Android Car Head Units Hit by Supply-Chain Proxy Botnet Attack
A supply-chain attack on Android car head units uses a legitimate update app to spread malware that builds a proxy botnet or commits ad fraud.
VPN & PrivacyA supply-chain attack on Android car head units uses a legitimate update app to spread malware that builds a proxy botnet or commits ad fraud.
VPN & PrivacyToxicPanda 2.0 adds 167 remote commands and targets 349 financial institutions. GoldDigger expands to South Africa and the U.K. via fake airline and retail apps
GuidesComcast's new Xfinity Shield platform uses existing WiFi signals to detect motion inside homes. Privacy questions remain over data retention and third-party dis
VPN & PrivacyA critical GitLab flaw rated CVSS 9.4 requires no authentication to exploit. Self-managed users should patch immediately or restrict GraphQL access.
GuidesTwo new papers examine how LLMs fail to control sensitive information flow based on context, and how reasoning and reinforcement learning may help.
GuidesA ransomware affiliate called Ransom Busters is charging victims $20,000–$60,000 to delete their stolen data, while posing as a helpful third party.
Tools
AmnesiaStealer is a new macOS infostealer distributed via ClickFix attacks. It clones browser profiles and gives attackers live, interactive control of authenti
Bruce Schneier has several public speaking engagements scheduled for fall 2026, spanning security conferences, festivals, and civic events across North America.
A free service called DecryptAds scrapes public adtech files to show which companies track users across websites and apps, flagging high-risk ad partners.
A compelling video explores deep-sea search techniques, showing how red light and bait reveal more about giant and colossal squid than traditional methods.
AI models are discovering software vulnerabilities at unprecedented scale. Could this surge eventually lead to safer, near-flaw-free software?
Delta Air Lines is investigating an unauthorized Wi-Fi network and deauthentication attack on a Las Vegas-to-Atlanta flight carrying DEF CON attendees.
Three vulnerabilities in Zoom's annotation tool allowed remote code execution with no user interaction. Patches shipped in June and July 2026.
AI tutoring tools are growing fast, but quality and safeguards vary widely. Parents should understand the privacy, security, and developmental risks involved.
A threat actor compromised BdThemes' upstream infrastructure to inject malicious JavaScript that creates rogue WordPress admin accounts on affected sites.