Book Release of the XZ Backdoor Incident: 'Half a Second' Available for Free
A Microsoft engineer's discovery of a backdoor in XZ Utils, prompted by a 0.5-second login lag, is now documented in a free book under CC BY-NC-ND 4.0.
A Microsoft engineer's discovery of a backdoor in XZ Utils, prompted by a 0.5-second login lag, is now documented in a free book under CC BY-NC-ND 4.0.
An Egyptian developer uses an ESP32-C3 microcontroller to build a DNS filter capable of blocking 537,000 domains. Leveraging 40-bit FNV-1a hashing, it fits within 4MB of flash memory.
On the same day Microsoft released a record-breaking number of patches, an anonymous researcher unveiled exploit code for a zero-day vulnerability, HiveLegacy, allowing low-privilege users to manipulate admin account registries.
xAI has filed a lawsuit against a man for generating and distributing CSAM using Grok. The focus is on safeguard circumvention and legal accountability of AI platforms.
Debian 13.6 point release is now available, featuring numerous security updates for Linux kernel, Nginx, and more. GeoIP database rolled back due to non-compliance with DFSG, and fwupd 2.0.20 addresses expired UEFI Secure Boot CA.
Researchers at Tel Aviv University have unveiled the "HalluSquatting" attack, a method exploiting AI hallucinations to execute malicious code, exposing vulnerabilities in all LLMs.
Patches have been merged into Linux 7.2-rc2 to implement indirect branch predictor and IBPB flushes in BPF JIT allocator memory reuse, significantly reducing the risk of JIT spraying attacks.
A review of Bitdefender VPN. Its $35 first-year price and simplicity stand out, but it lacks advanced privacy features. Wired's rating: 7/10.
AMD will restore TSME memory encryption for non-PRO Ryzen 9000 CPUs in July through a BIOS update, following community feedback.
Hacker group ShinyHunters exploited Oracle PeopleSoft zero-day CVE-2026-35273, breaching over 100 organizations, including the University of Nottingham, where 40 GB of data was stolen. Google threat intel confirms.
Account hijacking occurred on French government encrypted messaging service Tchap. ANSSI has launched an investigation, and authorities claim only public chats were compromised, but hackers claim access to over 70,000 user records.
This site uses cookies for access analysis and ad delivery. By clicking "Accept", you consent to the use of cookies. See our Privacy Policy for details.