Android Car Head Units Hit by Supply-Chain Proxy Botnet Attack
A supply-chain attack on Android car head units uses a legitimate update app to spread malware that builds a proxy botnet or commits ad fraud.
VPN & PrivacyA supply-chain attack on Android car head units uses a legitimate update app to spread malware that builds a proxy botnet or commits ad fraud.
VPN & PrivacyToxicPanda 2.0 adds 167 remote commands and targets 349 financial institutions. GoldDigger expands to South Africa and the U.K. via fake airline and retail apps
GuidesComcast's new Xfinity Shield platform uses existing WiFi signals to detect motion inside homes. Privacy questions remain over data retention and third-party dis
VPN & PrivacyTwo new papers examine how LLMs fail to control sensitive information flow based on context, and how reasoning and reinforcement learning may help.
GuidesA ransomware affiliate called Ransom Busters is charging victims $20,000–$60,000 to delete their stolen data, while posing as a helpful third party.
ToolsAmnesiaStealer is a new macOS infostealer distributed via ClickFix attacks. It clones browser profiles and gives attackers live, interactive control of authenti
Guides
Bruce Schneier has several public speaking engagements scheduled for fall 2026, spanning security conferences, festivals, and civic events across North America.
A compelling video explores deep-sea search techniques, showing how red light and bait reveal more about giant and colossal squid than traditional methods.
Delta Air Lines is investigating an unauthorized Wi-Fi network and deauthentication attack on a Las Vegas-to-Atlanta flight carrying DEF CON attendees.
Three vulnerabilities in Zoom's annotation tool allowed remote code execution with no user interaction. Patches shipped in June and July 2026.
AI tutoring tools are growing fast, but quality and safeguards vary widely. Parents should understand the privacy, security, and developmental risks involved.
A threat actor compromised BdThemes' upstream infrastructure to inject malicious JavaScript that creates rogue WordPress admin accounts on affected sites.
N-able issued a mandatory second hotfix for CVE-2026-18577 after threat actors evolved attack techniques to reach managed endpoints via Cloudflare Tunnels.
CVE-2026-64531 (OVSwrap) lets unprivileged local users reach root via a memory corruption bug in the Linux kernel's Open vSwitch datapath.
A multi-wave campaign uses fake Adobe and Zoom update lures to deploy ConnectWise ScreenConnect. A separate campaign distributes the Powercat Java stealer via f