RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

tech-culture

Artemis II Crew Faces Critical 14-Minute Reentry Through Earth's Atmosphere

NASA's Artemis II mission is set to conclude with splashdown off the Southern California coast at 8:07 PM ET Friday. The four astronauts aboard the Orion spacec

via Ars Technica ·
open-sourcedevops

asgi-gzip fix stops SSE streams from being incorrectly compressed

A production Datasette deployment broke when Server-Sent Events responses were being gzip-compressed by the asgi-gzip middleware, which had been extracted from

via Simon Willison ·
supply-chaincybersecurity

Backdoored Smart Slider 3 Pro Plugin Update Pushed via Compromised Nextend Servers

Attackers compromised the update infrastructure of Nextend, the company behind the popular WordPress plugin Smart Slider 3 Pro, to distribute a backdoored versi

via The Hacker News ·
vulnerabilitycybersecurity

BlueHammer Zero-Day Exposes Flaws in Microsoft's Disclosure

The discovery of the BlueHammer exploit, a zero-day vulnerability affecting Windows systems, has highlighted longstanding concerns about Microsoft's bug disclos

via Dark Reading ·
aicybersecurity

Browser Extensions Become Stealth AI Pipeline, Bypassing Enterprise Controls

Browser extensions have quietly become one of the largest unmanaged channels through which employees feed corporate data into AI systems. While security teams h

via The Hacker News ·
cybersecuritypolicy

Ceasefires Have Little Effect on Slowing Nation-State Cyber Operations

Historical patterns show that diplomatic ceasefires and peace agreements between nations do not meaningfully reduce cyber operations. State-sponsored hacking ca

via Dark Reading ·
cybersecurityidentity

Chrome 146 Introduces Device-Bound Session Credentials to Combat Cookie Theft

Google is shipping Device Bound Session Credentials (DBSC) in Chrome 146 for Windows, a feature designed to neutralize session hijacking attacks that rely on st

via The Hacker News ·
cybersecuritymalware

Chrome 146 ships hardware-bound session cookies to neuter infostealer theft

Chrome 146 on Windows now enforces Device Bound Session Credentials (DBSC), tying authenticated browser sessions to a private key that lives inside the device's

via BleepingComputer ·
cybersecuritysupply-chain

CPUID supply chain breach pushed trojanized CPU-Z and HWMonitor for six hours

Attackers compromised a secondary API at CPUID between April 9 and 10, swapping download links on the official site to point at Cloudflare R2-hosted trojanized

via BleepingComputer ·
privacycybersecurity

Discord's broken support left a hacker extorting kids for 8 days

A 12-year-old who lied about her age to create a Discord account had it hijacked after clicking a phishing link disguised as Discord support. Without two-factor

via Ars Technica ·
vulnerabilitysupply-chain

EngageLab SDK Bug Put 50M Android Users at Risk, Crypto Wallets Hit Hard

A security flaw in the EngageLab SDK - a third-party library integrated into Android applications - reportedly exposed roughly 50 million users, with an estimat

via The Hacker News ·
cybersecuritymalware

Fancy Bear Maintains Aggressive Global Cyber Campaign

Russia's APT28, widely known as Fancy Bear, continues to run persistent cyber-espionage operations targeting governments, defense contractors, and critical infr

via Dark Reading ·