Searching We Love Privacy Club

Twts matching #security
Sort by: Newest, Oldest, Most Relevant

Anthropic Reveals $30 Billion Run Rate, Plans To Use 3.5GW of New Google AI Chips
Anthropic says its annualized revenue run rate has surpassed $30 billion and disclosed plans to secure roughly 3.5 gigawatts of next-generation Google TPU compute starting in 2027. Broadcom will supply the key chips and networking gear for the effort, the company announced. The Register reports: News of the two d … ⌘ Read more

⤋ Read More

Cloudflare Fast-Tracks Post-Quantum Rollout To 2029
Cloudflare is accelerating its post-quantum security plans and now aims to make its entire platform fully post-quantum secure by 2029. “The updated timeline follows new developments in quantum computing research that suggest current cryptographic standards could be broken sooner than previously expected,” reports SiliconANGLE. From the report: The decision by Cloudflare t … ⌘ Read more

⤋ Read More

Security updates for Tuesday
Security updates have been issued by AlmaLinux (crun, kernel, and kernel-rt), Debian (dovecot), Fedora (calibre and nextcloud), Mageia (freerdp, polkit-122, python-nltk, python-pyasn1, vim, and xz), Red Hat (edk2 and openssl), SUSE (avahi, cockpit, python-pyOpenSSL, python311, and tar), and Ubuntu (lambdaisland-uri-clojure, linux-gcp, linux-gcp-4.15, linux-gcp-fips, linux-oem-6.17, and linux-realtime-6.17). ⌘ Read more

⤋ Read More

Linux 7.0-rc7 Adding More Documentation For AI Tools To Send Better Security Bug Reports
For helping with the increase of AI tools scouring the Linux kernel source tree and sending security bug reports, a pull request sent today ahead of the Linux 7.0-rc7 improves the documentation to better guide AI agents – and anyone reading the documentation – how to send better quality bug reports… ⌘ Read more

⤋ Read More

Top NPM Maintainers Targeted with AI Deepfakes in Massive Supply-Chain Attack, Axios Briefly Compromised
“Hackers briefly turned a widely trusted developer tool into a vehicle for credential-stealing malware that could give attackers ongoing access to infected systems,” the news site Axios.com reported Tuesday, citing security researchers at Google.

The compromised package … ⌘ Read more

⤋ Read More

Microsoft Pulls Then Re-Issues Windows 11 Preview Update. Also Begins Force-Updating Windows 11
Nine days ago Microsoft released a non-security “preview” update for Windows 11 — not mandatory for the average Windows user, notes ZDNet, “but rather as optional, more for IT admins and power users who want to test them.”
TechRepublic adds that the update “was to bring ‘production-rea … ⌘ Read more

⤋ Read More

IBM Teams Up With Arm To Run Arm Workloads On IBM Z Mainframes
IBM and Arm are teaming up to let Arm-based software run on IBM Z mainframes. Network World reports: The two companies plan to work on three things: building virtualization tools so Arm software can run on IBM platforms; making sure Arm applications meet the security and data residency rules that regulated industries must follow; and creating common techn … ⌘ Read more

⤋ Read More

Microsoft’s Newest Open-Source Project: Runtime Security For AI Agents
Microsoft today announced their newest open-source (MIT-licensed) software project.. the Agent Governance Toolkit. Microsoft is trying their hand at coming up with runtime security governance for autonomous AI agents… ⌘ Read more

⤋ Read More

Libinput Hit By Worrying Security Issues With Its Lua Plug-In System
Libinput devised a Lua-based plug-in system for modifying devices/events. The Lua plug-in support was introduced last year with libinput 1.30 but unfortunately some security issues have now come to light with the implementation… ⌘ Read more

⤋ Read More

Cloudflare Announces EmDash As Open-Source ‘Spiritual Successor’ To WordPress
In classic Cloudflare fashion, the CDN provider used April Fool’s Day to unveil an actual, “not a joke” product. Today, the company announced EmDash – an open-source “spiritual successor” to WordPress that aims to solve plugin security. Phoronix reports: With the help of AI coding agents, Cloudflare engineers have been re … ⌘ Read more

⤋ Read More

Cloudflare Announces EmDash As Open-Source “Spiritual Successor” To WordPress
Cloudflare continues to be full of open-source surprises. Today Cloudflare announced EmDash as an open-source “spiritual successor” to WordPress with an emphasis on better security… ⌘ Read more

⤋ Read More

Oracle Cuts Thousands of Jobs Across Sales, Engineering, Security
bobthesungeek76036 shares a report from the Register: Oracle laid off thousands of employees on Tuesday as it ramps spending on AI infrastructure projects internally and with major technology partners. The layoffs were carried out via email, according to copies of the message viewed by Business Insider. The email told affected workers they … ⌘ Read more

⤋ Read More

Top Brussels Official Urges Europeans To Work From Home, Drive Less As Energy Crisis Deepens
A top EU official is urging Europeans to work from home, drive less, and cut air travel as the bloc braces for a prolonged energy crisis triggered by the Gulf conflict. The European Commission is also pushing member states to accelerate renewables and other energy-security measures as oil and … ⌘ Read more

⤋ Read More

Claude Code’s Source Code Leaks Via npm Source Maps
Grady Martin writes: A security researcher has leaked a complete repository of source code for Anthropic’s flagship command-line tool. The file listing was exposed via a Node Package Manager (npm) mapping, with every target publicly accessible on a Cloudflare R2 storage bucket. $ du -hs .35M .$ find -type f | sed ’s/^.*\.//’ | sort | uniq -c | sort -bVr 1332 ts … ⌘ Read more

⤋ Read More

Google Moves Post-Quantum Encryption Timeline Up To 2029
Google has moved up its post-quantum encryption migration target to 2029. “This new timeline reflects migration needs for the PQC era in light of progress on quantum computing hardware development, quantum error correction, and quantum factoring resource estimates,” said vice president of security engineering Heather Adkins and senior staff cryptology engineer Sop … ⌘ Read more

⤋ Read More

Hong Kong Police Can Demand Passwords Under New National Security Rules
An anonymous reader quotes a report from the BBC: Hong Kong police can now demand phone or computer passwords from those who are suspected of breaching the wide-ranging National Security Law (NSL). Those who refuse could face up to a year in jail and a fine of up to $12,700, and individuals who provide “false or misleading informatio … ⌘ Read more

⤋ Read More

FCC Bans Imports of New Foreign-Made Routers, Citing Security Concerns
New submitter the_skywise shares a report from Reuters: The U.S. Federal Communications Commission said on Monday it was banning the import of all new foreign-made consumer routers, the latest crackdown on Chinese-made electronic gear over security concerns. China is estimated to control at least 60% of the U.S. market for home rout … ⌘ Read more

⤋ Read More

White House Unveils National AI Policy Framework To Limit State Power
An anonymous reader quotes a report from CNBC: The Trump administration on Friday issued (PDF) a legislative framework for a single national policy on artificial intelligence, aiming to create uniform safety and security guardrails around the nascent technology while preempting states from enacting their own AI rules.
The six-pronged out … ⌘ Read more

⤋ Read More

Work From Home and Drive More Slowly To Save Energy, IEA Says
As energy prices soar from the Iran conflict, the International Energy Agency is urging governments to cut energy use by taking up measures like remote work and reduced speed limits. The group warns the energy security crisis could persist for months, even if supply routes stabilize. “I believe the world has not yet well understood the depth of the … ⌘ Read more

⤋ Read More

Rogue AI Triggers Serious Security Incident At Meta
For the second time in the past month, an AI agent went rogue at Meta – this time giving an engineer incorrect advice that briefly exposed sensitive data. The Verge reports: A Meta engineer was using an internal AI agent, which Clayton described as “similar in nature to OpenClaw within a secure development environment,” to analyze a technical question another employee pos … ⌘ Read more

⤋ Read More

Walmart Wins Patents To Give Algorithms More Sway Over Prices
Walmart has secured patents for systems that use machine learning to forecast demand and automate pricing decisions, “pushing the U.S. retail behemoth into a debate over the use of algorithms to adjust product costs,” reports the Financial Times. From the report: In January Walmart obtained a U.S. patent for a “system and method for dynamically and auto … ⌘ Read more

⤋ Read More

Intel Ends Work On Open-Source kAFL-Fuzzer For Fuzzing VMs
An Intel project developed the past several years was kAFL-Fuzzer as a hardware-assisted feedback fuzzer for x86 virtual machines (VMs) to help with security. While it saw a lot of work in prior years, development activity slowed down last year and now the project has been formally ended… ⌘ Read more

⤋ Read More

Ubuntu’s Snap Affected By Local Privilege Escalation Vulnerability
Last week it was security issues with AppArmor to worry about on Ubuntu Linux while this week a “high” rated vulnerability for Ubuntu’s Snap daemon has been revealed… ⌘ Read more

⤋ Read More

Microsoft, OpenAI & Others Pony Up $12.5M To Strengthen Open-Source Security
The Linux Foundation announced today that $12.5 million USD in grants from the likes of OpenAI, Anthropic, AWS, GitHub, Google, and Microsoft have been collected to invest in strengthening the security of the open-source software ecosystem… ⌘ Read more

⤋ Read More

Nvidia Bets On OpenClaw, But Adds a Security Layer Via NemoClaw
During today’s Nvidia GTC keynote, the company introduced NemoClaw, a security-focused stack designed to make the autonomous AI agent platform OpenClaw safer. ZDNet explains how it works: NemoClaw installs Nvidia’s OpenShell, a new open-source runtime that keeps agents safer to use by enforcing an organization’s policy-based guardrails. OpenShell ke … ⌘ Read more

⤋ Read More

How One Company Finally Exposed North Korea’s Massive Remote Workers Scam
NBC News investigates North Korea’s “wide-ranging effort to place remote workers at U.S. companies in order to funnel money back to its coffers and, in some cases, steal sensitive information.”

And working with the FBI, one corporate security/investigations company decided to knowingly hire one of North Korea’s remote workers — th … ⌘ Read more

⤋ Read More

Does Canada Need Nationalized, Public AI?
While AI CEOs worry governments might nationalize AI, others are advocating for something similar. Canadian security professional Bruce Schneier and Harvard data scientist Nathan Sanders published this call to action in Canada’s most widely-read newspaper (with a readership over 6 million): “Canada Needs Nationalized, Public AI.”

While there are Canadian AI companies, they remain for-profit e … ⌘ Read more

⤋ Read More

FreeRDP 3.24 Released With Security Fixes & Improved X11 Client Support
FreeRDP as this open-source and cross-platform Remote Desktop Protocol (RDP) implementation is out with FreeRDP 3.24 to ship new security fixes as well as other improvements… ⌘ Read more

⤋ Read More

Ubuntu’s AppArmor Hit By Several Security Issues - Can Yield Local Privilege Escalation
The AppArmor Linux kernel security module used notably by Ubuntu Linux and currently maintained by Canonical has been affected by several vulnerabilities made public today… ⌘ Read more

⤋ Read More

Perplexity’s ‘Personal Computer’ Lets AI Agents Access Your Local Files
Perplexity AI has introduced a “Personal Computer” agent system that can run on a local machine such as a Mac mini, giving its AI agents access to a user’s files and applications to automate tasks. According to CEO Aravind Srinivas, the heavy AI processing runs on Perplexity’s “secure servers” but sensitive actions will require user approval … ⌘ Read more

⤋ Read More

China Moves To Curb OpenClaw AI Use At Banks, State Agencies
An anonymous reader quotes a report from Bloomberg: Chinese authorities moved to restrict state-run enterprises and government agencies from running OpenClaw AI apps on office computers, acting swiftly to defuse potential security risks after companies and consumers across China began experimenting with the agentic AI phenomenon. Government agencies and state- … ⌘ Read more

⤋ Read More

European Consortium Wants Open-Source Alternative To Google Play Integrity
An anonymous reader quotes a report from Heise: Pay securely with an Android smartphone, completely without Google services: This is the plan being developed by the newly founded industry consortium led by the German Volla Systeme GmbH. It is an open-source alternative to Google Play Integrity. This proprietary interface decid … ⌘ Read more

⤋ Read More

How AI Assistants Are Moving the Security Goalposts
An anonymous reader quotes a report from KrebsOnSecurity: AI-based assistants or “agents” – autonomous programs that have access to the user’s computer, files, online services and can automate virtually any task – are growing in popularity with developers and IT workers. But as so many eyebrow-raising headlines over the past few weeks have shown, these powerful and assert … ⌘ Read more

⤋ Read More

Anthropic Sues the Pentagon After Being Labeled a Threat To National Security
Anthropic is suing the Department of Defense after the Trump administration labeled the company a “supply chain risk” and canceled its government contracts when Anthropic refused to allow its AI model Claude to be used for domestic surveillance or autonomous weapons. Fortune reports: The lawsuit, filed Monday in the U.S. … ⌘ Read more

⤋ Read More

Ubuntu 26.04 LTS Officially Supporting Cloud-Based Authentication With Authd
Canonical for a while has been developing Authd as an authentication service for external cloud-based identity providers. Authd was designed from the ground-up to provide secure management of identity and access for Ubuntu systems while only with next month’s Ubuntu 26.04 LTS release is it actually hitting the universe archive… ⌘ Read more

⤋ Read More

A Security Researcher Went ‘Undercover’ on Moltbook - and Found Security Risks
A long-time information security professional “went undercover” on Moltbook, the Reddit-like social media site for AI agents — and shares the risks they saw while posing as another AI bot:

I successfully masqueraded around Moltbook, as the agents didn’t seem to notice a human among them. When I attempted a genuine connect … ⌘ Read more

⤋ Read More

How Anthropic’s Claude Helped Mozilla to Improve Firefox’s Security
“It took Anthropic’s most advanced artificial-intelligence model about 20 minutes to find its first Firefox browser bug during an internal test of its hacking prowess,” reports the Wall Street Journal.

The Anthropic team submitted it, and Firefox’s developers quickly wrote back: This bug was serious. Could they get on a call? “What else do yo … ⌘ Read more

⤋ Read More

US Cybersecurity Adds Exploited VMware Aria Operations To KEV Catalog
joshuark writes: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a VMware Aria Operations vulnerability tracked as CVE-2026-22719 to its Known Exploited Vulnerabilities catalog, flagging the flaw as exploited in attacks. VMware Aria Operations is an enterprise monitoring platform that helps organizations track t … ⌘ Read more

⤋ Read More

TikTok Says End-To-End Encryption Makes Users Less Safe
An anonymous reader quotes a report from the BBC: TikTok will not introduce end-to-end encryption (E2EE) – the controversial privacy feature used by nearly all its rivals – arguing it makes users less safe. E2EE means only the sender and recipient of a direct message can view its contents, making it the most secure form of communication available to the general … ⌘ Read more

⤋ Read More

Linux Preps IBPB-On-Entry Feature For AMD SEV-SNP Guest VMs
Heading toward the Linux 7.0 kernel and marked for back-porting to current stable Linux kernel versions is employing a new SEV-SNP security feature found on AMD Zen 5 processors for enhancing security of guest virtual machines… ⌘ Read more

⤋ Read More

A Possible US Government iPhone-Hacking Toolkit Is Now In the Hands of Foreign Spies, Criminals
Security researchers say a highly sophisticated iPhone exploitation toolkit dubbed “Coruna,” which possibly originated from a U.S. government contractor, has spread from suspected Russian espionage operations to crypto-stealing criminal campaigns. Apple has patched the exploited vulner … ⌘ Read more

⤋ Read More

Motorola Partners With GrapheneOS
At MWC 2026, Motorola announced a partnership with the GrapheneOS Foundation to bring the hardened, Google-free Android variant to future devices. Until now, the OS had been designed exclusively for Google Pixel phones. “We are thrilled to be partnering with Motorola to bring GrapheneOS’s industry-leading privacy and security-focused mobile operating system to their next-generation smartphone,” a GrapheneOS … ⌘ Read more

⤋ Read More

Google Quantum-Proofs HTTPS
An anonymous reader quotes a report from Ars Technica: Google on Friday unveiled its plan for its Chrome browser to secure HTTPS certificates against quantum computer attacks without breaking the Internet. The objective is a tall order. The quantum-resistant cryptographic data needed to transparently publish TLS certificates is roughly 40 times bigger than the classical cryptographic material used today. Today’s X.509 c … ⌘ Read more

⤋ Read More

CISA Replaces Bumbling Acting Director After a Year
New submitter DeanonymizedCoward shares a report from TechCrunch: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is reportedly in crisis following major budget cuts, layoffs, and furloughs under the Trump administration, says TechCrunch. The agency has now replaced its acting director, Madhu Gottumukkala, after a turbulent year marked by controversy and i … ⌘ Read more

⤋ Read More

South Korea Set To Get a Fully Functioning Google Maps
South Korea has reversed a two-decade policy and approved the export of high-precision map data, paving the way for a fully functional Google Maps in the country. Reuters reports: The approval was made “on the condition that strict security requirements are met,” the Ministry of Land, Infrastructure and Transport said in a statement. Those conditions include blurrin … ⌘ Read more

⤋ Read More

sudo-rs Breaks Historical Norms With Now Enabling Password Feedback By Default
On recent builds of Ubuntu 26.04 when being prompted by sudo for the password, password feedback is now enabled by default to show asterisk (*) characters when inputting your password. Traditionally sudo has not provided password feedback in the name of security to not divulge the length of your password in case anyone is looking/capturing your screen. But upstream sudo-rs has now changed the default behavior in the name of an improv … ⌘ Read more

⤋ Read More

Firefox 148 Lets You Kill All AI Features in One Click
Mozilla has released Firefox 148 for Windows, macOS and Linux, bringing a new AI Settings section that lets users disable all of the browser’s AI-powered features in one click and then selectively re-enable the ones they actually want, such as the local translation tool that works locally rather than in the cloud.

The update also patches more than 50 security vulner … ⌘ Read more

⤋ Read More