RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

cybersecuritycloud

Chinese APT Weaponizes Legitimate Cloud Services for Mongolia Espionage Campaign

A Chinese advanced persistent threat group is running a surveillance operation against Mongolian targets by piggybacking on trusted cloud infrastructure rather

via Dark Reading ·
cybersecuritysupply-chain

Chinese phishing campaign tricks NASA staff to reach U.S. defense software

A targeted phishing operation attributed to Chinese actors successfully compromised NASA employees as part of a broader effort to access U.S. defense software.

via The Hacker News ·
cybersecuritypolicy

DOJ Dismantles Myanmar-Based Fraud Ring Preying on American Victims

US authorities have disrupted a Myanmar-based criminal operation that targeted American citizens through financial fraud schemes. The takedown reflects the grow

via Dark Reading ·
cybersecuritypolicy

DORA Article 9 turns credential hygiene into a binding EU financial control

The Digital Operational Resilience Act, in force across the EU since January 2025, recasts credential management as a supervised financial risk control rather t

via BleepingComputer ·
cybersecuritymalware

FIRESTARTER implant persists on federal Cisco Firepower device through patching

A backdoor tracked as FIRESTARTER was recovered from a Cisco Firepower appliance in use at a U.S. federal agency, with the implant demonstrating the ability to

via The Hacker News ·
cybersecuritysupply-chain

Glasswing Locks Down the Code, But Your Stack's Exposure Is Still Yours to Own

Glasswing's pitch centers on hardening application code itself, closing off a class of vulnerabilities at the source layer. That narrows one attack surface, but

via Dark Reading ·
privacypolicy

Hidden Bluetooth tracker in postcard exposes Dutch warship's location

A journalist at Dutch outlet Omroep Gelderland followed a public mailing address on the Dutch government website and slipped a Bluetooth tracker inside a postca

via Schneier on Security ·
cybersecuritypolicy

Latin America Overtakes Africa as Most-Attacked Region in Q1 2026

Regional cyberattack rankings shifted this quarter, with Latin America surpassing Africa as the most-targeted region globally. The change reflects a measurable

via Dark Reading ·
cybersecuritymalware

Lazarus Group Pivots ClickFix Social Engineering to macOS Targets

North Korea's Lazarus Group has extended its ClickFix campaign to macOS, expanding a technique previously aimed at Windows users. ClickFix relies on social engi

via Dark Reading ·
identitycybersecurity

Microsoft Entra passkeys land on Windows, closing a gap on unmanaged devices

Microsoft is rolling out Entra passkey support on Windows starting late April, with general availability targeted for mid-June 2026. The feature lets users crea

via BleepingComputer ·
vulnerabilityopen-source

Pack2TheRoot: 12-year-old PackageKit flaw hands local users root on most Linux distros

A high-severity vulnerability in PackageKit, the daemon that brokers software install and update requests across most Linux distributions, lets unprivileged loc

via BleepingComputer ·
aicybersecurity

Project Glasswing: AI Finds the Bugs, But Humans Still Bottleneck the Fix

Project Glasswing demonstrated that AI systems can surface software vulnerabilities at a pace and scale human auditors cannot match. The finding pipeline is no

via The Hacker News ·