Search the Portal

Recent Articles

SEP29
DARPA Selects Xint to Use AI in Securing Military Messaging Apps

The AIxCC competition winner will analyze messaging app code and compiled binaries for vulnerabilities, with technology that could also help commercial customers secure their software. The post DARPA Selects Xint to Use AI in Securing Military Messaging Apps appeared first on SecurityWeek.

Security Week by Kevin Townsend
SEP29
New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel The post New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks appeared first on SecurityWeek.

Security Week by Eduard Kovacs
SEP29
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre-v2 variant has been codenamed Branch Target Reuse (BTR). "The key insight is that, while modern CPUs

The Hacker News by info@thehackernews.com (The Hacker News)
SEP29
RemoteThreat Launches With $7 Million for Offensive Operations Platform

The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe. The post RemoteThreat Launches With $7 Million for Offensive Operations Platform appeared first on SecurityWeek.

Security Week by SecurityWeek News
SEP29
Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company

The Hacker News by info@thehackernews.com (The Hacker News)
SEP29
101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical

The Hacker News by info@thehackernews.com (The Hacker News)
SEP29
Reco Raises $55 Million for Agentic Security

The company will use the funds to expand its sales, partnerships, channels, and customer support teams. The post Reco Raises $55 Million for Agentic Security appeared first on SecurityWeek.

Security Week by Ionut Arghire
SEP29
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands. The post Hackers Use ChatGPT Custom GPTs in ClickFix Attacks appeared first on SecurityWeek.

Security Week by Ionut Arghire
SEP29
Pentagon Personnel Agency Data Breach Impacts 3 Million People

The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense. The post Pentagon Personnel Agency Data Breach Impacts 3 Million People appeared first on SecurityWeek.

Security Week by Eduard Kovacs
SEP29
Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks

Rig provides an identity dependencies graph to distinguish between legitimate users and rogue AI agents The post Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks appeared first on SecurityWeek.

Security Week by Kevin Townsend
SEP29
Four Cyber Threats Harboring Big Plans for the Future

- AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. The post Four Cyber Threats Harboring Big Plans for the Future appeared first on SecurityWeek.

Security Week by Steve Durbin
SEP29
OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training

The GPT-6.1 Astra model was slated to debut in ChatGPT and Codex in October, but it fell short of expectations. The post OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training appeared first on SecurityWeek.

Security Week by Eduard Kovacs
SEP29
Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation

Pepijn van der Stap was convicted in 2023 for hacking multiple organizations, stealing their data, and extorting them. The post Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation appeared first on SecurityWeek.

Security Week by Ionut Arghire
SEP29
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday. Police said the individual is expected to appear before the

The Hacker News by info@thehackernews.com (The Hacker News)
SEP29
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and

The Hacker News by info@thehackernews.com (The Hacker News)