RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

cybersecuritycloud

Leaked AWS keys fuel surge in Amazon SES phishing that sails past SPF, DKIM, DMARC

Kaspersky reports a sharp rise in phishing campaigns sent through Amazon Simple Email Service. Because SES is a trusted sender, messages pass SPF, DKIM, and DMA

via BleepingComputer ·
tech-culturepolicy

NBER paper probes whether staying employed actually slows cognitive decline

A new NBER working paper examines a long-standing question in labor and aging economics: does continued employment preserve cognitive function in older workers,

via Hacker News ·
open-sourcetech-culture

Notepad++ creator disowns unauthorized "Notepad++ for Mac" port

Don Ho, the original author and maintainer of Notepad++, has publicly disavowed a third-party macOS release marketed as "Notepad++ for Mac." The app, built by A

via Ars Technica ·
aicloud

OpenAI's voice AI stack: how they squeeze latency out of real-time speech

OpenAI's engineering write-up walks through the infrastructure behind its real-time voice models, focused on keeping end-to-end latency low enough for natural c

via Hacker News ·
cybersecuritymalware

Phishing Crews Pivot to Signed RMM Binaries to Slip Past Endpoint Defenses

Attackers are increasingly weaponizing legitimate remote monitoring and management (RMM) tools as the payload of choice in phishing campaigns. Because products

via Dark Reading ·

Polymarket's Oracle Problem: Hairdryers on Weather Sensors and Insider Bets

Prediction market Polymarket lets users wager on real-world events, but the platform's reliance on external truth sources is becoming an attack surface. Verific

via Schneier on Security ·
supply-chainmalware

PyTorch Lightning 2.6.3 on PyPI shipped ShaiWorm credential stealer via import hook

A trojaned build of PyTorch Lightning (version 2.6.3) was published to PyPI carrying a hidden execution chain that fired on import. The chain pulled down the Bu

via BleepingComputer ·
aiopen-source

Quantized Granite 4.1 3B fails the pelican-on-bicycle SVG test across all 21 variants

IBM shipped its Granite 4.1 LLM family under Apache 2.0 in 3B, 8B, and 30B sizes, with training methodology documented by team member Yousaf Shah. Unsloth follo

via Simon Willison ·
malwarecybersecurity

Silver Fox expands ABCDoor campaign to India and Russia via tax-themed phishing

China-linked threat group Silver Fox is running tax-themed phishing waves against organizations in India and Russia, delivering a previously undocumented Python

via The Hacker News ·
cybersecuritymalware

Silver Fox Pivots to Tax-Themed Lures Against India and Russia

The China-aligned Silver Fox crew has expanded its targeting beyond its usual Chinese-speaking victim pool, running tax-themed social engineering campaigns agai

via Dark Reading ·
aitech-culture

Springer Nature retracts widely cited ChatGPT-in-education meta-analysis

Springer Nature has pulled a May 2025 paper in Humanities & Social Sciences Communications that claimed ChatGPT delivered a large positive effect on student lea

via Ars Technica ·
cybersecurityvulnerability

Strix uncovers zero-auth IDOR in DoD contractor's multi-tenant SaaS

An AI-driven security testing tool from Strix surfaced a broken authorization flaw in a DoD-backed startup's multi-tenant platform. The bug allowed cross-tenant

via Hacker News ·