RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

aicloud

OpenAI's voice AI stack: how they squeeze latency out of real-time speech

OpenAI's engineering write-up walks through the infrastructure behind its real-time voice models, focused on keeping end-to-end latency low enough for natural c

via Hacker News ·
cybersecuritymalware

Phishing Crews Pivot to Signed RMM Binaries to Slip Past Endpoint Defenses

Attackers are increasingly weaponizing legitimate remote monitoring and management (RMM) tools as the payload of choice in phishing campaigns. Because products

via Dark Reading ·

Polymarket's Oracle Problem: Hairdryers on Weather Sensors and Insider Bets

Prediction market Polymarket lets users wager on real-world events, but the platform's reliance on external truth sources is becoming an attack surface. Verific

via Schneier on Security ·
supply-chainmalware

PyTorch Lightning 2.6.3 on PyPI shipped ShaiWorm credential stealer via import hook

A trojaned build of PyTorch Lightning (version 2.6.3) was published to PyPI carrying a hidden execution chain that fired on import. The chain pulled down the Bu

via BleepingComputer ·
aiopen-source

Quantized Granite 4.1 3B fails the pelican-on-bicycle SVG test across all 21 variants

IBM shipped its Granite 4.1 LLM family under Apache 2.0 in 3B, 8B, and 30B sizes, with training methodology documented by team member Yousaf Shah. Unsloth follo

via Simon Willison ·
malwarecybersecurity

Silver Fox expands ABCDoor campaign to India and Russia via tax-themed phishing

China-linked threat group Silver Fox is running tax-themed phishing waves against organizations in India and Russia, delivering a previously undocumented Python

via The Hacker News ·
cybersecuritymalware

Silver Fox Pivots to Tax-Themed Lures Against India and Russia

The China-aligned Silver Fox crew has expanded its targeting beyond its usual Chinese-speaking victim pool, running tax-themed social engineering campaigns agai

via Dark Reading ·
aitech-culture

Springer Nature retracts widely cited ChatGPT-in-education meta-analysis

Springer Nature has pulled a May 2025 paper in Humanities & Social Sciences Communications that claimed ChatGPT delivered a large positive effect on student lea

via Ars Technica ·
cybersecurityvulnerability

Strix uncovers zero-auth IDOR in DoD contractor's multi-tenant SaaS

An AI-driven security testing tool from Strix surfaced a broken authorization flaw in a DoD-backed startup's multi-tenant platform. The bug allowed cross-tenant

via Hacker News ·
cybersecurityvulnerability

TRE regex engine shrugs off ReDoS attacks that choke Python's re module

Simon Willison built an experimental Python ctypes binding to Ville Laurikari's TRE regex library after noticing antirez had pulled it into Redis. The motivatio

via Simon Willison ·
cybersecuritysupply-chain

Trellix confirms breach after attackers access portion of source code repo

Trellix, the cybersecurity vendor born from the 2021 McAfee Enterprise and FireEye merger, has disclosed unauthorized access to part of its source code reposito

via BleepingComputer ·
cybersecuritymalware

VENOMOUS#HELPER campaign abuses SimpleHelp and ScreenConnect to backdoor 80+ orgs

A phishing operation tracked as VENOMOUS#HELPER has compromised more than 80 organizations, predominantly in the U.S., by weaponizing legitimate Remote Monitori

via The Hacker News ·