A vulnerability named HollowByte in OpenSSL allows attackers to trigger memory allocation freezes by sending specially crafted 11-byte TLS requests. This can lead to denial-of-service conditions on affected servers. The flaw highlights ongoing security risks in widely-used cryptographic libraries.
A newly discovered botnet named NadMesh is scanning the internet for exposed AI services, aiming to steal cloud API keys and Kubernetes authentication tokens. This threat exploits misconfigured AI infrastructure, potentially allowing attackers to gain unauthorized access to cloud resources and sensitive data. Organizations relying on AI services must secure their configurations to prevent credential theft and resource hijacking.
Cybercriminals are distributing OtterCookie malware through fake coding tests, with the malicious code hidden inside SVG flag images. The attackers lure developers into downloading the tests, then execute the malware to steal sensitive data. This technique exploits trust in common coding assessment formats, making it a notable threat to tech professionals.
The push to deploy autonomous military systems is intensifying, raising concerns about whether existing information infrastructure can ensure reliability and security. This matters because failures in trust and data integrity could have severe consequences for the effectiveness and safety of these systems.
New information has emerged about a voice encryption system developed by Alan Turing during World War II. The system, called Delilah, was designed to secure telephone conversations and its technical details have now been made public. This sheds light on Turing's lesser-known contributions to cryptography and secure communications.
Armenian authorities detained a Russian tourist on a U.S. warrant linking him to the REvil ransomware group. Lawyers for the detained man argue he is the wrong person and not the intended suspect. The incident highlights the complexities of international cybercrime investigations and the risk of wrongful arrests.
Two members of the Scattered Spider hacking group were each sentenced to 5.5 years in prison for a cyberattack that stole £29 million from Transport for London. The hackers targeted the transit authority's systems, causing major disruption and financial loss. This sentence highlights the growing legal repercussions for cybercriminals targeting critical infrastructure.
The Hacker News reports on a roundup of 15 cybersecurity threats, including cheat software hiding spyware, ransomware with a 24-hour deadline, and stalkerware exploiting Chrome Sync. These attacks target gamers, enterprise systems, and everyday users, underscoring the need for vigilance against evolving digital risks.
Schneier on Security examines the escalating conflict between AI innovation and personal privacy. The article outlines key strategies and policy recommendations to protect individual data as AI systems become more pervasive. This matters because unchecked data collection threatens fundamental privacy rights in an AI-driven society.