Knee-jerk corporate responses to data leaks protect brands like Qantas — but consumers are getting screwed

Source

When courts ban people from accessing leaked data – as happened after the airline’s data breach – only hackers and scammers win Follow our Australia news live blog for latest updates Get our breaking news email, free app or daily news podcast It’s become the playbook for big Australian …

Two Windows vulnerabilities, one a 0-day, are under active exploitation

Source

Two Windows vulnerabilities—one a zero-day that has been known to attackers since 2017 and the other a critical flaw that Microsoft initially tried and failed to patch recently—are under active exploitation in widespread attacks targeting a swath of the Internet, researchers say. The zero-day went undiscovered until …

Cloud CISO Perspectives: AI as a strategic imperative to manage risk

Source

Welcome to the second Cloud CISO Perspectives for October 2025. Today, Jeanette Manfra, senior director, Global Risk and Compliance, shares her thoughts on the role of AI in risk management. As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the Google Cloud blog. If …

Invisible npm malware pulls a disappearing act – then nicks your tokens

Source

PhantomRaven slipped over a hundred credential-stealing packages into npm A new supply chain attack dubbed PhantomRaven has flooded the npm registry with malicious packages that steal credentials, tokens, and secrets during installation. The packages appear safe when first downloaded, making them particularly difficult for security apps to identify.... [...]

NPM flooded with malicious packages downloaded more than 86,000 times

Source

Attackers are exploiting a major weakness that has allowed them access to the NPM code repository with more than 100 credential-stealing packages since August, mostly without detection. The finding, laid out Wednesday by security firm Koi, brings attention to an NPM practice that allows installed packages to automatically pull …

New physical attacks are quickly diluting secure enclave defenses from Nvidia, AMD, and Intel

Source

Trusted execution environments, or TEEs, are everywhere—in blockchain architectures, virtually every cloud service, and computing involving AI, finance, and defense contractors. It’s hard to overstate the reliance that entire industries have on three TEEs in particular: Confidential Compute from Nvidia, SEV-SNP from AMD, and SGX and TDX …

Signal’s Post-Quantum Cryptographic Implementation

Source

Signal has just rolled out its quantum-safe cryptographic implementation. Ars Technica has a really good article with details: Ultimately, the architects settled on a creative solution. Rather than bolt KEM onto the existing double ratchet, they allowed it to remain more or less the same as it had been …

« newer articles | page 83 | older articles »