generalnews.media
All World Business Technology Science Health Sports Entertainment Security
336 stories
science security technology

OpenAI and Hugging Face Partner to Address Model Evaluation Security Incident

OpenAI and Hugging Face announced a partnership to address a security incident that occurred during a model evaluation. The collaboration aims to investigate and resolve the issue, which could affect the integrity of AI model assessments. This matters because it highlights vulnerabilities in AI evaluation processes and the need for cross-company security cooperation.

Exclusive

Apple Fixes Bug That Exposed Real Emails in Hide My Email Feature

Apple has patched a bug in its Hide My Email feature that inadvertently exposed users' real email addresses in Mail logs. The issue could have allowed recipients or service providers to see the actual email behind the masked address. The fix prevents further privacy breaches for iCloud+ subscribers.

entertainment science security technology

Google DeepMind Unveils Gemini 3.6 Flash and Cybersecurity AI Model

Google DeepMind has introduced Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber AI models. The new 3.5 Flash Cyber variant is specifically designed to detect and fix software vulnerabilities. This launch underscores Google's push to integrate advanced AI into security operations.

Exclusive

Qilin Ransomware Uses PAN-OS Flaw for Initial Access

The Qilin ransomware group has been observed exploiting an authentication bypass vulnerability in Palo Alto Networks' PAN-OS to gain initial access to target networks. This attack technique allows the group to bypass security controls and deploy ransomware more efficiently. The incident highlights the ongoing risk of unpatched vulnerabilities in widely used enterprise security appliances.

Exclusive

MIT Becomes Hub for AI Video Surveillance Research

MIT is reportedly intensifying its focus on AI-powered video surveillance, becoming a major center for related research and development. This move raises significant privacy and ethical concerns, as well as questions about the future role of surveillance technologies in society. The development highlights the growing intersection of academic research and potentially controversial surveillance applications.

Exclusive

Public WordPress 'wp2shell' Exploit Triggers Mass Scanning

Attackers are actively exploiting a public proof-of-concept for the WordPress "wp2shell" vulnerability, which allows remote code execution. The release of the exploit has led to widespread scanning and attacks on unpatched WordPress sites. This increases the risk of site compromise if administrators do not apply available security updates.

Exclusive

ENCFORGE Ransomware Attacks Langflow via RCE, Targets AI Model Files

A new ransomware strain named ENCFORGE is exploiting a remote code execution vulnerability in Langflow to encrypt AI model files. The attack targets users of Langflow, an open-source tool for building AI applications. This matters because it underscores the increasing risk to AI infrastructure and the need to secure model files against targeted ransomware.

Exclusive

FakeGit Campaign Uses 7,600 GitHub Repos to Spread SmartLoader Malware

A widespread campaign called FakeGit has deployed over 7,600 fraudulent GitHub repositories to distribute SmartLoader malware. The repositories are designed to trick users into downloading malicious files disguised as legitimate projects. This large-scale operation poses a significant threat to developers and open-source users who might inadvertently install the malware.

Exclusive

HollowGraph Malware Hides Command Server & Stolen Data in Microsoft 365 Events

Cybersecurity researchers discovered the HollowGraph malware, which conceals its command-and-control server and stolen files within Microsoft 365 events timestamped in the year 2050. This novel evasion technique exploits future-dated calendar entries to bypass detection. The discovery highlights the evolving sophistication of threats targeting cloud services.