what it called “an extremely sophisticated attack against specific targeted individuals.”
Security Week reports that the bugs “could be exploited for information exposure, denial-of-service (DoS), arbitrary file write, privilege escalation, network traffic interception, … ⌘ Read more
Windows 11 Notepad Flaw Let Files Execute Silently via Markdown Links
Microsoft has patched a high-severity vulnerability in Windows 11’s Notepad that allowed attackers to silently execute local or remote programs when a user clicked a specially crafted Markdown link, all without triggering any Windows security warning.
The flaw, tracked as CVE-2026-20841 and fixed in the February 2026 Patch Tuesday upda … ⌘ Read more
Cyber-Espionage Group Breached Systems in 37 Nations, Security Researchers Say
An anonymous reader shared this report from Bloomberg:
An Asian cyber-espionage group has spent the past year breaking into computer systems belonging to governments and critical infrastructure organizations in more than 37 countries, according to the cybersecurity firm Palo Alto Networks, Inc. The state-aligned attacker … ⌘ Read more
Security Researchers Find Current RISC-V CPU Implementations Coming Up Short
While many open-source enthusiasts like to flaunt RISC-V as not having the security challenges as x86_64 CPUs have seen over the past several years with various speculative execution / side-channel attacks and arguing for the benefits of an open-source ISA in stronger security, in practice it’s not so clear-cut. Security researchers at Germany’s CISPA Helmholtz Center for Information Security have found current RISC-V CPU impleme … ⌘ Read more
Notepad++ Compromised By State Actor
Luthair writes: Notepad++ claims to have been targeted by a state actor, given their previous stance on Uyghurs one can speculate about a candidate. Notepad++, in a blog post: According to the analysis provided by the security experts, the attack involved infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org. The exact tec … ⌘ Read more
SoundCloud Data Breach Impacts 29.8 Million Accounts
A data breach at SoundCloud exposed information tied to 29.8 million user accounts, according to Have I Been Pwned. While SoundCloud says no passwords or financial data were accessed, attackers mapped email addresses to public profile data and later attempted extortion. BleepingComputer reports: The company confirmed the breach on December 15, following widespread reports … ⌘ Read more
Nike Says It’s Investigating Possible Data Breach
Nike says it is investigating a potential data breach, after a group known for cyber attacks reportedly claimed to have leaked a trove of data related to its business operations. From a report: “We always take consumer privacy and data security very seriously,” Nike said in a statement. “We are investigating a potential cyber security incident and are actively assessing the situ … ⌘ Read more
Predator Spyware Turns Failed Attacks Into Intelligence For Future Exploits
In December 2024 the Google Threat Intelligence Group published research on the code of the commercial spyware “Predator”. But there’s now been new research by Jamf (the company behind a mobile device management solution) showing Predator is more dangerous and sophisticated than we realized, according to SecurityWeek.
Long-ti … ⌘ Read more
Linux 7.0 Looks To Enable Intel TSX By Default On Capable CPUs For Better Performance
A patch queued up into tip/tip.git’s x86/cpu Git branch ahead of the upcoming Linux 6.20~7.0 kernel cycle enables the Intel Transactional Synchronization Extensions (TSX) functionality by default on the mainline kernel for capable CPUs and those not affected by side-channel attacks due to TSX Async Abort (TAA) and similar vulnerabilities. For newer Intel CPUs with safe TSX support, this change can mean better performance with … ⌘ Read more
Never-Before-Seen Linux Malware Is ‘Far More Advanced Than Typical’
An anonymous reader quotes a report from Ars Technica: Researchers have discovered a never-before-seen framework that infects Linux machines with a wide assortment of modules that are notable for the range of advanced capabilities they provide to attackers. The framework, referred to as VoidLink by its source code, features more than 30 modules … ⌘ Read more
EPA To Stop Considering Lives Saved By Limiting Air Pollution
An anonymous reader quotes a report from the New York Times: For decades, the Environmental Protection Agency has calculated the health benefits of reducing air pollution, using the cost estimates of avoided asthma attacks and premature deaths to justify clean-air rules. Not anymore. Under President Trump, the E.P.A. plans to stop tallying gains from th … ⌘ Read more
Linux Lands Safeguard For RISC-V Against Another Microarchitectural Attack Vector
Increasingly complex RISC-V cores aren’t magically immune to the speculative execution / side-channel vulnerabilities that have rattled the x86_64 and ARM64 landscape for years. Following recent work on Spectre V1 handling for RISC-V in the Linux kernel, merged this weekend for Linux 6.19-rc5 is another RISC-V attack vector safeguard… ⌘ Read more
VSCode IDE Forks Expose Users To ‘Recommended Extension’ Attacks
An anonymous reader shares a report: Popular AI-powered integrated development environment solutions, such as Cursor, Windsurf, Google Antigravity, and Trae, recommend extensions that are non-existent in the OpenVSX registry, allowing threat actors to claim the namespace and upload malicious extensions.
These AI-assisted IDEs are forked from Microso … ⌘ Read more
Airlines Cancel Hundreds of Flights After U.S. Attack on Venezuela
CNBC reports that U.S. airlines have “canceled hundreds of flights to airports in Puerto Rico and Aruba, according to flight tallies from FlightAware and carriers’ sites.”
JetBlue, Southwest, and American Airlines were among the multiple airlines showing cancelled flights, which “included close to 300 flights to and from San Juan, Puerto Rico’ … ⌘ Read more
@movq@www.uninformativ.de I’m pretty sure I know a bunch of people who love to blow up their money. :-(
Holy shit! :-O At least, the walls didn’t shake here. But we also had some very loud explosions, maybe they were far enough away. :-? Of course, the bangs continued last night.
Maybe some politicians need to be personally attacked with this sort of shit first in order to ban it once and forever.
European Space Agency Acknowledges Another Breach as Criminals Claim 200 GB Data Haul
The European Space Agency has acknowledged yet another security incident after a cybercriminal posted an offer on BreachForums the day after Christmas claiming to have stolen over 20GB of data including source code, confidential documents, API tokens and credentials.
The attacker claims they gained access … ⌘ Read more
Cybersecurity Employees Plead Guilty To Ransomware Attacks
Two cybersecurity professionals who spent their careers defending organizations against ransomware attacks have pleaded guilty in a Florida federal court to using ALPHV/BlackCat ransomware to extort American businesses throughout 2023.
Ryan Goldberg, a 40-year-old incident response manager from Georgia, and Kevin Martin, a 36-year-old ransomware negotiator f … ⌘ Read more
Pro-AI Group Launches First of Many Attack Ads for US Election
“Super PAC aims to drown out AI critics in midterms,” the Washington Post reported in August, noting its intial funding over $100 million from “some of Silicon Valley’s most powerful investors and executives” including OpenAI president Greg Brockman, his wife, and VC firm Andreessen Horowitz. The group’s goal was “to quash a philosophical debate … ⌘ Read more
Newer RISC-V CPUs Vulnerable To Spectre V1 - Linux Mitigation Patches Posted
Spectre V1 mitigations in the Linux kernel are coming for RISC-V with newer RISC-V core designs being vulnerable to Spectre Variant One style attacks… ⌘ Read more
Newer RISC-V CPUs Vulnerable To Spectre V1 - Linux Mitigation Patches Posted
Spectre V1 mitigations in the Linux kernel are coming for RISC-V with newer RISC-V core designs being vulnerable to Spectre Variant One style attacks… ⌘ Read more
Fake hero, wrong suspect: Misinformation floods social media after Bondi shooting
Elon Musk’s chatbot said Edward Crabtree – a fictional 47-year-old IT professional – was the hero who tackled one of the attackers and seized his weapon. ⌘ Read more
Rap musician tells court of pain and flashbacks after being set alight
Newcastle rapper Taison Brockbank tells the court he nearly died after being set on fire during an attack in inner-city Newcastle in 2023. ⌘ Read more
Gold Coast man jailed for nine years over one-punch attack
Alexander Rasic pleaded guilty to unlawful striking causing the death of Michael Hayes on the Gold Coast in June, 2023. ⌘ Read more
Three more teenagers charged over Ellenbrook school stabbing
Three more teenagers are charged over an alleged premeditated gang attack at Ellenbrook Secondary College on Monday that left a student with stab wounds. ⌘ Read more
Man charged over alleged gunfire, grenade attack in Sydney’s north-west
A 19-year-old is expected to front court on Wednesday after been charged over the alleged shooting at a Tallawong home. ⌘ Read more
Two charged over Heathrow suitcase robbery and suspected pepper spray attack
Two men have appeared in court charged with robbery and administering a noxious substance. ⌘ Read more
Two charged over Heathrow suitcase robbery and suspected pepper spray attack
Police say a substance was used when a woman’s suitcase taken in a car park lift on Sunday. ⌘ Read more
Two charged over Heathrow suitcase robbery and suspected pepper spray attack
Police say a substance was used when a woman’s suitcase taken in a car park lift on Sunday. ⌘ Read more
Gran punched by pregnant attacker at funeral disgusted at sentence
Danielle Oliver was given a suspended sentence for her assault on Belinda Stickland, 65, at a wake. ⌘ Read more
193 Cybercrims Arrested, Accused of Plotting ‘Violence-As-a-Service’
Europol’s GRIMM taskforce has arrested nearly 200 people accused of running or participating in “violence-as-a-service” schemes where cybercrime groups recruit youth online for real-world attacks. “These individuals are groomed or coerced into committing a range of violent crimes, from acts of intimidation and torture to murder,” the European … ⌘ Read more
Aussie quick ruled out for remainder of Ashes in blow to bowling attack
Coach Andrew McDonald confirms Josh Hazelwood will not play in the Ashes due to ongoing injuries. ⌘ Read more
Asylum seekers, 17, sentenced for girl’s rape
A judge has lifted reporting restrictions on naming the attackers, Jan Jahanzeb and Israr Niaza. ⌘ Read more