RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

cybersecurityvulnerability

CISA Gives Federal Agencies Days to Patch Actively Exploited Ivanti EPMM RCE Flaw

A critical unauthenticated remote code execution vulnerability in Ivanti Endpoint Manager Mobile (CVE-2026-1340) has been under active exploitation since Januar

via BleepingComputer ·
aivulnerability

Claude Mythos surfaces thousands of zero-days in autonomous sweep

Anthropic's Claude Mythos, an autonomous vulnerability-discovery agent built on the Claude model family, has reportedly identified thousands of previously unkno

via The Hacker News ·
cybersecurityvulnerability

Fancy Bear hijacks 18,000 SOHO routers' DNS to steal Microsoft OAuth tokens

Russia's GRU-linked APT28 (Forest Blizzard) compromised more than 18,000 unsupported or unpatched Mikrotik and TP-Link SOHO routers at the peak of a December 20

via Krebs on Security ·
cybersecuritycloud

Full Sail University Adding IBM Cyber Defense Range to Campus

Full Sail University is launching an on-campus IBM Cyber Defense Range, built on AWS infrastructure and powered by Cloud Range's simulation platform. The facili

via Dark Reading ·
cybersecuritymalware

Germany IDs REvil/GandCrab kingpin 'UNKN' as 31-year-old Russian Daniil Shchukin

Germany's Federal Criminal Police (BKA) have publicly named Daniil Maksimovich Shchukin, a 31-year-old from Krasnodar, Russia, as the operator behind the handle

via Krebs on Security ·
cybersecuritycryptography

Google Sets 2029 Deadline for Full Post-Quantum Cryptography Migration

Google has committed to completing a full transition to post-quantum cryptography by 2029. The deadline isn't driven by an imminent quantum threat - no cryptogr

via Schneier on Security ·
cybersecurityai

HackerOne Halts Bug Bounties Over AI Remediation Risks

HackerOne has temporarily paused its bug bounty programs due to concerns over the reliability of AI-driven vulnerability remediation. The platform observed a su

via Dark Reading ·
cybersecuritymalware

Hackers Use Emojis to Bypass Cybersecurity Defenses

Cybercriminals are increasingly leveraging emojis in malicious communications to evade detection by security tools that traditionally scan for known malware sig

via Dark Reading ·
privacypolicy

Hong Kong law compels travelers to surrender device passwords at the border

Hong Kong authorities revised enforcement rules under the National Security Law on March 23, 2026, granting police the power to demand passwords and decryption

via Schneier on Security ·
cybersecurityvulnerability

Iran-Linked APT Hits US Critical Infrastructure PLCs Amid Escalating Conflict

An Iranian government-affiliated threat group has been actively disrupting programmable logic controllers (PLCs) across US critical infrastructure since at leas

via Ars Technica ·
identitycybersecurity

IVIP: A New Category Pitches Visibility as the Cure for IAM Sprawl

Identity and access management has fragmented across SaaS, cloud, and on-prem systems faster than most organizations can map. The result is an attack surface de

via The Hacker News ·
privacycybersecurity

LinkedIn's Silent Browser Extension Scanning Triggers Two Privacy Lawsuits

LinkedIn is facing two class action lawsuits after reports emerged that it scans users' installed browser extensions without clear disclosure. The suits allege

via Ars Technica ·