RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

cybersecuritysupply-chain

SMS blasters, npm brandsquatting, and 3.4M exposed RDP/VNC servers headline weekly threat roundup

Canadian authorities arrested three men running an SMS blaster — a fake cellular tower that forces nearby phones to connect and delivers phishing texts imperson

via The Hacker News ·
cybersecuritymalware

Sygnia, DigitalMint insiders get 4 years for moonlighting as BlackCat affiliates

Two incident response professionals who were supposed to defend victims instead joined the attackers. Ryan Clifford Goldberg, a former Sygnia IR manager, and Ke

via BleepingComputer ·
supply-chainmalware

TeamPCP hijacks SAP npm packages in scaled-down Shai-Hulud-style worm attack

A threat actor tracking as TeamPCP compromised npm packages tied to SAP, deploying a self-propagating payload that researchers are calling a 'Mini Shai-Hulud' d

via Dark Reading ·
policytech-culture

Trump pulls Means surgeon general pick, taps Fox News radiologist Saphier

Trump withdrew Casey Means's stalled surgeon general nomination and replaced her with Nicole B. Saphier, a Memorial Sloan Kettering breast radiologist, Fox News

via Ars Technica ·
aicybersecurity

UK AISI: GPT-5.5 matches Claude Mythos on vuln-finding, and it's shipping now

The UK's AI Security Institute has published its evaluation of OpenAI's GPT-5.5, focusing on the model's ability to discover security vulnerabilities. AISI prev

via Simon Willison ·
devopsidentity

Windows 11 admins get dynamic uninstall list for preinstalled Store apps

Microsoft has expanded its RemoveDefaultMicrosoftStorePackages policy so IT admins can specify any preinstalled MSIX/APPX app for removal by Package Family Name

via BleepingComputer ·
cybersecurityvulnerability

Windows 11 KB5083631 preview ships Xbox mode, hardened batch file execution

Microsoft pushed the KB5083631 optional preview to Windows 11 24H2 and 25H2, bumping builds to 26100.8328 and 26200.8328 with 34 non-security changes destined f

via BleepingComputer ·
cybersecurityvulnerability

Windows 11 KB5083769 update breaks third-party backup tools via VSS timeout

Microsoft's April 2026 KB5083769 security update is breaking backup software on Windows 11 24H2 and 25H2 by causing Volume Shadow Copy Service snapshots to time

via BleepingComputer ·
aiopen-source

Zig creator: LLM-assisted PRs leave a 'digital smell' maintainers can detect

Andrew Kelley, creator of the Zig programming language, pushed back on the assumption that maintainers can't distinguish AI-generated contributions from human o

via Simon Willison ·
aivulnerability

AI Agent Surfaces 38 Bugs in OpenEMR, Exposing Health Record Attack Surface

An AI-driven code analysis run against OpenEMR, a widely deployed open-source electronic health record platform, surfaced 38 distinct security flaws. The findin

via Dark Reading ·
aivulnerability

AI-Assisted Reverse Engineering Surfaces High-Severity GitHub Flaw

Researchers leveraged AI tooling to reverse engineer GitHub internals and uncover a high-severity vulnerability in the platform. The approach demonstrates how l

via Dark Reading ·
aicybersecurity

Anthropic's Mythos Disclosure Rattles Japanese Financial Sector

Anthropic's recent disclosure of a Claude-driven autonomous attack campaign — dubbed Mythos — has triggered alarm across Japan's financial services industry. In

via Dark Reading ·