New display technology enables screens to capture video and images without separate cameras. This raises significant privacy and surveillance concerns as the same surface used for viewing can now record users. The development could change how devices are designed and how privacy is protected in public and private spaces.
Two previously unknown vulnerabilities in SonicWall's SMA 1000 series have been actively exploited in attacks. One of the flaws could allow attackers to execute arbitrary commands with administrative privileges. Organizations using the affected devices should apply patches immediately to prevent compromise.
Security researchers identified a vulnerability in the Claude for Chrome extension that lets malicious browser extensions access Gmail data without proper authorization. The flaw stems from incorrect permission handling in the AI assistant tool. This matters because it could expose sensitive email content, emphasizing the security risks of third-party browser extensions.
A new remote access trojan, LabubaRAT, is being distributed disguised as legitimate NVIDIA software to infect Windows hosts. Once installed, attackers can gain full control over the compromised system, including executing commands and stealing data. Users should verify software sources carefully to avoid infection.
A study of 85 cryptocurrency browser extensions found that many leak wallet addresses and allow cross-site tracking of users. This poses privacy and security risks for individuals using these extensions to manage digital assets. The findings highlight the need for users to be cautious about the extensions they install.
Pentera has developed a method to convert AI security workflows into validation engines that continuously test defenses. This approach helps organizations identify vulnerabilities and improve security posture through automated, realistic attacks. It matters because it enables proactive and efficient security testing without manual effort.
A security vulnerability has been identified in FIFA's network infrastructure. The flaw could potentially expose sensitive data or allow unauthorized access. This matters because FIFA manages global football operations and personal data of millions.
A discovery reveals that the AI tool Grok transmits complete Git repositories to xAI’s servers, rather than only the specific files it reads. This raises privacy concerns for developers, as entire codebases may be stored without user consent or awareness. The issue highlights potential data exposure risks in AI-assisted development workflows.
The US Treasury's OFAC imposed sanctions on a VPN provider and a malware cryptor seller for assisting ransomware attacks. This marks the first time a VPN service has been targeted, aiming to disrupt ransomware payment infrastructure and deter enablers.