Organizations are rushing to implement AI without fully grasping where its legal protections begin and end.
Hi, what are you looking for?
Organizations are rushing to implement AI without fully grasping where its legal protections begin and end.
SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs.
The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers.
Corma emerged from stealth with seed funding from Sequoia Capital, Khosla Ventures, and Coatue.
The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data.
Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did.
OpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI.
The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it.
The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold.
The startup analyzes subtle telemetry signals to detect attacks that traditional security tools cannot see inside accelerator-powered AI infrastructure.
Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition.
An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word.
Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states.
The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.
CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.
The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands.
Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them.
The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies.
The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data.
Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing.