RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

cybersecurityprivacy

Rituals breach exposes member data from 41M-strong loyalty database

Dutch cosmetics retailer Rituals confirmed that an attacker exfiltrated personal records from its My Rituals loyalty program database earlier this month. Expose

via BleepingComputer ·
aicybersecurity

The AI Agent Authority Gap: Why Continuous Observability Must Drive Runtime Decisions

Enterprise AI agents are being granted production-level permissions—executing trades, modifying records, calling internal APIs—without the runtime controls that

via The Hacker News ·
cybersecuritymalware

ThreatsDay Roundup: $290M DeFi Heist, macOS LotL Abuse, ProxySmart SIM Farms

The latest ThreatsDay bulletin spans a wide threat surface in a single news cycle. A $290M DeFi exploit dominates the financial-crime beat, underscoring that on

via The Hacker News ·
cybersecuritymalware

Trigona ransomware deploys custom exfiltration tool to dodge detection

Trigona ransomware operators have shifted from off-the-shelf utilities like Rclone and MegaSync to a bespoke command-line tool called uploader_client.exe, accor

via BleepingComputer ·
cybersecuritymalware

Tropic Trooper Weaponizes SumatraPDF and GitHub to Drop AdaptixC2

The Tropic Trooper APT group is abusing a trojanized build of the open-source SumatraPDF reader as a delivery vehicle for AdaptixC2, a newer command-and-control

via The Hacker News ·
cybersecuritymalware

UNC6692 Weaponizes Teams Helpdesk Impersonation to Drop SNOW Malware

A threat cluster tracked as UNC6692 is abusing Microsoft Teams as the initial access channel, posing as internal IT support staff to coax targets into executing

via The Hacker News ·
tech-culture

Vast unveils custom flight suits and Swiss watch for Haven-1 private station crews

Vast, the company racing to deploy the first commercial space station, has introduced a purpose-built two-piece astronaut flight suit and certified a custom Swi

via Ars Technica ·
cybersecurityai

Webinar pitch: defenders need AI-speed response to automated exploit chains

The Hacker News is promoting a vendor webinar framed around a now-familiar asymmetry: attackers are stitching together reconnaissance, vulnerability triage, and

via The Hacker News ·
privacyvulnerability

Apple patches iOS flaw that preserved deleted Signal notifications for forensic recovery

A bug in iOS retained notification data even after users deleted the underlying messages, giving anyone with physical device access — including forensic tools u

via BleepingComputer ·
aitech-culture

Ars Technica publishes its newsroom AI policy: no AI-generated sources, no synthetic documentation

Ars Technica has formalized and published the AI rules that have governed its newsroom since generative tools became available. The core prohibition: AI cannot

via Ars Technica ·
cybersecurityvulnerability

CISA Puts BlueHammer Zero-Day on KEV, Gives Agencies Three Weeks to Patch

CISA added the BlueHammer flaw to its Known Exploited Vulnerabilities catalog after confirming active zero-day exploitation in the wild. Federal civilian agenci

via BleepingComputer ·
policytech-culture

Class action: Nintendo plans to keep tariff refunds instead of passing them to buyers

A class action filed in the Western District of Washington accuses Nintendo of America of positioning itself to collect tariff refunds from the federal governme

via Ars Technica ·