Searching We Love Privacy Club

Twts matching #security
Sort by: Newest, Oldest, Most Relevant

AI Can Find Hundreds of Software Bugs – Fixing Them Is Another Story
Anthropic last week promoted Claude Code Security, a research preview capability that uses its Claude Opus 4.6 model to hunt for software vulnerabilities, claiming its red team had surfaced over 500 bugs in production open-source codebases – but security researchers say the real bottleneck was never discovery.

Guy Azari, a former securi … ⌘ Read more

⤋ Read More

Mesa 26.0.1 Released With Important Security Fix For OOB Memory Access From WebGPU
Mesa 26.0.1 is now available as the first point release of this quarter’s Mesa 26.0 series. Besides the usual bug fixing, Mesa 26.0.1 is more pressing than usual since it contains a security fix for possible out-of-bounds memory access in WebGPU contexts from web browsers… ⌘ Read more

⤋ Read More

HP Says Memory’s Contribution To PC Costs Just Doubled To 35%
HP has revealed that memory now accounts for 35% of the cost of materials it needs to build a PC, up from between 15 and 18% last quarter. And the company expects RAM’s contribution will rise through the year. From a report: Speaking on the company’s Q1 2026 earnings call, interim CEO Bruce Broussard said the company has secured long-term supply agreemen … ⌘ Read more

⤋ Read More

FreeRDP 3.23 Addresses 11 CVEs, Improved SDL Client
For those making use of the open-source FreeRDP project for your Remote Desktop Protocol (RDP) needs, FreeRDP 3.23 is out today with 11 CVEs addressed in taking care of various security-related issues that have been uncovered… ⌘ Read more

⤋ Read More

AMD Posts Linux Patches For SEV-SNP BTB Isolation
It’s quite a mouthful but today AMD posted Linux kernel patches for preparing SEV-SNP BTB isolation support for further enhancing the security of virtual machines (VMs) for confidential computing… ⌘ Read more

⤋ Read More

Meta AI Security Researcher Said an OpenClaw Agent Ran Amok on Her Inbox
Meta AI security researcher Summer Yue posted a now-viral account on X describing how an OpenClaw agent she had tasked with sorting through her overstuffed email inbox went rogue, deleting messages in what she called a “speed run” while ignoring her repeated commands from her phone to stop.

“I had to RUN to my Mac mini like I was d … ⌘ Read more

⤋ Read More
In-reply-to » The original twt is unavailable. It may have been edited or deleted, or is from an unknown or muted feed.

@kiwu@twtxt.net I am trying to read our Information Security Office “mind” to grasp what they want. So far they seem to want to get logs from our BIG-IP F5 load balancers into Azure Sentinel, but the Telemetry Streaming plugin normally used for it is on maintenance mode, with deprecations happening on the F5 and Microsoft side soonish. So, yeah… “fun”. Oh, and they want it on production by tomorrow. LOLz!

⤋ Read More

‘Open Source Registries Don’t Have Enough Money To Implement Basic Security’
Google and Microsoft contributed $5 million to launch Alpha-Omega in 2022 — a Linux Foundation project to help secure the open source supply chain. But its co-founder Michael Winser warns that open source registries are in financial peril, reports The Register, since they’re still relying on non-continuous funding from grants … ⌘ Read more

⤋ Read More

How Python’s Security Response Team Keeps Python Users Safe
This week the Python Software Foundation explained how they keep Python secure. A new blog post recognizes the volunteers and paid Python Software Foundation staff on the Python Security Response Team (PSRT), who “triage and coordinate vulnerability reports and remediations keeping all Python users safe.”

Just last year the PSRT published 16 vulnerabi … ⌘ Read more

⤋ Read More

eCryptfs Sees Renewed Patch Activity With Linux 7.0
We haven’t heard much about eCryptfs in recent years for that stackable in-tree Linux file-system providing per-directory encryption support. The FSCRYPT framework has shown its strong capabilities in recent years with various file-systems, Canonical hasn’t been pursuing its user home directory encryption like it did years ago for the Ubuntu desktop, and full disk encryption is the most secure approach for ensuring data security on your system. But to some surprise wi … ⌘ Read more

⤋ Read More

Cyber Stocks Slide As Anthropic Unveils ‘Claude Code Security’
An anonymous reader quotes a report from Bloomberg: Shares of cybersecurity software companies tumbled Friday after Anthropic PBC introduced a new security feature into its Claude AI model. Crowdstrike Holdings was the among the biggest decliners, falling as much as 6.5%, while Cloudflare slumped more than 6%. Meanwhile, Zscaler dropped 3.5%, SailPoint s … ⌘ Read more

⤋ Read More

PayPal Discloses Data Breach That Exposed User Info For 6 Months
PayPal is notifying customers of a data breach after a software error in a loan application exposed their sensitive personal information, including Social Security numbers, for nearly 6 months last year. From a report: The incident affected the PayPal Working Capital (PPWC) loan app, which provides small businesses with quick access to financing. PayP … ⌘ Read more

⤋ Read More

How Private Equity Debt Left a Leading VPN Open To Chinese Hackers
An anonymous reader quotes a report from Bloomberg: In early 2024, the agency that oversees cybersecurity for much of the US government issued a rare emergency order – disconnect your Connect Secure virtual private network software immediately. Chinese spies had hacked the code and infiltrated nearly two dozen organizations. The directive appli … ⌘ Read more

⤋ Read More

Cloud Hypervisor 51 Brings Performance Improvements, Better QCOW2 v3 Support
Cloud Hypervisor 51 is now available for this Rust-based VMM focused on secure cloud computing. For what began as an Intel open-source project years ago is continuing to be largely led by Microsoft, Cyberus Tech, Tencent, Ant Group, and others… ⌘ Read more

⤋ Read More

OpenClaw Security Fears Lead Meta, Other AI Firms To Restrict Its Use
An anonymous reader quotes a report from Wired: Last month, Jason Grad issued a late-night warning to the 20 employees at his tech startup. “You’ve likely seen Clawdbot trending on X/LinkedIn. While cool, it is currently unvetted and high-risk for our environment,” he wrote in a Slack message with a red siren emoji. “Please keep Clawdbot of … ⌘ Read more

⤋ Read More

Mark Zuckerberg Grilled On Usage Goals and Underage Users At California Trial
An anonymous reader quotes a report from the Wall Street Journal: Meta Chief Executive Mark Zuckerberg faced a barrage of questions about his social-media company’s efforts to secure ever more of its users’ time and attention at a landmark trial in Los Angeles on Wednesday. In sworn testimony, Zuckerberg said Meta’s grow … ⌘ Read more

⤋ Read More

LLM-Generated Passwords Look Strong but Crack in Hours, Researchers Find
AI security firm Irregular has found that passwords generated by major large language models – Claude, ChatGPT and Gemini – appear complex but follow predictable patterns that make them crackable in hours, even on decades-old hardware. When researchers prompted Anthropic’s Claude Opus 4.6 fifty times in separate conversations, only … ⌘ Read more

⤋ Read More

Texas Sues TP-Link Over China Links and Security Vulnerabilities
TP-Link is facing legal action from the state of Texas for allegedly misleading consumers with “Made in Vietnam” claims despite China-dominated manufacturing and supply chains, and for marketing its devices as secure despite reported firmware vulnerabilities exploited by Chinese state-sponsored actors. The Register: The Lone Star State’s Attorney … ⌘ Read more

⤋ Read More

Fake Job Recruiters Hid Malware In Developer Coding Challenges
“A new variation of the fake recruiter campaign from North Korean threat actors is targeting JavaScript and Python developers with cryptocurrency-related tasks,” reports the Register.

Researchers at software supply-chain security company ReversingLabs say that the threat actor creates fake companies in the blockchain and crypto-trading sectors and publ … ⌘ Read more

⤋ Read More

Apple Patches Decade-Old IOS Zero-Day, Possibly Exploited By Commercial Spyware
This week Apple patched iOS and macOS against what it called “an extremely sophisticated attack against specific targeted individuals.”

Security Week reports that the bugs “could be exploited for information exposure, denial-of-service (DoS), arbitrary file write, privilege escalation, network traffic interception, … ⌘ Read more

⤋ Read More

Sudden Telnet Traffic Drop. Are Telcos Filtering Ports to Block Critical Vulnerability?
An anonymous reader shared this report from the Register:

Telcos likely received advance warning about January’s critical Telnet vulnerability before its public disclosure, according to threat intelligence biz GreyNoise. Global Telnet traffic “fell off a cliff” on January 14, six days before security a … ⌘ Read more

⤋ Read More

Israeli Soldiers Accused of Using Polymarket To Bet on Strikes
An anonymous reader shares a report: Israel has arrested several people, including army reservists, for allegedly using classified information to place bets on Israeli military operations on Polymarket. Shin Bet, the country’s internal security agency, said Thursday the suspects used information they had come across during their military service to i … ⌘ Read more

⤋ Read More

Evaluating The Performance Cost To AMD SEV-SNP On EPYC 9005 VMs
AMD Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP) provides memory encryption and integrity protections that can be especially useful in modern cloud computing. Typically a 2~10% performance overhead is reported when engaging AMD SEV-SNP for these hardware-backed security protections. In this article is an extensive look at the current AMD SEV-SNP performance impact for confidential computing on EPYC 9005 “Turin” servers. The curr … ⌘ Read more

⤋ Read More

Windows 11 Notepad Flaw Let Files Execute Silently via Markdown Links
Microsoft has patched a high-severity vulnerability in Windows 11’s Notepad that allowed attackers to silently execute local or remote programs when a user clicked a specially crafted Markdown link, all without triggering any Windows security warning.

The flaw, tracked as CVE-2026-20841 and fixed in the February 2026 Patch Tuesday upda … ⌘ Read more

⤋ Read More

Linus Torvalds Rejects MMC Changes For Linux 7.0 Cycle: “Complete Garbage”
The Linux MultiMediaCard “MMC” subsystem was set to see some new hardware support, optimized support for secure erase/trim on some eMMCs, and a variety of other improvements. But all of the MMC changes are rejected and will be for the duration of the Linux 7.0 cycle due to an apparent lack of testing and vetting via linux-next that led Linus Torvalds to calling it “complete garbage” and “untested crap”… ⌘ Read more

⤋ Read More

Iceland is Planning For the Possibility That Its Climate Could Become Uninhabitable
Iceland in October classified the potential collapse of the Atlantic meridional overturning circulation – the ocean current system that ferries warm water northward from the tropics and essentially functions as the country’s central heating – as a national security risk, a designation that amounts to a form … ⌘ Read more

⤋ Read More

Google’s Personal Data Removal Tool Now Covers Government IDs
Google on Tuesday expanded its “Results about you” tool to let users request the removal of Search results containing government-issued ID numbers – including driver’s licenses, passports and Social Security numbers – adding to the tool’s existing ability to flag results that surface phone numbers, email addresses, and home addresses.

The update, ann … ⌘ Read more

⤋ Read More

Intel CPU Microcode 20260210 Brings Security Updates & Functional Fixes
Intel today for Patch Tuesday released several generations worth of CPU microcode updates for addressing multiple security issues and functional issues… ⌘ Read more

⤋ Read More

Microsoft Begins the First-Ever Secure Boot Certificate Swap Across Windows Ecosystem
Microsoft has begun automatically replacing the original Secure Boot security certificates on Windows devices through regular monthly updates, a necessary move given that the 15-year-old certificates first issued in 2011 are set to expire between late June and October 2026.

Secure Boot, which verifies th … ⌘ Read more

⤋ Read More

Cyber-Espionage Group Breached Systems in 37 Nations, Security Researchers Say
An anonymous reader shared this report from Bloomberg:

An Asian cyber-espionage group has spent the past year breaking into computer systems belonging to governments and critical infrastructure organizations in more than 37 countries, according to the cybersecurity firm Palo Alto Networks, Inc. The state-aligned attacker … ⌘ Read more

⤋ Read More

A New Era for Security? Anthropic’s Claude Opus 4.6 Found 500 High-Severity Vulnerabilities
Axios reports:

Anthropic’s latest AI model has found more than 500 previously unknown high-severity security flaws in open-source libraries with little to no prompting, the company shared first with Axios.

Why it matters: The advancement signals an inflection point for how AI tools can help cyber … ⌘ Read more

⤋ Read More

Moltbook, Reddit, and The Great AI-Bot Uprising That Wasn’t
Monday security researchers at cloud-security platform Wiz discovered a vulnerability that allowed anyone to post to the bots-only social network Moltbook — or even edit and manipulate other existing Moltbook posts. “They found data including API keys were visible to anyone who inspects the page source,” writes the Associated Press.

But had it been disco … ⌘ Read more

⤋ Read More

Salesforce Shelves Heroku
Salesforce is essentially shutting down Heroku as an evolving product, moving the cloud platform that helped define modern app deployment to a “sustaining engineering model” focused entirely on stability, security and support.

Existing customers on credit card billing see no changes to pricing or service, but enterprise contracts are no longer available to new buyers. Salesforce said it is redirecting engineering investment … ⌘ Read more

⤋ Read More

FBI Couldn’t Get Into Reporter’s iPhone Because It Had Lockdown Mode Enabled
The FBI has been unable to access a Washington Post reporter’s seized iPhone because it was in Lockdown Mode, a sometimes overlooked feature that makes iPhones broadly more secure, according to recently filed court records. 404Media: The court record shows what devices and data the FBI was able to ultimately access, and whi … ⌘ Read more

⤋ Read More

Microsoft’s New Open-Source Project: LiteBox As A Rust-Based Sandboxing Library OS
Microsoft engineers and other stakeholders have been developing LiteBox as a security-focused library OS written in the Rust programming language and leveraging Linux Virtualization Based Security “LVBS”. The design is for LiteBox to operate as a secure kernel protecting the normal guest kernel via virtualization hardware… ⌘ Read more

⤋ Read More

Russian Spy Satellites Have Intercepted EU Communications Satellites
European security officials believe two Russian space vehicles have intercepted the communications of at least a dozen key satellites over the continent. From a report: Officials believe that the likely interceptions, which have not previously been reported, risk not only compromising sensitive information transmitted by the satellites … ⌘ Read more

⤋ Read More

Ich hab es jetzt endlich geschafft, diese alte Podcastdatei anzuhören, die ich auf meiner Platte fand. Omega-Tau 293 über Wasserstraßen und im Speziellen den Neckar. Total interessant. Ich bin bisher noch nie über diese Serie gestolpert und habe keine Ahnung, wie ich überhaupt zu der Datei kam. Leider ist der Podcast mittlerweile eingestellt, das TLS-Zertifikat der Website die Tage abgelaufen und die Folgenseite tot, aber die Audiodatei gibt’s noch: https://traffic.libsyn.com/secure/omegataupodcast/omegatau-393-wasserstrassen.mp3

⤋ Read More

Adobe Actually Won’t Discontinue Animate
Adobe is no longer planning to discontinue Adobe Animate on March 1st. From a report: In an FAQ, the company now says that Animate will now be in maintenance mode and that it has “no plans toâdiscontinue or remove access” to the app.

Animate will still receive “ongoing security and bug fixes” and will still be available for “both new and existing users,” but it won’t get new features. Many creat … ⌘ Read more

⤋ Read More

Fintech CEO and Forbes 30 Under 30 Alum Charged for Alleged Fraud
An anonymous reader shares a report: By now, the Forbes 30 Under 30 list has become more than a little notorious for the amount of entrants who go on to be charged with fraud.[…] Gokce Guven, a 26-year-old Turkish national and the founder and CEO of fintech startup Kalder, was charged last week with alleged securities fraud, wire fraud, visa fra … ⌘ Read more

⤋ Read More

Feds Skipping Infosec Industry’s Biggest Conference This Year
An anonymous reader shares a report: The US Cybersecurity and Infrastructure Security Agency won’t attend the annual RSA Conference in March, an agency spokesperson confirmed to The Register. Sessions involving speakers from the FBI and National Security Agency (NSA) have also disappeared from the agenda.

“Since the beginning of this administration, CI … ⌘ Read more

⤋ Read More

Vibe-coded Social Network for AI Bots Exposed Data on Thousands of Humans
Moltbook, a Reddit-like social network that launched last week and bills itself as a platform “built exclusively for AI agents,” had a security vulnerability that exposed private messages shared between agents, the email addresses of more than 6,000 human owners, and over a million credentials, according to research published Mond … ⌘ Read more

⤋ Read More

Security Researchers Find Current RISC-V CPU Implementations Coming Up Short
While many open-source enthusiasts like to flaunt RISC-V as not having the security challenges as x86_64 CPUs have seen over the past several years with various speculative execution / side-channel attacks and arguing for the benefits of an open-source ISA in stronger security, in practice it’s not so clear-cut. Security researchers at Germany’s CISPA Helmholtz Center for Information Security have found current RISC-V CPU impleme … ⌘ Read more

⤋ Read More

Notepad++ Compromised By State Actor
Luthair writes: Notepad++ claims to have been targeted by a state actor, given their previous stance on Uyghurs one can speculate about a candidate. Notepad++, in a blog post: According to the analysis provided by the security experts, the attack involved infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org. The exact tec … ⌘ Read more

⤋ Read More

EU Deploys New Government Satcom Program in Sovereignty Push
The EU “has switched on parts of its homegrown secure satellite communications network for the first time,” reports Bloomberg, calling it part of a €10.6 billion push to “wean itself off US support amid growing tensions.”

SpaceNews notes the new government program GOVSATCOM pools capacity from eight already on-oribit satellites from France, Spain, It … ⌘ Read more

⤋ Read More

WhatsApp End-to-End Encryption Allegations Questioned By Some Security Experts, Lawyers
Several security experts have “questioned the lack of technical detail” in that lawsuit alleging WhatsApp has no end-to-end encryption, reports the Washington Post:

“It’s pretty long on accusations and thin on any sort of evidence,” Matthew Green, a cryptography professor at Johns Hopkins University, sa … ⌘ Read more

⤋ Read More

White House Scraps ‘Burdensome’ Software Security Rules
An anonymous reader quotes a report from SecurityWeek: The White House has announced that software security guidance issued during the Biden administration has been rescinded due to “unproven and burdensome” requirements that prioritized administrative compliance over meaningful security investments. The US Office of Management and Budget (OMB) has issued Memorandum … ⌘ Read more

⤋ Read More

County Pays $600,000 To Pentesters It Arrested For Assessing Courthouse Security
An anonymous reader quotes a report from Ars Technica, written by Dan Goodin: Two security professionals who were arrested in 2019 after performing an authorized security assessment of a county courthouse in Iowa will receive $600,000 to settle a lawsuit they brought alleging wrongful arrest and defamation. The case wa … ⌘ Read more

⤋ Read More

Massive AI Chat App Leaked Millions of Users Private Conversations
An anonymous reader shares a report: Chat & Ask AI, one of the most popular AI apps on the Google Play and Apple App stores that claims more than 50 million users, left hundreds of millions of those users’ private messages with the app’s chatbot exposed, according to an independent security researcher and emails viewed by 404 Media. The expose … ⌘ Read more

⤋ Read More

US Cyber Defense Chief Uploaded Sensitive Files Into a Public Version of ChatGPT
An anonymous reader quotes a report from Politico: The interim head of the country’s cyber defense agency uploaded sensitive contracting documents into a public version of ChatGPT last summer, triggering multiple automated security warnings that are meant to stop the theft or unintentional disclosure of government m … ⌘ Read more

⤋ Read More