RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

cybersecuritypolicy

Operation PowerOFF Seizes 53 DDoS-for-Hire Domains, Exposes 3M Accounts

International law enforcement coordinated under Operation PowerOFF has seized 53 domains tied to DDoS-for-hire services, commonly known as booters or stressers.

via The Hacker News ·
cybersecuritymalware

Payouts King ransomware hides payloads inside QEMU VMs to evade endpoint scans

Sophos has documented two active campaigns abusing the open-source QEMU emulator to run hidden Alpine Linux virtual machines on compromised Windows hosts, placi

via BleepingComputer ·
cybersecuritypolicy

Sanctioned Grinex exchange loses $13.7M, pins breach on 'Western intelligence'

Grinex, a Kyrgyzstan-based crypto exchange widely regarded as a rebrand of the seized Russian platform Garantex, halted operations after attackers drained $13.7

via BleepingComputer ·
cybersecurityvulnerability

Three Defender Zero-Days Under Active Exploitation, Two Remain Unpatched

Three zero-day vulnerabilities in Microsoft Defender are being actively exploited in the wild, with only one of the flaws currently addressed by a patch. The re

via The Hacker News ·
cybersecurityidentity

Tycoon 2FA Operators Pivot to Device Code Phishing After Takedown Pressure

Operators behind the Tycoon 2FA phishing-as-a-service kit are fragmenting and shifting tactics, moving toward device code phishing as law enforcement and platfo

via Dark Reading ·
aicybersecurity

AI SOCs Stuck at Triage: Why Summarizing Alerts Isn't Running Operations

Vendors are flooding the market with 'AI SOC' platforms, but most simply accelerate the front end of the workflow — summarizing alerts, enriching events, and su

via BleepingComputer ·
tech-culturepolicy

Artemis II crew backs NASA pivot to lunar surface base after deep-space test flight

NASA's Artemis II astronauts, fresh off the first human deep-space mission in over five decades, say building a permanent lunar base is achievable on an acceler

via Ars Technica ·
cybersecurityai

ATHR turns vishing into a productized SaaS — AI agents handle the calls

ATHR is a new underground platform that productizes telephone-oriented attack delivery (TOAD) end-to-end: email lure generation, brand-specific templates, sende

via BleepingComputer ·
cybersecurityvulnerability

Cisco patches critical Webex SSO flaw, forces customers to rotate SAML certificates

Cisco pushed fixes for four critical vulnerabilities this week, headlined by CVE-2026-20184 in Webex Services. The bug sat in the SSO integration with Control H

via BleepingComputer ·
cybersecurityvulnerability

Cisco Ships Emergency Fixes for Four Critical ISE and Webex RCE Bugs

Cisco has released patches addressing four critical vulnerabilities across its Identity Services Engine (ISE) and Webex product lines, each capable of enabling

via The Hacker News ·
open-sourcedevops

Datasette 1.0a27 drops Django-style CSRF for header-based protection, adds rename events

The latest Datasette alpha replaces Django-style CSRF form tokens with a modern header-based approach modeled on Filippo Valsorda's browser-header technique. Th

via Simon Willison ·
open-sourcedevops

datasette-export-database 0.3a1 patches CSRF cookie breakage from Datasette 1.0a27

Simon Willison shipped a point release of his datasette-export-database plugin to repair a regression introduced by Datasette 1.0a27. The plugin had been relyin

via Simon Willison ·