www.zdnet.com
DuckDuckGo's new iPhone feature is a privacy win - I recommend getting it now
The iPhone version of the DuckDuckGo app has a new feature that makes sharing links easier and safer.
#hackernews is an active hashtag on Bluesky. In the last 30 days, 26 people shared 3,503 posts with it — around 117 a day. Activity is up 2% versus the previous week, peaking on Jul 15 with 167 posts.
Tags most often used together with #hackernews.
www.zdnet.com
DuckDuckGo's new iPhone feature is a privacy win - I recommend getting it now
The iPhone version of the DuckDuckGo app has a new feature that makes sharing links easier and safer.
www.theregister.com
OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack
It started with an 'impossible task' and led to AI deciding it needed to act as a collective intelligence
hackernoon.com
I Fell Into a Machinima Rabbit Hole And I’m Glad I Did
Went looking for GTA machinimas on YouTube, found Rest in Pieces by Alvin Soprano instead. Got hooked. Watched her other Sims 4 machinimas (Drained, Bone-Skinny, Goodbye Mommy.) Each one weird, funny, creepy, or all three. Loved the dry humor, subtle messages, and the odd, haunting vibe. Never played The Sims, still enjoyed it. Wish I’d found her channel before she deleted her older stuff.
www.helpnetsecurity.com
Indusface SwyftComply AI enables autonomous virtual patching for AI-discovered flaws
Indusface has announced SwyftComply AI, an autonomous vulnerability remediation solution that virtually patches vulnerabilities surfaced by AI-assisted pentesting. Artificial intelligence has changed the economics of application security. AI-powered security agents now uncover exponentially more vulnerabilities than ever before. Yet remediation has not accelerated. Security teams are overwhelmed by findings while remediation remains constrained by engineering bandwidth. The cybersecurity industry has entered a new phase: the race has moved from finding vulnerabilities to protecting applications before …
thehackernews.com
AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of the attack paths, the model never ran at all, so system prompts, content filters, and model-level guardrails never got a chance to intervene. The affected products include Amazon
thehackernews.com
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it. A third flaw could expose sensitive data and control-plane details through application programming interface (API) routes
www.spreaker.com
Wall Street Under Cyber Attack
https://www.osintinvestigate.com In this episode , we explore the recent cyberattack attempts targeting some of Wall Street's largest financial institutions. Discover how hackers are shifting from traditional malware to sophisticated social engineering, AI-powered phishing, and voice impersonation techniques to breach even the most secure organizations. We discuss why the financial sector remains a prime target, how companies are strengthening their cyber defenses, and what individuals can learn from these evolving threats. Whether you're a cybersecurity professional, tech enthusiast, or simply interested in the latest hacker news, this episode offers valuable insights into the ever-changing landscape of digital security.
thehackernews.com
29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy. The bug traces to a 1997 FTP-parsing change and is still live in Squid's default configuration. Researchers at Calif.io disclosed it in June and named it Squidbleed (
www.helpnetsecurity.com
Global tensions are pushing cyber activity toward dangerous territory
Cybersecurity is inseparable from geopolitics. Ongoing conflicts, sanctions, trade wars, geoeconomic rivalry, and technological competition have pushed state competition into cyberspace. States use cyber operations to exert pressure on rivals, enabling disruption without resorting to conventional weapons. Infrastructure vulnerabilities in a geopolitical context 72% of IT leaders worry that nation-state cyber capabilities could tip into a full-scale cyberwar, and that critical infrastructure would be hit hardest. Although the cause was not a cyberattack, the large-scale …
thehackernews.com
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The "evil twin" extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as of
www.bleepingcomputer.com
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. [...]
hackernoon.com
62 Blog Posts To Learn About Gpu
Learn everything you need to know about Gpu via these 62 free HackerNoon blog posts.
seclists.org
Dangling DNS record for bastion.certb.cdp.bethesda.net
Posted by shed riot on Aug 06# Summary The hostname resolved to an address within a dynamic cloud IP pool. The address had been released and was no longer controlled by the organisation operating the hostname. This condition is referred to as an "afterlife" issue. Unlike a conventional CNAME-based subdomain takeover, the DNS record pointed directly to a reusable cloud IP address. An attacker obtaining that address could receive traffic intended for the...
seclists.org
CL.0 desync in www.microsoft.com
Posted by shed riot on Aug 06# Summary I reported the issue to the Microsoft Security Response Center twice: * VULN-165381, MSRC case 102964 * VULN-165876, MSRC case 103259 In both cases, they do not appear to have even looked at the PoCs, and so have failed to adequately investigate before reaching a decision. # Vulnerability CWE-444: HTTP Request/Response Smuggling The observed behaviour was consistent with CL.0 HTTP desync within the request-processing chain. #...
seclists.org
CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass (PoC)
Posted by Öner Efe Güngör on Aug 06Hello Full Disclosure, I'd like to share an independent lab Proof-of-Concept for CVE-2026-15013. ### CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass SAML Signature Algorithm Confusion vulnerability. An unauthenticated attacker can forge a valid SAMLResponse by forcing HMAC-SHA1 verification against the IdP's public key, allowing full account takeover (including administrators). Root cause:...
seclists.org
[KIS-2026-16] Telenia Software TVox <= 26.5.3 (nice) Local Privilege Escalation Vulnerability
Posted by Egidio Romano on Aug 06------------------------------------------------------------------------------- Telenia Software TVox <= 26.5.3 (nice) Local Privilege Escalation Vulnerability ------------------------------------------------------------------------------- [-] Software Link: https://www.teleniasoftware.com [-] Affected Versions: Version 26.5.3 and prior 26.x versions. Version 24.9.21 and prior 24.x versions. Older versions may be affected as well. [-]...
seclists.org
[KIS-2026-15] Telenia Software TVox <= 26.5.3 (action_audio.php) OS Command Injection Vulnerability
Posted by Egidio Romano on Aug 06------------------------------------------------------------------------------------- Telenia Software TVox <= 26.5.3 (action_audio.php) OS Command Injection Vulnerability ------------------------------------------------------------------------------------- [-] Software Link: https://www.teleniasoftware.com [-] Affected Versions: Version 26.5.3 and prior 26.x versions. Version 24.9.21 and prior 24.x versions. Older versions may be affected...
seclists.org
[KIS-2026-14] Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass Vulnerability
Posted by Egidio Romano on Aug 06--------------------------------------------------------------------------------- Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass Vulnerability --------------------------------------------------------------------------------- [-] Software Link: https://www.teleniasoftware.com [-] Affected Versions: Version 26.5.3 and prior 26.x versions. Version 24.9.21 and prior 24.x versions. Older versions may be affected as well....
seclists.org
[KIS-2026-13] vBulletin <= 6.2.1 (runMaths) Remote Code Execution Vulnerability
Posted by Egidio Romano on Aug 06----------------------------------------------------------------- vBulletin <= 6.2.1 (runMaths) Remote Code Execution Vulnerability ----------------------------------------------------------------- [-] Software Link: https://www.vbulletin.com [-] Affected Versions: Version 5.7.5 and prior 5.x versions. Version 6.2.1 and prior 6.x versions. [-] Vulnerability Description: The vulnerable code is located within the...
seclists.org
[SYSS-2026-050]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)
Posted by Matthias Deeg via Fulldisclosure on Aug 06Advisory ID: SYSS-2026-050 Product: DCMTK (DICOM ToolKit) Manufacturer: OFFIS e.V. / DCMTK Community Affected Version(s): 3.7.0 Tested Version(s): 3.7.0 Vulnerability Type: Integer Overflow or Wraparound (CWE-190) Risk Level: Medium Solution Status: Fixed Manufacturer Notification: 2026-07-02 Solution Date: 2026-07-03 Public Disclosure:...
Posts are pulled live from Bluesky and cached briefly. Posts with content labels are hidden.