RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

cybersecuritymalware

DarkSword: Leaked iOS Zero-Click Chain Spreads from State Actors to the Wild

Google's Threat Intelligence Group attributes DarkSword, a full-chain iOS exploit stitching together six zero-days, to likely government developers. The chain w

via Schneier on Security ·
aiopen-source

Datasette-llm 0.1a7 adds per-model default option config

Simon Willison shipped a small but useful update to datasette-llm, the plugin layer that lets Datasette plugins call language models. The 0.1a7 release introduc

via Simon Willison ·
open-sourceprivacy

Datasette plugin lets sites override default no-referrer policy for OSM tiles

Simon Willison debugged broken OpenStreetMap tiles on the Datasette global-power-plants demo and traced the issue to two separate problems. A CAPTCHA he had rec

via Simon Willison ·
cybersecurityvulnerability

Edge Leaves Saved Passwords Sitting in Process Memory

Microsoft Edge retains saved credentials in plaintext within its running process memory, where any local actor with sufficient privileges — malware, a compromis

via Dark Reading ·
privacypolicy

FTC settlement bars Kochava from selling precise location data without consent

The FTC has reached a proposed settlement with Idaho-based data broker Kochava and its subsidiary Collective Data Solutions, ending a four-year case that began

via BleepingComputer ·
cybersecurityvulnerability

Germany's .de TLD reportedly disrupted by DNSSEC chain-of-trust failure

Germany's national top-level domain experienced a resolution outage tied to DNSSEC validation. Verisign Labs' DNSSEC analyzer output shows the chain-of-trust tr

via Hacker News ·
aiopen-source

llm-echo 0.5a0 adds thinking-block simulation for LLM 0.32a0 testing

Simon Willison shipped version 0.5a0 of llm-echo, a plugin that registers a fake "echo" model inside the LLM CLI tool. The model performs no inference — it simp

via Simon Willison ·
vulnerabilitycybersecurity

MetInfo CMS Flaw CVE-2026-29014 Under Active Exploitation for Unauthenticated RCE

A critical PHP code injection vulnerability in MetInfo CMS versions 7.9 through 8.1, tracked as CVE-2026-29014 with a CVSS score of 9.8, is being actively explo

via The Hacker News ·
cybersecuritypolicy

Middle East cyber conflict expands, with UAE emerging as a primary target

Cyber operations across the Middle East are widening in scope, and the UAE is taking a disproportionate share of the activity. The shift reflects the country's

via Dark Reading ·
aipolicy

Musk's lawyers grill OpenAI's Brockman over diary entries revealing profit motives

OpenAI president Greg Brockman took the stand in Elon Musk's lawsuit against OpenAI, where Musk's attorney Steven Molo forced him to read aloud personal journal

via Ars Technica ·
identitycybersecurity

OAuth Tokens Are the Unwatched Back Door: Drift Breach Shows the Cost

OAuth grants issued to AI tools, automation platforms, and productivity apps don't expire, don't reset when passwords change, and rarely sit under any centraliz

via The Hacker News ·
aipolicy

Pennsylvania sues Character.AI over chatbot posing as licensed psychiatrist

Pennsylvania's Department of State and Board of Medicine have sued Character.AI, alleging the platform hosts chatbot characters that impersonate licensed medica

via Ars Technica ·