Security
Showing 12 of 140 articles · Page 4 of 12

FROST Attack: How Websites Spy on Your SSD Activity via Browser Tabs
Discover how the FROST attack uses SSD activity and JavaScript to spy on your open tabs and apps without your consent.

Carnival Cruise Data Breach Exposes Information of 6 Million Customers
Carnival Cruise confirms a data breach affecting 6 million customers after a social engineering attack. ShinyHunters claims to have stolen terabytes of data.

New Security Risk: Attackers Poison SKILL.md Files for Prompt Injection
Security researchers reveal how simple modifications to SKILL.md files can lead to prompt injection and help attackers bypass AI detection mechanisms.

Google API Keys Remain Active After Deletion
Security research reveals Google API keys remain functional for up to 16 minutes after deletion, requiring a 30-minute safety window for security teams.

Missing Documents Lead to Release of R$800 Million Hackers in Spain
Brazilian hackers who stole R$800 million were released in Spain after Brazil missed an extradition deadline. Learn more about the procedural error.

Microsoft Accused of Intentional Backdoor in BitLocker Encryption
Researcher Nightmare-Eclipse claims Microsoft added a backdoor to BitLocker (CVE-2026-45585) affecting Windows 11 and Windows Server 2022/2025.

Google Accidentally Leaks Exploit Code for Unpatched Chromium Vulnerability
Google leaks Chromium exploit code for a long-standing unpatched flaw. Learn how it affects Brave, Edge, and Opera users and how to stay safe.

CISA GitHub Repository Leak: Plaintext Passwords Exposed for Months
CISA exposed plaintext passwords and private keys on a public GitHub repository for six months before a security researcher reported the leak.

GitHub Investigates Massive Internal Code Leak via Malicious VS Code Extension
GitHub confirms 3,800 internal repositories leaked after a malicious VS Code extension attack. Customer data is safe as investigation continues.

Grafana Codebase Stolen After GitHub Token Compromise
Grafana Labs refuses to pay ransom after an attacker used a stolen GitHub token to capture the company's full source code. No customer data was compromised.

Microsoft Patches 137 Vulnerabilities Including Rare Perfect 10 Severity Score
Microsoft releases patches for 137 CVEs, including 30 critical flaws and a CVSS 10.0 vulnerability. Secure your systems against these high-risk bugs.

Google Identifies First AI-Generated Zero-Day Exploit
Google detects the first AI-generated zero-day exploit designed to bypass 2FA. Learn how AI models are now being used to find and weaponize code flaws.