RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

cybersecuritymalware

MuddyWater Hides Iranian Espionage Behind Chaos Ransomware Brand via Teams Phishing

Rapid7 attributes an early-2026 intrusion to Iran's MuddyWater group operating under the cover of the Chaos ransomware-as-a-service brand. Operators initiated c

via The Hacker News ·
cybersecuritymalware

New bypass punches through Chrome's app-bound encryption for cookie theft

Researchers have demonstrated another technique that defeats Google Chrome's app-bound encryption, the protection Google introduced to stop infostealers from li

via Dark Reading ·
cybersecurityvulnerability

PAN-OS Captive Portal zero-day exploited since April 9 by suspected state actors

Palo Alto Networks disclosed CVE-2026-0300, an unauthenticated remote code execution flaw in the PAN-OS User-ID Authentication Portal caused by a buffer overflo

via BleepingComputer ·
tech-culturepolicy

Permacomputing: 10 Principles for Sustainable, Resilient Digital Practice

Permacomputing borrows from permaculture's ethics of Earth Care, People Care, and Fair Share, translating them into ten design principles aimed at reducing the

via Hacker News ·
cybersecurityvulnerability

Rowhammer Jumps to NVIDIA GPUs, Yielding Full Host Compromise

Three independent research teams have demonstrated Rowhammer attacks against NVIDIA Ampere GPUs that escalate from GDDR memory bitflips to full control of the h

via Schneier on Security ·
tech-culture

SpaceX dials back Falcon 9 cadence as Starship takes over the manifest

SpaceX's Falcon 9 launch rate is starting to ease off after years of relentless growth. The company flew 165 Falcon 9 missions in 2025, up from 134 in 2024 and

via Ars Technica ·
cybersecuritytech-culture

The Hacker News Opens Submissions for CyberStars Awards 2026

The Hacker News has launched the Cybersecurity Stars Awards 2026, a global recognition program aimed at surfacing the often-invisible work behind successful cyb

via The Hacker News ·
supply-chainmalware

Three PyPI packages drop ZiChatBot malware that uses Zulip chat APIs as C2

Kaspersky uncovered three malicious PyPI packages — uuid32-utils, colorinal, and termncolor — uploaded in a one-week window in July 2025 and collectively pulled

via The Hacker News ·
tech-cultureai

TSMC locks in 30-year offshore wind deal as Taiwan's gas supply buckles

TSMC signed a 30-year power purchase agreement covering the entire output of Northland Power's Hai Long offshore wind project, more than 1 gigawatt across three

via Ars Technica ·
vulnerabilityopen-source

Twelve critical vm2 sandbox escapes expose Node.js hosts to RCE

Researchers disclosed twelve critical vulnerabilities in vm2, the popular Node.js library used to run untrusted JavaScript inside a proxied sandbox. Every flaw

via The Hacker News ·
cybersecuritysupply-chain

Two Decades of Cyber: 20 Inflection Points From Stuxnet to ChatGPT

Dark Reading frames the modern cybersecurity era through 20 pivotal events, anchored at one end by Stuxnet's 2010 demonstration that code could physically destr

via Dark Reading ·
open-sourcetech-culture

Valve drops Steam Controller CAD files under CC non-commercial license

Valve has published CAD files for its newly shipping Steam Controller and Puck, including .STP and .STL exports of the external shell plus engineering diagrams

via Hacker News ·