- — Thousands of servers can be backdoored by exploiting buggy motherboard controllers
- Baseboard management controllers from the world's biggest manufacturers are a security mess.
- — Claude published malicious code to the Internet and attacked 3 real companies
- Had the hacks used conventional methods, someone would likely go to prison.
- — Max-severity Exchange server flaw under active exploitation by Kremlin hackers
- Exploits can give persistent server access that survives credential rotation and disk re-imaging.
- — Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
- HAWK withstood years of testing that had yet to uncover a fatal weakness found through Mythos.
- — We now have a better understanding how OpenAI hacked into Hugging Face
- 10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch.
- — Microsoft unveils AI security tools it says outperform competing platforms
- Microsoft says tools cost less than competing ones and outperform them, too.
- — TreeSize won't renew perpetual-license support unless users subscribe
- "Current economic conditions" have shifted TreeSize's business model.
- — HP fined 1.4 billion rupees for “cartelization” of ink cartridges, toner, PCs
- Resellers threatened to ditch HP printing supplies for counterfeits.
- — Now, even Russia's most elite hackers are using Clickfix to infect devices
- The social-engineering technique has primarily been a tool of financially motivated criminals.
- — Energy IPOs surge as investors hunt for ways to play AI boom
- Companies coming to market are raising money at fastest pace this century.
- — Sheetz is quitting VMware, migrating 11,000 virtual machines
- The convenience store chain will use StorMagic instead.
- — Windows 0-day drops the same day Microsoft releases record number of patches
- HiveLegacy is a "powerful primitive" that's likely capable of other nefarious actions.
- — Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
- Old and forgotten "shims" Microsoft failed to revoke have made Secure Boot bypasses simple.
- — The US government warns that Russia state hackers are coming after your router
- With residential proxies all the rage, CISA urges router users to be vigilant.
- — Now, defenders are embracing the prompt injection, too
- "Context bombing" tricks hacking agents into shutting down before they can do harm.
- — Patch for Windows Defender 0-day could allow attackers to fill hard disk
- The feud between NightmareEclipse and Microsoft shows no signs of resolving soon.
- — Allstate accuses Broadcom of auditing it because it quit VMware, CA
- Broadcom accuses Allstate of dodging VMware audits.
- — Google pays $250K for Linux vulnerability allowing guest VM escapes
- Both vulnerabilities allow untrusted users to gain root privileges.
- — Aussie gov't tells volunteers to throw out thousands of functioning test routers
- But the devices could "easily be reflashed."
- — US rare earths flow to Asia as domestic demand is slow to emerge
- Miners backed by Trump admin sell to Japan, South Korea despite push to develop domestic supply chain.
- — Hackers can use 9 of the most popular AI tools to assemble massive botnets
- "HalluSquatting" weaponizes LLMs' inability to say "I don't know."
As of 8/9/26 11:19am. Last new 8/5/26 5:30pm.
- Next feed in category: Wired


![direct link [l]](img/ib-link_nm.png)