RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

tech-culturepolicy

Why Alzheimer's Research Keeps Stalling Despite Decades of Investment

Freakonomics examines why Alzheimer's disease has proven so resistant to therapeutic progress despite massive funding and scientific attention. The dominant amy

via Hacker News ·
cybersecurityidentity

ADT Confirms Breach After ShinyHunters Vishing Hit Okta SSO, Salesforce Data Stolen

ADT detected unauthorized access to customer data on April 20 and has now confirmed the intrusion after ShinyHunters listed the company on its leak site claimin

via BleepingComputer ·
cybersecurityvulnerability

Firestarter backdoor on Cisco firewalls survives reboots, patches, and firmware updates

CISA and the UK's NCSC are warning about Firestarter, a custom ELF backdoor planted on Cisco Firepower and Secure Firewall appliances running ASA or FTD. The im

via BleepingComputer ·
tech-culture

Squid Genomes Reveal Deep-Sea Refuges Enabled Survival Through Mass Extinctions

Newly sequenced cephalopod genomes paired with global datasets indicate squid and cuttlefish originated in deep ocean environments more than 100 million years a

via Schneier on Security ·
aidevops

Willison ships a millisecond-to-time converter to stop doing the math himself

Simon Willison published a small utility that converts milliseconds into seconds and minutes, built because LLM tooling routinely emits prompt durations in raw

via Simon Willison ·
cybersecurityvulnerability

10,500 Zimbra servers still exposed as CISA confirms active XSS exploitation

Shadowserver reports more than 10,500 internet-facing Zimbra Collaboration Suite instances remain unpatched against CVE-2025-48700, a zero-click XSS flaw in the

via BleepingComputer ·
malwarecybersecurity

26 Fake Crypto Wallet Apps Slipped Past Apple's App Store Review

Researchers have flagged 26 fraudulent cryptocurrency wallet applications that cleared Apple's notoriously strict App Store review process. The apps impersonate

via The Hacker News ·
aicybersecurity

AI Agent Memory Is the New Attack Surface — and It's Barely Defended

Persistent memory is what makes modern AI agents useful across sessions, but it is also what makes them durably exploitable. An attacker who plants a poisoned i

via Dark Reading ·
cybersecurityai

AI-Generated Phishing Tops Attacker Toolkits as Defenders Scramble

Phishing remains the dominant intrusion vector, but generative AI has sharpened its edge. Attackers now produce grammatically flawless, context-aware lures at s

via Dark Reading ·
supply-chainmalware

Bitwarden CLI npm package hijacked in Checkmarx-linked supply chain attack

A malicious version 2026.4.0 of the @bitwarden/cli npm package sat in the registry for roughly 90 minutes on April 22 before being pulled. The tampered package

via BleepingComputer ·
supply-chaincybersecurity

Bitwarden CLI Pulled Into Ongoing npm Supply Chain Campaign Tracked by Checkmarx

A malicious package impersonating the Bitwarden command-line client has surfaced as the latest artifact in a supply chain campaign that Checkmarx researchers ha

via The Hacker News ·
cybersecurityidentity

BlackFile extortion crew uses vishing to plunder Salesforce and SharePoint data

A financially motivated group calling itself BlackFile — also tracked as CL-CRI-1116, UNC6671, and Cordial Spider — has been hitting retail and hospitality targ

via BleepingComputer ·