Comcast Xfinity Shield Uses WiFi Signals as Home Motion Detectors
Comcast's new Xfinity Shield platform uses existing WiFi signals to detect motion inside homes. Privacy questions remain over data retention and third-party dis
VPN & PrivacyComcast's new Xfinity Shield platform uses existing WiFi signals to detect motion inside homes. Privacy questions remain over data retention and third-party dis
VPN & PrivacyTwo new papers examine how LLMs fail to control sensitive information flow based on context, and how reasoning and reinforcement learning may help.
GuidesAmnesiaStealer is a new macOS infostealer distributed via ClickFix attacks. It clones browser profiles and gives attackers live, interactive control of authenti
GuidesBruce Schneier has several public speaking engagements scheduled for fall 2026, spanning security conferences, festivals, and civic events across North America.
ThreatsDelta Air Lines is investigating an unauthorized Wi-Fi network and deauthentication attack on a Las Vegas-to-Atlanta flight carrying DEF CON attendees.
GuidesThree vulnerabilities in Zoom's annotation tool allowed remote code execution with no user interaction. Patches shipped in June and July 2026.
VPN & Privacy
AI tutoring tools are growing fast, but quality and safeguards vary widely. Parents should understand the privacy, security, and developmental risks involved.
A threat actor compromised BdThemes' upstream infrastructure to inject malicious JavaScript that creates rogue WordPress admin accounts on affected sites.
N-able issued a mandatory second hotfix for CVE-2026-18577 after threat actors evolved attack techniques to reach managed endpoints via Cloudflare Tunnels.
CVE-2026-64531 (OVSwrap) lets unprivileged local users reach root via a memory corruption bug in the Linux kernel's Open vSwitch datapath.
A multi-wave campaign uses fake Adobe and Zoom update lures to deploy ConnectWise ScreenConnect. A separate campaign distributes the Powercat Java stealer via f
A Chinese-speaking threat actor is running 100+ fake AWS and Apple ID pages to deliver the leaked DarkSword iOS exploit kit and GHOSTBLADE malware.
Hugging Face released a forensic timeline of the OpenAI agent intrusion, reconstructing ~17,600 attacker actions across a two-stage campaign targeting its infra
A critical flaw in Rails' Active Storage framework allows unauthenticated file reads and potential RCE. Patch immediately and rotate all secrets.
Laundry Bear is exploiting a zero-day XSS flaw in Exchange OWA to deploy the OWAReaper backdoor, enabling persistent mailbox access that survives credential res