Wasmer 7.0 Released For Advancing WebAssembly On The Desktop & Anywhere
Wasmer 7.0 is out today for this WebAssembly “WASM” run-time for enabling lightweight containers that can run “anywhere” from the desktop to cloud and the edge. The security-minded and extensible WASM runtime provided by Wasmer has already proven to be quite robust while with Wasmer 7.0 has become even more featureful… ⌘ Read more
France To Ditch US Platforms Microsoft Teams, Zoom For ‘Sovereign Platform’ Amid Security Concerns
France will replace the American platforms Microsoft Teams and Zoom with its own domestically developed video conferencing platform, which will be used in all government departments by 2027, the country said. From a report: The move is part of France’s strategy to stop using foreign … ⌘ Read more
Nike Says It’s Investigating Possible Data Breach
Nike says it is investigating a potential data breach, after a group known for cyber attacks reportedly claimed to have leaked a trove of data related to its business operations. From a report: “We always take consumer privacy and data security very seriously,” Nike said in a statement. “We are investigating a potential cyber security incident and are actively assessing the situ … ⌘ Read more
Infotainment, EV Charger Exploits Earn $1M at Pwn2Own Automotive 2026
Trend Micro’s Zero Day Initiative sponsored its third annual Pwn2Own Automotive competition in Tokyo this week, receiving 73 entries, the most ever for a Pwn2Own event.
“Under Pwn2Own rules, all disclosed vulnerabilities are reported to affected vendors through ZDI,” reports Help Net Security, “with public disclosure delayed to allow time … ⌘ Read more
AI Agents ‘Perilous’ for Secure Apps Such as Signal, Whittaker Says
Signal Foundation president Meredith Whittaker warned that AI agents that autonomously carry out tasks pose a threat to encrypted messaging apps [non-paywalled source] because they require broad access to data stored across a device and can be hijacked if given root permissions.
Speaking at Davos on Tuesday, Whittaker said the deeper integrat … ⌘ Read more
Nvidia Contacted Anna’s Archive To Secure Access To Millions of Pirated Books
An anonymous reader quotes a report from TorrentFreak: NVIDIA executives allegedly authorized the use of millions of pirated books from Anna’s Archive to fuel its AI training. In an expanded class-action lawsuit that cites internal NVIDIA documents, several book authors claim (PDF) that the trillion-dollar company directly … ⌘ Read more
OPEN_TREE_NAMESPACE To Provide A Security & Performance Win For Dealing With Containers
A new feature expected to be merged for the upcoming Linux 7.0 kernel cycle is adding an OPEN_TREE_NAMESPACE flag for the open_tree() system call. This OPEN_TREE_NAMESPACE option can provide a nice performance win with added security benefits if you are dealing a lot with containerized workloads on Linux… ⌘ Read more
SPDX SBOM Generation Tool Proposed For The Linux Kernel
For those organizations on the Software Bill of Materials (SBOM) bandwagon for increasing transparency around software components with license compliance, vulnerability management, and securing the software supply chain, proposed patches to the Linux kernel would introduce an SPDX SBOM Generation Tool… ⌘ Read more
Hundreds Answer Europe’s ‘Public Call for Evidence’ on an Open Digital Ecosystem Strategy
The European Commission “has opened a public call for evidence on European open digital ecosystems,” writes Help Net Security, part of preparations for an upcoming Communication “that will examine the role of open source in EU’s digital infrastructure.”
The consultation runs from January 6 to Februa … ⌘ Read more
To Pressure Security Professionals, Mandiant Releases Database That Cracks Weak NTLM Passwords in 12 Hours
Ars Technica reports:
Security firm Mandiant [part of Google Cloud] has released a database that allows any administrative password protected by Microsoft’s NTLM.v1 hash algorithm to be hacked in an attempt to nudge users who continue using the deprecated function … ⌘ Read more
NASA Livestreams the Rocket That Will Carry Four Astronauts Around the Moon
“A mega rocket set to take astronauts around the Moon for the first time in decades is being taken to its launch pad,” the BBC reported this morning.
NASA is livestreaming their move of the 11-million-pound “stack” — which includes the Artemis II Space Launch System (SLS) rocket and the Orion spacecraft secured to it, al … ⌘ Read more
What Happened After Security Researchers Found 60 Flock Cameras Livestreaming to the Internet
A couple months ago, YouTuber Benn Jordan “found vulnerabilities in some of Flock’s license plate reader cameras,” reports 404 Media’s Jason Koebler. “He reached out to me to tell me he had learned that some of Flock’s Condor cameras were left live-streaming to the open internet.”
This led … ⌘ Read more
CVE-2026-0915: GNU C Library Fixes A Security Issue Present Since 1996
CVE-2026-0915 was published on Friday as a security issue with the GNU C Library “glibc” for code introduced 30 years ago. The latest Glibc Git code is now patched for this issue introduced in 1996… ⌘ Read more
US Approves Sale of Nvidia’s Advanced AI Chips To China
The U.S. has approved limited sales of Nvidia’s H200 AI chips to China, the Department of Commerce said on Tuesday. Exports will be allowed to “approved customers” with security safeguards and a 25% U.S. government cut. The company’s most advanced Blackwell chips will remain restricted. The BBC reports: The H200, Nvidia’s second-most-advanced semiconductor, had … ⌘ Read more
Beijing Tells Chinese Firms To Stop Using US and Israeli Cybersecurity Software
An anonymous reader shares a report: Chinese authorities have told domestic companies to stop using cybersecurity software made by roughly a dozen firms from the U.S. and Israel due to national security concerns, two people briefed on the matter said.
As trade and diplomatic tensions flare between China and the U.S. a … ⌘ Read more
Anthropic Invests $1.5 Million in the Python Software Foundation and Open Source Security
Python Software Foundation: We are thrilled to announce that Anthropic has entered into a two-year partnership with the Python Software Foundation (PSF) to contribute a landmark total of $1.5 million to support the foundation’s work, with an emphasis on Python ecosystem security. This investme … ⌘ Read more
Microsoft Pulls the Plug On Its Free, Two-Decade-Old Windows Deployment Toolkit
Microsoft has abruptly retired the Microsoft Deployment Toolkit, a free platform that IT administrators have relied on to deploy Windows operating systems and applications for more than two decades. The retirement, reports the Register, came with “immediate” notice, meaning no more fixes, support, security patches, or u … ⌘ Read more
Debian 13.3 Released With Many Security & Bug Fixes
Debian 13.3 is out today as the newest stable point release for Debian Trixie… ⌘ Read more
French-UK Starlink Rival Pitches Canada On ‘Sovereign’ Satellite Service
An anonymous reader quotes a report from CBC.ca: A company largely owned by the French and U.K. governments is pitching Canada on a roughly $250-million plan to provide the military with secure satellite broadband coverage in the Arctic, CBC News has learned. Eutelsat, a rival to tech billionaire Elon Musk’s Starlink, already provid … ⌘ Read more
Samsung Hit with Restraining Order Over Smart TV Surveillance Tech in Texas
Texas Attorney General Ken Paxton has secured a temporary restraining order against Samsung, blocking the company from continuing to collect data through its smart TVs’ Automated Content Recognition technology.
The ACR system captured screenshots of what users were watching every 500 milliseconds, according to the state’s la … ⌘ Read more
Linux Kernel Considers Linking The Relocatable x86 Kernel As PIE In 2026
To allow for additional security hardening of the Linux kernel, a patch series has been updated more than one year later to link the relocatable x86_64 kernel as Position Independent Executable (PIE) code… ⌘ Read more
DHS Says REAL ID, Which DHS Certifies, Is Too Unreliable To Confirm US Citizenship
An anonymous reader shares a report: Only the government could spend 20 years creating a national ID that no one wanted and that apparently doesn’t even work as a national ID. But that’s what the federal government has accomplished with the REAL ID, which the Department of Homeland Security (DHS) now considers un … ⌘ Read more
European Space Agency Acknowledges Another Breach as Criminals Claim 200 GB Data Haul
The European Space Agency has acknowledged yet another security incident after a cybercriminal posted an offer on BreachForums the day after Christmas claiming to have stolen over 20GB of data including source code, confidential documents, API tokens and credentials.
The attacker claims they gained access … ⌘ Read more
Cyber expert gets rare Australian visa by hacking the government
The self-taught British security researcher found a unique way to beat 99 per cent rejection odds for the elite visa. ⌘ Read more
Life in a Shrinking Japan
Japan’s demographic transformation is no longer a distant forecast but an accelerating reality, and the National Institute of Population and Social Security Research now estimates the country’s population will fall to roughly 100 million by 2050 – more than 20 million fewer people than today.
The share of residents aged 65 and over stood at 29.4% as of September and is expected to reach 37.1% by midcentury. The dependenc … ⌘ Read more
Trump Administration To Overhaul Lottery System For H-1B Visas
The Trump administration has announced it would replace the lottery programme used to grant H-1B visas for skilled foreign workers with a system that prioritises higher-paid individuals. From a report: The Department of Homeland Security said it would begin to implement a “weighted” selection process to give an advantage to higher-skilled and higher- … ⌘ Read more
Nuclear Developer Proposes Using Navy Reactors For Data Centers
An anonymous reader quotes a report from the Financial Post: A Texas power developer is proposing to repurpose nuclear reactors from Navy warships to power the United States grid as the Trump administration pushes to secure massive amounts of energy for the artificial intelligence boom. HGP Intelligent Energy LLC filed an application to the Ene … ⌘ Read more
FCC Bans Foreign-Made Drones Over National Security, Spying Concerns
The FCC has banned approval of new foreign-made drones and components, citing “an unacceptable risk” to national security. The move will most heavily impact DJI but it “does not affect drones or drone components that are currently sold in the United States.” Reuters reports: The tech was placed on the commission’s “Covered List,” barring D … ⌘ Read more
Visa Says AI Will Start Shopping and Paying For You In 2026
BrianFagioli writes: Visa says it has completed hundreds of secure, AI-initiated transactions with partners, arguing this proves agent driven shopping is ready to move beyond experiments. The company believes 2025 will be the last full year most consumers manually check out, with AI agents handling purchases at scale by the 2026 holiday season. Nearly half of U … ⌘ Read more
The U.S. Could Ban Chinese-Made Drones Used By Police Departments
Tuesday the White House faces a deadline to decide “whether Chinese drone maker DJI Technologies poses a national security threat,” reports Bloomberg. But their article notes it’s “a decision with the potential to ground thousands of machines deployed by police and fire departments across the US.”
One person making the case against the drones is … ⌘ Read more
Parrot OS Switches to KDE Plasma Desktop
“Yet another distro is making the move to the KDE Plasma desktop,” writes Linux magazine.
“Parrot OS, a security-focused Linux distribution, is migrating from MATE to KDE Plasma, starting with version 7.0, now available in beta.”
Based on Debian 13, Parrot OS’s goal is a shift toward “modernization, focusing on clearing technical debt and future-proofing the system.” One big under-the-hood c … ⌘ Read more
Google Sues SerpApi Over Scraping and Reselling Search Data
An anonymous reader quotes a report from Search Engine Land: Google said today that it is suing SerpApi, accusing the company of bypassing security protections to scrape, harvest, and resell copyrighted content from Google Search results. The allegations: Google said SerpApi:
-Circumvented Google’s security measures and industry-standard crawling controls. … ⌘ Read more
Airbus Moving Critical Systems Away From AWS, Google, and Microsoft Citing Data Sovereignty Concerns
Airbus is preparing to tender a major contract to move mission-critical systems like ERP, manufacturing, and aircraft design data onto a digitally sovereign European cloud, citing national security concerns and fears around U.S. extraterritorial laws like the CLOUD Act. “I need a so … ⌘ Read more
Cloud Hypervisor 50 Released With QCOW2 Compression, Performance Improvements
Cloud Hypervisor 50.0 is out today for this cloud-minded, security-focused and Rust-based hypervisor. Cloud Hypervsior began as an open-source Intel project while in more recent times has shifted to being largely maintained by Microsoft, Crusoe, Cyberus Tech, Rivos, and others… ⌘ Read more
North Korean Infiltrator Caught Working In Amazon IT Department Thanks To Lag
An anonymous reader quotes a report from Tom’s Hardware: A North Korean imposter was uncovered, working as a sysadmin at Amazon U.S., after their keystroke input lag raised suspicions with security specialists at the online retail giant. Normally, a U.S.-based remote worker’s computer would send keystroke data within tens … ⌘ Read more
Man Boards Heathrow Flight Without Passport or Ticket
Bruce66423 writes: A man boarded a flight at Heathrow without a ticket, boarding pass or passport. ‘The unnamed individual walked onto the 7.20am British Airways (BA) flight to Oslo, Norway, on Saturday after tailgating other passengers through security and evading checks at the departure gate.
An aviation expert described the incident as a “significant lapse in sec … ⌘ Read more
How China Built Its ‘Manhattan Project’ To Rival the West in AI Chips
Chinese scientists have built a working prototype of an extreme ultraviolet lithography machine in a high-security Shenzhen laboratory, a development that represents exactly what Washington has spent years and multiple rounds of export controls trying to prevent: China’s path toward semiconductor independence and an end to the West’s monopoly o … ⌘ Read more
Browser Extensions With 8 Million Users Collect Extended AI Conversations
An anonymous reader shares a report: Browser extensions with more than 8 million installs are harvesting complete and extended conversations from users’ AI conversations and selling them for marketing purposes, according to data collected from the Google and Microsoft pages hosting them.
Security firm Koi discovered the eight ex … ⌘ Read more
SoundCloud Confirms Breach After Member Data Stolen, VPN Access Disrupted
An anonymous reader quotes a report from BleepingComputer: Audio streaming platform SoundCloud has confirmed that outages and VPN connection issues over the past few days were caused by a security breach in which threat actors stole a database containing user information. The disclosure follows widespread reports over the past four … ⌘ Read more
Torvalds On Linux Security Modules: “I Already Think We Have Too Many Of Those Pointless Things”
Stemming from a security researcher and his team proposing a new Linux Security Module (LSM) three years ago and it not being accepted to the mainline kernel, he raised issue over the lack of review/action to Linus Torvalds and the mailing lists. In particular, seeking more guidance for how new LSMs should be introduced and raised the possibility of taking the issue to the Linux Foundation Technical Advisory Board … ⌘ Read more
Security Researcher Found Critical Kindle Vulnerabilities That Allowed Hijacking Amazon Accounts
The Black Hat Europe hacker conference in London included a session titled “Don’t Judge an Audiobook by Its Cover” about a two critical (and now fixed) flaws in Amazon’s Kindle. The Times reports both flaws were discovered by engineering analyst Valentino Ricotta (from the cybersecurit … ⌘ Read more
Like Australia, Denmark Plans to Severely Restrict Social Media Use for Teenagers
“As Australia began enforcing a world-first social media ban for children under 16 years old this week, Denmark is planning to follow its lead,” reports the Associated Press, “and severely restrict social media access for young people.”
The Danish government announced last month that it had secured an agreement b … ⌘ Read more
Entry-Level Tech Workers Confront an AI-Fueled Jobpocalypse
AI “has gutted entry-level roles in the tech industry,” reports Rest of World.
One student at a high-ranking engineering college in India tells them that among his 400 classmates, “fewer than 25% have secured job offers… there’s a sense of panic on the campus.”
Students at engineering colleges in India, China, Dubai, and Kenya are facing a “jobpo … ⌘ Read more
“If COP30 cannot deliver the mechanisms for decarbonisation or social protection, then the hope must lie in movements of people: workers, peasants, indigenous people, women, youth, and the urban poor. Outside of a global mass movement rooted in national realities, the necessary steps to confront the climate crisis will not occur. Yet such a movement cannot be built if it fails to address the immediate needs of the working classes and the poor. The fight for climate protection and ecological justice must therefore begin with the fight for life itself — for clean water, decent housing, jobs, food, and security against the elements.
Right-wing climate denialists exploit the desperation of the poor to drive a wedge between ordinary people and climate action. They present environmentalism as a threat to livelihoods rather than the path to survival. To win the majority, our movement must link ecological transformation with social justice. We must demand the redistribution of wealth and power away from the billionaire class, big tech, and ruling elites who plunder the planet for profit.”
Bill Gates’ Daughter Secures $30 Million For AI App Built In Stanford Dorm
Phoebe Gates, Bill Gates’ youngest daughter, has raised $30 million for the AI shopping app she built in her Stanford dorm room with classmate Sophia Kianni. The app is called Phia and is pitched as a way to simplify price comparison and secondhand shopping. “Its AI-powered search engine – available as an app and as a browser e … ⌘ Read more
Berlin Approves New Expansion of Police Surveillance Powers
Berlin’s regional parliament has passed a far-reaching overhaul of its “security” law, giving police new authority to conduct both digital and physical surveillance. From a report: The CDU-SPD coalition, supported by AfD votes, approved the reform of the General Security and Public Order Act (ASOG), changing the limits that once protected Berliners from int … ⌘ Read more
Linux Patches Fix eMMC Secure Erase Of 1GB Taking ~10 Minutes To Now Just 2 Seconds
A new patch series from an NXP engineer optimizes the secure erase performance for certain Kingston eMMC devices. Currently with the Linux kernel performing a secure erase on 1GB of data can take around ten minutes. With these new patches that 1GB secure erase can be done in around two seconds… ⌘ Read more
Cadmium Zinc Telluride: The Wonder Material Powering a Medical ‘Revolution’
Cadmium zinc telluride (CZT), a hard-to-manufacture semiconductor produced by only a handful of companies, is enabling a quiet revolution in medical imaging, science, and security by delivering faster scans, lower radiation doses, and far more precise X-ray and gamma-ray detection. “You get beautiful pictures from this scann … ⌘ Read more
Over 10,000 Docker Hub Images Found Leaking Credentials, Auth Keys
joshuark shares a report from BleepingComputer: More than 10,000 Docker Hub container images expose data that should be protected, including live credentials to production systems, CI/CD databases, or LLM model keys. After scanning container images uploaded to Docker Hub in November, security researchers at threat intelligence company Flare foun … ⌘ Read more
Microsoft Is Back To Working On “Hornet” Security For eBPF Programs On Linux
Earlier in the year Microsoft proposed the “Hornet” Linux security module to provide signature verification capabilities for eBPF programs to provide for better system security. It’s been months since hearing anything more about it and not being merged, but yesterday they “reintroduced” it to the Linux kernel community… ⌘ Read more